Business Technology Summit 2010 on SOA and Cloud Computing
Member Login
Password

 

Information Security Solutions for India in the New Decade
2009 has been titled as the most productive year for Trojan/malware writers. There were about 25 million new malware strains in 2009 compared to a combined total of 15 million in Panda Security's 20-year history. Panda Labs, the malware research arm of Panda Security, says its research laboratory receives about 55,000 daily samples with the database crossing the 40 million mark.

The previous year saw Trojans such as Zeus, UrlZone and Clampi performing their operations with a high level of anonymity. The attacks left affected users completely unaware of their presence. Every detail from identity information to financial details were reported to have been captured by these Trojans. This is a clear indication of the complexities that information security providers of today are dealing with.

The increasing adoption of cloud, social media and virtualisation technologies is blurring the network parameter by adding additional layers to cope with. Cyber criminals are employing new techniques such as ransomware, scareware and crime-as-a-service to entice unsuspecting users and threatening the enterprise at large.

2010 will see cyber crime take on a more organized persona with specialized directed enterprise attacks. And India is at the forefront of the rising Web threats, according to Internet security provider Symantec. So what are Indian companies to do?

A large number of security breaches in organisation occur due to employees' indulging in non-work related surfing. A recent survey found the average time an employee spends on non work-related websites is five hours per week. While enterprises incur a productivity loss of approximately Rs. 160,000 per employee per annum due to non work-related surfing, the more grave threat is the security threat this poses to the company. "A majority of employees today spend a significant time on the Internet when at work. However, the majority of these employees are not aware of and hence not worried about the security threats arising from the Internet" says Surendra Singh, Regional Director, SAARC, Websense Inc.

The top five challenges and trends information security providers will have to contend with in 2010 are:
  • Data Leakage: organisations generate large amounts of information every day and classifying data becomes a daunting task. But without classifying, priorities cannot be established. So companies need solutions that help them classify and encrypt data on the fly (as and when information exits the organization). Another key reason for data leakage is insider threats. Technologies like data loss prevention (DLP), document right management (DRM) that will help fight these threats will be adopted on a wider scale horizontally across an organization. With TrendMicro stating that Windows 7 default settings happen to be less sheltered than Windows Vista, it won't hurt to be a little cautious.
  • Virtual Security: the need to integrate security with virtualisation is more real than the system it is protecting. Averting inconsistencies from migrating between related virtual machines will play a key role in the adoption of virtualisation. A rigid barrier separating virtual machines on all levels with properly addressed memory allocations will reduce risk migration.
  • Securing the Cloud: as corporations begin to adopt cloud services the cloud is more likely to suffer from cyber crime. Third-party cloud providers who offer the reliant systems to host data and applications and provide secure data pipes resistant to data infection and theft will be most preferred. User identity and access management will assume further significance in such environments.
  • Scareware: applications that demand money were seen in 2009, and it is set to become more common in 2010. Rogue anti-malware software take control of a user's computer and ask for a ransom to regain control of the machine. Other scarewares con users into downloading “anti-virus” software that detects spurious infections, and asks the user for cash to remove it. “In order to avoid crimeware, Indian organizations should adopt content filtering solutions which use behavior based technology instead of signature based detection” said Sameer Ratolikar CISO, Bank of India.
  • Multiplatform Bombing: with the growing popularity of multiple platforms cyber criminals are pointing the crosshairs towards non-Windows users who until now had the luxury of being relatively immune to the Windows-centric malwares that hogged the media light in 2009.
  • Secure access issues: organisations now have a large number of mobile employees who require remote access to applications on a 24/7 basis. SSL VPNs and IPSec VPNs have been popular technologies to provide secure access. Organisations are now deploying advanced solutions for authentication and access management like Single sign-on and two-factor authentication.
Unified Threat Management Solutions Ideal for India

The primary reason for lack of security amongst Indian organizations is because information security systems alone sometimes cost more than a company's annual IT budget, especially SMBs.

There is some solace in the horizon with Unified Threat Management (UTM). The UTM concept encompasses facilities such as firewall, gateway antivirus, intrusion detection system (IDS), IPS, anti-malware, content filtering, antispam, virtual private network (VPN), load balancing, bandwidth management, and secure wireless access.

Unified Threat Management (UTM) allows SMBs to cover security compliance requirements enforced upon them by the new IT amendments act of 2008.  "Generally, a UTM comes configured to suit the needs of most businesses without the need for significant security expertise. It is likely to be more economical than buying all the parts individually, assuming that you would need a dedicated server for the firewall in the latter case." says Graham Titterington, Ovum.
Related Articles
Oracle Revs AutoVue Enterprise Visualization Oracle has unveiled AutoVue 20.0,...
3PAR Unveils Utility Storage in India 3PAR, a global provider of utility...
Related Podcasts & Videos
Best Practices for Enterprise SOA Deployment Bob Marcus, the leader for SOA and Distributed Virtualization standards at the Network Centric Operation Industry Consortium (NCOIC.org), discusses requirements and best practices for enterprise SOA Deployment, in this talk recorded at Saltmarch Media's Business Technology Summit 2008. The session is based on Bob's experience working with large enterprises such as General Motors and Boeing. It also includes recommendations from a Session on 'SOA Deployment: Industry Best Practices' that Bob has organized for several US government agencies.
Business Transformation vs. SOA Transformation - Can I do Both? Corporations are transforming their business models in an attempt to increase revenue, operational efficiency and global competition by designing innovative business models and processes to be disruptive in their market space. In this keynote, recorded at Saltmarch Media's Business Technology Summit 2008, the Vice President of IBM's Global Solutions and Assets division says business leaders are looking for IT to provide and support the disruptive business models. However, the majority of IT's budget and resources are spent in maintenance leaving little time and resources for IT to be innovative and meet the business demands. In addition, many IT Corporations have adopted SOA in adhoc fashion and achieved some maturity in the technology. The key to aligning the IT objectives with the business objectives is a structured approach. Come hear about new ways to develop the required capabilities and prioritize the initiatives to create a Business and SOA transformation roadmap.
State of the Union - SOA Standards The author of the seminal book "Great Global Grid: Emerging Technology Strategies" discusses the current status of SOA-related standards and their applicability in this talk recorded at Saltmarch Media's Business Technology Summit 2008. This has been an active area over the last few years with multiple standards being developed and supported by different organizations. However there are still concerns about the complexity and maturity of SOA standards. The content will be based on Bob's recommendations for government agencies in the US and Asia. It will also include information from an "Emerging Standards for SOA" Session that Bob organized bringing together leading standards groups.
Virtualization 360 Increase your virtualization IQ: learn about Microsoft's virtualization roadmap, understand the technologies and get ready for the Virtualization from Ravi Sankar. This session, recorded at Saltmarch Media's Business Technology Summit 2008, will provide you with an overview of Microsoft's comprehensive virtualization strategy and product offerings, including server virtualization and management (Hyper-V and System Center Virtual Machine Manager 2008), Microsoft Application Virtualization, presentation virtualization (Terminal Services) and desktop virtualization (Virtual PC 2007, App-V).
Software + Services: Fundamental Shifts in Platform Computing We are at the cusp of a big industry change. The way software is delivered and monetized is undergoing a fundamental shift. The multiple models for monetization are fundamentally shifting the software industry and business models. Traditionally software companies have made monies only in Licensing and now there are three additional models to monetize. In this talk recorded at Saltmarch Media's Business Technology Summit 2008, Srikanth Karnakota says software licensing is going to continue to exist and grow. Online advertising will grow. Online transactions and subscriptions will grow. But perhaps most importantly for a number of our partners, the amount of value that will be delivered by humans providing customization services, application development services, management services, hosting services, will also continue to grow, and so we see a big opportunity for our partners as we make this transformation to Windows and Windows Live and the new software plus service user interface and computing model.
Designing Reusable Service Interfaces One of the challenges of SOA is the development of services, which are reusable. Such services can participate in several different processes and orchestrations. Experienced architects are aware that designing and implementing reusable services is much harder task than implementing services for single use. In this talk recorded at Saltmarch Media's Business Technology Summit 2008, Matjaz B. Juric discusses best practices for designing reusable service interfaces. We will discuss the possibilities provided by WSDL. We will address the versioning issue, which becomes crucial when changing/modifying services in order to make them more reusable.
Most Popular
Most Read

Softlink Logistic Systems, an Indian logistics software provider, today revealed the survey results on – ‘Adoption of Technology in Indian Logistics Sector-2009’, conducted amongst 700 Indian logistics players operating as Customs Clearing, Freight Forwarding, NVOCCs and 3PL players. The survey revealed that larger logistic players are opening up for technology investments in the year 2010. It highlights that the number of larger players, making technology investments up to Rs. 10 mn have been doubled to 14 percent in 2010 compared to last year.

3PAR, a global provider of utility storage, has launched its first sales and customer service office in India and has named Arvind Khurana as country manager. This move into India is intended to position 3PAR to meet growing demand for technologies to support cloud computing, the virtual datacenter,green IT initiatives, and enhanced infrastructure agility in an economy that has been expanding in the midst of a worldwide recession.

There have been a lot of questions lately if India is ready for adopting cloud computing solutions and vice versa. Microsoft clearly believes in the affirmative and launched Windows Azure. Now more than 50 partners including HCL Technologies, Wings Info, Cerebrate and CDC Software are developing commercial applications and solutions on Windows Azure platform.

Softlink Logistic Systems, an Indian logistics software provider, today revealed the survey results on – ‘Adoption of Technology in Indian Logistics Sector-2009’, conducted amongst 700 Indian logistics players operating as Customs Clearing, Freight Forwarding, NVOCCs and 3PL players. The survey revealed that larger logistic players are opening up for technology investments in the year 2010. It highlights that the number of larger players, making technology investments up to Rs. 10 mn have been doubled to 14 percent in 2010 compared to last year.

Oracle has unveiled AutoVue 20.0, featuring a new architecture that aims to scale with an organization’s evolving enterprise requirements and more efficiently serve the document visualization and collaboration needs of enterprise and desktop users. New capabilities within AutoVue 20.0 support customers in a variety of industries including Engineering and Construction, Utilities, Oil and Gas, and Manufacturing.

Microsoft has been working on a micro-blogging tool for the enterprise and has christened it 'OfficeTalk'. With the new ALL IN campaign that Microsoft has launched for cloud computing, understanding how social media works at the enterprise level can give them the edge they have been looking for.

Advertisement

More Videos

Best Practices for Enterprise SOA Deployment Bob Marcus, the leader for SOA and Distributed Virtualization standards at the Network Centric Operation Industry Consortium (NCOIC.org), discusses requirements and best practices for enterprise SOA Deployment, in this talk recorded at Saltmarch Media's Business Technology Summit 2008. The session is based on Bob's experience working with large enterprises such as General Motors and Boeing. It also includes recommendations from a Session on 'SOA Deployment: Industry Best Practices' that Bob has organized for several US government agencies.

More...
Off the Press

Red Hat Upgrades Middleware Platform with JBoss Enterprise SOA Platform 5.0 Red Hat has updated its middleware portfolio with JBoss Enterprise SOA Platform 5.0 that it says can provide improved web services and cloud integration. The company claims businesses can use JBoss...

Oracle Launches OLTP Machine Exadata 2 in India OLTP is a widely accepted technology known to deliver extreme performance and scalability for online transaction processing. Oracle has launched Oracle Exadata Version 2 in the Indian market, which...

Nordic Edge Turns Google NexusOne, Windows Mobile and Jave ME phones into Security Devices Companies and organizations want to find an economical, secure and user-friendly security solutions that employees or customers can use to connect without requiring hardware tokens can now turn to...

More...
Whitepapers

Cost Effective Defence-in-depth Security Controls and Solutions Information ranging from trade secrets to financial data to privacy related information has become the target of sophisticated attacks from both sides of the firewall. While most organizations have...

How to Leverage SOA Investments using Agile Methods Transitioning to SOA is a complex process that adds its supporting technologies, methodologies and staff to an enterprise’s existing layers of already fixed and difficult-to-change architecture....

Cloud Computing Use Cases For this white paper the Cloud Computing Use Case Discussion Group brought together cloud consumers and cloud vendors to define common use case scenarios for cloud computing. The use case scenarios...

More...