Categories: Newsletter

Network Monitoring News – Sep 2016

Drones

We have been hearing a lot about drones as of late. A new trend is for hackers to use drones to hover close to buildings or perch on a roof or ledge to feed open connections for Bluetooth and WiFi to internal users. They are also using drones to hack solar panels and other devices/equipment that were previously inaccessible.

Much more concerning is the use of drones to hack into cars. Drone jammers are devices that can jam the signal between the drone and handset, forcing them to land, my guess is we will be seeing companies mass produce these devices to prevent drones from accessing areas where they are not wanted.

Apple Patches

Apple issued emergency OS patches for the Mac, fixing the same three vulnerabilities the company addressed last week on the iPhone.

The trio of bugs were used to spy on an activist in the United Arab Emirates by turning his iPhone into a surveillance tool.

Getting Secure

Intrusion Detection is now a must have. Years ago IDS consisted of a single software package that parsed data against a rule set. Now, Intrusion Detection is pulling data from multiple sources (Log files from servers, logs from firewalls and other network equipment etc.) and parsing, categorizing, summarizing all data.

  1. Monitor Applications with Access to Data
  2. Create Specific Access Controls
  3. Collect Detailed Logs
  4. Maintain Security Patches
  5. Be Aware of Social Engineering
  6. Educate and Train Your Users
  7. Outline Clear Use Policies for New Employees and Vendors
  8. Monitor User Activity
  9. Create a Data Breach Response Plan
  10. Maintain Compliance

Not only does modern IDS look for problems, it is also looking for unexplained traffic or anomalous activity. IDS also looks for internal users connecting to command control servers, malicious web links, phishing, ransomware and much more. Most important, they enable us to find when our prevention systems have failed. Once an event is found, modern IDS can also retrieve all the records and logs to help track down the 5 W’s (Who? What? When? Where? Why? How?) about the incident.

Ron Samson

Share
Published by
Ron Samson

Recent Posts

SIEM Management Services: When Log Collection Becomes Too Expensive to Operate Internally

Turn SIEM logs into faster response with managed SOC services—optimize telemetry, tune detections and gain…

2 weeks ago

Cloud Security Monitoring for AWS and Azure: What Your MSSP Should Actually Watch

Detect AWS and Azure identity abuse before it becomes a breach. Learn the signals, log…

57 years ago

Security Operations Metrics That Matter: KPIs for Risk Reduction, Response Speed, and Executive Reporting

Prove security risk reduction with KPIs for exposure aging, critical asset coverage, detection quality, and…

57 years ago

Microsoft 365 Security Monitoring: What SMBs Miss After Basic Configuration

Catch MFA and OAuth abuse in Microsoft 365 before attackers create forwarding rules or steal…

57 years ago

Managed Vulnerability Management: How to Turn Scanner Findings Into Remediation That Reduces Risk

Reduce measurable exposure with managed vulnerability management: validate findings, prioritize exploitable risk, verify fixes, and…

3 weeks ago

Co-Managed Security Operations: How Internal IT Teams Can Keep Control While Gaining 24/7 Coverage

Gain 24/7 security coverage without losing control. Learn how co-managed operations cut alert fatigue, share…

57 years ago