Author Archive

The U.S. Department of Labor’s website was infected and spreading malware, researchers discovered this morning, and the malware has since been removed.

Jaime Blasco, director of AlienVault research labs, says the Labor Department’s website was infiltrated with malicious code that appears to be the handiwork of an intelligence-gathering operation. Blasco says the command-and-control protocol used in the attack matches a backdoor used by DeepPanda, a Chinese nation-state cyberespionage group. But it’s unclear so far whether the same group is involved in the Labor Department hack.

 

 

READ MORE …

Category: IT Security  | Leave a Comment

An undisclosed number of customers had their personal information accessed, after an online reputation management company was breached.

On Tuesday, Reputation.com, a Redwood City, Calif.-based business, sent emails to customers about the incident. The company provides services such as removing negative or unwanted information about individuals or businesses from search sites.

According to the email sent to customers, accessed data includes names, email and physical addresses, and in some instance, phone numbers, dates of birth and job information of clients.

In addition, encrypted user passwords were breached for a “small minority” of Reputation.com users.

 

 

 

READ MORE …

Category: IT Security  | Leave a Comment
IBM InfoSphere Guardium Newsletter: April 2013
Wednesday, May 01st, 2013 | Author:
IBM April 2013




In this Issue:

  • IBM X-Force 2012 Annual Trend & Risk Report
  • IBM PureSystems Turning One and Tackling Big Data, ITBusinessEdge Server Watch
  • Big Data Storage Buying Guide, Enterprise Storage Forum.com
  • Hardening a Teradata Database: Best Practices for Access Rights Management
  • Live Webcast – Secure All Your ‘Data at Rest’ with IBM Key Lifecycle Management
  • Live Webcast – IBM X-Force 2012 Trend Report: Cyber vs. Insider Data Breaches
  • InfoSphere Guardium Tech Talk – Implementing Database Activity Monitoring for DB2 for z/OS
  • Live Webcast – Best Practices for Securing and Protecting MongoDB Data, 10Gen
  • Tech Tip: Accelerate the Path to PCI-DSS Data Compliance Using InfoSphere Guardium
  • InfoSphere Guardium Training Courses
  • Proof of Technology and Technical Demonstrations
  • InfoSphere Guardium Bootcamp for Business Partners
  • Upcoming Events
  • IBM Blogs
  • Quick Links and Resources

IBM X-Force 2012 Annual Trend & Risk report has released! 

IBM X-Force monitors the latest threat trends including vulnerabilities, exploits and active attacks, viruses and other malware, spam, phishing, and malicious web content.
Looking back over the year, there was a measurable increase in the public announcements of security incidents and breaches, where SQL injection and DDoS attacks continued to wreak havoc on IT infrastructures.

Over the past year the discovery of sophisticated toolkits with ominous names like Flame to cross-platform zero-day vulnerabilities, had both consumers and corporations inundated with advisories and alerts regarding emerging threats. The frequency of data breaches and incidents—which had already hit a new high in 2011—continued their upward trajectory.

Read more
IBM PureSystems Turning One and Tackling Big Data 
ITBusinessEdge ServerWatch

“Over the past year, the IBM PureSystems family of expert integrated systems has continued to expand to meet the evolving needs of clients and partners around the world,” Jason McGee, IBM Fellow and IBM CTO for IBM PureApplication System, told ServerWatch.

McGee noted that the PureSystems family of server systems has been particularly well suited to help those organizations that are trying to transform their businesses and take advantage of opportunities being afforded by cloud, mobile and Big Data, but are challenged by a lack of IT skills and resources.

“PureData for Hadoop is also architected for high availability and features best in class security for Hadoop with advancements in both BigInsights and integration with Guardium software.”

Read more.

Big Data Storage Buying Guide
Don’t Forget Security
Enterprise Storage Forum.com

Enterprise Storage Forum has prepared a series of buying guides covering all aspects of storage. This one takes a somewhat different tack, providing advice from analysts on how storage managers should be addressing big data.

An integral part of strategy is how to secure that growing stash of unstructured data.  …the open source distribution of Hadoop does not include many security capabilities, though commercial distributions such as Shadoop can often add features such as access control, audit logging and authentication. In addition, IBM InfoSphere Guardium has introduced tools for securing big data environment. Disk encryption is another recommended action.

Read more. 

Hardening A Teradata Database: Best practices for access rights management (PDF, 1.8MB)

This joint IBM – Teradata white paper provides an overview and identifies best practices for access rights management for the Teradata Database not only to protect your data, but also to improve overall performance for authorization checking. And, introduces IBM InfoSphere® Guardium Vulnerability Assessment as an aid to help organizations automate the detection of vulnerabilities and to provide guidance on recovering from failures of Vulnerability Assessment tests.

Live Webcast: Secure All Your “Data at Rest” with IBM Key Lifecycle Management

Date: Wednesday, May 8, 2013
Time: 11:00AM ET
Speaker: Gordon Arnold

Targeted attacks on critical data continue to escalate and regulatory compliance to protect data has become increasingly more demanding. Encryption has been viewed as one of the most reliable ways to protect data and comply with regulations but it was also considered complex to implement. Today encryption has become the most critical component in an organization’s arsenal to meet compliance objectives, while at the same time it has become much easier to implement and manage successfully. The problem is knowing when and where to use encryption, how it can simplify the task of proving compliance and what controls need to be in place to ensure it delivers on its promise. This overview will help provide a look into the options for encryption and practical advice on how to deploy options like encrypted storage with key management will be a focus for this talk.

Register now


Live Webcast: IBM X-Force 2012 Annual Trend Report: Data Breach Issues and Solutions

Date: Thursday, May 9, 2013
Time: 2:00 PM ET / 11:00 AM PT
Speakers: Robert Freeman, IBM X-Force Advanced Research and Kimberly Madia, Product Marketing for InfoSphere Guardium

Join Robert Freeman of IBM X-Force® Advanced Research as he presents an in-depth analysis of 2012 public vulnerability disclosures and discusses important lessons learned.
In this session, you will learn:

  • Types of threats and the varying levels of sophistication
  • Most damaging exploit kits and the java connection
  • Web content trends, vulnerabilities and statistics
  • Operational security practices

Gain insight into emerging trends in security and how to address new threats presented by mobile devices, cloud computing, social media and more. And, why IBM’s holistic approach to data security can deliver a much lower total cost of ownership with best-in-class data security and compliance solutions

Register here.

InfoSphere Guardium Tech Talk: Implementing Database Activity Monitoring with DB2 for z/OS

Date: Thursday, May 16, 2013 
Time: 
11:30 AM ET / 8:30 AM PT

Hosted by:
 Kathryn Zeidenstein (IBM)

IBM Presenters: Roy Panting and Ernest Mancill

Learn how to manage multiple IBM InfoSphere Guardium appliances in heterogeneous environments and understand the tools available for system self-monitoring and system tuning. Members of our L3 support organization will cover best practices in maintaining, upgrading and expanding your InfoSphere Guardium environment.

For more information about this tech talk, contact Kathy Zeidenstein at krzeide@us.ibm.com or visit the Tech Talk page on the Guardium community wiki. http://ibm.co/Wh9x0o

Register here.

 

Live Webcast: Best Practices for Securing and Protecting MongoDB Data
Hosted by 10Gen

Date: Wednesday, May 29, 2013
Time: 2:00 PM ET/1:00 PM CT/11:00 AM PT
Duration: 60 minutes
IBM Presenters: 
Kathryn Zeidenstein, InfoSphere Guardium Evangelist and Sundari Voruganti, QA Lead

The value of the fast growing class of NoSQL databases is the ability to handle high velocity and volumes of data while enabling greater agility with dynamic schemas.  MongoDB gives you those benefits while also providing a rich querying capability and a document model for developer productivity. Many organizations are just getting started with MongoDB, and now is the time to build security into the environment to save time, prevent breaches and avoid compliance violations. This session describes several tips to get started ensuring security of MongoDB data, including real-time activity monitoring capability developed by IBM and validated by 10gen, the MongoDB Company. We will cover protection of data in motion and data at rest to build a defense in depth approach.

In this session you will learn:

  • How to evaluate the data security and privacy landscape and determine risk factors
  • New capabilities in MongoDB for authentication and management of data access
  • New capabilities in IBM InfoSphere Guardium data security and protection solutions to help  organizations monitor access to sensitive collections, log details of privileged user activity, detect risky query practices, and much more.

Register here 

Tech Tip: Accelerate the Path to PCI-DSS Data Compliance Using InfoSphere Guardium

Use prebuilt reports, policies, and groups to simplify configuration 

This article gives you a step-by-step overview of using the Payment Card Industry (PCI) Data Security Standard (DSS) accelerator that is included with the standard InfoSphere® Guardium® data security and protection solution. The PCI-DSS is a set of technical and operational requirements designed to protect cardholder data and applies to all organizations who store, process, use, or transmit cardholder data. Failure to comply can mean loss of privileges, stiff fines, and, in the case of a data breach, severe loss of consumer confidence in your brand or services. The InfoSphere Guardium accelerator helps guide you through the process of complying with parts of the standard using predefined policies, reports, group definitions, and more.

In this article, you will learn:

  • How to install the accelerator and configure a PCI role that will see the GUI enhancements specifically for the PCI accelerator.
  • The layout of the accelerator and the reports that are included to demonstrate compliance. You will learn how to add members to groups that will enable those reports to return the correct information. The article also briefly discusses security policies and rules.
  • How to use audit processes to automate compliance workflow for reviews and sign-offs.

Read more.

On-Demand Webcasts: 

If you missed our recent live broadcast, download these replays to catch up on hot topics, accelerate learning and view demonstrations of IBM data security and privacy solutions.

2013 InfoSphere Guardium Training Courses

Guardium’s training courses help you achieve results quickly and easily. For more information about training, to sign up for a training course, or to schedule a training session, go to:

  • GU201: IBM InfoSphere Guardium Technical Training - This three-day course offers a balanced mix of lectures, hands-on lab work, case studies, and testing. Students will learn how to create reports, audits, alerts, metrics, compliance oversight processes, and database access policies and controls. Students will also learn about system administration, archiving, purging, and back-ups.
  • 2U201: IBM InfoSphere Guardium 8 Technical Training – New Self-Paced Course - In this self-paced course, students will learn how to implement and support Guardium solutions within their environment. The course will highlight report creation, audits, alerts, metrics, compliance oversight processes, and database access policies and controls. See how system administration, archiving, purging, and backups are completed.

Register today!

Proof of Technology and Technical Demonstrations
To attend one of the Proof of Technology sessions – Email an IBM Representative. Include in your email the location you are interested in attending one.

InfoSphere Guardium Bootcamp for Business Partners

This technical workshop is for IBM business partners who are currently working with or are interested in working with IBM InfoSphere Guardium. It provides training on InfoSphereGuardium in a classroom setting. Detailed presentations and hands-on labs on Guardium 8 are included where attendees will gain in-depth knowledge on topics including:

  • InfoSphere Guardium product overview
  • Guardium installation concepts, planning, and configuration
  • Auditing database servers with the Guardium system
  • Monitoring for unusual traffic
  • S-GATE and S-TAP Terminate Functions
  • Vulnerability Assessments
  • Enhanced Enforcement Actions
  • And much more…

Learn how IBM InfoSphere Guardium can add value to your security and data management solutions and extend your market opportunity. Business partners working in the consulting industry who are currently working with or plan to work with InfoSphere Guardium are also welcome to attend.

Schedule and registration information

Please Note: We will send an email confirmation to all registrants 1-2 weeks before the bootcamp begins.

Date Country City Registration Information
May 20 – 24, 2013 Korea Seoul Register here
May 27 – 31, 2013 Russia Moscow Register here
June 4 – 7, 2013 Ukraine Kiev Register here

Fore more information, go to IBM InfoSphere Guardium Bootcamp

Upcoming Events
Please visit us at the following upcoming events:

Big Data, Integration, & Governance Forum
Toronto, Canada – May 9, 2013
Pittsburgh, PA – May 16, 2013
St. Louis, MO – June 11, 2013
Paris, France – June 11, 2013

Join us at an IBM Big Data, Integration and Governance Forum to hear from industry experts on how to turn your ever-growing supply of data into an enterprise source of knowledge. The forum—which addresses both strategies and technologies—will identify the pains associated with the overabundance of information and spur thinking around building an information strategy for smarter analytics.

Register today for the IBM Big Data, Integration and Governance Forum near you. 

ISSA CISO Executive Forum
Dallas, TX – May 9 – 10, 2013

X-Force Evolving Threats 2013 
Milwaukee, WI – May 14, 2013
Atlanta, GA – May 21, 2013
Dallas, TX – May 21, 2013
Southfield/Detroit, MI – May 22, 2013
San Francisco, CA – May 23, 2013
Washington, DC – May 23, 2013

Blogs 

The Big Data Hub Blog

Institute for Advanced Security Blog

Quick Links
Monitor Data Activity in Real Time 
Identify unauthorized or suspicious activities by continuously monitoring access to databases, data warehouses, Hadoop systems and file share platforms in real time.

Audit and Validate Compliance
Simplify SOX, PCI-DSS, and Data Privacy processes with pre-configured reports and automated oversight workflows (electronic sign-offs, escalations, etc.) to satisfy mandates.

Secure and Protect Big Data Environments 
Build security into big data environments to prevent breaches, ensure data integrity and satisfy compliance.

Protect Data Privacy and Support Compliance 
Develop a holistic approach to data protection to ensure compliance and reduce costs.

Assess Vulnerabilities 
Scan the entire data infrastructure for vulnerabilities and receive an ongoing evaluation of your data security posture, using both real-time and historical data.

Safeguard both Structured and Unstructured Data 
Ensure structured and unstructured data is identified, transformed and audited.

Produce Better Business Outcomes with Information Goverance
Ensure Enhance information integrity, availability and quality

InfoSphere Data Security and Privacy Offerings:
InfoSphere Discovery
InfoSphere Guardium Data Encryption
InfoSphere Guardium Activity Monitor
InfoSphere Guardium Vulnerability Assessment
InfoSphere Optim Data Privacy

Social media links
Follow Guardium on www.twitter.com/IBM_Guardium

Follow @IBMSecurity for the latest updates

View the Guardium channel on YouTube

Ongoing exploits infecting tens of thousands of reputable sites running the Apache Web server have only grown more powerful and stealthy since Ars first reported on them four weeks ago. Researchers have now documented highly sophisticated features that make these exploits invisible without the use of special forensic detection methods.

Linux/Cdorked.A, as the backdoor has been dubbed, turns Apache-run websites into platforms that surreptitiously expose visitors to powerful malware attacks. According to a blog post published Friday by researchers from antivirus provider Eset, virtually all traces of the backdoor are stored in the shared memory of an infected server, making it extremely hard for administrators to know their machine has been hacked. This gives attackers a new and stealthy launchpad for client-side attacks included in Blackhole, a popular toolkit in the underground that exploits security bugs in Oracle’s Java, Adobe’s Flash and Reader, and dozens of other programs used by end users. There may be no way for typical server admins to know they’re infected.

 

 

 

READ MORE …

Category: IT Security  | Leave a Comment

The Guardian became the latest publication to be hit by a group calling itself the Syrian Electronic Army.

A previous attack on the Associated Press caused stocks to dip.

Security experts have said Twitter itself needs to take more action to ensure its users are protected.

An email sent by Twitter to news organisations on Monday urged them to take a close look at their internal measures for dealing with social media.

Advice included making sure passwords were more than 20 characters long and made up of random strings of letters and numbers.

 

 

READ MORE …

Category: IT Security  | Leave a Comment
Guardian Twitter accounts compromised, SEA takes credit
Wednesday, May 01st, 2013 | Author:

Fake tweets sent out by the Associated Press Twitter feed forced the microblogging site to promise better defenses, but has not stopped the Syrian Electronic Army from targeting another news source.

According to a blog post written by the Syrian Electronic Army (SEA), 11 Guardian accounts were breached over the weekend. At the time of writing, The Guardian’s business feed appears to be compromised, with a tweet from that account — as well as the publication’s green section — advertising the SEA’s political motives.

 

 

READ MORE …

Category: IT Security  | Leave a Comment
Prioritizing Your Database Security Patches
Thursday, April 25th, 2013 | Author:

Prioritizing patches is tricky enough when organizations are not thinking about the downtime that can result from taking down a production database. When that comes into play, however, the patching process can slow down — so much so that databases can be months behind in critical updates.

Solving this issue, in part, means properly prioritizing what vulnerabilities need to be fixed — a process that starts with the relevance of a particular patch to the organization and its severity. For example, notes Imperva CTO Amichai Shulman, a vulnerability in a package that is not deployed on the database does not justify patching. Neither necessarily does a vulnerability that can be mitigated by shutting down a service that is unneeded for a specific organization.

 

 

READ MORE …

Some consolidation in the world of open source database startups:SkySQL, a provider of open source database solutions, is mergingwith Monty Program Ab, the creators of MariaDB, an open source database technology that is used by Facebook, Twitter, Wikipedia and other services. The merger is also a reunion of sorts: both companies employ key people from MySQL, the database company that was bought by Sun in 2008, and in turn became a part of Oracle. Monty Program was founded and led by Michael “Monty” Widenius, the founder of MySQL.

Financial terms of the deal were not disclosed; the merger is expected to complete in four months.

As part of the deal, SkySQL says it will dedicate more resources to MariaDB to make it more interoperable with both NoSQL and SQL database systems, and it will also see SkySQL develop new solutions that allow users of MySQL and MariaDB databases “to manage their data effectively in the enterprise and cloud.” SkySQL says that MariaDB currently sees some 500,000 user downloads per year, not counting community Linux distributions.

 

 

READ MORE …

Bank Sues Cyberheist Victim to Recover Funds
Wednesday, April 24th, 2013 | Author:

A bank that gave a business customer a short term loan to cover $336,000 stolen in a 2012 cyberheist is now suing that customer to recover the fronted funds, after the victim company refused to repay or even acknowledge the loan.

On May 9, 2012, cyber crooks hit Wallace & Pittman PLLC, a Charlotte, N.C. based law firm that specializes in handling escrow and other real-estate legal services. The firm had just finished a real estate closing that morning, initiating a wire of $386,600.61 to a bank in Virginia Beach, Virginia. Hours later, the thieves put through their own fraudulent wire transfer, for exactly $50,000 less.

At around 3 p.m. that day, the firm’s bank — Charlotte, N.C. based Park Sterling Bank (PSB)– received a wire transfer order from the law firm for $336,600.61. According to the bank, the request was sent using the firm’s legitimate user name, password, PIN code, and challenge/response questions. PSB processed the wire transfer, which was sent to an intermediary bank — JP Morgan Chase in New York City — before being forwarded on to a bank in Moscow.

 

 

READ MORE …

Category: IT Security  | Leave a Comment

A former employee of Hostgator has been arrested and charged with installing a backdoor that gave him almost unfettered control over more than 2,700 servers belonging to the widely used Web hosting provider.

Eric Gunnar Gisse, 29, of San Antonio, Texas, was charged with felony breach of computer security by the district attorney’s office of Harris County in Texas, according to court documents. He worked as a medium-level administrator from September 2011 until he was terminated on February 15, 2012, according to prosecutors and a company executive. A day after his dismissal, Hostgator officials discovered a backdoor application that allowed Gisse to log in to servers from remote locations, including a computer located at the Hetzner Data Center in Nuremberg, Germany. He took pains to disguise his malware as a widely used Unix administration tool to prevent his superiors from discovering the backdoor process, prosecutors said.

 

 

READ MORE …