Educause Security Discussion mailing list archives

Re: GWU and content monitoring


From: Gerry Sneeringer <sneeri () UMD EDU>
Date: Wed, 19 Jul 2006 09:05:23 -0400

Gary,

My first reaction when I saw this solution was to wonder how much of our
sensitive data is leaking encrypted (SSL, SSH, etc) versus unencrypted.
 Without spoiling the VAscan talk, do you have a sense so far of how
useful the product has been?

Thanks,
Gerry

Gary Golomb wrote:
Lol... If it's not too late, we're going to be putting forth a synopsis
for a talk about this for VAscan. We did a somewhat similar talk last
year about a host-to-host audit of ~200 servers searching for
confidential data, compromises, and security configurations. Over the
past year, we've expanded that to network-focused solutions, and are
kicking off the auditing of ~500 desktops for confidential data,
compromises, and security configurations. Interestingly enough the
desktop audit project is far more difficult since it needs to run on a
desktop-class machines, in the middle of the day, in a fraction the
amount of time, and at a lower priority (CPU-wise) so it doesn't impact
the user's experience (unlike server scans which can run in the middle
of the night). A number of processes/applications have been developed as
part of these processes, and I believe they will be hitting the street
in the not-so-distant future... (I have contact information for some
people that I've ta
lked with offlist. If you have similar audit projects underway and would
like to take part in application beta testing, let me know!)

-gary


--
Gerry Sneeringer
Director, IT Security
University of Maryland - Office of Information Technology
PGP Key: http://security.umd.edu/contact/Gerry_Sneeringer.asc

Current thread: