11:15 AM
Connect Directly

Time To Send Out For Security Help?

Providers are looking to provide everything from e-mail security to log management, all from the cloud.

Security software as a service is increasing in popularity in tandem with the growth in cloud computing, as emerging providers promise to lower costs while increasing security.

Attacks on the scale of a full-on domain hijacking are the nightmare scenario, and outsourced protection against DNS flaws is currently limited to using managed services that patch DNS for you. However, there are other proactive steps companies can take to protect data. Cloud-based Web security companies such as Purewire and Zscaler offer a host of services, including URL filtering, anti-malware, and antivirus, and are seeking to protect against emerging browser-based attacks. Even Google is offering basic security services based on technology from SafeScan.

Purewire and Zscaler can detect malware that has been placed on domains that have been hijacked, and they maintain their own DNS servers. Webroot Software and Savvis provide antivirus and anti-malware scanning of e-mail. Both take advantage of the scalability of the cloud and pitch a "no-capital-expense" service; organizations no longer need to update mail gateways with performance-crimping scanning software. Savvis also performs spam filtering in the cloud, competing with Google's Postini service.

Many have tried--and failed--to sell outsourced log management. Still, Savvis, SecureWorks, and Verizon Business Services are all giving it a go with a new twist, leveraging the cloud. Decreased bandwidth, storage, and hosting costs and increased availability lower the barriers to entry for these companies. It's worth noting that SecureWorks is one of the few remaining original players in the managed security services arena offering log management.

What's next? We expect more vulnerability scanning, Web application firewalls, and even outsourced firewalls in the form of cloud-based offerings.

Return to the story:
Locking Down The Cloud: Why DNS Security Must Be Improved

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
E-Commerce Security: What Every Enterprise Needs to Know
The mainstream use of EMV smartcards in the US has experts predicting an increase in online fraud. Organizations will need to look at new tools and processes for building better breach detection and response capabilities.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio