'Patch Tuesday' this
month brought nine
bulletins from Microsoft
covering fourteen
vulnerabilities in total
and ranging in scope from
a vulnerability in the
Windows FTP client, which
could allow an attacker
to tamper with the file
transfer location on the
client during an FTP file
transfer session, to a
vulnerability in Internet
Explorer, which could
allow remote code
execution.
MetaSolv Software, a
global leader in
comprehensive operational
support system solutions
for next-generation
communications service
providers, has announced
that its 2005
Provisioning Symposium
will be held October 18th
and 19th, 2005 in London,
UK.
The Renault F1 Team has
announced that Xansa will
become the team's
Official Supplier of
Software Development and
Consulting. Growing from
a successful project
collaboration during the
team's
championship-winning 2005
season, this multi-year
agreement will harness
Xansa's leading-edge
technology to deliver
enhanced off-car data
analysis systems,
ultimately leading to
improved on-track
performance.
LiveVault Corporation,
the leading provider of
disk-based online backup
and recovery solutions
for business servers,
launched LiveVault InSync
Service for Microsoft
DPM, which supports and
extends the capabilities
of Microsoft System
Center Data Protection
Manager (DPM).
8e6 Technologies, a
leading supplier of
Internet Content
Filtering, Monitoring and
Reporting Appliances,
announced they are
reselling two of Tandberg
Data Corporation's
Network Attached Storage
(NAS) solutions. These
NAS units, the InteliNAS
4100 and the InteliNAS
4160, can be connected to
the 8e6 Enterprise
Reporter to enhance its
ability to retain years
of Internet usage
history.
To enable the secure
transmission of critical
business data to mobile
workers, Oracle announced
that Oracle Database Lite
10g Release 2 will
support Symbian OS, the
global open industry
standard operating system
installed on more than 39
million data-enabled
mobile phones.
Further expanding its
identity management
offerings, BMC Software,
Inc., a leading provider
of enterprise management
solutions, announced the
global availability of
BMC Identity Management
Suite, version 5.0.
Business and technology
leaders around the world
now have the opportunity
to experience what
hundreds of Business
Objects customers who
tested the
ground-breaking new
platform already know --
that significant
innovations in
BusinessObjects XI
Release 2 give users a
way to access information
and share knowledge as
they have never done
before.
Quest Software Inc., a
leading provider of
application, database and
infrastructure management
solutions, announced
that the new version of
JClass ServerChart is now
certified by IBM as an
integrated plug-in for
the IBM Rational Software
Development Platform
(SDP), which is built on
Eclipse.
Astaro Corporation has
released version 6.1 of
its award-winning Astaro
Security Gateway software
that provides the first
unified threat
management, network
security solution with
dual virus scanning,
utilizing two of the
market leading engines -
Kaspersky and ClamAV.
SenSage, the leading
provider of enterprise
security analytics, has
introduced SenSage 3.5
which overcomes
event-data management
obstacles, and
streamlines compliance,
investigation and
monitoring processes.
Oracle has announced the
general availability of
Oracle TimesTen In-Memory
Database Release 6.0,
marking the first product
upgrade following the
acquisition of TimesTen
in June 2005. The release
adds significant
enhancements focused on
major reases in caching
performance and
availability, larger
in-memory databases and
data caches, tighter
integration with other
Oracle products, and
broader support of
industry standards such
as SQL and Java.
Symantec Corp has
extended the capabilities
of VERITAS Cluster
Server, the industry's
leading independent
heterogeneous clustering
and availability
software, to lude full
support for leading
replication solutions
that lude: EMC SRDF
(luding SRDF/A), EMC
MirrorView, Hitachi
TrueCopy, HP Continuous
Access XP, the IBM
High-Availability
Disaster Recovery
capability of DB2
Universal Database.
Quest Software, a leading
provider of application,
database and
infrastructure management
solutions, has announced
that it has been named by
IDC as the No. 1 market
share leader in
distributed data
management facilities
(DMF) software.
Nick Mayes, Principal
Analyst for Global
Computing Services at
Datamonitor, noted:
'Overall, this has been a
major quarter for
offshore sourcing. Large
corporations such as ABN
AMRO are dealing directly
with offshore services
vendors, and are signing
deals worth hundreds of
millions of dollars with
them. Global IT sourcing
models are gaining
mainstream acceptance.'
ArcSight, the global
leader in Enterprise
Security Management (ESM)
software, has announced
the release of version
3.5 of its flagship
solution. ArcSight ESM
3.5 specifically
addresses the
mission-critical security
and compliance
requirements of the
largest, most demanding
deployments in the
enterprise security
management market .
'Google worked quickly to
complete the fix on its
website, which is no
longer exposed to this
vulnerability,' said
secure content management
solutions provider
Finjan, as it
back-announced that it
had informed Google last
week of a dangerous cross
site scripting
vulnerability on its
website.
Overland Storage today
announced that it has
signed a License and
Distribution Agreement
with a major OEM customer
for the company's REO
Protection OS
intelligent, embedded
data protection software.
Internet security pioneer
and leader Check Point
Software Technologies has
agree to buy privately
held Sourcefire, creator
of Snort, for $225M -
helping Check Point
expand its strategy from
primarily offering
perimeter gateway
security solutions to
provide a fully
integrated architecture
for perimeter, internal,
Web and endpoint
security.
McAfee today raised the
risk assessment to Medium
on the recently
discovered
W32/Sober.r@MM!M-151,
also known as Sober.r.
The worm arrives as a
.zip file attached to
e-mail and has many of
the same functionalities
as its Sober
predecessors.
Global Software, which
calls itself the premier
provider of real-time
spreadsheet financial and
business performance
management (BPM)
analytics tools,
announced that it will
partner with Paris,
France-based ERA
Informatique to resell
its Spreadsheet Server
for J.D. Edwards, Budget
Manager for J.D. Edwards,
and Executive DASH
applications.
TriGeo Network Security,
the pioneer and leader of
Automated Remediation
through Intelligent
Correlation, announced
the 64-bit version of
TriGeo Security
Information Manager
(SIM). Version 3.2 is the
first completely 64-bit
security information
management appliance on
the market and was
designed specifically to
leverage the power of
high-performance
processors.
Strategic Computer
Solutions, an IBM Premier
and On Demand Business
Partner with more than
1,500 customers in the
northeast, announced the
acquisition of Principle
Software, a New England
eBusiness and portal
solutions innovator, by
its related company,
Strategic Computer
Services, LLC.
IBM and Univa Corporation
announced a joint
agreement whereby IBM
will license commercial
releases of Globus
software from Univa, the
leading provider of
commercial software and
professional services for
open source Globus
software.
Altiris, a pioneer of IT
lifecycle management
solutions that reduce the
total cost of owning IT
resources,announced
'revolutionary' new
software management
capabilities available
with the upcoming release
of Altiris Software
Virtualization Solution.
Interlink Networks, a
leading developer of
network security and
access control software,
today announced the
release of the newest
version of its RAD-Series
RADIUS authentication,
authorization, and
accounting (AAA) server,
Version 7.1, engineered
specifically for Internet
service providers (ISPs)
of all sizes, OEMs, and
larger enterprises
customers.
nCircle, a leading
provider of
enterprise-class
vulnerability and risk
management solutions, has
announced the general
availability of version
6.5 of nCircle IP360.
With this industry
leading release, IP360
becomes the only
vulnerability and risk
management solution to
offer integrated network
line of sight risk
analysis, providing an
order-of-magnitude
improvement in
prioritizing
vulnerability and risk
remediation in large
enterprises.
Idera, a leading provider
of management and
administration solutions
for the Microsoft SQL
Server and NEC Solutions
(America), Inc., a
premier provider of
integrated solutions for
the Connected Enterprise
in North America
announced, a technology
partnership that will
deliver a high
performance managed SQL
Server database
operations environment.
Packeteer, a provider of
WAN Application
Optimization, and Tacit
Networks, a provider of
enterprise-wide branch
office IT solutions, have
announced a strategic
alliance that will enable
joint customers to
consolidate and
centralize e-mail, Web
and file servers at
corporate data centers
while delivering optimal
application performance
to branch-office users.
Behavior-based security
technology, i.e.
technology that
identifies online threats
such as worms, viruses,
Trojan horses, keystroke
loggers, and phishing
sites by their actions
and characteristics, is
about to become a core
component of Symantec's
baseline consumer
security and enterprise
desktop solutions.
A Florida-based provider
of business e-mail
security solutions is
offering companies in the
path of Hurricane Rita a
free service to protect
and preserve e-mail
traffic should their
servers be affected by
the impact of the storm.
CEO Larry Ellison
delivered an ambitious
24-month roadmap of
priorities for the nearly
35,000 attendees at
Oracle OpenWorld San
Francisco yesterday
afternoon. From open
standards and security to
industry functionality,
business intelligence and
automation, Oracle has
the scale to invest in
meeting customers'
most-demanding
requirements.
Mozilla Firefox 1.0.7 was
released yesterday and is
now available for
download. Fixes are
included for the
international domain name
(IDN) link buffer
overflow vulnerability
and the Linux command
line URL parsing flaw.
'We commend AOL for
taking advantage of our
industry-leading
anti-spyware solution to
protect their users from
these pervasive threats,'
said Jeff Clarke, CA's
Chief Operating Officer,
as America Online
yesterday launched AOL
Spyware Protection 2.0
powered by by eTrust
PestPatrol Anti-Spyware
technology from CA.
SAP and Siemens today
announced that they have
expanded their global
strategic alliance
through the delivery of a
flexible, standards-based
identity management
solution.
In a move to reduce the
ongoing cost of managing
complex and increasingly
heterogeneous enterprise
application environments,
EDS and Oracle announced
plans to provide joint
application management,
hosting and modernization
services. Expanding their
long-standing
partnership, the two
companies will integrate
existing core service
offerings to help clients
simplify, standardize,
and modernize
applications to adapt to
ongoing business changes.
Microsoft has announced
the acquisition of
Alacris Inc., a global
provider of certificate
management and identity
assurance software
products, an acquisition
that enhances Microsoft's
declared strategy of
providing easily
administered identity and
access management
solutions.
'Attackers are moving
away from large,
multipurpose attacks on
network perimeters and
toward smaller, more
targeted attacks directed
at Web and client-side
applications,' said
Arthur Wong, vice
president of Symantec
Security Response and
Managed Security
Services, as Symantec
yesterday released its
eighth volume of the
Internet Security Threat
Report.
HP and Peregrine Systems
have agreed that HP will
acquire Peregrine for
$26.08 per share,
representing an aggregate
equity value of $425
million. Upon close of
the acquisition,
Peregrine, and its
leading IT asset and
service management
software portfolio, will
be integrated into the HP
OpenView business unit.
IT groups need to be able
to consider adopting new
backup software for many
good reasons. New
software might have
features and benefits the
company needs. The curren
Unlike older spam
filters, in which the
author programs the
characteristics of spam,
statistical filtering
automatically chooses the
characteristics (or
'features')
This article is an
excerpt from Risk
Management for Computer
Security: Protecting
Your Network &
Information Assets.
Printed with permission
from Butterworth-Heinem