Posts Tagged Security Threats

Sumo Logic drops cloak, picks up cash to take on Splunk

Posted by on Tuesday, 31 January, 2012

Sumo Logic emerged from the shadows Tuesday with million in Series B funding from Sutter Hill Ventures, Greylock Partners and Shlomo Kramer bringing its total to .5 million since its founding in April, 2010. Greylock and Kramer also participated in the Series A round.

The company, founded by Arcsight veterans Kumar Saurabh and Christian Beedgen, aims to bring log monitoring and analytics to cloud computing environments via a software-as-a-service model. In that arena, Sumo Logic is bound to face off against Splunk, which filed for a 5 million IPO two weeks ago, as well as Loggly, a company that spun out of Splunk (see disclosure.)

Computer logs —  and other machine data — are an important component of the big data phenomenon. This machine data, if collected, analyzed and searched — provides important insights into how systems and applications are working (or not) and can pinpoint bottlenecks, server errors, and other glitches before they get out of hand.

“As infrastructure gets more complex, there are not only more systems and more heterogeneous systems but not everything sits in the customer data center anymore,” said Beedgen, who is also Sumo Logic’s chief architect and director of engineering. That means on-premises logging systems — which he contended are expensive to maintain and upgrade — are on their way out.

“The idea of sitting in a data center with a nice perimeter around it and just listening to what’s happening there isn’t going to cut it anymore,” Beedgen said in an interview Monday. The trick is to see out into a customer’s computing infrastructure regardless of where it is running. Once those logs can be viewed and monitored, forensics can be applied to pinpoint and trace security threats or other problems.

The service has been in use by select customers including Roblox and Ooyala, for a few months. Roblox, the online gaming company, integrates Sumo’s service into the Amazon Machine Images (AMIs) it uses to run its business. These “instrumented” AMIs give Roblox visibility into its Amazon infrastructure, Beedgen said.

The ability for companies to have a window into their compute infrastructure, wherever that is, will only get more important as more workloads move out of the customer’s own data centers and into the cloud. For more on this big data phenomenon, be sure to check out GigaOM’s Structure: Data Conference in New York City March 21 and 22.

Disclosure: Loggly is backed by True Ventures, a venture capital firm that is an investor in the parent company of this blog, Giga Omni Media. Om Malik, founder of Giga Omni Media, is also a venture partner at True.

Photo courtesy of  Flickr user 401K

Related research and analysis from GigaOM Pro:
Subscriber content. Sign up for a free trial.

  • Infrastructure Q4: Big data gets bigger and SaaS startups shine
  • Dissecting the data: 5 issues for our digital future
  • What Amazon’s new Kindle line means for Apple, Netflix and online media



alt=''
border='0'
/>


GigaOM


Citrix and Cotendo team up to accelerate enterprise SaaS apps

Posted by on Wednesday, 26 October, 2011

Citrix Systems has partnered with dynamic web acceleration startup Cotendo to introduce a new product that will add more speed and security to enterprise applications that need remote availability with LAN-like reliability. The NetScaler CloudConnector, which the companies are announcing Wednesday, combines the Citrix NetScaler infrastructure with Cotendo’s web and mobile acceleration services.

The solution works by putting Citrix NetScaler products within Cotendo points of presence around the world, in addition to enterprise data centers. The combination enables dynamic acceleration of enterprise applications throughout a mix of private and public clouds, boosting performance by 50 percent to 80 percent. It also reduces bandwidth requirements for associated network connections by between 50 and 95 percent.

The NetScaler CloudConnector uses a combination of amplified performance optimization and enhanced compression techniques to speed up delivery while lowering the amount of outbound data center traffic. That reduces the amount of infrastructure needed to support enterprise applications, and the amount of bandwidth used by mobile, web and SaaS applications.

In addition to speeding up the delivery of mobile, web and SaaS applications to native LAN-like performance levels, the NetScaler CloudConnector creates secure connections with users on home and mobile networks. By combining Cotendo’s distributed monitoring technology with Citrix application firewalls, the combined solution can detect security threats. It also provides higher levels of personalization and localization for remote workers, by optimizing support for individual mobile devices.

This isn’t the first time a CDN has connected with an infrastructure company to speed up private and public cloud applications. The Citrix-Cotendo hookup is similar to a partnership between Akamai and Riverbed announced earlier this year. In both cases the goal is to improve the availability or enterprise apps as they move into the cloud.

Related research and analysis from GigaOM Pro:
Subscriber content. Sign up for a free trial.

  • Big Data, ARM and Legal Troubles Transformed Infrastructure in Q4
  • Infrastructure Q3: OpenStack and flash step into the spotlight
  • What Amazon’s new Kindle line means for Apple, Netflix and online media



alt=''
border='0'
/>


GigaOM


Stopping threats like Operation Shady RAT

Posted by on Sunday, 7 August, 2011

Earlier this week, McAfee published information about a new cyber security threat it dubbed “Operation Shady RAT”. Operation Shady RAT, and others like it that have emerged over the past months, represent a new kind of cyber crime called Advanced Persistent Threats. These threats are a step-up in computer crime: they are massive, they target specific high-value data, and they lie dormant, undetected within computer systems, until remotely activated. These threats target specific high-value data, not just credit cards and customer account data but often records, in the form of email, legal contracts, design schematics, operational plans and images, pertaining to IP and trade secrets,

In the specific case of Shady RAT, spear fishing emails were sent to the target containing links to a web page that when clicked on automatically loaded a malicious remote access tool (RAT) program on the computer, thus gaining access to the network and the high-value information.

The new security threats.

In the “old” days, it was fairly straightforward to imagine boundaries around your business data. Today, it’s fair to say, with the rapid adoption of cloud and mobile computing, and the overall consumerization of IT, traditional boundaries have become fluid and, in most cases, non-existent. In today’s world, hackers have figured out how to target the data when it is most exposed, whether it’s on a corporate server, an iPhone, or in the cloud.

In this new IT world without boundaries the traditional ‘layered’ approach to enterprise data security becomes ineffective. Instead of assuming that data perimeter protection (protecting the networks and data ‘containers’) will keep data safe, we need to assume the bad guys are smart enough to not care about the containers and to instead attack the data. As the continued severity of data breaches show, bad guys are interested in the data itself, whenever it might be, and whenever they decide the time is right to strike.

What do we do in this new world? How do we protect data so that it is locked down and unusable by the bad guys while it is still accessible to those who need to use it for business purposes? While we can’t ignore the old approaches and steps for data protection, such as protecting IT infrastructure and putting in place effective monitoring approaches, we need a new step. Encryption, and not the traditional public key encryption, is the only way to keep sensitive data protected while at the same time keeping it usable.

Secure the data, not the perimeter.

Protecting private and sensitive data in a cloud/mobile world is difficult, expensive and increasingly mandatory to comply with federal and state regulations as well as to protect brand and business reputations. Thus, we need to think about data protection from a data-centric point of view where the data itself is protected. When you start thinking about how to protect your data in a world without boundaries, think about these four things:

  • Monitoring matters. Monitoring is an essential component of your overall security; network monitoring and database monitoring solutions help identify the kinds of attacks that are all around, such as script kiddies. They are also very useful for identifying internal threats such as unauthorized access to the database. These approaches give you a lot of information about what has happened but they don’t actually stop an attacker from getting high value data.
  • Keep data safe when it’s on the move. Of course not all encryption is created equal, many encryption solutions are like bank vaults, they protect the money, but as soon as the money is moved, or thieves break in and steal the money, the money is out in the open and can be used. So now, many banks use dye protection packs which make the cash useless if it is stolen, as soon the cash is removed from the vault the dye packs explode making it clear the cash has been stolen. A data-centric encryption approach renders stolen data useless to the attacker.
  • Protect your keys. Encryption and other types of protection means there are keys or tables involved that can give you access to the original data, these must be protected too. The best security solutions have keys that are never stored, so they can’t be stolen. The keys are computed only as needed. The recent RSA SecureID breach illustrates that hackers are getting more sophisticated and are going after keys.
  • Make yourself less of a target. The price for credit card data has dropped from 0 per ‘gold’ card to less than , driving attackers to plan and execute more sophisticated attacks designed to pull out more valuable data. this includes trade secrets, legal documents, more complete customer records than can be mined for high net worth individuals, etc. Hackers look for the highest reward, profits or publicity, with the lowest protections in place. If they hack you and all they get is encrypted data they will move on.
  • We can win.

    We can beat the bad guys. We have the technology to stop these new advanced persistent threats. Data-centric protection focuses on encrypting the digital assets, emails, documents, database records, in a way that they remain encrypted wherever they go. If they are stolen, those assets cannot be used, credit cards will not validate, emails will show up garbled and documents will not reveal their contents.

    Format Preserving Encryption (FPE/FFX) which is the encryption technology underlying data-centric encryption is being standardized by NIST and is backed by several solution providers Voltage, Verifone and Ingenico. With Shady RAT, data-centric encryption would not have stopped the programs from taking the data, but they would prevent the attackers from using it. Data–centric encryption turns gold into straw, making the data useless.

    Matt Pauker is Co-founder of Voltage Security.

    Related research and analysis from GigaOM Pro:
    Subscriber content. Sign up for a free trial.

    • A field guide to cloud computing: current trends, future opportunities
    • The Structure 50: The Top 50 Cloud Innovators
    • Will Standardizing the Cloud Cause Clarity or Confusion?



    alt=''
    border='0'
    />


    GigaOM — Tech News, Analysis and Trends


    Spyware And Adware Really A Pain

    Posted by on Saturday, 2 April, 2011

    For anybody who is encountering issues with your software programs or your hardware then it could be likely that you’ve Spyware and Adware on your pc. For those that use the net, these glitches are often very irritating. We certainly have become quite complacent with spyware and adware as it is all through the net but we still shouldn’t accept it.

    Being Familiar With How Spyware Works

    Spyware is software programs that spies on your web consumption. As an example, if you disclose your credit card over the internet, this spyware can collect this number together with your home address and IP address. Your credit card numbers are compiled by the spyware computer software any time you type in them into a web-based form or application. Some spyware are actually programmed to be able to document your usage of the web, what internet sites you go to, what computer files you download and install and exactly how long you stay on the internet.

    Advertisers now purchase this information and facts as they can deliver marketing promotions to an audience who are interested in that precise marketplace. Users, in many scenarios have not provided permission and have no idea that their purchasing patterns are being monitored along with their IP addresses, by the spyware which has infiltrated their computer. There are a number of ways that this kind of information is compiled. Some of the techniques of acquiring this information is by either being able to access the documents on your computer’s hard disk or even by recording the keystrokes.

    Spyware Is Now A Significant Danger To PC Users

    The present definition of spyware did not come about until 5 years after its first launch in 1995. Spyware has been recognized as the top security threats to pcs using the Microsoft Windows operating systems. Those that were at risk to the attacks of spyware were those which used Internet Explorer. Windows and Internet Explorer are very popular programs and for that reason these were the target of the spyware. Spyware infiltrated parts of Windows operating system by gaining access to your Internet Explorer program via the web.

    You Can Find New Developments In Anti-Spyware Programs Everyday

    The anti-spyware business is blossoming at the moment because these risks are very serious. Several types of spyware are being created everyday and consequently anti-spyware software programs are being created or being kept up to date regularly.

    Spyware in your computer system is usually disabled or perhaps erased by these anti-spyware software programs. Protection is generally supplied to those which have an anti-spyware software program installed and will prevent the installation of some of these spyware programs .

    These anti-spyware programs have to be kept up to date frequently. The Web is a fast pace carrier. Everything in there alters speedily and even sporadically. Spyware is the same, it transforms at a swift pace. You never know when marketers, internet developers or perhaps the government will think of improved versions of spyware or adware which have improved techniques of accessing your data files as well as private facts. Sometimes you will find an uninstall option in the spyware program which is installed.

    These uninstall alternatives hardly ever do the job. A few even install a lot more spyware as opposed to removing that specific one. The most effective thing to undertake for your computer system is to use a reputable anti-spyware program.

    Utilising The Right Programs Is The Key To Protecting Against Spyware

    Prevention is invariably much better than a treatment, so if you can stay away from these spyware programs, do so. Installing pop-up blockers is a method to avoid spyware, as well as disabling the automatic installation of programs in your internet browser is the one other one.

    The bothersome marketing pop-ups are where we acquire the adware and spyware from. Whenever using your e-mail, it is a very good practice to disregard e-mails which originated from individuals that you simply don’t recognize as well as those that contain a vague subject matter. It is better that you simply erase these emails without opening them.

    It is rather cumbersome, but you really have to to take time doing these things to make sure that your pcs are free of spyware.

    If you have been inflicted by a adware or spyware infection in the past you may find that your personal computer is still running poorly, this happens because a number of of these malicious files go after the registry files. The only alternative to fix this is to use a program such as Registry Smart to fix these problems.


    Will Information Security Management Be Of Use To You?

    Posted by on Friday, 24 December, 2010

    Overlooking information security management and the risks posed by cyber threats is common place in business.

    This article will go through some of the consequences that could potentially arise if you decide to overlook information security management, as well as how it could help a business grow.

    So why is it important to consider implementing thorough information security management?

    Don’t compromise your privacy

    Some people will do whatever it takes to be number one in business, even if it means not playing by the rules.

    Cyber security threats are no longer a thing of science-fiction movies. Regardless of the size of your business, the risk is still present.

    Your competitor may now have access to the data you’ve worked hard to attain. Your competition will be reap the rewards of your hard work.

    It is said that a good reputation is more valuable than money, and this is especially true in business. The damage to reputation sustained from the leak of personal data is unimaginable. Your organisation may never recover from this.

    Overlooking information security management can cripple organisations of all sizes.

    Opportunity

    Removing cyber threats isn’t what information security management is all about. The correct implantation of ISM can transform potential threats into opportunities and strengths.

    The best interests of a business are served when information is recognised as an asset.

    The effective management and streamlining of information helps you realise these opportunities by assessing, manage and mitigating risk.

    If you want your information to remain one of your business’ most crucial assets, then implementing effective ISM principles is imperative.


    Know And Learn A Lot More About Security Tool

    Posted by on Thursday, 18 November, 2010

    Regardless of how “secured” the name itself may sound, “Security Tool” in reality is a rouge anti-spyware program that is designed to give you fake alerts regarding system security which will try to make you think that your computer has got infected by malware. This rogue program is from the same family that other similars like System Security and Total Security 2009. Here Top Antivirus Software you will learn more about the Best Antivirus software.

    Once Security Tool has been installed on your PC, expect this program to launch automatically on each Windows reboot. Then the program will initiate a fake system scan and will come up with a list of infections that are irreparable unless the program is purchased. Please remind that the files detected by this tool are either good files (part of your Windows system), or totally inoffensive ones. Those files won’t do any kind of damages to your computer. Check here Security Tool Removal to read more about how to remove security tool.

    Some software that will push Security Tool unto your PC are: fake anti-spyware scanners, Trojans, and any other related threats. They will install this rogue program with Trojan Fake AV, that will show you fake security warnings, and that will promote Security Tool. Once this program starts to run in your system, it will block the anti-virus software along with other legit programs. Something important to keep in mind about “malware attacks” is that if you do click on the Update option, you will see “Updating” while in fact there is absolutely no network activities going on.

    Security Tool is also capable of impersonating the Windows Security Center and it will constantly display notifications regarding security threats. You can also get the warning that your PC is under attack by some threat, or that your confidential information has been stolen. For those unaware about such spyware problems, they might be very scared.

    In addition to this, Security Tool will hijack the web browsers and will block off certain security websites in order to protect itself from being removed from the system. But, if your PC get infected by such problem, it does not mean there is nothing you cannot do against it. There are very good ways to fight such malware. There is no need to panic. Simply follow the right method to remove this threat from your computer.