Risk
9/25/2008
11:15 AM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Time To Send Out For Security Help?

Providers are looking to provide everything from e-mail security to log management, all from the cloud.

Security software as a service is increasing in popularity in tandem with the growth in cloud computing, as emerging providers promise to lower costs while increasing security.

Attacks on the scale of a full-on domain hijacking are the nightmare scenario, and outsourced protection against DNS flaws is currently limited to using managed services that patch DNS for you. However, there are other proactive steps companies can take to protect data. Cloud-based Web security companies such as Purewire and Zscaler offer a host of services, including URL filtering, anti-malware, and antivirus, and are seeking to protect against emerging browser-based attacks. Even Google is offering basic security services based on technology from SafeScan.

Purewire and Zscaler can detect malware that has been placed on domains that have been hijacked, and they maintain their own DNS servers. Webroot Software and Savvis provide antivirus and anti-malware scanning of e-mail. Both take advantage of the scalability of the cloud and pitch a "no-capital-expense" service; organizations no longer need to update mail gateways with performance-crimping scanning software. Savvis also performs spam filtering in the cloud, competing with Google's Postini service.

Many have tried--and failed--to sell outsourced log management. Still, Savvis, SecureWorks, and Verizon Business Services are all giving it a go with a new twist, leveraging the cloud. Decreased bandwidth, storage, and hosting costs and increased availability lower the barriers to entry for these companies. It's worth noting that SecureWorks is one of the few remaining original players in the managed security services arena offering log management.

What's next? We expect more vulnerability scanning, Web application firewalls, and even outsourced firewalls in the form of cloud-based offerings.

Return to the story:
Locking Down The Cloud: Why DNS Security Must Be Improved

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6856
Published: 2014-10-02
The AHRAH (aka com.vet2pet.aid219426) application 219426 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6857
Published: 2014-10-02
The Car Wallpapers HD (aka com.arab4x4.gallery.app) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6858
Published: 2014-10-02
The Mostafa Shemeas (aka com.mostafa.shemeas.website) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6859
Published: 2014-10-02
The Daum Maps - Subway (aka net.daum.android.map) application 3.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6860
Published: 2014-10-02
The Trial Tracker (aka com.etcweb.android.trial_tracker) application 1.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Chris Hadnagy, who hosts the annual Social Engineering Capture the Flag Contest at DEF CON, will discuss the latest trends attackers are using.