A very Typical Corporate Network Scenario with the level of access and the threat perceptions. You will notice that as the network expands the threat perception also varies. Green denotes the safe zone and red denotes the most common means of infections entering the network or data leaving the network.
It used to be hacking for glory, Now it is hacking fro money; the next motion picture Ocean 11-12 (13) will be about a bunch of guys working on computers trying to enter a major bank
Govind Rammurthy - Securing The Endpoints In Networks - Interop Mumbai 2009 - Presentation Transcript
Securing the Endpoints in Networks By Govind Rammurthy CEO & Managing Director
Agenda
Business Continuity Demands
Threat Scenario – Past & Present
Endpoints & Endpoint Security
Layers of Endpoint Security
Endpoint Security Best Practices
Business Continuity Demands
Unified Networks for
Email, Text Chat, Web Browsing, File Sharing, Games
Voice, Audio, Video, Tele-presence, Telemedicine
Web Services, EDI, SCADA, Emergency Services
Users To Enjoy Mobility
Any service from any device on any network
Seamless mobility across devices and networks
Strong but easy user authentication
Reliability and Security of Networks.
Business Continuity Demands
Increased Access to Sensitive Information
Mission-critical network
Mobile and remote devices and users
Wide variety of endpoints
Wide variety of users: employees, customers, contractors, guests
Interoperability
File Servers Web or App Servers Email Servers Typical Network Security Scenario Very High High Medium Risks Very Low Low Vendors Mobile PDA Mobile Laptops Home Computer Local Users Desktops
Typical Network Security Scenario Very High High Medium Risks Very Low Low
Business Continuity Vs Security Statistics on Attack Trends that could lead to Data/Identity Theft. 54% 28% 13% 4% 1%
Threat Scenario – Past & Present Threats were indiscriminate, hit everyone Threats are highly targeted, regionalized Threats were disruptive impact visible Threats steal data & damage brands impact unclear Remediation action was technical (“remove”) Remediation more complex, may need to investigate data leak Entry through perimeter and gateway Entry through uneducated network clients and endpoints Threats were noisy & visible to everyone Threats are silent & unnoticed with variants
Endpoints & Endpoint Security
Key Influencers:
Devices and Storage Mediums
Portability of Data
Accessibility
Compliance Laws & Regulations (HIPAA, SOX, etc.)
Extranet/Intranet Access provided to employees & partners.
Network Downtime due to infections
Endpoints & Endpoint Security
Loss/leak of confidential information
Losing valuable employees
Unknown/invisible threats and loss of productivity due to using non-complaint storage mediums
Unauthorized intrusions – via Web Servers, email Servers, etc.
Access to internal networks via individual end points
Loss of Productivity due to Infections
Endpoints & Endpoint Security
IPODs / Portable Entertainment devices
Bluetooth Cell Phones
Wireless LAN
USB Devices
Open Non-authenticated Mail/Proxy Servers
Lack of defined employee security policies
Authorized Applications
Endpoints & Endpoint Security
Data in Motion
Emails
Instant Messaging
P2P
File Transfers
Web Posts
Blogs
Data at Rest
Laptops/Desktops/File Servers
USB
Key Data to be Protected Endpoint Security Is Mission Critical
A few years back, endpoint security entailed the in more
A few years back, endpoint security entailed the installation of antivirus software to prevent virus infections. Now it encompasses anti-spyware, personal firewall, application control, USB control, etc, to protect the access and movement of confidential information. less
0 comments
Post a comment