Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, November 27, 2007

HP unveils automated services tools

US tech giant HP has bolstered its service offerings with a suite of new software and services to help customers transform their IT operations and automate the management of business operations.

The HP Automated Operations 1.0 offering is a set of products that automates IT operations, eliminating labor-intensive tasks and ad hoc, error-prone manual processes. The company says the product dramatically lowers the day-to-day cost of IT operations.

The HP Automated Operations 1.0 software suite is composed of IT Service Management, Business Service Management and Business Service Automation solutions.

It also launched its HP Business Service Automation software, a single platform to automate all IT processes and drive change across applications, servers, networks, storage and clients.

“We have been aggressively expanding our software portfolio in the last two years to broaden and deepen our capabilities to help customers improve their top and bottom lines,” HP’s Software senior vice-president Tom Hogan said.

IDC Enterprise Management Service research director Stephen Elliot said business service automation was an opportunity for IT organisations to more closely align with business objectives such as compliance, security, and cost reduction, and the delivery of innovative products.

“The legacy manner in which many IT organisations execute enterprise infrastructure management processes is quickly becoming obsolete as they are too static, take too long to execute and lengthen time to market cycles,” Mr Elliot said.

“IT organisations must mature toward processes and technologies that enable a more dynamic, business-driven impact.”

For more IT Services news, click here.

Sunday, November 4, 2007

IBM boosts security investment

GLOBAL tech conglomerate IBM says it will spend a record US$1.5 billion (A$1.64 billion) next year developing and marketing products specifically for the security market.

The company last week introduced a swag of new security services, products and research breakthrough aimed at helping businesses more effectively manage operational and IT risk.

IBM said the IT security market was being transformed by the growth in more collaborative business models, by more sophisticated criminal attacks, and by increasingly complex infrastructure.

IBM says today’s wide array of security technologies, implemented tactically in silos, are not sufficient to deal with the new risk reality. IBM's approach is to strategically manage risk end-to end across all five domains of information technology security - Information Security; Threat and Vulnerability; Application Security; Identity and Access Management and Physical Security.

“For many enterprises, security is broken,” said IBM Internet Security Systems general manager Tom Noonan.

“The nature of evolving threats is such that installing point solutions to 'keep the bad guys out' is no longer a viable way to secure a business,” Mr Noonan said.

“We advocate new approaches to reduce complexities, adapt to new business imperatives and enable business value versus just threat protection. The path to a more secure world begins with a risk management strategy that limits the impact of threats, improves business resilience and creates an enterprise free of fear.”

IBM's Internet Security Systems (ISS) unit, acquired just over a year ago, is helping lead the way, teaming with IBM Research and integrating with IBM's Software and Systems businesses to deliver the world's most advanced risk management capabilities.

For more IT Security news, click here.

Users take Facebook addiction to work

IT security and control firm Sophos has revealed the results of a new survey examining the potential productivity implications for businesses that allow their employees to access Facebook during office hours.

Sophos polled 500 Facebook users to find out how often they accessed or checked the popular social networking site from work and found that while 37.2 per cent only visited the site once or twice a day, eight per cent admitted using it up to ten times a day, and an astonishing 14.8 per cent, about one in seven, confessed to being logged onto Facebook almost permanently during their working day.

About 40 per cent of respondents said they never accessed Facebook from work, only using the social networking phenomena from home.

“The results show that more than one fifth of these Facebook users are actually Facebook abusers,” said Sophos senior technology consultant Graham Cluley.

“They're seriously struggling to tear themselves away from the website when they should be concentrating on their job,” he said.

"Several trade unions have spoken out in the site's defence, suggesting that employers should put more trust in their workforce, and clearly the majority of people are using the site in moderation. The problem is that a 20 percent addiction rate equates to an awful lot of loafing, while there's also the likelihood that the abusers could ruin it for the other rule-abiding users.”

According to Sophos, the survey results add weight to growing fears that sites such as Facebook are having a hugely detrimental impact on business productivity. Employment law firm Peninsula recently estimated that 233 million hours are lost every month in the UK alone as a result of employees using social networking sites.

"Many companies are now aware that Facebook brings with it a series of security concerns, particularly the risk of employees inadvertently revealing sensitive or confidential information to the wider world,” Mr Cluley said.

“When combined with the threat of an accompanying productivity slump, they may well decide that social-networking at work is simply more trouble than it's worth.”

For more Web Applications news, click here.

Tuesday, July 3, 2007

Huawei inks joint-venture with Symantec

CHINESE networking giant Huawei has signed a groundbreaking joint-venture with US security specialists Symantec to develop and distribute security and storage appliances for corporate customers.

The joint-venture’s storage and security appliance products will also target phone companies and service providers.

“The joint venture will help carriers and enterprises effectively address these challenges by offering security and storage appliances that are easy to implement and maximize value to customers,” the companies said.

The yet-unnamed joint-venture is subject to government approvals, though Huawei and Symantec hope it will be operational by the end of the year.

The joint-venture will be headquartered in the Chinese city of Chengdu. It will be 51 per cent owned by Huawei and 49 per cent by Symantec.

“Network security will definitely form the foundation as telecom networks migrate toward an All IP environment,” Huawei chief executive officer Ren ZhengFei

“The partnership will enable us not only to provide leading network security solutions to carriers, but also to deliver professional security and storage solutions to enterprises, helping our customers build a safer and more efficient network.”

Huawei will contribute its telecommunications storage and security businesses including its integrated supply chain and integrated product development management practices.

Additionally, the new company will have access to Huawei’s intellectual property (IP) licenses, research and development capabilities, manufacturing expertise and engineering talent, which includes more than 750 employees.

The joint venture’s services and support infrastructure will draw upon Huawei's successful model for customer service and technical support, including worldwide technical support and call centre operations.

Symantec will contribute some of its leading enterprise storage and security software licenses, working capital, and its management expertise into the new company. Symantec will also contribute US$150 million toward the joint venture’s growth and expansion.

For more IT Security news, click here.

Thursday, April 5, 2007

Spam virus activity spikes in first quarter

DESPITE slowing marginally furing March, Spam levels increased more than 75 per cent during the first quarter to the highest levels in two years, according to managed security service provider MessageLabs.

MessageLabs Intelligence Report for March also found that it is small and medium sized businesses that are copping the worst of the spam problem, with SMBs receiving more than double the volume of spam compared to enterprise organisations.

Quarter on quarter, virus and botnet activity also increased, also with SMB wearing more than larger, better resourced organisations.

MessageLabs said SMBs were not targeted by spammers any more than large organisations, but were less likely to have defences in place to deal with the problem.

For small businesses, spam can very quickly become a silent killer, overwhelming the resources of the mail system before any effective countermeasures can be enforced, the report said.

“Today, spam is considered a side effect of email,” MessageLabs chief security analyst Mark Sunner said.

“The majority of small businesses view spam as an ongoing irritation rather than a real threat and have given up on dealing with the issue only to find that bad guys target them even more aggressively.

“If the first quarter data tells us anything, it’s that malicious activity in the form of spam will only continue on an upward trend,” Mr Sunner said.

Also in Q1 2007, MessageLabs saw virus and trojan traffic levels steadily decline from last year with rates of 1 in 126.1 emails. While the overall levels decreased, MessageLabs believes that virus and Trojan activity is actually on the rise with spammers delivering them disguised as spam.

Phishing activity accounted for 70.8 per cent of the malware threats this quarter, an increase of 8.6 per cent on the previous quarter.

For more Managed Service news, click here.

Friday, March 30, 2007

Warezov now targets Skype users

ROGUE net users have created a new variation of Warezov/Stration malicious code that is currently spreading through the Skype network, attacking Skype users’ machines, security specialists have warned.

WebSense Security Labs issued a warning that Skype users receive a message that says “Check this up”, with a URL containing a hyperlink.

Although the code itself is not self-propagating, when it runs, a URL is sent to all users within the user's contacts list.

When users click on the link, they are redirected to a site that is hosting an .exe file that users are prompted to click. WebSense notes that there is no vulnerability within Skype itself, but if the users runs the .exe file, several other files are automatically downloaded and run.

Once the computer is infected it can be accessed by the attacker and the Trojan will start propagating by sending the rogue message to everyone in the users contact list.

Skype has warned users against opening the malicious .exe file. The company said users should be careful before opening any attachment in general.

For more Net Working, VOIP Expo and IT Security news, click below.





Wednesday, March 7, 2007

Civil liberties group eyes RFID hack

THE high profile Black Hat tech conference in Washington last week has attracted the attention of civil libertarians in the US as legal action forced a speaker to delete parts of a speech on RFID security problems.

The American Civil Liberties Union’s (ACLU) was on hand to watch IOActive research and development director Chris Paget drastically modify his speech – removing a section that outlines specific security problems with RFID technology.

Mr Paget had been threatened with legal action by radio-frequency ID (RFID) card maker HID, which claimed the speech would breach HID intellectual property rights by making public HID code.

The action has caused a storm of controversy in global security circles. Mr Paget ultimately gave the speech outlining security concerns, but broadened it to say the security problems were not restricted to a single RFID vendor.

But the ACLU’s interest in the presentation was less about the use of IP rights to attack free speech – and more about the security concerns raised by Mr Paget, which it says has enormous implications for the US Department of Human Services Real ID proposal.

For the past three years, the ACLU has been looking closely at the privacy and security-related issues for RFID-enable passports, student IDs and driver’s licences.

It says there are real problems, because RFID cards can be hacked – and the IOActive presentation at Black Hat showed how.

RFID has become a hot-button issue for the ACLU since the Homeland Security Real ID proposal was attached to a bill through congress last year.

With the Australian Federal Government well advanced in planning for its smartcard-based Access Card, the security issue will almost certainly be taken up local privacy advocates and civil libertarians.

The Real ID initiative mandates that state’s overhaul their driver’s licence procedures and systems to include machine readable technology and a database holding citizen’s information. The database would then be connected to other state’s databases as well as a federal database – effectively federalising driver’s licenses as a national ID.

The ACLU says RFID-enabled ePassports in the UK and the Netherlands have already suffered security problems and wants to highlight the issue before Real ID gathers momentum.

For more RFID News click here.

Spooks give Cybertrust security tick

MANAGED security services specialist Cybertrust has achieved the Defence Signals Directorate Highly Protected accreditation for its Canberra internet gateway, the only commercial provider to do so.

The accreditation means the company’s unified gateway facility is certified to secure information classified to the federal government's In confidence, Protected, and Highly Protected levels. It follows multi-million investments by Cybertrust in people and infrastructure in Canberra and follows a lengthy evaluation process.

The company provides information security services to more than 50 Federal Government departments and agencies with more than 80,000 end-users. The Unified Gateway actively manages more than 200 firewalls and processes an average of two million emails everyday.

As part of the certification process, DSD three key areas – people, technology and processes – at the unified gateway. The DSD provides information security services to the government and defence forces to standards set out in the Australian Government Information and Communications Technology Security Manual - known as ACSI 33.

Cybertrust has focused heavily on the Australian market and has invested heavily in both in the unified gateway and in upgrading its Bruce Data Centre in Canberra to become a fully functional Security Operations Centre – the third in the company’s global follow-the-sun infrastructure.

Opening the SOC a month ago, the company said it was seeking to fill 15 new positions across the Asia Pacific as part of an expansion program in the region, including 10 new high-level security staff in Canberra.

For more Managed Services news click here.