Risk
7/30/2012
12:51 PM
50%
50%

NIST Updates Computer Security Guides

Guidelines focus on wireless security and protecting mobile devices from intrusion.

10 New Mobile Government Apps
10 New Mobile Government Apps
(click image for larger view and for slideshow)
The National Institute of Standards and Technology has released updated guidance on how federal agencies and businesses can deal with network attacks and malware.

The advice comes in the form of two publications that have been revised to reflect the latest in security best practices: NIST's Guide to Intrusion Detection and Prevention Systems and Guide to Malware Incident Prevention and Handling for Desktop and Laptops. The agency is seeking public comments on the draft publications before releasing them in final form.

This is the first revision to the intrusion detection and prevention system (IDPS) guide since its original release in February 2007. The most substantive changes are in the areas of mobile devices and wireless networking, including the emergence of the 802.11n wireless standard.

"Wireless technology is used so much more than it used to be, and there are many more wireless threats now," said Karen Scarfone, a guest researcher at NIST and co-author of the revised Guide to Intrusion Detection and Prevention Systems.

[ For more on NIST's updated security guidelines, see Uncle Sam Wants To Secure Your Smartphone. ]

In other areas, intrusion detection hasn't changed much, according to Scarfone. In her research, she said, some sources said IDPSs aren't "quite as valuable as they used to be," raising questions of whether they need to improve or are the right tools at all.

The guide covers wireless, network-based, and host-based intrusion detection, as well as network behavior analysis, architecture, detection methodologies, and security capabilities. "They'll monitor IP addresses, protocols--it could even be a geographic location--to try to assess whether activity is benign or malicious," Scarfone said. The deadline for filing comments on the draft IDPS guide is August 31.

NIST also revised its Guide to Malware Incident Prevention and Handling for Desktops and Laptops, which has been updated to correspond with a refreshed version of its Computer Security Incident Handling Guide, expected to be issued in final form later this summer.

Scarfone, who co-authored both guides, said the malware incident guide was updated "to take today's threats into account." Whereas malware in the past tended to be fast-spreading and easy to spot, it now spreads more slowly, eventually leading to exfiltration of sensitive data, she said.

Earlier this month, NIST issued new guidelines for securing mobile devices.

The Office of Management and Budget demands that federal agencies tap into a more efficient IT delivery model. The new Shared Services Mandate issue of InformationWeek Government explains how they're doing it. Also in this issue: Uncle Sam should develop an IT savings dashboard that shows the returns on its multibillion-dollar IT investment. (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1449
Published: 2014-12-25
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.

CVE-2014-2217
Published: 2014-12-25
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.

CVE-2014-3971
Published: 2014-12-25
The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote attackers to cause a denial of service (daemon crash) by attempting authentication with an invalid X.509 client certificate.

CVE-2014-7193
Published: 2014-12-25
The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtain sensitive information, and potentially obtain the ability to spoof requests to non-CORS routes, via a crafted web site ...

CVE-2014-7300
Published: 2014-12-25
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.