Advertisement
Promo

Security threats Toolkit

Start-up aims to improve internal security

Marguerite Reardon CNET News

Published: 25 Jan 2005 09:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A start-up has launched software designed to stop leaks of sensitive business information by focusing on the greatest risk: insiders.

On Monday, software maker Vontu introduced version 4.0 of its Vontu gateway, which sits on a network and monitors the content of email and instant messages. The San Francisco-based company said the product will stop emails that violate security policies from being sent.

"The ability to block the leaks of sensitive or confidential business information is of tremendous benefit and value to those individuals charged with minimizing data security and privacy risks," said Larry Ponemon, head of the Tuscon, Arizona, think tank the Ponemon Institute.

For years, companies have focused security efforts on keeping hackers out of their networks. But research indicates that insiders cause more security problems than the average hacker.

Companies such as Vontu and its rival Vericept have built data interception products that monitor email, instant messages, FTP files and other electronic communications on corporate networks, sniffing for leaks of sensitive information.

Up to this point, these products have only generated reports about insiders' behaviour. Now Vontu will allow companies to filter traffic and block inappropriate messages, the company said. The software, which works in real time, can look for contextual clues in a message to determine whether or not it is all right to send. Policies can also be set so that specific information, such as a particular file containing software source code, can be directly matched and blocked.

The Vontu software only stops information from being sent over email. It does nothing to prevent a partner or a disgruntled employee from downloading information onto a data stick via a USB port or printing the information and walking out the door with it.

Studies indicate that most security breaches are the result of well-intentioned employees inadvertently violating security policies. Vontu CEO Joseph Ansanelli said that the new release is intended to avert such breaches, but noted that such data interception products are only a small piece of the overall solution for businesses.

"Today, insider protection is at zero," he said. "With every release of our product, we're taking steps to increase that protection. I think the market will evolve very much like the firewall market did. First, you had gateway products protecting the perimeter, and now you have personal firewalls sitting on desktops."

There is one drawback: Because the Vontu product sits within the data path, monitoring and making decisions on traffic in real time, network performance suffers slightly, Ansanelli said.

Adoption of Vontu and similar products will likely depend on whether companies are willing to trade small efficiency losses for a much higher state of data security, Ponemon said.

"Many IT leaders view system efficiency or speed as their primary success measure," Ponemon said. "If IT leaders view these solutions as an incremental overhead burden, even products that reduce security risk may not be readily accepted by them."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
46 out of 103 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters