To advertise, contact
Nathalie Akl
+971 4 2108520
nathalie.akl@itp.com
بالعربية
Where am I? Home /


BREAKING NEWS :

Out of credit

By Colin Edwards on Sunday, April 01, 2007

Awareness of the global standard that requires merchants and other businesses to ensure they have networks able to protect credit cardholder data remains low.

Most enterprises are not even aware that their traditional network firewalls cannot protect against application layer attack, according to a report by Forrester.

Payment card ignorance prevails despite more than six months passing since American Express, Visa International, MasterCard Worldwide and other credit card issuers updated the Payment Card Industry (PCI) Data Security Standard.

According to Forrester, the use of Web application firewalls (WAFs) to comply with PCI will become part of global security strategies.

"Improvement in network security means that attackers are commonly probing Web servers and Web applications for an easy way in, and WAFs have grown along with this kind of attack," says the study.
Story continues below
advertisement



The updated PCI (version 1.1) includes 12 requirements seeking to establish a defence-in-depth network strategy at merchants with heavy fines being considered for non-compliance. The requirements include implementing strong access control measures, monitoring and tracking all access to network resources and restricting access to the network on a need-to-know basis.

As PCI impacts every merchant with credit card facilities - that includes tens of thousands formal retailers in the region - it is essential that security vendors educate the market as to WAFs' role in blocking attacks on Web application and why they are necessary in complying with PCI.

"What many firms do not understand is how they (WAFs) differ from a traditional network firewall. Network firewalls look at traffic on a packet-by-packet basis, whereas WAFs look at multiple packets together, modelling the entire session to understand overall application activity," explains the report, which forecasts rapid growth for WAFs.

According to the recently-published Symantec internet security threat report, more than 69% of vulnerabilities affected Web applications. The same study says 77% of easily exploitable vulnerabilities affected Web applications.

The PCI standards, which have to be met by next year. The report expects WAFs to be commoditised by the end of the decade. In the meantime, the merchants have a choice of complying with the standard by installing a WAF, or by code reviewing each individual Web applications used.

Forrester says that although stand-alone equipment will be deployed in the initial phases, gradually the functionality of these devices will be built-in to other equipment. It lists Breach Security, Citrix Systems, F5 Networks, Imperva, NetContinuum and Protegrity as currently the leading WAF vendors.

According to the Symantec internet threat report Underground Economy Servers are being used by criminals and criminal organisations to sell stolen information, including credit cards, bank cards, PIN codes and user accounts.

"As cyber criminals become increasingly malicious, they continue to evolve their attack methods to become more complex and sophisticated in order to prevent detection," says Arthur Wong, senior VP, Symantec Security Response and Managed Services.

"End users, whether consumers or enterprises, need to ensure proper security measures to prevent an attacker from gaining access to their confidential information, causing financial loss, harming valuable customers, or damaging their own reputation."


User Comments

All posts are sent to the administrator for review and are published only after approval. ITP.net reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic.
Name *
( Remmber Me )
Email *
(Your email address will not be published)
City
Country
Subject *
Comment *
Security Code * Code
 


Please click post only once - your comment will not be published immediately.
Subscribe

Network Middle East English edition


The Middle East's leading monthly magazine for network professionals.

Subscription Rates:
FREE for GCC Countries, Egypt, Jordan & Lebanon *

AED 249.00 for International

Subscribe Now »

* Terms & Conditions Apply

Current Issue  |  Media Info  |  Subscribe to other Magazines »

Related Comment

Todd McGregor
IT organisations measure the wrong things, says Forrester's Todd McGregor, who outlines five management metrics that can help ... 

Related Feature

What’s in store?

Hardware

The need for a scalable infrastructure to cope with electronic data management should now be a priority for the discerning... 

Related Feature

Getting to grips with SOA

Service-orientated architecture (SOA) and business process management (BPM) provider, WebMethods, has stepped up its campaign... 


Competitions

Win Megabytes of memory

Ends On Monday, 15 December 2008

Diskettes are ancient history, and while re-writeable CDs and DVDs offer space and convenience when it comes to data transfers, you can’t beat a high-capacity flash drive for outright ease-of-use.


Advertising Features


Latest Products
Sony VAIO VGN-Z12GN

Hardware | Notebooks | November 2008

Portable and powerful but can you live with it?

RATING


Draytek Vigor 2820Vn

Hardware | Peripherals | November 2008

Can it justify its high price tag?

RATING


Casio Exilim Card EX S10

Hardware | Digital Imaging | November 2008

A camera designed for even the tightest pockets.

RATING


Crysis Warhead

Games | PC | November 2008

Is this another crisis for PC components?

RATING


Technology Jobs
Information Technology Manager
Location: Dubai, UAE
Account (Sales) Executive
Location: Dubai, UAE
Implementation Engineers
Location: Dubai, UAE

For editorial enquiries contact
Mark Sutton
mark.sutton
@itp.com
To advertise, contact
Ahmad Bashour
+971 4 210 8549
or ahmad.bashour
@itp.com


Arabian Computer News Channel Middle East Channel Middle East - Arabic Charged CommsMEA Network Middle East Windows Middle East Windows Middle East - Arabic ALL ITP TITLES