<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Network View &#187; firewall</title>
	<atom:link href="http://www.anuesystems.com/blog/tag/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anuesystems.com/blog</link>
	<description></description>
	<lastBuildDate>Thu, 15 Jul 2010 15:30:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Network Security Model &#8211; Defining an Enterprise Security Strategy</title>
		<link>http://www.anuesystems.com/blog/2010/02/22/network-security-model-defining-an-enterprise-security-strategy/</link>
		<comments>http://www.anuesystems.com/blog/2010/02/22/network-security-model-defining-an-enterprise-security-strategy/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 20:29:38 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Log Inspection]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Networking Protocols]]></category>
		<category><![CDATA[data center]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[dmz]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[extranet]]></category>
		<category><![CDATA[ezine articles]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[ibm]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[intrusion prevention]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[mainframe]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[perimeter]]></category>
		<category><![CDATA[shaun hummel]]></category>
		<category><![CDATA[strategy]]></category>
		<category><![CDATA[syslog]]></category>
		<category><![CDATA[transaction]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[virus detection]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=597</guid>
		<description><![CDATA[Today we are sharing with you an insightful article by Shaun Hummel, focused on how to align the five primary functions of security inside an enterprise. Enjoy and please give a look at Shaun's service as indicated below.]]></description>
			<content:encoded><![CDATA[<p>Today we are sharing with you an insightful article by Shaun Hummel, focused on how to align the five primary functions of security inside an enterprise. Enjoy and please give a look at Shaun&#8217;s service as indicated below.</p>
<p style="text-align: center;">_________________________</p>
<div id="body">
<p><strong>Overview</strong></p>
<p>These are the 5 primary security groups that should be considered with any enterprise security model. These include security policy, perimeter, network, transaction and monitoring security. These are all part of any effective company security strategy. Any enterprise network has a perimeter that represents all equipment and circuits that connect to external networks both public and private. The internal network is comprised of all the servers, applications, data, and devices used for company operations. The demilitarized zone (DMZ) represents a location between the internal network and the perimeter comprised of firewalls and public servers. It that allows some access for external users to those network servers and denies traffic that would get to internal servers. That doesn&#8217;t mean that all external users will be denied access to internal networks. On the contrary, a proper security strategy specifies who can access what and from where. For instance telecommuters will use VPN concentrators at the perimeter to access Windows and Unix servers. As well business partners could use an Extranet VPN connection for access to the company S/390 Mainframe. Define what security is required at all servers to protect company applications and files. Identify transaction protocols required to secure data as it travels across secure and non-secure network segments. Monitoring activities should then be defined that examine packets in real time as a defensive and pro-active strategy for protecting against internal and external attacks. A recent survey revealed that internal attacks from disgruntled employees and consultants are more prevalent than hacker attacks. Virus detection should then be addressed since allowed sessions could be carrying a virus at the application layer with an e-mail or a file transfer.</p>
<p><strong>Security Policy Document</strong></p>
<p>The security policy document describes various policies for all employees that use the enterprise network. It specifies what an employee is permitted to do and with what resources. The policy includes non-employees as well such as consultants, business partners, clients and terminated employees. In addition security policies are defined for Internet e-mail and virus detection. It defines what cyclical process if any is used for examining and improving security.</p>
<p><strong>Perimeter Security</strong></p>
<p>This describes a first line of defense that external users must deal with before authenticating to the network. It is security for traffic whose source and destination is an external network. Many components are used to secure the perimeter of a network. The assessment reviews all perimeter devices currently utilized. Typical perimeter devices are firewalls, external routers, TACACS servers, RADIUS servers, dial servers, VPN concentrators and modems.</p>
<p><strong>Network Security </strong></p>
<p>This is defined as all of the server and legacy host security that is implemented for authenticating and authorizing internal and external employees. When a user has been authenticated through perimeter security, it is the security that must be dealt with before starting any applications. The network exists to carry traffic between workstations and network applications. Network applications are implemented on a shared server that could be running an operating system such as Windows, Unix or Mainframe MVS. It is the responsibility of the operating system to store data, respond to requests for data and maintain security for that data. Once a user is authenticated to a Windows ADS domain with a specific user account, they have privileges that have been granted to that account. Such privileges would be to access specific directories at one or many servers, start applications, and administer some or all of the Windows servers. When the user authenticates to the Windows Active Directory Services distributed it is not any specific server. There is tremendous management and availability advantages to that since all accounts are managed from a centralized perspective and security database copies are maintained at various servers across the network. Unix and Mainframe hosts will usually require logon to a specific system, however the network rights could be distributed to many hosts.</p>
<p>·  Network operating system domain authentication and authorization</p>
<p>·  Windows Active Directory Services authentication and authorization</p>
<p>·  Unix and Mainframe host authentication and authorization</p>
<p>·  Application authorization per server</p>
<p>·  File and data authorization</p>
<p><strong>Transaction Security </strong></p>
<p>Transaction security works from a dynamic perspective. It attempts to secure each session with five primary activities. They are non-repudiation, integrity, authentication, confidentiality and virus detection. Transaction security ensures that session data is secure before being transported across the enterprise or Internet. This is important when dealing with the Internet since data is vulnerable to those that would use the valuable information without permission. E-Commerce employs some industry standards such as SET and SSL, which describe a set of protocols that provide non-repudiation, integrity, authentication and confidentiality. As well virus detection provides transaction security by examining data files for signs of virus infection before they are transported to an internal user or before they are sent across the Internet. The following describes industry standard transaction security protocols.</p>
<p>Non-Repudiation &#8211; RSA Digital Signatures</p>
<p>Integrity &#8211; MD5 Route Authentication</p>
<p>Authentication &#8211; Digital Certificates</p>
<p>Confidentiality &#8211; IPSec/IKE/3DES</p>
<p>Virus Detection  &#8211; McAfee/Norton Antivirus Software</p>
<p><strong>Monitoring Security </strong></p>
<p>Monitoring network traffic for security attacks, vulnerabilities and unusual events is essential for any security strategy. This assessment identifies what strategies and applications are being employed. The following is a list that describes some typical monitoring solutions. Intrusion detection sensors are available for monitoring real time traffic as it arrives at your perimeter. IBM Internet Security Scanner is an excellent vulnerability assessment testing tool that should be considered for your organization. Syslog server messaging is a standard Unix program found at many companies that writes security events to a log file for examination. It is important to have audit trails to record network changes and assist with isolating security issues. Big companies that utilize a lot of analog dial lines for modems sometimes employ dial scanners to determine open lines that could be exploited by security hackers. Facilities security is typical badge access to equipment and servers that host mission critical data. Badge access systems record the date time that each specific employee entered the telecom room and left. Cameras sometimes record what specific activities were conducted as well.</p>
<p><strong>Intrusion Prevention Sensors (IPS)</strong></p>
<p>Cisco markets intrusion prevention sensors (IPS) to enterprise clients for improving the security posture of the company network. Cisco IPS 4200 series utilize sensors at strategic locations on the inside and outside network protecting switches, routers and servers from hackers. IPS sensors will examine network traffic real time or inline, comparing packets with pre-defined signatures. If the sensor detects suspicious behavior it will send an alarm, drop the packet and take some evasive action to counter the attack. The IPS sensor can be deployed inline IPS, IDS where traffic doesn&#8217;t flow through device or a hybrid device. Most sensors inside the data center network will be designated IPS mode with its dynamic security features thwarting attacks as soon as they occur. Note that IOS intrusion prevention software is available today with routers as an option.</p>
<p><strong>Vulnerability Assessment Testing (VAST)</strong></p>
<p>IBM Internet Security Scanner (ISS) is a vulnerability assessment scanner focused on enterprise customers for assessing network vulnerabilities from an external and internal perspective. The software runs on agents and scans various network devices and servers for known security holes and potential vulnerabilities. The process is comprised of network discovery, data collection, analysis and reports. Data is collected from routers, switches, servers, firewalls, workstations, operating systems and network services. Potential vulnerabilities are verified through non-destructive testing and recommendations made for correcting any security problems. There is a reporting facility available with the scanner that presents the information findings to company staff.</p>
<p><strong>Syslog Server Messaging</strong></p>
<p>Cisco IOS has a Unix program called Syslog that reports on a variety of device activities and error conditions. Most routers and switches generate Syslog messages, which are sent to a designated Unix workstation for review. If your Network Management Console (NMS) is using the Windows platform, there are utilities that allow viewing of log files and sending Syslog files between a Unix and Windows NMS.</p>
<p style="text-align: center;">_________________________________</p>
</div>
<p><em>Shaun Hummel is the author of <a href="http://www.amazon.com/s/ref=nb_ss?url=search-alias%3Daps&amp;field-keywords=shaun+hummel" target="_new">Network Planning and Design Guide</a> and has a web site focused on information technology job search solutions and certifications.</em></p>
<p>Article Source: <a title="Ezine Articles" href="http://ezinearticles.com/" target="_blank">EzineArticles.com</a></p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Network Security Model &#8211; Defining an Enterprise Security Strategy";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2010/02/22/network-security-model-defining-an-enterprise-security-strategy/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;t=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;t=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;T=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2010%2F02%2F22%2Fnetwork-security-model-defining-an-enterprise-security-strategy%2F&amp;title=Network+Security+Model+%26%238211%3B+Defining+an+Enterprise+Security+Strategy"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2010/02/22/network-security-model-defining-an-enterprise-security-strategy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Look Inside Security Tools (ALIST): Johnnie Konstantas of Altor Networks</title>
		<link>http://www.anuesystems.com/blog/2009/11/19/a-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks/</link>
		<comments>http://www.anuesystems.com/blog/2009/11/19/a-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 19:01:01 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[Log Inspection]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tool Aggregation]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[data center]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[altor networks]]></category>
		<category><![CDATA[altor vf]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[clouds]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[drs]]></category>
		<category><![CDATA[evan almighty]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[groups]]></category>
		<category><![CDATA[Hotmail]]></category>
		<category><![CDATA[hypervisor]]></category>
		<category><![CDATA[Johnnie Konstantas]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[noah]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[salesforce]]></category>
		<category><![CDATA[steve carrell]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[virtual data centers]]></category>
		<category><![CDATA[vm sprawl]]></category>
		<category><![CDATA[vmotion]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=485</guid>
		<description><![CDATA[After our one-week hiatus from the ALIST series, we turn our attention back here to profile a key executive at Altor Networks. Johnnie Konstantas has a long track record of technical and marketing leadership success at leading companies such as Juniper Networks, CheckPoint, and most recently, Varonis Systems. Now, she leads the charge to market Altor Networks' virtualization security products. Let's get right to the interview...]]></description>
			<content:encoded><![CDATA[<p><strong></p>
<div class="wp-caption alignright" style="width: 249px"><strong><img class="   " title="ALIST: Johnnie Konstantas of Altor Networks" src="http://www.anuesystems.com/blog/Johnnie_Konstantas.jpg" alt="ALIST: Johnnie Konstantas of Altor Networks" width="239" height="305" /></strong><p class="wp-caption-text">ALIST: Johnnie Konstantas of Altor Networks</p></div>
<p></strong></p>
<p>After our one-week hiatus from the ALIST series, we turn our attention back here to profile a key executive at Altor Networks. Johnnie Konstantas has a long track record of technical and marketing leadership success at leading companies such as Juniper Networks, CheckPoint, and most recently, Varonis Systems. Now, she leads the charge to market Altor Networks&#8217; virtualization security products. Let&#8217;s get right to the interview&#8230;</p>
<p><strong>Name: </strong>Johnnie Konstantas<br />
<strong>Title/Role:</strong> Vice President of Marketing<br />
<strong>Company: </strong><a title="Altor Networks Home Page" href="http://altornetworks.com/" target="_blank">Altor Networks</a><br />
<strong>Product Focus:</strong> Security for <a title="Virtual Data Centers Ezine" href="http://searchdatacenter.techtarget.com/generic/0,295582,sid80_gci1313630,00.html" target="_blank">virtual data centers</a> and clouds<br />
<strong>Twitter Handle:</strong> <a title="Twitter: Altor Networks" href="http://twitter.com/altornetworks" target="_blank">@altornetworks</a><br />
<strong><em><br />
</em></strong></p>
<p><strong><em>1. What is your company&#8217;s flagship product, and why is it important for security purposes?</em></strong><br />
Altor Networks&#8217; flagship product is <a title="Altor VF" href="http://altornetworks.com/products/features/" target="_blank">Altor VF</a> &#8211; an industry first purpose-built firewall that offers comprehensive security of virtualized networks and the hypervisor. Now in it&#8217;s third major release, the Altor solution protects virtualized servers and the platform they run on from unwarranted access and malware without impacting throughput or virtualization&#8217;s scalability (i.e. <a title="vMotion" href="http://www.vmware.com/products/vmotion/" target="_blank">vMotion</a>, <a title="DRS" href="http://www.vmware.com/products/drs/" target="_blank">DRS</a>).</p>
<p><strong><em>2. What areas of security are most important to you professionally, and which do you enjoy working with most?<br />
</em></strong>Virtual network and cloud security impact me most at the moment, since it&#8217;s my current charter to educate the market on the risks and mitigation strategies. After [having spent] 16 years in the market, there are a lot of areas which fascinate me, although I have to admit that, in this place I find myself now,  there is extreme gratification in seeding and educating a market on what you know to be imminent risks. You feel a little like <a title="IMDB: Steve Carrell" href="http://www.imdb.com/name/nm0136797/" target="_blank">Steve Carrell</a> playing Noah in <a title="IMDB: Evan Almighty" href="http://www.imdb.com/title/tt0413099/" target="_blank">Evan Almighty</a>, trying to convince the townspeople to come to the boat.</p>
<div class="wp-caption aligncenter" style="width: 460px"><img title="Evangelism: Explaining Virtualization Strategy Akin to Noahs Quandary" src="http://www.post-gazette.com/images4/20070622hobruceAl2_450.jpg" alt="Evangelism: Explaining Virtualization Strategy Akin to Noahs Quandary" width="450" height="290" /><p class="wp-caption-text">Evangelism: Explaining Virtualization Strategy Akin to Noah&#39;s Quandary</p></div>
<p><strong><em>3. What is the most common security challenge you are brought in on to help fix on behalf of customers?<br />
</em></strong>Restoring the virtual environment to a compliant or compliance-acceptable security posture is the biggest driver to Altor deployment at the moment. People virtualize their servers and then someone asks &#8220;How are we going to demonstrate access control enforcement and separation of duties?&#8221;</p>
<p><em><strong>4. How do you see Cloud Computing, virtualization, and Social Media affecting security in the coming months?<br />
</strong></em>Enterprises of all sizes are shifting their workloads to virtualized platforms in droves. When they do, the questions start flowing: How do I demonstrate compliance? How do I segment my resources? How do I control VM sprawl and mitigate security risks? There are available products and approaches, but the degree to which they preserve virtualization&#8217;s savings vary, so I suspect there will be a rush to educate and implement. To the extent that clouds may use virtualization as their platform, the net effect is the same. How do I protect my business and my customer&#8217;s assets?</p>
<p>[Companies need] corporate guidelines in play regarding what can be shared outside the firm via social media outlets, which largely requires that  people know the right thing to do. That effort is largely a focus on  building and &#8220;socializing&#8221; (pardon the pun) proper use policies.</p>
<p><strong><em>5. Tell me what your most pressing security concern is over the next 1-2 years.<br />
</em></strong>I worry that, in a rush to build green, efficient, data centers, well-intended folks who are short handed and following corporate mandates may shortchange security in the architecting of these new networks. I worry that my personal information maybe more at risk in the next two years than it is today.</p>
<p><em><strong>6. How do you stay abreast of the latest market developments in your space? Shows, social media, RSS, etc.<br />
</strong></em>All of the above. It is imperative to leverage the &#8220;groups&#8221; features of the various social media outlets so that you not only get the latest breaking stories, but for me as a marketeer, I need to understand what the prevalent attitudes are about a company, a market, a trend, etc.</p>
<p><strong><em>7. In closing, give us one idea you have about security that everyone should consider. Your &#8220;Golden Egg&#8221;, so to say.</em></strong><br />
Assuming that you are using some sort of cloud service (and chances are good you are, i.e. <a title="Gmail" href="http://mail.google.com/" target="_blank">Gmail</a>, <a title="Hotmail" href="http://www.hotmail.com/" target="_blank">Hotmail</a>, <a title="SalesForce" href="http://www.salesforce.com/" target="_blank">Salesforce</a>), make sure you know what protects your piece of the cloud from someone else&#8217;s? What one measure, policy, or guarantee can the provider make to you?</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "A Look Inside Security Tools (ALIST): Johnnie Konstantas of Altor Networks";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/11/19/a-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;t=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;t=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;T=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F19%2Fa-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Johnnie+Konstantas+of+Altor+Networks"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/11/19/a-look-inside-security-tools-alist-johnnie-konstantas-of-altor-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Look Inside Security Tools (ALIST): Rick Basile of Fortinet</title>
		<link>http://www.anuesystems.com/blog/2009/11/05/a-look-inside-security-tools-alist-rick-basile-of-fortinet/</link>
		<comments>http://www.anuesystems.com/blog/2009/11/05/a-look-inside-security-tools-alist-rick-basile-of-fortinet/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 18:06:37 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Infrastructure Security]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[fortigate]]></category>
		<category><![CDATA[fortimail]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[jennifer leggio]]></category>
		<category><![CDATA[mediaphyter]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network perimeter]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[rick basile]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=460</guid>
		<description><![CDATA[Welcome to the third installment of our ALIST series. Today we offer you Rick Basile, the Senior Director of Technical Services for Fortinet.  We want to thank our friend Jennifer Leggio (@mediaphyter), Strategic Communications Director at Fortinet and Social Business blogger for ZDnet, for helping us arrange this interview with Rick.]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 268px"><img class="  " title="ALIST: Rick Basile of Fortinet" src="http://s178.photobucket.com/albums/w258/TPLTX/R-BasileFortinetHeadshot.jpg" alt="ALIST: Rick Basile of Fortinet" width="258" height="310" /><p class="wp-caption-text">ALIST: Rick Basile of Fortinet</p></div>
<p>Welcome to the third installment of our ALIST series. Today we offer you Rick Basile, the Senior Director of Technical Services for Fortinet.  We want to thank our friend Jennifer Leggio (<a title="Twitter: Jennifer Leggio" href="http://twitter.com/mediaphyter" target="_blank">@mediaphyter</a>), Strategic Communications Director at Fortinet and <a title="ZDnet: Jennifer Leggio Social Media Blog" href="http://blogs.zdnet.com/feeds/" target="_blank">Social Business blogger for ZDnet</a>, for helping us arrange this interview with Rick.</p>
<p><strong>Name:</strong> <a title="Fortinet Blog: Rick Basile Video on Application Visibility vs. Application Security" href="http://blog.fortinet.com/application-visibility-vs-application-security/" target="_blank">Rick Basile</a><br />
<strong>Title/Role:</strong> Senior Director, Technical Services<br />
<strong>Company: </strong><a title="Fortinet" href="http://www.fortinet.com/" target="_blank">Fortinet</a><br />
<strong>Product Focus: </strong>Entire security product portfolio<br />
<strong>Twitter Handle: </strong><a title="Twitter: Fortinet" href="http://twitter.com/fortinet" target="_blank">@fortinet</a><br />
<em><strong><br />
1. What is your company&#8217;s flagship product, and why is it important for security purposes?</strong></em><br />
Our flagship product is our <a title="FortiGate" href="http://www.fortinet.com/products/fortigate/" target="_blank">FortiGate security appliance</a> line, a hardware platform allowing enterprise companies to deploy multiple security applications, i.e. IPS, firewall, VPN, antivirus, and so on, in a more manageable security solution. Our consolidated security approach allows for a more secure, cost-effective, and easy-to-manage solution for our customers.</p>
<p><strong><em>2. What areas of security are most important to you professionally, and which do you enjoy working with most?</em></strong><br />
<a title="Network Perimeter Security" href="http://www.itsecurity.com/features/security-edge-020408/" target="_blank">Network perimeter based security</a>; [which is] the ability to help corporations control access into their infrastructures, as well as controlling what intellectual assets and behaviors are allowed out of their infrastructures. This can be done with our FortiGate product line as a multifaceted security appliance, or our <a title="FortiMail Product" href="http://www.fortinet.com/products/fortimail/" target="_blank">FortiMail secure messaging product</a>, which allows for the mitigation of inbound SPAM and threats and also intelligent encryption of sensitive data leaving the infrastructure.</p>
<p><em><strong>3. What is the most common security challenge you are brought in on to help fix on behalf of customers?</strong></em><br />
The most common security challenge for customers is looking for an enterprise-wide posture and policy. It’s my job to help them secure their infrastructures against internal and external threats. While our product set is all about the ability to consolidate, it does not minimize the need for a layered security policy. We help our customers determine where those layers need to be in the infrastructure.</p>
<p><strong><em>4. How do you see Cloud Computing, virtualization, and Social Media affecting security in the coming months?</em></strong><br />
As more enterprises investigate leveraging <a title="Wikipedia: Cloud Computing" href="http://en.wikipedia.org/wiki/Cloud_computing" target="_blank">cloud computing</a> environments to store and manipulate their data, they have to be confident that these providers are ensuring the segregation and security of their data and resources from unwarranted access.  Beyond these basic concerns in choosing a cloud computing environment, I also have concerns around the ability of an enterprise to have confidence in their continued control of their intellectual property.  As an example, should an enterprise choose to leave one cloud computing vendor for another, how would they know that their data truly leaves with them?  What mechanisms are being put in place to guarantee the revocation of that data from a vendor&#8217;s cloud?</p>
<p>On the social media side, these social networks don’t just offer a security risk from malware exploits or unwanted access, they present risks on authenticity of information as well. Information mishandling is another concern against which companies need to protect.  As these social media outlets grow, it is becoming increasingly challenging to ensure that users are going to the authoritative owners of the data for their information.</p>
<p><strong><em>5. Tell me what your most pressing security concern is over the next 1-2 years.</em></strong><br />
My most pressing concern is around people focusing more on being compliant than on being secure. Compliance is what drives a lot of buying cycles, but being secure should be first and foremost when they look at what they are going to deploy and how they are going to deploy it. Compliance is clearly important, but you have to make sure you are secure as well.</p>
<p><strong><em>6. How do you stay abreast of the latest market developments in your space? Shows, social media, RSS, etc.</em></strong><br />
I spend a lot of time researching and working with our own research analysts and product and development teams. Most of what I do to stay abreast is working directly with customers in pre- and post-sales situations. I also get to spend a lot of time with analysts in the space, learning what they are hearing from their customers.</p>
<p><strong><em>7. In closing, give us one idea you have about security that everyone should consider. Your &#8220;Golden Egg&#8221;, so to say.</em></strong><br />
When considering a security solution, ask yourself, “What are the assets you are trying to protect? What are you trying to accomplish?” Don’t get lost in trying to purchase a solution on name alone. Even though I work for a vendor, it’s my job to best position our product line to actually address customer needs. Determine your requirements and your needs, and work with the vendor that best matches your requirements.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "A Look Inside Security Tools (ALIST): Rick Basile of Fortinet";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/11/05/a-look-inside-security-tools-alist-rick-basile-of-fortinet/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;t=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;t=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;T=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F11%2F05%2Fa-look-inside-security-tools-alist-rick-basile-of-fortinet%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rick+Basile+of+Fortinet"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/11/05/a-look-inside-security-tools-alist-rick-basile-of-fortinet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Look Inside Security Tools (ALIST): Rob Andrews of Sonicwall</title>
		<link>http://www.anuesystems.com/blog/2009/10/20/a-look-inside-security-tools-alist-rob-andrews-of-sonicwall/</link>
		<comments>http://www.anuesystems.com/blog/2009/10/20/a-look-inside-security-tools-alist-rob-andrews-of-sonicwall/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 20:16:14 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[Content Filtering]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Tool Aggregation]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[alist]]></category>
		<category><![CDATA[deep packet inspection]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[gui]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[igoogle]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[mac os]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[rob andrews]]></category>
		<category><![CDATA[rss]]></category>
		<category><![CDATA[slashdot]]></category>
		<category><![CDATA[sonicwall]]></category>
		<category><![CDATA[ssl-vpn]]></category>
		<category><![CDATA[system engineer]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[utm]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[wep]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=424</guid>
		<description><![CDATA[Today we are kicking off our "A Look Inside Security Tools" (ALIST) series, starting with Rob Andrews, System Engineer from Sonicwall. Over the next several weeks, we will be interviewing technical sales professionals from leading security monitoring tool companies. But don't worry, this will not be a straight product pitch. We do offer each subject to share an elevator pitch about their flagship product, but we will also delve into a range of security topics associated with virtualization, cloud computing, and "Golden Eggs".]]></description>
			<content:encoded><![CDATA[<p>Today we are kicking off our &#8220;A Look Inside Security Tools&#8221; (ALIST) series, starting with Rob Andrews, System Engineer from Sonicwall. Over the next several weeks, we will be interviewing technical sales professionals from leading security monitoring tool companies. But don&#8217;t worry, this will not be a straight product pitch. We do offer each subject to share an elevator pitch about their flagship product, but we will also delve into a range of security topics associated with virtualization, cloud computing, and &#8220;Golden Eggs&#8221;.</p>
<div class="wp-caption alignright" style="width: 298px"><img class=" " title="ALIST: Rob Andrews of Sonicwall" src="http://www.anuesystems.com/blog/Picture%209.jpg" alt="ALIST: Rob Andrews of Sonicwall" width="288" height="216" /><p class="wp-caption-text">ALIST: Rob Andrews of Sonicwall</p></div>
<p>So let&#8217;s get this ALIST party started&#8230;</p>
<p><strong>Name: </strong>Rob Andrews<br />
<strong>Title/Role: </strong>System Engineer<br />
<strong>Company:</strong> <a title="Sonicwall" href="http://www.sonicwall.com/us/index.html" target="_blank">Sonicwall</a><br />
<strong>Product Focus: </strong><br />
UTM Firewall<br />
SSL VPN appliances<br />
Email Security<br />
Secure wireless</p>
<p><em><strong>1. What is your company&#8217;s flagship product, and why is it important for security purposes?</strong></em><br />
The <a title="Network World: Review of Sonicwall NSA E7500" href="http://www.sonicwall.com/downloads/NWW_Snyder_E7500_Review.pdf" target="_blank">Sonicwall NSA E7500</a> is our enterprise class UTM (<a title="Wikipedia: Unified Threat Management" href="http://en.wikipedia.org/wiki/Unified_Threat_Management" target="_blank">Unified Threat Management</a>) Firewall.  It combines firewall, routing, IPS/IDS, gateway anti-virus, gateway anti-spyware, <a title="Wikipedia: Content Filtering" href="http://en.wikipedia.org/wiki/Content_filtering" target="_blank">content filtering</a>, <a title="Wikipedia: IPsec" href="http://en.wikipedia.org/wiki/IPsec" target="_blank">IPSEC</a>, and <a title="Wikipedia: SSL VPN" href="http://en.wikipedia.org/wiki/SSL_VPN" target="_blank">SSL VPN</a> capabilities into one slim 1u chassis.  It&#8217;s the only appliance on the market that can deliver nearly 2 Gbps of UTM scanning at its price point.</p>
<p><strong>2. What areas of security are most important to you professionally, and which do you enjoy working with most?</strong><br />
I suppose I am a bit biased, but I really enjoy working with my company&#8217;s products, but more specifically the <a title="Sonicwall NSA Firewalls" href="http://www.sonicwall.com/us/products/E-Class_NSA_Series.html" target="_blank">Sonicwall NSA firewalls</a> and <a title="Sonicwall SSL-VPN" href="http://www.sonicwall.com/us/products/Secure_Remote_Access.html" target="_blank">SSL-VPN</a>.  Building a secure network requires the basic building blocks &#8211; firewall and secure remote access.  Essentially, these devices are the gateway to your &#8220;kingdom,&#8221; and the network admin holds the &#8220;key&#8221;.</p>
<p>I find it gratifying in knowing that I control and safeguard access to my resources including where, when, and how; and I think a lot of other IT admins do as well.  Keeping undesirables off my network, whether it is due to access controls or threat prevention mechanisms (i.e. <a title="Wikipedia: Intrusion Prevention System" href="http://en.wikipedia.org/wiki/Intrusion_prevention_system" target="_blank">IPS</a>), helps me sleep at night.  Sonicwall&#8217;s browser based management of the NSA line makes it super simple to configure firewall rules, intrusion prevention/detection policies, content filtering, and routing.  I find anyone that used to have to manage a PIX  falls in love with the simplicity and power of our GUI.</p>
<p><strong><em>3. What is the most common security challenge you are brought in on to help fix on behalf of customers?</em></strong></p>
<p>I have two common scenarios I&#8217;m engaged with.  Almost everyone knows they need a firewall to build a secure network, but how to decide on correct model, features, capacity, and functionality is where I assist.  There are a lot of 5+ year old firewalls installed out there that don&#8217;t meet the demands of today&#8217;s requirements, i.e. throughput, IPS, etc.</p>
<p>The other is when customers need to deploy a VPN solution.  Many folks are using an IPSEC solution for VPN access, and they&#8217;ve discovered that it doesn&#8217;t meet their evolving business needs for things like granular access control, end point interrogation, and browser-based access.  I find many customers have an idea of what they&#8217;d like for VPN access but aren&#8217;t entirely sure how to meet their requirements.</p>
<p><strong><em>4. How do you see Cloud Computing, virtualization, and Social Media affecting security in the coming months?</em></strong><br />
I just had this debate internally with some colleagues.  Some are on the side that cloud infrastructures have more sophisticated individuals maintaining and looking at the security stack, while companies that house data internally have limited IT staff, so the &#8220;cloud&#8221; is therefore it is more secure.  On the other side of the fence, some argue that you are entrusting your data to a third party who may promise the world in security, but in the end, you have no real way of auditing what they are doing.  For most folks, it&#8217;s a balancing act.  If you have no idea what you are doing or how to properly secure your data (and possibly want someone else to blame when things go wrong), using cloud services is something you should consider.  If you&#8217;re on the opposite end of the spectrum&#8230;you have the tools and skill set&#8230;my recommendation is to approach cloud services with caution.</p>
<p>When it comes to <a title="Wikipedia: Application Virtualization" href="http://en.wikipedia.org/wiki/Application_virtualization" target="_blank">virtualization</a>, I&#8217;ve seen some folks take an interest in virtual firewalling.  I&#8217;d have to say this market is still relatively young and fits a certain niche of customers.  The issue with running a VM firewall is its overall performance.  If you are only using the VM firewall to do stateful inspection, it may not be such a big deal for you.  However, we know that most attacks are buried in the <a title="Wikipedia: Payload" href="http://en.wikipedia.org/wiki/Payload_%28software%29" target="_blank">payload</a> of allowed traffic. To do DPI (<a title="Wikipedia: Deep Packet Inspection" href="http://en.wikipedia.org/wiki/Deep_packet_inspection" target="_blank">deep packet inspection</a>) effectively, you need a dedicated UTM appliance so you can see reasonable levels of network performance.  We discovered long ago that <a title="Wikipedia: x86" href="http://en.wikipedia.org/wiki/X86" target="_blank">x86</a> processors don&#8217;t scale well for UTM scanning.</p>
<p>With regard to Social Media, it is and will continue to be a source of malicious attacks and other threats.  I&#8217;m seeing more and more organizations restrict access to Web 2.0 sites with highly positive results, such as reclaiming network bandwidth and employee productivity.  We&#8217;ve already seen numerous issues with threats being propagated through <a title="Facebook" href="http://www.facebook.com/" target="_blank">Facebook</a>, <a title="MySpace" href="http://www.myspace.com/" target="_blank">Myspace</a>, and <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a>.  Anytime you have a place where you get a lot of traffic and information is easily and quickly distributed, there is room for the unscrupulous to take advantage.  This is part of the reason I limit my social networking consumption.  There are others, but that&#8217;s another story for another day.</p>
<p><em><strong>5. Tell me what your most pressing security concern is over the next 1-2 years.</strong></em><br />
I have two concerns for your consideration.</p>
<p>The first how to get customers off old insecure technology.  I find far too many customers relying on antiquated, insecure, or (even worse) technologies that they believe are secure which, in fact, are not.  Unfortunately a lot of organizations are resistant to change, whether that be due to lack of expertise, laziness, budget, etc.  In the end, technology and threats evolve. You either keep pace, or you find yourself a victim or a target of attack.  For example, I recently worked with an organization that insisted on using WEP to secure their wireless infrastructure for hundreds of users.  Never mind the fact that <a title="Wikipedia: WEP" href="http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy" target="_blank">WEP</a> can be cracked in seconds by almost anyone.</p>
<div class="wp-caption alignleft" style="width: 288px"><img title="Fallacy: Linux and Mac OS are inherently more secure" src="http://upload.wikimedia.org/wikipedia/commons/thumb/3/35/Tux.svg/335px-Tux.svg.png" alt="Fallacy: Linux and Mac OS are inherently more secure" width="278" height="327" /><p class="wp-caption-text">Fallacy: Linux and Mac OS are inherently more secure than Windows</p></div>
<p>The other is what I would consider the &#8220;head buried in the sand&#8221; syndrome.  Too many individuals believe <a title="Wikipedia: Linux" href="http://en.wikipedia.org/wiki/Linux" target="_blank">Linux</a> and Mac operating systems are secure by default and don&#8217;t require any safeguarding.  Unfortunately, this myth is also further perpetuated by the media i.e. the Mac/PC commercials on TV. The worst part about this is the false sense of security it brings. Attacks and vulnerabilities have already been demonstrated against these systems.  While these platforms may not have as many vulnerabilities as Windows, they still have their own issues. As Mac continues to gain popularity, I&#8217;m confident we will be seeing more and more security issues for it.</p>
<p><em><strong>6. How do you stay abreast of the latest market developments in your space? Shows, social media, RSS, etc.</strong></em><br />
For more &#8220;mainstream&#8221; type news, I use iGoogle and have about a dozen different gadgets that provide news feeds.  I also visit slashdot.org and hackaday.com on a daily basis, and  Sonicwall has an internal daily news bulletin with information from various sources that goes out to all employees. The folks over at insecure.org have a few different RSS feeds I subscribe to as well.</p>
<p>It&#8217;s almost alarming to see the rate at which vulnerabilities are discovered. If I want to read something on the plane, I&#8217;ll pick up a copy of Hakin9 or 2600.  Finally, I occasionally frequent sites like securitytube.net or the forums at remote-exploit.org.</p>
<p><strong><em>7. In closing, give us one idea you have about security that everyone should consider. Your &#8220;Golden Egg&#8221;, so to say.</em></strong><br />
UTM should be on everyone&#8217;s checklist when it comes to firewall security.  There are far too many threats that are being propagated out there, because regular stateful firewalls are letting them through.  Securing your network is much more than closing ports, it&#8217;s also inspecting the allowed traffic through.  The best analogy I can use is a trip to the airport.  Would you let everyone that holds a boarding pass through security?  Or would you want to scan the payload of the passengers to ensure nothing malicious was brought on board?  Of course, we all know the answer there. This same approach needs to be taken for your network.</p>
<p>___________________________________________________________________</p>
<p>The Anue Systems Team wants to thank Mr. Andrews for jumping in as the first ALIST-er. We are still accepting requests to take part in this program from qualified technical sales / SE professionals at leading security tool vendors. If you wish to be considered for inclusion, please contact Tommy Landry at tlandry (at) anuesystems (dot) com.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "A Look Inside Security Tools (ALIST): Rob Andrews of Sonicwall";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/10/20/a-look-inside-security-tools-alist-rob-andrews-of-sonicwall/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;t=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;t=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;T=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F10%2F20%2Fa-look-inside-security-tools-alist-rob-andrews-of-sonicwall%2F&amp;title=A+Look+Inside+Security+Tools+%28ALIST%29%3A+Rob+Andrews+of+Sonicwall"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/10/20/a-look-inside-security-tools-alist-rob-andrews-of-sonicwall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): Justin Foster/@justin_foster</title>
		<link>http://www.anuesystems.com/blog/2009/07/28/security-pros-on-twitter-spot-justin-fosterjustin_foster/</link>
		<comments>http://www.anuesystems.com/blog/2009/07/28/security-pros-on-twitter-spot-justin-fosterjustin_foster/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 13:00:35 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Networking Protocols]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[blogger]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[intergrity monitoring]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[justin foster]]></category>
		<category><![CDATA[Log Inspection]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security as a service]]></category>
		<category><![CDATA[trend micro]]></category>
		<category><![CDATA[tweetdeck]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[vmsafe]]></category>
		<category><![CDATA[vswitches]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=266</guid>
		<description><![CDATA[As the second installment of our SPoT series, The Network View turns our attention to another Canadian Security Pro, Justin Foster (@justin_foster). Mr. Foster is employed by Trend Micro during working hours, and he also maintains his own independent blog, Developing Security. Go check out his Top 10 signs you are a Security Twit post from June 2009 for a quick chuckle. On that note...]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignright" style="width: 240px"><img class="     " title="SPoT: Justin Foster (@justin_foster)" src="https://s3.amazonaws.com/twitter_production/profile_images/222257811/profile_small.jpg" alt="SPoT: Justin Foster (@justin_foster)" width="230" height="230" /><p class="wp-caption-text">SPoT: Justin Foster (@justin_foster)</p></div>
<p>As the second installment of our SPoT series, The Network View turns our attention to another Canadian Security Pro, Justin Foster (<a title="Twitter: Justin Foster" href="http://twitter.com/justin_foster" target="_blank">@justin_foster</a>). Mr. Foster is employed by <a title="TrendMicro" href="http://us.trendmicro.com/us/home/" target="_blank">Trend Micro</a> during working hours, and he also maintains his own independent blog, <a title="Developing Security Blog" href="http://www.developingsecurity.com/" target="_blank">Developing Security</a>. Go check out his <a title="Developing Security: Top 10 signs you are a Security Twit" href="http://www.developingsecurity.com/weblog/2009/06/top-10-signs-you-are-a-security-twit.html" target="_blank">Top 10 signs you are a Security Twit</a> post from June 2009 for a quick chuckle. On that note&#8230;</p>
<p><strong>Real Name: </strong>Justin Foster<br />
<strong>Twitter Handle: </strong><a title="Twitter: Justin Foster" href="http://twitter.com/justin_foster" target="_blank">@justin_foster</a><br />
<strong>Top 3 Social Media/Networking Sites:</strong><br />
<a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> / <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn</a> / <a title="Security Bloggers Network" href="http://www.securitybloggers.net/" target="_blank">Security Bloggers Network</a></p>
<p><strong><em>1. In which area(s) of security are you most involved?</em></strong><br />
I&#8217;m an Architect for <a title="TrendMicro" href="http://us.trendmicro.com/us/home/" target="_blank">Trend Micro</a> focusing on <a title="IDS vs. IPS Explained" href="http://www.networksecurityjournal.com/features/ids-vs-ips-052907/" target="_blank">IDS/IPS</a>, <a title="Wikipedia: Firewall" href="http://en.wikipedia.org/wiki/Firewall" target="_blank">Firewall</a>, <a title="Network Integrity Monitoring" href="http://www.dailyblogtips.com/sucuri-guest-post/" target="_blank">Integrity Monitoring</a>, and <a title="Developing Security: Log Inspection" href="http://www.developingsecurity.com/weblog/log-inspection/" target="_blank">Log Inspection</a>. At work, I generally concentrate on network and endpoint security management. Personally, I&#8217;m interested in a wide spectrum of information security disciplines.</p>
<p><strong><em>2. What security topics will be the most important in the next 18 months? Why?</em></strong><br />
Over the next 18 months, we will see the promises made in virtualized security become reality. Third party vSwitches and VMsafe-based appliances have the potential to dramatically change how compensating controls are deployed and what security vendors will be capable of. I also believe <a title="Security as a Service" href="http://en.wikipedia.org/wiki/Security_as_a_service" target="_blank">Security as a Service</a> will introduce new products and product architectures.</p>
<p><strong><em>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</em></strong><br />
I think perimeter security is becoming increasingly irrelevant. We all know the perimeter is porous and the demands of mobile and Cloud computing require security applied much closer to the endpoint. What we sometimes fail to understand is how important it is to take advantage of that proximity and tailor the security policy to each individual endpoint.</p>
<p><strong><em>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</em></strong><br />
I initially joined <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> to keep pace with the news from the security community, but I quickly found it has so many uses. With Twitter I have had engaging open-ended debates, aided my research efforts, discovered new topics I wouldn&#8217;t have even known to look for, and found a wealth of security blogs to read. I use ongoing searches in <a title="TweetDeck" href="http://tweetdeck.com/beta/" target="_blank">TweetDeck</a> to stay tuned to specific security and development topics; a technique that has paid off by saving me substantial time more than once.</p>
<p><strong><em>5. Name one security peer whom everyone with an interest in Network Security should follow. (OK to name 2 if you can’t decide on only one)</em></strong><br />
Two people I would highly recommend are @<a title="Twitter: Andrew Hay" href="http://twitter.com/andrewsmhay" target="_blank">andrewsmhay</a> and @<a title="Twitter: FalconsView" href="http://twitter.com/falconsview" target="_blank">falconsview</a>. Both live and breathe security and can always be counted on for a considered opinion or lively debate. Each is a prolific blogger and author, and it doesn&#8217;t hurt that they are both good people in real life as well.</p>
<p><strong><em>6. What’s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</em></strong><br />
Fundamentally, securing a highly interactive web application like <a title="Facebook" href="http://www.facebook.com" target="_blank">Facebook</a> or <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> is extremely challenging. While we have seen significant exploitation of weaknesses in these applications, the fact that they are centrally deployed has resulted in extremely rapid remediation of the issues (sometimes within hours). Compare that to traditional software, and the benefits and drawbacks tend to balance out. When it comes to leakage of personal information, we all have to remember that anything we put into the Cloud is ultimately out of our control.</p>
<p><em><strong>7. What are the top 3 real-world (i.e. live) events you’d recommend for networking with security professionals?</strong></em><br />
For sure <a title="RSA Conference" href="https://365.rsaconference.com/index.jspa" target="_blank">RSA</a> and <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">BlackHat</a>/<a title="Defcon" href="http://www.defcon.org/" target="_blank">DEFCON</a> top the list, but it&#8217;s important to network with other security-minded people in your local community as well. <a title="Twitter" href="http://twitter.com" target="_blank">Twitter</a> is a great tool to carry on the conversation long after the convention or meeting has passed.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): Justin Foster/@justin_foster";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/07/28/security-pros-on-twitter-spot-justin-fosterjustin_foster/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F28%2Fsecurity-pros-on-twitter-spot-justin-fosterjustin_foster%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+Justin+Foster%2F%40justin_foster"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/07/28/security-pros-on-twitter-spot-justin-fosterjustin_foster/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Pros on Twitter (SPoT): James Arlen/@myrcurial</title>
		<link>http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/</link>
		<comments>http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 16:39:59 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[#FollowFriday]]></category>
		<category><![CDATA[Blackhat]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Defcon]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Hotmail]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[James Arlen]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[LiquidMatrix]]></category>
		<category><![CDATA[myrcurial]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[SourceBoston]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=253</guid>
		<description><![CDATA[Beginning this week, we are kicking off our new SPOT (Security Pros on Twitter) series, profiling security professionals who are present and active on Twitter. We will profile one SP each week through the rest of the summer.

Since Anue Systems  (@AnueSystems) first joined in on the Twitter fun, we have followed and interacted with a variety of folks, and these are the thought leaders who we'd turn to first with a specific, hands-on question regarding security of the internal network, the cloud, or even virtualized environments.

Without further ado, let's get to it...]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignright" style="width: 240px"><img class="   " title="James Arlen (@myrcurial)" src="http://www.anuesystems.com/blog/Myrcurial.jpg" alt="SPot: James Arlen/@myrcurial" width="230" height="286" /><p class="wp-caption-text">SPoT: James Arlen (@myrcurial)</p></div>
<p>Beginning this week, we are kicking off our new SPoT (Security Pros on <a title="Twitter" href="http://twitter.com" target="_blank">Twitter</a>) series, profiling security professionals who are present and active on Twitter. We will profile one SP each week through the rest of the summer.</p>
<p>Since Anue Systems  (<a title="Anue Systems Twitter Profile" href="http://twitter.com/AnueSystems" target="_blank">@AnueSystems</a>) first joined in on the Twitter fun, we have followed and interacted with a variety of folks, and these are the thought leaders who we&#8217;d turn to first with a specific, hands-on question regarding security of the internal network, the cloud, or even virtualized environments.</p>
<p>Without further ado, let&#8217;s get to it&#8230;</p>
<p><strong>Real Name: </strong>James Arlen<br />
<strong>Twitter Handle: </strong><a title="myrcurial Twitter Profile" href="http://twitter.com/myrcurial" target="_blank">@myrcurial</a><br />
<strong>Top 3 Social Media/Networking Sites: </strong><br />
<a title="Twitter" href="http://twitter.com" target="_blank">Twitter </a>/ <a title="LinkedIn" href="http://www.linkedin.com/" target="_blank">LinkedIn </a>/ <a title="LiquidMatrix Security Digest" href="http://www.liquidmatrix.org/" target="_blank">Liquidmatrix Security Digest</a>!</p>
<p><em><strong>1. In which area(s) of security are you most involved?</strong></em><br />
I used to be technical/tactical &#8211; IT Security. These days, I&#8217;m spending most of my time working on Organizational Security and Risk Management.</p>
<p><em><strong>2. What security topics will be the most important in the next 18 months? Why?</strong></em><br />
Of key importance (of course) is going to be the increasingly porous &#8220;perimeter&#8221; which will surpass database flaws as the primary source of data breaches. Unfortunately, the vendors are not on our side and are not going to help solve the problem. It needs to be fixed at the employee/user level through increased awareness of the problem and active cooperation on solutions.</p>
<p><em><strong>3. Biggest Pet Peeve: Name one thing about Network Security that you wish business stakeholders would understand and why.</strong></em><br />
The thing that is the hardest to explain is that the presence of a firewall isn&#8217;t going to save you (the business user) from your own foolish actions &#8211; the best preventative technological controls available can be bypassed by (a) 14 year old kids and (b) users doing what they feel is the best thing at the time. <em>[Once more for effect</em>] A firewall won&#8217;t save you from sending your customer list to 100 sales people and 1 ex-sales person&#8217;s Hotmail account.</p>
<p><em><strong>4. Tell us why you became so active on Twitter and any other important social media outlets. What value are you getting?</strong></em><br />
The primary reason that I became active on Twitter is to have access to a peer group. The Canadian security space is fairly compact, and sometimes, having an international opinion is a great thing. And of course, [I'm there for] the fooling about and goofing off &#8211; Twitter is an outlet for stress as much as it is an inlet for knowledge.</p>
<p><em><strong>5. Name one security peer whom everyone with an interest in Network Security should follow. (OK to name 2 if you can&#8217;t decide on only one)</strong></em><br />
Wow &#8211; it&#8217;s <a title="#FollowFriday search on Twitter" href="http://search.twitter.com/search?q=%23FollowFriday" target="_blank">#FollowFriday</a>! If you&#8217;re focused on Network Security, you should really be following <a title="Jack Daniel Twitter Profile" href="http://twitter.com/jack_daniel" target="_blank">@jack_daniel</a> and <a title="Jennifer J. Twitter Profile" href="http://twitter.com/jjx" target="_blank">@jjx</a>. He&#8217;s a curmudgeon who generally cuts to the core of the issue FAST. She&#8217;s about as unlikely a security expert as you can imagine &#8211; short, blonde, southern accent &#8211; but if you&#8217;re mature enough to value people for their skill rather than the package, she&#8217;ll teach you a thing or two that you never expected. <em>[The Network View has engaged with both of these security experts for inclusion in SPoT series as well.]</em></p>
<p><em><strong>6. What&#8217;s your take on security for social media and cloud services in general? Top concerns, overstated issues, etc.</strong></em><br />
Security &#8211; for social media? I&#8217;m pretty sure there isn&#8217;t much of that. My simplest response is that you shouldn&#8217;t depend on social media to provide you with any security &#8211; if you&#8217;re not comfortable putting it on a postcard or wearing it on a t-shirt, you shouldn&#8217;t be posting it to a social media site. With regard to cloud security &#8211; ask <a title="Beaker Twitter Profile" href="http://twitter.com/beaker" target="_blank">@Beaker</a>, I get all of my opinions from him.</p>
<p><strong><em>7. What are the top 3 real-world (i.e. live) events you&#8217;d recommend for networking with security professionals?</em></strong><br />
The number one thing is to remember that for any event &#8211; from a local SIG all the way up to <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">Blackhat </a>or <a title="RSA Conference" href="https://365.rsaconference.com/index.jspa" target="_blank">RSA </a>- the most important thing to do is cruise the &#8220;Hallway Track&#8221;, get involved in conversations, and have an opinion. If you were coming to me and asking me where to spend your money &#8211; considering value for dollar &#8211; <a title="Defcon" href="http://www.defcon.org/" target="_blank">DEFCON</a>, <a title="Shmoocon" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a>/<a title="Source Conference" href="http://www.sourceconference.com/" target="_blank">SourceBoston</a>/<a title="SecTor Conference" href="http://www.sector.ca/" target="_blank">SecTor</a>, and your local SIG. The big names (<a title="RSA Conference" href="https://365.rsaconference.com/index.jspa" target="_blank">RSA</a> and <a title="Blackhat" href="http://www.blackhat.com/" target="_blank">Blackhat</a>) are awesome, but unless someone is covering the tab, they&#8217;re crazy expensive and you can get the same content at the second tier conferences for less money with better access to the speakers.</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Security Pros on Twitter (SPoT): James Arlen/@myrcurial";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;t=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;T=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F07%2F21%2Fsecurity-pros-on-twitter-spot-james-arlenmyrcurial%2F&amp;title=Security+Pros+on+Twitter+%28SPoT%29%3A+James+Arlen%2F%40myrcurial"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/07/21/security-pros-on-twitter-spot-james-arlenmyrcurial/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monitoring Resources: SecurityFocus</title>
		<link>http://www.anuesystems.com/blog/2009/04/02/monitoring-resources-securityfocus/</link>
		<comments>http://www.anuesystems.com/blog/2009/04/02/monitoring-resources-securityfocus/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 21:11:11 +0000</pubDate>
		<dc:creator>Tommy P. Landry</dc:creator>
				<category><![CDATA[Anue Systems]]></category>
		<category><![CDATA[Monitoring Optimization]]></category>
		<category><![CDATA[Network Monitoring]]></category>
		<category><![CDATA[Networking Protocols]]></category>
		<category><![CDATA[Tool Aggregation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[beta]]></category>
		<category><![CDATA[bugtraq]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[infocus]]></category>
		<category><![CDATA[jobs]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[pen-test]]></category>
		<category><![CDATA[security focus]]></category>
		<category><![CDATA[securityfocus]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.anuesystems.com/blog/?p=127</guid>
		<description><![CDATA[Now that we've taken a brief aside to share some application performance related blogs, let's turn our attention back to Security. Today we offer another intriguing Security-centric resource: SecurityFocus]]></description>
			<content:encoded><![CDATA[<p><em><br />
NOTE: The Network View is offering a series of reviews on network visibility-related resources and blogs available online. If you have a URL which we should consider reviewing, please send to tlandry (at) anuesystems (dot) com.</em></p>
<p>Now that we&#8217;ve taken a brief aside to share some application performance related blogs, let&#8217;s turn our attention back to Security. Today we offer another intriguing Security-centric resource:</p>
<p style="text-align: center;">
<p style="text-align: center;"><a title="SecurityFocus" href="http://www.securityfocus.com/" target="_blank">SecurityFocus</a></p>
<p style="text-align: center;">
<p><a title="SecurityFocus" href="http://www.securityfocus.com/" target="_blank"></p>
<div class="wp-caption alignleft" style="width: 267px"><a href="http://www.securityfocus.com/"><img title="SecurityFocus Screenshot" src="http://www.anuesystems.com/blog/SecurityFocusScreenshot%2C4-2-09.JPG" alt="SecurityFocus: Nice Community for Security Professionals" width="257" height="257" /></a><p class="wp-caption-text">SecurityFocus: Nice Community for Security Professionals</p></div>
<p>SecurityFocus</a> wants to be a &#8220;one stop shop&#8221;, so to say, for everything security. While that is a tall order to take on, the site does provide a wealth of topics and resources that security-focused professionals will find worth of their time. In fact, the site dubs itself &#8220;The Largest Community of Security Professionals Available Anywhere&#8221;. And that&#8217;s hard to argue with, considering their monthly page view counts in excess of 18 million, and their 2.5 million unique visitors per annum. It doesn&#8217;t hurt that all of this is provided completely free of charge.</p>
<p>Since 2002, <a title="SecurityFocus" href="http://www.securityfocus.com/" target="_blank">SecurityFocus </a>has been under ownership by <a title="Symantec Corporation" href="http://www.symantec.com/index.jsp" target="_blank">Symantec Corporation</a>, but this website is in no way biased toward Symantec&#8217;s products or secretly pushing their objectives. The <a title="SecurityFocus: About Us" href="http://www.securityfocus.com/about" target="_blank">About Us</a> page stresses repeatedly that their goal is to remain vendor neutral, and the site has retained full unfettered editorial autonomy even after the acquisition seven years ago.</p>
<p>They classify all of the written materials as &#8220;InFocus&#8221;, which is a suitable sub-brand for a site of its name. In addition to being able to sort by <a title="SecurityFocus: Columnists" href="http://www.securityfocus.com/columnists" target="_blank">Columnists </a>to review materials, InFocus topic areas include:</p>
<ul>
<li><a title="SecurityFocus: Foundations" href="http://www.securityfocus.com/foundations" target="_blank">Foundations</a></li>
<li><a title="SecurityFocus: Microsoft" href="http://www.securityfocus.com/microsoft" target="_blank">Microsoft</a></li>
<li><a title="SecurityFocus: Unix" href="http://www.securityfocus.com/unix" target="_blank">Unix</a></li>
<li><a title="SecurityFocus: IDS" href="http://www.securityfocus.com/ids" target="_blank">IDS</a></li>
<li><a title="SecurityFocus: Incidents" href="http://www.securityfocus.com/incidents" target="_blank">Incidents</a></li>
<li><a title="SecurityFocus: Virus" href="http://www.securityfocus.com/virus" target="_blank">Virus</a></li>
<li><a title="SecurityFocus: Pen-Test" href="http://www.securityfocus.com/pen-test" target="_blank">Pen-Test</a></li>
<li><a title="SecurityFocus: Firewalls" href="http://www.securityfocus.com/firewalls" target="_blank">Firewalls</a></li>
</ul>
<p>But the site is not just for content. In addition to the above InFocus materials, you can find the following on SecurityFocus:</p>
<ul>
<li><a title="SecurityFocus: BugTraq" href="http://www.securityfocus.com/archive/1" target="_blank">BugTraq Database</a>: not searchable, but very in-depth</li>
<li><a title="SecurityFocus: Vulnerabilities" href="http://www.securityfocus.com/vulnerabilities" target="_blank">Vulnerabilities Database</a>:  searchable by Vendor/Version or CVE</li>
<li><a title="SecurityFocus: Mailing Lists" href="http://www.securityfocus.com/archive" target="_blank">Mailing Lists:</a> on nearly any topic you can conjure up in this area</li>
<li><a title="SecurityFocus: Jobs" href="http://www.securityfocus.com/jobs" target="_blank">Jobs Database</a>: for both applicants and employers (requires login)</li>
<li><a title="SecurityFocus: Tools" href="http://www.securityfocus.com/tools" target="_blank">Tools Database</a>: listing available tools and what to expect from those tools</li>
<li><a title="SecurityFocus: Beta" href="http://www.securityfocus.com/beta" target="_blank">Beta Program:</a> where companies can get vendor-neutral feedback on early releases from the security community</li>
</ul>
<p>Another great feature of the site is that they accept submissions for new contributed articles. Anyone with security expertise can apply, so if you have something to say, why not throw your name in the hat? If you would like to make a submission, please do so as instructed below (excerpt from the site):</p>
<blockquote><p><em>Submissions should include a short summary along with the author&#8217;s name, email address and contact information. All submissions should be in MS Word format and should be sent to: editor@securityfocus.com.</em></p></blockquote>
<p>All-in-all, <a title="SecurityFocus" href="http://www.securityfocus.com/" target="_blank">SecurityFocus </a>does a great job of encouraging and incentivizing community activities for the betterment of all participants. The more I dug into the site, the more impressed I was with the resources they offer therein. This is one resource that security professionals should check out, bookmark, and frequent in the coming months.</p>
<p>Come back once you review the site and let us know what you think in the comments section. And if you know of another resource that is deserving of our attention, please feel free to reach out to us directly. Enjoy!</p>
<p class="bookmark-me">
    <script type="text/javascript">
	    yahooBuzzArticleHeadline = "Monitoring Resources: SecurityFocus";
	    yahooBuzzArticleId = "http://www.anuesystems.com/blog/2009/04/02/monitoring-resources-securityfocus/";
    </script>
    <script type="text/javascript"
        src="http://d.yimg.com/ds/badge2.js"
        badgetype="logo">
    </script>    
    <a title="technorati.com" href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/technorati.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="del.icio.us" href="http://del.icio.us/post?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/delicious.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="stumbleupon.com" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/stumbleupon.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="digg.com" href="http://digg.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/digg.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.facebook.com" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;t=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/facebook.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="bookmarks.yahoo.com" href="http://bookmarks.yahoo.com/toolbar/savebm?opener=tb&amp;u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoo.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="www.google.com" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/google.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="furl.com" href="http://www.furl.net/storeIt.jsp?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;t=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/furl.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="reddit.com" href="http://reddit.com/submit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/reddit.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="propeller.com" href="http://www.propeller.com/submit/?U=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;T=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/propeller.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="windowslive.com" href="https://favorites.live.com/quickadd.aspx?mkt=en-us&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/windowslive.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="myweb2.search.yahoo.com" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/yahoomyweb.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="linkedin.com" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/linkedin.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> <a title="twitthis.com" href="http://twitthis.com/twit?url=http%3A%2F%2Fwww.anuesystems.com%2Fblog%2F2009%2F04%2F02%2Fmonitoring-resources-securityfocus%2F&amp;title=Monitoring+Resources%3A+SecurityFocus"><img src="http://www.anuesystems.com/blog/wp-content/plugins/bookmark-me/images/twitter.png" style="margin:0;border:0;padding:0" alt="bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.anuesystems.com/blog/2009/04/02/monitoring-resources-securityfocus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
