GENESIS COMMUNICATION Solution News on
Security Risk Management.

Please forward this news on to others who might be interested in this subject.

GENESIS - SOLUTION NEWS: SNEWS-2003-03-20

SECURITY RISK MANAGEMENT


Computer and network security has been viewed as an engineering problem, and companies have tried to solve it through the application of technologies. The real problem is not one of technology, but of process. Network security is no different from real-world security. The correct paradigm is "risk management".

A typical description of the security threats are : Website defacements, corruption and loss of data due to network penetrations, denial-of-service
attacks, viruses and Trojans. The traditional paradigm of computer security is to avoid the threats but unfortunately this is only part of the process.
Security is a people problem, not a technology problem. Prevention systems are never perfect. No bank ever says: “Our safe is so good, we don’t
need an alarm system”. Businesses manage all sorts of risks; network security is just another one. Real-world security includes prevention, detection,
and response. A preventive countermeasure provides two things:

  • Barrier to overcome
  • Time to overcome the barrier

On the Internet, this translates to monitoring. IT monitoring implies a series of sensors in and around the network. Every firewall produces a
continuous stream of audit messages. So does every router and server. Intrusion Detection Systems (IDS) send messages when they notice
something. Realtime detection can catch attackers, regardless of the vulnerability and rapid response can repel attackers, before they do lasting damage.

To discover and react to attacks within the IT infrastructure a Security management and monitoring system must be implemented.
The following 2 possibilities exist:

Seminar invitation on this subject


SECURITY INFORMATION MANAGEMENT (SIM) SYSTEM

Corporations have invested heavily in building their enterprise security infrastructures with point products such as IDS, firewalls, etc. Unfortunately, many of them lie dormant or are ignored because they generate realms of security information that require laborious analysis. The effect of this “Log Data Overload” is that finding a true attack in a timely manner is as difficult as finding a needle in a haystack.

Security teams need an enterprise-level security solution that enables more efficient, more effective threat management. A solution that:

  • Enables centralized attack monitoring and incident response
  • Minimizes log data overload to uncover true attacks quickly
  • Views threat holistically using correlated attack and vulnerability data
  • Maximizes limited security budgets

neuSECURE is a security event management software solution designed to provide a comprehensive, coherent view of enterprise security.
It correlates event data files from disparate machines such as firewalls, intrusion detection systems, computer systems and routers and
automatically analyzes this data to uncover legitimate threats to the enterprise. neuSECURE allows security analysts to prioritize their
investigations and focus on the mission-critical task of responding to threats as they are occurring, rather than after the damage is done.
And with neuSECURE a security team can manage security threats from early detection to final resolution without ever leaving the intuitive,
web-based console.

Business Benefits:

  • Reduce the Cost of Security Operations
  • Generate Value from Current Security Investments
  • Reduce Business Risk by Responding in Real-time
  • Comply with Government Regulations and Customer/Partner Agreements

CONTACT FORM


 

MANAGED SECURITY MONITORING (MSM) SERVICE

GENESIS COMMUNICATION together with Counterpane Internet Security, Inc. has brought this thinking to computer networks by offering the Managed Security Monitoring (MSM) Service for real-time detection and response using advanced correlation technology and expert human security analysts.


Instead of major investments in software,hardware and services, the company pays an annual user fee for a predefined
“Managed Service”. Thus the customer does not have to tie up any additional staff resources, but can immediately
obtain the services offered, and benefit from established know-how.

READ MORE ABOUT

CONTACT FORM

 

DNS SECURITY SOLUTIONS OF NOMINUM

DNS is included in the top 20 security threats listed by the SANS Institute and the FBI. Attacks on DNS servers have shut down Internet access for large, technically-oriented enterprises -- for example, microsoft.com was rendered unreachable for a week by a DNS attack in 2001.

A recent security alert issued by CERT disclosed a new and much broader DNS attack, which threatens applications that use DNS, rather than the DNS servers themselves as all previous DNS attacks have done. The only complete protection is to modify all vulnerable applications that use DNS. Until all your applications are fixed, or if some applications cannot be fixed -- for example, if a software vendor is out of business -- the Nominum DRV (DNS Response Validator) is the only defense.

Nominum DNS Response Validator
The industry's first DNS armed guard, Nominum DNS Response Validator (DRV), blocks potential attacks on a widespread network vulnerability in business applications running on UNIX systems.
More about this product


Nominum Foundation™ Authoritative Name Server

Foundation ANS is a carrier class DNS server product. ANS was designed from the start for excellent performance as a dedicated authoritative name server. ANS outperforms any other name server product in query responses and is able to scale to millions of names. Supports the DNSSEC protocols.
More about this product


Nominum Foundation™ Caching Name Server

Optimizing DNS performance - Foundation CNS, a dedicated caching name server, performs better, in name resolutions per second, than any other name server. Foundation CNS is the only caching name server that offers Response Validation. Supports secure DNS – DNSSEC cryptographic validation.
More about this product

CONTACT FORM

 

 

SEMINARS AND EVENTS

GENESIS COMMUNICATION  offers a variety of half-day technology seminars and we would be very glad to welcoming you.For lLatest information and news about seminars and events please go to www.GenesisCom.ch.


 

APRIL

 

 SUBJECT SECURITY RISK MANAGEMENT: SECURITY MONITORING AND INFORMATION MANAGEMENT
 Date: Wednesday, 2 April 2003
 Language:  English
 Location:   Swissôtel, Zurich-Oerlikon
 Duration: 08.30 am- 12.45 pmfollowed by lunch

MORE INFO AND REGISTRATION CLICK HER

 
 SUBJECT SECURITY RISK MANAGEMENT: SECURITY MONITORING AND INFORMATION MANAGEMENT
 Date: Thursday, 3 April 2003
 Language:  English
 Location:   Mövenpick Hotel ICC, Geneva
 Duration: 08.30 am- 12.45 pm followed by lunch

 

MORE INFO AND REGISTRATION CLICK HER


AGENDA

  • Introduction Security Monitoring
  • What does Managed Security Monitoring Services (MSM) mean?
  • Security Information Management (SIM)
  • Demo neuSecure from GuardedNet
  • DNS Security - DNS Threats and Defences (David Conrad)

This seminar takes place in co-operation with our partners Counterpane, GuardedNet and Nominum and is
free of charge.


MAY

 

 SUBJECT SYMPOSIUM: CHALLENGE IT-SECURITY
Trends, problems and solutions
 Date: Thursday, 15 May 2003
 Language:  German
 Location:   Nôvotel, Zurich, City-Technopark
 Duration: 08.30 am- 17.00 pm

MORE INFO AND REGISTRATION CLICK HER

AGENDA

  • Security risk Wireless-LAN?
  • Security Monitoring
  • Risk Management in projects
  • Efficient and economical promotion of security awareness
  • Enterprises on the Internet: Risks and chances of transparency
  • Security certification for enterprises
  • Security requirements in the near future

 

 

TRAINING NEWS

COMMUNICATION SECURITY TRAINING

Internet and E-commerce open more and more new opportunities, but also new threats.

The training will cover the following topics:

  • Some well known and destructive attacks
  • Cryptography basics and key terms
  • Crypto systems: DES, IDEA, RC4, Blowfish, RSA, Diffie Hellman, MD5, SHA-1, RIPEMD
  • What is a Digital Signature?
  • Certificate authority CA
  • Public key infrastructure PKI
  • Virtual Private Network (VPN)
  • Design criteria
  • IPsec and IKE
  • SKIP
  • SSL and S-HTTP protocols
  • Link encryption
  • Firewall categories and functionality

This training gives an overview of the risk of Internetworking and the technologies to protect sensitive information.

More Information


GENESIS COMMUNICATION provides technology courses about current themes/technologies like DNS, DHCP, network security and network management as well as product specific courses (e.g. QIP, eHealth, NMS etc.) with practical hands-on exercises. Our courses should offer a real value-add and best ROI of our proposed solutions; for our main goal is and will always be total customer satisfaction!

Our training products are:

 

1.   Standard courses or „Open trainings“ take place either in our training centre in Ostermundigen or by request at the customer's location. For the scheduled dates (Open trainings), participants can subscribe to any course. A detailed course description (flyer) is available for each Standard training.

2.   The customer specific trainings are project-oriented and customized for each individual customer need and specific requirement.

3.   Our trainings are available in German, French and English.

 

Detailed information are available upon request  training@GenesisCom.ch, Phone: +41 (0) 31 560 35 35

Click here for the Training schedule 2003  Training Schedule 2003

 


SUBSCRIPTION INFORMATION

GENESIS COMMUNICATION Solution-News is distributed via email to GENESIS COMMUNICATION contacts. To subscribe, please make sure that your email request to info@GenesisCom.ch includes full name, company name, address, phone number, email address. To update your subscription information, add additional recipients or remove your name from the subscription list, please send an email to:  info@GenesisCom.ch. To make sure this newsletter is useful, we welcome your input and suggestions and encourage you to contact us at info@GenesisCom.ch. To unsubscribe, please send an email to info@GenesisCom.ch with the following information: "unsubscribe Solution-News" followed by your email address and name.

Copyright © 2003 GENESIS COMMUNICATION, Switzerland. All rights reserved.