Endpoint
4/7/2013
01:00 AM
Dark Reading
Dark Reading
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Tools And Strategies For File-Level Data Protection

Securing applications is helpful, but file-level protection can make data even more secure. Here's some advice on how to do it right

[Excerpted from "Tools and Strategies for File-Level Data Protection," a new report posted this week on Dark Reading's Application Security Tech Center.]

As security pros, we tend to overprotect the perimeter and underprotect the most basic and fundamental asset in our organizations: your simple, run-of-the-mill Word docs, spreadsheets and slide decks that are the lifeblood of our users and our organizations.

The real truth is that the biggest threat to your organization isn't an attack from some eastern European crimeware syndicate; your biggest threat is your own users. And it's not that your users are acting maliciously; it's just that they want to access their data from any device and from any location.

In many cases, users are taking advantage of new tools and apps to make that happen faster than security pros can stay on top of it. Many organizations have already lost control of vast amounts of sensitive corporate data, all because they've been concentrating their defenses, time and effort elsewhere.

The standard approach of using file and folder permissions to protect data is woefully inadequate. Standard file permissions do an adequate job of ensuring that only certain users can access certain data, but they don't prevent users who already have access from abusing their rights. And file permissions themselves can be too easily circumvented by admins or by users sharing credentials.

Today, cloud file sharing apps are introducing a completely new threat vector that few IT managers are properly accounting for. Just unleash the application intelligence capabilities of your firewall to see how bad the problem really is in your environment: You're likely to see a shocking number of your users syncing data to Box, Dropbox, Sky-Drive, Google Drive or some other cloud-based file sync tool.

One of the reasons that tools like Dropbox are so popular with users, aside from being free, is that they're really easy to use. Corporate employees get the concept of dropping a file in a certain folder and having it magically appear in their Dropbox online, and cloud encryption tools like BoxCryptor, Viivo and CloudFogger build on that ease of use by wrapping strong encryption around the files synchronized to Dropbox.

Cloud encryption tools are a simplistic but possibly compelling solution to many of the file protection problems currently plaguing IT. To find out more about these emerging technologies -- and other tools and techniques for file-level data protection -- download the free report.

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-6651
Published: 2014-07-31
Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

CVE-2014-2970
Published: 2014-07-31
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of CVE-2014-5139, and has also been used to refer to an unrelated topic that is currently outside the scope of CVE. This unrelated topic is a LibreSSL code change adding functionality ...

CVE-2014-3488
Published: 2014-07-31
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

CVE-2014-3554
Published: 2014-07-31
Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

CVE-2014-5171
Published: 2014-07-31
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

Best of the Web
Dark Reading Radio