Universal Plug-n-Play – (UPnP) is a suite of protocols that enables a device to discover other devices on a network, configure itself to operate in the network, and advertise its services. This allows a device to locate routers, printers and other resources on a network. UPnP runs on UDP port 1900 and communicates using SOAP messages over HTTP. The actual configuration and management interface are implemented using a SOAP-based HTTP service running over a dynamically allocated TCP port. The UPnP protocol allows management of aspects of a device’s operation to extend support by the protocol implementation on the device and its…
Lateral Movement Definition: Lateral movement is a technique used by cyber attackers to infiltrate and move through a network with the intent of obtaining secure data. The Cause The term “Lateral Movement” has been around for a little over four years and was in the news when ransomware like WannaCry and APT’s like APT28 and APT29 used lateral movement techniques. Most often an attacker may not have direct access to a machine or resource on the internal network, which the attacker considers a prized trophy. The prized trophy may be the domain controller, a machine hosting confidential information, or the…
The 2018 Data Breach Investigations Report (DBIR) compiled by Verizon is loaded with cloak and dagger cyber events conducted by both known and unknown bad actors and mechanisms. Verizon identified 53,000-plus incidents and 2,200 breaches in only 12 months, suggesting an information parallel universe in which an uneven playing field exists whereby the bad guys and rouge bots consistently probe from the outside. Here are some of the key findings in terms of actual breaches: 73 percent were perpetrated by external forces 50 percent were carried out by organized crime groups 48 percent were due to hacking; 30 percent from…
Once again, recently we heard about an enterprise that succumbed to a major security breach. Shipping giant COSCO lost email and IP phone connectivity throughout their entire US network. And without finding the cause, the company shut down networks within other regions. This example, along with countless others, solidifies the point that distributed networks and security are inherently symbiotic. COSCO says the incident was a network breakdown that led to the ransomware infection. While some are arguing it was the network, others say it was a Malware security breach. The COSCO event was not only a network breakdown, it was…
Typically, WAN solution vendors talk about performance in terms of speeds and feeds. But, I like to think about performance as it relates to all aspects of connectivity. This includes speed, control, visibility, reliability, ease of deployment and monitoring, and of course security. I think about it in these terms because each of these areas are controllable by the right holistic SD-WAN architecture. Unfortunately, the accumulation of multiple disparate routing and switching devices, including firewalls, intrusion detection and threat mitigation, makes it difficult to obtain network visibility and correlate real-time events that can degrade or disrupt performance. With Secure SD-WAN,…
Networking and security IT infrastructures have evolved to a level of complexity unmanageable by operators and enterprises using a conventional approach. The ongoing reliance upon legacy network hardware and disjointed WAN architectures inhibit the operational agility required by global organizations looking to digitize business services with secure, multi-cloud connectivity. The intersection of network reliability and application performance requires a more flexible, versatile network architecture with security and cloud integration at the forefront; thus, optimal WAN-path selection alone is no longer good enough in a multi-threaded threat environment. Large-scale enterprises with far-flung remote locations and highly distributed data centers are facing…
Subscribe to the Versa Blog