- +
Your World. . . Hacked 02 October, 2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
- +
Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44
Adobe to launch Web site offering users free hosted services for document creation, sharing and storageAdobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. The Secrets of C-Suite Success
The CIO Executive Council Guide to Success
Dude! You Say I Need an Application-Layer Firewall?!
Why Security SaaS Makes Sense Today
Enterprise Wireless WLAN Security
Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar
Using EMC Celerra IP Storage with Vmware Infrastructure 3 over iSCSI and NFS
Understanding Email Marketing: A Guide for SMBs
Newsletter Subscription
Voice over IP offers great savings in long-distance calls. But without extensive safeguards, VoIP can expose your phone system to the havoc affecting the rest of the Web
Reader ROI
- Why VoIP is more vulnerable to hackers than are traditional phone systems
- What you can do to safeguard your VoIP systems
- When it makes sense to convert to VoIP and when it doesn't
Phone service is abruptly cut off at a brokerage house after a hacker launches a full-scale denial-of-service attack, flooding the firm's voice servers with registration requests. An Internet worm makes its way from a retail giant's data network to its voice network, shutting down call centres and costing millions in lost revenue. An impostor enters the phone network of a top government agency and makes away with classified information by spoofing his caller ID.
Sound far-fetched? According to security experts, such scenarios are not only plausible, they may be inevitable as companies and government agencies around the world scrap their traditional circuit-switched phone systems and move to voice over IP (VoIP). By sending voice calls over the Internet, companies are saving millions of dollars and gaining flexibility to provide multimedia services at the desktop. But they are also exposing their voice systems to all of the hazards that now plague data networks, including worms, viruses, denial-of-service attacks, spam over Internet telephony (SPIT), eavesdropping and fraud. And they are increasing their vulnerability to attacks against the rest of the network by creating new openings into critical infrastructure, networks and systems.
CIOs ready to take the plunge with VoIP need to understand that data firewalls alone won't protect them. They need only look to the past to remember the state of the Internet 10 years ago, when security was usually an afterthought. That was before the Nimda and Sasser worms and countless other threats came to haunt them. To head off attacks on their voice networks, IT executives need to devise a plan that includes voice encryption, authentication, VoIP-specific firewalls, and the separation of voice and data traffic. They also need to ensure redundancy in case of power loss (most traditional phone networks already require backup, but the systems will need to be expanded with VoIP). And they will have to physically secure voice servers and other equipment from intruders.
Traditional private branch exchange (PBX) phone systems have their own vulnerabilities, and in the past hackers have broken into large phone and voice mail networks. But VoIP expands vulnerability, offering more opportunities for hackers to gain access. In a recent 93-page report on VoIP security, the National Institute of Standards and Technology notes that in most offices there are many more points to connect to a LAN than there are points to connect to a PBX box. "Based on the history of attacks on various Internet services and things we've seen, it's inevitable that there will be attacks on VoIP networks," says Rick Kuhn, a computer scientist at NIST and co-author of the report. "Eventually, someone will find a way to take advantage of it."
Some experts in the US are even urging Congress to consider VoIP security implications as it starts to revise the Telecommunications Act of 1996. They believe the government may need to impose new standards or requirements for critical infrastructure, especially where it relates to emergency services or national security. "I do know that if there is a significant VoIP security event, there will be a reaction from Congress and the executive branch," says Roger Cressey, a former White House cybersecurity official from 1999 to 2002 and now the president of Good Harbour Consulting.
CIOs who have already begun using VoIP advise those considering it to start focusing on security now. That way, they can avoid the expense and frustration of patching and fixing their systems after the fact. "You'll be sorry if security is an afterthought with VoIP," says Gary Heller, deputy CIO for the Arizona Healthcare Cost Containment System, the state agency that administers Medicaid. Heller recently helped install VoIP between the agency's five metro Phoenix offices and its 11 call centres. "We're comfortable now only because we took the time to do the due diligence and proactive monitoring that can lead to a safe VoIP environment. If we didn't have all that, I'd be scared." Here's what a number of early VoIP adopters have done to realize the cost savings of VoIP and to save their companies from a potential disaster.
Full VoIP Ahead
With VoIP, PBXs - the backbone of the traditional phone system - are replaced by IP voice servers that usually run on Microsoft or Linux operating systems. These "call management boxes" deliver VoIP services and log call information - and they are susceptible to virus attacks and hackers. VoIP is even more sensitive than data when it comes to disruption and packet loss. Yet many security measures that are applied to data networks don't work well for VoIP. For example, traditional firewalls can result in delays or blocked calls, and encryption can cause "latency" and "jitter" (packet slowdowns that can disrupt calls). As a result, security techniques must be specialized for VoIP. And it should go without saying that VoIP equipment should be placed in a secure, locked location.
Despite the perceived gaps in VoIP security, there haven't been any reports of large-scale cyberattacks or security breaches of VoIP networks. That's due in part to the fact that vendors and service providers are offering a wider variety of VoIP firewalls, intrusion prevention systems and other protective devices when they install the systems. VoIP adoption also is still in its early phases. According to Osterman Research, only one in 10 US companies has deployed VoIP in the workplace. But that will soon change. By late 2007, the research firm predicts, 45 percent of companies will have some form of VoIP, and adoption is expected to accelerate thereafter as many large organizations will need to replace ageing telecommunications infrastructures.
Already, experts say early VoIP adopters have suffered voice-line outages. For example, a Merrill Lynch manager of voice product development said at a major VoIP conference last northern autumn that e-mail viruses including Sasser and Code Red took down the company's VoIP network for two to four hours because it rode on top of the data network. Darrell Epps, director of the convergence and IP telephony professional services practice for NextiraOne, a consulting and integration company, confirms that some Fortune 500 companies using VoIP have already suffered from VoIP hacking incidents that have hurt company operations.
2008 CIO Summit
19th August, 2008 Four Seasons Hotel, Sydney Developed in partnership with CIO Magazine, IDC, INTEP and the CIO Executive Council.
The world of the CIO is extremely complex and diverse. Multiple priorities demand attention and decisions are needed instantly. Individual teams need to be driven towards common goals, and businesses strive to become more mobile, agile and responsive. For CIOs, the challenge never ends.
Every year the CIO Summit identifies what is top of mind for CIOs across Australia and New Zealand, and offers insight for CIO benchmarking and vendor strategic planning alike.
Recent IDC research shows that over 59% of CIO's believe that 'to achieve their business strategies, technology should be used more aggressively than today.'
Join us on August 19th to discover how this is possible with the latest technologies including Virtualisation, Web 2.0, IP Surveillance and Software as a Service (Saas).
Click here for more information.
Please email Denyse_Robertson@idg.com.au for further information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Best Western forced to play defense on data breach disclosure 29 August, 2008 08:08:00
Could hotel chain have done a better job of defusing story about system intrusion?The headline in this week's Glasgow Sunday Herald -- "Revealed: 8 million victims in the world's biggest cyber heist" -- was a grabber. - +
US Terror threat system crippled by technical flaws 28 August, 2008 09:53:00
US Congress charges that US$500m project to prevent another 9/11 is a complete failure.A US House subcommittee is charging that a US$500 million IT project intended to "connect the dots" on terrorists and help prevent another 9/11 is a failure; it can't even handle basic Boolean search terms, such as "and, or and not." - +
Malware infects space station laptops 28 August, 2008 08:15:00
Not the first time, says NASA; astronauts load up Norton AntiVirusMalware has managed to get off the planet and onto the International Space Station, NASA confirmed yesterday. And it's not the first time that a worm or virus has stowed away on a trip into orbit. - +
Separation of duties and IT security 28 August, 2008 09:40:00
Muddied responsibilities create unwanted risk. Kevin Coleman says auditors may start labeling poorly defined IT duties as a material deficiency.Separation of duties is a key concept of internal controls and is the most difficult and sometimes the most costly one to achieve. This objective is achieved by disseminating the tasks and associated privileges for a specific security process among multiple people. - +
How to recruit and retain the best young security employees 27 August, 2008 08:32:00
Today's youngest generation of workers, known as Generation Y, have different career goals than their parents did. What do you need to know to get them to work for you?The final installment in a series of articles about generational differences and security. Part one looked at managing workers in different age groups. Part two examined the types of security concerns that are most commonly associated with different generations in the general workforce. This article provides recruiting and retention advice for security employees.
Tumbleweed appoints O2 Networks to its Australian Channel Partner Program 29 August, 2008 12:31:00
HP ProCurve Brings Big Business Gigabit Switching Features to Small Businesses 29 August, 2008 12:00:00
GlobalConnect Provides Treatment for Healthcare Provider’s Contact Support Requirements 29 August, 2008 09:59:00
Sybase and Logica Partner To Mobilise The Supply Chain 29 August, 2008 09:47:00
New global landscape for qualitative researchers with Spanish and Chinese software releases 29 August, 2008 09:34:00
|
||
|
||
|
|
||
|
Radicati Market Quadrant 2008 on Corporate Web Security
An Analysis of the Market for Corporate Web Security Solutions, revealing Top Players, Mature Players, Specialists and Trail Blazers. Read on to discover who makes the grade.













