Monday, September 23, 2013

August Newsletter - Advanced persistent threat (APT)


Vega newsletter is published monthly by Vega BI, and distributed to our partners to facilitate pursuit of a common interest in top-notch technologies. 
Once rare and sophisticated, the APT is now becoming a common attack.
 Is your organization ready?   Any organization linked to the Internet is at risk. To protect your organization against APTs, it’s important to know what an APT is.
 
Typically, the intention of an APT attack is to steal data rather than to cause damage to the network or to the organization. APT attacks target organizations in sectors with high-value information, such as national defense, manufacturing and the financial industry.

In an APT attack, the goal is to achieve ongoing access, therefor it is characterized as a network attack in which an unauthorized person gains access to a network and stays there undetected for a long period. In order to maintain access without discovery, the intruder must imitate a normal user’s behavior and thus continuously rewrite code and employ sophisticated evasion techniques. Advanced Persistent Threat (APT) actors follow a staged approach, as articulated in the “APT-life Cycle” diagram , to target, penetrate and exploit the organization.


Monday, September 16, 2013

APT - Advanced Persistent Threat


APT - Highlights 

Advanced persistent threat (APT) refers to a planned and assembled activity of an entity (usually an organized group) with both the capability and the intent to determinedly and effectively attack a specific target. The term is commonly used to refer to cyber threats, in particular that of Internet-enabled espionage using a variety of intelligence gathering techniques to access sensitive information.

Typically, the intention of an APT attack is to steal data rather than to cause damage to the network or to the organization. APT attacks target organizations in sectors with high-value information, such as national defense, manufacturing and the financial industry. In an APT attack, the goal is to achieve ongoing access, therefor it is characterized as a network attack in which an unauthorized person gains access to a network and stays there undetected for a long period. In order to maintain access without discovery, the intruder must imitate a normal user’s behavior and thus continuously rewrite code and employ sophisticated evasion techniques. Advanced Persistent Threat (APT) actors follow a staged approach, as articulated in the “APT-life Cycle” diagram , to target, penetrate and exploit the organization. APTs present a greater threat based on their intense attention to preparations and their desire to expand access across the organization’s networks.

Although APT attacks are difficult to identify, the intruder can never be completely invisible. Detecting anomalies in outbound data is perhaps the best way for an administrator to discover that his network has been the target of an APT attack.

There’s a lot we know about advanced persistent threats, but there’s a lot we don’t know. This is due, in large part, to the complexity of the attacks and the stealth of the attackers. Our knowledge about APTs is growing, but, unfortunately, that’s because the attacks themselves are growing in frequency. Criminals using APTs want data, so the more valuable an organization’s data, the more likely it is to be targeted. Government agencies and organizations in industries such as finance, energy, IT, aerospace, and chemical and pharmaceuticals are the most likely to be the victims of APT infections, as are those involved in international trade. Users and organizations with access through business relationships to organizations holding valuable data, such as smaller defense contractors, are also beginning to be targeted in order to be used along time as entry gate into their valuable partners’ networks.

Any organization linked to the Internet is at risk. 
To protect your organization against APTs, it’s important to know what an APT is !!!

Monday, September 9, 2013

The World's 20 Hottest Startup Scenes

Entrepreneur, By Kathleen Davis

Sure, Silicon Valley is still No. 1, but some surprising cities like Sao Paulo, Brazil and Bangalore, India have become successful startup hubs over the past decade. Startup Genome's Startup Ecosystem Report 2012 ranked the top 20 most active startup scenes in the world based on criteria including funding, entrepreneurial mindset, trendsetting, support, talent and more.

According to data compiled by financial-software firm Intuit, some of the cities even outshine entrepreneurial darling Silicon Valley. For example, 20 percent of Santiago, Chile's entrepreneurs are women compared with a paltry 10 percent in the Valley.

For the full list and more about the top 20 entrepreneurial cities around the world, take a look at the infographic below.
Click to Enlarge+


Tuesday, September 3, 2013

Israel's startups are catching the eye of tech heavyweights

Shopping for security: Israel's startups are catching the eye of tech heavyweights
By David Shamah for Tel Aviv Tech 

Thanks to the growth in mobile and cloud computing, and the more porous borders it brings to the enterprise, the security industry is growing, and Israel's is no exception.
IBM's  recent purchase of Israeli security company Trusteer is just one example of the new popularity of security in the startup nation. Earlier in August, GE announced it was investing in Israel's Thetaray, the company's first security investment here. And in May, Cisco CEO John Chambers announced that the company is starting its own incubator in Israel, specifically to help security startups come to market.
The ThetaRay team at workElsewhere, digital vault Cyber-Ark announced this week that it was increasing its staff by 50 percent, due to a rise in new business (nearly half the companies on the Fortune 50 list are among Cyber-Ark's 1,400 or so clients, including 17 of the 20 largest banks worldwide). The company's sales, according to its Israeli centre manager Chen Bitan, have risen 40 percent annually year on year for the past several years, and today the company is the largest private IT security company in Israel.
But the road from security startup to acquisition or investment by an IBM or a GE is a long one.
Why would multinationals think to go shopping in Israel altogether? Because, said Gadi Tirosh, a general partner at VC firm Jerusalem Venture Partners (JVP), multinationals already know Israel and are comfortable here. Many of them already have R&D facilities in Israel, and in a sort of virtuous cycle, they meet entrepreneurs and innovators who work in or with startups.
Security to deal with the new class of security attacks — advanced persistent threats (APT) or highly-destructive zero day attacks is very much on the mind of enterprise and tech companies, Tirosh said, making security startups attractive targets. And very often, companies use their new acquisitions or investments to open up new R&D labs in Israel, dedicated to working on security.
"Once a company has a beachhead in Israel it is much easier for them to search among startups for the technologies they need," Tirosh said. One example of this trend was the 2011 acquisition of Israeli security firm Navajo Systems by Salesforce.com. Navajo's encryption platform for SaaS was just what Salesforce needed, and in order to continue to draw on Israeli security technology, Salesforce turned the Navajo offices into its first Israeli R&D center (Navajo, Cyber-Ark, and ThetaRay are or were part of JVP's portfolio).
And there's NDS, the largest security firm in Israel, acquired by Cisco. "Although most people don't think of it as such, NDS, which develops systems to ensure that cable and satellite TV premium broadcasts can only be viewed by paying customers, it is, operating at the junction of security and digital media," Tirosh said.
Acquiring NDS opened up a new vista for Cisco — laying the foundations for the decision to open an incubator specifically geared towards security. The field is so hot, in fact, that JVP itself is opening its own security incubator, Tirosh said.
IBM, too, is jumping on the bandwagon, and will use its recent acquisition of security firm Trusteer — for which IBM is rumoured to have paid in the neighbourhood of $1bn, possibly even besting the Waze-Google deal — to open up its own IT security R&D centre.
IBM already has numerous labs in Israel, and the new one will consist of, to begin with, more than 200 Trusteer and IBM researchers and developers to focus on mobile and application security, advanced threat, malware, counterfraud, and financial crimes. And there are dozens of potential Trusteers out there, ripe for exits. Expect more big deals in the Israeli security space, Tirosh said.





Monday, August 26, 2013

July Newsletter - Business Services Management (BSM)

The Vega newsletter is published monthly by Vega BI, and distributed to our Brazilian partners to facilitate pursuit of a common interest in top-notch technologies

Business Services Management (BSM)


The goals and objectives of Business Services Management (BSM) include an up-to-the-minute understanding of active Information Technology (IT) elements, how they relate to each other, and how the collective combinations are performing in support of essential business processes and activities. Optimally, this puts IT in a position of control for recognizing and measuring business value and prioritizing projects and actions according to business needs – true IT/business alignment. Case studies of successful BSM deployments have proven the operational and financial advantages that can be and have been achieved.



For more .... See Vega's July Newsletter


Monday, August 19, 2013

7th largest IT market, Brazil should move R $ 300 billion in 2013

IDC Consulting provides high up to 12% for thesector that earned U.S. $ 270 billion last year
Copywriting Digital Look

The Brazilian IT sector should maintain the same pace of growth last year and jump between 10% and 12% in 2013. A prediction was made ​​by IDC and released on Wednesday, 26 by BRASSCOM - Brazilian Association of Information Technology and Communication.  If the goal is achieved, the country will close the year with revenues of $ 135bn (£ 300bn), which represents just over 5% of GDP. For 10 years from now, the expectation is that the country progresses 54% and move around U.S. $ 250 billion (R $ 550 billion.) In 2012, Brazil's performance was better than twice the global average (5.9%) and was only behind China (15%) on the growth rate. According BRASSCOM, areas of IT In-House (54%) and Hardware (35.3%) are the most concentrated investments, followed by Services, Software, BPO and Exports.

Monday, August 12, 2013

BSM – Business Service Management


What does BSM stand for ?

Business service management (BSM) is a way to bridge between your organization’s view of applications and services with the IT operations’ view of infrastructure; it maps business services to the components used to deliver them. The promise is that this insight will provide visibility into IT from a business service standpoint and gives IT the ability to resolve issues faster, focus on key business services, and better align IT management processes with business needs.  In other words BSM is simply the package of whatever it takes to deliver the desired/required technology to the business community,   in a way that the business entities can understand, appreciate, absorb and benefit from that delivery.

Why do I care about BSM ?
IT organization are called to prioritize efforts and resources by working on what’s most important to the business, deliver more business services — better and faster — while reducing costs and risks.IT operations must enable their companies to work more efficiently and also drive revenue, even with flat or declining budgets. IT entities need a “business” approach to maximize effectiveness of IT activities.
BSM simplifies, standardizes, and automates IT processes so one can manage business services efficiently across their lifecycles, whether using self-owned infrastructure or leveraging cloud services. With BSM, the organization has the trusted information it needs, can prioritize work according to business-critical services, and can orchestrate workflows across core IT management functions.

BSM Benefits
Business views IT as a source of productivity and competitiveness. Business processes, from purchasing products to customer service to employee payroll, are accelerated through automation that IT services provide. Coupled with the right quality of service, well-managed business processes improve productivity and make the enterprise more competitive.


BSM in action

BSM needs a roadmap; BSM’s discipline comes in the forms of IT activities, technologies, metrics, processes and best practices creating meaningful context for the business user of technology. Maturity models define service management in terms of IT tasks, tools or processes, and the opportunity of correlating IT deliverables to business values.

“Business Maturity” model
IT operations should Know their companies’ business needs and align IT management processes with these needs. This is a prerequisite in determining how to get there The BSM Maturity Model’s objective is to help you identify both where you are and where you want to be, and then provide some clues as to how to close the gap.
The BSM “level” reflects the business objectives and how it aligned with IT activities. IT is aligned with the business when there is a match between business’s objectives and IT’s efforts to meet business needs.
BSM Maturity refers to the extent of the match between business operating needs/desires and IT’s understanding and efforts to meet those needs.