<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Palo Alto Networks Research Center &#187; firewall</title>
	<atom:link href="http://www.paloaltonetworks.com/researchcenter/category/firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paloaltonetworks.com/researchcenter</link>
	<description>The Palo Alto Networks Research Center Blog</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:27:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>BusinessWeek and the &#8220;Facebook Generation&#8221;</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2011/10/businessweek-and-the-facebook-generation/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2011/10/businessweek-and-the-facebook-generation/#comments</comments>
		<pubDate>Sat, 22 Oct 2011 00:44:34 +0000</pubDate>
		<dc:creator>Rene Bonvanie</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>
		<category><![CDATA[enterprise 2.0]]></category>

		<guid isPermaLink="false">http://www.paloaltonetworks.com/researchcenter/?p=1776</guid>
		<description><![CDATA[A very big day for Palo Alto Networks, indeed. The significant time Ashlee Vance of Bloomberg BusinessWeek spent with Nir, our board members, customers and analysts resulted in an article we are very excited about: “Building a Firewall for the Facebook Generation”.  It tells the story of Palo Alto Networks&#8217; history and points towards our future potential. [...]]]></description>
			<content:encoded><![CDATA[<p>A very big day for Palo Alto Networks, indeed. The significant time Ashlee Vance of Bloomberg BusinessWeek spent with Nir, our board members, customers and analysts resulted in an article we are very excited about: “<a href="http://www.businessweek.com/magazine/building-a-firewall-for-the-facebook-generation-10202011.html">Building a Firewall for the Facebook Generation</a>”. <span id="more-1776"></span></p>
<p>It tells the story of Palo Alto Networks&#8217; history and points towards our future potential. It also articulates the desire of enterprise IT organizations to safely enable applications, rather than just blocking them outright. Like Nir says, “Our customers don’t want to block Facebook. They want to use it, but they also want some control.” David Cohen of All Facebook weighed in on the topic today with <a href="http://www.allfacebook.com/facebook-work-usage-2011-10">this post</a>.</p>
<p>Vance also calls out a recent report: “Gartner estimates that by the end of 2014, about 60 percent of firewall-type purchases will be for these next-generation products.” Finally, Gartner analyst John Pescatore nicely summed things up when he said, “firewalls need to evolve.”</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2011%2F10%2Fbusinessweek-and-the-facebook-generation%2F&amp;linkname=BusinessWeek%20and%20the%20%26%238220%3BFacebook%20Generation%26%238221%3B"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2011/10/businessweek-and-the-facebook-generation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Now More Than Ever.</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/10/now-more-than-ever/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/10/now-more-than-ever/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 03:09:22 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>

		<guid isPermaLink="false">http://www.paloaltonetworks.com/wp2/?p=781</guid>
		<description><![CDATA[Now more than ever, business and security teams need to align their business priorities. Case in point, highlighted by two recent articles on social networking use in the business world. The first article, published in eWeek UK, states that most CIOs are blocking (or trying to block) social networking sites. http://www.eweekeurope.co.uk/news/cios-frown-on-social-networking-at-work-2007 http://community.zdnet.co.uk/blog/0,1000000567,10014107o-114626b,00.htm https://www.mckinseyquarterly.com/home.aspx http://www.aiim.org/ In [...]]]></description>
			<content:encoded><![CDATA[<p>Now more than ever, business and security teams need to align their business priorities. Case in point, highlighted by two recent articles on social networking use in the business world. The first article, published in eWeek UK, states that most CIOs are blocking (or trying to block) social networking sites.</p>
<p><a href="http://www.eweekeurope.co.uk/news/cios-frown-on-social-networking-at-work-2007">http://www.eweekeurope.co.uk/news/cios-frown-on-social-networking-at-work-2007</a> <a title="http://community.zdnet.co.uk/blog/0,1000000567,10014107o-114626b,00.htm" href="http://community.zdnet.co.uk/blog/0,1000000567,10014107o-114626b,00.htm">http://community.zdnet.co.uk/blog/0,1000000567,10014107o-114626b,00.htm</a> <a href="https://www.mckinseyquarterly.com/home.aspx">https://www.mckinseyquarterly.com/home.aspx</a> <a href="http://www.aiim.org/">http://www.aiim.org/</a> <span id="more-781"></span></p>
<p>In response to the eWeek article, this author raises the case that if there are business benefits to be derived in the use of social networking, then it should be allowed.</p>
<p>We could not agree more. Although we would add the caveat that they should be allowed provided that regulatory policies remain in tact and are adhered to. The position of summarily blocking a new or unknown application is unreasonable and in some cases, could be career limiting. Imagine that the CIO blocks the CEO’s favorite application.</p>
<p>Looking specifically at social networking users, most of them are in the 35 and under age group. The fastest growing group of users are those who are over 35. Currently, there are at least 30 social networking applications <a href="../../applipedia/">http://www.paloaltonetworks.com/applipedia/</a> available to end users with FaceBook as the most dominant. 315 MILLION users.</p>
<p>What does this mean? It means that theses users will be in the workforce for many years to come and they are accustomed to using these applications whenever they want. So it makes sense to figure out a social media strategy that benefits employees and the company itself. Two reports from AIIM  and McKinsey  both highlight the fact that social networking, and the other web 2.0/enterprise 2.0 applications are indeed resulting in measurable benefits. If they are spending too much time on these applications, then perhaps it is a personnel issue – not an application issue.</p>
<p>Now more than ever. It’s time to fix the firewall.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F10%2Fnow-more-than-ever%2F&amp;linkname=Now%20More%20Than%20Ever."><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/10/now-more-than-ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Traffic Analysis: P2P Found 92% of the Time</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/07/traffic-analysis-p2p-found-92-of-the-time/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/07/traffic-analysis-p2p-found-92-of-the-time/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 18:00:52 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>
		<category><![CDATA[application usage & risk report]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=276</guid>
		<description><![CDATA[The most recent discovery of the first lady’s safe house (Laura Bush) and a detailed list of the civilian nuclear complex, including precise locations of weapons grade nuclear fuel follows closely on the heals of previous P2P discoveries of Marine One blueprints and healthcare records. Should we really be surprised? No not really, given the [...]]]></description>
			<content:encoded><![CDATA[<p>The most recent discovery of the <a href="http://voices.washingtonpost.com/securityfix/2009/07/report_locations_of_all_us_nuc.html?wprss=securityfix">first lady’s safe house (Laura Bush) and a detailed list of the civilian nuclear complex, including precise locations of weapons grade nuclear fuel </a>follows closely on the heals of previous P2P discoveries of Marine One blueprints and healthcare records.</p>
<p>Should we really be surprised? No not really, given the findings form the latest <a href="http://www.paloaltonetworks.com/literature/AUR_report0409.html">Application Usage and Risk Report: </a></p>
<p>* An average of six P2P variants were found in 9 out of 10 organizations.<br />
* In one extreme case, 17 P2P variants were found. <span id="more-276"></span><br />
* The most common P2P applications found were BitTorrent and Gnutella – both at 68%<br />
* Bandwidth consumed was a whopping 2.3 terabytes, or 5% of the total bandwidth viewed across the participating enterprises.</p>
<div id="attachment_279" class="wp-caption aligncenter" style="width: 568px"><img class="size-full wp-image-279" title="rampant_p2p_use1" src="http://blog.paloaltonetworks.com/wp-content/uploads/2009/07/rampant_p2p_use1.jpg" alt="he most commonly detected P2P-based file sharing applications found across the 63 participating organizations." width="558" height="329" /><p class="wp-caption-text">The most commonly detected P2P-based file sharing applications found across the 63 participating organizations.</p></div>
<p>The logical question is: why can’t enterprises stop P2P usage? There are several reason why.</p>
<p>The first reason is that employees are using what ever application they want. And in the case of P2P, the enterprise networks are typically far faster than home networks so why not take advantage of the connection speeds.</p>
<p>Dovetailing nicely into the high speed network access is the ability to get music, movies, software, and many things for free. Copy right laws are easily ignored when the latest movie, only seen in theatres, can be downloaded for free.</p>
<p>Possibly the most significant reason that IT cannot stop P2P is the plain fact that P2P applications use a variety of techniques to pass through the existing security infrastructures. Common techniques include port hopping and masquerading as HTTP. And as security administrators developed ad hoc techniques to detect these applications, P2P developers modified the application to use proprietary encryption as a means of bypassing the firewall, and signature based detection mechanisms. For example, uTorrent, the official BitTorrent client, uses proprietary encryption to evade detection.</p>
<p>Can Palo Alto Networks next-generation firewalls help?</p>
<p>We think we can. We can identify and control more than 40 P2P networks including BitTorrent, eMule, and LimeWire with more added as they are released to market. <a href="http://ww2.paloaltonetworks.com/applipedia/">See the entire list here</a>. Our customers are using our next generation firewall to reign in the use of these applications – blocking use for others while enabling controlled use for some (like engineers who need Linux distributions). Want to learn more? Check out the <a href="http://www.paloaltonetworks.com/literature/whitepapers/Controlling_P2P_Apps.pdf">whitepaper on controlling P2P</a>.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F07%2Ftraffic-analysis-p2p-found-92-of-the-time%2F&amp;linkname=Traffic%20Analysis%3A%20P2P%20Found%2092%25%20of%20the%20Time"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/07/traffic-analysis-p2p-found-92-of-the-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPv6 Threat &#8211; Real or Perceived?</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/07/ipv6-threat-real-or-perceived/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/07/ipv6-threat-real-or-perceived/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 23:20:35 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=270</guid>
		<description><![CDATA[This Network World article talks about the hidden threat posed by rogue IPv6 usage. To a certain extent, this is a bit of a red herring and here’s why. For IPv6 to traverse the corporate network, the routers, switches and infrastructure components need to (a) support IPv6 and (b) it has to be enabled. Now, [...]]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://www.networkworld.com/news/2009/071309-rogue-ipv6.html">Network World </a>article talks about the hidden threat posed by rogue IPv6 usage. To a certain extent, this is a bit of a red herring and here’s why. For IPv6 to traverse the corporate network, the routers, switches and infrastructure components need to (a) support IPv6 and (b) it has to be enabled.</p>
<p>Now, assuming that the infrastructure is indeed up to date and that the IPv6 is enabled, then and only then will the rogue IPv6 become an issue. At this point, many of the security infrastructure vendors will fail to stop the use. Palo Alto Networks is different. Here is how we can help alleviate this issue before it becomes one.<span id="more-270"></span></p>
<p>* We can detect and block IPv6 with a set of signatures and decoders included in App-ID.<br />
* If IPv6 is allowed, we can detect that traffic, and then apply appropriate security polices to the traffic (allow, deny, inspect for malware and threats).<br />
* In the event that an intrepid employee is using IPv6 tunneled inside IPv4, we can detect and block that use as well.</p>
<p>Perhaps I have simplified it too much? Let us know if you agree.</p>
<p>To learn more about the applications, protocols and services we detect and control, check out the <a href="http://ww2.paloaltonetworks.com/applipedia/?id=ipv6">applipedia. </a></p>
<p>Thanks for reading.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F07%2Fipv6-threat-real-or-perceived%2F&amp;linkname=IPv6%20Threat%20%26%238211%3B%20Real%20or%20Perceived%3F"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/07/ipv6-threat-real-or-perceived/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Case for Application Enablement</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/07/the-case-for-application-enablement/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/07/the-case-for-application-enablement/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 20:36:14 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[application usage & risk report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=256</guid>
		<description><![CDATA[What do LinkedIn, Twitter, Blogging and Wikis have in common? According to this article, they are increasingly used within enterprises with a quarter of organizations actually rolling out these types of tools across all departments, up from 12% in the previous survey. The survey also points out the blended use of these applications for both [...]]]></description>
			<content:encoded><![CDATA[<p>What do <a href="http://ww2.paloaltonetworks.com/applipedia/apps/linkedin">LinkedIn</a>, <a href="http://ww2.paloaltonetworks.com/applipedia/apps/twitter">Twitter</a>, Blogging and Wikis have in common? According to this <a href="http://www.prosecurityzone.com/Customisation/News/Education_Training_and_Professional_Services/Books_magazines_journals_analysis_and_reports/Web_20_technology_in_the_enterprise_takes_off.asp">article</a>, they are increasingly used within enterprises with a quarter of organizations actually rolling out these types of tools across all departments, up from 12% in the previous survey. The survey also points out the blended use of these applications for both business and professional purposes.<BR><BR></p>
<ul>
<li> LinkedIn is twice as popular as FaceBook for business networking, and 68% think that professional networking on the web is vital to career progression.</li>
<li> 27% of people aged 18-30 consider Twitter is an important rapid-feedback tool for business. Only 7% of those over 45 agree. </li>
</ul>
<p><span id="more-256"></span></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><strong>July 14 update &#8211; </strong> Two more proof points on why companies need to positively enable applications. Both articles talk about how new employees are pressing employers for more lenient web surfing policies. The balance of course is allowing not only web use, but the use of non-web based applications, in a secure manner.</p>
<p><a href="http://www.google.com/hostednews/ap/article/ALeqM5jqxzAma9_6gLCKPQtfvB6kFQhKZgD99D1Q8O0">From the AP article: </a></p>
<p><em>It&#8217;s no different than spending too much time around the water cooler or making too many personal phone calls. Do you take those away? No,&#8221; says Gary Rudman, president of GTR Consulting, a market research firm that tracks the habits of young people. &#8220;These two worlds will continue to collide until There&#8217;s a mutual understanding that performance, not Internet usage, is what really matters.&#8221;</p>
<p>This is, after all, a generation of young people known for what University of Toronto sociologist Barry Wellman calls &#8220;media multiplexity.&#8221; College students he has studied tell him how they sleep with their  smart phones and, in some cases, consider their gadgets to be like a part of their bodies. They&#8217;re also less likely to fit the traditional 9-to-5 work mode and are willing to put in time after hours in exchange for flexibility, including online time.</p>
<p>So, Wellman and others argue, why not embrace that working style when possible, rather than fight it?<br />
</em></p>
<p><a href="http://techdirt.com/articles/20090712/2332215520.shtml">From the Techdirt article: </a></p>
<p><em>It&#8217;s not hard to figure out why, really. First, allowing for a good balance between the two allows workers to take short mental breaks which allows them to be more fully focused on work when needed. On top of that, they don&#8217;t have to worry about personal things while at work, but can take care of issues quickly and easily. Finally, and most importantly, many start using social networking and other online tools to help them work. After all, despite what naysayers say, these tools can be very useful in many different jobs.</em></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>More interesting is the fact that while most companies have security and approval policies for the use of corporate tools such as email and press releases, very few have the same for the use of these applications.<br />
<em>“…we found that whereas nearly all businesses have policies on the use and content of emails, only 30% set similar policies for blogs, wikis and forums.” [<a href="http://www.aiim.org/Research/Collaboration-Enterprise20-Research.aspx">see full report here– registration required</a>]. </em></p>
<p>This policy discrepancy strengthens the case for what we call positive application enablement. A process by which the security team, in conjunction with the business units perform the following:<br />
•	<a href="http://www.paloaltonetworks.com/technology/appid.html">Identify the application</a> and what it is being used for.<br />
•	<a href="http://www.paloaltonetworks.com/technology/userid.html">Determine who</a> is using it.<br />
•	<a href="http://www.paloaltonetworks.com/products/policy.html">Decide whether or not to</a> allow it – if so, under what conditions and parameters.<br />
•	<a href="http://www.paloaltonetworks.com/technology/contentid.html">Scan</a> the allowed content.<br />
•	<a href="http://www.paloaltonetworks.com/products/reporting.html">Log and report</a> on the activity.</p>
<p><a href="http://blog.paloaltonetworks.com/?p=224">As we have said before</a>, the days of blocking applications that might not be “approved” are gone. These applications are here to stay. The applications themselves are not risks, but make no mistake, they can introduce risks and as such, need to be secured right along side <a href="http://ww2.paloaltonetworks.com/applipedia/apps/oracle">Oracle</a>, <a href="http://ww2.paloaltonetworks.com/applipedia/apps/sap">SAP</a>, <a href="http://ww2.paloaltonetworks.com/applipedia/apps/sharepoint">SharePoint </a>and other business applications.</p>
<p>Thanks for reading.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F07%2Fthe-case-for-application-enablement%2F&amp;linkname=The%20Case%20for%20Application%20Enablement"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/07/the-case-for-application-enablement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Applications are like dogs</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/06/applications-are-like-dogs/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/06/applications-are-like-dogs/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 00:15:08 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[application usage & risk report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=234</guid>
		<description><![CDATA[A recent survey assembled by RSA and IDG on the “hyper-extended enterprise” highlighted the challenges enterprises face as they move at light speed into the new applications landscape and two points stuck out. The first point was that enterprises need to rework their acceptable use policies and the second is that users need to be [...]]]></description>
			<content:encoded><![CDATA[<p>A recent survey <a href="http://www.rsa.com/innovation/docs/IDGResearchWhitePaper_Final_060409.pdf">assembled by RSA and IDG on the “hyper-extended enterprise” highlighted the challenges enterprises face as they move at light speed into the new applications landscape and two points stuck out. The first point was that enterprises need to rework their acceptable use policies and the second is that users need to be educated on that policy</a>. This got me to thinking (dangerous, I know) that applications are like dogs. Here is how I came to this analogy. <span id="more-234"></span></p>
<p>I like dogs. Preferably big, active, smart dogs. So it stands to reason that I would like the American Staffordshire Terrier, a recognized member of the Terrier Group according to the <a href="www.akc.org/">American Kennel Club (AKC)</a>. Never heard of this breed? Maybe you’ve heard of a Pit Bull – a breed that can strike fear into many people because of the highly visible nature of their attacks. Ask any dog trainer or avid dog lover and they will tell you that there are no bad dogs – merely bad dog owners. Bad dog owners who mistreat the dogs, train them to fit, follow improper breeding practices and so on. Sure, this is open to debate and this is not the forum for such a debate.</p>
<p>Let’s look at a couple of examples of how applications are like dogs.</p>
<p><strong>P2P:</strong> The underlying technology was developed back in the early days of networking as a means of moving large files by harnessing unused computing resources. The premise still works today in commercially available applications like BitTorrent, Gnutella and many others. Everyone know that the rap against P2P that they are used to illegally share files. Worse yet, many of the largest data breaches were the result of improperly configured P2P applications. Yet properly configured and used by say, IT, P2P is a very powerful tool. See the relationship here? Employee records do not naturally migrate to a P2P network. MarineOne blueprints are not stored on a P2P network. Users are the ones who are sharing the files. Users are the ones who failed to properly configure the application.</p>
<p><strong>TOR (The Onion Router):</strong> Developed by the US military to encrypt spy and covert operation communications and is now in the public domain. Not only is the message encrypted, it uses other TOR nodes to send the data, finally being assembled by the intended recipient. The advantage here is that no one node has all the data so intercepting it is of little use. In an oppressive regime, TOR is an invaluable tool and it is recommended by several human rights organizations as a tool to communication with the outside world. In the hands of an employee or student, TOR is a black hole that acts as an avenue for threats (inbound) and data leakage (outbound). Again, the application is not acting on its own. It is acting on the commands of the user.</p>
<p>Ok, P2P and TOR may be extreme cases (and easy pickings). Let’s see how social networking applications like <strong>FaceBook and MySpace </strong>hold up to the analogy. Both applications are designed to keep friends, colleagues and family updated on what’s happening. An admirable goal to be sure. Yet social networking has been invaded by malware writers who prey on users who do not think before they click. Case in point, a friend received a FaceBook update from someone they thought was a friend – the update had a URL in it. So you guessed it, they clicked it. Bad user! The PC is infected with malware.</p>
<p>I challenge you to take any application and put it to this test. My guess is that more often than not, you will come to the same conclusion. There are several points to my ramblings.</p>
<p><strong>Applications are not threats. </strong>The threats are from what the users do with them and the content that is transferred. If enterprises treat applications as threats, several things may occur:<br />
1) The CEO may be the one using the application which may result in a quick termination.<br />
2) The application in use may be benefiting the bottom line, so why stop it.<br />
3) Today’s employees expect to be able to use many of these types of applications, so blocking them may reduce the ability to attract new employees. (No bad dogs, remember).</p>
<p><strong>IT must become business enablers.</strong> The application landscape is moving more rapidly than ever before and it is an understandable challenge for IT to keep up. But somehow they need to determine what applications are on their network and then analyze the risk and weigh it with the business benefit. If the trade-offs are positive, then the use should be documented as part of the appropriate application usage policy. (IT needs to train the users dog owners).</p>
<p><strong>Educate users on the appropriate application usage policy.</strong> When we ask companies (IT guys) what their appropriate application usage policy is, they tend to laugh, or ask “what policy” or worse yet, say we do not have one. Many of our customers are using our solution to achieve the two previous points and in so do, make their application usage policy a living, breathing document that is reviewed on a regular basis, as users try new applications. Just like dogs will continually learn what the master allows and press for more, so to will users.</p>
<p>Thanks for putting up with me.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F06%2Fapplications-are-like-dogs%2F&amp;linkname=Applications%20are%20like%20dogs"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/06/applications-are-like-dogs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Please Ignore That Sucking Sound…</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/05/please-ignore-that-sucking-sound%e2%80%a6/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/05/please-ignore-that-sucking-sound%e2%80%a6/#comments</comments>
		<pubDate>Fri, 22 May 2009 18:48:09 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[application usage & risk report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>
		<category><![CDATA[streaming media]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=211</guid>
		<description><![CDATA[It is merely the bandwidth being consumed by video (and photo) application usage. A somewhat random factoid posted on TechCrunch.com stated that every minute, 20 hours of video is uploaded to YouTube. Think about that. There are 1,440 minutes in a day, which equates to 2,880 hours of video. It is a remarkable statistic, given [...]]]></description>
			<content:encoded><![CDATA[<p>It is merely the bandwidth being consumed by video (and photo) application usage. A somewhat random factoid posted on <a href="http://www.techcrunch.com/2009/05/20/every-minute-just-about-a-days-worth-of-video-is-uploaded-to-youtube/">TechCrunch.com stated that every minute, 20 hours of video is uploaded to YouTube</a>. Think about that. There are 1,440 minutes in a day, which equates to 2,880 hours of video. It is a remarkable statistic, given that YouTube videos are not full featured films or TV shows.</p>
<p><a href="http://blog.nielsen.com/nielsenwire/nielsen-news/americans-watching-more-tv-than-ever/">The YouTube statistic combined with a recent Nielsen report confirms that users</a>, at home or at work, are using the Internet to entertain themselves. The Nielsen report shows that the hours of Internet video watched, at home and at work, is up 53.2% to just about 3 hours per month. <span id="more-211"></span></p>
<p>The one thing that neither of these statistics looked at specifically was the use of video/photo applications within the enterprise. During our own analysis summarized in the <a href="http://www.paloaltonetworks.com/literature/AUR_report0409.html">Application Usage and Risk Report</a>,  guess which application consumed the highest amount of bandwidth? You guessed it. YouTube gobbled up nearly gig of bandwidth.</p>
<p><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/uploads/2009/05/vidoe_bw_consumed_web5.jpg" alt="vidoe_bw_consumed_web5" width="512" height="407" class="aligncenter size-full wp-image-214" /></p>
<p>Delving more deeply into the video application findings within the report shows the following:<br />
<em>* A sizable 4.4 terabytes of bandwidth was consumed by video applications alone, nearly double the amount observed in the previous report (2.3 terabytes).<br />
*  There were 44 different photo/video applications found – up from 30 detected in the previous report.<br />
*  The underlying technology used is primarily browser-based (24) with p2p and client/server powering 10 applications each.</em></p>
<p>To a certain extent, these enterprise specific statistics support the findings mentioned earlier in this post – video use and the corresponding bandwidth consumption is up.</p>
<p>Before the naysayers jump on me and say employees should be allowed to do what they want, let’s be perfectly clear here – no one is saying we should block these applications. The decision on what to do with these applications is left entirely to the corporations. In nearly every case, our customers felt their bandwidth was being consumed by non-business applications but were unsure which ones. Now they know which are the heaviest consumers – both in terms of applications and users. Some customers are hardnosed about it, blocking the use, others are merely collecting data while others are re-writing their policies, allowing the use but scanning for threats. In one case, the applications were blocked and user backlash was such that management bought a bigger pipe, allowing use but adding control elements around it.</p>
<p>The bottom line is that now the customers know that a big chunk of that sucking sound is video oriented.</p>
<p>Thx for reading.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F05%2Fplease-ignore-that-sucking-sound%25e2%2580%25a6%2F&amp;linkname=Please%20Ignore%20That%20Sucking%20Sound%E2%80%A6"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/05/please-ignore-that-sucking-sound%e2%80%a6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hulu Networks’ Battle Against External Proxies</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/05/hulu-networks%e2%80%99-battle-against-external-proxies/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/05/hulu-networks%e2%80%99-battle-against-external-proxies/#comments</comments>
		<pubDate>Tue, 12 May 2009 14:45:47 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[application usage & risk report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[circumvention]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=171</guid>
		<description><![CDATA[This TechCrunch article outlines how Hulu Networks, the rapidly growing purveyor of streaming HD content, is taking some fairly extreme steps to make sure that their content is only accessed by users in the US. Apparently anyone with an anonymous IP address is blocked. An interesting step that will, in all likelihood, fail. Why? It’s [...]]]></description>
			<content:encoded><![CDATA[<p>This <a href="http://www.techcrunch.com/2009/05/06/control-freaks-hulu-now-blocks-anonymous-proxies-too/">TechCrunch article outlines how Hulu Networks</a>, the rapidly growing purveyor of streaming HD content, is taking some fairly extreme steps to make sure that their content is only accessed by users in the US. Apparently anyone with an anonymous IP address is blocked. An interesting step that will, in all likelihood, fail.</p>
<p>Why? It’s all about numbers. There are millions of users worldwide who want access to their content. And as we discuss in this <a href="http://threatpost.com/blogs/how-employees-evade-it-security-controls">ThreatPost article</a>, users will proactively circumvent controls. A 45 second search on the web provides a wealth of information on how to circumvent security controls and blocking mechanisms. Some examples:<br />
*  There are at least 7700 public proxies that users can access merely by visiting proxy.org.<br />
*  Users can build their own private proxy.<br />
*  Visit circumventor.net to find a list of circumvention tools.<br />
*  There are new encrypted tunneling applications like <a href="http://ww2.paloaltonetworks.com/applipedia/apps/gbridge">Gbridge</a> popping up on a regular basis.<br />
I could go on. And while I am sure that Hulu has a very smart and dedicated team of IT professionals, can they win against millions? My view is that they will not because of the sheer numbers. But I do wish them luck. But let’s look on the bright side, they have a good product and people want it.</p>
<p>Thanks for reading.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F05%2Fhulu-networks%25e2%2580%2599-battle-against-external-proxies%2F&amp;linkname=Hulu%20Networks%E2%80%99%20Battle%20Against%20External%20Proxies"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/05/hulu-networks%e2%80%99-battle-against-external-proxies/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Remote Desktop Control – Valuable Tool or Gaping Hole?</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/04/remote-desktop-control-and-management-%e2%80%93-valuable-tool-or-gaping-hole/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/04/remote-desktop-control-and-management-%e2%80%93-valuable-tool-or-gaping-hole/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 17:59:03 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[application usage & risk report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[application control]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=162</guid>
		<description><![CDATA[Today’s post will cover several interesting tidbits of data about remote control products. The first tidbit comes from the recently released Verizon Data Breach Report which paints a detailed picture of how cybercrime is making money. The report looked at 90 data breaches that resulted in a loss of 285 million records. The item that [...]]]></description>
			<content:encoded><![CDATA[<p>Today’s post will cover several interesting tidbits of data about remote control products. The first tidbit comes from the recently released <a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf">Verizon Data Breach Report</a> which paints a detailed picture of how cybercrime is making money. The report looked at 90 data breaches that resulted in a loss of 285 million records. The item that struck me as interesting is the section discussing attack vectors.</p>
<p><em>“In approximately four of 10 hacking-related breaches, an attacker gained unauthorized access to the victim via one of the many types of remote access and management software. Rather than for internal usage, most of these connections were provisioned to third parties in order to remotely administer systems. As discussed extensively in this and previous reports, the ultimate attacker is not typically the third party (although that certainly happens). More often, an external entity compromises the partner and then uses trusted connections to access the victim. From the victim’s perspective the attacker appears to be an authorized third party, making this scenario particularly problematic. This is especially so when trusted access is coupled with default credentials.”</em> <span id="more-162"></span></p>
<p>Why is it interesting to me? Because our own <a href="http://www.paloaltonetworks.com/literature/AUR_report0409.html">Application Usage and Risk Report (April 2009)</a> indicates that these types of applications are being used not only by IT – but also by sophisticated employees who want to access their home machine – or someone else’s &#8211; while they are at work. Overall we found that 95% of the companies who participated in the analysis had remote control applications present. Not surprising really. What is surprising is [1] the breadth of application variants (24 different remote access control applications) and [2] the high rate of SSH usage (89% out of 63).</p>
<p>No doubt there are IT personnel in this group, but we know from looking at the user names and talking with customers that SSH usage is expanding to non-IT users. These intrepid users are accessing their home machines to do whatever they want. Little do they know that they are exposing themselves and the company they work for to numerous business and security risks. A visit to wikipedia provides background on SSH, free dameons and clients for anyone to use. And today’s end users ARE smart enough (or bold enough?) to use these tools.</p>
<p>But as the Verizon Data Breach Report points out, remote access applications carry risk – which is confirmed by the <a href="http://isc.sans.org/diary.html?storyid=6214">Internet Storm Center article about SSH</a>. This article reminds IT folks to tighten their controls around SSH – particularly the passwords – which are easy to crack if less than 8 characters. So the 89% of the companies we found using SSH had better make sure that their SSH is locked down.</p>
<p>So back to the question in the title: are remote desktop access/control applications valuable? Without question – yes &#8212; assuming proper controls and security are implemented and is being followed. But given the two data points above, it looks like we need to do some work.</p>
<p>Thx for reading.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F04%2Fremote-desktop-control-and-management-%25e2%2580%2593-valuable-tool-or-gaping-hole%2F&amp;linkname=Remote%20Desktop%20Control%20%E2%80%93%20Valuable%20Tool%20or%20Gaping%20Hole%3F"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/04/remote-desktop-control-and-management-%e2%80%93-valuable-tool-or-gaping-hole/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Real Data Does Not Lie &#8211; Existing Security Controls Are Failing</title>
		<link>http://www.paloaltonetworks.com/researchcenter/2009/04/real-data-does-not-lie-existing-security-controls-are-failing/</link>
		<comments>http://www.paloaltonetworks.com/researchcenter/2009/04/real-data-does-not-lie-existing-security-controls-are-failing/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 16:33:01 +0000</pubDate>
		<dc:creator>Matt</dc:creator>
				<category><![CDATA[Application Advisory/Analysis]]></category>
		<category><![CDATA[application usage & risk report]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Threat Advisory/Analysis]]></category>

		<guid isPermaLink="false">http://blog.paloaltonetworks.com/?p=153</guid>
		<description><![CDATA[On April 15th, we participated in a very successful webinar with Dark Reading entitled “Why Bad Security Breaches Keep Happening To Good Organizations”. During the back and forth between the two speakers, we took a poll of the attendees, asking them the following question: Which applications do you think are currently running in your organization’s [...]]]></description>
			<content:encoded><![CDATA[<p>On April 15th, we participated in a very successful webinar with Dark Reading entitled <a href="http://w.on24.com/r.htm?e=137541&amp;s=1&amp;k=0A946C145A3AE17BD5D3C1D66FBD6DFA">“Why Bad Security Breaches Keep Happening To Good Organizations”</a>. During the back and forth between the two speakers, we took a poll of the attendees, asking them the following question:</p>
<p><strong>Which applications do you think are currently running in your organization’s IT environment? Attendees were able to select all that applied and the results of a total of 181 votes showed the following:</strong> <span id="more-153"></span><br />
<em>  P2P  43.6% (79)<br />
  Google apps  73.5% (133)<br />
  Anonymizers/proxies  33.7% (61)<br />
  Unauthorized IM  56.4% (102)<br />
  Encrypted tunneling apps (e.g. TOR)Â   43.6% (79)</em></p>
<p>In this case, the poll is a valuable tool to keep audience members engaged but often times they do not show all the data or tell the entire story.</p>
<p>Here’s why I say this. Our recently published <a href="http://www.paloaltonetworks.com/literature/AUR_report0409.html">Application Usage and Risk Report</a> analyzed application traffic on more than 60 customer networks and the findings show very different numbers.<br />
<em>  P2P 92%<br />
  Google apps  81%<br />
  Anonymizers/proxies  81%<br />
  Unauthorized IM  97% (to be fair, we did not ask if the use of IM is approved or not).<br />
  Encrypted tunneling apps (e.g. TOR) 11%</em></p>
<p>Real data always tells a more complete story. And what this report tells us is that enterprises collectively spend more than $6 billion annually on firewall, IPS, proxy and URL filtering products – yet the data shows that these products are unable to control the application traffic traversing the network. Here’s some of the key findings to support that conclusion.</p>
<p><em><strong>* Applications are designed for accessibility.</strong> More than half of the nearly 500 unique applications found are “firewall friendly” in that they can hop from port to port, use port 80 or port 443 as a means of simplifying end-user access.<br />
  <strong>* Users are actively circumventing security controls.</strong> Employees are going to the extreme measure of using external proxies (typically not endorsed by corporate IT), remote desktop access and encrypted tunnel applications to do what they want on the network.<br />
  <strong>* File sharing usage is rampant.</strong> Despite the known risks, employee use of P2P is rampant and browser-based file sharing has effectively doubled in use over the last 12 months. </em></p>
<p>What else did we find? We found more than 111 collaborative applications – social networking, email, webmail, IM, blogging – you name it we found it. Many of these applications are beneficial. <a href="http://blogs.gartner.com/david_m_smith/">David Smith, from Gartner </a>comments in this <a href="http://www.scmagazineus.com/The-benefits-and-dangers-of-consumer-applications-in-business/article/130761/">SC Magazine article</a> that “some applications enable users to more easily do their job”. Absolutely true. No question about it. But when employees use them without IT oversight and the associated security, then the company is exposed to unnecessary business and security risks. Bill Brenner from CSO Magazine summarizes some of the risks in his article about the <a href="http://www.csoonline.com/article/489402/Botnets_Reasons_It_s_Getting_Harder_to_Find_and_Fight_Them">4 Reasons Botnets are Hard to Fight</a>.</p>
<p>You get the picture. I encourage you to read the executive summary, download the report or listen to a 10 minute overview <a href="http://www.paloaltonetworks.com/literature/AUR_report0409.html">here</a>.</p>
<p>Check it out. Post a comment. The data does not lie.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paloaltonetworks.com%2Fresearchcenter%2F2009%2F04%2Freal-data-does-not-lie-existing-security-controls-are-failing%2F&amp;linkname=Real%20Data%20Does%20Not%20Lie%20%26%238211%3B%20Existing%20Security%20Controls%20Are%20Failing"><img src="http://www.paloaltonetworks.com/researchcenter/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.paloaltonetworks.com/researchcenter/2009/04/real-data-does-not-lie-existing-security-controls-are-failing/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

