Security's Everyman

Security's Everyman

Monday, March 03, 2008

Screen Savers

Recently we implemented mandatory screen savers for all PC's at work. There were a few systems that we had to exempt from the policy due to legitimate business need. These systems are in secured areas and have limited access by only a few users. The rest of the systems received the policy early last week.

The decision was made to use a common Text based screen saver and allow the user to change the text but not theme of the screen saver. We sent out several messages informing the users of the change and when it was scheduled to happen. The day that it went into effect you would have thought that we took away their PCs and replaced them with an etch-a sketch. All of a sudden no one could work because they would be in the middle of intense computation and all of a sudden the screen saver would kick in and they would lose all of their work. In reality the problem was that they either didn't like having to reenter their passwords or they were upset because they couldn't change the screen saver to something else.

The manager of the help desk is also the one who sent out the emails explaining everything that was going to happen. She is also the one catching the wrath of many of the users. She has been bombarded with calls, emails and visits by people who complain that they can't work or extremely upset because they no longer have pictures scrolling across their screen when the screen saver kicks in. The sad thing about this is that in the past this has worked. A new policy is put into place, the users whine and cry, the policy is rescinded. Fortunately things are different now. Management realizes that the policies have to be put into place whether the users like it or not.

Often management caves to the whims of the user without taking the bigger picture into account. I've seen this in many companies that I've worked for and have heard stories of many others. Management wants the users to be happy, which is important, and security wants them to be secure, which also is important. The important thing is to reach a "happy medium". The point where users are happy and can actually do their job, yet the systems and network are secured. In a company that has a history of allowing the users to make policy decisions it can be a challenge to reach this happy medium.

There are several steps involved in getting past history and to where the company needs to be. It starts with education.

  • Management needs to be educated in the need to find balance. They need to understand that users want convenience, ease of use and control over their systems (ability to add programs, manage how it looks and feels, etc).
  • Users need to be educated. They are not concerned, at least by default, about security. They push back on most anything that changes how they are able to control their systems. The problem with this is that users are not "secure by default". They don't understand how to secure a system or why "that cool screen saver" they downloaded may just be the back door into the network. They need to understand "WHY" security is important and how it affects them personally.
  • Communication of changes MUST happen well ahead of the actual change. All affected parties need an opportunity to think about this and how it may affect them and then ask questions. Maybe they need time to work out new processes to minimize the impact on their jobs without compromising security. This step does not happen just by sending out an email telling that the change is coming. The communication needs to tell them to think (kinda sad isn't it?). Unfortunately many people don't think by default.
  • Feedback from users needs to be taken into account to work around issues that may come up. An example from our screen saver issue is we have a few systems that are used by our call centers to view call queues. That is all these systems do so we need to exempt them from the policy while still ensuring that they are secured. Remember, we have to balance security with usability.
  • IT/Security has to remember that they do not have the final say on what, when, where, how or why these things happen. Their job is to come up with solutions to problems and convince the company why this is what we need and then work with the business units to make the solution as painless as possible.

Saturday, March 01, 2008

Digital Forensics

I've mentioned before that I'm not a forensics guy by any means. I've never done any "real" forensics, at least not anything beyond simple looking for fairly obvious evidence of a breach or problem. I enjoy reading about digital forensics because it fascinates me. The way that data can be extracted from media after it has been deleted, hidden, and even when the disk has been formatted. Not to mention how someone who is trained can look at the system and determine what happened, how it happened, who did it, how they gained access to the system, etc....

Last week I read this post by Harlan Carvey here. This quote that he made got me to thinking:

My personal thought on this is that ideally what an organization would want to do is develop an in-house capability for tier 1 response...trained folks whose job it is to respond to, triage, and diagnose a technical IT incident. By "trained", I mean in the basics, such as NSM, incident response, troubleshooting, etc...enough to be able to triage and accurately diagnose level 1 and 2 incidents, as well as preserve data until outside professionals can respond to level 3 or 4 incidents.

What is it that companies really need? What are the basics to ensure that triage is done in a manner that doesn't compromise "the crime scene". I decided to post that question to my friends in the Security Catalysts Community here. As I expected I have gotten some good responses.

On Thursday of this week I attended a one day event put on by ISC2 called SecureAtlanta 2008. I had forgotten what the topic was and it turned out to be Digital Forensics. It was a high level discussion that covers a lot of the basics of what DF is and why companies need to be informed and concerned about it. Not much of the content was technical but it was informative. One of the things that grabbed my attention was the topic of DF and the law. We need to keep in mind that what we are doing in incident response and forensics needs to keep in mind the possibility of going to court. Our findings may need to be presented in court to convict or defend. Therefore we need ensure that our teams are trained in the basics but also trained in how to not contaminate the crime scene.

One last thing to consider is that just as all things related to security there has to be a balance. We have to balance IR and DF with ensuring that we get (or keep) the company running. We can't forget that our company probably relies on these systems running in order for them to make money. So if your company doesn't have proper policies and procedures in place for this that you start the conversation with your boss. Then work with management to put in place the proper program and training get put in place.

Thursday, February 28, 2008

Real Life Awareness

Here's a great user awareness story from real life.

My wife and I just finished attending a 4 week long Sunday School class on Parenting Preshoolers. Yesterday the girl who was the class coordinator sent out an email to the whole class. She ended the class with the following statement

"If any of you are interested, please let me know and I will email her your email address. I did not want to send everyone's address to everyone without their consent."

If you stop to think about it you will know where this is going. :) When I looked at the "to" address sure enough there was each and every address for the whole class. I couldn't help but smile. It sort of has a happy ending though. A few minutes later she sent out a follow up email
"I apologize for not hiding the addresses in the last email. I meant to press a different button but hit send before I could correct it. Sorry."

So either she realized what she did or someone else pointed it out to her. Either way I was impressed with the fact that she was aware of the fact that she should not have just sent out every ones email address w/o their permission. Way too often people just forward emails with the address of everyone in their address book w/o thinking about it. I'd like to know where she learned about the need to hide addresses. I saw her last night and we had a good laugh over this I wish I'd asked her then. Was this something that she learned from a work User Awareness program? Did her husband pass this on to her? Maybe a friend told her about it. Either way it's a good that she know it and that she puts it into practice..........usually.

I sent her a reply and told here that with her permission I'd like to use her in my blog. Of course I assured her that I'd not reveal her name or email address........unless I forgot. :)

Thursday, February 21, 2008

What?!?!

I thought these guys were getting better at this. Apparently whoever sent this failed "Basic Phishing Emails 101" I've got all sorts of comments and tips on how to do this better but I'll let you come up with your own.

From FedEx Express
 
FedEx Express Logo   
                                             
                                              FedEx Nigeria Head Office
                                             
70 International Airport Road

                                              Mafoluku, Lagos.
                                              Tel +234-807-493-8690

 

 

Attention' Attention’ Attention'''


                                                CLAIM NOTIFICATION.

 

This is to notify you that your parcel is still in our possession, this parcel contained an International Cashier Bank Draft/Cheque worth the sum of $2 Million dollars only and it is ready for delivery to your door step. Meanwhile, before the delivery or shipment will take place, you are advice to send to us the following data’s mention below:

 

1. Your Name
2.Address
3.Telephone

 

The above requested information’s will enable us deliver your parcel correctly without any mistake or delivering your parcel to a wrong person. Further more, you might be asking yourself how comes this email, cheque or draft, Anyway, your cheque was brought to this office by a Lottery Fiduciary Agent Or Claim Agent, signifying that you are a rightful winner to their Lottery Award selected randomly from 10 lucky email addresses which your email address is one of the lucky email address.

 

FedEx courier service company mailing you as per your parcel that was brought to this company to be delivered to you by  lottery groups, along the delivery process that brought a misunderstanding between you and the lottery claim agent and in regards of their request as per their insurance certificate cost and tax fee which happened to be the course of your parcel being pending for the past months/one year.

 

Meanwhile we are hereby happy to inform you that the FedEx Company has finalized everything with the nicon insurance company of Nigeria ? and the internal revenue office as the company organization has also listed 24 valuable parcel’s to be intact in their office after the released of the parcel’s from the nicon insurance company and internal revenue office.

 

We are happy to inform you once again that your parcel that contains the sum of $ 2 million dollars is among the 24 parcel’s listed which is now in our office and also with your name as the receiver despise that we lost your private residential address’s, which is an indication that you can now re-send your residential address, telephone as stated above back to the FedEx company where your parcel can be delivered to you without hesitation with this e-mail  (fedex_courier1@web2mail.com)
 
Meanwhile remember that the sender of this parcel to you that’s the fiduciary agent still owns this company the sum of  $150 before incident occurs Note this fee is not just for delivery but with the stamp duty, this company has spend out of their incomes in the process by recovery back your parcel? so dear customer we once again appreciate your patronage in our favor.

 

Without hesitations you are to pay for just the balance left by your sender since we have lost his contact. this payment have to be via western union money transfer with the below payment information so that your parcel can be delivered to your residential address before it accumulate a demurrage after one week only,as you know your parcel is not just an ordinary parcel but with a huge amount and I think you understand what I mean by accumulating a demurrage? Which you will not allow to happen to your recovery parcel that almost gone if not for the love that the good god have for you by favoring you with his favor because it was god who did it not by your power but by the spirit say the lord.
 
We assure you that your parcel will arrive at your country in two days time and it will get to your door step the third day as soon as this company receive the balance left by your sender and the tracking number of your parcel will be sent to you via e-mail immediately so that you can track it yourself to see your parcel coming on the way and you will also know when it will arrive at your country because we operate in trust and loyalty in your favor.
 
And also the FedEx Courier Service Company is hereby to inform all their customers by eradicating all their communication with the scam mails that are going all-over the world be careful with their e-mails so that your parcel will not be in danger with their evil planes.
 
FedEx provides access to a growing global market place through a network of supply chain, transportation, business and related information services.
 
PAYMENT INFORMATION

 

Receivers Name: Nbu Philip

Senders Name: Your Name

Text Question: Who is your father?

Answer: God almighty
Amount: $150

Location; Lagos Nigeria Africa

MTCN Number... 

 

Please you have to send the full payment information including the MTCN Number for we to fully proceed on your delivery
 
FedEx is one of the world's great success stories, the start-up that revolutionized the delivery of packages and information. In the past 30 years, we've grown up and grown into a diverse family of companies as FedEx that's bigger, stronger, better than ever. Call me: Tel: +234-807-493-8690
 
WAITING TO READ YOUR E-MAIL.

YOURS AFFECTIONATLY.


MR.SAM BROWN.
Tel +234-807-493-8690


FEDEX COURIER MANAGING DIRECTOR..
 
 

Sunday, February 17, 2008

When does security begin?

I ran across this the other day and had to save it for later. Now later has arrived.

It makes me feel good to know that I'm not alone. One of the biggest frustrations with my job is that since they didn't have an official security program before I got here security is often an afterthought. Sometimes that means after a project has begun and often it begins after the project has been completed. Similarly to Mathias so far the best I've been able to do is get a few of the PM's on my team and my signature is required on the final paperwork before something goes live. Unfortunately there are a few problems with this.

  • The first problem is that after a project has gone from vision to final testing and is ready to deploy the project team and sponsor get a little upset if security tries to put it on hold.
  • Often by the time I've found out about a project it is almost too late to ensure proper security is in place.
  • One of the most common things that I've run into is the lack of understanding of the need of security. I regularly hear "It's not on the Internet so why does it need security?" or "You have to have a username and password to access the application so it's secure."

I have been working on, and am slowly starting to see some results, getting the rest of the enterprise to think about the need for security early on. We have a major project coming up that has already asked my input and it isn't even slated to begin until 2010 or 2011. That makes a security guy smile. :)

It's never too early to think about security for an application or a project but it's often not the case. Security is still an afterthought in the mind of many and it requires that we not only be prepared to start at the beginning but to also jump in at any point in the process and ensure that security is properly implemented.

InfraGard Speaking Schedule Change

My talk at the Birmingham, AL InfraGard Chapter has been moved from March to April 8, 2008. If you are in the Birmingham area and either regularly attend the InfraGard meetings or are interested I'd love to meet you there. I'll post location information once I know it myself.

Thursday, February 14, 2008

The 7th way the Starbucks-AT&T deal will change mobility

ComputerWorld has an article "6 ways the Starbucks-AT&T deal will change mobility". They failed to list the 7th (actually probably it's the first) way it will change mobility.

  • More laptops will be pwned.

Now access is free for thousands of people who wouldn't pay the $30 to $40 a month that T-Mobile charged. That means that every person with a laptop that lives near a Starbucks and is an AT&T broadband customer will go there to access the Internet. Their laptops are not hardened. They have no idea how to protect themselves or that they need to protect themselves. They will conduct financial transactions and someone will be waiting to sniff their traffic, hack their system, or convince them to connect to a rogue AP.

Thanks James

I appreciate the help.

Thursday, February 07, 2008

If I had a nickel for every patch

UPDATE: I'm now up to over $3!!!!!!

http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12


I'd have 75 cents today alone (hey, in a possible recession every penny counts). Today the following Companies announced patches for their software.

  1. Microsoft has 12 patches coming out next week on Patch Tuesday.
  2. Adobe has a patch for Acrobat Reader.
  3. Apple has a patch for Quicktime.
  4. Sun has a patch for Java SE 6.

Luckily for most these are all apps that have auto patching capabilities and usually they are turned on. This is a good time to remember to check the other software on your systems that don't have auto patching.

I also seem to remember that Skype just released a patch and Apple released a patch for IPhoto so that takes me up to 80 cents. I wonder what's in the couch under the cushions. :) If I go back a few weeks I'm well over a dollar and possibly pushing 2 dollars.

Just remember to keep your systems patched and keep an eye out for that forgotten application and update it also. While you're at it check your DSL/Cable modem, wireless or wired router, printer, and anything that can connect to a computer or network. Check out Pauldotcom.com for more information on imbedded device security.

Good Tips

PC Magazine has a list of 72 Tips for Safer Computing that I wanted to point you to. I know lots of us are constantly asked by friends and family how they can keep their computers safe. Unless you have a ready made list it can be time consuming to give them all the tips they need. Well here is a pretty good list that you can give them and if they follow it they should be in pretty good shape.

Odd things

Sometimes odd things happen one right after another. I've had one of those weeks. It started a few days ago when I was walking to lunch. I got to the restaurant and ordered my food to go. As I was waiting I touched my hand to my phone which I keep on the right side of my hip. Next to it I keep a belt clip that has my Employee ID, Door Access card and Transit card. As I felt my phone I noticed that something didn't seem right. My belt clip and cards were gone. I immediately started to panic. I work in Atlanta and foot traffic is heavy. I was sure that someone had picked it up and I was hoping that they would take it to my office and leave it at the security desk. Luckily my food arrived at that time and I started to retrace my steps. I found it about half way between the office and the restaurant. It was in the middle of the road and I watched 3 cars run over it. I was able to retrieve it and except for the clip it was undamaged.

I was listening to Pauldotcom Security Weekly (an odd thing in itself :)) the other day and they were talking about lost laptops and Paul was saying that he never leaves his laptop unattended. He makes sure he carries it with him everywhere to prevent it from getting stolen. I'm pretty much the same way. If I'm going somewhere and I know that I won't need my laptop I leave it at home. If I'm one my way to or from work and I have to stop somewhere I will take it with me instead of leaving it in the car.

Well, yesterday I had to drive to work because I missed the bus into town. The temp light on my Jeep came on about 1/2 the way there. I pulled over to let it cool down and decided that I needed to replace the thermostat (I've been putting it off). So during lunch I grabbed a thermostat and planned on changing it in the parking garage after work. Since I usually dress in a Shirt and Tie I needed to change before doing the work. I grabbed my laptop bag and headed down to the locker room where I keep my workout clothes and changed into a pair of shorts and a tee shirt. I grabbed my stuff and headed to the parking deck to start working. I replaced the thermostat, added some coolant and hit the road. Unfortunately it seems that the thermostat wasn't the problem because the temp light came on again about 1/2 way home. More troubleshooting needed.

As I got home and started to grab my stuff it hit me that my laptop bag was NOT in the car. I really panicked this time. I had visions of it sitting in the parking garage thinking that I had set it on the ground beside my Jeep while I worked on it and forgot to put it in when I left. I searched my mind trying to remember where I may have left it. Was it still in my office? WHERE!?!?!?! Then it hit me that I had left it in the locker room. My panic subsided a little because it is an employee only facility, but I was still worried none the less. So I grabbed my 2 girls and hit the road to go back to the office and get it. It was still there and had been undisturbed. I guess if anyone saw it they just assumed that it belonged there. WHEW!!!

Both of these incidents could have had much worse endings. The loss of my cards could have given someone unauthorized access to the facility (and lots of free train rides). We have processes in place so that I can disable the cards quickly so that would have reduced the window of opportunity. The laptop loss would not have been such a big deal since I use TrueCrypt (they now have whole disk encryption now) and keep all of my data on the encrypted volume. It would have been a headache more than anything.

So lessons learned. PAY ATTENTION!!!!! Don't get so distracted by what is going on around you that you lose focus on important things.

Wednesday, February 06, 2008

(Another) Good SANS ISC Entry

There are just some resources that are invaluable to Security IT Professionals no matter what area of IT you work in or what your position in the company is. SANS is one of those resources. They watch our back, block for us and give us new plays for our playbook. Not to mention that they coach and train us to make us better at what we do.

Today the ISC Diary has another good reminder and tip for us. One of our primary responsibilities is to secure our environment. We apply patches, double check our configurations, ensure least privilege, etc..... but are we often overlooking something? Do we spend so much of our energy on these things that we forget to make sure that we didn't leave something that doesn't need to be there? Do we fail to look beyond our standard procedures and checklists? How long has it been since they were updated?

Just as we need to ensure that we do the things that we need to do we also need to ensure that we don't do things that aren't needed. The key is knowing what these things are.

Security Catalysts Community Roundup

When I started following blogs a couple of years ago I discovered several blogger's who impressed me with their knowledge of various aspects of security. I thought I had hit a gold mine in finding their blogs. Now I had places to go and get information on various topics. I could even ask them questions and usually get a reply from them. Towards the end of 2006 a few of them started talking about a new community that was starting up. It offered a place to post your thoughts, questions, comments, ideas, etc and interact with other security professionals. So I decided to check it out and saw a few things that I liked.

  1. The boards weren't stuffed to the gills with questions so it made it easy to find what you were looking for.
  2. The boards are kept organized. There aren't hundreds of user created main topic areas that clutter the boards.
  3. When you posted a question or idea others chimed in with comments that were meaningful. There is no name calling or belittling others. If someone does do that their comment is removed and they may soon follow.
  4. You actually saw who you were interacting with and not some cryptic screen name. This allowed me to have a sense or whether or not I could trust them. All members are required to register with and use their real names. (OK, so we don't do ID checks on everyone but you get the picture)

These are just a few of the things  that I really liked. I then hooked up via email with Michael Santarcangello who could be called the "Father of the Security Catalyst Community". I had listened to his podcast and read his blog and liked what he had to say and the way that he thinks. He, like many in the SCC, doesn't think along the same old "best practices" lines that seem to infect many in IT and Security. He thought outside the box and tried to get others to do the same.

That was Jan. 2006 and since joining the SCC I have benefited tremendously. It has provided me a place to get answers, feedback, support and development friendships and networking with other Security Professionals. Lots of people have joined the community and many of them participate regularly in what is going on. I'd like to invite you to stop by and check out what is going on. I'm going to highlight a few of the conversations that have gone on in the recent past and a few of the people who have their own blogs. My goal in this is to give you a little more insight into what the community is all about and entice you to come join us and add your voice to what will become a major voice in security in the future.

Recent SCC Posts of note:

  • Rootkits and MBRs - As soon as news of the new (ok, not new but new in the news) MBR Rootkits hit the gang at the SCC jumped on this one. Read what the community has to say about this topic. I personally think that the first response post is packed with wisdom and insight. :)
  • ICMP Tunneling - I went back a while on this one because it has some useful information on a topic that we don't hear much about and many people haven't really considered as a threat to our data.
  •  Value of asp.net web.config file encryption - Here is another topic that isn't very sexy and doesn't get a lot of attention in the media and blogs but that doesn't stop us from discussing it. We all know the importance of web app security but we can't forget the server itself.
  • Project Management Training - We all like to stay on top of our game and training and opportunities to learn and improve ourselves is a major focus of the community. Here we discuss how to prepare yourself to be successful in Project Management.

We have lots of blogger's and others who have their own web sites. You can find a complete list of them by clicking on the "members" link from any page in the community and then click on the website column. Many of the names you will recognize right away because they are the "big names" in information security blogging (and usually in their field of specialty also) and some you may not be familiar with but they have great things to say. I wanted to bring a couple of them to your attention.

  • Michael Dickey (aka - LonerVamp) blogs at terminal23. Michael caught my attention early on because he has lots of good things to say. He's a Linux guru who understands security and has a great grasp on using linux both to help secure your environment and as your everyday OS. He can get pretty technical so beware. Sometimes he makes my head hurt.
  • Adam Dodge has a website called Educational Security Incidents (ESI) where he maintains a ongoing list and discussion of breaches in the .edu space. Those of you who work in the .edu space need to know Adam and his site. Colleges and Universities have their own unique challenges when it comes to information security that most of us don't face. They have to find the balance between the "free flow of data" nature in a university environment and protecting the PII, research and other important data. There are lots of other .edu security gurus in the community that will benefit you greatly if you are in that field.
  • Alex Hutton is another blogger that is worth your read. His focus is on Risk Management and he blogs at and maintains a site called Riskanalys.is (yes the .is is correct). Alex usually doesn't talk too technical but don't let that fool you. He knows his stuff from everyday security to the implications of not being compliant to how risk can make or break your company.

Well, that's it. A quick recap of what's going on in the Security Catalysts Community and why you should be involved.

Tuesday, February 05, 2008

ActiveX Vulnerabilities

As many of you are aware Symantec recently announced that several ActiveX vulnerabilities exist that have to do with image uploaders in many social network sites. The current recommended fix is to set the kill bit on each of the CLSID's. If you have ever done this manually it can be time consuming if you have several machines to do it on. The other option is to make the changes on one system and then export those registry keys out and import them to the other machines.

One of the SANS Handlers, Tom Listen, has released a tool that will allow you to manually make these changes via either GUI or CLI. I've tested both and find them to be very easy to use and a time saver. The command line version probably can be used via script or pushed out via AD although I have not tried this.

If you are interested in giving it a try you can find his write up and download the tool here.

New (at least to me) SPAM Vector

Has anyone seen much of this? I've been getting lots of "Yahoo Groups" spam in the last couple of weeks. Usually I immediately delete it but this morning I decided to investigate a little further. Here is the text of today's message.

www.creatxxxxxxxx@yahoo.com has invited you to join the BUILD_YOUR_WAYS_TO_EARN_AT_HOME group!

Greetings,

Are you tired of finding a job? apllying
to a large company and still unrecognized
your ability of doing work.
How about putting the work at home and let
those company paid you at home?

A Simple Step By Step System
For Selling Your Online Marketing Skills
To Businesses Right In
Your Local City

http://urlmin.com/gethirednow
http://urlmin.com/gethirednow
http://urlmin.com/gethirednow

Being a Complete Stranger to Putting Checks
in Your own Pocket.

To your Success,

Nicole R.
Success Builder Team

I've masked part of the top url to keep others from going to it but I wanted to point out something. Notice that the first part is "ww.creat". That is how it originally was and then they started a new word. I'm assuming (based upon the rest of the url) that they were wanting to say "create" but if you look at the rest of the message and see the grammar you will understand. :)

Fortunately for those who received the message the http://urlmin.com/gethirednow link failed to contain the actual link so you can't click on it and be taken to where ever it takes you. Of course you could still manually go there, but if you do that you probably deserve never mind. I did do a google search on urlmin.com because I've never heard of it before and it appears to be a spanish language url shortening service. Anyone know anything about it's legitimacy?

I just wanted to see if any of the rest of you have seen this and what your take on it is. Let me know if you have any insight.

P.S. Nicole R - If you are on the Success Team maybe you should look into taking some English as a second language and grammar lessons.

A funny thing happened on the way to reviewing my logs

At work we're in the process of implementing a SIEM (Security Information Event Management) system. I'll leave the vendor nameless for the moment but they have a reputation of making most everything harder than it needs to be. Until that time all logs have to be reviewed manually and obviously that means that they are not reviewed in real time. I have others that monitor most of the logs but I monitor our IPS logs from the UTM device. Usually I review them each morning when I come in  but last week I didn't get a change to so yesterday I was playing catchup.

As I reviewed them I noticed something new. There were lots of  entries where XSS had been stopped. At first I was really worried thinking that if there were that many attempts then that must mean that there was a vulnerability that someone found and now they were trying to exploit it. Of course I had no real way of knowing if they had been successful or not. At least not w/o more research. As I looked into it more I noticed that it only happened on one day and that it was only for a short period of time. Then I started to do a whois lookup on the IP address and discovered that it was me. I had been doing some testing on a new feature of our web site and part of that was for XSS vulnerabilities.

It's good to know that the IPS caught this and stopped it before it got the the server itself. That makes me feel a little better but I sure will be glad when the SIEM implementation is complete so I can see these things in real time and have a better grasp on what is going on.

Friday, February 01, 2008

What a week!

It's amazing how a week can go to pot in no time. I had such big plans for the week and they all just went up in smoke. I had several things that I was going to blog about and several things at work that I was going to accomplish. Very little of either happened. It all started Tuesday afternoon when I found out that I had unplanned meetings pop up. I was in a meeting every working hour Wednesday and Thursday. Of course most meetings equal unproductivity.

When I got a chance to slow down last night and check my email, RSS feeds and various other communication methods I was floored. Where does all this stuff come from? Most of it was quickly filed away to be dealt w/ today (which meant that I didn't get other things done). Now finally my inbox is either empty or at least prioritized, my RSS feeds are clear (mostly marked as read even if just to get it out of my face) and now I'm going to slow down and relax this weekend. The blog posts will have to wait a day or two (or maybe just go unwritten).

Hope y'all have a great weekend.

Tuesday, January 29, 2008

Join me at CSO Perspectives

I just got word from the CSO Perspectives team that I can bring a friend with me to the conference for a deeply discounted rate. The normal rate is $1495 and if you are interested in going I can get you in for $395. The date is March 16-18, 2008 here in Atlanta. If you are interested in joining me and the rest of the attendees drop me a note and I'll get you the information.

The lunatic is in my head

timeline_darkside You can stop with the snide comments now. :)

It seems that every week we read about another insider who has done something to damage the company. Sometimes it is physical (postal shootings, Coke document theft), sometimes it is digital theft, planting of a virus or logic bomb, unauthorized access after termination of employment, etc... It seems to me that there are two common themes in most of these:
1) Disgruntled employee.
2) Human error. This ranges from a lack of implementing proper controls or procedures, lack of following proper controls or procedures, laziness, apathy, or carelessness.

This morning I read this story on FoxNews.com about an inside job where an employee of AT Systems (an armored money delivery service) stole 8.5 million dollars. He was able to pull it off by being smart and observant.

He used another employees security code to gain entry to the building after hours. The story doesn't say how he got the code. Did the other employee give it to him? Did he get it by "shoulder surfing"? Did he find it written down somewhere? Let's look at each of these and see what went wrong.

  • It was given to him. I would imagine that a company that handles large amounts of cash would have a policy against sharing your access code with others. So the human error of laziness, apathy or carelessness comes into play.
  • He "shoulder surfed" it. I would think that the company teaches their employees to be careful when entering security codes to ensure that others do not find out what their code is. So again laziness, apathy, or carelessness comes into play.
  • He found it. I also imagine that they have a policy that forbids you to write your code down. Most of these codes are fairly short (4 to 6 digits) and are easy to memorize. So what went wrong here? Again, I have to point to human error.

Regarding this I have a couple of questions. Why did the code give 24/7 access (I'm assuming) to the building in the first place? Was there a legitimate business need for full and unfettered access? I doubt it and if there is when access to that much cash is involved I would think that dual access control would be called for. This is where policy and procedure needs to step up. Never should any one person be allowed to gain access to that much cash or even the facility that houses that much money.

The other thing that the article mentions is that he "watched and listened".

 "I decided to steal money from AT Systems' vault," he wrote. "I set about learning codes and watching and listening."

One thing that I preach in User Awareness is that you have to be careful what you talk about and where you talk about it. Even if you are at work. There are things that not everyone need to know. Don't discuss procedures around people who don't need to know them. Again, when entering passwords, access codes, combinations, etc ensure that no one else can see what you are doing. In my opinion those who were careless in what they discussed and how they didn't protect the information to gain access to the money are partially to blame for the loss. 

Friday, January 25, 2008

SANS Top 10 Security Threats for 2008

SANS has released it's list of the Top 10 Security Threats for 2008. Since I didn't make my own list of predictions (you can't really count the one I did) I decided to comment on theirs.

  1. Increasingly Sophisticated Web Site Attacks That Exploit Browser Vulnerabilities - Especially On Trusted Web Sites
    This is the thing that scares me the most. It has gotten amazingly easy for the bad guys to infect our machines. Historically we had to do something to get infected with malware (click on a link, run an .exe, etc). Now all you have to do is visit a site that has been compromised. Even better worse that site itself may not be compromised but maybe the site that hosts the banner ads on it has been compromised. It's almost a no win situation. Even those who are very careful may end up getting pwned. The best defense is to stay on your guard and make sure that you keep your system patched. That means all parts of it. Operating System, Applications and browser addons. (See "Will Malware Kill the Internet?" for more tips.)

  2. Increasing Sophistication And Effectiveness In Botnets
    This is another scary one. Storm work and others like it are almost smart. It's almost like this thing thinks on it's own. The techniques that they use to keep a botnet up and running make it almost impossible to defeat. At least the good news (as far as I know) is that you have to do something to get it.

  3. Cyber Espionage Efforts By Well Resourced Organizations Looking To Extract Large Amounts Of Data - Particularly Using Targeted Phishing
    I wish I was as good a fisherman as these guys are. Phishing emails have come a long, long way. No longer are they (the good ones) filled with bad spelling and grammar. No longer do they look fake. Now they look, sound and even feel real. Then to add insult to injury the bad guys are making the emails very personal. They often mention things about you and your company that all but ensure that they are illegitimate messages. These types of attacks will force us to pay closer attention to our emails. If we are to prevent a possible major catastrophe we will be forced to make User Awareness Training a higher priority and we will require that the be relevant, effective and interesting.

  4. Mobile Phone Threats, Especially Against iPhones And Android-Based Phones; Plus VOIP
    For the last few years we have been hearing warnings about how we had better get a handle on mobile devices before they become commonplace. I'm afraid that most organizations have ignored this warning. This means that now instead of being ahead of the curve and having a policy and plan in place to deal with them companies are having to play catchup. What is going to make this even more difficult is that now the users are used to having them and connecting them to the network. They are used to doing as they please and we have the fun job of telling them to stop. This does not go over well in most organizations and in even more management gives in and allows it to continue.
    As for VOIP it to will become a headache because, as in most things, security wasn't built in and taken into consideration from the early stages. Now we are having to figure out how to secure it after the fact. Another factor in this is that many organizations are deploying it and thinking that there are no security concerns with it. They approach it like they have traditional voice in the past. It's not the same and it has lots of potential to be trouble if not implemented and managed correctly.

  5. Insider Attacks
    We've already seen several examples of insider attacks this year. The bank in France that was defrauded out of $7 BILLION dollars by a rogue trader who worked for the bank and the Administrative Assistant who deleted $2.5 million dollars worth of documents because she thought that she was going to be replaced. The sad part of this is that these are just those who are trying to do bad things to our networks and companies. Another front that we have to secure against is the insider mistake. While this isn't an attack per se it can still have a devastating effect on our systems. Ensure that your employees don't have more rights than they need to do their jobs and we have to put controls in place to prevent their mistakes from becoming our nightmare.

  6. Advanced Identity Theft from Persistent Bots
    Getting a keystroke logger or rootkit on your machine is never fun. Especially if it leads to identity theft or extortion. This is a fairly new attack vector where the goal is still financial gain for the bad guy but they seem to have an additional motive of playing games. Maybe they learn enough about you to impersonate you online because they have all of your social media credentials or they send nasty emails to others on your behalf (of course w/o your knowledge or permission). Then it usually comes down to trying to get more money from you. If they can't have fun while doing it through extortion or such they will just take it out of your account.

  7. Increasingly Malicious Spyware
    So far I've never seen malware get less malicious and easier to detect and remove so there is no reason that it will start this year. The thing about this is that it is now a business just like legitimate software sales. The bad guys are offering support and various levels of use. Since they are making money from using it themselves and selling it they will work harder and harder to make it better and more effective.

  8. Web Application Security Exploits
    Again these get worse every year and more prevalent. This will require that our Web dev teams take security seriously and learn how to not only code securely but to think about security while coding. Then of course the rest of IT has to play it's part. The DBA's have to ensure that the databases are secured and the network team has to ensure that the firewalls, IPS and the rest of the infrastructure does their part.

  9. Increasingly Sophisticated Social Engineering Including Blending Phishing with VOIP and Event Phishing
    Social engineering is another area where the bad guys are getting better and unfortunately this is an area where technology is limited. We can put the controls in place but if the users give out the information over the phone or click on the link or send the data in an email then there is little we can do. You can say that there is technology to stop most of this but it's too expensive for most companies to deploy all of it and if they do they don't have the staff to support it. Our best bet here again is better User Awareness Training. We have to constantly update our message to keep it fresh and ensure that the users are hearing us.

  10. Supply Chain Attacks Infecting Consumer Devices (USB Thumb Drives, GPS Systems, Photo Frames, etc.) Distributed by Trusted Organizations
    This is an area that I think will continue to grow as a malware distribution point. As we get more and more "connected" in all we do we are plugging everything we get into our computers. About the only way to ensure that it doesn't happen to you is to have a system that you check all of these devices on before you put it on your main system. Of course you and I may do that but I can assure you that my in-laws won't. I quit using the USB keys that I get at conferences for this very reason. Not that I don't trust the vendor who gave it to me but I don't trust where they got it.

There you have it. My thoughts on this Top 10. I hope you found it helpful.

Conferences and Speaking

Correction - The Birmingham InfraGard meeting is March 11, 2008 not the 4th.

One thing that I really enjoy doing is going to conferences and getting to meet others in IT and Security. Unfortunately I don't get to attend as many as I would like. There are a couple of events here in Atlanta that I'll be attending in the next few weeks that I hope will prove to be fruitful.

The first is SecureAtlanta 2008. This is an ISC2 event that takes place Feb 28th at Georgia Tech. The focus is on Computer forensics. It's pretty high level and is aimed at gaining a better understanding of the why's and legalities of digital forensics than the how to do it. If you are interested in going you can register here. It's free for ISC2 members and ISSA members get a reduced rate.

I'm also attending CSO Perspectives 2008 March 16-18 here in Atlanta. The nice people at CSO Executive Programs were kind enough to allow me to attend as Press. This is a conference that I'm really looking forward to.

Finally March 4th I'm speaking at the Birmingham InfraGard Chapter. I'll be talking about some of the challenges in my current position as Security Officer as well as about the Security Catalysts Community.

I'm hoping to make RSA this year but once again I have a few challenges that I have to overcome to get there. Maybe it will all work out.

If any of you are going to be at any of the events that I'll be at let me know. I'd love to get the chance to meet you.

Tuesday, January 22, 2008

Did I Say That?

Last week I read about the bank robbery where the guy dressed up like a courier and was able to get away with $850,000 and it struck me somewhat funny that I could see that happening. In the past I've worked for a couple of banks and I have no doubt that it could happen pretty easily. Today I saw on BankInfoSecurity.com an article about this and a couple of other Social Engineering attacks that have recently been in the news. Good article that I think you will enjoy reading (site registration is required).

Social engineering has been around for a long, long time. Long before computers. We've all seen the movies or heard the stories about how spies would social engineer people during war to gain secrets that would help their side win the war. This usually involved sex or at least the promise of it.  Social engineering can take many routes. It happens via email, over the phone, face to face, and even by paper. They try to get you to divulge information directly or indirectly. They may try to get you to sign something that gives them access to what they want without your knowledge. They may try to get you to answer questions and then use those answers (recorded) to authorize access to their target.

Sometimes they will use flattery (we all have our vanities), they try to confuse you by asking trick or misleading questions, they may avoid answering your questions w/ ramblings so that you get off track and allow them to go on their way. Sometimes they play on your sympathies by telling you sad stories or they may try to take advantage of your generous nature. Often they just come right out and ask and hope that your are either not paying attention, don't care, or are just too stupid ok stupid is what they are hoping for.

The successful social engineer relies on a toolbox full of tricks that can hack away at the psychological traits we all share. These traits include human desires to be:

  • helpful or friendly
  • competent in our positions
  • trusting of other people
  • advancing our own cause and career
  • attractive to those we admire or desire
  • perceived as a team player
  • avoiding bad consequences for ourselves or others

But bad people are bad people, and they will want to exploit an employee’s goodness. Your employees should routinely verify:

  • 1. With whom they are talking and,
  • 2. That they are entitled to the information they are requesting.

“Your employees should be absolutely sure of this,” Cole notes. They should be encouraged to think carefully and, when in doubt, take a message and check with a supervisor.

The above is a quote from the bankinfosecurity article that helps us to see a little of why social engineering works and what we can do to stop it. This is something that I stress to everyone that I talk to about this. VERIFY, VERIFY, VERIFY the identity of anyone who comes to you asking for information, seeking to work on something in your area, or hoping to find their way somewhere within the building. If they are lost and you don't know them escort them to where they say they need to go after you have verified their identity. Don't just let them continue to wander aimlessly around the building.

The other thing that the article points out that I want to comment on is the rise of "spear phishing" attacks. We need to teach our employees not to blindly answer emails or phone calls from someone just because they say that they are someone important. An email that looks like it came from the CEO (or anyone for that matter) needs to be verified before you blindly send sensitive information to them. I know the idea of teaching your users how to check email headers makes you sick, but it's worth it if it prevents the leak of sensitive data.

The important thing is that we make our users aware of social engineering threats and at the very least teach them to not just blindly give out information. If they are unsure then they need to refer the person to management. Teach them to stop and think before acting.

Monday, January 21, 2008

A little clarity

I've gotten a bit of feedback on my post "Will Malware Kill the Internet" and I want to clarify a few things.

  • I don't really think that malware will kill the internet. As Kurt Wismer put it "malware profiteers need the internet"
  • I won't quit using the internet. I can assure you that I my usage will most likely increase not decrease. Just today I joined Twitter.
  • I may quit using the Internet for financial dealings. Things such as online banking, stocks, etc...
  • For online purchases I'll probably start using one time use credit card numbers.

I do have fears that things will continue to get more dangerous to the average user. I'm not an average user. I'm very careful but as the bad guys get smarter and better at what they do it makes it more difficult for even the most careful of us.

Now on Twitter

I'm not sure why but I have decided to join Twitter. I have a few friends who are one it and thought "Why not?". If I don't like it I can always quit using it and delete my account.

So if you want to follow me via twitter you can check the home page of my blog, go here, or add me to your list of those to follow. I can't promise just how much I'll update. I guess it will depend on what I'm doing and if I remember to add updates.

Thursday, January 17, 2008

Will Malware Kill the Internet?

There was a question posted to the Security Catalyst Community forums earlier asking about our thoughts on the MBR (Master Boot Record) malware that is circulating again. I've mentioned several times in the past that the Internet scares me since it is so easy to drop malware on your computer. The fact that now it is getting more common for Owned sites to be Pwned makes it even worse. Then to hear that security companies and malware researchers are saying that malware increased between 500% and 1000%.

What chance do we have? I hate to sound so "doom and gloom" but you almost hate to think what things will be like this time next year. I've gotten used to not writing checks and doing all of my banking online. Yet, I hate to think of what would happen if my computer was infected by a site that was serving up malware unknowingly. I may have to go back to writing checks.

I'm not normally negative about such things, but this has me worried. Also, not being one to point out a problem w/o offering up solutions I will repeat what all of you probably know. A few things that you can do to reduce the chance of getting malware on your system when surfing the Internet.

  1. Don't use your computer logged in with privileges any higher than "User"
  2. Don't click on links from emails, IM's unless you are 100% sure that they are valid and safe.
  3. When possible type the address in yourself.
  4. Verify links before clicking on them by making sure that they take you where they say they are going to take you. You can do this by putting your mouse over them and checking the browser status bar or by looking at the page source.
  5. Be very wary of shortened links that are created with things such as TinyURL.
  6. Use Firefox or another alternative browser instead of Internet Explorer.
  7. If offered by your browser community use things such as "no script" and "ad blocker".
  8. Stay off of web sites that are known for serving up malware. (Porn, gambling, hacker, etc)

There are lots of other things that you can and should be doing to keep yourself safe. These are just the basics. If you are not aware of what else you can do then I highly recommend that you search for ways to secure your PC or email me and I'll give a more detailed list.

Asking the right questions?

Tom Olzak has a post on his ITToolbox blog "Adventures in Security" about the theft of equipment, including 2 laptops with voter PII, from the Davidson County Tennessee Election Commission Office.

It's obvious that they didn't take "reasonable" security precautions by keeping them in an office that was only minimally secured. The next thing is the fact that the laptops contained PII and especially Social Security Numbers of the voters. I like the question that Tom asks.

The first question the election commission should ask is whether information like social security account numbers is actually required on a laptop.
Too often this simple, basic question is not asked. IMHO this question should be answered before ANY data is put on a mobile device. Actually it should be answered before any data is allowed to be stored on any device, even desktop PC's. If the data is stored anywhere but on devices that are controlled by the IT staff (servers, SANs, etc) then there needs to be a valid "business need". Allowing this because it is easy or keeps the users quiet is not a good reason. Office politics are not a valid reason to allow this.

We have to ask the right questions about what we allow and don't allow the users to do. I get lots of request every week from users who want us to forward their email to their personal devices such as their IPhone, Blackberry, Palm, etc... The first question I ask is "What is the business need for you to get your email on your phone?" Usually they say "So I can get my email while in meetings." That is not a valid business need. Unless your job requires immediate response or action to email then you don't need immediate access to your email in meetings.

The other thing is that if there is a valid business need then at least 2 things should happen. First, your manager should request that your email be sent to your phone. Second, the company should provide you with a email enabled phone. The IT department should not be responsible for supporting personal devices. Not to mention the security and legal implications around allowing company data on personal devices that are not managed by corporate IT.

So, we need to learn what the right questions are and start asking them and requiring that they be answered satisfactorily before we allow users to have control of data.

Wednesday, January 16, 2008

Reacting or Thinking

Yesterday I drove to work which isn't something that I typically do. I like my sanity too much (what little is left) to fight Atlanta traffic on a regular basis. I woke up late and missed the one bus that will get me to the office in a decent amount of time so I decided to work from home for a couple of hours and then drive in after rush hour was over. I had the same thought process for my commute home. Leave before rush hour and work remotely for a couple of hours. So I left early and went to my favorite coffee house and set up office for a while. I let my wife know that I was close by in case something happened and she needed me in an emergency.

Some would say that I was setting myself up for this but about an hour later my cell phone rang and it was her. "You've got to come home right now! Bella drank about 1/4 cup of Hydrogen Peroxide!" CLICK My phone went dead just as I was about to tell her to call Poison Control. So, I packed up quickly and hit the road. I called back to calm my wife down and to have her call Poison Control. When I arrived home my wife informed me that our youngest daughter may have also drank some of the peroxide also.

My wife was rushing around getting ready to take the girls to the doctor and getting upset with me because I wasn't panicking. I knew that peroxide could be dangerous to a child if enough was ingested but I also knew that it would cause them to throw up soon. So I convinced her to wait a while and see what happens. I also asked my daughters about how much they had actually drunk and called Poison Control myself to talk to them. It turns out that the oldest only had a "good swallow" and that the youngest just tasted it. The oldest did throw up and Poison Control told me not to worry.

That got me to thinking about how IS/IT teams often react to emergencies at work. Do they panic and rush into a plan that hasn't been thought out or do they take a deep breath and look at what is going on and try to learn the facts of what has happened and what their options are? If you don't have an incident response plan I can tell you that more than likely people are reacting instead of thinking. Even if you have an IR Plan if it hasn't been tested and the team isn't familiar with the plan and their role in the incident they will usually just do whatever comes to mind first. Sometimes that works well and sometimes not so much. You can't take that chance.

Tuesday, January 15, 2008

Yeah! MySpace

MySpace has been a Security Professionals, Privacy Rights Advocate and Parents nightmare from the beginning. Between the security vulnerabilities, privacy concerns, ease of ruining or tarnishing your reputation and ability for predators and others to harass you there has not been a lot of good to come from MySpace. Of course all of this is my opinion. There those who love MySpace and don't think the issues associated with it are any greater than any other social networking site including business related sites such as Linkedin or ITToolbox. In fact some say that all web sites present equal potential to do harm to you or your computer.

Even though I'm not a big fan of MySpace I have to give them credit for working towards making things more secure and safe for their users. They are working with the Attorney Generals from 49 States and the District of Columbia to come up with a plan that hopefully will be adopted by most other social networking sites. NetworkWorld has a write up on it here. You can read the article and also find the original document to read.

Some of the things that they are doing are:

  • All profiles of users under 16 years old are automatically set to private
  • No one over 18 can view the profile of anyone under 18 (w/o jumping through hoops)
  • No one under 14 can have a MySpace profile
  • Create a database or email addresses that can't have a profile (parents can add their kids to this database)
  • Monitor and remove inappropriate material uploaded
  • Break links to porn sites and other inappropriate sites.
These are all good and well to help make things safer and hopefully guard privacy of our kids. Unfortunately most of these can be easily gotten around.
  • To keep my profile from being set to private automatically I just lie about my age
  • To be able to view and contact those under 16 I just create a profile of someone under 16
  • If I'm 12 I just lie about my age so I can have a profile
  • If my email address is blocked I create a new email address
So, as good as it seems most of this is just fluff designed to make us think that MySpace and other sites are safe for us and our kids. It will encourage deception and create a false sense of security for kids and parents. This will lead to less monitoring by parents and more risky behavior by kids.

Like it or not parental monitoring of sites such as MySpace is the only way to ensure that your kids are safe and not doing things that they shouldn't be doing and to lessen the possibility of them communicating with those they don't need to communicate with.

Sunday, January 13, 2008

PCI Compliance "Why Bother?"

Alex is convinced that PCI compliance has little to do with information security, at least in terms of companies desire to achieve compliance. It's all about the semantics involved in getting past the legal mumbo jumbo involved in meeting each section of the DSS. His hypothesis is based partially on the questions that are asked in the Yahoo! Groups PCI Compliance group. I'm also a member of that group and I would agree that most of the questions are not "how do I become more secure" but "How do I comply with a particular section?" That is to be expected just because of the nature of the group. It is about PCI compliance and not security in general.

I still have to agree with Alex though. Based on the discussions that I've had with others about their PCI experience and also with vendors the quest isn't "more secure" but "just enough". It appears that companies aren't working towards protecting their networks, systems and data but keeping the auditors happy and getting a check mark in all of the check boxes.

This leads me to wonder then do the auditors need to expand their scope beyond the regulations? Of course not. That wouldn't work because they have to have limits on their power and scope. What we need to do is get management out of the compliance mindset and into the security mindset. This will take time and will require that we be able to quantify the benefit of security. Maybe it's building cases based on past breeches of other companies and showing what the associated costs were. The real cost not the cost that the analysts come up with.

What will actually work better (and in concert with) is to show the vulnerabilities that have been remediated by what has been currently done and those that will be remediated when other controls are put into place. Then show real world examples of how not being affected by these issues saved time, money and resources.

We have to build our case built on reality and not on FUD. A good example (going back a few years) is blaster. Lots and lots of companies were hit time and time again with blaster. Just when they thought it was cleaned up a forgotten system was turned on or a laptop user connected to the network and then it was running amuck again. Yet those companies that had been patching regularly were unaffected. A good plan for maintaining AV (especially in emergencies), patching, keeping up with all systems (permanent and mobile), having the right routing and firewall rules in place, etc... would have kept your company blaster free. Yet most companies did not employ these things.

So back to PCI. I'm not a big fan of security by compliance because human nature causes us to do just enough to get by but it does at least open our eyes to the need for more security. It also (hopefully) paves the way for us to realize that check boxes aren't enough and reach for real security. Build your case and sell it.

Friday, January 11, 2008

Is Your Information Security Program Real or Only a Check box?

We all know that in order for a Information Security Program to really be successful it has to have support starting at the top. The IT manager can't decide that a program is needed and start implementing it and expect it to really succeed. That doesn't mean that it won't succeed but the IT manager will have to do a lot of leg work to make it happen.

Often a company will be informed by their Internal Audit Team that they need to have an "official" Information Security Program in order to achieve compliance w/ Regulations X,Y and Z or to continue to pass external audits. Then they will start the process of finding and hiring a Security Officer and hopefully some staff.

This is all good and well but is it effective? An audit or regulatory initiated program does not guarantee management support. So the program is still going to face a huge uphill battle to succeed. If the program does not have the support from the CEO and if that support does not cascade down to the levels below then it doesn't matter that they have a program in place it will be severely hampered. To further make things more difficult the information security team will be aware of the lack of support and it will affect their attitude and therefore their performance.

A good Information Security Officer will work tirelessly to get the needed support of the CEO and the rest of the C-Level Management team. It's not easy to do sometimes and it surely isn't a quick process. You have to start out with doing what you can and then build your case. You have to show the benefit of what has been done and what can be done.

There are a couple of things that are troubling to some Information Security Officers. Things that can severely hamper their ability to win the needed support. The first is when the C-Level team is practically unreachable. When they are too busy to be bothered by lower level staff. When they feel that other things more important than hearing about the need for information security.

The obvious thing to do next would be to start with members of management teams that do have the ear of the C-Level team. Of course that means that you have to have the support of that level of management and often time that is also missing. This can happen in companies that have been around for a while and that have management that is from the "old school". They have the mind set that says "We don't need no stinkin' information security program". Information Security is new and it is the "hot" things right now and therefore it can be threatening to the "old guard". They see it as being something that they got along without for years and now it has been forced on them. So what's next will it become more important than their teams and take away some of their prestige, power and pull with upper management?

These are some pretty big hurdles to overcome in lots of companies. They can frustrate security teams and have to be overcome. So what is the answer? First, the Information Security Management has to keep a positive attitude around the rest of the staff. They have to be diligent in building their case and getting it in front of those that matter. Start small and gain the allies that you can. Use them to gain more allies until you have what you need to present your case. During this phase you have to do two other things. 1) You have to be building your C-Level case so that it is rock solid when you present it. 2) You have to do what you can to secure the environment and get the program going. You man not be able to do all that you want but do what you can.

Keep on keepin' on and success should soon follow.

Wednesday, January 09, 2008

Breaches and Incident Response

This is old, December of last year but Darknet reported about a GFI sponsored study on SMB security (this will open a pdf in a browser window). I don't want to talk about the survey results so much as about the next step. Incident response. What are these companies doing in response to their lack of security? Do they have a security incident response plan in place to give guidance or do they just play it off the cuff. I know a guy who asked his manager if the company had a IR plan and his boss said "Yes, we call you and you investigate it, fix it and keep it from happening again." Not exactly a good plan.

An incident response plan is crucial to your security plan and to the successful investigation, response and (hopefully) recovery from an incident. If a plan is not in place then anything can happen to hamper recovery or even worsen the effect of the incident. There needs to be a clear plan of action so that staff knows what to do and what not to do. The plan also needs to outline when to call in outside help. There are times when an investigation requires more skill and expertise than you have in house. If there is the possibility of legal action then a trained digital forensics expert needs to be called in. He/She will know how to best gather evidence and conduct the investigation so that the evidence will be admissible in court. They understand chain of custody and how to maintain it.

A IR plan will cover all of this and more. Each type of system may require different responses to different attacks. A one-size-fits-all approach to IR will not do it unless you are a very small company with a very limited IT infrastructure. I know that for my company I have a generic plan for non-critical systems and then it gets specific for certain systems. My ERP system requires a different plan of action than other non-mission critical systems.

The last thing I want to say about your IR plan is that they are like all policies and plans. They are living and they need to be reviewed regularly and updated. They need to be tested and re-tested. You can write it and file it.

Tuesday, January 08, 2008

The Importance of Good Change Control Practices

A while back one of our Server Admins logged into a server that runs our SNMP management application. Immediately he was hit with an IP address conflict message. Some other machine had taken his IP address. He was on his toes and wrote down all the information that the message gave him (system name and MAC address). Then he sent out an email to the technology group asking who was responsible for this system and no one responded.

Needless to say it raised a red flag in my mind. We started an internal investigation to find out where the system was, what it was, what it was doing, etc... I immediately ran some scans on the system to find out what I could about it. Everything came back blank. NMap and several other scanners all reported that it couldn't tell anything about the OS because the fingerprint matched too many different things. The MAC address was reporting back as all 0's (00:00:00:00:00:00). Finally Nessus was able to tell me that it thought it was a Samba system. A quick check of the team determined that no one here was even familiar w/ Samba much less had deployed one.

Now we decided to shut down the port that it was connected to and hunt it down. Of course the cable had to be traced and it was a mess. Once we finally found the system it turned out to be an ILO port on a DB server. One of the very DB teams that we had asked about it and they denied knowing anything. That is another topic for another post.

Now we have a change control process that works pretty well. It's still young and his not fully automated yet but if the proper procedures had been followed we could have eliminated this whole fiasco. They could have had a free IP assigned for them to use and lots of time and manpower could have been saved. Not to mention the gray hairs that it added to my head. It's a good thing that I'm a blond so they don't show (no blond jokes allowed). :)

So please follow the proper procedures and policies that your company has in place. They are there for a reason and it's not all about making the auditors happy.

Monday, January 07, 2008

Where's Andy?

I'm still here. It's been an odd year so far. Most of my work life isn't worth blogging about and the parts that are I can't talk about. Nothing in the news has grabbed my attention so I'm keeping quite. I doubt it will continue for long and when I get started again you may long for my days of silence. :)

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.