Posts by author:

SteveHanna

In the Information Security field, we’re faced with a constant barrage of bad news: new vulnerabilities, exploits, and successful attacks. When we do our jobs well, there’s no news at all. Just an absence of bad news as systems hum along normally and t…

{ 0 comments }

This week, I’ve been at an IETF meeting in Quebec City, wrapping up the IETF NEA effort (getting NAC standards approved as IETF RFCs). Looking around the IETF, I see many well-intentioned efforts but I know from my 15 years of experience in IETF …

{ 0 comments }

For too long, our security systems have acted like territorial bureaucrats, hoarding the information that they have and refusing to share with each other. An Intrusion Detection System notices odd behavior but only logs it. A Virtual Private Network (V…

{ 0 comments }

Integrated security based on the IF-MAP standard has sparked a lot of excitement in the industry. Learn more about Juniper’s new integrated security products on this video or see them in action at the Juniper booth at the RSA Confer…

{ 0 comments }

The industry is abuzz with talk of cloud computing. Customers are intrigued but concerned about issues like security and availability. Is cloud computing safe enough to use for mission-critical applications? How can it be made safer?

Message…

{ 0 comments }

For those considering deperimeterization, how can this goal be practically achieved? Steve Hanna describes an integrated approach that encompasses endpoint security, network security of various kinds, and server security.

{ 0 comments }

The latest security buzzword is APT: Advanced Persistent Threat. Is APT important and should we be concerned? I’m afraid the answer to both these questions is “yes.” But knowledge is power. If we understand APT, we can learn how to pr…

{ 0 comments }

Q’s Bag of Tricks

by SteveHanna on 8 February 2011

Do you remember Q? He’s the guy who provides all of James Bond’s coolest gadgets. I’m sure that all of us techno-geeks wish we had a Q to fit us out. Or maybe we imagine ourselves as Q, the guy or gal with the coolest, newest tools an…

{ 0 comments }

At the recent IT Security Automation Conference, U.S. Government cybersecurity experts like Howard Schmidt and Tony Sager spoke about the value of security automation and continuous monitoring. What are they talking about and can it be useful in a comm…

{ 0 comments }

Integrated security based on the IF-MAP standard has sparked a lot of excitement in the industry. Learn more about Juniper’s new integrated security products on this video or see them in action at the Juniper booth at the RSA Conference next week. 

 

Message Edited by ac on 04-17-2009 12:29 PM
Message Edited by ac on 08-06-2009 04:10 PM

{ 0 comments }

The industry is abuzz with talk of cloud computing. Customers are intrigued but concerned about issues like security and availability. Is cloud computing safe enough to use for mission-critical applications? How can it be made safer?

Message Edited by ac on 04-20-2009 03:58 PM
Message Edited by ac on 08-06-2009 04:08 PM

{ 0 comments }

Virtualization is a powerful tool with many applications: data center consolidation, desktop virtualization, etc. However, people often don’t consider the security implications of virtualization. Virtualization can make you more secure or less. To learn more about how this works and what you can do about it, watch this video or come see my talk at CSI SX.

{ 0 comments }

Virtualization is a powerful tool with many applications: data center consolidation, desktop virtualization, etc. However, people often don’t consider the security implications of virtualization. Virtualization can make you more secure or less. To lear…

{ 0 comments }

For those considering deperimeterization, how can this goal be practically achieved? Steve Hanna describes an integrated approach that encompasses endpoint security, network security of various kinds, and server security.

{ 0 comments }