Access "Ping: Nate Lawson"
This article is part of the September 2007 issue of How to dig out rootkits
In an industry where most people have narrowly focused specialties, Nate Lawson is the equivalent of a Swiss Army knife. He was the lead designer of RealSecure, the first commercial IDS, designed the BD+ DRM scheme for Blu-ray, and has dabbled in hardware security. Now running his own consultancy, Root Labs, Lawson is putting his skills to work to embed security into devices. Nate Lawson Devices like the iPhone have full computing capabilities, but security seems to be a challenge. Do you expect to see more devices with embedded security? Yes, I think embedded security is a growing segment that is underserved by security firms. As software becomes the most valuable asset on a device, even vendors of cell phones, MP3 players and game consoles are adding protection. The number of devices that could benefit from signed code updates is staggering. Your PC has numerous devices that are flash-updatable, and none of them use digital signatures. There is no protection against bricking the device or installing a rootkit that survives a full OS reinstall. The ... Access >>>
Premium Content for Free.
Database Security: Oracle Database Vault
Oracle Database Vault
At Your Service: Atlas Vigilar
What CISOs need to know about computer forensics
With computer forensics needed for civil litigation, human resources investigations and criminal cases, organizations need to ensure they're prepared and evidence is preserved. This feature details steps involved in computer forensics, common missteps, and forensics resources.
Consolidation's impact on best-of-breed security
Standalone security vendors are attractive targets for large infrastructure players such as EMC. This feature looks at the consolidation in the security market and the potential for best-of-breed security to eventually disolve into a mashup of suites and services by big vendors like EMC, IBM, Microsoft, and HP.
Intrusion Prevention: Stonesoft's SGI-2000S IPS
CA Host-Based Intrusion Prevention System
- Database Security: Oracle Database Vault
Norman SandBox Analyzer Pro
Rootkit detection and removal know-how
Get advice on how to detect malware and rootkits and the best ways to achieve rootkit removal and prevent hacker attacks.
Logical, physical security integration challenges
Integrating physical and IT security can reap considerable benefits for an organization, including enhanced efficiency and compliance plus improved security. But convergence isn't easy. Challenges include bringing the physical and IT security teams together, combining heterogenous systems, and upgrading a patchwork of physical access systems.
SIM and NBA product combination is powerful
The recent announcement that Mazu Networks, a provider of network-based analysis (NBA) tools, and eIQnetworks, a supplier of SIM products, underscores the trend towards convergence in the NBA and SIM markets. The value proposition is clear: two useful network/security data analysis tools in one integrated package.
- Malware Analysis
Bruce Schneier, Marcus Ranum debate home users and security
by Marcus J. Ranum, Contributor
Bruce Schneier and Marcus Ranum debate how to deal with the security problems posed by home computer users. Both dismiss user education, but Schneier believes ISPs should be forced to become IT departments while Ranum argues that building simpler systems is not the answer.
Ping: Nate Lawson
Perspectives: The Lesson of Estonia
Prof. Dorothy Denning writes the cyberattacks on Estonia and how they took activism to a new level.
Time to take cyberterrorism talk seriously
With the power of botnets, SCADA systems becoming less proprietary and the recent attacks on Estonia, have we reached an inflection point where we need to take the likelihood of cyberterrorism?
- Viewpoint: Correlate SIMs and log management
- Bruce Schneier, Marcus Ranum debate home users and security by Marcus J. Ranum, Contributor
More Premium Content Accessible For Free
As more security professionals take on greater roles in global risk management, Global 2000 companies are investing in cybersecurity measures above ...
All indications show that DDoS attacks are increasing in variety, number and size. No network system is immune and information security pros can't ...
The Fast Identity Online (FIDO) standards reached the public draft stage in February, and the first deployments of FIDO-ready technologies followed ...