Click here to close now.

Welcome!

Web 2.0 Authors: Elizabeth White, Pat Romanski, Dana Gardner, Carmen Gonzalez, Cloud Best Practices Network

Related Topics: Security, Wireless, MICROSERVICES, Web 2.0, Cloud Expo

Security: Article

Online Holiday Sales Have Begun: Have You Secured Your Enterprise Network?

Do employees really need access to the corporate network via their smartphones?

It's that time of the year again. The flood of email alerts showcasing online holiday shopping deals fill the inbox at your office PC, laptops and wireless devices as merchants attempt to lure online shoppers to "click and save" while supplies last. In fact, reports show that this year's "holiday shopping" deals have already started as retailers attempt to stretch the holiday shopping season - to begin even earlier than Black Friday.

According to a recent report in Time, Booz & Co. chief retail strategist, Thom Blischok states. "We're not going to see a huge increase in sales growth for Black Friday this year....What we do expect is a lot of ‘showcasing' on Black Friday. Shoppers will check things out in stores, electronics especially, but then purchase online on the Monday after. Cyber Monday sales will explode this year."

While this is good news for merchants, it can become a virtual nightmare for corporate network administrators. With millions of online shoppers turning their office PCs, laptops, and wireless devices into online shopping carts, they hog valuable network bandwidth meant for corporate applications such as e-mail, SAP, Salesforce, and other business-critical applications.

The onslaught of personal smartphones and tablets connecting to corporate networks fully capable of performing browser-based shopping are further affecting normal business operations. According to ABI Research, more than 36 percent of consumers own at least three wireless devices. eCommerce merchants now alert wired consumers with daily deals almost instantly via mobile marketing. This surge has placed greater demands on network monitoring solutions as the mobile device market continues to grow at an astounding rate of five billion subscribers worldwide.

Most organizations allowing employee-owned devices onto their corporate networks (73% according to Aberdeen) find it not only drains their bandwidth, but also opens up severe internal security threats to proprietary information stored on the network. Employers assume this as increased productivity for employees armed with mobile devices and cost savings for hardware not purchased by the corporate office as most employees (54 percent, according to Yankee Group) demand to use their own devices at work.

According to IDC Research, however, 30-40 percent of Internet use in the workplace is non-business related. Vault.com found 37 percent of workers admit to surfing the Web constantly at work for personal interests. This underscores the need for mobile device traffic monitoring. How can network admins monitor employee internet usage and take corrective action?

Companies can easily set guidelines for network traffic monitoring to safeguard against employees armed with BYOD - especially during high traffic holiday shopping/sale months - in a few easy steps.

MAC Addresses and Mobile Devices
The old and sort of cumbersome way is to monitor the unique MAC addresses that are used by each smart mobile device that accesses an Ethernet network. The 6 byte (i.e., 48 bit) MAC address is generally in two parts: The first 3 bytes are the MAC Address vendor ID generally shared by hundreds or even tens of thousands of devices produced by the manufacturer; the second set of three bytes are unique to the device.

A 48-bit Ethernet MAC address has two components, each of which is 24 bits:

*24-bit Organizational Unique Identifier (OUIIEEE regulates the assignment of OUI numbers. Within the OUI, the two following bits have meaning only when used in the destination address:

  1. Broadcast or multicast bit - indicates to the receiving interface the frame is destined a group of end stations on the LAN segment.
  2. Locally administered address bit - normally combines OUI and a 24-bit station address. This is universally unique; however, if the address is modified locally, this bit should be set. Some vendors like Apple set this bit automatically.

Generally, the MAC address is not changed by the end user, thus dynamic IP addresses are often not used to track or report on mobile phone devices. Organizations using NetFlow and IPIX can in fact track these MAC addresses.

MAC Addresses and NetFlow
Traditional flow data (e.g., NetFlow v5) exports IP addresses, but not MAC addresses. NetFlow v9 and IPFIX introduce the ability to export any information on the router including MAC address.

A reliable Network Traffic Analyzer can be used to report to report on NetFlow and IPFIX. The NetFlow Analyzer should offer a filtering architecture to allow traffic analysts to include or exclude portions of MAC addresses. If the administrator wants to narrow a particular vendor (e.g., 00.00.0c) or the iPhone (e.g., 60:33:4b, 64.b9.38, etc.), a reporting tool can filter on these vendor IDs. Once vendor IDs are added to the report, the type can be changed to view different reports. For example, the top domains these mobile devices are visiting can be obtained if the router, switch, or firewall exporting the NetFlow or IPFIX includes URL information. The IT manager can often click on the domain (e.g. facebook.com) and look at URLs visited with mobile device.

Tracking BYOD
By forcing users to authenticate all devices onto the network and agreeing to an operating system scan, network administrators can maintain an active inventory of who (i.e., username) authenticated onto the network and with what type of device. Detailed reports can be run on the volume of iPhones, Androids, Blackberries, iPads, etc. that have authenticated onto the network. Since the MAC address is obtained from every authenticated device, it can be cross referenced with the NetFlow and IPFIX received to look at traffic patterns. This is a much more scalable solution and less error prone approach than the traditional track-down-all-the-mac-addresses approach.

Smartphones: Network Security Challenge
Allowing smartphone access to corporate resources often requires adapting new corporate mobile strategies and policies. Many companies provide VPN access to the corporate network from computers when working remotely. While VPNs offer a secure connection by encapsulating data, many smartphones don't support them (e.g., iPhone). This is partly because the hardware doesn't have the processing power to keep up with encryption processes on-the-fly. Due to pressure from management and remote users, VPN enforcement is often lax. Most employees obtain corporate access from any public network, which includes public places like local coffee shops. This opens Pandora's Box when it comes to security threats.

Smartphones are an ideal tool for cybercriminals to push their malware, viruses, worms and other threats onto corporate networks. With many important titles, email addresses and phone numbers sitting on just about every network-capable mobile phone, stealing confidential emails or pushing botnets onto the company network is easier with traditional security measures put aside in favor of easy remote access. With smartphone synchronization, infection can easily migrate onto a PC - a Trojan horse method that infects the PC could provide access to the corporate network. On the other hand, the data carried on smartphones can be targeted through malware on PCs.

Direct Attacks on the Mobile Phone
Some employees try to increase the security of their phone with special anti-theft software or by encrypting their memory card. These solutions are aimed at making data protected from physical attacks. However, those are done by pickpockets, who are less interested in the mobile phone content than reusing or reselling the device.

Cybercriminals do care about sensitive information stored on smartphones, but they don't need physical access to the phone to retrieve it. Rather, they will exploit any vulnerability - for instance in the phone's Web browser (such as the WebKit vulnerabilities on Android phones) - or use social engineering tricks to install malware on the phone. Once the phone is infected, it's easy for the cybercriminal to access any data on the device. In those cases, the locks are useless and the memory card is dynamically decrypted when used.

Businesses must add employees to the corporate network easily and cost-effectively while maintaining desired security levels and remote management capabilities. Traditionally, the RIM BlackBerry Enterprise Server (BES) has been the gold standard among organizations with corporate-liable policies, providing sophisticated security and management capabilities.

However, smartphones like Androids and iPhones are becoming more popular, and some organizations feel obligated to embrace these as part of the employee-owned smartphone strategy. These are also supporting minimum security requirements, like timed-lock and remote wipe in the case of a lost or stolen handset. Some mobile apps, like Touchdown for Android, provide Exchange ActiveSync capabilities that support security policies to ensure security of the corporate data on the smartphone. Clearly, organizations need to rethink their mobile Smartphone strategies and take into account the proliferation of employee-owned smartphones.

Setting up single sign-on is another strategy that could be implemented on corporate networks. However, as of today, it's not supported on the iPhone. Whatever the decision, a careful evaluation of mobile devices accessing the network needs to be executed.

Ultimately, the question is: Do employees really need access to the corporate network via their smartphones? If they are provided access, then IT must secure the network to make sure the onslaught of online holiday shopping and sales offerings don't turn the season to "nightmare" before Christmas for the network bandwidth.

So, this holiday season, stay safe out there and don't forget to drive safe - on the road and in cyberspace.

More Stories By Michael Patterson

Michael Patterson, is the founder & CEO of Plixer and the product manager for Scrutinizer NetFlow and sFlow Analyzer. Prior to starting Somix and Plixer, Mike worked in a technical support role at Cabletron Systems, acquired his Novell CNE and then moved to the training department for a few years. While in training he finished his Masters in Computer Information Systems from Southern New Hampshire University and then left technical training to pursue a new skill set in Professional Services. In 1998 he left the 'Tron' to start Somix and Plixer.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that CommVault has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. A singular vision – a belief in a better way to address current and future data management needs – guides CommVault in the development of Singular Information Management® solutions for high-performance data protection, universal availability and sim...
Cloud is not a commodity. And no matter what you call it, computing doesn’t come out of the sky. It comes from physical hardware inside brick and mortar facilities connected by hundreds of miles of networking cable. And no two clouds are built the same way. SoftLayer gives you the highest performing cloud infrastructure available. One platform that takes data centers around the world that are full of the widest range of cloud computing options, and then integrates and automates everything. Join SoftLayer on June 9 at 16th Cloud Expo to learn about IBM Cloud's SoftLayer platform, explore se...
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
The list of ‘new paradigm’ technologies that now surrounds us appears to be at an all time high. From cloud computing and Big Data analytics to Bring Your Own Device (BYOD) and the Internet of Things (IoT), today we have to deal with what the industry likes to call ‘paradigm shifts’ at every level of IT. This is disruption; of course, we understand that – change is almost always disruptive.
SYS-CON Media announced today that 9 out of 10 " most read" DevOps articles are published by @DevOpsSummit Blog. Launched in October 2014, @DevOpsSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce softw...
Wearable technology was dominant at this year’s International Consumer Electronics Show (CES) , and MWC was no exception to this trend. New versions of favorites, such as the Samsung Gear (three new products were released: the Gear 2, the Gear 2 Neo and the Gear Fit), shared the limelight with new wearables like Pebble Time Steel (the new premium version of the company’s previously released smartwatch) and the LG Watch Urbane. The most dramatic difference at MWC was an emphasis on presenting wearables as fashion accessories and moving away from the original clunky technology associated with t...
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on Twitter at @MicroservicesE
SYS-CON Events announced today that Site24x7, the cloud infrastructure monitoring service, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Site24x7 is a cloud infrastructure monitoring service that helps monitor the uptime and performance of websites, online applications, servers, mobile websites and custom APIs. The monitoring is done from 50+ locations across the world and from various wireless carriers, thus providing a global perspective of the end-user experience. Site24x7 supports monitoring H...
After making a doctor’s appointment via your mobile device, you receive a calendar invite. The day of your appointment, you get a reminder with the doctor’s location and contact information. As you enter the doctor’s exam room, the medical team is equipped with the latest tablet containing your medical history – he or she makes real time updates to your medical file. At the end of your visit, you receive an electronic prescription to your preferred pharmacy and can schedule your next appointment.
SYS-CON Events announced today that SafeLogic has been named “Bag Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. SafeLogic provides security products for applications in mobile and server/appliance environments. SafeLogic’s flagship product CryptoComply is a FIPS 140-2 validated cryptographic engine designed to secure data on servers, workstations, appliances, mobile devices, and in the Cloud.
The WebRTC Summit 2014 New York, to be held June 9-11, 2015, at the Javits Center in New York, NY, announces that its Call for Papers is open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 16th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps Summit.
@ThingsExpo has been named the Top 5 Most Influential M2M Brand by Onalytica in the ‘Machine to Machine: Top 100 Influencers and Brands.' Onalytica analyzed the online debate on M2M by looking at over 85,000 tweets to provide the most influential individuals and brands that drive the discussion. According to Onalytica the "analysis showed a very engaged community with a lot of interactive tweets. The M2M discussion seems to be more fragmented and driven by some of the major brands present in the M2M space. This really allows some room for influential individuals to create more high value inter...
SYS-CON Events announced today the IoT Bootcamp – Jumpstart Your IoT Strategy, being held June 9–10, 2015, in conjunction with 16th Cloud Expo and Internet of @ThingsExpo at the Javits Center in New York City. This is your chance to jumpstart your IoT strategy. Combined with real-world scenarios and use cases, the IoT Bootcamp is not just based on presentations but includes hands-on demos and walkthroughs. We will introduce you to a variety of Do-It-Yourself IoT platforms including Arduino, Raspberry Pi, BeagleBone, Spark and Intel Edison. You will also get an overview of cloud technologies s...
Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 16th Cloud Expo at the Javits Center in New York June 9-11 will find fresh new content in a new track called PaaS | Containers & Microservices Containers are not being considered for the first time by the cloud community, but a current era of re-consideration has pushed them to the top of the cloud agenda. With the launch of Docker's initial release in March of 2013, interest was revved up several notches. Then late last...
SOA Software has changed its name to Akana. With roots in Web Services and SOA Governance, Akana has established itself as a leader in API Management and is expanding into cloud integration as an alternative to the traditional heavyweight enterprise service bus (ESB). The company recently announced that it achieved more than 90% year-over-year growth. As Akana, the company now addresses the evolution and diversification of SOA, unifying security, management, and DevOps across SOA, APIs, microservices, and more.
GENBAND has announced that SageNet is leveraging the Nuvia platform to deliver Unified Communications as a Service (UCaaS) to its large base of retail and enterprise customers. Nuvia’s cloud-based solution provides SageNet’s customers with a full suite of business communications and collaboration tools. Two large national SageNet retail customers have recently signed up to deploy the Nuvia platform and the company will continue to sell the service to new and existing customers. Nuvia’s capabilities include HD voice, video, multimedia messaging, mobility, conferencing, Web collaboration, deskt...
The Open Compute Project is a collective effort by Facebook and a number of players in the datacenter industry to bring lessons learned from the social media giant's giant IT deployment to the rest of the world. Datacenters account for 3% of global electricity consumption – about the same as all of Switzerland or the Czech Republic -- according to people I met at the recent Open Compute Summit in San Jose. With increasing mobility at the edge of the cloud and vast new dataflows being predicted with the growth of the Internet of Things (and The Coming Age of Many Zettabytes) in the near...
SYS-CON Events announced today that Cisco, the worldwide leader in IT that transforms how people connect, communicate and collaborate, has been named “Gold Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cisco makes amazing things happen by connecting the unconnected. Cisco has shaped the future of the Internet by becoming the worldwide leader in transforming how people connect, communicate and collaborate. Cisco and our partners are building the platform for the Internet of Everything by connecting the...
15th Cloud Expo, which took place Nov. 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA, expanded the conference content of @ThingsExpo, Big Data Expo, and DevOps Summit to include two developer events. IBM held a Bluemix Developer Playground on November 5 and ElasticBox held a Hackathon on November 6. Both events took place on the expo floor. The Bluemix Developer Playground, for developers of all levels, highlighted the ease of use of Bluemix, its services and functionality and provide short-term introductory projects that developers can complete between sessions.
Temasys has announced senior management additions to its team. Joining are David Holloway as Vice President of Commercial and Nadine Yap as Vice President of Product. Over the past 12 months Temasys has doubled in size as it adds new customers and expands the development of its Skylink platform. Skylink leads the charge to move WebRTC, traditionally seen as a desktop, browser based technology, to become a ubiquitous web communications technology on web and mobile, as well as Internet of Things compatible devices.