Update: Online encyclopedia lists internal network security threats
Promisec includes popular Web-based applications among possible data-loss threats
A free online encyclopedia of internal network security issues was released Tuesday by network security provider Promisec, which includes popular Web-based applications among possible data-loss threats.
Internal threats may come from various sources such as usage of USB (Universal Serial Bus) memory sticks, programs like Skype, unwanted file types, and any services or applications that are not permissible or aren't covered by registered software licenses, according to Promisec, based in Rishon Letziyon, Israel.
[ Learn how to secure your systems with Roger Grimes' Security Adviser blog and newsletter, both from InfoWorld. ]
Promisec hopes that the encyclopedia -- which lists and dates dozens of potential threats and ranks them on a five-part scale, ranging from "extremely critical" to "not critical" -- will help promote its marketing and sales efforts.
The newest applications that may pose threats -- such as EnterMyPC, Kismet and Wireshark -- are included and described with information on the manufacturer, systems affected, relevant links and date added. In addition, the site contains monthly charts showing how internal network risk trends have changed in the past year, an internal security tips and tricks section, articles on recent internal security incidents, an overview of internal threats, and other resources.
Today, the top five threats listed by the encyclopedia are MySpace, Skype, Tencent QQ, PacketTrap and Google Talk.
However, PacketTrap Networks has challenged Promisec over its inclusion on the list. The vulnerability in its pt360 software that the online encyclopedia lists was discovered by San Antonio network security auditing firm Digital Defense earlier this year. A patch was issued in February, according to the San Francisco maker of network monitoring tools.
Given that PacketTrap has registered about 80,000 downloads, by its count, since releasing the software, its vice president of marketing and corporate development, Anna Yen, said in an e-mail message that she considered it odd that her company could be considered a "top five" threat along with MySpace, Skype and Google. She added that only 106 users downloaded the version of the software that included the vulnerability.
The encyclopedia is part of the Promisec Risk Center, a resource for statistics highlighting significant internal network threats.
"This tool helps us make sense of internal threats and actually beg companies to draw comprehensive policies and action plans to deal with these threats," said Amir Kotler, Promisec CEO. "It is set to include thousands of terms and enable IT professionals to post feedback and comments."
Promisec's network security software aims to detect and eliminate internal threats, without using ActiveX or any other type of dissolvable agent, run-once technology that removes traces of itself. The company estimates that over 80 percent of attacks and corporate abuse originate internally. As an example, Kotler noted last year's data breach in Pfizer, where the data of about 15,700 existing and former employees were compromised when the spouse of an employee downloaded file-sharing software onto a company-issued laptop.
-

- COMMENTS
Technology White Papers
- Solving Downtime Challenges to Manufacturing and Supply Chain Operations - Explore how an information availability solution can unlock the latent potential of your manufacturing and supply chain ...
- IDC Workbook: Assess the Value of Deduplication for your Storage Consolidation Initiatives - Enterprises are caught between the continued growth in the amount of data they create, store, and depend on, and the need...
- Frost & Sullivan Competitive Ranking Report - In this paper, Frost & Sullivan has detailed leading mobile solution deployments, products in development and new product...
- Good Mobile Messaging Product White Paper - Mobile Messaging-a standards-based, wireless messaging application and management system that connects mobile workers to...
- The Enterprise Mobile Messaging Benchmark Report - In this report Aberdeen takes an in-depth look at how best-in-class organizations are using mobile messaging to improve ...
- Choosing the Right CMDB: Smart Considerations for Strategic Decision Makers - Drawing on industry-leading research, this white paper discusses: -The strengths and limitations of CMDBs based on relational...
-
-
- Technology White Papers
- Technology White Papers E-mail Alert
-
TOP STORIES
ADDITIONAL RESOURCES

- Virtual Machines: Sun's xVM Virtualization Portfolio
- Migrating to Vista
- Turning Information Into A Competitive Advantage

- Speeding Business Innovation with Data Center Transformation
- Security and Trust: The Backbone of Doing Business over the Internet
- Forrester Data Center Automation
- World Tech Update, November 21, 2008
-
This week's wrapup of the top tech news stories includes Jerry Yang stepping...
more
- [+] Watch the Video
- World Tech Update, November 14, 2008
-
This week's wrapup of tech news includes CEA's CES preview, MP3 players ...
more
- [+] Watch the Video











