ad info




CNN.com
 MAIN PAGE
 WORLD
 ASIANOW
 U.S.
 LOCAL
 POLITICS
 WEATHER
 BUSINESS
 SPORTS
 TECHNOLOGY
   computing
   personal technology
   space
 NATURE
 ENTERTAINMENT
 BOOKS
 TRAVEL
 FOOD
 HEALTH
 STYLE
 IN-DEPTH

 custom news
 Headline News brief
 daily almanac
 CNN networks
 CNN programs
 on-air transcripts
 news quiz

  CNN WEB SITES:
CNN Websites
 TIME INC. SITES:
 MORE SERVICES:
 video on demand
 video archive
 audio on demand
 news email services
 free email accounts
 desktop headlines
 pointcast
 pagenet

 DISCUSSION:
 message boards
 chat
 feedback

 SITE GUIDES:
 help
 contents
 search

 FASTER ACCESS:
 europe
 japan

 WEB SERVICES:
COMPUTING

How to keep the snoops away from your files

December 8, 1999
Web posted at: 10:00 a.m. EST (1500 GMT)

by Stuart McClure and Joel Scambray

From...
InfoWorld
Image

(IDG) -- We've talked a lot about network-layer security measures, such as Tiny Software's Winroute and Network Ice's BlackICE, for defending personal systems. These programs are great for blocking a nosy neighbor's or a malicious intruder's attempt at a toehold. But these are only the first lines of defense. If you believe in a deep defense, you'll take steps to secure an attacker's ultimate goal: access to the file system.

Literally hundreds of tools are available that can monitor or secure file systems. Here we present some of the tools we've used first-hand and found competent at keeping prying eyes from our data.

  MESSAGE BOARD
Insurgency
 

DuoMark International's 9Lives runs only on Windows 9.x, but we wish it had an NT counterpart. The 9Lives product allows users to enter into a protected mode, in which an installable virtual driver intercepts all file-system calls in a private area of the disk and records all attempts to modify, create, or delete files. It then asks, when returning to normal mode, if you want to make the changes. If you choose yes, changes are written to disk and everything continues as normal. If you say no, then no changes are made and all new, modified, or deleted files are saved to the folder 8thlife.

DuoMark 9Lives' purpose is mostly to protect from ugly software installations. However, we think 9Lives' security implications are interesting: How about browsing the Web in Protected Mode to ensure against unauthorized file-system access? It might also be great at spotting Trojans in the 8thlife folder. The idea of a "firewall for the file system" has merit to us -- we'd probably keep it on all the time!

Of course, even if you can prevent unauthorized file I/O, that doesn't mean someone can't read your disk, either over a network or locally. The only real solution to this problem is encryption.

MORE COMPUTING INTELLIGENCE
IDG.net   IDG.net home page
  InfoWorld home page
  InfoWorld forums home page
  InfoWorld Internet commerce section
  E-BusinessWorld
  Reviews & in-depth info at IDG.net
  IDG.net's personal news page
  Year 2000 World
  Questions about computers? Let IDG.net's editors help you
  Subscribe to IDG.net's free daily newsletter for IT leaders
  Search IDG.net in 12 languages
  News Radio
  * Fusion audio primers
  * Computerworld Minute

There are a lot of disk-encryption players, and you don't want to trust your data to some fly-by-night cryptanalyst. One of our favorites is SafeGuard Easy, from Utimaco Safeware. SafeGuard Easy is flexible, fast, and transparent, and offers three modes of operation: standard (for hard-and floppy-drive encryption); boot protection (for boot sectors, file-system tables, and root directory); and partitioned (for individual partitions and floppy drive). Because boot protection doesn't have to encrypt and decrypt the entire disk, it causes the least impact on performance, but doesn't protect against booting to an alternate OS and attempting to overwrite drive information. Standard encryption didn't prove to be much slower, and it keeps the entire file system under wraps.

SafeGuard Easy optionally employs Pre-Boot Authentication (PBA) to generate encryption keys at boot time so the keys are not stored on disk. SafeGuard Easy has a decent complement of encryption algorithms. Choose from simple XOR if speed is more important than security, or use Data Encryption Standard, International Data Encryption Algorithm, Stealth-40, or Blowfish-16. Keys can be defined by the user or randomly generated.

When using PBA, the system boots to an inscrutable DOS-like password prompt. Beyond that, we didn't even notice that SafeGuard Easy was around. A recovery option is provided, and can be enhanced so that only floppy disks encrypted with the system keys can be used to rescue the disk.

Another transparent file-encryption tool is seNTry2020, from SoftWinter. It boasts a simple interface, and mounts encrypted files as virtual drives. SoftWinter's seNTry2020 offers a good selection of algorithms, and also allows network access via the standard NT password. When dismounted, the encrypted virtual drives disappear, and the raw files become inaccessible.

We've run out of room to talk about Network Associates' PGP and RSA's SecurPC. And we haven't even touched on the Windows 2000 Encrypting File System. Plus, we've skipped file checksumming tools Tripwire and ISS System Scanner.


RELATED STORIES:
FBI, Pentagon brace for Y2k hacker attacks
December 2, 1999
New tools thwart Webjackers
November 2, 1999
ClickNet develops hacker detection product
October 29, 1999
Is it time for Net cops?
October 27, 1999

RELATED IDG.net STORIES:
Who's invading your turf?
(Network World Fusion)
Locking doors, latching windows
(LinuxWorld)
'Standard' security is different for everybody
(Computerworld)
FunLove virus uncommon, but may affect NT file security system
(Network World Fusion)
Scanned your Web apps for security holes lately? Try these free audit tools
(InfoWorld.com)
OpenBSD comes close to security nirvana with a system that is 'secure by default'
(InfoWorld.com)
Feeling secure behind that firewall? Tiny's WinRoute lets you take it with you wherever you go
(InfoWorld.com)
Bane of e-commerce: We're secure, we only allow Web traffic through our firewall
(InfoWorld.com)
Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.

RELATED SITES:
Duomark International's 9Lives
Ultimaco Software
SoftWinter
Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.
 LATEST HEADLINES:
SEARCH CNN.com
Enter keyword(s)   go    help

Back to the top   © 2001 Cable News Network. All Rights Reserved.
Terms under which this service is provided to you.
Read our privacy guidelines.