Newsletter 
January 6, 2009
Search 
Home
News
CXOtoday Plus
Industry Verticals
BFSI
Education
Energy
Government
IT
Manufacturing
Pharma
Retail
Services
Telecom
Events
Tech Insight
Market Scan
Interview
Case Study
CXO Lifestyle
White Papers
Editorial
CXO Views
Tech Terms
   TECH INSIGHT
Secure Your Online Transactions
Online businesses today need enhanced security to withstand heightened online threats. Shekhar Kirani, VP, Verisign India talks about the passive-active approach to security in this article. More...
    MARKET SCAN
Cisco Issues Malware Red Alert
The Cisco Threat 2008 report has warned that Internet-based attacks are becoming increasingly sophisticated and specialized. Cisco sees insider threats and data loss as the main problem areas in 2009 More...
   TECH TERMS
  • Blue Tooth
  • BI
  • CDMA
  • CRM
                             More...
Home > News > Security
Email Print View Comments   

Security in Patches, Not Advisable!
By Sonal Desai
Mumbai, Nov 11, 2008 1522 hrs IST


In an era where enterprises are consolidating data centers, networks and applications, and are focusing energies to drive compliance needs, content and application security has emerged as a major threat.

Users are getting globally distributed, the branch office growth is explosive, and plus employees are increasingly using mobiles and other devices to stay connected. Even as the security organization within an enterprise controls network access, deploys user lock-downs (to segment users as per their profiles (work/home/device), there is a need for predictable configuration. This stems from different needs in which a CEO and a user want anywhere anytime access by being device independent. The challenge for any IT organization is to balance the need.

Traditionally, the IT organization focuses on the network layer. 75 per cent of the investments are on firewalls. However, analysts across the globe said that more and more attacks are penetrating the applications, and thus opening up the crown jewel of confidential information, said Ratnesh Sharma, director, Product Management and Marketing, Citrix R&D, India.

He said that the attitude of the IT organizations has to change towards active security. For example, vendors issue a patch at regular intervals. By the time the IT organization updates the patch, the vendor releases a new one. And the cycle goes on. This is reactive attitude toward security. "The approach of the IT organization is not scalable, and attacks keep surfacing, penetrating more branches, partners, devices and now products and information on companies that have been acquired or merged. Practically, it is not possible for any IT department to support all applications and also update the patches regularly."

The need of the hour is "Secure by Design." It means consolidating all applications in one data center, control user access and critical demarcation of zones.

Even then, hackers can use cross site scripting or SQL injunctions to break into the TCPs and get confidential information. Here is how they do it.

  • Cross Site Scripting: You go to a legitimate website, and look at the sale site. There is an attack through a browser. You lose connection to the site, and there is a pop-up that asks you to login again. So you are re-entering the password.


  • SQL injunctions: Normally hackers take advantage of badly written code i.e. some thing network layer will not catch. This is at layer 7, Sharma said.


  • The trends in India are not too different. The profile of attackers and those being attacked is the same. People are using various devices to seek information. There is a lot of traction for encryption, SSL VPN security and application security in industries chiefly the banks, financial services and insurance companies. A lot many companies with a large branch office network are using access gateway solutions and encryption technology for protection.

    Some of the emerging verticals are healthcare in which hospitals or doctors share confidential patient related information, industrial design where companies are circulating designs to be shared with partners. Besides, there is a lot of in-house demand, essentially for the HR (employee information) and sales (customer information) applications, Sharma said.
    Home  |  Security  
    Share and Connect   del.icio.us del.icio.us   Digg.com Digg.com   Myweb MyWeb   Newsvine.com Newsvine.com
     
     
    Comment :

    Name :
    Company :
    City :
    E-mail :
    Word verification : Type the characters you see in the picture below.
     
    Characters are not case-sensitive
       


    Disclaimer
    ITNation (India) Pvt. Limited and its sites: www.channeltimes.com, www.techtree.com and www.cxotoday.com provide Comments and discussion boards as a professional medium for the various businesses of the IT industry to discuss business problems. Gossip, personal attacks and unsubstantiated charges are prohibited. Messages posted on this Web site as discussion threads or Comments (Content) are solely the opinions of their creators and do not necessarily reflect the opinions of ITNation (India) Pvt. Limited or its sites www.channeltimes.com, www.techtree.com and www.cxotoday.com.
    All individuals who post material to this web site are solely responsible for all Content that they upload, post or otherwise transmit via the Web Site.
    ITNation cannot vouch for the authenticity of the user or company names or e-mail addresses associated with posted messages. Under no circumstances will ITNation India Pvt.Ltd. or Cxotoday.com be liable in any way for any Content, including, but not limited to, for any errors or omissions in any Content, or for any loss or damage of any kind incurred as a result of the use of any Content posted or otherwise transmitted via the Bulletin Boards.
    ITNation reserves the exclusive right to edit or remove messages containing inappropriate language or other material that could be construed as libelous, potentially libelous, or otherwise offensive or inappropriate. Discussion forums, bulletin boards and chat facilities are provided by ITNation solely for the convenience of those who make use of the service. ITNation does not endorse the products and services or other offerings mentioned in messages.
    More BFSI News
    Kotak Goes Green
    HCL Inaugurates SDC
    BFSI Cost Cutting Tips
    Max New York Life
    IDBI Enhances Mobile Pay
    Visa to Launch Payments
    Businesses Seek Ways to
    Madhav Bank Outsources
    Kotak Stock Broking
    Montext for PCI Guidelin
    TODAY'S HEADLINES
    IBSG International Appt
    22% Indian SBs to Buy PC
    C-DAC Initiatives for NE
    Oracle to Replace Legacy
    TTSL Creates New Telecom
        CXO VIEWS
    Financial Crisis: An Opportunity for IT Industry
    The global financial meltdown may throw up growth opportunities for Indian IT industry, explains Sudhakar Ram, CMD, Mastek Ltd in this article More...
    LATEST COMMENTS
    I want to rent out my space to telecom company ..
    To leverage the power of UC participant ..
    sir, please let us know whether you can ..
    really all in one saving technology - first ..
    Excellent breather of an article. This really ..
    MOST POPULAR STORIES
    e-Governance Corruption? (5)
    Global Alliance for BIT (2)
    Weather Does Not Wither (1)
    Novatium Jaideep COO (1)
    3D Representation (1)
    Feedback | Sales Offices | Advertising Options | About CXOToday | Site Map |
    Copyright (C) 2009 ITNation India Pvt. Ltd. All Rights Reserved.