May 15, 2008   Sign In |  About ebizQ |  Contact Us |  Join ebizQ Gold Club
Data Integration/EII Syndicate This
Print this article    Email this article    Talk Back!    Write to Editor
Secure Endpoints Need More Than Just Device Protection
01/28/2008
By Ari Tammam, VP of Channels, Promisec, Inc.
Untitled Document

ADVERTISEMENT
Our Popular Webinars
Achieving Process Optimization and Efficiency in Manufacturing –
A BPM Best Practice
Accelerate Agility and Lower Costs by Virtualizing and Governing Your SOA
PepsiAmericas: Realizing Real-Time Communication
a refreshing approach to ESB and data integration
Avoid the SOA Pitfalls that Prevent ROI
BAM for BPM Survey Results Are In! Learn What’s Driving New BAM Investments
More Webinars

Security vendors are increasingly surveying enterprises and quantifying the threats present on their networks, whether active or passive. This adds to the bigger picture on network security and helps end-user organizations get a better understanding on what their company is up against in terms of security. A recent comprehensive security audit conducted by an endpoint security vendor which surveyed 30 large organizations covering 193,000 corporate endpoints and servers revealed that 25,090 (13%) of the corporate PCs surveyed had unauthorized mass storage devices attached to them, opening the door to data leakage and the opportunity for USB-borne viruses, surveillance applications and Malware to enter the corporate network. While this was the single, most common potential threat, it was by no means the only one.

This may explain the wave of interest in device control applications and the increase in the number of vendors offering these niche solutions. However, corporations need to understand the other types of threats their internal endpoints are exposed to that can be as harmful as the USB threat in the same vein.

The below list shows other methods where classified data can leak out of a company or introduce malicious software into an organization:

  • e-mail- both in the body of an e-mail, as an attachment or even a link
  • P2P Applications
  • Internet telephony service
  • File Sharing applications
  • File Transfers – FTP
  • Shared folders enabling easy access by P2P applications
  • Remote Control Applications
  • Floppy disks or CDs

Further results showed that 7720 (4%) of the 193,000 audited corporate PCs had Peer-to-Peer (File Sharing and Instant Messengers) applications installed. 2895 (1.5%) did not have the latest Microsoft service packs, 3281 (1.7%) had their anti-virus client either turned off or out of date, 2316 (1.2%) were without required 3rd party desktop security agents and 1582 (0.8%) had unauthorized remote control software, with only a few of those showing thunauthorized and unprotected shared folders. These results indicate the prevalence of unauthorized software, rogue processes and endpoint security gaps that have the potential to explode into major security breaches if left unchecked.

Page 1

More Top Stories
Edging Towards Secure Application Development Gold Club Protected
Secure-Access Vendor AppGate Looks to US for Expansion Gold Club Protected
Like McAfee, Symantec Will Address Anti-Data Leakage Through Acquisition Gold Club Protected
More Top Stories
Related News
Vericept Partners with Blue Coat Systems To Protect Data
Truviso Joins EnterpriseDB Blade Partner Program
PopCap Games Joins Forces With Breach Security
More News
Subscribe to our Newsletters
ebizQ Weekly Gold Club Update
Live Webinar Updates
Updates from ebizQ Partners
ebizQ SOA Update
ebizQ BPM Update
ebizQ Security Update
ebizQ BI Update
ebizQ Open Source Software Update
Virtual Show Newsletter
ebizQ Web 2.0 and the Enterprise
Your E-mail Address:
PepsiAmericas: Realizing Real-Time Communication
a refreshing approach to ESB and data integration

Date: May 28, 2008
Time: 13:00 PM ET
(17:00 GMT)

REGISTER TODAY!
Accelerate Agility and Lower Costs by Virtualizing and Governing Your SOA
Date: May 29, 2008
Time: 12:00 PM ET
(16:00 GMT)

REGISTER TODAY!
Archived Webinars | Upcoming Webinars
  Introducing BEA AquaLogic Pages: Do-It-Yourself Web Application Building

Read this white paper to learn more about BEA AquaLogic Pages - a simple, powerful system that helps everyday participants create Web pages -...Learn More

ebizQ also recommends
 BI for Telecom
 BI for Process Industries
 BI for Health Care
 BI for Decision Makers
 BI for Consumer Packaged Goods
More White Papers

Marketing Solutions | Feedback | About ebizQ | Unsubscribe | Privacy Policy | Site Map