Monday, November 5, 2012

Agent or Agentless Security?


Which is better, agent or agentless security monitoring?
Many of the companies which are associated with computer security and virus scanning are agent based products, meaning that the user has to install the product onto the systems that they wish to monitor. Many of these systems require the user to update the system or monitor it themselves, while it is possible to send alert to a central location. This still requires a person to go and update or deal with the issue locally.
Agentless security on the other hand does not require the user to install anything on each host but to have a centralized monitoring console where they can see all of the assets that they are monitoring. With agentless security it is easier to scale the solution to many more devices, but there is the drawback of internal network traffic which is normally avoidable when the scans are run at certain times of the day.
While there are benefits to each one and they can both help to protect a network. I would say that agentless security would be the easiest to deploy into a larger network verses trying to install a program to each computer. Agentless is also easier to monitor with fewer company resources and can be monitored remotely for all of the systems. For the number of people that can monitor and the number of things that are able to be monitored remotely through agentless security I think that agentless is the best way to go with larger corporations and large networks that need to be monitored.

Monday, October 22, 2012

Colocation Centers, Good or Bad?


     Is it good to use a co-location site for the storage of servers and other business systems or is it better to manage the systems within the company and to keep them on-site? There are benefits to both and there are also issues which each plan of action. For keeping servers on-site there are costs to keep the lab running and operational. Most companies will have to pay someone to control the server room and manage all issues that come with managing a server room. There is also the ability for the servers to be accessed more quickly when they are onsite than when they are in an off-site co-location facility. With an off-site co-location storage there is also the payment to reserve the rack space which will cost about 800-1000 dollars a month. While if it is necessary for a company to get have space and they are not able to expand their current server room then this is a viable opportunity but I would not say that this is an ideal solution or an answer to this problem. There is also the risk that the security of the servers is not able to be secured by the company as well and rely on the co-location company to manage the security of the facility.

Monday, October 8, 2012

The Risk of Premature Updates

     Have you ever upgraded a mobile device just to find that there was a larger issue with the newest version that what you were trying to upgrade away from? It seems like in the recent few weeks there have been many issues with upgrading devices, uncovering more problems with the devices than there previously were. It seems like on a weekly basis there are updates and new features  released to fix previous versions that were released only a few weeks before.
     With all of these problems it is getting to the point that I do not want to upgrade my devices immediately anymore. There will always be problems with updating a devices to a newer major release version, but it seems like that issue is amplified many times over when upgrading from one version to another recently. With issues and bugs like these it makes it more difficult to stay at the leading edge of technology. There are constantly issues which need to be worked through and respond to which take time for developers to fix and release to the public. Many people are now recommending the public to wait until the first service pack has been released to adopt the newest technology because many of the major issues with the device have been repaired and work better than they did when the device was first released. The first service pack release is a major increase in the functionality of the devices and the security which has been implemented into the device. This is why many people have begun to say that it is better to wait until fixes have been released to help mediate the zero day issues with a product.

Monday, September 17, 2012

Private Sector Security Regulation


Is there a need for private sector regulations when it comes to Information Security?
In a recent survey, "nCircle 2012 Government Policy Security Trend Study," carried out by nCircle Network Security the results show that the majority of network admins do not think that there is any need for an increase in the minimum level of regulated network security. This is because many of the network admins know that being compliant to a third party policy does not mean their network is secure from potential hackers. Between higher level management and network security admins there is always a struggle for more money to put towards security and to use that money for other parts of the company. This comes at no surprise that in this study 81% of the participants concluded that there was a need for more money to be spent on the network security side of the company to better protect their assets. There will always be a struggle for more security against the higher ups in the company competing to be more "beneficial" to the company.

Article:

http://www.ncircle.com/index.php?s=news_press_2012_09-13-Study-and-Infographic-66-percent-of-IT-Security-Professionals-Dont-Believe-Regulation-Will-Improve-Cyber-Security

Monday, September 10, 2012

Corporate Practices of Disclosure?


While security is a needed part of any company there are many other things which help to keep them more secure in their daily operations. These security measures do not include disclose of information about the company’s security. While this information could be important for potential clients it becomes a security risk for the company more often than not.
While I agree with the principle of avoiding “security through obscurity,” I would not recommend a company to give up much of their information about their security practices. There are some security disclosure postings which would hurt a company and therefore should never be freely disclosed to the general population. I think that a company could disclose some information about their practices and operational strategy to the general public but the information would be so limited and vague that it would not be useful for customer to know this information. Even without this information a customer should never decide to use a password based on the lowest settings required by the company they should always use a strong password and determine for their self if a password’s strength is applicable for a certain type of account.
To show that there is a proper level of security which is in place at a company there should be some categories of “low hanging fruit” which a company should receive a compliance score regarding, and this score could be shared with the public after an appropriate amount of time for the company to fix any shortcomings that they may have. With this scoring system there would be an increase in the disclosure for companies with higher levels of security while still giving them protection from releasing too much information. While there are many possibilities for disclosure for a company’s security settings full disclosure should not be considered with how the world operates currently. 

Tuesday, September 4, 2012

Is it too expensive to avoid tracking?



Is it too expensive to avoid being tracked through the internet and by other companies?
     I agree with the article written by Tim Keanini. It this article he talks about how easy it is to track people who are mostly unsuspecting unless they have been exposed to this type of information. Most people do not realize that anything we fill out or use today to save money while making purchases is used against us. All rewards cards have a certain incentives for all of us to enroll in the program to receive discounts among other things. I had never thought about this until I read this article about tracking and monitoring people and their purchases.

     I do have a few rewards cards for businesses that I use fairly frequently but I never thought of the information that I am exposing to different companies. There are certain things that I will decide if they are necessary after reviewing this article. There are many things that I have bought in the past that could have been avoided. I prefer my life to be a private affair and not use for information and exploit by companies. There are times that I do enjoy buying different things but it is a little scary to think that I am so easy to track in my everyday life. After reading this article I do not think that there would be anyway for me to be completely hidden for the information age. It makes me wonder what all of the spies for different countries use to hide from the information age.

Monday, August 27, 2012

Intro Blog

Hello, my name is Joey Lyons. I am 22 years old and an ISA major at KSU. I am planning on graduating at the end of the semester (Dec '12). I am currently working as an intern for nCircle network security in Alpharetta. My job entails QA testing and managing all of the scan targets for my division within nCircle, CCM (configuration compliance manager). I enjoy my job while there are some times where the work can be a little hectic it is still a great job and a fun atmosphere to work in.

Most of my days are busy and filled with many different activities. Much of my time is spent with friends joking around, having a few beers or playing soccer somewhere around KSU. The rest of it is currently spent working or doing work for school. When I get some down time I spend it watching movies and watching college football.


I am a big Virginia Tech fan and have been since I started high school. I went there for my freshmen year and decided that for the money and the classes that I was taking that it was not going to be the place that I would stay for the rest of my academic career. I still love the campus and atmosphere up there and always will, but I am finishing out my undergraduate degree at KSU.