Showing posts with label virtualization. Show all posts
Showing posts with label virtualization. Show all posts

Wednesday, August 14, 2013

Some defenses against Advanced Persistent Threats




Remember that Advanced Persistent Threats (APTs) take advantage of vulnerabilities in software such as the Web browser, Microsoft Office applications, or Adobe Acrobat to install malware (think of malware as bad software) -- usually a remote access tool (RAT) on your system that communicates with the attacker through command-and-control servers. As an individual, your best defense against these attacks is to make sure that you apply all available software updates. On Windows systems, you can set up automatic updates so that this happens routinely. If not, you should check manually by running Windows Update (or by looking for a "check for updates" option that's available in most software applications). The main point is that you need to make sure your system's software is up to date, so that at least the known vulnerabilities are patched up.

In addition to keeping up with software updates, you should also use some security software such as Microsoft Security Essential or any of the many commercial products. You need to deploy all currently available defenses even though it's impossible to fully defend against APTs because, in addition to known vulnerabilities, software often contains vulnerabilities that may have been discovered by the attackers, but not yet patched by the software vendor.

Additionally, you should use 2-factor authentication for sensitive transactions, including logging into social networking sites such as Google+, LinkedIn, and Facebook. For example, Google+ provides 2-factor authentication that works for logging into all services such as Gmail, Blogger, Google+, and others (see my previous video http://nbtmv.blogspot.com/2011/11/nbtmv-turn-on-2-step-verification-on.html for more information).

Organizations have more resources and can use more advanced defenses that are based on some key behavior of all APTs -- they install malware on the system, then periodically communicate to the command-control-server.

First, organizations should start with the existing defenses of firewall and usual patching and anti-virus regimen. Beyond that, there are security appliances (basically computers that inspect network traffic) available that can inspect email and web traffic to detect suspicious behavior and, potentially stop installation of malware. Third, organizations should collect event logs of various activities occurring in their systems and analyze those logs to detect any potential APT activities.

These are not perfect defenses, but they are a start. Unfortunately, it seems that APT attacks are bound to succeed, so organizations would just have to be prepared to deal with the aftermath.

As for individuals, I wish some low-cost security appliance were available to help us deal with the APT problem.

Note: There are some promising defenses based on running applications in a virtual environments where the activities of the malware could be contained before it causes damage, but this seems to be a cat-and-mouse game between the defenders and the attackers. Attackers are now designing malware that try to avoid being caught by looking for user activity such as mouse move or simply go to sleep for some time before initiating any contact with the remote command-and-control server.

Sunday, November 6, 2011

Why public cloud





In previous videos I discussed what is cloud computing, why it’s important to consider as an option, and what are some of the risks.
Because of the risks, especially those relating to security and loss of control over where data resides, your organization may prefer the private cloud option, which, as I have said previously, is still a good option that provides you with the benefits of reduced number of physical machines along with lower electricity and cooling needs, as well as needing fewer staff to administer the machines.
However, unless your organization has hundreds of thousands of employees, a private cloud is not going to give you the cost savings that come from the economies of scale that public clouds enjoy.
To implement the private cloud, you’ll need upfront investment to virtualize your servers and add the software needed to operate it as a cloud. You are not going to just pay for what computing resources you need - - you basically still have to maintain the systems you need for your worst-case computing load.
Some go as far as to say that a private cloud is not a cloud at all because a cloud should have “elasticity” - - meaning you can create new virtual machines on demand and shut them down when you don’t need them. A private cloud cannot easily provide this elasticity, unless it’s for a huge number of employees.
With a public cloud, you can truly pay for computing as you go - - just buy what you need, when you need it. That’s why, unless you have hundreds of thousands of employees or information that’s very sensitive (like military information), you have to consider public clouds to get the benefits of cloud computing. If that’s not acceptable, you can consider a community cloud suitable for your organization. For example, government agencies could opt for a government community cloud where you could at least get some economies of scale.

Here's some more information to help you
Here are some books on cloud computing that you may consider:

Saturday, October 29, 2011

What are some of the risks of Cloud Computing



In other videos I explained what cloud computing is and why it’s useful. In this video, I want to mention some of the risks of cloud computing - - things that could potentially go wrong and affect your organization when you use cloud computing. Of course, if you implement a cloud in your own data center for your organization’s use, then the risks are similar to ones you already have - - security, privacy, disaster recovery, etc.

However, if you are planning to use cloud services provided by a third party, then you need to think of any new risks that may apply to your situation and that’s what I’ll cover.
First, the obvious risks - - security and privacy risks because of not knowing whether the vendor’s cloud is secure, that the staff who manages the facilities are trustworthy, that privacy protections are up to the level required by law.
Second, we have some management and oversight risks - - relating to potential lack of control in figuring out where data is stored and processed and how to get it back, if you change provider. The oversight risk is the possibility that your auditor cannot get access to the cloud provider’s systems to check them out.
Third, there are some technical risks, relating to lack of standard definitions of what a cloud service is, how are fees set, how to move data from one cloud to another, whether you can get reliable performance...
And, finally, a fourth set of risks may be relating to potential foreign laws and regulations that apply to your data because of where the cloud service is located.
Anyway, this is not an exhaustive list, but the point is that you should think what risks apply to you and then manage them, as is the prudent thing to do. Some risks already have mitigation approaches such as putting things in the contract and some have ongoing activities to help business mitigate those risks.
And, even if there is no mitigation for some, you may still decide to accept the risks and forge ahead with cloud computing. After all, that’s how we get the good things in life... by taking risks.



Here are some more things to help you...

Please see my previous post on "What is Cloud Computing" - - there I have a slide presentation on cloud computing that I used when I gave a talk in Seoul, Korea in Nov 2010 and the 30-minute video of the talk as well.

Why you should consider cloud computing as an option





You might wonder why is “cloud” a big deal. First, and foremost, if you have a collection of servers for your business, once you use virtualization, you’ll be able to support many virtual machines on a small number of physical machines - - some experts suggest that for each “core” on an Intel or AMD processor, you can have 3 to 5 virutal machines. Many servers are 4- or 6-core, so you could have anywhere from 12 to 30 virtual machines on one server, but you’d need to have lots of memory and storage as well. Nevertheless, the ability to run lots of virtual machines on a physical server means that you reduce the number of physical servers and that translates to less space, less electricity, less heat, and less messy cables, etc. So these benefits make a cloud an worthwhile proposition for businesses, even if you were to convert your current server farm to a cloud.
If you can move on to buying the cloud services from a third party, the benefits are even more. Now you can simply buy the computing power you need, without having to spend money up front. You can benefit from the economy of scale, the cloud vendor would typically have better redundant power and network connectivity that you could afford. Even security may be enhanced because the cloud provider can afford to hire more experienced information security staff and apply patches across all virtual machines more efficiently and promptly than you could.
You’d notice that I have a lot of “may” and “could” in justifying the benefits of cloud, that’s because you have to check it out for yourself to see if it meets the needs of your business. What you don’t want to do is dismiss cloud as an option because of knee-jerk reaction from others inside your organization who may bring up risks relating to security, data ownership, and many other issues as reasons why you shouldn’t go the cloud. All of these may be valid risks, but they also have equally valid solutions that mitigate the risk enough for you to take the plunge. The savings in IT costs alone make it worth taking the step to, at least consider cloud services as an option.


Here are some more things to help you...


Please see my previous post on "What is Cloud Computing" - - there I have a slide presentation on cloud computing that I used when I gave a talk in Seoul, Korea in Nov 2010 and the 30-minute video of the talk as well.


Tags: , , ,  

What is Cloud Computing


Cloud computing has become a popular buzzword, but many managers find it confusing. Those old enough to remember time share computing tend to say, “oh, it’s just like timeshare systems we had in old days,” but cloud computing is more than that. It’s w-a-a-y more than lots of users logging into a mainframe through green-screen terminals.
You can understand “cloud computing” better by focusing on just the basics. Let’s start with the physical computer. Whether it’s a laptop, desktop, or a rack-mounted server, at its heart you have the processor, memory, storage, and network connection. On that physical computer you had an operating system -- Windows, Linux, etc. - - and many applications - - email, word processing, spreadsheet, databases.
Along comes the concept of “virtualization” - - the idea that instead of just running multiple applications on a physical computer, you can create “virtual machines”, each with its own virtual collection of memory, storage and network connection, RUNNING an operating system and set of applications. Thanks to the virtualization software, each virtual machine will be able to operate as if it had its own memory, storage, and network connection (or multiple network connections, for that matter).
So virtualization gives you the ability to run multiple “virtual machines” on a single physical machine. You can, in fact, have multiple virutal machines running different operating systems (Windows, Linux, what have you) irrespective of what operating system is running on the underlying physical system. The virtualization is possible through software, for example, VMware or .
There is another element as well - - management software that enables a system administrator to easily create virtual machines and “provision” them - - allocate memory, storage, install operating system etc. on the virutal machines.
Once you have the virtualization software with the management software to easily provision virtual machines, throw in Internet connectivity and you have a cloud - - the term is used because in network diagrams, the Internet is typically depicted by a cloud. You could say “virtualization + great Internet connectivity” = cloud computing - - BECAUSE now users can access your computing resources from anywhere and make use of the capabilities.
All the other terms you hear about cloud computing - - relating to types of service such as infrastructure as a service, platform as a service, or software as a service or <insert your favorite application name> as a cloud… AND terms relating to how they are deployed (read “for whom”) such as public cloud, community cloud, or government cloud or hybrid cloud or, again, insert <your favorite qualifer> cloud (such as Joe’s cloud or Jane and Mary’s cloud) are just qualfiers... at the heart, each must be a “cloud” as I explained earlier -- use virtualization, be able to create and provision virtual machines easily, and have great Internet connectivity.


Here are some more things to help you..

I had presented a talk on cloud computing (it was about IT and Network convergence, which, when I began developing became a presentation on cloud computing) that you may find helpful Below are the slides and then I have the 30-minute video in two parts (had to split into two 15-minute parts) of my talk based on the presentation.








After you skim through the slides (there are only 15 slides :-) you can watch the videos below:
 
Part 1 of KISDI talk Nov 2010

Part 2 of KISDI talk Nov 2010
Tags: , , ,