Join any G-TechEd Module and get a Calling (SIM) Tab along with your study material & G-Dream Service. For more information about G-TechEd Module Write us : info@gtechnosoft.in

Saturday, March 22, 2014

What is UTM ???

UTM (Unified Threat Management)


Unified Threat Management (UTM) is a solution in the network security industry, and since 2004 it has gained currency as a primary network gateway defense solution for organizations.In theory, UTM is the evolution of the traditional firewall into an all-inclusive security product able to perform multiple security functions within one single appliance: network firewall, network intrusion prevention and gateway antivirus (AV), gateway anti-spam, VPN, content filtering, load balancing, data leak prevention and on-appliance reporting.

The worldwide UTM market was approximately worth $1.2 billion in 2007, with a forecast of 35-40% compounded annual growth rate through 2011. The primary market of UTM providers is the SMB and enterprise segments, although a few providers are now providing UTM solutions for small offices/remote offices.

The term UTM was originally coined by market research firm IDC. The advantages of unified security lie in the fact that rather than administering multiple systems that individually handle antivirus, content filtering, intrusion prevention and spam filtering functions, organizations now have the flexibility to deploy a single UTM appliance that takes over all their functionality into a single rack mountable network appliance.

Unified threat management (UTM) refers to a comprehensive security product that includes protection against multiple threats. A UTM product typically includes a firewall, antivirus software, content filtering and a spam filter in a single integrated package. The term was originally coined by IDC, a provider of market data, analytics and related services. UTM vendors include Fortinet, LokTek, Secure Computing Corporation and Symantec.

The principal advantages of UTM are simplicity, streamlined installation and use, and the ability to update all the security functions or programs concurrently. As the nature and diversity of Internet threats evolves and grows more complex, UTM products can be tailored to keep up with them all. This eliminates the need for systems administrators to maintain multiple security programs over time.

Utility of UTM


A single UTM appliance simplifies management of a company's security strategy, with just one device taking the place of multiple layers of hardware and software. Also from one single centralized console, all the security solutions can be monitored and configured.

In this context, UTMs represent all-in-one security appliances that carry a variety of security capabilities including firewall, VPN, gateway anti-virus, gateway anti-spam, intrusion prevention, content filtering, bandwidth management, application control and centralized reporting as basic features. The UTM has a customized OS holding all the security features at one place, which can lead to better integration and throughput than a collection of disparate devices.

For enterprises with remote networks or distantly located offices, UTMs are a means to provide centralized security with control over their globally distributed networks.

Pros :


  • Reduced complexity: Single security solution. Single Vendor. Single AMC
  • Simplicity: Avoidance of multiple software installation and maintenance
  • Easy Management: Plug & Play Architecture, Web-based GUI for easy management
  • Reduced technical training requirements, one product to learn.
  • Regulatory compliance


Cons : 

  • Single point of failure for network traffic, unless HA is used
  • Single point of compromise if the UTM has vulnerabilities
  • Potential impact on latency and bandwidth when the UTM cannot keep up with the traffic


Some Popular UTM OEM







Wednesday, March 19, 2014

Tech News - A New Hacking Trend To Steal Your Google Account

A New Hacking Trend To Steal Your Google Account


Warning: If you receive an email with the subject "Documents," and it directs you to a webpage that looks like a Google Drive sign-in page, do not enter your information.

It's likely a new phishing scam, in which a thief creates a fake portal that asks for people's private information and then steals it. (Netflix recently faced a similar issue.)

This one uses a fake Google Drive landing page to get your Gmail address and password, cyber security company Symantec's official blog reported last Thursday. You're meant to think that the documents you'll be viewing are on Google Docs and that you need to sign in to see them. Remember, though, it's all a scam.

"We've removed the fake pages and our abuse team is working to prevent this kind of spoofing from happening again," a representative from Google tells The Huffington Post. "If you think you may have accidentally given out your account information, please reset your password."

If you were to put your Gmail address and password in the fake login, your credentials would be stolen, but you'd be taken to a real document on Google Docs, so you might not even know you'd been scammed, Symantec says.

With access to your Gmail account, scammers can make purchases on Google Play, use your Google+ account, access your Google Drive documents and more.

As always, the easiest way to protect yourself from phishing scams is to not click on unknown links and not open emails from unknown senders. Also, don't type your password anywhere that you're not 100 percent sure is real.




Tech News - WhatsApp and Android Security Flaws

WhatsApp and Android Security Flaws


WhatsApp, the mobile messaging company recently acquired by Facebook for $16 billion, said last week Thursday that reports of a security flaw in its system were “overstated”, 

Earlier this week, tech consultant and CTO at DoubleThink Bas Bosschert released a report warning that an exploit in the app’s Android encryption would enable another app to access WhatsApp chat transcripts and use them for any purpose. The key to the hack, according to Bosschert, is that WhatsApp uses a phone’s SD card to store messages, which “can be read by any Android application if the user allows it to access the SD card.”

However, WhatsApp denies that Bosschert’s methods are accurate. The company claims it’s not WhatsApp’s security problem — any user who downloads a malicious app that can access other information on the SD card is always at risk of losing information to hackers, WhatsApp’s data included.




Saturday, March 15, 2014

What is Distributed Denial of Service (DDoS) Attacks !!!


Distributed Denial of Service (DDoS) Attacks


A Distributed Denial-of-Service (DDoS) attack is one in which a multitude of compromised systems attack a single target, thereby causing denial of service for users of the targeted system. The flood of incoming messages to the target system essentially forces it to shut down, thereby denying service to the system to legitimate users.

In a typical DDoS attack, the assailant begins by exploiting a vulnerability in one computer system and making it the DDoS master. The attack master, also known as the botmaster, identifies and infects other vulnerable systems with malware. Eventually, the assailant instructs the controlled machines to launch an attack against a specified target. 

There are two types of DDoS attacks: a network-centric attack which overloads a service by using up bandwidth and an application-layer attack which overloads a service or database with application calls. The inundation of packets to the target causes a denial of service. While the media tends to focus on the target of a DDoS attack as the victim, in reality there are many victims in a DDoS attack -- the final target and as well the systems controlled by the intruder. Although the owners of co-opted computers are typically unaware that their computers have been compromised, they are nevertheless likely to suffer a degradation of service and not work well. 

A computer under the control of an intruder is known as a zombie or bot. A group of co-opted computers is known as a botnet or a zombie army. Both Kaspersky Labs and Symantec have identified botnets -- not spam, viruses, or worms -- as the biggest threat to Internet security.

Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root nameservers. DoS threats are also common in business, and are sometimes responsible for website attacks.This technique has now seen extensive use in certain games, used by server owners, or disgruntled competitors on games, such as server owners' popular Minecraft servers. Increasingly, DoS attacks have also been used as a form of resistance. Richard Stallman has stated that DoS is a form of 'Internet Street Protests’. The term is generally used relating to computer networks, but is not limited to this field; for example, it is also used in reference to CPU resource management.

One common method of attack involves saturating the target machine with external communications requests, so much so that it cannot respond to legitimate traffic, or responds so slowly as to be rendered essentially unavailable. Such attacks usually lead to a server overload. In general terms, DoS attacks are implemented by either forcing the targeted computer(s) to reset, or consuming its resources so that it can no longer provide its intended service or obstructing the communication media between the intended users and the victim so that they can no longer communicate adequately.

Denial-of-service attacks are considered violations of the Internet Architecture Board's Internet proper use policy, and also violate the acceptable use policies of virtually all Internet service providers. They also commonly constitute violations of the laws of individual nations.

The United States Computer Emergency Readiness Team (US-CERT) defines symptoms of denial-of-service attacks to include:

  • Unusually slow network performance (opening files or accessing web sites)
  • Unavailability of a particular web site
  • Inability to access any web site
  • Dramatic increase in the number of spam emails received—(this type of DoS attack is considered an e-mail bomb)
  • Disconnection of a wireless or wired internet connection
  • Long term denial of access to the web or any internet services



In the Police and Justice Act 2006, the United Kingdom specifically outlawed denial-of-service attacks and set a maximum penalty of 10 years in prison.

In the US, denial-of-service attacks may be considered a federal crime under the Computer Fraud and Abuse Act with penalties that include years of imprisonment. Many other countries have similar laws.


Wednesday, March 12, 2014

Four Important Tasks Need To Complete Before Migrating to Exchange 2013 from Exchange 2010


Preparing for a migration to Exchange Server 2013 is not a small activity. There are a number of tasks you must complete before you can even begin installing the Exchange 2013. Following some of the most important tasks you'll have to complete before you can bring an Exchange Server 2013 Client Access Server into an Exchange 2010 environment.

Task 1: Install the correct Service Packs (SP)


Make sure existing Exchange Servers are running the correct service pack level before migrating to Exchange 2013. All of your Exchange 2010 servers will need to be running SP3 for Exchange.

If your Exchange Server organization contains multiple Active Directory sites, you must apply the service pack to all the Exchange servers in the Internet-facing site first. Once that's done, you can begin applying the service pack to internal sites.


After your Exchange Server 2010 machines have been upgraded to the correct service pack version, you'll need to download Cumulative Update 2 for Exchange Server 2013. This update is necessary for Exchange Server 2010 and Exchange Server 2013 to coexist. You should be able to install the cumulative update without first installing Exchange Server 2013.

Task 2: Prepare Active Directory (AD)


Next you'll need to update Active Directory before migrating to Exchange 2013. To do so, you'll need administrative rights at the forest level and at the domain level. The account you use will also need Schema Admin permissions.

It's technically possible to skip the Active Directory preparation because Exchange Server setup will detect whether AD is ready and, assuming you have the correct permissions, will automatically prepare it. However, many organizations prefer to prepare the Active Directory ahead of time. Sometimes this is done to reduce the amount of time it takes to deploy the first Exchange 2013 server; it's more often because the Exchange admin lacks the appropriate permissions to modify the Active Directory schema. Microsoft provides instructions for updating AD.

Task 3: Set up a temporary Exchange Server


Microsoft made major architectural changes to the Client Access Server role in Exchange Server 2013; the CAS is now lightweight and offers extremely limited functionality. In fact, there are really only three things an Exchange Server 2013 Client Access Server can do: it can authenticate requests, redirect requests and proxy requests. The Client Access Server does not natively perform any data processing.The reason why this is a problem is because the Mailbox Server role handles all data processing in Exchange Server 2013, including the execution of remote PowerShell cmdlets. Therefore, a lone Exchange 2013 Client Access Server is completely powerless to do anything. It totally depends on a back-end Mailbox Server to perform basic functions. 

This is why it's important to set up a temporary Exchange 2013 server on a VM. The first Exchange 2013 server you bring into an Exchange 2010 organization must contain both the Client Access Server and the Mailbox Server roles. This is obviously not a desirable configuration for organizations that want to separate these roles. So, you'll need to deploy a temporary Exchange 2013 server containing both server roles. Once the server is in place, you can bring other Exchange 2013 servers online that are running just the Client Access Server role or just the Mailbox Server role. When you're done, simply remove Exchange Server from your temporary VM.

Task 4: Certificates


The final step before installing your first Exchange 2013 server is to evaluate your certificate requirements and acquire any necessary certificates.

Depending on your namespace requirements and what types of certificates you currently use, it may be possible to reuse the certificates you already have in place. Often new certificates are required. This is especially true for organizations using something other than Subject Alternate Name certificates or wildcard certificates.

If your organization still has Exchange Server 2007 servers, you'll most likely need new certificates due to legacy namespace requirements. 






Sunday, March 2, 2014

Virtual Private Network (VPN) - At a glance

Virtual Private Network (VPN)


A virtual private network (VPN) is a network that uses a public telecommunication infrastructure, such as the Internet, to provide remote offices or individual users with secure access to their organization's network. A virtual private network can be contrasted with an expensive system of owned or leased lines that can only be used by one organization. The goal of a VPN is to provide the organization with the same capabilities, but at a much lower cost.

A VPN works by using the shared public infrastructure while maintaining privacy through security procedures and tunneling protocols such as the Layer Two Tunneling Protocol (L2TP). In effect, the protocols, by encrypting data at the sending end and decrypting it at the receiving end, send the data through a "tunnel" that cannot be "entered" by data that is not properly encrypted. An additional level of security involves encrypting not only the data, but also the originating and receiving network addresses.

A virtual private Network (VPN) extends a private network across a public network, such as the Internet. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two.

A virtual private network connection across the Internet is similar to a wide area network (WAN) link between the sites. From a user perspective, the extended network resources are accessed in the same way as resources available from the private network.

VPNs allow employees to securely access their company's intranet while traveling outside the office. Similarly, VPNs securely and cost-effectively connect geographically disparate offices of an organization, creating one cohesive virtual network. VPN technology is also used by ordinary Internet users to connect to proxy servers for the purpose of protecting one's identity.

Early data networks allowed VPN-style remote connectivity through dial-up modems or through leased line connections utilizing Frame Relay and Asynchronous Transfer Mode (ATM) virtual circuits, provisioned through a network owned and operated by telecommunication carriers. These networks are not considered true VPNs because they passively secure the data being transmitted by the creation of logical data streams. They have given way to VPNs based on IP and IP/Multiprotocol Label Switching Networks (MPLS), due to significant cost-reductions and increased bandwidth provided by new technologies such as Digital Subscriber Line (DSL) and fiber-optic networks.

VPNs can be either remote-access (connecting an individual computer to a network) or site-to-site (connecting two networks together). In a corporate setting, remote-access VPNs allow employees to access their company's intranet from home or while traveling outside the office, and site-to-site VPNs allow employees in geographically disparate offices to share one cohesive virtual network. A VPN can also be used to interconnect two similar networks over a dissimilar middle network; for example, two IPv6 networks over an IPv4 network.

VPN systems classified by:

  • The protocols used to tunnel the traffic.
  • The tunnel's termination point location, e.g., on the customer edge or network-provider edge.
  • Whether they offer site-to-site or remote-access connectivity.
  • The levels of security provided.
  • The OSI layer they present to the connecting network, such as Layer 2 circuits or Layer 3 network connectivity.

Authentication Process:

  • Tunnel endpoints must authenticate before secure VPN tunnels can be established.
  • User-created remote-access VPNs may use passwords, biometrics, two-factor authentication or other cryptographic methods.
  • Network-to-network tunnels often use passwords or digital certificates. They permanently store the key to allow the tunnel to establish automatically, without intervention from the user.

From the security standpoint, VPNs either trust the underlying delivery network, or must enforce security with mechanisms in the VPN itself. Unless the trusted delivery network runs among physically secure sites only, both trusted and secure models need an authentication mechanism for users to gain access to the VPN.