Corporate Blog

Archives: August, 2010

Microsoft (and others’) DLL Load Hijacking Bug – Remote Exploit Possible

Posted By | August 25th, 2010

Microsoft’s  security advisory that came out Monday is a bit vague on this bug, but the issue is a bit more serious matter and deserves security pro’s attention, especially if your company uses in-house applications.  MS KB is here.  The issue itself is not new, but recently published research that details remote attack vectors is. … Continue reading

No Comments »

Tags: , , , ,
Filed In: IT Infrastructure Security

Management Style – A Foundational Component of Information Assurance

Posted By | August 23rd, 2010

Management style is an area of operations that has more impact on an organization’s security posture than most would assume. There are a lot of policy level decisions with legal ramifications that management is faced with on a daily basis as part of their overarching responsibilities. Driving standards and approved operating procedure from the management level can exude some fantastic benefits if approached in a suitable manner. Creating and adhering to well-developed processes takes a lot of the guess work out of daily activities of employees, and moreover, provides a solid foundation to ensure that all requirements are being met and that all employees know the rules of the game. Continue reading

No Comments »

Tags: , , , , ,
Filed In: Business Practices, Management Practices

IATAC SME Program: Approved Products Lists?

Posted By | August 18th, 2010

As part of the IATAC SME (Subject Matter Expert) Program, we are occasionally forwarded questions and asked for our input.  The most recent request for information was interesting, so I thought I’d share my response here. Due to Federal Information Security Management Act (FISMA) Certification and Accreditation (C&A) requirements, the government and military operate using … Continue reading

No Comments »

Tags: , , , , , ,
Filed In: Business Practices, IATAC SME Program, IT Infrastructure Security, Software and Automation

Kaspersky Labs reports new SMS Trojan for Android OS

Posted By | August 17th, 2010

“The new malicious program penetrates smartphones running Android in the guise of a harmless media player application. Users are prompted to install a file of just over 13 KB with the standard Android extension *.APK. Once installed on the phone, the Trojan uses the system to begin sending SMSs to premium rate numbers without the … Continue reading

No Comments »

Tags: , , ,
Filed In: Malware, Mobile

Proso CEO to be Published in Fall 2010 IATAC Newsletter

Posted By | August 16th, 2010

Proso CEO, Chris Merritt, to have another article published in the IATAC Newsletter in their Fall 2010 issue.  This free quarterly publication features timely articles from the IA community.  These articles are solicited from such organizations as OSD/Joint Staff, the Combatant Commands, Services, Systems Commands, Government R&D Labs and Academia.  Each issue also features regular … Continue reading

No Comments »

Tags: , ,
Filed In: News & Events, Press Releases

Analyze Malware In The Time It Takes To Grab a Cup Of Coffee

Posted By | August 12th, 2010

Malware analysis is not a skill that every IT security professional has. It comes with a heavy amount of programming experience, an understanding of assembly, computer memory, debuggers and decompilers. Malware analysis can take a lot of time and skill, and is usually not done by organizations’ security staff. The staff leaves it to AV … Continue reading

1 Comment »

Tags: , ,
Filed In: IT Infrastructure Security, Security Testing

The Perfect Storm – A Story of Snort False Positive Verification

Posted By | August 10th, 2010

I recently had an opportunity to do some research into a large volume of Snort IDS rules that had begun to fire (to the tune of millions of alerts a day) for an organization.  At first glance these alerts appeared to be false positives, but they smelled like a lazy application DDoS attempt from some … Continue reading

No Comments »

Tags: ,
Filed In: IT Infrastructure Security, Security Testing

Automation in Compliance and Information Security

Posted By | August 9th, 2010

With the launch of an updated version of proGD (1.0.0.19), a software we developed to automate the manual process of scanning with DISA Gold Disk, a DoD MS Windows scanner, I thought it made sense to publish a brief post about how automation can really lighten the load of information security professionals in any organization. … Continue reading

No Comments »

Tags: , ,
Filed In: Software and Automation