Advertisement
Co Presented By
Co Presented By

"Log Analysis Helps Tackle Multiple Attack Types"

Murali V - product specialist, Enterprise Solutions, Sify, talks about the significance and various facets of information security.

Advertisement
FP Archives|Jan 31, 2017, 01:48:15 IST

Information security is and will always remain at the top of CIO priority lists. In an interaction with Biztech2.0, Murali V – product specialist, Enterprise Solutions, Sify, talks about the significance and various facets of information security.

Can you cite the importance of 'Vulnerability Assessment' within enterprises from an information security perspective?

Advertisement

Security is a very dynamic space. A one-time investment in security is inadequate. One cannot be static in dealing with information security. It is similar to a master healthcare check that is repeated on an annual basis to check the body’s vital parameters. Enterprise security should be regularly checked, watched and monitored for necessary corrective action. This process is typically known as 'Vulnerability Assessment' and helps in finding out the strengths and weaknesses of the system and how somebody can exploit the weaknesses.

biztechMore from Biztech

What is the significance of 'Log Analysis'?

Enterprises have protective systems like Firewall, Anti-Virus, Anti-Spam and other IDS (Intrusion Detection Systems). They have to be monitored continuously to check if they are operational and working as per the design. All these systems generate logs that comprise information on the various types of activities within the system.

Advertisement

The concerned person will have to intelligently analyse and correlate activities to find out whether somebody is taking advantage of loopholes in the system and if yes, generate alerts about the same. It is not always possible for the security expert to keep watching the systems and conduct the log analysis, so there are sophisticated tools available that do the online log analysis and suggest a solution if there is a breach.

Logs help to identify and tackle multiple types of attacks. For example, to avoid an identity theft attack in the BFSI segment, one has to regularly update the Anti-Virus to prevent any unidentified software from running on the system. There are various tools like NetForensic, ArchSite etc that help enterprises do correlation of activities after tracking logs of the chain of security devices. These tools help in identifying attack patterns and trace whether the source of the attack is from a specific IP address. Further action can then be taken to identify the geography of the IP address and accordingly defences can be set up like fixing up the firewall, IDS or whichever security tool has been installed.

Advertisement

How do you view the Defence-In-Depth strategy?

Defence-In-Depth is a method of having multiple lines of defence. It could mean having one firewall for applications in the militarised zone where only a certain employee group has access and a separate firewall for applications in the demilitarised zone, which can be accessed universally by all employees. It must be ensured that traffic comes from specific computers or IP addresses. Enterprises can achieve this efficiency by using multiple firewalls.

The Defence-In-Depth strategy can also be effectively utilised for trapping viruses. There are various kinds of virus manufacturers. They are identified by generating signatures using the Blacklisting model (most enterprises use this model). One school of virus manufacturers might be using a different method from the other. Enterprises can intercept both kinds of viruses by using the Anti-Virus engines on the system.

Digital signatures are important from an information security standpoint. How reliable are they from the accountability perspective?

Accountability is the single most important aspect in the online transactions space. In the physical world, transactions are authorised using a signature where the relying party, for example, a bank, ensures the signature is matching the model and any changes are also endorsed by a supporting signature. However, in the digital world, money transfers are authorised by a password, which does not bind oneself to the transaction as they are bits of data. It is at this juncture that digital signatures play an important role. The digital signature holds a person responsible for the act or online transaction, technically known as 'Non-repudiation' or accountable in simple terms. The person cannot deny the act and this is of great significance for all financial transactions.

Can you tell us about the security solutions provided by Sify?

Sify offers end-to-end security solutions for network security. We provide security solutions at the transaction layer or application layer that address desktop security. Transaction security is ensured using digital signatures for online transactions. We also provide MSS (Managed Security Service) that can help enterprises monitor their security devices. Sify also provides an incident response model that issues alerts in case of critical matters.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Aug 04, 2008, 16:38:13 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next