Using Technology to Secure Your World

By: Alex Zeltmann

Imagine a world of crime for a moment. Kids being bullied in school, property gets damaged, items are stolen, etc. After spinning these thoughts around in your head for a bit, you may realize that these things happen every day in the real world. Too often these crimes occur when no one is looking—unnoticed. Traditionally, the solution to these problems was handled with independent systems such as closed circuit video surveillance. However, there is a solution for today’s modern networks and the solution is Cisco’s IP Video Surveillance (IPVS) system.

Today the physical security industry is rapidly shifting to IT network systems—where physical security will be managed as an application on the network. Cisco’s IPVS solution uses the network as a platform to integrate physical security for both the public and private sectors. At the heart of Cisco’s IPVS solution are Cisco’s Video Surveillance Software and IP Cameras.

Cisco’s Video Surveillance Software optimizes cost, performance, and capability with high-quality video surveillance. The Cisco Video Surveillance Manager provides a comprehensive system to enable your network and security teams to collaborate effectively by combining both video and network techniques to optimize the experience. The Surveillance Manager was designed to be flexible; it is standards-based and supports a broad range of devices. Cisco’s embedded video analytics strengthen security by analyzing surveillance video in real time—improving incident response time. Video analytics offer unique solutions to classify objects, detect tampering, trigger alerts, and count people/vehicles. But of course none of this software is useful without cameras.

Cisco offers superior performance in a wide variety of environments with high-resolution, professional digital cameras. Depending on your needs, Cisco offers features like pan-tilt-zoom (PTZ), 1080p and H.264 compression, and models for indoor or outdoor environments. Video Surveillance Encoders can also be used for analog cameras to convert analog video to digital format.

Crimes affect every country, every economy, every community, and every person.  Cisco’s IP Video Surveillance systems use the network as a platform to make Cisco best in the world, and most important—best for a safe and more secure world.

Are We Really Secure?

By: Jonathan Taylor

Security is one of those concepts that sits in the back of one’s mind but is never put into practice until something happens. Ever heard the comment “I have an antivirus and a firewall. I should be ok?” In fact, that is where security starts. Security involves aspects like intrusion prevention/detection, physical security, network access control, policies and more.

The simplest aspect is physical security. Physical security includes things like making sure networking equipment is inaccessible to average users. This could include things like locking cabinets or placing the equipment in rooms where only administrative staff has keys. Also this includes having cable locks on computer equipment so that it is not stolen from the office. This is not a warning saying that everything needs to be chained to a desk, but this does help small companies that do not have some type of tracking system to see who comes and goes from the office to keep people from coming in late at night and taking valuables. Another portion of security is tracking employees via something like a card entry system. This will allow an employer to track employees to help with theft and other security related issues.

Next would be network access control. This refers to such things like system authentication via Microsoft Active Directory. This type of security can be applied as far down as the network layer. This is usually done with things like 802.1X authentication at the switch so that users can access network resources. Beyond this an engineer can also deploy access control lists (ACL’s) that will restrict what network resources the user has access to. There are products that have been introduced to the market that will allow an engineer to not only do 802.1X authentication but will also allow them to do such things like finger printing the operating system of the machine, do posturing of the machine to make sure it has the proper firewall along with antivirus, authenticate the user, and deliver downloadable ACL’s to that user based on username. This gives an administrator greater and tighter restrictions on the network to help prevent data theft from authorized and un-authorized users.

Intrusion prevention/detection is a very useful tool that most people overlook. Company A has a firewall to keep people out. It’s doing its job by disallowing all people from getting in but allowing all traffic out. Ports have been opened on the firewall to allow the public to access things like e-mail, web sites, SQL databases, etc. There is a hacker that is sitting in a coffee shop two states away that is running port scans against Company A’s firewalls. The hacker finds that a random port is open for the server that hosts Company A’s website. The hacker in a typical fashion tries to exploit this weakness to gain entry into the system. If there is a IPS in place it can detect the hacker trying gain access and actually prevent them from getting into Company A’s private network. This could help save a company from losing valuable information like financials, top-secret information, client lists, and so forth.

I am not saying that an engineer should go out and buy every security product under the sun to protect a network. I am trying to say that these threats are there and that security shouldn’t be an afterthought or reactive, but be proactive. As technology changes and evolves and the world becomes more mobile additional vulnerabilities will arise. Unless we use the technologies that are available to at least stay current to protect ourselves then we could all be at risk to losing something valuable.