Risk
7/15/2013
12:08 PM
50%
50%

In-Q-Tel, HyTrust Fight Insider Threats

CIA's investment arm cuts deal with HyTrust, maker of virtual appliance that monitors virtualized and cloud-based environments to spot insider abuses.

Military Drones Present And Future: Visual Tour
Military Drones Present And Future: Visual Tour
(click image for larger view and for slideshow)
The actions of Edward Snowden, the National Security Agency contract employee who has been leaking information on vast classified data-gathering programs carried out by the agency, has raised fresh questions about how to guard against risks from insiders exposing government secrets.

Agencies might take a cue from In-Q-Tel, the investment arm of the U.S. intelligence community, which said it is investing in a strategic partnership with HyTrust. The California firm offers a virtual appliance that acts as a gateway between systems administrators and their virtualized and cloud-based systems that can help identify the risk of insider abuses.

Although In-Q-Tel's action isn't likely in response to the Snowden incident, it does reflect growing efforts to deal more effectively with insider threats, and shore up the defenses of virtual infrastructure and cloud environments.

"The world does an appalling job of securing against inside threats -- they just care about the perimeter," said Eric Chiu, president and cofounder of HyTrust, in an interview with InformationWeek.

[ Did you know about the government trade in bugs? Read Bug Data Buys Businesses Intel From U.S. Government. ]

"What's really happened here is a wakeup call to government agencies and commercial companies that inside threats are real. Whether systems administrators are trying to steal information [or it's] outside threats that are trying to act like sys admins, you need a system to protect the crown jewels that make up your organization," he warned. "If people don't care about protecting data from the inside, you get what happened with Snowden."

HyTrust's virtual appliance monitors all administrative requests made to the virtual infrastructure and matches them to the organization's defined policies for access and allowable actions; the appliance allows requests to go through if they fit the policies, but denies them if they're inappropriate.

"That leads to a key piece of functionality -- continuous role-based monitoring and alerting," said Chiu. "Everything is being logged. We can compare what's happening against what is supposed to be happening. We can detect breaches with near 100% accuracy, and within seconds."

The IQT partnership is significant for HyTrust, he said, both in financial investment and market reach. As the agencies of the intelligence community move to virtual environments for their computing and data management, the need to protect that infrastructure -- and avoid another big breach -- becomes more urgent, he said.

"The assurance of critical infrastructure and data assets is paramount, and we believe that the HyTrust solution has the potential to greatly benefit our government customers," said Robert Ames, senior VP in charge of IQT's Information and Communication Technologies Practice, in a press release.

The HyTrust appliance works with both VMware (another investor, Chiu noted) and Cisco. "It's a great alignment point to have both of the biggest providers in the space," he said.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: just wondering...Thanx
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.