In the dramatically titled Fatal System Error, Joseph Menn tells the story of a young hacker who, in 2004, helped protect American online-betting businesses from a gang of Russian hacker-extortionists. The essence of their threats: “pay up or we’ll hit your servers with a Denial of Service (DoS) attack rendering your online gambling site unusable.” Attackers would fire a warning shot, launching a sample attack prior to a holiday or major event, and then demand a payment to ensure it wouldn’t happen again.
Read MoreIf there’s anything scarier than the Stuxnet attack and its variants, it would have to be the rapid proliferation of mobile malware. 2011 has seen exponential growth in mobile malware, fueled by the pace of smartphone adoption. Lookout Mobile just published a mobile threat report that estimates between a half million and one million users were affected by mobile malware in the first half of 2011. The takeaway: Don’t expect to see this trend reverse in 2012. Start preparing now. Doing our part to minimize the impact of security threats, we recently added more mobility testing and SCADA testing capabilities to the BreakingPoint products.
Read MoreLate last year, Enterprise Strategy Group reported that less than a third of companies in critical infrastructure industries (banking, electric utilities, etc.) conducted consistent vendor evaluations. In the SANS Institute survey on network security BreakingPoint just conducted, only 18 percent of respondents said that they have a formal testing and validation program in place to harden elements of their infrastructure against attack.
Read MoreIn an era of steep budget cuts for the U.S. Department of Defense (DoD), the objective in government circles has been to “get small” — to do more without spending more. Although some budget allocations for cybersecurity may be protected from cuts, the imperative to get small still makes sense. Smaller typically means more agile, easier to deploy widely, and, of course, less costly. This certainly holds true on the cyber range front, where those charged with cyber defense await the online training grounds they need to develop incident response and defense techniques. By investing in newer, compact, and agile cyber ranges, the DoD could deliver full Internet-scale simulation capabilities to military bases worldwide. Who says you can’t have better, faster, AND more cost-effective?
Read MoreStriking a balance between performance and security has always presented a tightrope walk for IT professionals charged with securing enterprise networks and data centers. Veer too far toward performance, and you open yourself up to a DDoS attack that will bring performance to a standstill. Lock security down too tight, and you risk blocking functionality or frustrating users who have come to demand low latency. Navigating this tightrope has been difficult enough; add virtualization to the mix, and you’re now walking a tightrope in the dark. Security threats, heavy user load, infrastructure changes, and compliance requirements still come at you from all angles — only now they do it within a dynamically changing infrastructure.
Read More