Wednesday, June 17, 2015

Tabula Rosa Systems Security Bulletin For 6/17/15 - Adobe Releases Security Updates for Multiple Products

National Cyber Awareness System:
06/16/2015 07:17 PM EDT

Original release date: June 16, 2015
Adobe has released security updates for Adobe Photoshop Creative Cloud (CC) and Bridge CC to address multiple vulnerabilities. Exploitation of one of these vulnerabilities may allow a remote attacker to take control of an affected system.
US-CERT encourages users and administrators to review Adobe Security Bulletins APSB15-12 and APSB15-13 and apply the necessary updates.
===============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tuesday, June 16, 2015

Tabula Rosa Systems Technical Term Of The Day - Mini Botnet


======================================================

Micro-botnet (mini-botnet or baby botnet)
Posted by
Margaret Rouse
A micro-botnet, also called a mini-botnet or baby botnet, is a small network of Internet-connected computers that have been hijacked to attack specific companies or individuals within a company.

A micro-botnet, also called a mini-botnet or baby botnet, is a small network of Internet-connected computers that have been hijacked to attack specific companies or individuals within a company. Micro-botnets are often used in corporate espionage. Typically, the bots will monitor the enterprise network to identify key individuals and assets and target them for attack. The bots are used to seek out information like financial authentication passwords or data that can be sold to competitors.
Network Security Visibility
Because there are usually fewer than one hundred computers to control in a micro-botnet, attackers can fine-tune an exploit to circumvent an enterprise intrusion detection system (IDS) or firewall. A successful micro-botnet infiltration often depends on social engineering because it's much easier to gain access and hide a small botnet's activities when the attacker has legitimate credentials. Red flags indicating the presence of a micro-botnet include new spikes in an individual's normal traffic patterns or quickly accelerating rights in a specific end user's permissions.
Read more:
According to Gunter Ollmann, VP of research at Damballa, small botnets account for 57 percent of all botnets.
This was first published in October 2009
=====================================================**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Monday, June 15, 2015

Tabula Rosa Product Of The Day - ExtraHop - A Case Study For A SaaS

    
====================================================
ExtraHop is a prime product for Tabula Rosa. It is a proven tool for many companies to analyze their transactions through their networks and applications. Some of the key elements are mentioned below. For anyone interested in the product, please contact Tabula Rosa through the methods mentioned below.
 ============================================


The Problem
The operations and systems administration staff of a 250-employee medical device manufacturer were tasked with maintaining the company's cloud-based applications to understand usage patterns, resource consumption, and to protect against unauthorized use of unsanctioned applications.
The IT team didn't know all applications in use, the total amount of traffic consumed by their cloud and SaaS based applications, had no visibility into end-user performance, and didn't have the visibility to segment on-premises from cloud-based applications. They depended exclusively on their SaaS and cloud providers for performance information, found troubleshooting difficult, and had significant concerns regarding compliance and data loss through applications like file sharing services. They also found capacity planning a challenge because they lacked a comprehensive picture of application resource consumption.
Desired Outcome
·         A simple way to discover and measure SaaS and cloud-based applications
·         Information that would definitively show resource consumption by type
·         A means for continuous observation to prevent unsanctioned applications
·         Information on SaaS user performance and usage for better SLA management
The IT department realized that these cloud applications posed a serious vulnerability of data leakage, a vulnerability completely out of their hands. They needed to proactively investigate this shadow IT issue but without causing disruption to employees.


The Solution
The company deployed the ExtraHop platform behind a proxy that could decrypt their SaaS-based applications. Extending ExtraHop's Cloud Application Bundle, they quickly began measuring total transactions, performance, and bandwidth consumption on a per application as well as a per cloud category perspective.
The teams created cloud- and SaaS-specific dashboards correlated with internally observed behavior, creating a central source of information that exposed not only all requests, bytes, error codes and rates, but also provided definitive evidence showing performance from their users' perspective, not the SaaS provider's perspective. They modified their dashboards to be able to view end-user performance today compared to seven days ago, so they had an early warning system if their SaaS applications and end-user experience was trending positively or negatively.
They did the same with their on-premises based applications so they could compare and contrast resource consumption by application type. Not only could they diagnose top consumers that could be causing congestion and performance issues but they now had the trend data to inform future capacity needs.
Finally, they added a list of unsanctioned applications to their ExtraHop bundle as a proactive means to identify and act on any unauthorized activity. The compliance team and the CSO were relieved to know that they now had a proactive means to identify and act on any unauthorized activity.
User Impact
Instead of reactively responding to performance issues and being wholly dependent upon the SaaS provider, they were now in control and could hold their providers accountable which the CIO found invaluable. For the first time they had a means to definitively eliminate their own environment as the source of the problem and could identify the specific resources (URIs) that were degraded and correlate that with their overall network performance and utilization by all other applications.
The Director of IT Operations estimated that they've saved over 200 personnel hours annually in unproductive SaaS troubleshooting efforts. The manufacturer was able to demonstrate that 80 users accessed this application only a few times a year so they were able to reduce several of their SaaS application license counts, saving an estimated $20,000 per year. Usage information provided by one of their SaaS providers was used to determine the annual license fee which was, "a bit like the fox guarding the hen house" as the Director of IT said. With ExtraHop's trending data the Director of IT said he feels 12 months ahead on their planning curve. They have a complete understanding of their capacity needs as they grow and can prepare more accurate budgets based on both performance and usage. They can also audit all user, network and application activity to be sure employees are using only authorized cloud file-sharing services.
They have started to expand ExtraHop's security monitoring capabilities—identifying and correlating anomalous behavior focusing first on all engineering file access by client, directory, file, frequency, and volume and correlating that information with other user behavior like outbound activity. Not only do they have a solid perimeter and internal controls for protection, now they can perform real-time internal activity surveillance, putting them in a much stronger position to protect their intellectual property.

=====================================================
**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================


Tabula Rosa Security Bulletin For 6/15/15 - SB15-166: Vulnerability Summary for the Week of June 8, 2015



National Cyber Awareness System:
06/15/2015 06:26 AM EDT

Original release date: June 15, 2015
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.

===============================================
**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Sunday, June 14, 2015

Tabula Rosa Systems Special Blog - Happy Flag Day! - Flag Etiquette Do's and Don'ts

Most U.S. citizens do not know proper flag etiquette. I presume that they would not know flag for other countries as well. My theory is that most countries have their own similar set of rules. At some point soon, I will write a blog on this topic since I have never seen any document about flag Netiquette. I wanted to include this article since I felt one should be careful with displaying flags in social media.


===============================================
 Flag Etiquette Do's and Don'ts From www.military .com

The U.S. Flag Code formalizes and unifies the traditional ways in which we give respect to the flag, also contains specific instructions on how the flag is not to be used.
The following is a list of do’s and don’ts associated with Old Glory, the U.S. Flag.
When displaying the flag, DO the following:
    • Display the U.S. flag from sunrise to sunset on buildings and stationary flagstaffs in the open. When a patriotic effect is desired the flag may be displayed 24-hours a day if properly illuminated during the hours of darkness.
    • When placed on a single staff or lanyard, place the U.S. Flag above all other flags.
    • When flags are displayed in a row, the U.S. flag goes to the observer’s left. Flags of other nations are flown at same height. State and local flags are traditionally flown lower.
    • When used during a marching ceremony or parade with other flags, the U.S. Flag will be to the observer’s left.
    • On special days, the flag may be flown at half-staff. On Memorial Day it is flown at half-staff until noon and then raised.
    • When flown at half-staff, should be first hoisted to the peak for an instant and then lowered to the half-staff position. The flag should be again raised to the peak before it is lowered for the day. By "half-staff" is meant lowering the flag to one-half the distance between the top and bottom of the staff. Crepe streamers may be affixed to spear heads or flagstaffs in a parade only by order of the President of the United States.
    • When the flag is displayed over the middle of the street, it should be suspended vertically with the union (blue field of stars) to the north in an east and west street or to the east in a north and south street.
    • When placed on a Podium the flag should be placed on the speaker’s right or the staging area. Other flags should be placed to the left.
    • When displayed either horizontally or vertically against a wall (or other flat surface), the union (blue field of stars) should be uppermost and to the flag's own right, that is, to the observer's left.
    • When displayed in a window it should be displayed in the same way -- with the union or blue field to the left of the observer in the street.
    • When the flag is displayed on a car, the staff shall be fixed firmly to the chassis or clamped to the right fender.
    • When the flag is used to cover a casket, it should be so placed that the union is at the head and over the left shoulder. The flag should not be lowered into the grave or allowed to touch the ground.
When saluting the flag DO the following:
    • All persons present in uniform (military, police, fire, etc.) should render the military salute. Members of the armed forces and veterans who are present but not in uniform may render the military salute.
    • All other persons present should face the flag and stand at attention with their right hand over the heart, or if applicable, remove their headdress with their right hand and hold it at the left shoulder, the hand being over the heart.
When stowing or disposing of the flag, DO the following:
    • Fold in the traditional triangle for stowage, never wadded up.
    • The VFW offers the following instructions for properly disposing of a worn flag:
      • The flag should be folded in its customary manner.
      • It is important that the fire be fairly large and of sufficient intensity to ensure complete burning of the flag.
      • Place the flag on the fire.
      • The individual(s) can come to attention, salute the flag, recite the Pledge of Allegiance and have a brief period of silent reflection.
      • After the flag is completely consumed, the fire should then be safely extinguished and the ashes buried.
      • Please make sure you are conforming to local/state fire codes or ordinances.
Quick list of Flag Etiquette Don’ts:
    • Don’t dip the U.S. Flag for any person, flag, or vessel.
    • Don’t let the flag touch the ground.
    • Don’t fly flag upside down unless there is an emergency.
    • Don’t carry the flag flat, or carry things in it.
    • Don’t use the flag as clothing.
    • Don’t store the flag where it can get dirty.
    • Don’t use it as a cover.
    • Don’t fasten it or tie it back. Always allow it to fall free.
    • Don’t draw on, or otherwise mark the flag.
    • Don’t use the flag for decoration. Use bunting with the blue on top, then white, then red.

**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:
www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================