Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, March 19, 2012

Cybersecurity is hard, we need some assist


Cybersecurity is so much harder than physical security! In physical security, you have a well-defined physical perimeter -- your doors, windows, gates etc -- to watch and protect, but in cybersecurity the perimeter is not well-defined. Think of cybersecurity for a typical home or business -- you usually have a box -- the “router,” perhaps a wireless one -- that lets you connect your network of PCs and other devices to the Internet via your Internet Service Provider. Although there is a single physical connection to the Internet, the software applications in your PCs and devices are making lots of network connections. If you think of each of these as a door, it’s like trying to watch over and protect thousands of doors at once and, on top of that, you need to check the packets of information that are coming in and going out of these “doors” -- like checking each visitor to a building, only the number of visitors is in the billions! To make matters worse, the software applications -- think of Web browsers, Office suite, PDF reader, etc have their own weaknesses and could serve as gateways through which bad guys get access to your information... so that’s even more “doors” to protect. Anyway, you get the idea -- compared to physical security, cybersecurity is too difficult for us to tackle in a routine manner.

Does that mean we do nothing about cybersecurity? Of course not! We already try to do our best with antivirus and firewalls etc, but to keep up with the ever-changing number and types of “doors” that we have to watch over, we need some assist from the information security companies.

First, we need a way to monitor the status of cybersecurity, similar to the way we have guards monitoring doors, fences, and gates through video cameras etc. Only in cybersecurity, someone needs to build a simple dashboard to show us how well our defenses are working against the torrent of potential malicious packets coming through the cyber “doors” to our network.

Second, someone needs to build a consumer “cybersecurity appliance” -- I envision a box that sits between that router and the rest of your network, a box that watches over all the network connections and does whatever is needed to keep our internal network safe. Come to think of it, the cybersecurity appliance can both monitor cybersecurity and provide protection.

I hope someone takes up the challenge and builds us a “cybersecurity appliance” someday soon.


Here's some more information to help you...
You may find the following books useful:




Here's an old GAO report that's still quite relevant: 

Cybersecurity for Critical Infrastructure Protection

GAO-04-321, May 28, 2004

Here's a presentation on Cybrsecurity research an development (R&D) based on this report:

Thursday, January 19, 2012

Cloud security from a user’s point of view



As more and more of us begin to rely on cloud services, security is definitely one of the topmost concerns on our mind. From the user’s perspective, whether it’s an individual or an organization, cloud security translates to protecting the information that you’re storing on the cloud. You want the information to be available when you want it, and not be shared with anyone that you don’t want to share with, and make sure that nobody changes that inform ation without your permission or knowledge.
When you use cloud services the cloud provider has a lot of responsibilities for security, but you also share the responsibility of making sure that your login information is secure and you use any security features that are available to you. For example, if the cloud provider offers 2-step verification, as Google does, then you must make sure that you turn on this extra security feature.
As a user, you know that the same cloud services are used by many other users, so you definitely want your cloud service to offer good walls between you and your neighbors so that information cannot maliciously or inadvertently be shared with your neighbors. You’d also want the cloud provider to back up your information and protect it from loss due to technical or natural disasters.
In a nutshell, cloud security is a shared responsibility, where you take care of using all the security features available to you for the login process and the provider carries a much larger burden of protecting your information from other users as well as from outsiders. in particular you’d expect the cloud provider to employ the best security personnel available, follow the latest security procedures,  and adopt the latest technology to keep users separate from each other and to keep any outside attackers away from your information. From my perspective, I think this is what users expect from cloud security.
Here's some more information to help you...
For my earlier videos on cloud security, please see:



Tuesday, November 22, 2011

NBTMV - Turn on 2-step verification on your Google account



In previous videos I have mentioned how important it is to turn on 2-step verification (or 2-factor authentication) on your Google account. In this three-minute video, I’ll walk you through the process because you really ought to do this.
After you turn on 2-step verification, to log into your Google account, you have to first enter your normal password and then you have to enter a verification code that Google sends to your phone. Even if someone steals your password, they’d face the additional step of having to enter the verification code before getting into your account. That;s why you should turn on 2-step verification -- to get the benefit of an extra layer of security.
To set up 2-step verification, first log into your Gmail (or Google+) account and click on your name or your profile photo on the upper right hand corner. You’ll get a Google Accounts overview page showing all the settings. Click the “Edit” link next to “Using 2-step verification”. That will take you to the page where you have to enter your current password and then you'll get the page where you can click a link to turn on 2-step verification. You’ll then go through steps where you enter a phone number to receive the verification code and test that it works. You also need to enter a backup phone number for the verification code, in case your primary phone is not available.
At this point, you should also generate the printable backup codes that you can use when you don’t have your phone or can’t use your phone. Google generates 10 backup verification codes that you should print out and carry in your wallet. In a pinch, you can use these one at a time when you need them.
For accessing Google services such as Gmail on a smartphone or a tablet or when you read Gmail using Microsoft Outlook, you have to generate and use application-specific passwords. There is a link on 2-factor authentication page for application specific passwords. You should pick a descriptive name for the application such as “Gmail on my smartphone” and then click Generate Password. Then enter that long complicated looking password (ignore the spaces) in place of your normal password. You have to enter the password only once for each application and you can always revoke a password and generate a new one.
That, in a nutshell, is how you turn on 2-step verification. If you haven't done so already, I hope you'd turn it on as soon possible.
Here's some more information to help you...
To learn a bit more about 2-step verification, see the Google support page on Getting started with 2-step verification and for more on application-specific passwords, you can:  Watch the video on application-specific passwords 

Sunday, November 6, 2011

Why public cloud





In previous videos I discussed what is cloud computing, why it’s important to consider as an option, and what are some of the risks.
Because of the risks, especially those relating to security and loss of control over where data resides, your organization may prefer the private cloud option, which, as I have said previously, is still a good option that provides you with the benefits of reduced number of physical machines along with lower electricity and cooling needs, as well as needing fewer staff to administer the machines.
However, unless your organization has hundreds of thousands of employees, a private cloud is not going to give you the cost savings that come from the economies of scale that public clouds enjoy.
To implement the private cloud, you’ll need upfront investment to virtualize your servers and add the software needed to operate it as a cloud. You are not going to just pay for what computing resources you need - - you basically still have to maintain the systems you need for your worst-case computing load.
Some go as far as to say that a private cloud is not a cloud at all because a cloud should have “elasticity” - - meaning you can create new virtual machines on demand and shut them down when you don’t need them. A private cloud cannot easily provide this elasticity, unless it’s for a huge number of employees.
With a public cloud, you can truly pay for computing as you go - - just buy what you need, when you need it. That’s why, unless you have hundreds of thousands of employees or information that’s very sensitive (like military information), you have to consider public clouds to get the benefits of cloud computing. If that’s not acceptable, you can consider a community cloud suitable for your organization. For example, government agencies could opt for a government community cloud where you could at least get some economies of scale.

Here's some more information to help you
Here are some books on cloud computing that you may consider:

Saturday, October 29, 2011

What are some of the risks of Cloud Computing



In other videos I explained what cloud computing is and why it’s useful. In this video, I want to mention some of the risks of cloud computing - - things that could potentially go wrong and affect your organization when you use cloud computing. Of course, if you implement a cloud in your own data center for your organization’s use, then the risks are similar to ones you already have - - security, privacy, disaster recovery, etc.

However, if you are planning to use cloud services provided by a third party, then you need to think of any new risks that may apply to your situation and that’s what I’ll cover.
First, the obvious risks - - security and privacy risks because of not knowing whether the vendor’s cloud is secure, that the staff who manages the facilities are trustworthy, that privacy protections are up to the level required by law.
Second, we have some management and oversight risks - - relating to potential lack of control in figuring out where data is stored and processed and how to get it back, if you change provider. The oversight risk is the possibility that your auditor cannot get access to the cloud provider’s systems to check them out.
Third, there are some technical risks, relating to lack of standard definitions of what a cloud service is, how are fees set, how to move data from one cloud to another, whether you can get reliable performance...
And, finally, a fourth set of risks may be relating to potential foreign laws and regulations that apply to your data because of where the cloud service is located.
Anyway, this is not an exhaustive list, but the point is that you should think what risks apply to you and then manage them, as is the prudent thing to do. Some risks already have mitigation approaches such as putting things in the contract and some have ongoing activities to help business mitigate those risks.
And, even if there is no mitigation for some, you may still decide to accept the risks and forge ahead with cloud computing. After all, that’s how we get the good things in life... by taking risks.



Here are some more things to help you...

Please see my previous post on "What is Cloud Computing" - - there I have a slide presentation on cloud computing that I used when I gave a talk in Seoul, Korea in Nov 2010 and the 30-minute video of the talk as well.

Why you should consider cloud computing as an option





You might wonder why is “cloud” a big deal. First, and foremost, if you have a collection of servers for your business, once you use virtualization, you’ll be able to support many virtual machines on a small number of physical machines - - some experts suggest that for each “core” on an Intel or AMD processor, you can have 3 to 5 virutal machines. Many servers are 4- or 6-core, so you could have anywhere from 12 to 30 virtual machines on one server, but you’d need to have lots of memory and storage as well. Nevertheless, the ability to run lots of virtual machines on a physical server means that you reduce the number of physical servers and that translates to less space, less electricity, less heat, and less messy cables, etc. So these benefits make a cloud an worthwhile proposition for businesses, even if you were to convert your current server farm to a cloud.
If you can move on to buying the cloud services from a third party, the benefits are even more. Now you can simply buy the computing power you need, without having to spend money up front. You can benefit from the economy of scale, the cloud vendor would typically have better redundant power and network connectivity that you could afford. Even security may be enhanced because the cloud provider can afford to hire more experienced information security staff and apply patches across all virtual machines more efficiently and promptly than you could.
You’d notice that I have a lot of “may” and “could” in justifying the benefits of cloud, that’s because you have to check it out for yourself to see if it meets the needs of your business. What you don’t want to do is dismiss cloud as an option because of knee-jerk reaction from others inside your organization who may bring up risks relating to security, data ownership, and many other issues as reasons why you shouldn’t go the cloud. All of these may be valid risks, but they also have equally valid solutions that mitigate the risk enough for you to take the plunge. The savings in IT costs alone make it worth taking the step to, at least consider cloud services as an option.


Here are some more things to help you...


Please see my previous post on "What is Cloud Computing" - - there I have a slide presentation on cloud computing that I used when I gave a talk in Seoul, Korea in Nov 2010 and the 30-minute video of the talk as well.


Tags: