|

Q & A
Contents:
Dynamic Security Business Value
How can Dynamic! Security help me fight Identity Theft?
How can Dynamic! Security help me fight Laptop Theft?
How can Dynamic! Security help me fight Wi-Fi Hacking?
How can Dynamic! Security help me Comply with regulations?
How can Dynamic! Security complement my IDM?
How can Dynamic! Security improve my Premises’ Physical Security?
How can Dynamic! Security help me with Strong Authentication?
How can Dynamic! Security help improve my Over All Security?
How can Dynamic! Security help me respond to External Alert Level changes?
Dynamic! Security Uniqueness
What is Dynamic! Security’s uniqueness?
Implementation Aspects
Doesn’t Dynamic! Security invade employee privacy?
How long does it take to implement Dynamic! Security?
What is DS’s impact on network performance?
How can I do a proof-of-concept of Dynamic! Security?
How scalable is the Dynamic! Security solution?
Can Dynamic! Security be implemented in a phased manner?
Technical Aspects
Which platform does Dynamic! Security run on?
What does Dynamic! Security monitor?
How secure is Dynamic! Security?
Dynamic Security Business Value
- How can Dynamic! Security help me fight Identity Theft?
Identity thieves, whether internal or external to your organization, are phishing for legitimate credentials
which they can than use to enter your network.
As a matter of fact, it is the weakness of the credentials that created the entire market of security
products such as firewalls, smart cards and tokens. If the credentials were strong enough to stand a password
cracking attack, your life as a security professional would much easier and less demanding.
Wouldn’t life been wonderful if there were no credentials for predator usage?
DS is in the business of fortifying the credentials so they stand against all those predators’ attacks.
What good will it do to the hackers if they couldn’t make use of the credentials they worked so hard to
obtain?
DS converts the hackers’ pain into your gain.
- How can Dynamic! Security help me fight Laptop Theft?
First and foremost let’s understand that Dynamic! Security can only help you prevent Laptop thefts from your
own campus and not from an airplanes’ overhead compartment or other external location. However, it can minimize
the damage from theft of the laptop outside your campus.
By keeping track of the owner - laptop relationship and correlating it with the physical location of both the
owner and the laptop, Dynamic! Security helps you fight effectively against those laptop thieves.
For example:
If an employee left the campus two hours ago, leaving the laptop inside, and suddenly the laptop starts
moving towards the exit, it is a strong indication of a theft-in-action and Dynamic! Security will notify the
lobby guards, asking them to check out every individual who is leaving the campus.
If you do not want to check, or cannot physically check the people who are exiting the campus, Dynamic!
Security can automatically prepare an investigation folder in which you will find all the relevant information
for the laptop theft. Such information will be:
- The name of the laptop.
- The owner of the laptop.
- The people who were inside the zone from which the laptop was stolen, at the time of the theft.
- The people who left the campus around the same time that the laptop left it.
- Any other information which the Forensic-based Investigation (FBI) module was pre-designed to collect from
digital sources.
- How can Dynamic! Security help me fight Wi-Fi Hacking?
In the past, anyone who wanted to access network assets they needed to somehow cross the physical check-point
while identifying themselves to the guards or to the automated Access Control system.
Than the Internet was invented, and suddenly people could enter the network electronically while bypassing
the physical check-point. This situation called for a solution, and pretty soon companies such as Checkpoint
invented the firewall concept which, in essence, is an imitation of the physical check-point. You needed to be
identified first in order to be allowed inside.
The Wi-Fi invention made these two access methods obsolete for the hackers. Now they do not have to enter
through physical or logical screening and they can enter the network directly, bypassing both barriers. Some
organizations argue that they are Wi-Fi hacking proof since they do not deploy this technology.
They are usually dead wrong!!!
With the proliferation of Wi-Fi devices (laptops, Smart phones, Cellular phones, simple plug-in Wi-Fi access
points, home Wi-Fi networks and cheap Wi-Fi signal boosters), the working assumption of the security teams must
be that the network might and will be exposed to an unprotected Wi-Fi exploit.
It’s enough that one employee synchronizes his or her Smartphone with his Outlook, while the Wi-Fi option on
the Smartphone is on.
The thought of all those employees who are allowed to enter from home, and of their children installing a
home unprotected Wi-Fi access point, can drive any security professional into sleep deprivation.
The risks which came with the Wi-Fi technology are real and numerous, but whatever they are, the predators
still have to find valid credentials if they really wish to enter the network -- and that is exactly where
Dynamic! Security comes to your rescue, by drying up the fountain of credentials and correlating physical
presence with the ability to login from within the campus.
- How can Dynamic! Security help me comply with regulations?
Various regulations require that the organization try to prevent unauthorized access on one hand, and
monitors who could have accessed at any given time, on the other hand.
That is exactly what Dynamic! Security does.
- How can Dynamic! Security complement my IDM?
IDM deals with the employee in three occasions:
- The employee joins the organization
- The employee changes status within the organization
- The employee leaves the organization
Now let me share with you a true story which occurred in one of the largest European financial institutions.
The organization runs branch offices throughout the world. In one of those offices they fired an employee who
was an over five year veteran.
The branch office resides in a shared building which enjoys the security services of the landlord for the
whole building.
Immediately after the employee was let go, the IDM went into action and revoked all the employees’ access
rights.
The first Saturday after being fired, the ex-employee came to the buildings’ lobby and told the guard on duty
that he forgot his employee badge at home, which is 60 minutes drive from the office.
The guard, who knew the ex-employee for a number of years, but didn’t know that he no longer works for the
financial institution, felt bad for the guy and offered to open the office door for him with his master key.
The ex-employee thanked the guard and went into the office, used one of his ex-peers’ credentials and sent
out to his web mail tons of confidential information which he was going to use in his next job.
Although the simplicity of this story is mind boggling, you can rest assured that with Dynamic! Security this
could not happen, just because Dynamic! Security wouldn’t allow credentials to log-in while the credentials’
owner is not physically present in the campus.
- How can Dynamic! Security improve my Premises’ Physical Security?
DS can detect changes on a computer screen. When the screen comes back from energy saving mode, (the black
screen mode it goes into after some idle time) into a lighted screen mode (usually after someone touched the
mouse or the keyboard).
An event of that type, if happens during non working hours, when presumably nobody is supposed to be in that
area, can be reported to the guard on duty, and the guard can then check the area.
If the organization has a security panel on which the last to go out moves the alarm system to ‘night mode’;
Dynamic! Security can acquire that event and move the network also to ‘night mode’. This mode will typically
include logging off all administrators’ User-IDs, locking all active desktops and monitoring the network for
suspicious activities until an event such as moving to ‘day mode’ again.
- How can Dynamic! Security help me with Strong Authentication?
DS, through its IDentiWall option, performs multi-factor authentications for both restricted Web and direct
network clients.
IDentiWall has various modes of operation, but the common functionality of them all is that it uses the
clients’ mobile phone to perform its authentications.
The following is a list of some of the IDentiWall’ modes:
In this mode the client logs into the network or the Web site using his or her original credentials.
IDentiWall’ Radius challenges the client with a One Time Password (OTP) which is sent to him or her via SMS.
The client copies the OTP to the challenge response screen, and only then is authenticated and allowed to
enter the web site or the network.
- SMS with pro-active response capabilities mode
This mode adds a pro-active response possibility. Imagine yourself sitting by the seaside sipping a nice
glass of wine, when out-of-the-blue you get an SMS with OTP from your online bank or organizational network.
Wouldn’t it be helpful if you could respond with an agreed SMS code telling the bank or the organizational
network to block your account to any online access until further notice?
In fact, that is what the Pro-Active mode of IDentiWall makes possible.
In this mode, mobile client software is installed on the client mobile device.
This mobile client is the only one that can read the encrypted SMSs.
In order for that mobile client to work it has to be invoked by the owner of the phone, by entering a pin
code.
This mode supports Voice Identification, which is a unique biometric identifier for every person.
- How can Dynamic! Security help improve my Over All Security?
DS has the following functionality:
- Policy and role based automatic administrator
- Physical and IT security convergence platform
- Tightens up security profiles and procedures by converting them to dynamic ones, as opposed to their current
static nature.
Those functions, when implemented, harden the security in a very meaningful way.
- How can Dynamic! Security help me respond to External Alert Level changes?
DS supports ‘Alert Level Context’ behavior. It is equipped, out-of-the-box, with one-stop behavioral changes
in response to changes in the:
- Terror Alert Level,
- Climatic Alert Level,
- Cyber Attack Alert Level
- And changes which can easily be defined by the organization itself.
In response to each alert level change, Dynamic! Security changes its response to the same events it used to
respond to differently before the change occurred.
Dynamic Security Uniqueness
The failure of the first invented IT security measure, the credentials, lead to expensive implementations of
point security solutions which you probably would have avoided if the credentials could have defended against
the predator attacks.
Regrettably, Dynamic! Security was not around before to help you fortify the credentials to a satisfactory
level.
The fact that it converges physical and IT security into one realm enables DS to provide you with peace of
mind that was not available before its emergence.
When you add to that its add-on modules such as:
- Forensic-based Investigations (FBI)
- Compliance Information Assurance (CIA)
- IDentiWall
- Security Syndication Platform (SSP)
Coupled with built-in technologies such as:
- Workflow engine
- Policy management facility
- Role based implementation
- Scheduler facility
- Integration facilities
- Semantic web
- SOA
- Mobile integration
- Polite implementation facility
- And many more
You get a strong, robust and scalable solution for your important security problems.
Dynamic! Security, impressive as it is, is merely in the first phase of its road map.
Our commitment to you is to develop it further into uncharted security areas for your benefit.
We realize that there is no other product like that in the market today and we hope that with the progress we
are going to make in implementing its road map, you’ll realize that DS is going to stay the unchallenged market
leader.
Implementation Aspects
- Does Dynamic! Security invade employee privacy?
Dynamic! Security is designed to strengthen organizational security without invading the privacy of
employees. The product manages ‘employee card number’ without storing the actual employee name.
Furthermore, Dynamic! Security protects employee privacy by fighting the ID thieves and not allowing them to
exploit the employee ID that they obtained, to convert the employee’s life into living hell.
- How long does it take to implement DS?
DS implementation consists of the following phases:
- Developing integration with the organizational physical access control system. If we have already developed
an interface to the physical system, this phase can be bypassed.
In any case, it is our responsibility to supply integration for local access control.
- Analysis of the way the organization would like to implement DS, the organizational data sources etc.
- Building an automated implementation builder which gathers the information DS needs from the organizations
sources, structures it into the DS format and insert it into DS database.
By the end of the builder execution, which runs right after the actual installation of the product, the
solution should be running and implemented.
The builder is also our responsibility and we arrive with it to the customer’s site on the installation date.
- If nothing else was agreed, the builder implements DS in a silent mode and only after the organization is
perfectly confident in DS performance, the Polite Implementation mechanism is used to gradually move the
implementation from Silent (log only) to Active (production) mode.
- All-in-all, DS installation and implementation should take a few hours on the customer’ site, provided that
both the access control interface and the suitable builder were prepared ahead of time.
- What is Dynamic! Security’s impact on network performance?
DS’s impact on the customer’s network depends on the policies the customer wishes to implement. It is obvious
that an organization that wishes to ping all its networked devices every minute might feel some network
performance degradation.
However, our experience shows that we never encountered an implementation in which the organization wanted
such comprehensive ping practice, and in fact we never experienced network performance issues.
Since DS is highly scalable and can be configured to run in various configurations, it is not likely that
we’ll face a situation where the implementation can’t be planned to avoid network performance issues.
- How can I do a proof-of-concept of DS?
Your proof of concept is the product’s Silent mode. All you have to do is have us install the product,
integrate it with your physical access control, have us build the implementation builder for you and run it in
Silent mode for some time until you’re content that it performs to your utmost satisfaction.
We’re sure you understand that this proof of concept requires some work on our end, which is why we must
charge for proof of concept.
However, if you move from POC status to purchased status within an agreed timeframe, you can get 50% of POC
payment credited towards the purchase cost.
- How scalable is the Dynamic! Security solution?
DS was designed to cater to extremely demanding implementations. It supports huge implementations as well as
complicated ones.
DS can be implemented in a hierarchy of DSs where each instance controls part of the network (one or more
subnets) and they all are interconnected in a web of copies that are able to support any demanding requirement.
- Can Dynamic! Security be implemented in a phased manner?
As was discussed above, DS can be implemented in a phased manner and the options are as follows:
- Hierarchy of products in which each is managing part of the whole.
- Polite Implementation, which supports phased implementation. In this mode the organization progresses the
implementation path only after it is assured and satisfied with the product's ability to implement politely the
organizational policy.
- The implementation can be location dependent and deal with one location (site) at a time.
- Other methods of supported phased implementation are:
- Phased departmental implementation
- Phased policies implementation
- Phased measures implementation
- Phased context implementation
Technical Aspects
- Which platforms does Dynamic! Security run on?
DS runs on Windows 2003 server, although in some instances we can set it up to run on desktop hardware rather
than on pure server hardware.
In any case, the Win2003 operating system has to be installed on that hardware.
- What does Dynamic! Security monitor?
DS monitors physical presence of people and devices. By correlating their activities, it implements
Location-based Security, converting the security landscape from a static to a dynamic one.
Messages can be sent over the network encrypted and digitally signed. DS supports console filtering so that
each person who has access to the console sees only the information type that is defined in their filter.
|