Endpoint
4/7/2013
01:00 AM
Quick Hits
Quick Hits
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Tools And Strategies For File-Level Data Protection

Securing applications is helpful, but file-level protection can make data even more secure. Here's some advice on how to do it right

[Excerpted from "Tools and Strategies for File-Level Data Protection," a new report posted this week on Dark Reading's Application Security Tech Center.]

As security pros, we tend to overprotect the perimeter and underprotect the most basic and fundamental asset in our organizations: your simple, run-of-the-mill Word docs, spreadsheets and slide decks that are the lifeblood of our users and our organizations.

The real truth is that the biggest threat to your organization isn't an attack from some eastern European crimeware syndicate; your biggest threat is your own users. And it's not that your users are acting maliciously; it's just that they want to access their data from any device and from any location.

In many cases, users are taking advantage of new tools and apps to make that happen faster than security pros can stay on top of it. Many organizations have already lost control of vast amounts of sensitive corporate data, all because they've been concentrating their defenses, time and effort elsewhere.

The standard approach of using file and folder permissions to protect data is woefully inadequate. Standard file permissions do an adequate job of ensuring that only certain users can access certain data, but they don't prevent users who already have access from abusing their rights. And file permissions themselves can be too easily circumvented by admins or by users sharing credentials.

Today, cloud file sharing apps are introducing a completely new threat vector that few IT managers are properly accounting for. Just unleash the application intelligence capabilities of your firewall to see how bad the problem really is in your environment: You're likely to see a shocking number of your users syncing data to Box, Dropbox, Sky-Drive, Google Drive or some other cloud-based file sync tool.

One of the reasons that tools like Dropbox are so popular with users, aside from being free, is that they're really easy to use. Corporate employees get the concept of dropping a file in a certain folder and having it magically appear in their Dropbox online, and cloud encryption tools like BoxCryptor, Viivo and CloudFogger build on that ease of use by wrapping strong encryption around the files synchronized to Dropbox.

Cloud encryption tools are a simplistic but possibly compelling solution to many of the file protection problems currently plaguing IT. To find out more about these emerging technologies -- and other tools and techniques for file-level data protection -- download the free report.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-0460
Published: 2014-04-16
The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

CVE-2011-0993
Published: 2014-04-16
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.

CVE-2011-3180
Published: 2014-04-16
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

CVE-2011-4089
Published: 2014-04-16
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

CVE-2011-4192
Published: 2014-04-16
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."

Best of the Web