home.social

#forescout — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #forescout, aggregated by home.social.

  1. New blog posted discussing various forms of “micro-segmentation”, and use of tags instead of IP addresses in ACL’s. With callout to a great post about flows by Daniel Dib with some great comments. linkedin.com/pulse/microsegmen
    Tags: #PeterWelcher #CCIE1773 #Security #MicroSegmentation #NAC #SecurityGroupTag #Cisco #Elisity #ForeScout #Flows

  2. Zwecks Auffindbarkeit ein paar Hastags dazu:
    Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
    Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
    forescout.com/research-labs/su
    @bsi

    Recommendations
    Manufacturers
    Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
    • Applications: proper authorization checks on web applications, mobile applications and cloud backends
    Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
    Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

    Users
    Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
    Commercial and utility installations (in addition) •
    Include security requirements into procurement considerations
    • Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

  3. Zwecks Auffindbarkeit ein paar Hastags dazu:
    Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
    Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
    forescout.com/research-labs/su
    @bsi

    Recommendations
    Manufacturers
    Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
    • Applications: proper authorization checks on web applications, mobile applications and cloud backends
    Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
    Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

    Users
    Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
    Commercial and utility installations (in addition) •
    Include security requirements into procurement considerations
    • Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

  4. Zwecks Auffindbarkeit ein paar Hastags dazu:
    Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
    Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
    forescout.com/research-labs/su
    @bsi

    Recommendations
    Manufacturers
    Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
    • Applications: proper authorization checks on web applications, mobile applications and cloud backends
    Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
    Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

    Users
    Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
    Commercial and utility installations (in addition) •
    Include security requirements into procurement considerations
    • Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

  5. Zwecks Auffindbarkeit ein paar Hastags dazu:
    Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
    Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
    forescout.com/research-labs/su
    @bsi

    Recommendations
    Manufacturers
    Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
    • Applications: proper authorization checks on web applications, mobile applications and cloud backends
    Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
    Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

    Users
    Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
    Commercial and utility installations (in addition) •
    Include security requirements into procurement considerations
    • Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

  6. Zwecks Auffindbarkeit ein paar Hastags dazu:
    Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
    Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
    forescout.com/research-labs/su
    @bsi

    Recommendations
    Manufacturers
    Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
    • Applications: proper authorization checks on web applications, mobile applications and cloud backends
    Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
    Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

    Users
    Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
    Commercial and utility installations (in addition) •
    Include security requirements into procurement considerations
    • Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments