<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Greg Young &#187; Uncategorized</title>
	<atom:link href="http://blogs.gartner.com/greg_young/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/greg_young</link>
	<description>A member of the Gartner Blog Network</description>
	<lastBuildDate>Wed, 11 Nov 2009 14:42:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Remembrance Day</title>
		<link>http://blogs.gartner.com/greg_young/2009/11/11/remembrance-day/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/11/11/remembrance-day/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 14:42:39 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/11/11/remembrance-day/</guid>
		<description><![CDATA[In Canada Nov.11th is Remembrance Day, the equivalent of Memorial Day and a holiday for Gartner associates in Canada.&#160; Poppies are worn on the lapel by most everyone and it is a fairly significant event here.
Pretty much every male in our family served, so today we&#8217;ll take time at the 11th hour of the 11day [...]]]></description>
			<content:encoded><![CDATA[<p>In Canada Nov.11th is <a href="http://en.wikipedia.org/wiki/Remembrance_Day">Remembrance Day</a>, the equivalent of Memorial Day and a holiday for Gartner associates in Canada.&nbsp; Poppies are worn on the lapel by most everyone and it is a fairly significant event here.</p>
<p>Pretty much every male in our family served, so today we&#8217;ll take time at the 11th hour of the 11day of the 11th month to think of old army buddies, the thousands serving <a href="http://en.wikipedia.org/wiki/Canada%27s_role_in_the_invasion_of_Afghanistan">in nasty places</a>, and military families worldwide who don&#8217;t have a dad or mom around for long periods.&nbsp; To those serving today, thanks.</p>
<p>Grand-dad (middle) after liberation of Paris, Dad, my brother and I with mom.</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2009/11/WindowsLiveWriterRemembranceDay_8888Remi-Paris-April-45_2.jpg"><img style="border-right: 0px;border-top: 0px;border-left: 0px;border-bottom: 0px" height="286" alt="Remi Paris April 45" src="http://blogs.gartner.com/greg_young/files/2009/11/WindowsLiveWriterRemembranceDay_8888Remi-Paris-April-45_thumb.jpg" width="191" border="0"></a> <a href="http://blogs.gartner.com/greg_young/files/2009/11/WindowsLiveWriterRemembranceDay_8888Dad-uniform_2.jpg"><img style="border-right: 0px;border-top: 0px;border-left: 0px;border-bottom: 0px" height="272" alt="Dad uniform" src="http://blogs.gartner.com/greg_young/files/2009/11/WindowsLiveWriterRemembranceDay_8888Dad-uniform_thumb.jpg" width="158" border="0"></a>&nbsp; <a href="http://blogs.gartner.com/greg_young/files/2009/11/WindowsLiveWriterRemembranceDay_8888greg-095_2.jpg"><img style="border-right: 0px;border-top: 0px;border-left: 0px;border-bottom: 0px" height="180" alt="greg 095" src="http://blogs.gartner.com/greg_young/files/2009/11/WindowsLiveWriterRemembranceDay_8888greg-095_thumb.jpg" width="244" border="0"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/11/11/remembrance-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unsafe Networks and Security Conferences</title>
		<link>http://blogs.gartner.com/greg_young/2009/10/20/unsafe-networks-and-security-conferences/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/10/20/unsafe-networks-and-security-conferences/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 18:46:13 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/10/20/unsafe-networks-and-security-conferences/</guid>
		<description><![CDATA[Some unhappy bloggers ended up on the Wall of Shame at a recent security/hackers conference and (I summarize&#8230;) cried foul because it wasn&#8217;t pre-advertised that the network would be hostile.&#160; There is a good post on the hub-bub here. 
The yin of rubbing elbows with vulnerability researchers and semi-bad guys who reveal the most recent [...]]]></description>
			<content:encoded><![CDATA[<p>Some unhappy bloggers ended up on the Wall of Shame at a recent security/hackers conference and (I summarize&#8230;) cried foul because it wasn&#8217;t pre-advertised that the network would be hostile.&nbsp; There is a good post on the hub-bub <a href="http://securityuncorked.com/2009/10/good-bad-and-ugly-on-sectors-wall-of-shame/">here</a>. </p>
<p>The yin of rubbing elbows with vulnerability researchers and semi-bad guys who reveal the most recent hacks on the the unassuming comes with the yang that you are the nearby unassuming one to these semi-bad guys and vulnerability researchers.&nbsp; </p>
<p>Blogging is the new gonzo journalism.&nbsp; To those crying foul, I suggest a lesson from the gonzo-est journalist Hunter S. Thompson who while writing his book<em> Hells Angels h</em>e enjoyed the access and excitement which he knew would sell books.&nbsp; At the end of his tale when he became the unwanted object of the excitement he made that a part of the story.</p>
<p>The object lesson here for me is really that OPN (other people&#8217;s networks) generally give you as much security as you pay for.&nbsp; OPNs are the bad part of town, and it is a good idea to change your behavior accordingly, which could include not connecting.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/10/20/unsafe-networks-and-security-conferences/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Defining The Next Generation Firewall Research Note: The Liner Notes</title>
		<link>http://blogs.gartner.com/greg_young/2009/10/15/defining-the-next-generation-firewall-research-note-the-liner-notes/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/10/15/defining-the-next-generation-firewall-research-note-the-liner-notes/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 04:13:10 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/10/15/defining-the-next-generation-firewall-research-note-the-liner-notes/</guid>
		<description><![CDATA[John Pescatore and I published today &#8220;Defining The Next Generation Firewall&#8221; (NGFW).&#160; The note &#8216;liner notes&#8217; may help provide some context.&#160; Gartner has been talking about Next Generation Firewalls (NGFW) for a while &#8211; in 2004 we had a note titled &#8220;Next generation Firewalls Include Intrusion Prevention&#8221;.&#160; 
We have been increasing the weighting for NGFW [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blogs.gartner.com/john_pescatore/">John Pescatore</a> and I published today <a href="http://www.gartner.com/DisplayDocument?doc_cd=171540">&#8220;Defining The Next Generation Firewall&#8221;</a> (NGFW).&nbsp; The note &#8216;liner notes&#8217; may help provide some context.&nbsp; Gartner has been talking about Next Generation Firewalls (NGFW) for a while &#8211; in 2004 we had a note titled &#8220;Next generation Firewalls Include Intrusion Prevention&#8221;.&nbsp; </p>
<p>We have been increasing the weighting for NGFW capabilities in each successive Enterprise Network Firewall Magic Quadrant (MQ), so there will not be a separate MQ for NGFW: this next generation is not a new product or an artificial label, but a progression of firewall and IPS technology.</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2009/10/WindowsLiveWriterDefiningTheNextGenerationFirewallResearc_314vrg33_2.jpg"><img style="border-right: 0px;border-top: 0px;margin: 0px 45px 0px 0px;border-left: 0px;border-bottom: 0px" height="240" alt="vrg33" src="http://blogs.gartner.com/greg_young/files/2009/10/WindowsLiveWriterDefiningTheNextGenerationFirewallResearc_314vrg33_thumb.jpg" width="240" align="left" border="0"></a>The note was published now because the market is starting to see early versions of these enterprise class products: some firewall vendors waking up to a big IPS market, changes in network traffic to being squeezed through fewer ports and protocols, an emerging firewall policy management market, and the signaling between other network security products.&nbsp; In the note we also specify what a NGFW is <em>not</em>, in response to inquiries from Gartner clients and as a further guide to where this market is heading.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/10/15/defining-the-next-generation-firewall-research-note-the-liner-notes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Private Clouds and Phishy Clouds</title>
		<link>http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/#comments</comments>
		<pubDate>Tue, 06 Oct 2009 21:39:57 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/</guid>
		<description><![CDATA[Two items this week bring into focus the security issues around cloud computing.
According to an article on DISA&#8217;s RACE (Rapid Access Computing Environment), the comment is made that RACE is more secure and stable than the Google cloud.&#160; Arguments aside about the definition of clouds and whether private clouds are really clouds, I find this [...]]]></description>
			<content:encoded><![CDATA[<p>Two items this week bring into focus the security issues around cloud computing.</p>
<p>According to an <a href="http://www.networkworld.com/news/2009/100509-pentagon-cloud-computing.html?t51hb">article</a> on DISA&#8217;s RACE (Rapid Access Computing Environment), the comment is made that RACE is more secure and stable than the Google cloud.&nbsp; Arguments aside about the definition of clouds and whether private clouds are really clouds, I find this interesting because it highlights that looking at clouds is not a &#8220;if you don&#8217;t like it, leave&#8221; security proposition, but you can have choices.&nbsp; Just don&#8217;t try to shoehorn your requirements into an existing cloud that doesn&#8217;t meet those.</p>
<p>Second was the <a href="http://news.bbc.co.uk/2/hi/technology/8292928.stm">news from the BBC</a> that an estimated 30k Gmail accounts had allegedly been compromised through phishing: 1) you get the security you pay for and 2) not much new here &#8211; this wasn&#8217;t likely a new cool super-sophisticated attack but an old one, and it just went where the fishing (arg) was good.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/10/06/private-clouds-and-phishy-clouds/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Unicorns, Pixies, and Enterprise UTM</title>
		<link>http://blogs.gartner.com/greg_young/2009/09/29/unicorns-pixies-and-enterprise-utm/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/09/29/unicorns-pixies-and-enterprise-utm/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 22:26:02 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/09/29/unicorns-pixies-and-enterprise-utm/</guid>
		<description><![CDATA[ The child actor who died from drinking Pop Rocks candy and Coke and the Nigerian minister who just needs a little help with some money transfer.. I need to call someone at Snopes.com and pull in some favors to get &#8220;Enterprise UTM&#8221; added to the myths list.
The Loch Ness Enterprise UTM message has again [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blogs.gartner.com/greg_young/files/2009/09/WindowsLiveWriterUnicornsPixiesandEnterpriseUTM_FCBB19535_21.jpg"><img style="border-right: 0px;border-top: 0px;margin: 0px 15px 0px 0px;border-left: 0px;border-bottom: 0px" height="100" alt="19535" src="http://blogs.gartner.com/greg_young/files/2009/09/WindowsLiveWriterUnicornsPixiesandEnterpriseUTM_FCBB19535_thumb1.jpg" width="80" align="left" border="0"></a> The child actor who died from drinking Pop Rocks candy and Coke and the Nigerian minister who just needs a little help with some money transfer.. I need to call someone at Snopes.com and pull in some favors to get &#8220;Enterprise UTM&#8221; added to the myths list.</p>
<p>The Loch Ness Enterprise UTM message has again been sighted in the security market.&nbsp; At Gartner, we haven&#8217;t seen enterprises shifting to using UTMs or SMB multifunction firewalls, nor do we forecast that this will happen any time soon.&nbsp; </p>
<p>Here are some of the tricks used in security marketing to make these claims:</p>
<p><strong>Trick #1: Redefining what an enterprise is.</strong>&nbsp; Enterprises are in fact about 1000 employees.&nbsp; Between 500 and 1000 employees we consistently see IT buying behavior, including security, differ from the SMB.&nbsp; For firewalls, companies shift from buying what we call SMB multifunction firewalls (what is also called UTM) and start moving consistently to point products at about that 750-ish employee mark and don&#8217;t go back.&nbsp; Redefining by vendors of what an enterprise is in order to fit the product just games the equation.&nbsp; The trend is the key: calling an enterprise 200 or 2 employees doesn&#8217;t change the selection trend.&nbsp; </p>
<p><strong>Trick #2: Calling a non-enterprise an enterprise.</strong>&nbsp; Sure a branch office may use a converged device, but that isn&#8217;t the enterprise.&nbsp; As&nbsp; a sidebar, branch offices generally aren&#8217;t doing mail security in the firewall (the mail servers aren&#8217;t usually out in the branches).&nbsp; Also, carriers, ISPs, and hosting companies aren&#8217;t enterprises: they are carriers, ISPs, and hosting companies and serve up security in a very different manner than both enterprises and SMBs.&nbsp; </p>
<p><strong>Trick #3: Holding up the recession as a reason to see unicorns</strong>.&nbsp; During the last year some vendors have claimed that enterprises can now use SMB products or UTMs because of the recession.&nbsp; In fact, the recession may have been a reason to seek a less expensive enterprise product.&nbsp; If your construction company has come upon tough times, the solution is not to start hauling gravel in minivans.&nbsp; Maybe a vendor who is selling the enterprise UTM message can find a reference customer to hold up as proof, however this is them having sold into their niche and have found the exception rather than the rule.</p>
<p><strong>Trick #4: Calling a few point products together a UTM</strong>. Getting fuzzy with the definition of what is this mysterious UTM is the biggest trick.&nbsp; This is why Gartner doesn&#8217;t use the term &#8220;UTM&#8221;: we expressly separate products into &#8220;SMB Multifunction Firewalls&#8221; and &#8220;Enterprise Firewalls&#8221;.&nbsp; UTMs and SMB multifunction firewalls are generally understood to be all the network security products in one appliance.&nbsp; Enterprise firewalls are generally firewall, VPN, and maybe IPS: that isn&#8217;t the same as the SMB product or what has generally been called UTM.&nbsp; In our Gartner research, we provide some considerable detail to this topic, however a firewall and IPS together is not a UTM.&nbsp; The unicorn-solvent is email anti-virus: if they mean to propose doing email anti-virus on the firewall then good luck with meeting your firewall latency SLAs (see below), otherwise they are being realistic but tricksy by just calling what is a firewall or next generation firewall a UTM.</p>
<p>There isn&#8217;t one big convergence happening in network security products.&nbsp; In our Gartner research, we provide some considerable detail to this topic, but enterprises won&#8217;t be deploying UTMs as their firewall anytime soon because: </p>
<ul>
<li>Buying and operations centers.&nbsp; In enterprises, mail security and network security are different security operations groups, and the safeguard is usually required in different places: i.e. firewall at edge and anti-spam in the data center.</li>
<li>Latency sensitivity and inspection differences.&nbsp; You can wait a little while for mail anti-virus and not for network packets.&nbsp; It also turns out that the types of inspection for handling packets quickly and doing deep inspection and expression matching are very different.&nbsp; At the lower bandwidth and connection rates of the SMB this inefficiency isn&#8217;t a big problem, but at true enterprise throughput and iMix the inefficiency quickly becomes a service-killer.</li>
<li>Best of breed requirements.&nbsp; Enterprises continue to favor getting good protection, and a single vendor offering 10 safeguards in a single appliance is likely not be to great at all of them.&nbsp; If you look at the Magic Quadrants (MQ) for messaging security, firewalls and IPS you will very little overlap across quadrants in the MQs.</li>
</ul>
<p><strong>Greg Young| Research Vice President </strong><strong>| Gartner</strong><b><br /></b>Network Security<br /><a href="http://blogs.gartner.com/greg_young/">http://blogs.gartner.com/greg_young/</a><br /><a href="http://twitter.com/Gartnergreg">http://twitter.com/Gartnergreg</a><br /><a href="http://www.gartner.com/7_search/Search2Frame.jsp?op=16&amp;authorId=19535">Browse my published research</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/09/29/unicorns-pixies-and-enterprise-utm/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>The Importance of Uncertainty</title>
		<link>http://blogs.gartner.com/greg_young/2009/08/31/the-importance-of-uncertainty/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/08/31/the-importance-of-uncertainty/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 14:22:03 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/08/31/the-importance-of-uncertainty/</guid>
		<description><![CDATA[People, it turns out, are really bad at dealing with uncertainty and randomness.&#160; We are pre-programmed to see direct causes between independent factors and to treat direct links as unrelated or random.&#160; Likelihood, causation, and randomness are fundamental to IT security, and humans having blind spots in these areas are but one reason why we [...]]]></description>
			<content:encoded><![CDATA[<p>People, it turns out, are really bad at dealing with uncertainty and randomness.&#160; We are pre-programmed to see direct causes between independent factors and to treat direct links as unrelated or random.&#160; Likelihood, causation, and randomness are fundamental to IT security, and humans having blind spots in these areas are but one reason why we aren&#8217;t better at IT Security.</p>
<p>For a jaw-dropping read on these blind spots, read &quot;<a href="http://www.amazon.ca/Drunkards-Walk-Randomness-Rules-Lives/dp/0375424040">The Drunkard&#8217;s Walk: How Randomness Rules Our Lives</a>&quot;, where Leonard Mlodinow shows through example and history how likely we are to take the wrong action dependent on the degree of uncertainty, and how we usually draw the wrong conclusions in response to false positives, regression to the mean, and &#8216;recency&#8217; of bad events.&#160; </p>
<p>Think you&#8217;re immune?&#160; Quick &#8211; tell me what the odds are of one of a set of twins being a girl.&#160; If you answered anything other than 75% you have passed the Turing test and are a flawed human (and then go on to wrestle with knowing that the odds of one of them being a boy is also 75%&#8230;).</p>
<p>Security budgets cannot continue to outpace IT spending indefinitely at the rate have through this recession.&#160; Enterprise security budgets are limited, and tradeoffs mean making the right choices based on what is best for your company.&#160; These choices have to be made with a great degree of uncertainty and having to defend them to people who are by nature are not good at dealing with uncertainty&#160; and handling the random.</p>
<p>&#160;</p>
<p><font face="Arial">&#160;</font></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/08/31/the-importance-of-uncertainty/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hype Cycle for Infrastructure Protection</title>
		<link>http://blogs.gartner.com/greg_young/2009/08/10/hype-cycle-for-infrastructure-protection/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/08/10/hype-cycle-for-infrastructure-protection/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 13:15:36 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/08/10/hype-cycle-for-infrastructure-protection/</guid>
		<description><![CDATA[I was honored to be the lead author for the 2009 Hype Cycle for Infrastructure Protection (limited to Gartner customers).
First in thanks and second to demonstrate the depth the depth of work and research we do at Gartner, I&#8217;d like to thank my 15 co-authors:
Vic Wheatman, Joseph Feiman, Neil MacDonald, Adam Hils, Jeffrey&#160; Wheatman, Peter [...]]]></description>
			<content:encoded><![CDATA[<p>I was honored to be the lead author for the <a href="http://www.gartner.com/DisplayDocument?doc_cd=169194">2009 Hype Cycle for Infrastructure Protection</a> (limited to Gartner customers).</p>
<p>First in thanks and second to demonstrate the depth the depth of work and research we do at Gartner, I&#8217;d like to thank my 15 co-authors:</p>
<p>Vic Wheatman, Joseph Feiman, <a href="http://blogs.gartner.com/neil_macdonald/">Neil MacDonald</a>, <a href="http://blogs.gartner.com/adam-hils/">Adam Hils</a>, Jeffrey&#160; Wheatman, Peter Firstbrook, <a href="http://blogs.gartner.com/john_pescatore/">John Pescatore</a>, John Girard, Kelly M. Kavanagh, Lawrence Orans, Mark Nicolett, Arabella Hallawell, <a href="http://blogs.gartner.com/frank_kenney/">L. Frank Kenney,</a> Ray Wagner, and David Norton.</p>
<p>Infrastructure Protection is composed of the &#8216;keeping the bad guys out&#8217; security technologies. This year we see considerable forward movement in the technologies as driven by the relentless and constantly changing threats.&#160; </p>
<p>The technologies listed in this edition include(in no particular order):</p>
<p>Web Application Firewalls    <br />E-Mail Security Boundary     <br />DDoS Defense     <br />HIPS on Servers     <br />Stateful Firewalls    <br />Software Composition Analysis     <br />Application Inspection     <br />Penetration Testing Tools     <br />&quot;In the Cloud&quot; Security Services     <br />Security in the Switch     <br />Database Activity Monitoring (DAM)     <br />Open-Source Security Tools     <br />SMB Multifunction Firewall     <br />Endpoint Deep Packet Inspection     <br />Endpoint Protection Platform     <br />Network Security Silicon     <br />Application Control     <br />Mobile Data Protection     <br />Data Masking     <br />Static Application Security Testing     <br />HIPS on PCs     <br />Network Access Control     <br />Network IDS     <br />Next-Generation Firewalls     <br />Secure Web Gateways     <br />WLAN IPS     <br />XML Firewalls     <br />Dynamic Application Security Testing     <br />Network IPS     </p>
<p><font color="#000000">There is a great top level summary in the Gartner&#8217;s Hype Cycle Special Report for 2009.&#160; The Infrastructure Protection Hype Cycle is a companion to the other security Hype Cycles:</font></p>
<ul>
<li>Hype Cycle for Governance, Risk and Compliance Technologies, 2009 </li>
<li>Hype Cycle for Data and Application Security, 2009 </li>
<li>Hype Cycle for Identity and Access Management Technologies, 2009 </li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/08/10/hype-cycle-for-infrastructure-protection/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>DNS BIND Vulnerability</title>
		<link>http://blogs.gartner.com/greg_young/2009/07/29/dns-bind-vulnerability-requires-action/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/07/29/dns-bind-vulnerability-requires-action/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 15:42:58 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/07/29/dns-bind-vulnerability-requires-action/</guid>
		<description><![CDATA[My colleague and guest blogger Lawrence Orans joins me today in giving his take on the DNS BIND vulnerability:
 
Another July, another DNS vulnerability.&#160; Last year, it was the Kaminsky vulnerability.&#160; Yesterday, the ISC announced another vulnerability in BIND.&#160; It&#8217;s serious &#8212; a specially-crafted dynamic update message can crash your BIND 9 name servers.&#160; According [...]]]></description>
			<content:encoded><![CDATA[<p><em>My colleague and guest blogger Lawrence Orans joins me today in giving his take on the DNS BIND vulnerability</em>:</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2009/07/windowslivewriterdnsbindvulnerabilityrequiresaction-a4c0image-2.png"><img height="104" alt="image" src="http://blogs.gartner.com/greg_young/files/2009/07/windowslivewriterdnsbindvulnerabilityrequiresaction-a4c0image-thumb.png" width="84" border="0" /></a> </p>
<p>Another July, another DNS vulnerability.&#160; Last year, it was the Kaminsky vulnerability.&#160; Yesterday, the <a href="https://www.isc.org/node/474">ISC announced another vulnerability in BIND</a>.&#160; It&#8217;s serious &#8212; a specially-crafted dynamic update message can crash your BIND 9 name servers.&#160; According to the ISC, &#8220;an active remote exploit is in wide circulation at this time&#8221;.&#160; Fortunately, the ISC has released BIND versions which address the vulnerability.&#160; BIND users should upgrade immediately to one of the three BIND 9 versions specified in the ISC announcement.&#160; </p>
<p>I can count on one hand the number of Gartner clients that scheduled inquiries with us last year to discuss the Kaminsky vulnerability.&#160; At first, that surprised me.&#160; But, after thinking about it, I realized that clients weren&#8217;t calling because there really wasn&#8217;t anything to discuss.&#160; If you were running a vulnerable version of DNS, you had to apply the patch &#8211; it&#8217;s that simple.&#160; You don&#8217;t ask the dentist if you need to brush your teeth, and you don&#8217;t need to ask Gartner if you should patch the Kaminsky DNS vulnerability.&#160; I imagine that with this DNS vulnerability, Gartner will also see a similar lack of inquiries from our clients.&#160; Sure, two serious DNS vulnerabilities in two years will stimulate lots of discussion and debate about best practices for securing DNS, but the immediate priority is to get those BIND 9 name servers upgraded &#8211; there is no need to discuss that.&#160; So, go out there and brush (and floss) your teeth!&#160;&#160;&#160; </p>
<p><em>- Lawrence Orans is a research director in Gartner&#8217;s Research organization. His research focuses on the integration of security within internal networks, with a particular emphasis on network access control, VoIP and content filtering.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/07/29/dns-bind-vulnerability-requires-action/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Social Media Data Leaks: TMI</title>
		<link>http://blogs.gartner.com/greg_young/2009/07/28/social-media-data-leaks-tmi/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/07/28/social-media-data-leaks-tmi/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 01:30:05 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/07/28/social-media-data-leaks-tmi/</guid>
		<description><![CDATA[TMI: Too Much Info.&#160; Sure the below example isn&#8217;t as egregious (i.e. bad) as the others I&#8217;ve posted recently, but it falls into that soft gray category of TMI.
 
See the other posts on this thread:
Social Media Data Leaks: Password Reset Helpers
Social Media Data Leaks: The Polarity of Security Models
and Social Media Data Leaks.
]]></description>
			<content:encoded><![CDATA[<p>TMI: Too Much Info.&#160; Sure the below example isn&#8217;t as egregious (i.e. bad) as the others I&#8217;ve posted recently, but it falls into that soft gray category of TMI.</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2009/07/windowslivewritersocialmediadataleakstmi-12e5btwits3.jpg"><img height="123" alt="twits3" src="http://blogs.gartner.com/greg_young/files/2009/07/windowslivewritersocialmediadataleakstmi-12e5btwits3-thumb.jpg" width="406" border="0" /></a> </p>
<p>See the other posts on this thread:</p>
<h4><a href="http://blogs.gartner.com/greg_young/2009/07/27/social-media-data-leaks-password-recovery-helpers/">Social Media Data Leaks: Password Reset Helpers</a></h4>
<h4><a href="http://blogs.gartner.com/greg_young/2009/07/24/social-media-data-leaks-the-polarity-of-security-models/">Social Media Data Leaks: The Polarity of Security Models</a></h4>
<p>and <a href="http://blogs.gartner.com/greg_young/2009/07/23/social-media-leaks/"><em>Social Media Data Leaks</em></a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/07/28/social-media-data-leaks-tmi/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Social Media Data Leaks: Password Reset Helpers</title>
		<link>http://blogs.gartner.com/greg_young/2009/07/27/social-media-data-leaks-password-recovery-helpers/</link>
		<comments>http://blogs.gartner.com/greg_young/2009/07/27/social-media-data-leaks-password-recovery-helpers/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 01:49:50 +0000</pubDate>
		<dc:creator>Greg Young</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/greg_young/2009/07/27/social-media-data-leaks-password-recovery-helpers/</guid>
		<description><![CDATA[There are some slightly sensitive things which if leveraged can be turned into more sensitive things.&#160; Ye olde Mother&#8217;s Maiden name is one of those often used in attacks on password reset challenges, of the likes of which have been reported on here.
 
 Here is an example via Twitter of making an account reset [...]]]></description>
			<content:encoded><![CDATA[<p>There are some slightly sensitive things which if leveraged can be turned into more sensitive things.&#160; Ye olde Mother&#8217;s Maiden name is one of those often used in attacks on password reset challenges, of the likes of which have been reported on <a href="http://www.techcrunch.com/2009/07/14/in-our-inbox-hundreds-of-confidential-twitter-documents/">here</a>.</p>
<p><a href="http://blogs.gartner.com/greg_young/files/2009/07/windowslivewritersocialmediadataleakspasswordrecoveryhelp-132fbmaiden.jpg"><img height="72" alt="maiden" src="http://blogs.gartner.com/greg_young/files/2009/07/windowslivewritersocialmediadataleakspasswordrecoveryhelp-132fbmaiden-thumb.jpg" width="421" border="0" /></a> </p>
<p> Here is an example via Twitter of making an account reset attack that much easier.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/greg_young/2009/07/27/social-media-data-leaks-password-recovery-helpers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
