<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityNowBlog&#187; SecurityNowBlog-Network Security</title>
	<atom:link href="http://www.blueridgenetworks.com/securitynowblog/tag/application-control/feed" rel="self" type="application/rss+xml" />
	<link>http://www.blueridgenetworks.com/securitynowblog</link>
	<description>Secure Communications</description>
	<lastBuildDate>Wed, 28 Sep 2011 18:27:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Business Partner Data Leak Prevention</title>
		<link>http://www.blueridgenetworks.com/securitynowblog/business-partner-data-leak-prevention</link>
		<comments>http://www.blueridgenetworks.com/securitynowblog/business-partner-data-leak-prevention#comments</comments>
		<pubDate>Thu, 21 Aug 2008 18:48:39 +0000</pubDate>
		<dc:creator>Eirik Iverson, Product Management</dc:creator>
				<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[anti- anti-spyware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[application control]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[browser security]]></category>
		<category><![CDATA[data leak prevention]]></category>
		<category><![CDATA[disk encryption]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[NAC]]></category>
		<category><![CDATA[nap]]></category>
		<category><![CDATA[network access control]]></category>
		<category><![CDATA[network access protection]]></category>
		<category><![CDATA[Network Admission Control]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[usb thumbdrive]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.securitynowblog.com/?p=15</guid>
		<description><![CDATA[If your business partners are accessing your sensitive data on your mission critical servers, you may find yourself living in excessively interesting times.
A signed agreement among business partners helps, but guarantees nothing. Incidentally, it can also discourage disclosure. Persuading them to implement better information security practices (i.e., spend more) can be fruitless.
Despite the difficulties, we [...]]]></description>
			<content:encoded><![CDATA[<p>If your business partners are accessing your sensitive data on your mission critical servers, you may find yourself living in excessively interesting times.<span id="more-15"></span></p>
<p>A signed agreement among business partners helps, but guarantees nothing. Incidentally, it can also discourage disclosure. Persuading them to implement better information security practices (i.e., spend more) can be fruitless.</p>
<p>Despite the difficulties, we often need an agreement signed to help facilitate avoiding the following risks posed by our business partner endpoints:</p>
<ul>
<li>Infect our mission critical servers (Risk 1)</li>
<li>Leak data via malware (Risk 2)</li>
<li>Leak data via removable media (Risk 3)</li>
<li>Leak data via high-risk endpoint hard drives (Risk 4)</li>
</ul>
<p><strong>Limit server access to partner endpoints of acceptable risk.</strong><br />
Limit access to machines not just people. Limiting access based on both identity and health requires network access control (NAC) technology, such as Microsoft Network Access Protection (NAP).</p>
<ul>
<li>Try to limit access to machines that process as little data, documents, or media from the outside world as practical (Risk 2). This also means denying access to endpoints running p2p and other software.</li>
<li>Ensure that anti-virus and anti-spyware software are running, up-to-date, and frequently conduct full scans (Risk 2)</li>
<li>Try to require other anti-malware tools because signature-based anti-malware products are becoming more ineffective every week (Risk 2).</li>
<li>Deny access to endpoints with promiscuous removable media settings (Risk 3)</li>
</ul>
<p><strong>Data stored on partner endpoints must be encrypted.<br />
</strong>Fixed and mobile PCs can be physically compromised. Limit server access to endpoints with full disk encryption (Risk 4). Second, also limit access to machines that require two factor authentications to utilize the endpoint (Risk 4). If your partner&#8217;s disk encryption solution can ensure that write operations to removable media are encrypted, then you might ease up on removable media settings requirements (Risk 3).</p>
<p><strong>Consider limiting partner server access to thin client machines.</strong><br />
One can be very confident that no malware is operating within a freshly <strong>rebooted</strong> thin client machine (Risk 1). This can also be the most effective, albeit Draconian, risk mitigation to data leaks (Risk 2, 3, and 4). BTW, you could also have them access mirrors of your mission critical servers instead (Risk 1).</p>
<img src="http://www.blueridgenetworks.com/securitynowblog/?ak_action=api_record_view&id=15&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.blueridgenetworks.com/securitynowblog/business-partner-data-leak-prevention/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can End-users Install Software Without Administrative Privileges? Yes They Can!</title>
		<link>http://www.blueridgenetworks.com/securitynowblog/can-end-users-install-software-without-administrative-privileges-yes-they-can</link>
		<comments>http://www.blueridgenetworks.com/securitynowblog/can-end-users-install-software-without-administrative-privileges-yes-they-can#comments</comments>
		<pubDate>Fri, 18 Jul 2008 15:35:23 +0000</pubDate>
		<dc:creator>Eirik Iverson, Product Management</dc:creator>
				<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[application control]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.securitynowblog.com/?p=6</guid>
		<description><![CDATA[In general, IT personnel are far more knowledgeable and skilled than end-users when it comes to information security. Consequently, IT personnel prefer to limit what end-users can do on their assigned endpoints by provisioning end-users without administrative privileges. This sounds reasonable: the less users can do to alter their machines, the less likely they are [...]]]></description>
			<content:encoded><![CDATA[<p>In general, IT personnel are far more knowledgeable and skilled than end-users when it comes to information security. Consequently, IT personnel prefer to limit what end-users can do on their assigned endpoints by provisioning end-users without administrative privileges. This sounds reasonable: the less users can do to alter their machines, the less likely they are to expose their networks and systems to security breaches. By the way, minimizing dependence on end-users making correct information security decisions is almost always good policy.</p>
<p><span id="more-6"></span></p>
<p>Without endpoint administrative privileges, an end-user cannot add or modify files and registry settings in many “sensitive” places. The “Program Files” directory is one of them. This is where software applications are typically installed. Some application installations, such as client security software, must add or modify files in yet more “sensitive” places. In theory, these write-privilege limitations prevent end-users from installing peer-to-peer, recreational, pirated, and other unauthorized software. In reality, however, most such software can be installed elsewhere in the endpoint by these end-users, and run normally.</p>
<p>So, how do end-users circumvent these software installation restrictions? They do little more than just point and click!</p>
<p>After double-clicking on the Limewire set-up executable, for example, the end-user is asked to click “Ok”, “Next”, or “Continue” on several prompt windows. One such prompt window generally presented to the end-user concerns the destination of the installation, which normally defaults to within the “Program Files” directory. However, this prompt usually includes an “Browse” or “Custom” button that allows an end-user to specify a different location. The end-user merely needs to point to a directory within the user directory space such as “Desktop” or “My Documents”, for example. Most undesirable applications will operate fine in these locations. And, for the most part, these applications will run okay even if their executable has been renamed. Such end-users might rename limewire.exe to be winword.exe (wouldn’t interfere with Microsoft Word) to avoid detection, for example.</p>
<p>Some good news on the side, these installations alone cannot inject a rootkit into the host. Bad news, if such software has a Trojan embedded within it, the “bad guys” will have a logical presence within the host from which they might exploit a vulnerability to infest “sensitive” places in the endpoint. But, while this is a threat not to be ignored, the threat of malware (i.e., Trojan) infested end-user installed software installation is not the most immediate risk that requires action from IT personnel. There are far more numerous and impacting security breach reports from peer-to-peer software sharing “sensitive” documents on the host to anyone on the Internet. Additionally, end-users generally fail to keep the software they install up to date with the last security patches provided by the vendors. The SANS Institute reported in November 2007 that hackers are increasingly targeting such client software. So, any application running on a endpoint that interacts with the outside world generally increases the exposure of that endpoint and the organization that hosts the endpoint. Now, outside of Microsoft, Apple, Adobe, who amongst the other software vendors have been targeted enough to motive themselves to invest heavily in hardening their software? Answer: be afraid, be very afraid! This is especially so if endpoints in your organization possess sensitive data or documents that could generate bad press, law suits, and regulatory attention.</p>
<p>Considering the above risks and others, do you know what software is running on your organization’s endpoints? Do you know what software the endpoints run when they are off the enterprise? Please do not rely on firewall, router, and other logs to discover unauthorized client software. These applications are increasingly using common network ports, encryption, and even obfuscation to avoid detection and to ensure privacy.</p>
<p>The bottom line for organizations is that their IT personnel need application control capabilities whether their end-users have endpoint administrative privileges or not. If trade-offs have been accepted allowing end-users to have administrative privileges, then IT application controls must be capable of superseding those privileges. And worth repeating, IT personnel require monitors and controls that provide them operational awareness for endpoints both on and off the enterprise.</p>
<img src="http://www.blueridgenetworks.com/securitynowblog/?ak_action=api_record_view&id=6&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.blueridgenetworks.com/securitynowblog/can-end-users-install-software-without-administrative-privileges-yes-they-can/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

