Endpoint
4/7/2013
01:00 AM
Dark Reading
Dark Reading
Quick Hits
50%
50%

Tools And Strategies For File-Level Data Protection

Securing applications is helpful, but file-level protection can make data even more secure. Here's some advice on how to do it right

[Excerpted from "Tools and Strategies for File-Level Data Protection," a new report posted this week on Dark Reading's Application Security Tech Center.]

As security pros, we tend to overprotect the perimeter and underprotect the most basic and fundamental asset in our organizations: your simple, run-of-the-mill Word docs, spreadsheets and slide decks that are the lifeblood of our users and our organizations.

The real truth is that the biggest threat to your organization isn't an attack from some eastern European crimeware syndicate; your biggest threat is your own users. And it's not that your users are acting maliciously; it's just that they want to access their data from any device and from any location.

In many cases, users are taking advantage of new tools and apps to make that happen faster than security pros can stay on top of it. Many organizations have already lost control of vast amounts of sensitive corporate data, all because they've been concentrating their defenses, time and effort elsewhere.

The standard approach of using file and folder permissions to protect data is woefully inadequate. Standard file permissions do an adequate job of ensuring that only certain users can access certain data, but they don't prevent users who already have access from abusing their rights. And file permissions themselves can be too easily circumvented by admins or by users sharing credentials.

Today, cloud file sharing apps are introducing a completely new threat vector that few IT managers are properly accounting for. Just unleash the application intelligence capabilities of your firewall to see how bad the problem really is in your environment: You're likely to see a shocking number of your users syncing data to Box, Dropbox, Sky-Drive, Google Drive or some other cloud-based file sync tool.

One of the reasons that tools like Dropbox are so popular with users, aside from being free, is that they're really easy to use. Corporate employees get the concept of dropping a file in a certain folder and having it magically appear in their Dropbox online, and cloud encryption tools like BoxCryptor, Viivo and CloudFogger build on that ease of use by wrapping strong encryption around the files synchronized to Dropbox.

Cloud encryption tools are a simplistic but possibly compelling solution to many of the file protection problems currently plaguing IT. To find out more about these emerging technologies -- and other tools and techniques for file-level data protection -- download the free report.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8148
Published: 2015-01-26
The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system bus and possibly execute arbitrary code with root privileges.

CVE-2014-8157
Published: 2015-01-26
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

CVE-2014-8158
Published: 2015-01-26
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

CVE-2014-9571
Published: 2015-01-26
Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter.

CVE-2014-9572
Published: 2015-01-26
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If youíre a security professional, youíve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.