<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lawrence Pingree</title>
	<atom:link href="http://blogs.gartner.com/lawrence-pingree/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/lawrence-pingree</link>
	<description>A Member of The Gartner Blog Network</description>
	<lastBuildDate>Fri, 22 Mar 2013 15:07:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Threats come from everywhere, so you must deal with it as such.</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2013/03/22/threats-come-from-everywhere-so-you-must-deal-with-it-as-such/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2013/03/22/threats-come-from-everywhere-so-you-must-deal-with-it-as-such/#comments</comments>
		<pubDate>Fri, 22 Mar 2013 14:58:48 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=68</guid>
		<description><![CDATA[How great a threat does Gartner perceive state sponsored cyber espionage? Since Gartner does not track individual threats or actors it is difficult to say for certain which attacks are state sponsored or not. The recent mandiant report highlighted China as the threat actor. Gartner does not believe that the country of origin is as [...]]]></description>
			<content:encoded><![CDATA[<p>How great a threat does Gartner perceive state sponsored cyber espionage?</p>
<p>Since Gartner does not track individual threats or actors it is difficult to say for certain which attacks are state sponsored or not. The recent mandiant report highlighted China as the threat actor. Gartner does not believe that the country of origin is as important as the protection mechanisms that must be in place.</p>
<p>&nbsp;</p>
<p>What are are the biggest threats, and from where do they originate?</p>
<p>Threats originate globally, and in the hacker underground the most sophisticated hackers most often originate from Russia. In general, a nation state actor (if targeting you) will likely be successful since they often are given time and resources in order to breach the security of your organization with many different capabilities beyond just cyber assets.  Attribution of attacks is extremely difficult since counter intelligence can be used on the internet such as spoofing source IP&#8217;s, using proxy servers, using botnets to deliver attacks out of other locations, developers using keyboard maps of different languages, for example a Chinese American or European that understands Chinese but develops their exploits for their country of origin will result in problematic or impossible attribution.</p>
<p>&nbsp;</p>
<p>In the recent report published by the company Mandiant titled &#8220;APT1&#8243; hackers appear to originate in China. These threat actors were utilizing common forms of zero day exploitation, botnets and other tools readily available in the underground hacking community. Given they are using the same tools and capabilities of the underground hackers, it is most important to focus on generic security controls that protect against all of these attack capabilities. An organization should take a general approach to combat threats from any location and not focus on the country of origin. In a report published by Gartner last year titled &#8220;<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1534314&amp;ref=QuickSearch&amp;sthkw=lean+forward"><strong>Network Security Monitoring Tools for &#8216;Lean Forward&#8217; Security Programs</strong></a>&#8221; to call out technologies that can assist in advanced targeted attack detection at the network layer.</p>
<p>&nbsp;</p>
<p>What responses are organizations making?</p>
<p>I have written a report titled “Best Practices for Mitigating Advanced Persistent Threats” as a guide for raising the bar for prevention and detection of advanced forms of malware and targeted attacks and these technologies and security techniques are what organizations today are focusing on refining/deploying. The two primary attack vectors of choice for today’s  threat actors is <span style="text-decoration: underline">malware</span> to gather unstructured data and <span style="text-decoration: underline">web-based attacks</span> such as SQL injection to grab database stored structured data types. The malware can be handled by a number of technologies  at the network layer and  at the windows endpoint. Web attacks can be addressed with a combination of Intrusion Prevention System and Web application firewalls. See report titled “<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1898616&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threats"><strong>Best Practices for Mitigating Advanced Persistent Threats</strong></a>” and “<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2170815&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threats"><strong>Market Trends: Advanced Threat Protection Appliances, Worldwide, 2012</strong></a>“ for advanced Malware threats and “<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2067715&amp;ref=QuickSearch&amp;sthkw=web+application+firewalls"><strong>Competitive Landscape: Web Application Firewall Market, Worldwide, 2012</strong></a>” for web application firewalls.</p>
<p>&nbsp;</p>
<p>Are organizations in a regulated environment facing a greater threat?</p>
<p>Nation states do not often target structured data types such as financial data, however disruption of a banking system or critical infrastructure can be akin to a nuclear attack if an entire banking system, power or water delivery system is properly disrupted. Government regulations target sensitive areas of the economy. Most attackers are financially motivated and thus regulated environments such as Financial organizations often face the largest threat from these actor groups. A nation state would likely consider disruption of critical infrastructure as an end goal during a time of war vs. data acquisition. Prior to wartime, a nation state would likely be focused on distributing “capability” for disruption as a preparatory measure for evocation at a later date. Although we don’t have direct research in this area, we do have many supporting research notes. Please see the list below as a very comprehensive way to deal with both threat actor groups.</p>
<p>&nbsp;</p>
<p>Research:</p>
<p>-          <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1898616&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threats"><strong>Best Practices for Mitigating Advanced Persistent Threats</strong></a></p>
<p>-          <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2170815&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threats"><strong>Market Trends: Advanced Threat Protection Appliances, Worldwide, 2012</strong></a></p>
<p>-          <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1767516&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threats"><strong>Malware, APTs, and the Challenges of Defense</strong></a></p>
<p>-          <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2076026&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threats"><strong>Decision Point for Anti-malware</strong></a></p>
<p>-          <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2067715&amp;ref=QuickSearch&amp;sthkw=web+application+firewalls"><strong>Competitive Landscape: Web Application Firewall Market, Worldwide, 2012</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2013/03/22/threats-come-from-everywhere-so-you-must-deal-with-it-as-such/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where do the most hackers come from?</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2013/03/08/where-do-the-most-hackers-come-from/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2013/03/08/where-do-the-most-hackers-come-from/#comments</comments>
		<pubDate>Fri, 08 Mar 2013 17:04:44 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=62</guid>
		<description><![CDATA[Recently, there have been a lot of stories surrounding the Chinese and hackers originating from their intelligence agency.  Although I do not want to diminish the findings of a particular technology company that disclosed some of their own investigations, I do believe it is necessary to draw some attention towards  locations of the globe where [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, there have been a lot of stories surrounding the Chinese and hackers originating from their intelligence agency.  Although I do not want to diminish the findings of a particular technology company that disclosed some of their own investigations, I do believe it is necessary to draw some attention towards  locations of the globe where  many of the attacks actually originate to be fair.  It is fairly well known  by most security professionals that the best hackers on the planet often originate from Russia,  however it is  more newsworthy to talk about  a country such as China whom we trust with many of our manufacturing facilities and research and development activities and have greater resources at their disposal if they intended to inflict harm.</p>
<p>There certainly political motivations for talking about China  and I think it&#8217;s fair to say  they are certainly many participants in the global stage of cyber security and intelligence gathering.  In fact, the United Stateshas a long history with its intelligence agencies for performing signals intelligence (SIGINT).  I would like to point out  that as far as sophistication goes, the United States is unmatched with its intelligence gathering capabilities and extends this capability across the globe with an extensive  array of spy satellites and listening stations with strong support of several other countries.  It does not strike me as odd  or newsworthy that governments across the planet attempt to track each other&#8217;s  military capabilities and monitor situations through signal intelligence and other intelligence gathering capabilities.  These activities are a necessary function to enable transparency across borders between governments and be ready if another country is planning some sort of attack.  I do think however it is important to mention that I believe that all countries should uphold  strong intellectual property rules in order to maintain fair competition  which creates a dynamic that encourages new developments and technologies and enables fair competition across the globe.</p>
<p>Now lets turn to some of the data often known  &#8221;behind the scenes&#8221;  that many security practitioners know and consistently defend against. Deutsche Telecom publishes a real-time dashboard of hacking attacks detected by its global network of attack sensors known as a &#8220;honey net&#8221;. As many practitioners know, a &#8220;honey net&#8221; the reference to honey is an analogy to how one might attract a bear in the woods, the bear being the hacker in the case of a &#8220;honey net&#8221;. For some fun, I used some statistics from the Deutsche Telecom dashboard located at <a href="http://www.sicherheitstacho.eu/">http://www.sicherheitstacho.eu/</a> to provide data points for some basic analysis. At the time of this writing, the total number of attacks detected over the last month globally were 30,144,538 when tallying the &#8220;<span style="font-size: 0.83em">Top 5 of Attack Types (Last month)&#8221; table. They also publish a table called &#8220;</span><span style="font-size: 0.83em">Top 15 of Source Countries (Last month)&#8221; with detected attack values which I found interesting but I wanted to extract percentages so I used those values and threw them into excel to calculate percentage values by top 15 countries and the following is my output.</span></p>
<p>Attacks by percentage of total global attack detections.</p>
<table width="221" border="0" cellspacing="0" cellpadding="0">
<col span="2" width="64" />
<col width="93" />
<tbody>
<tr>
<td width="64" height="49">Russian Federation</td>
<td width="64">2,402,722</td>
<td align="right" width="93">7.97%</td>
</tr>
<tr>
<td width="64" height="49">Taiwan, Province of China</td>
<td width="64">907,102</td>
<td align="right">3.01%</td>
</tr>
<tr>
<td width="64" height="49">Germany</td>
<td width="64">780,425</td>
<td align="right">2.59%</td>
</tr>
<tr>
<td width="64" height="49">Ukraine</td>
<td width="64">566,531</td>
<td align="right">1.88%</td>
</tr>
<tr>
<td width="64" height="33">Hungary</td>
<td width="64">367,966</td>
<td align="right">1.22%</td>
</tr>
<tr>
<td width="64" height="33">United States</td>
<td width="64">355,341</td>
<td align="right">1.18%</td>
</tr>
<tr>
<td width="64" height="21">Romania</td>
<td width="64">350,948</td>
<td align="right">1.16%</td>
</tr>
<tr>
<td width="64" height="21">Brazil</td>
<td width="64">337,977</td>
<td align="right">1.12%</td>
</tr>
<tr>
<td width="64" height="21">Italy</td>
<td width="64">288,607</td>
<td align="right">0.96%</td>
</tr>
<tr>
<td width="64" height="21">Australia</td>
<td width="64">255,777</td>
<td align="right">0.85%</td>
</tr>
<tr>
<td width="64" height="21">Argentina</td>
<td width="64">185,720</td>
<td align="right">0.62%</td>
</tr>
<tr>
<td width="64" height="21">China</td>
<td width="64">168,146</td>
<td align="right">0.56%</td>
</tr>
<tr>
<td width="64" height="21">Poland</td>
<td width="64">162,235</td>
<td align="right">0.54%</td>
</tr>
<tr>
<td width="64" height="21">Israel</td>
<td width="64">143,943</td>
<td align="right">0.48%</td>
</tr>
<tr>
<td width="64" height="21">Japan</td>
<td width="64">133,908</td>
<td align="right">0.48%</td>
</tr>
<tr>
<td height="20"></td>
<td align="right">7,407,348</td>
<td align="right">24.61%</td>
</tr>
</tbody>
</table>
<p>Source: <a href="http://www.sicherheitstacho.eu/">http://www.sicherheitstacho.eu/</a></p>
<p>As you can see with this quick analysis, roughly 24.61% of total detected attacks were from the top 15 attacking countries and roughly 8% of all attacks came from the Russian Federation and only half a percent came from China. So the question is, who will you pay most attention to?</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2013/03/08/where-do-the-most-hackers-come-from/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Concerned about NY Times type malware attack? Read this research.</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2013/01/31/concerned-about-ny-times-type-malware-attack-read-this-research/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2013/01/31/concerned-about-ny-times-type-malware-attack-read-this-research/#comments</comments>
		<pubDate>Thu, 31 Jan 2013 15:00:55 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=56</guid>
		<description><![CDATA[For those of you reading the latest news about &#8220;Advanced Persistent Threats&#8221; (aka. Advanced Targeted Attacks) you&#8217;ll want to read through a few notes that Gartner has published on this topic. See the following and examine what you can do about it today: - Best Practices for Mitigating Advanced Persistent Threats (Lawrence Pingree, Neil MacDonald) - Market Trends: [...]]]></description>
			<content:encoded><![CDATA[<p>For those of you reading the latest news about &#8220;Advanced Persistent Threats&#8221; (aka. Advanced Targeted Attacks) you&#8217;ll want to read through a few notes that Gartner has published on this topic. See the following and examine what you can do about it today:</p>
<p>- <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1898616&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threat">Best Practices for Mitigating Advanced Persistent Threats</a> (Lawrence Pingree, Neil MacDonald)</p>
<p>- <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2170815&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threat">Market Trends: Advanced Threat Protection Appliances, Worldwide, 2012</a> (Lawrence Pingree)</p>
<p>- <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=2285916&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threat">Competitive Landscape: Network Behavior Analysis Market, Worldwide, 2012</a> Lawrence Pingree)</p>
<p>- <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1767516&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threat">Malware, APTs, and the Challenges of Defense</a> (Dan Blum)</p>
<p>- <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1960615&amp;ref=QuickSearch&amp;sthkw=advanced+persistent+threat">Information Security Is Becoming a Big Data Analytics Problem</a> (Neil MacDonald)</p>
<p>- <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1534314&amp;ref=QuickSearch&amp;sthkw=lean+forward">Network Security Monitoring Tools for &#8216;Lean Forward&#8217; Security Programs</a> (John Pescatore, Lawrence Orens)</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2013/01/31/concerned-about-ny-times-type-malware-attack-read-this-research/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>An estimated $650 million dollars spent by Venture Capitalists on security start-ups in 2012</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2013/01/17/649-million-dollars-spent-by-venture-capitalists-on-security-startups-in-2012/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2013/01/17/649-million-dollars-spent-by-venture-capitalists-on-security-startups-in-2012/#comments</comments>
		<pubDate>Thu, 17 Jan 2013 22:03:38 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=41</guid>
		<description><![CDATA[Below is a list of estimated venture capital (VC) funds provided to security start-up companies in 2012. A surprising total estimate of $649 million dollars were invested in 2012. Please feel free to comment if you know of any others. Note: The table below are Gartner Estimates (actual numbers may vary). Company Name 2012 (Millions USD) Norse [...]]]></description>
			<content:encoded><![CDATA[<p>Below is a list of estimated venture capital (VC) funds provided to security start-up companies in 2012. A surprising total estimate of $649 million dollars were invested in 2012. Please feel free to comment if you know of any others.</p>
<p>Note: The table below are Gartner Estimates (actual numbers may vary).</p>
<table width="271" border="0" cellspacing="0" cellpadding="0">
<col span="2" width="64" />
<col width="143" />
<tbody>
<tr>
<td colspan="2" width="128" height="20">Company Name</td>
<td width="143">2012 (Millions USD)</td>
</tr>
<tr>
<td colspan="2" height="20">Norse Corporation</td>
<td align="right">3.5</td>
</tr>
<tr>
<td height="20">Tenable</td>
<td></td>
<td align="right">50</td>
</tr>
<tr>
<td height="20">zScaler</td>
<td></td>
<td align="right">38</td>
</tr>
<tr>
<td height="20">Mocana</td>
<td></td>
<td align="right">25</td>
</tr>
<tr>
<td height="20">Lockpath</td>
<td></td>
<td align="right">6</td>
</tr>
<tr>
<td colspan="2" height="20">Alienvault</td>
<td align="right">30</td>
</tr>
<tr>
<td height="20">Bit9</td>
<td></td>
<td align="right">34.5</td>
</tr>
<tr>
<td colspan="2" height="20">Alarm.com</td>
<td align="right">136</td>
</tr>
<tr>
<td colspan="2" height="20">Alertlogic</td>
<td align="right">12</td>
</tr>
<tr>
<td colspan="2" height="20">Xceedium</td>
<td align="right">7.5</td>
</tr>
<tr>
<td height="20">Unikey</td>
<td></td>
<td align="right">1.5</td>
</tr>
<tr>
<td height="20">Bromium</td>
<td></td>
<td align="right">30</td>
</tr>
<tr>
<td colspan="2" height="20">Securekey</td>
<td align="right">30</td>
</tr>
<tr>
<td colspan="2" height="20">AnchorFree</td>
<td align="right">52</td>
</tr>
<tr>
<td height="20">Pindrop</td>
<td></td>
<td align="right">1</td>
</tr>
<tr>
<td colspan="2" height="20">Appthority</td>
<td align="right">6.25</td>
</tr>
<tr>
<td colspan="2" height="20">41st Parameter</td>
<td align="right">13</td>
</tr>
<tr>
<td colspan="2" height="20">Cloudpassage</td>
<td align="right">14</td>
</tr>
<tr>
<td colspan="2" height="20">IntrinsicID</td>
<td align="right">6.57</td>
</tr>
<tr>
<td height="20">Veracode</td>
<td></td>
<td align="right">30</td>
</tr>
<tr>
<td colspan="2" height="20">Shape Security</td>
<td align="right">6</td>
</tr>
<tr>
<td colspan="2" height="20">Itadsecurity</td>
<td align="right">0.07</td>
</tr>
<tr>
<td colspan="2" height="20">Watchdox</td>
<td align="right">9</td>
</tr>
<tr>
<td colspan="2" height="20">CloudLock</td>
<td align="right">8.7</td>
</tr>
<tr>
<td colspan="2" height="20">ThreatMetrix</td>
<td align="right">18</td>
</tr>
<tr>
<td colspan="2" height="20">StoptheHacker</td>
<td align="right">1.1</td>
</tr>
<tr>
<td colspan="2" height="20">Duo Security</td>
<td align="right">5</td>
</tr>
<tr>
<td height="20">Vaultive</td>
<td></td>
<td align="right">10</td>
</tr>
<tr>
<td colspan="2" height="20">CrowdStrike</td>
<td align="right">26</td>
</tr>
<tr>
<td colspan="2" height="20">LookingGlass</td>
<td align="right">5</td>
</tr>
<tr>
<td height="20">Accellion</td>
<td></td>
<td align="right">13.4</td>
</tr>
<tr>
<td colspan="2" height="20">Solera Networks</td>
<td align="right">20</td>
</tr>
<tr>
<td colspan="2" height="20">Stormpath</td>
<td align="right">1.5</td>
</tr>
<tr>
<td height="20"></td>
<td>Total</td>
<td align="right">650.59</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2013/01/17/649-million-dollars-spent-by-venture-capitalists-on-security-startups-in-2012/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Morning Coffee Thoughts: Quote of the day</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2012/10/16/morning-coffee-thoughts-quote-of-the-day/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2012/10/16/morning-coffee-thoughts-quote-of-the-day/#comments</comments>
		<pubDate>Tue, 16 Oct 2012 14:36:45 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=36</guid>
		<description><![CDATA[&#8220;There are a billions of un-executed ideas  each day in the world, only those who evoke their vision create a chance to progress themselves or the people around them.&#8221; &#8211; Lawrence Pingree]]></description>
			<content:encoded><![CDATA[<p>&#8220;There are a billions of un-executed ideas  each day in the world, only those who evoke their vision create a chance to progress themselves or the people around them.&#8221; &#8211; Lawrence Pingree</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2012/10/16/morning-coffee-thoughts-quote-of-the-day/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Software Defined Networks</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2012/07/19/software-defined-networks/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2012/07/19/software-defined-networks/#comments</comments>
		<pubDate>Thu, 19 Jul 2012 23:00:04 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=29</guid>
		<description><![CDATA[Some rambling brainstorming on software defined networks&#8230;. My sense is that most cloud service providers and enterprises will likely gravitate their preference to the hardware or hypervisor infrastructure provider rather than a third party software provider. My position stems from a belief that a strong relative background in networking or a closely tied hypervisor is [...]]]></description>
			<content:encoded><![CDATA[<p>Some rambling brainstorming on software defined networks&#8230;.</p>
<p>My sense is that most cloud service providers and enterprises will likely gravitate their preference to the hardware or hypervisor infrastructure provider rather than a third party software provider. My position stems from a belief that a strong relative background in networking or a closely tied hypervisor is likely to be preferred by customers over a third party software defined network provider that has limited deployment time in the networking industry.  Personally when I receive inquiry on the topic of proper zoning within a virtualization infrastructure.  I generally gravitate towards the infrastructure provider over third parties as the provider of network segmentation (see Gartner&#8217;s Burton research on &#8220;Zones&#8221;). I lean towards the traditionalist path with physical versus software based zoning for sensitive security zones rather than deployment within a single hypervisor environment. This is likely also why the recent FedRamp program does not intend to move sensitive workloads into Fedramp certified entities. In general I question the ability of a third-party software packages to deliver all of the adequate network technologies within a virtualization infrastructure one step removed from the traditional network infrastructure providers or the hypervisor provider as they likely have divergent business goals for product stickiness and meeting contractual obligations of providing high stability. I&#8217;m interested in hearing from you, what do you feel are the security risks or operational risks of relying on a third party software defined network provider and what would you prefer?</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2012/07/19/software-defined-networks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Official FedRamp Launch</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2012/06/07/official-fedramp-launch/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2012/06/07/official-fedramp-launch/#comments</comments>
		<pubDate>Thu, 07 Jun 2012 21:03:01 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=27</guid>
		<description><![CDATA[Today I received an official announcement that the FedRAMP officially launched today: Email states: &#8220;As of 9am on Wednesday, June 6th, 2012, the Federal Risk and Authorization Management Program (FedRAMP) Program Management Office (PMO) achieved Initial Operating Capability. As a part of IOC, the FedRAMP PMO is now accepting applications for provisional authorization of cloud [...]]]></description>
			<content:encoded><![CDATA[<p>Today I received an official announcement that the FedRAMP officially launched today:</p>
<p>Email states:</p>
<p>&#8220;As of 9am on Wednesday, June 6th, 2012, the Federal Risk and Authorization Management Program (FedRAMP) Program Management Office (PMO) achieved Initial Operating Capability. As a part of IOC, the FedRAMP PMO is now accepting applications for provisional authorization of cloud systems. The application is currently housed on <a href="http://fedramp.gov/" target="_blank">fedramp.gov</a> and can be accessed via the following URL: <a href="http://www.gsa.gov/portal/content/125991" target="_blank">http://www.gsa.gov/portal/content/125991</a>&#8220;</p>
<p>So now all those cloud providers can chop chop their way into the federal government GSA Schedule. Happy Selling!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2012/06/07/official-fedramp-launch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Advanced Persistent Threats Need Advanced Persistent Security Programs</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2012/01/18/advanced-persistent-threats-need-advanced-persistent-security-programs/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2012/01/18/advanced-persistent-threats-need-advanced-persistent-security-programs/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 23:20:58 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=17</guid>
		<description><![CDATA[The other day, I was thinking that I&#8217;d love to change the marketing hype around Advanced Persistent Threats, whats really more relevant for customers is to pay attention to what they MUST do to address targeted attacks and one could call the technique an &#8220;Advanced Persistent Security Program&#8221; Advanced = Continuously Improving Controls Persistent = [...]]]></description>
			<content:encoded><![CDATA[<p>The other day, I was thinking that I&#8217;d love to change the marketing hype around Advanced Persistent Threats, whats really more relevant for customers is to pay attention to what they MUST do to address targeted attacks and one could call the technique an &#8220;Advanced Persistent Security Program&#8221;</p>
<p>Advanced = Continuously Improving Controls<br />
Persistent = Continuously Monitoring Controls<br />
Security = Security Controls as they relate to addressing risks and threats<br />
Program = Apply the prior concepts to the overall security program from budget, organizational structure and how we operate security.</p>
<p>More to follow in my research but thought, what would I do to change this marketing mantra <img src='http://blogs.gartner.com/lawrence-pingree/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>If interested, I just published a best practices research note called &#8220;<a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=256&amp;mode=2&amp;PageID=2350940&amp;resId=1898616&amp;ref=QuickSearch&amp;sthkw=pingree" target="_blank">Best Practices for Mitigating Advanced Persistent Threats</a>&#8220;</p>
<div style="width: 450px;padding: 3px;background-color: #ffffff;overflow: auto;text-align: center;color: #000000;border: 0px 0px 2px 2px dashed grey"><textarea></textarea>AfrikaansAlbanianArabicArmenianAzerbaijaniBasqueBelarusianBulgarianCatalanChinese (Simplified)Chinese (Traditional)CroatianCzechDanishDetect languageDutchEnglishEstonianFilipinoFinnishFrenchGalicianGeorgianGermanGreekHaitian CreoleHebrewHindiHungarianIcelandicIndonesianIrishItalianJapaneseKoreanLatinLatvianLithuanianMacedonianMalayMalteseNorwegianPersianPolishPortugueseRomanianRussianSerbianSlovakSlovenianSpanishSwahiliSwedishThaiTurkishUkrainianUrduVietnameseWelshYiddish<span style="font-weight: bold;cursor: pointer;color: lightgrey">⇄</span>AfrikaansAlbanianArabicArmenianAzerbaijaniBasqueBelarusianBulgarianCatalanChinese (Simplified)Chinese (Traditional)CroatianCzechDanishDutchEnglishEstonianFilipinoFinnishFrenchGalicianGeorgianGermanGreekHaitian CreoleHebrewHindiHungarianIcelandicIndonesianIrishItalianJapaneseKoreanLatinLatvianLithuanianMacedonianMalayMalteseNorwegianPersianPolishPortugueseRomanianRussianSerbianSlovakSlovenianSpanishSwahiliSwedishThaiTurkishUkrainianUrduVietnameseWelshYiddish</p>
<div style="text-align: left;background-color: #ebeff9">Detect language » English</div>
<div style="width: 444px;padding: 2px;background-color: #ffffff;text-align: justify;border: 1px solid grey"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2012/01/18/advanced-persistent-threats-need-advanced-persistent-security-programs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Next-Generation Virtualized Malware</title>
		<link>http://blogs.gartner.com/lawrence-pingree/2011/11/04/next-generation-virtualized-malware/</link>
		<comments>http://blogs.gartner.com/lawrence-pingree/2011/11/04/next-generation-virtualized-malware/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 21:40:58 +0000</pubDate>
		<dc:creator>Lawrence Pingree</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/lawrence-pingree/?p=6</guid>
		<description><![CDATA[I thought I would start my blog with a bang by concluding that it may be possible that the next major threat we all face may not just be the fact that we have virtual workloads or virtualized infrastructure, it could be the virtualization capability itself that may be used against us to deploy malwares [...]]]></description>
			<content:encoded><![CDATA[<p>I thought I would start my blog with a bang by concluding that it may be possible that the next major threat we all face may not just be the fact that we have virtual workloads or virtualized infrastructure, it could be the virtualization capability itself that may be used against us to deploy malwares or malicious operating systems.</p>
<p>It may be entirely possible to auto-deploy a malicious virtual image and run it on a host&#8230;&#8230; once deployed, what could it do?</p>
<p>Malware capabilities:</p>
<p>With a complete operating system downloaded onto the target system  just about anything could be possible including surreptitious network  monitoring, network information gathering, data grabbing, vulnerability  scanning from inside the network as well as just about anything else  including forming an outbound virtual private network to use as a way  inside the internal network.  Add encryption to the scenario by  encrypting the virtualized drives used by the virtual host and it now  becomes almost unstoppable.</p>
<p>Let&#8217;s walk through this a bit by examining how this may be possible:</p>
<ol>
<li>Create a malware payload which consists of a virtual machine player and an infected image or an image created with hacker tools installed on it.</li>
<li>Craft a zero day attack to infect a host with a file dropper to download the image and player.</li>
<li>Spread the malware infection using a specially crafted social engineering based e-mail to induce your target to click and execute your zero day and deploy the malware .</li>
<li>Have the malware download dropped files containing a virtual machine player (with command line capabilities) along with the malicious image you created in the first step.</li>
<li>Launch your newly downloaded virtual machine image on targeted host as an installed service.</li>
<li>Use host memory and process obfuscation techniques to make the processes and memory hidden.</li>
</ol>
<p>A scary concept, one that many of us should think about and plan against.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/lawrence-pingree/2011/11/04/next-generation-virtualized-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
