Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 2 members online
 
Advertisement

You are here: Home arrow Resourcesarrow Mass Mediaarrow Very interesting article
EH-Net
May 20, 2013, 04:36:30 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Very interesting article  (Read 11516 times)
0 Members and 1 Guest are viewing this topic.
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« on: March 22, 2011, 10:52:15 AM »

http://www.infoworld.com/d/security/prepare-advanced-persistent-threats-or-risk-being-the-next-rsa-180?page=0,0

I have the same feeling about my company. I think we are in a deep s..t, and that we have to find the whole. Our alerts are too clean, and that's not normal.
Being and insurnace company and haveing a lot of confidential data we should be more searched.

But... they are very comfortable they way things are, and are hoping that the tools will solve the problems (Arcsight, IDS, Firewalls, soon DLP)   Huh

I hope I will be able to convince them.
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
R3B005t
Newbie
*
Offline Offline

Posts: 43


View Profile
« Reply #1 on: March 22, 2011, 11:46:06 AM »

My company recognized the criticalality of APT's last year so we had Mandiant come by for some APT training and we picked up a Mir controller box, best security investment in years!  We can easily identify any suspicious activity on client machines looking for signs of APT's.  I would highly recommend anyone interested in APT's reach out to mandiant those guys practically wrote the book on identification and remediation of APT's they also do some kick ass unknown binary analysis and offer up free versions of most of their tools.
Logged
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #2 on: March 22, 2011, 12:11:59 PM »

Yawn at APT. I advise you read the following two articles I wrote surrounding failures...

Cyber Warfare Analysis - You're Doing It Wrong
https://www.infosecisland.com/blogview/12529-Cyber-Warfare-Analysis-Youre-Doing-It-Wrong.html

Security Vendors Vow to Defend Against Cyber Boogeyman
https://www.infosecisland.com/blogview/12663-Security-Vendors-Vow-to-Defend-Against-Cyber-Boogeyman.html
Logged

hayabusa
Hero Member
*****
Offline Offline

Posts: 1631



View Profile
« Reply #3 on: March 22, 2011, 02:09:06 PM »

<nod>
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
alucian
Full Member
***
Offline Offline

Posts: 225



View Profile
« Reply #4 on: March 25, 2011, 07:34:15 PM »

@R3B005t 
I will look further at what you propose.

@sil
As always, you are a great help. I will look deeper at your articles and I will try to adapt your advices.
My only obstacle is the mentality of others, but I will beat them  Smiley

Thanks again!
Logged

CISSP ISSAP, CISM/A, GWAPT, GCIH, eCPPT, OSWP
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.