Amazon

18.1.11

"Cyber Warfare"


This term has been thrown around a little and yesterday the Organization for Economic Cooperation and Development (OECD) released a report saying that "true cyberwar is unlikely." Here's an excerpt that was sent to me for comment:


“There is nothing new in what the hacktivists are doing,” Mr. Sommer said. “It really should not be exaggerated. It’s really more like the kind of thing Greenpeace does.”

“We have to get used to the fact that popular protests, as well as skirmishes between nations, are going to have a cyber dimension,” he added. “Some people say cyberespionage is just a few clicks away from cyberwar. It’s not; it’s just another way of spying.”

Report challenges cyberwar doomsday scenarios
New York Times January 17, 2011
https://www.nytimes.com/2011/01/17/technology/17cache.html?_r=2&ref=global

A new study commissioned by the Organization for Economic Cooperation and Development says a true cyberwar is unlikely, and that -- unlike scenarios painted by many recent books and articles on the topic -- advanced countries could recover from such a conflict within days, even hours. "You have this sort of competition between writers to say, 'I have a scarier story than you do,'" said co-author Peter Sommer of the London School of Economics.

I agree that sometimes infosec folks can get into the habit of telling the scarier story. If that scarier story is true though shouldn't we take heed? I responded with the following:

This is an interesting take and really just seems to be a language issue. I suppose it all depends on how you define "war" and "warfare." Mr. Sommer's quote "... skirmishes between nations, are going to have a cyber dimension,” is war in some people's eyes. Also, if it's "..just another way of spying" do wars ever start because of more traditional espionage? I also don't really understand the Greenpeace reference since they don't really attempt government-level espionage. As for the statement that "... advanced countries could recover from such a conflict within days, even hours." That's a great point, cyber-based attack would only be devastating if followed by a tactical operational attack to take advantage of the service disruption. The ability to disrupt, or intercept, communications to and from your target would give you a significant advantage. This ability has brought about encrypted communications by default for the military while critical infrastructure has not yet seen the need for this. One of the issues we discuss with our customers when penetration testing is to assess the impact of the operational decisions made based on information received from a field-connected device. Can I get a human, or machine, to initiate an action if I provide false data?

In 2008 Russia attacked Georgia and used cyber attacks as part of their campaign. I wonder if that would be considered cyber warfare by the authors or just a skirmish? Then, to be fair, I wonder how Georgia would define it.
http://www.zdnet.com/blog/security/coordinated-russia-vs-georgia-cyber-attack-in-progress/1670

I believe cyber "war" is a reality and will be used as a component of real large-scale attacks in the future. What do you think?

16.1.11

We lost a good man yesterday



The attached song is one I play when my heart is grieving but my spirit is rejoicing. When I saw Mercy Me perform it the first time they shared the heart-wrenching story of how it had been written and it seems appropriate today.
Jason Kennard died last night in a car accident. When I was in the praise band at The Church at Sterchi Hills, his wife Lisa would always ask for prayer that the Lord would convict Jason and he would be saved. During this time, we built a new building and had a week-long revival to celebrate the opening. During the revival Jason came to hear one of the messages and received Christ as his savior. It was one of the greatest moments God has allowed me to witness. Shortly after this, Lisa was in Florida and Jason "dropped dead" of a massive stroke while home alone with his young children. I remember clearly sitting in the ER waiting room at St. Mary's hospital waiting for Lisa to return home from Florida so that Jason's life support could be removed. While we waited, and prayed, Jason showed some level of responsiveness which then prevents life support from being cancelled. Also during that time, one of Jason's friends contacted Lisa and told her that God had told her that Jason would be raised up from this because the Lord had plans for him. She quoted Jeremiah 29:11 "..For I know the plans I have for you,” declares the LORD, “plans to prosper you and not to harm you, plans to give you hope and a future."(NIV) I had the wonderful opportunity to spend every afternoon for the next two weeks watching Jason be healed by the hand of God. Each day he became more responsive and gave everyone a visualization of faith. Jason beacame a faithful servant of the Lord, leading his family and being the man God had called him to be. He was a walking miracle and one of the examples God showed me of walking through the fire of life's trials and emerging as a better man on the other side.
Please keep Lisa, Zack, Whitney, and Seth in your prayers. We know that Jason has been raised up by the Father and healed but our earthly hearts still hurt for the man we will be missing.
Grace and Peace to you.

6.1.11

Compliance != Security




We have so many compliance regulations and auditors now that information security should be getting exponentially better every year. PCI just came out with a new standard, HIPAA received an overhaul recently, and who knows how many other NIST standards are being re-written and re-worked. This is not the case; we see compliant entities are hacked all the time. Worse, they are hacked with what seems like the same old techniques. Disclaimer: I know some talented auditors and they understand where the pitfalls and shortcomings are, do not blame the auditors.

I understand, and sympathize, with the fact that some you have to be compliant to some organization. I also believe that compliance was (is) a good idea and that it means well. What appears to happen is that compliance becomes something you can purchase. We also believe that a compliance-based certification makes our auditor an expert. Business owners want to know "How secure can I be for n dollars?" "How much will it cost to be secure in area x?" For some reason we (security dudes) have not adequately conveyed, (or maybe we have) that this is not a static black and white area. Threat and attack vectors shift and change from day to day, hour to hour, and sometimes form one minute to the next. Is there an effective way to combat this without bankrupting your organization? Can this be done without implementing a police state on your users? Yes, it can. Can you be "hacker proof,” ever relax, and do things the same way you always have? No, you cannot. Working together with the right information security personnel, policies, procedures, and technical controls, you can bring balance to the force.

When preparing for an audit, remember that an auditor can be used to enhance your security posture. One organization I have seen in the past viewed an auditor as an enemy and spent weeks planning how to lie and hide things. It would have been less expense and effort to be compliant. The auditor you choose, or is chosen for you, can also determine your security posture. An auditor with experience as a penetration tester is likely to ask better questions when using the unfortunate checklists. An auditor who is only trained to observe a checklist may view things differently. For example, firewalls are typically required by compliance mechanisms. An auditor thinking like a hacker is used to overcoming and bypassing firewalls and may choose to audit your rule set or assist with configuration changes. You may have a best-of-breed monster firewall but if you have 700 exceptions then you may be leaking data. Web proxies are another good example. You may have every user flowing through a proxy to prevent abuse, drive-by downloads, and policy enforcement. An auditor with a penetration testing background may think to ask how many SSH tunnels (users possibly bypassing the proxy) are exiting your network where a standard auditor may not think of this. Remember, not all CISA, CISM, and QSAs are created equally. If you need an auditor, send me an email I know several excellent folks that are also active pen testers.

Next, make sure you do prepare for compliance, or certification & accreditation audits. How you prepare is critical. While you should make sure you are prepared for the auditor's checklist, do not stop there. Do not assume an attacker will be using that checklist or that the creator of that checklist thinks like an attacker. As a best practice, have an independent third party red team your environment. Penetration testing from multiple perspectives can provide excellent insight concerning your security posture. Being tested externally and internally from black\white\crystal box perspectives will provide you with a comprehensive understanding of where you stand. When I say third party I mean completely not affiliated with your organization. If you are a govt agency, I am not referring to your agency's IG or internal audit. Hire people who will think like a bad guy but are not part of your blue team efforts. There are several reasons for not using your own people; I will list a few here:


Your people are familiar with your culture and environment. While this can be a good thing, it can skew results by overlooking points of failure or vulnerability.
Pride may come into play. How forthcoming will your people be in pointing out issues in a program they have spent years "perfecting."
A third party does not stand to lose (or gain) from your organization's internal culture. (Performance reviews, bonuses, profit sharing, etc.)
A third party will see if your paper policy is effective. A policy without a control is an exercise in writing and awareness.

I am sure there are more but my ADHD has kicked in and I lost interest.

Most importantly, remember that threat and attack vectors change rapidly. You passed your audit today, you got red teamed and remediated every single finding; good job but remember what the attacker could not break yesterday they can today. Information security is a never-ending profession and requires constant vigilance and dedication. Make sure you (and/or your team) are constantly learning. Stay on top of new threats and attacks by listening to the security researchers out there. If you and your people are behind, get some training and/or hire some consultants to get you up to speed. The only thing that will make you secure is you and your team.






5.1.11

Interesting Acquisition Trends


Let's take a look at some of the mergers, acquisitions, and takeovers that have taken place recently.I no particular order, here are the big ones that come to mind.

Intel snags McAfee - Don't forget that McAfee had also been buying up IDS, Firewall, and DLP solutions prior to this.

HP acquires ArcSight - ArcSight is a small company but regarded as best of breed in what they do.

HP acquires TippingPoint - Also known as 3Com, anyone remember them? Tipping Point is regarded by some as a best-of-breed IPS.

Dell grabs SecureWorks - Very interesting move for Dell.

I am sure there are more of these but these all stuck out as companies which want to be able to provide, now or sometime in the future, some sort of complete solution for their customers. This business model will be interesting to watch. Will the people who spend the money prefer one solution "silver bullet" or will they see this as all their eggs in one basket? What happens to people who want a Dell data center with Tipping Point IPS and/or ArcSight SIEM? This also blurs the lines between competition and interoperability.

29.12.10

Laptop Bag Review (Spire Torq)


I needed a pack that can carry a Dell M4500, a few hard drives, some wireless gear, and standard office-type junk. This pack is perfect, it's construction appears much sturdier than anything else I looked at. After 8 months of abuse, I travel a lot, it looks brand new. The laptop sleeve, and the hanging design, are perfect.

The interior has enough pockets and zippers for me to adequately separate my gear by function. I can get to what I want easily even when it is stuffed under an airplane seat. It seems to fit there fine and I can still rest my size 12 shoes comfortably next to it.

The exterior has the "must-have" features I couldn't find in other packs like compression straps, stowable waist belt, molle-type loops in the front, and rings for attaching things to the outside of the pack. For the outside rings, I attach a ball cap and a rain shell since I am allergic to umbrellas;-). The shoulder straps are very wide and padded as is the waist belt. This is critical for load distribution and a place where many other bags fall short.

I f I HAD to knock anything, the pack is so roomy and sturdy you might overpack it and it would be super heavy. I would also like to see the laptop sleeve modified to tote around your laptop brick somehow as well. For the exterior, I could see home some might want more molle but the four on the front are enough for me.

27.12.10

Cyber Security Sucks

Warning, rant ahead:

For several years as I have learned more and more about how computers, networks, and policy are interrelated. I have felt security in these areas is actually getting weaker. I listen to people just blame security issues on Bill Gates and think they are immune because they can bash a vendor.  This seems to be happening by over governing some aspects, under funding, and hiring of absolutely the wrong people. Today I saw a couple of blog posts that should let you know exactly how bad it is out there.

First, consider this from Taosecurity. If you don't believe that is our stolen technology staring you in the face, it is. APT is a really hip buzzword, but it's real and you better figure out what it is and where it is on your networks. I know a couple of govie orgs suffering from this right now but they are too arrogant to think it could happen to them so it will remain on their networks until.. well probably awhile.

Saving the best for last, I read about the carders.cc job. No, I didn't read the 900 cut-and-paste opinions on it, I read it from the d00dz who did it. Are you still confident about your security, wanting to trust your users, wanting to trust some 1337 guy you hired? Read this e-zine from the 0wned and Exp0sed crew. If that doesn't make you realize we all suck at security, I don't know what will.

I am not at all saying we, or anyone mentioned, is stupid. I am stating that the enforcement of the status quo must stop. We all need to learn more, do more, and weed out the lameness. Note in the zine that if you have used (installed) ettercap in the last five years, you might want to check your "shit." Do you know how many of us use that? ALL OF US!! That sucks!. These people went after several high-profile well-respected security pros, and their websites and 0wned them at will. If you think you're immune please share your awesomeness with the rest of us because this should make you realize how bad the state of security is. What this group did is wrong but things like this need to happen in order to get things moving in the right direction.

2.12.10

There are no internal applications


I read this post by Rafal Los (Wh1teRabbit) and wanted to agree completely. If you still believe you can have a firewall and an IDS and "trust" your users, you are inviting a problem. If you have a team that is convinced that nothing bad could ever happen to their infrastructure because they are 1337, you have a bigger problem. The blog post and comments focus on the fact that data is what needs protected, not just the location of the data. As mentioned in an earlier post, mobile computing and new threat and attack vectors are removing your borders for you.
Your people are your greatest asset and your biggest risk. Somebody in your organization clicks links, brings in infected USB drives, plays of Facebook all day, or actually wants to steal your data. I have been inside some supposedly very secure networks before where nothing but everyone's good intentions, and some veiled threats, stopped them from doing whatever they wanted. I don't just mean a penetration tester with network access, I mean anyone that knows how to open network neighborhood or send email. Talking with the management in these organizations resulted in some head nodding and furrowed brows but no change or desire to change. Every now and then a technical person would get frustrated and leave only to be replaced by a project manager or an "architect." At one place, a mid/senior-level analyst left and the management decided to replace him with someone  that had no security experience. One of the quotes overheard from that management group was "We don't need anymore smarty pants around here, we need someone who can get along with everyone." I agree that your team should function well together, just not at the expense of your data's security.
So, think of it this way:
1. Can a malicious insider, no matter how unlikely, steal your data?
2. Can a non-malicious insider bring a threat inside that compromises your data?
3. In either case would you even know if this had happened?
4. Why can it happen?
5. What can be done to lower the risk or impact?
Good luck planning for future security projects, don't forget to use the wiki leaks trend to increase your budget for next year.