Please wait while the page is being loaded Skip this advertisement >
Friday | 21 November, 2008
ARN

Strengthening the security barricades

Nadia Cameron 24 January, 2007 12:25:32

The shift in security attacks from technology vulnerabilities onto human weaknesses is putting the spotlight on user authentication. Where a single memorised password was once enough to get into your bank account, work PC or network, organisations are realising they are no longer adequate to fight cyber crime.

Security breaches destroying password reliability include brute password forcing, more sophisticated cracking tools, spyware, keystroke monitoring and phishing. The rise in remote workforces also poses a dilemma about how to ensure information going across the airwaves is received by an appropriate user.

In a bid to improve individual security, an array of authentication technologies has come to the fore. Solutions available today extend from traditional physical tokens, public key infrastructure (PKI) certificates and smartcard products, through to biometrics tools that scan anything from a user's eyes to their fingertips.

These are being taken up in various fields - as a login tool for notebooks (fingerprint scanners); in national passports (facial recognition); to identify government agency staff (smartcards); or to validate customers (bank tokens and digital certificates).

CHANGING FORCES

Authentication technology is broken into two camps: single sign-on and two/multi-factor authentication. The latter, which is also called strong authentication, consists of something the user has (such as a physical token), as well as something the user is (biometrics) or what the user knows (password).

RSA Security country manager, Mark Pullen, said there had been a significant shift over the last 18 months towards variable two-factor authentication. While a token, digital certificate or smartcard was traditionally the extent of choice, people had realised one size doesn't fit all.

"There's been a change in the market - customers are looking for variance, and don't just need a token," he said. "You need a range of options and to balance the cost of security with the convenience of use for the end user."

One of the major reasons for this is the rise in remote user access. As an example, Pullen said RSA had noticed several larger enterprises now employing its SecurID tokens on mobile devices as a way of securing mobile users. Another driver for strong authentication is the Australian security policy standard AS17799.

This security best practices guideline requires a company to maintain two-factor authentication for users connecting via a VPN. The AS17799 standard is used by several institutions, including the NSW government.

Pullen said many enterprises had taken the standard on-board as a way of measuring their own security policies.

In cases where all employees needed these authentication checks, it was often too expensive to give them a token, he said. RSA has introduced a digital certificate within the VPN application toolbar in an effort to make this process more cost-effective.

Users were also increasingly looking for multifactor authentication within a single device, such as a USB key, Pullen said. This would allow them to carry more credentials, such as digital certifications for specific transactional types, as well as one-time passwords.

"We have the SD800 which is a USB, token and smartcard together. They can still use a token but get the best of both worlds. There's been significant increase this year in take-up as it can give you three factors potentially," he said.

Related Stories
  • +

    The year ahead 21 December, 2007 06:47:49

    ARN takes a look at some of the industry's top technology and trend predictions for 2008
    Unified communications and IP telephony, virtualisation and SMB were on the lips of almost every IT vendor this year, but what will be the biggest technologies and trends next year? ARN asked a cross-section of the community for their predictions on what would be hot in 2008.
  • +

    ARN's A-Z guide to networking 19 December, 2007 14:50:54

    As business needs change, so do the requirements for the business backbone. ARN looks at networking trends and technologies and reports on predictions for 2008 and beyond.
Additional Resources
ARN Library
white paper Click here for case studies, whitepapers and other useful vendor content
Newsletter Subscription
Sign up for our ARN newsletters!
RSS Feeds
Market Place
 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news
Play
Channel Watch
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

How to Beef Up Your Sales Pipeline

Our economy may be heading towards a recession. Sales rates are dropping. Promotional campaigns are proving less effective than you would like. So how do you continue to grow your business and bring home the sales in such an environment? Download this white paper now to find the answers.

Sponsored Links