Over 30 South African websites - including those of major insurance, retail, financial and technical companies, and even the `Who Wants to Be a Millionaire` site - were defaced by hackers over the festive season.
And this, says Marius Swart, GM: IS Security Solutions - the security business unit at e-business infrastructure provider, IS (The Internet Solution) - raises serious questions about the level of Internet security within local businesses.
"If hackers can get at the websites of some of the country`s largest, and most IT-savvy corporations, how difficult can it be for them to access the network of any SA company and do far worse than just leave a message on the website?
"Indeed, one of the major concerns of IT managers is the security implications which arise from connecting an enterprise network to the Internet. And not without reason. Research has shown that one of every five companies on the Internet gets hacked, with one in three break-ins occurring after a firewall is installed," he adds.
According to Swart, the primary reason companies` IT systems can be hacked after the installation of a firewall is the perception that a firewall is an off-the-shelf or shrink-wrapped product which can be easily bought and installed. Unfortunately, this type of firewall can also be easily hacked because it does not provide for the changing nature of the Internet protocol and new hacking efforts being deployed.
"A firewall`s status and integrity must be assessed, maintained and upgraded continuously to ensure optimum security at all times. However, few SA companies have the expertise in-house to do this," he adds.
In a move designed to overcome this problem, IS has launched Outsourced Firewall, a value-added service which provides customers with an end-to-end, 24x7 strategy to protect their networks without having to invest in expensive infrastructure or scarce IT security skills.
"In addition to maintaining and updating our customers` firewalls - which are hosted in our secure hosting centres to provide physical protection and redundancy in the event of power cuts or equipment failure - IS can also monitor their networks for any possible intrusions," he explains.
The intrusion detection technology used currently protects against 53 common attacks by using signatures to detect patterns of misuse in network traffic. These signatures represent severe breeches of security, including the most common network attacks and information gathering scans which often precede an attack.
By acting as an inline intrusion detection sensor, the Outsourced Firewall solution scans each packet and session as they flow through the firewall for a match with any of the signatures. When suspicious activity is detected, the system will log the details of the attack and can also drop the packet or reset the Transmission Control Protocol (TCP) connection.
Signatures can be acted upon differently, depending on the interface on which it was detected. The solution also allows for signatures to be individually disabled.
The Outsourced Firewall solution also provides sophisticated web based management reports that allow network managers to perform statistical analysis of unauthorised usage, traffic quantities, and event logging for potential cost accounting. Network managers can also audit URL logs in the reports to monitor which websites their users visit most.
"By outsourcing their firewall to IS, companies are assured of more than access to the world`s leading security hardware and software. They also have round-the-clock access to high-level security skills," Swart concludes.

