<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecurityNowBlog&#187; SecurityNowBlog-Network Security</title>
	<atom:link href="http://www.blueridgenetworks.com/securitynowblog/tag/pki/feed" rel="self" type="application/rss+xml" />
	<link>http://www.blueridgenetworks.com/securitynowblog</link>
	<description>Secure Communications</description>
	<lastBuildDate>Thu, 19 Aug 2010 20:02:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Retail MPLS Data Networks at Risk</title>
		<link>http://www.blueridgenetworks.com/securitynowblog/retail-mpls-data-networks-at-risk</link>
		<comments>http://www.blueridgenetworks.com/securitynowblog/retail-mpls-data-networks-at-risk#comments</comments>
		<pubDate>Tue, 16 Jun 2009 15:30:45 +0000</pubDate>
		<dc:creator>Jim Byrd, Director, Product Marketing</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security Applications]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Blue Ridge Networks]]></category>
		<category><![CDATA[Dark Reading]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[MPLS]]></category>
		<category><![CDATA[MPLS Networks]]></category>
		<category><![CDATA[MPLS Security]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[Retail Data Networks]]></category>

		<guid isPermaLink="false">http://www.blueridgenetworks.com/securitynowblog/?p=87</guid>
		<description><![CDATA[Although the inherent flaws in MPLS security have been known for sometime, only in the last few months has there been a concerted effort to deliver hacking tools designed specifically to exploit MPLS security vulnerabilities, putting retail data networks at risk of attack.

At a Black Hat Europe Conference last April a team of researchers released [...]]]></description>
			<content:encoded><![CDATA[<p>Although the<a title="MPLS Flaws" href="http://www.scmagazineus.com/For-managed-MPLS-based-network-migrations-to-be-truly-successful-enterprises-must-apply-due-diligence/article/34912/" target="_blank"> inherent flaws in MPLS security </a>have been known for sometime, only in the last few months has there been a concerted effort to deliver hacking tools designed specifically to exploit MPLS security vulnerabilities, putting retail data networks at risk of attack.</p>
<p><span id="more-87"></span></p>
<p>At a <a title="Dark Reading Article" href="http://www.darkreading.com/securityservices/services/data/showArticle.jhtml?articleID=216403220" target="_blank">Black Hat Europe Conference last April </a>a team of researchers released tools that can automate attacks on MPLS and Ethernet backbone technologies.  According to one of the researchers,&#8221;These technologies do not provide any security themselves, but just rely on the assumption that the underlying network is secure.&#8221;</p>
<p>As MPLS VPNs evolved from proprietary networks to supporting internet-based services, so did their risk of attack increase. German researcher Ray says,&#8221;Enterprises that use these VPN services should be aware they are vulnerable. Perform risk analysis and encrypt your traffic.  &#8221;Just because it&#8217;s called MPLS VPN [doesn't mean] you should [automatically] trust it.&#8221;</p>
<p>Many retailers followed their service providers advice and simply migrated from Frame Relay and ATM networks to MPLS.  However, over time the majority of problems meant to be solved by MPLS no longer exist, and holes in the technology are being exploited. </p>
<p>Total information security for retail data networks is possible.  Solutions using PKI technology, unique digital certificates with mutual mandatory authentication between security appliances, end-to-end data encryption and data integrity checking can provide a standalone data network solution or act as the security layer for<br />
an existing MPLS VPN network.</p>
<p>Retailers need to <a title="Retail Data Network Page" href="http://www.blueridgenetworks.com/solutions/retail.php" target="_blank">re-examine wide area networking technologies and topologies </a>as they seek to optimize the security, reliability and cost of their current data network.</p>
<h2><a title="The Most Secure Commercially Available VPN Solution" href="http://www.blueridgenetworks.com/solutions/retail/military-grade-vpn.php" target="_self">Blue Ridge Military Grade VPN, Fully Managed Solution</a></h2>
<img src="http://www.blueridgenetworks.com/securitynowblog/?ak_action=api_record_view&id=87&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.blueridgenetworks.com/securitynowblog/retail-mpls-data-networks-at-risk/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>All Security Depends on Authentication</title>
		<link>http://www.blueridgenetworks.com/securitynowblog/all-security-depends-on-authentication</link>
		<comments>http://www.blueridgenetworks.com/securitynowblog/all-security-depends-on-authentication#comments</comments>
		<pubDate>Tue, 22 Jul 2008 16:42:54 +0000</pubDate>
		<dc:creator>Eirik Iverson, Product Management</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[2-factor]]></category>
		<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Audit]]></category>
		<category><![CDATA[Authorization]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[One-time pass code]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.securitynowblog.com/?p=8</guid>
		<description><![CDATA[Authorization, privacy, integrity, and audit are very important security services to any organization. Their efficacy is limited by the level of assurance provided by the authentication that supports them. When authentication is unreliable, then so too are authorization, privacy, integrity, and audit.

Authentication &#8211; WHO’s who?
With flawed authentication:
• Authorization systems effectively become indiscriminate,
• Privacy services are [...]]]></description>
			<content:encoded><![CDATA[<p>Authorization, privacy, integrity, and audit are very important security services to any organization. Their efficacy is limited by the level of assurance provided by the authentication that supports them. When authentication is unreliable, then so too are authorization, privacy, integrity, and audit.</p>
<p><span id="more-8"></span></p>
<p><strong>Authentication &#8211; WHO’s who?</strong></p>
<p>With flawed authentication:<br />
• Authorization systems effectively become indiscriminate,<br />
• Privacy services are pointless when the encryption key is available to anyone<br />
• Integrity services (i.e., has ‘this’ been altered?) can be subverted<br />
• Audit services capture events attributed to no one in particular and for events that may not have actually occurred.</p>
<p>BEST PRACTICE: Employ two-factor, mandatory, mutual PKI authentication whenever practical.</p>
<p><strong>Authorization &#8211; WHO can access it?</strong></p>
<p>A flawed authorization system can allow Bob to access and modify resources that only Alice may, also violating privacy and integrity. If your Active Directory, other LDAP, or some standalone server application cannot effectively distinguish between one user and another, then its ability to regulate who may access what is undermined.</p>
<p>BEST PRACTICE: Employ two-factor, mandatory, mutual PKI authentication whenever practical.</p>
<p><strong>Privacy &#8211; WHO can see it?</strong></p>
<p>Privacy, though a more general term, is frequently equated with encryption. Encryption is a commodity, generally. Any vendor’s implementation is usually as good as another’s. Administrators should always select an AES setting. In many circumstances, AES 256 adds little to no additional overhead as compared with AES 128 or AES 192. Nonetheless, weak authentication devalues strong encryption.</p>
<p>BEST PRACTICE: Employ two-factor, mandatory, mutual PKI authentication whenever practical.</p>
<p><strong>Integrity &#8211; WHO can change it?</strong></p>
<p>Cryptographic mechanisms enable a recipient of delivered electronic data to determine if it has been altered since it left the sender. If the ‘receive’ does not credibly know the data came from the ‘sender’. What’s the point of testing for data integrity?</p>
<p>BEST PRACTICE: Employ two-factor, mandatory, mutual PKI authentication whenever practical.</p>
<p><strong>Audit &#8211; WHO did it?</strong></p>
<p>Without assurance that data is unaltered, audit records are useless because the events they capture have no credible association with who did what.<br />
Organizations are driven to meticulously audit activities due to regulatory requirements and security best practices.</p>
<p>BEST PRACTICE: Employ two-factor, mandatory, mutual PKI authentication whenever practical.</p>
<p><strong>Why two-factor?</strong></p>
<p>Endpoints, such as desktops and laptops, can be compromised with malware. Over 20% of malware found on endpoints is designed to steal user name and password credentials. A digital identity that resides within a second, physical device that prevents any copying or spoofing of that data ensures that one can rely on assertions that Alice is indeed Alice.</p>
<p><strong>Why mutual authentication?</strong></p>
<p>Most authentication deployments support the server (a.k.a., its administrator) authenticate any user that approaches it. But, how does the end-user authenticate the server or site? If this is untrustworthy, then all other security measures can be compromised. That is why half the email or junk mail any end-user receives points to fake websites.</p>
<p><strong>Why PKI?</strong></p>
<p>One-time pass code authentication schemes are generally one-way, authenticating the end-user only. PKI facilitates mutual authentication. It also provides for non-repudiation and other useful security services.</p>
<img src="http://www.blueridgenetworks.com/securitynowblog/?ak_action=api_record_view&id=8&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.blueridgenetworks.com/securitynowblog/all-security-depends-on-authentication/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
