<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.coretraceblogs.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>WhiteSpace</title>
	
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Mon, 08 Mar 2010 23:20:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.coretraceblogs.com/whitespace_blog" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="whitespace_blog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">whitespace_blog</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://feeds.coretraceblogs.com/whitespace_blog" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.plusmo.com/add?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://plusmo.com/res/graphics/fbplusmo.gif">Subscribe with Plusmo</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.thefreedictionary.com/_/hp/AddRSS.aspx?http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://img.tfd.com/hp/addToTheFreeDictionary.gif">Subscribe with The Free Dictionary</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bitty.com/manual/?contenttype=rssfeed&amp;contentvalue=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.bitty.com/img/bittychicklet_91x17.gif">Subscribe with Bitty Browser</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsalloy.com/?rss=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.live.com/?add=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://mix.excite.eu/add?feedurl=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://image.excite.co.uk/mix/addtomix.gif">Subscribe with Excite MIX</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://download.attensa.com/app/get_attensa.html?feedurl=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.attensa.com/blogs/attensa/WindowsLiveWriter/BadgeredintoBadges_10C02/attensa_feed_button5.gif">Subscribe with Attensa for Outlook</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.webwag.com/wwgthis.php?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.webwag.com/images/wwgthis.gif">Subscribe with Webwag</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.podcastready.com/oneclick_bookmark.php?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.podcastready.com/images/podcastready_button.gif">Subscribe with Podcast Ready</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.flurry.com/pushRssFeed.do?r=fb&amp;url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.flurry.com/images/flurry_rss_logo2.gif">Subscribe with Flurry</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.wikio.com/subscribe?url=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.wikio.com/shared/img/add2wikio.gif">Subscribe with Wikio</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.dailyrotation.com/index.php?feed=http%3A%2F%2Ffeeds.coretraceblogs.com%2Fwhitespace_blog" src="http://www.dailyrotation.com/rss-dr2.gif">Subscribe with Daily Rotation</feedburner:feedFlare><item>
		<title>New exploit technique could mean more Microsoft headaches</title>
		<link>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/</link>
		<comments>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 18:42:02 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[data compromise]]></category>
		<category><![CDATA[exploit technique]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security enhancement]]></category>
		<category><![CDATA[security software]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1337</guid>
		<description><![CDATA[Last week, a new exploit technique was disclosed that bypasses a critical Windows security feature, DEP (data execution prevention), as well as an ASLR security enhancement for address space layout randomization.
In the article, &#8220;New exploit technique nullifies major Windows defense,&#8221; some researchers worry that a proof-of-concept code published by Google security software engineer, Berend-Jan Wever, [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, a new exploit technique was disclosed that bypasses a critical Windows security feature, <a href="http://en.wikipedia.org/wiki/Data_Execution_Prevention" target="_blank">DEP</a> (data execution prevention), as well as an ASLR security enhancement for address space layout randomization.</p>
<p>In the article, <a href="http://www.computerworld.com/s/article/9165378/New_exploit_technique_nullifies_major_Windows_defense?taxonomyId=17&#038;pageNumber=2" target="_blank">&#8220;New exploit technique nullifies major Windows defense,&#8221;</a> some researchers worry that a proof-of-concept code published by Google security software engineer, Berend-Jan Wever, could actually lead to more successful attacks against Microsoft&#8217;s newer operating systems.</p>
<p>While Wever claims the proof-of-concept doesn&#8217;t do any harm because it&#8217;s wrapped around an exploit of a bug in Internet Explorer 6 (IE6) that was patched years ago, MicroTrend&#8217;s Ria Rivera wrote in the company&#8217;s malware blog that the exposure could be used to further enhance exploits, and expects to see it used within exploits soon.</p>
<blockquote>
<p>&#8220;After Wever released his <a href="http://en.wikipedia.org/wiki/Heap_spraying" target="_blank">heap-spraying</a> exploit codes in 2005, a lot of new exploits started using that technique. It would thus be not far-fetched that the release of this new proof-of-concept could lead to the same scenario &#8212; new exploits could start using &#8216;return-to-libc&#8217; to achieve DEP bypass.&#8221;</p>
</blockquote>
<p>With so many data compromises arising from the latest disclosed vulnerability it seems so clear that now is the time to completely re-evaluate the way we approach desktop security. Vulnerabilities lose their power when you address the core issue of controlling what applications are allowed to run on your system in the first place whether these applications were added by a user or by malicious code exploiting a security hole.</p>
<div class="feedflare">
<a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=NE3AIAORsxU:LKL-dfZcZ0c:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=NE3AIAORsxU:LKL-dfZcZ0c:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?i=NE3AIAORsxU:LKL-dfZcZ0c:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=NE3AIAORsxU:LKL-dfZcZ0c:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/whitespace_blog/~4/NE3AIAORsxU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/new-exploit-technique-could-mean-more-microsoft-headaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Observations from RSA – 100% compliant does not mean 100% secure</title>
		<link>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/</link>
		<comments>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 21:08:58 +0000</pubDate>
		<dc:creator>Dan Teal</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[security compliance]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1334</guid>
		<description><![CDATA[Yesterday, I sat in the RSA panel titled, &#8220;Cyber Security: An Arms Race.&#8221; It was an interesting panel because, of course, cyber security is an arms race. One of the recurring comments from the audience was centered around, &#8220;Who should be responsible for defending our networks?&#8221; This is a question that has been debated for [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I sat in the RSA panel titled, &#8220;Cyber Security: An Arms Race.&#8221; It was an interesting panel because, of course, cyber security is an arms race. One of the recurring comments from the audience was centered around, &#8220;Who should be responsible for defending our networks?&#8221; This is a question that has been debated for some time now. The answer kept leading back to government and compliance. However, members of the audience did not realize that one of the fundamental axioms of computer security is: Compliance does not mean secure.</p>
<p>We are familiar with the above statement. We all know that security compliance may increase security, but not completely provide it. A great example of this occurred in the fall of 2008 within the DOD. Systems running in the DOD networks were compliant with FIPS 140-2, common criteria, and other standards. The systems and networks were operated by a staff of trained professionals. But even with all of the compliant security measures in place, Conficker still propagated throughout the DOD networks causing over $100 million in cleanup costs.</p>
<p>A similar problem occurred at Heartland Payment Systems. Even though Heartland was fully PCI compliant, hackers still stole information on the 100 million credit card transactions that are processed each month.</p>
<p>Compliance is important, but we must remember that compliance standards may take years to create and are never updated fast enough to stay current with today&#8217;s threats. Organizations must protect against the threats of the past by being compliant. They must also defend against the threats of today by being proactive.  Application whitelisting is the proactive solution against today&#8217;s threats and must become the cornerstone of any security strategy.</p>
<div class="feedflare">
<a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=0hi9IHrrCX0:Jt1ysy114Rg:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=0hi9IHrrCX0:Jt1ysy114Rg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?i=0hi9IHrrCX0:Jt1ysy114Rg:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=0hi9IHrrCX0:Jt1ysy114Rg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/whitespace_blog/~4/0hi9IHrrCX0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/observations-from-rsa-100-compliant-does-not-mean-100-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top endpoint security stories for February 2010 – Security professionals don’t feel the love</title>
		<link>http://www.coretraceblogs.com/2010-02/top-endpoint-security-stories-for-february-2010-security-professionals-don%e2%80%99t-feel-the-love/</link>
		<comments>http://www.coretraceblogs.com/2010-02/top-endpoint-security-stories-for-february-2010-security-professionals-don%e2%80%99t-feel-the-love/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 17:43:27 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[endpoint protection]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1323</guid>
		<description><![CDATA[In a month known for love, February was filled with more heartbreaking stories of security problems and problematic fire drill patching. Is it me, or does it seem like everybody&#8217;s experiencing security compromises stemming from patching flaws and vulnerabilities within their system? Instead of resulting in more secure networks, what these and other recent stories [...]]]></description>
			<content:encoded><![CDATA[<p class="margin_bottom_2em">In a month known for love, February was filled with more heartbreaking stories of security problems and problematic fire drill patching. Is it me, or does it seem like everybody&#8217;s experiencing security compromises stemming from patching flaws and vulnerabilities within their system? Instead of resulting in more secure networks, what these and other recent stories point out is that malware only highlights the fact that existing desktop security isn’t working properly. Check out some of the top stories from February 2010.</p>
<h3>Security patches cripple Windows XP computers</h3>
<p>Windows customers were up in arms over a <a href="http://www.computerworld.com/s/article/9155419/Windows_patch_cripples_XP_with_blue_screen_users_claim" target="_blank">Microsoft security patch that left their PCs locked down</a> with the notorious Blue Screen of Death.  This was yet another glaring example of the problems organizations experience when rolling out patches quickly.<span id="more-1323"></span></p>
<p>In a follow-up article to Microsoft&#8217;s patching problems, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1381423,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">evidence suggested that a rootkit infection was behind problems</a> Windows users experienced after installing several security updates. According to the computer expert who discovered the infection:</p>
<blockquote class="margin_bottom_2em">
<p>&#8220;This particular rootkit can be very difficult to detect. Atapi.sys is an important driver for all Windows systems and it loads very early during the boot process, so infecting this file can make it very hard to detect or remove the rootkit before it loads.&#8221;</p>
</blockquote>
<h3>Zeus Trojan found on 74,000 PCs in global botnet</h3>
<p>It was reported that over <a href="http://news.cnet.com/8301-27080_3-10455525-245.html" target="_blank">74,000 computers at nearly 2,500 organizations around the world were compromised over the past year and a half</a> in a botnet infestation designed to steal login credentials to bank sites, social networks and email systems. While Operation Aurora had its own success with popular networks internationally, the number of corporate and government systems infected paled in comparison to the Zeus Trojan.</p>
<p>The Wall Street Journal reported that Merck, Cardinal Health, Paramount Pictures and Juniper Networks were among the targets in the attack.</p>
<p class="margin_bottom_2em">To make matters worse, a <a href="http://www.theregister.co.uk/2010/02/09/spyeye_bots_vs_zeus/" target="_blank">competing crimeware toolkit called SpyEye is waging a turf war against the mighty Zeus bot</a>. For $500, aspiring rival cybercriminals can use the tool to uninstall Zeus from an infected system and keep SpyEye running on the system to steal credit cards and email accounts. Talk about cyber gang warfare.</p>
<h3>Malicious PDF files comprised 80% of all exploits in 2009</h3>
<p class="margin_bottom_2em">In the often-seen case where hackers gravitate to the most popular Internet applications, it was reported that <a href="http://blogs.zdnet.com/security/?p=5473&#038;tag=col1;post-5473" target="_blank">rogue PDFs accounted for 80% of all exploits by the end of 2009</a>.  And much like other leading technology companies, Adobe continues to patch several critical vulnerabilities in Adobe Reader and Adobe Acrobat for Windows, Mac and Linux.</p>
<h3>Google teams up with NSA to fight cybercrime</h3>
<p>As a result of Operation Aurora, The Washington Post reported that <a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/03/AR2010020304057.html" target="_blank">Google has teamed up with the National Security Agency</a> (NSA) to help the Internet research firm defend itself and its users from future attacks. The Director of National Intelligence call the Google attacks a &#8220;wake-up call,&#8221; and that cyberspace cannot be protected without a &#8220;collaborative effort that incorporates both the U.S. private sector and our international partners.&#8221;</p>
<p>Unfortunately, what we are continuing to see in early 2010 is that patching and other traditional antivirus software are failing to adequately defend our systems. In fact, if anything they appear to be causing more problems. Organizations are better off focusing on ways to effectively stop Web-malware and malicious code from executing in the first place.  This is where a solution such as application whitelisting can defend even flawed networks from running malware within their operation systems. If it’s not an authorized application, it does not run in the system. It&#8217;s that simple.</p>
<p>As always, I thank you for stopping by to read this blog. I hope it continues to bring to light some of the important issues we all face as security professionals. Come back soon.</p>
<div class="feedflare">
<a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=AhlsMPOSAyk:LylB0HRYw1Q:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=AhlsMPOSAyk:LylB0HRYw1Q:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?i=AhlsMPOSAyk:LylB0HRYw1Q:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=AhlsMPOSAyk:LylB0HRYw1Q:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/whitespace_blog/~4/AhlsMPOSAyk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/top-endpoint-security-stories-for-february-2010-security-professionals-don%e2%80%99t-feel-the-love/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guest Blog By GlobalSCAPE’s COO: Defending Cyberspace…</title>
		<link>http://www.coretraceblogs.com/2010-02/guest-blog-by-globalscapes-coo-defending-cyberspace/</link>
		<comments>http://www.coretraceblogs.com/2010-02/guest-blog-by-globalscapes-coo-defending-cyberspace/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 19:05:30 +0000</pubDate>
		<dc:creator>Craig Robinson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[CoreTrace]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[GlobalSCAPE]]></category>
		<category><![CDATA[proactive]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1307</guid>
		<description><![CDATA[There is no question that cyberspace is a new frontline in traditional and untraditional conflict. Many nations and organizations have the ability, directly and by proxy, to target and attack critical infrastructure within the US and worldwide. The recent cyber attacks launched within China against Google and several other companies raised questions about the state [...]]]></description>
			<content:encoded><![CDATA[<p>There is no question that cyberspace is a new frontline in traditional and untraditional conflict. Many nations and organizations have the ability, directly and by proxy, to target and attack critical infrastructure within the US and worldwide. The recent <a href="http://blog.globalscape.com/2010/01/china-vs-google-the-policy-strategy-and-technology-perspective" target="_blank">cyber attacks launched within China against Google</a> and several other companies raised questions about the state of industry preparedness to help defend cyberspace.</p>
<p>The US government relies on commercial industry to safeguard the Internet, telecommunications, power, water, and other critical infrastructure that underpin our national economy. Elements of this infrastructure also directly support our ability to project military power worldwide.<span id="more-1307"></span></p>
<p>Industry works closely with the government to advance the ‘state of the possible’ in cyber defense. As a former CIO and military systems analyst, I have witnessed several generational cycles of defensive technology developments in the cyber arena. In the mid-90s, for example, system administrators configured firewalls (from standard computer systems) by hand, and reviewed log files (either manually or through then-clever application of scripts) to detect, characterize, assess, and potentially contain cyber intrusions. Today, automated intrusion prevention systems are available as commercial-off-the-shelf (COTS) products, integrated with firewalls and incident management solutions to allow very rapid detection and blocking of cyber attacks. This is just one example of how industry has worked closely with the government to deliver significant advances in cyber defense technologies.</p>
<p>Unfortunately, our cyber adversaries today have proven relentless and highly flexible in their endless pursuit of effective attacks (for an entertaining perspective on the topic, please read Toney Jenning&#8217;s <a href="http://blog.globalscape.com/2010/02/caddyshack-the-defense-of-cyberspace-no-more-%e2%80%9cwack-a-mole%e2%80%9d/" target="_blank">&#8220;Caddyshack &#038; The Defense of Cyberspace: No More “Wack-a-Mole”&#8221;</a> post on GlobalSCAPE&#8217;s blog site). Those of us in the information security industry understand that the next major terrorist strike very well may come from the cyber domain or, at a minimum, include cyber attacks as part of a broader operation. From a traditional national security perspective, it is a near certainty that future adversaries will continue to develop their cyber attack capabilities. Such asymmetric warfare capabilities are increasingly attractive, given the overwhelming superiority of US forces in conventional, force-on-force combat.</p>
<p>As a result, GlobalSCAPE, our partners and many others in the industry are working tirelessly to deliver next-generation cyber defense capabilities and stay one step ahead of our adversaries. Our continued development in this area is a national imperative. We are excited by the prospects for transformational solutions like application whitelisting to allow more assured defense of the cyber frontier. We’ll be addressing a variety of cyber defense topics in future posts. Stay tuned!</p>
<div class="feedflare">
<a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=IqqCuyBuOEU:A_GgaJ68nU4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=IqqCuyBuOEU:A_GgaJ68nU4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?i=IqqCuyBuOEU:A_GgaJ68nU4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=IqqCuyBuOEU:A_GgaJ68nU4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/whitespace_blog/~4/IqqCuyBuOEU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/guest-blog-by-globalscapes-coo-defending-cyberspace/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Window’s crashes linked to rootkits after problems with latest patch</title>
		<link>http://www.coretraceblogs.com/2010-02/windows-crashes-linked-to-rootkits-after-problems-with-latest-patch/</link>
		<comments>http://www.coretraceblogs.com/2010-02/windows-crashes-linked-to-rootkits-after-problems-with-latest-patch/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 19:03:52 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[patching]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1297</guid>
		<description><![CDATA[Growing evidence suggests that a rootkit infection was *one* of the culprits behind last week&#8217;s Blue Screen of Death incident that caused countless Windows PCs to lock down after installing several Microsoft security patches.  While many follow-up articles have focused on the malware infection that caused the problem, including Robert Westervelt&#8217;s SearchSecurity.com article, &#8220;Windows [...]]]></description>
			<content:encoded><![CDATA[<p>Growing evidence suggests that a rootkit infection was *one* of the culprits behind last week&#8217;s Blue Screen of Death incident that caused countless Windows PCs to lock down after installing several Microsoft security patches.  While many follow-up articles have focused on the malware infection that caused the problem, including Robert Westervelt&#8217;s SearchSecurity.com article, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1381423,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">&#8220;Windows blue screen may be result of rootkit infection,&#8221;</a> from an endpoint security standpoint, most seem to be missing the point. And that point is even though malware may be causing this problem, rushed patching is a process that can always cause problems.<span id="more-1297"></span></p>
<p>As I mentioned in last week&#8217;s entry, <a href="http://www.coretraceblogs.com/2010-02/latest-microsoft-patch-illustrates-the-dilemma-and-dangers-of-fire-drill-patching/" target="_blank">&#8220;Latest Microsoft patch illustrates the dilemma and dangers of fire drill patching,&#8221;</a> relying on antivirus defenses to protect endpoints ties organizations to fire drill software patching. Reactive software application patching will never provide the level of protection today&#8217;s companies need to adequately protect their networks against harmful malware. As Mr. Westervelt goes on to write:</p>
<blockquote>
<p>Rootkits are fairly common. They are installed by attackers who first gain access to the machine by exploiting a vulnerability. Once inside, the rootkit is deployed giving the attacker the ability to mask intrusion and gain root or privileged access to the computer. It can also be a package of spyware programs that monitor traffic and record keystrokes. Antivirus vendors typically have trouble detecting rootkits.</p>
</blockquote>
<p>What these recent stories point out is that malware infections on these devices only highlights the fact that existing desktop security isn&#8217;t working properly. Why else are these companies regularly patching?  The desktop security paradigm of antivirus and patching simply isn&#8217;t working.</p>
<p>Unfortunately, what we&#8217;re seeing is that patching itself is also causing problems with their systems. Organizations are better off focusing on ways to effectively stop Web-malware and malicious code from deploying in the first place than aimlessly reacting to cyber criminals exploiting the known and unknown vulnerabilities within their network.  Playing catch up with more patches is not only a losing proposition for IT security professionals, it seems to be compounding the problem.</p>
<div class="feedflare">
<a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=BtguYKeAMkI:yGpoXS8-TCc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=BtguYKeAMkI:yGpoXS8-TCc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?i=BtguYKeAMkI:yGpoXS8-TCc:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.coretraceblogs.com/~ff/whitespace_blog?a=BtguYKeAMkI:yGpoXS8-TCc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/whitespace_blog?d=yIl2AUoC8zA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/whitespace_blog/~4/BtguYKeAMkI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-02/windows-crashes-linked-to-rootkits-after-problems-with-latest-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
