
Virtual
Private Networking
Site-to Site VPNs
Remote Access VPNs
Firewall Landscape
Intrusion Detection
Network Scanning Risk Assessment “Ethical
Hacking”
Physical Security
End User Security (monitoring)
Security Management
Consulting Services
E-mail security
Insurance and Reinsurance /Monitoring
When a tree falls in
the forest and no one is around to hear it, it sure certainly makes
a sound. But if a computer network has security vulnerability and no
one knows about it, is it insecure? Only the most extreme Berkelian
idealist might argue against the former, but the latter is not
nearly so obvious.
A network with security vulnerability is insecure to those who know
about the vulnerability. If no one knows about it – if it is a
literally a vulnerability that has not been discovered – then the
network is secure. If one person knows about it, then the network is
insecure to everyone else. If the network equipment manufacturer
knows about it… if security researchers know about it… if the
hacking community knows about it – the insecurity of the network
increases as news of the vulnerability gets out.
Virtual Private Networking
Corporations use VPN’s to establish secure, end-to-end private
network connections over a public networking infrastructure. VPNs
have two main applications: site-to-site and remote-access
connectivity. VPNs are like armored transport cars, permitting
secure, confidential transit between two or more locations though a
public network.
Site-to Site VPNs
Site-to-site VPNs are alternative wide-area-networks (WAN)
infrastructure. They replace and augment existing private networks
that utilize leased lines, frame relay, or Asynchronous Transfer
Mode (ATM) to connect remote branch offices and central sites.
Site-to-site VPNs do not inherently change private WAN requirements,
such as support for multiple protocols, high reliability, and
extensive scalability, but instead meet these requirements more cost
effectively and with greater flexibility. Site-to-site VPNs can
utilize most pervasive transport technologies available today, such
as the public Internet or service provider IP networks, by employing
tunneling and encryption for data privacy and quality of service (QoS)
for transport reliability.
Remote Access VPNs
VPNs have become logical for remote-access connectivity. Deploying a
remote-access VPN enables corporations to reduce communication
expenses by taking advantage of the local dialup infrastructures of
servers providers (ISPs). At the same time, VPNs allow mobile
workers, telecommuters, and day extenders to take advantage of
broadband connectivity over cable ISDN and DSL lines. To fully
realize the benefits of high-performance, remote –access VPNs, a
corporation must deploy a robust, highly-available VPN solution.
Purpose-built VPN devices are optimal for application.
Firewall Landscape
Two types of firewalls dominate the market today:
Application proxies and packet filtering gateways. While application
proxies are widely considered more secure than packet filtering
gateways, their restrictive nature and performance limitations have
kept their adoption limited to traffic out the company rather than
traffic into a company’s web server. Packet filtering gateways or
the more sophisticated packet filtering gateways, on the other hand,
can be found in many larger organizations with high performance
inbound traffic requirements.
Ever since the first firewall was plugged in, firewalls have
protected countless networks from prying eyes and malicious vandals
– but they are far from a security panacea. Security
vulnerabilities are discovered every year with just about every
firewall on the market. What’s worse, most firewalls are often
misconfigured, unmaintained, and unmonitored, turning them into
electronic doorstops (holding the gate wide open).
Intrusion Detection
Organizations continue to deploy firewalls as their central
gatekeepers to prevent unauthorized users from entering their
networks. However, network security is in many ways similar to
physical security in that no one technology serves all the needs –
rather, a layered defense provides the best results. Organizations
are increasingly looking to additional security technologies to
counter the risks and vulnerabilities that firewalls alone cannot
address. Network-Based Intrusion Detection System (IDS) solutions
provide around-the-clock network surveillance. They analyze the
packet data stream within the network, searching for unauthorized
activity, such attacks by hackers, enabling users to respond quickly
to security attacks. When authorized activity is detected, the IDS
can send alarms to a management console with details of the activity
and can often order other systems, such as routers, to terminate the
unauthorized sessions.
Network Scanning Risk Assessment “Ethical
Hacking”
Scanners conduct a detailed analysis of networked systems to compile
an electronic inventory to assets and detect vulnerabilities that
could result in a security compromise. This technology is
“proactive”, providing prevention insight into your security
posture and allowing you to fix security weaknesses before intruders
can exploit them. Scanning is like conducting a periodic building
walk-though to ensure that doors are locked and windows are closed
it helps you understand the risk.
Physical Security
Network scanning assessment alone is not enough, a physical security
assessment should take place in order to the Security Assessment be
complete, assessing the Network Operation Center (NOC), Network
Technology, Server locations and physical access….
End User Security (monitoring)
When monitoring end users, you can receive a report including
passwords, chat, email, sites visited, programs used, etc.
You can monitor whether an employee is working or wasting time
and/or the company’s resource's.
Security Management
A security management system enables the simple and uniform
deployment of network policies or rules throughout a network. These
policies may support various services, in particular, may include
several technologies and products such as firewalls, VPN gateway,
Intrusion Detection Sensors, and authentication and encryption
mechanisms. In comparison to physical network security, a security
manager is equivalent to a central security control room where
security personal can activate and monitor alarms and locks
throughout the building or the campus.
Consulting Services
A security assessment is concentrated analysis of the security
posture of a network, highlighting security weakness or
vulnerability that need to be improved. Periodic assessment are
needed to ensure that, in the midst of frequent changes in a
network, the security posture of that security assessment is like a
guard patrolling the entire secured area, checking locks on doors
and windows, reporting any irregularities that may exist, and
providing guidance for correction.
Network Security
E-mail security
In recent years, there has been a decided upswing in unsolicited
email, primarily of the commercial variety. Advertisers reputable
and otherwise have discovered that they can use telemarketing
techniques without spending a dime for each call.
Fortunately, there are ways to attempt to stem the flood and express
your displeasure. Be aware, however, that the "dedicated
spammers" are growing ever more canny as they practice their
trade. Don't just reply to the message in your box! Chances are,
you'll be sending mail to an invalid address or to an innocent
party, or even helping the spammer out by showing yourself as a
"live" address.
We provide email protection: filtering, antivirus, monitoring
Insurance and Reinsurance /Monitoring
Last year, the possibility of losing business to computer hackers
and viruses loomed on the horizon like threatening clouds, but the
reality of cyber-risk cracked like a thunderstorm over the insurance
industry in recent months. We can cover the business loss of these
companies with a certain amount of money as long as they follow our
security methodology and plans. We can take over and protect their
network/web site/ intranet/ VPN/Internet connection, to reduce there
losses, in keeping it updated 24/7/365 monitored around the clock
with a specialized team of security experts.
We provide security solutions and servers for:
1. e-banking
2. dot com
3. military
4. e-commerce
5. e-learning
6. e-government
7. enterprise network security: network strategy design and
implement
Training
Conduct training, for corporate IT professionals on Security
Products, Methodologies, physical security, intranet security,
network security… and Inconet Data Management Security
Certification.
For additional information please contact our Sales Department:
by email at sales@idm.net.lb
or by phone at 01-512 513
|