We’re on the road across North and South America with Citrix and CA for the next few weeks. Join us to talk about how enterprises can streamline virtualized data centers, radically simplify network services for delivering critical applications, and reduce complexity and cost, all without sacrificing performance and security.
See the full list below and click the link to register and join us at an event near you:
We just wrapped up a big week at VMworld Europe, where among daily activities we were featured as part of VMware CEO Pat Gelsinger’s main stage keynote address, announcing the latest milestone in our integration with VMware.
Read Samantha Madrid’s discussion of our new Palo Alto Networks VM-Series release here. And have a look at scenes from the VMworld Europe exhibit hall and throughout the conference below and in this gallery on our Facebook page.
Palo Alto Networks announced this week that we have extended our enterprise security platform to bring next-generation security right to the public cloud – all while preserving speed and efficiency. Find out more.
Sebastian Goodwin with Palo Alto Networks is at Black Hat Europe in Amsterdam and wanted to share his experience at a great hands-on workshop at the conference, “PDF Attack: A Journey From the Exploit Kit to the Shellcode,” hosted by Jose Miguel Esparza.
This week three Google researchers revealed details around the latest attack on SSLv3, code named POODLE. The POODLE (Padding Oracle On Downgraded Legacy Encryption) attack allows an attacker who is already in the network path between the client and server to decrypt portions of the SSL session, including HTTP cookie data used for authentication. Unit 42 further examines this attack.
Brian Tokuyoshi highlights security risks of devices connected to the Internet of Things (IoT) and how to secure them against unauthorized network access.
Join us on next Wednesday, October 22 for a webinar hosted by David Guretz, a Palo Alto Networks engineer and IT security expert to learn more about the hot topic of network segmentation in financial services. Register.
Pamela Warren attended and spoke at AFCEA TechNet Europe last week in Paris. She participated in a panel delving into Modern Cyber Defence and whether it requires “built-in security.” Find out her key takeaways from the event.
Last week we brought our top partners from Europe, the Middle East and Africa to Barcelona for our 6th Annual NextWave Partner Conference. Watch this video to hear from our executives and partners about what propelled growth behind our Enterprise Security Platform in 2014 — and what will keep EMEA on an upswing throughout the next 12 months.
We invite you to view a webcast featuring ISA99 Managing Director Joe Weiss and Palo Alto Networks SCADA Product Marketing Manager Del Rodillas, who will discuss cybersecurity for SCADA and ICS with an Oil & Gas SCADA security practitioner and explain real world use cases and cyber incidents.
Here are upcoming events around the world that you should know about:
1999 was a pretty interesting year for the Internet and security. To jog your memory, here are just a few of the major events from the ultimate (or penultimate, depending on your point of view) year of the last millennium.
The Melissa Virus was infecting millions of hosts using malicious e-mails.
Both Napster and MySpace made their first public appearances.
Internet Explorer 5.0 was released for Windows 3.1, 95 and 98.
The TLSv1 specification was published to replace SSLv3 to improve security of Internet communications.
In the 15 years since TLS was introduced it has been widely adopted, but in many ways SSLv3 has hung on. The two specifications are very similar, but not interoperable and applications that implement TLS are often capable of falling back to SSL to support legacy servers. Cryptologists have slowly chipped away at the security of SSL over the last decade, discovering ways to reveal larger and larger pieces of information from encrypted sessions.
This week three Google researchers announced the latest attack on SSLv3 (named POODLE), which may prove to be the deathblow for this protocol. The POODLE (Padding Oracle On Downgraded Legacy Encryption) attack allows an attacker who is already in the network path between the client and server to decrypt portions of the SSL session, including HTTP cookie data used for authentication.
As all modern browsers and most servers support TLS, this attack should only apply to a small number of connections, but that is not the case. When most browsers fail to connect using TLS, they assume the server must be expecting SSL and downgrade their connections to the vulnerable protocol. This means that even two TLS-capable systems can be forced into using SSLv3 by an attacker who controls the network path. That attacker can then decrypt parts of the encrypted channel without the server or client’s knowledge.
The only permanent fix for POODLE is disabling the SSLv3 protocol completely. This can be done either from the server side or the client side depending on the applications. To address this issue, our IPS team issued an emergency update this morning, which contains a signature that alerts on any SSLv3 connection.
Hits on this signature do not indicate an attack is underway, but any SSLv3 session should be considered vulnerable to POODLE and potentially compromised.
Think you’re ready for the top job? Here’s part 1 of a series to help you land that prime chief information security officer position.
So you want to be a CISO, huh? Think you’re ready to lead a small band of white knights into battle against a countless, hidden enemy? Ready to play both savior and scapegoat, depending on what the day brings? Ready to beg, borrow, and steal for the resources you need to protect your company?
Yes? OK, then, you’re ready to do the job… but can you get the job? For the next several weeks, we’re dedicating Mondays to helping you find the path to the big job, which won’t be easy to define.
“There’s not a standard path [to the CISO job] like so many other professions,” says Mark Aiello, president of the Boston cyber security staffing firm Cyber360 Solutions. “We can’t even agree on how to spell cyber security.” (Cybersecurity? Cyber-security?)
Even the words “engineer” and “administrator” don’t mean the same thing from company to company. The bad news, then, is that it is hard to know what career steps to take next.
The good news, though, is that the ladder you’re already climbing could lead you to the CISO seat.
Despite the variety of routes to the top, Aiello does identify a few consistent trends:
Most CISOs are hired from outside the company.
Following the perplexing logic that somebody you don’t know must be smarter than somebody you do know, “the vast majority” of organizations look outside their walls for a CISO, Aiello says. However, they will be more likely to hire an insider for the CISO job if it’s a newly created position.
So being in the right place at the right time may help you get that newly minted CISO gig, but beware…
A company’s first CISO has less power than its subsequent CISOs.
“That first CISO tends to not have as many teeth as the second one,” Aiello says. They’re likely to be a step below the true C-suite and report to the chief information officer.
Aiello thinks the CISO should be separate from the rest of the IT organization, because security not only impacts technology. “Security organizations are still relatively small [in size], in comparison to the IT department, but huge in terms of importance.”
Most companies want to hire a CISO who’s already a CISO somewhere else.
This raises a question: How do you get that first CISO job if you can only get one if you already have one? Aiello says you may convince a new employer to take you on if you’ve reached the highest security position at your current company — like director or vice president of security — as long as you have experience within the appropriate industry vertical: finance, healthcare, etc.
CISOs are more likely to come from a technical background.
Though there are people who rise to the security job from outside the IT department — we’ll hear some of their stories in the course of this series — Aiello says that most of today’s CISOs began their careers in an information techology job of some ilk. As the field matures and more IT functions are outsourced, that may change.
A CISSP certification isn’t necessarily required for a CISO.
In order to have climbed the infosecurity ladder high enough to be eligible for the “chief” title, you probably will have needed a CISSP already. However, if you’ve made it this far without one, you probably won’t need one now, says Aiello. A four-year college degree, however, is something a prospective employer will want.
As the CISO job grows bigger and more important, Aiello says, the key is proactively gathering all the knowledge and experience you can.
“Raise your hand. Volunteer,” he says. If you’ve spent most of your career outside of the nitty-gritty, hard-core IT security world, spend more time learning about the tactical side — the day-to-day tasks of securing a business. If you are from a heavy technical background, learn as much as you can about the business side.
“Understand the problems your technology is there to solve,” he says. “Understand what [the company is] securing and why they’re securing it.”
In the coming weeks, we’ll spin out the origin stories of men and women currently holding the CISO position at a variety of organizations. Come back to Dark Reading next Monday for the first “how I became a CISO” tale.
Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad of other topics. She authored the 2009 CSI Computer Crime and Security Survey and founded the CSI Working Group on Web Security Research Law — a collaborative project that investigated the dichotomy between laws regulating software vulnerability disclosure and those regulating Web vulnerability disclosure.