Working together, the two types of software can further help corporations defend themselves against attacks, the companies said.
More info: [url=http://zdnet.com.com/2100-1105_2-5124542.html]http://zdnet.com.com/2100-1105_2-5124542.html[/url]
Security News Curated from across the world
Working together, the two types of software can further help corporations defend themselves against attacks, the companies said.
More info: [url=http://zdnet.com.com/2100-1105_2-5124542.html]http://zdnet.com.com/2100-1105_2-5124542.html[/url]
The center is one of many that industries and their government liaisons formed since 1998 to share vulnerability information and alerts when incidents occur that affect critical infrastructure, such as telecommunications and banking.
Money from Treasury will allow the center to expand to serve the entire financial industry, department officials said. By the end of fiscal 2005, officials expect that the center will be funded entirely by membership fees, which range from $750 to $50,000 per year. Upgrades include:
* Enhancing the network so it can serve more than 30,000 institutions.
* A secure forum for real-time information sharing.
* Physical data threats to the cyberthreat information.
* Web-based warnings and alerts service
* Setting more than 16 performance metrics
More info: [url=http://www.fcw.com/fcw/articles/2003/1208/web-fsisac-12-10-03.asp]http://www.fcw.com/fcw/articles/2003/1208/web-fsisac-12-10-03.asp[/url]
The technologies include:
Core Security Technologies discovered that the Windows Workstation vulnerability announced by Microsoft last month could be exploited using the same type of data used by the SQL Slammer worm to spread across the Internet in just minutes. “We believe these new attack vectors make the vulnerability even more dangerous and critical as the proposed workarounds are not sufficient to close them and particularly because they outline a very plausible scenario for a highly efficient worm,” Ivan Arce, chief technology officer for security software maker Core Security Technologies, wrote in an e-mail to CNET News.com.
The company’s report also found that flaws in the Windows Messenger service, which allowed the MSBlast worm to spread this summer, could be exploited using the same “fire-and-forget” user datagram protocol (UDP) packets.
Core ST acknowledged that the patches will prevent the attacks and also urged people to apply the fixes.
More info: [url=http://zdnet.com.com/2100-1105_2-5118580.html]http://zdnet.com.com/2100-1105_2-5118580.html[/url]
The report, prepared for the House of Representatives’ Committee on Government Reform, found that almost all agencies had improved their computer-security grade since last year. However, several key federal departments continued to fail to adequately protect their networks and earned an “F.” Two agencies, the Department of Health and Human Services and the National Aeronautics and Space Administration, slipped in the rankings since 2002.
The newest department in the federal government, the Department of Homeland Security, got off to a bad start with an overall “F” for its computer security, despite the fact that securing the nation’s network is part of its mission.
Davis took the private sector to task for poor security overall as well. “The culture of our top-level chief executives in the private sector, and top executives in government, must be changed,” he said in the statement. “We must get those at the very top, the decision makers, the ones accountable to the shareholders, the customers or the electorate, to recognise that lack of network security in an organisation is a material weakness and one that deserves necessary resources and immediate action.”
This year, two agencies earned an “A”: the Nuclear Regulatory Commission and the National Science Foundation. Ironically, a privately maintained nuclear reactor under the NRC’s jurisdiction suffered an attack by the Slammer worm in early 2003.
More info: [url=http://www.silicon.com/management/government/0,39024677,39117281,00.htm]http://www.silicon.com/management/government/0,39024677,39117281,00.htm[/url]
The beta version of Windows XP Service Pack 2 is expected to be made available to testers soon via Microsoft’s developer Web site. The final version is expected to be released in the first half of next year, Microsoft said.
“The Windows XP SP2 beta is intended to provide software developers and IT professionals an opportunity to conduct early testing and to allow Microsoft to collect valuable customer feedback,” the software company said in a fact sheet it provided to reporters. “During this beta, Microsoft hopes to garner significant feedback from developers and IT professionals that will be incorporated into and improve the final product.” Microsoft said that the software will be made available to information technology managers and developers via the MSDN Web site, and the company also will test the software using a number of people who have registered to be beta testers. In all, there will be hundreds of thousands of testers, Microsoft said.
Among the security improvements in Service Pack 2 are a beefed-up version of Windows Firewall, previously called Internet Connection Firewall, and software designed to block pop-up ads and prevent the unintended downloading and installation of software. The company also turned off the Windows Messenger service, which had been abused by some hackers. The improved firewall will be turned on by default and is designed to prevent all ports from accepting information from outside networks, unless permitted to by an application.
Microsoft also said it has taken a number of steps to reduce a type of exploit known as a buffer overrun, but the company warned that it is probably impossible to completely eliminate such vulnerabilities. “Although no single technique can completely eliminate this type of vulnerability, Microsoft is employing a number of security technologies to reduce the likelihood and potential of an attack in a number of different ways,” Microsoft said.
Additionally, the company said the new Windows XP will make it easier for customers to turn on the automatic update feature, which downloads and installs critical updates automatically.
Microsoft stressed the importance of the additional security features for smaller businesses and consumers. All computers that are connected to the Internet need protection against network-based attacks like Blaster,” Microsoft said. The software maker has been under pressure to improve the security of Windows after a spate of high-profile attacks earlier this year.
The new Service Pack will upgrade Windows XP to support a later version of the short-range Bluetooth wireless technology, Microsoft said. It also includes a utility that makes it easier to connect a PC in a wide range of wireless hot spots, places where wireless Web access is available to the public, without adding special software.
More info: [url=http://news.com.com/2100-1016_3-5120138.html?tag=nefd_top]http://news.com.com/2100-1016_3-5120138.html?tag=nefd_top[/url]