Internet.com
CLEC-Planet Home
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us














CLEC Getting Started

CLECs Should Be Proactive In Security

By David M. Piscitello
Core Competence, Inc.

February, 2000 has been a watershed—or perhaps bloodshed—month for Internet security. Unless you were in hibernation, you can’t have missed the unheralded press coverage the distributed denial of service attacks on major e-Commerce sites attracted. 

The response from my security colleagues? “What did you expect?” and “expect more of the same in months to come.”

We glorify hackers in commercials, TV dramas and movies. That’s the bad news. The good news is that everyone now has an opinion on security, and anything that helps drive the message security matters is a Good Thing.

Opportunistic individuals and companies in both the private and public sector are filling the air- and e-waves with tales of new security shortcomings, calls for government intervention and the formation of cyber-security analysis centers. And, of course, discussions also focus around remedies involving the purchase and deployment of hundreds of millions of dollars of new security technology.

While ISP’s are taking the brunt of the cries for change and improved security practices, competitive local exchange carriers (CLECs) should also bear some of the burden.  After all, broadband local access hasn’t been excused from criticism, and public sentiment is growing more alarmist. More attention than ever is being drawn to the need to improve security over last mile, broadband connections. Imagine the black eye the entire DSL community might experience should someone decide a really clever hack would be to simultaneously deny service to every broadband subscriber. 

This attention really spells opportunity for CLECs. You can spin negative press to positive by taking a proactive in security, for you, and your customers. Here are some of the things you can do.

Be sure your standard operating procedure (SOP) includes anti-spoofing measures.  For instance, implement filters to restrict outbound packets leaving your network to only those networks that you have assigned and agreed to advertise. Block ports known to support zombie agents and other Trojans and worms. Implement some form of network Intrusion Detection.

Take measures to assure that your own infrastructure isn't a harbor and breeding ground for attacks of any form. Consider whether any point in your topology facilitates sniffing and scanning. Actively scan your systems, maintain hosts with current security patches, and run only services you need on servers.

If you’re hosting customer network management services and want to avoid the embarrassment of getting DDOS’d yourself, look into some of the ways to tune and distribute the load across multiple servers.  Two terrific, evolving sources of useful information on DDOS can be found in SecurityPortal.com’s DDOS FAQ and David Dittrich’s Distributed Denial of Service (DDoS) Attacks/tools page at the University of Washington.

Be proactive on behalf of your subscribers. Provide education to your enterprise and consumer subscribers. Covad Communications invited me to provide a white paper on DSL security for teleworker PCs and LANs over a year ago; while a bit outdated, many aspects remain relevant today.

Another useful service is to provide links from your Web site to security news that affects broadband local access users. Issue or re-distribute relevant security advisories.  Consider strategic relationships with security services companies who can advise enterprise customers about VPNs, strong authentication, and security for corporate desktops that are located outside physically secured corporate premises.

It’s especially important to provide plain-speak advice and education to your consumer subscribers. This population is destined to be your cash cow, and growing the base of early adopters is essential to near-term growth. Follow the laudable lead Excite @home has taken and offer free or subsidized personal firewall software to your subscribers. Take the initiative to offer to scan your customers as a service.  Point them to places where they can have their PC's scanned, or add scan software to your “security downloads”.

Consumer and government anxiety, and increased skepticism over the security of e-commerce are bad for the Internet. These worries hurt the sale of broadband access. Internet security isn't someone else's problem: It's also the responsibility of CLECs. Plus, there's the marketing advantage: Being proactive in security is a good differentiator in a noisy marketplace.

David Piscitello is president of Core Competence, Inc., a network consulting firm and founder of The Internet Security Conference. He writes for CLEC-Planet from the comfort of his DSL-enabled home on Hilton Head Island, South Carolina.

Email this article to a colleague
ISP News
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010

More >


ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly


Best of ISP-Planet
 

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Intel PDF: Virtualization Delivers Data Center Efficiency
Intel eBook: Managing the Evolving Data Center
Microsoft Article: BitLocker Brings Encryption to Windows Server 2008
Symantec eBook: The Guide to E-Mail Archiving and Management
Microsoft Article: RODCs Transform Branch Office Security
Go Parallel Article: James Reinders on the Intel Parallel Studio Beta Program
Avaya Article: Advancing the State of the Art in Customer Service
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Avaya Article: Avaya AE Services Provide Rapid Telephony Integration with Facebook
Go Parallel Article: Getting Started with TBB on Windows
HP eBook: Storage Networking , Part 1
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Seminar: Efficiencies in Hardware/Software Virtualization
HP Webcast: Disaster Recovery Planning
Go Parallel Video: Performance and Threading Tools for Game Developers
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
IBM TCO eKIT: Your IT Budget is Under Attack, Get in Control
IBM Energy Efficiency eKIT: Learn How to Reduce Costs
30-Day Trial: SPAMfighter Exchange Module
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Microsoft Article: Silverlight Streaming--Free Video Hosting for All
Featured Algorithm: Intel Threading Building Blocks - parallel_reduce
HP Demo: StorageWorks EVA4400
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES