Showing posts with label Firewalls. Show all posts
Showing posts with label Firewalls. Show all posts

Tuesday, June 4, 2013

Slideshow: A Practical Example to Using SABSA Extended Security in Depth Strategy


A Practical Example to Using SABSA Extended Security-in-Depth Strategy from Allen Baranov

Following on from my last post, this is a practical way of using the extensions I proposed for the Security in Depth part of SABSA.

It gives an example of creating a Firewall Standard using the extensions.

I found this to be easier to do with a presentation than explaining it on the Blog so there you go.

Please let me know if you have any comments on this process.

Also, note that I am still looking for a job preferably in Information Security Management, Compliance or Information Security Architecture. Have a look at my linkedin profile for more information - http://au.linkedin.com/in/allenbaranov

- Allen Baranov

Tuesday, June 2, 2009

Quick Tought - The Pelzman Effect

I was reading about Ralph Nader on Wikipedia, and came across something called the Pelzman Effect.

This is something I see a lot and I spend a lot of time in my induction meetings trying to work against.

The Pelzman Effect (named after Sam Peltzman, a professor of Economics) is when you are aware of safety controls.

Knowing that you are fairly well protected, you take more risky behavior. This essentially makes all the controls less valuable, worthless or actually creates more risk than if the controls were not in place.

Two of these controls (Firewalls and Antivirus) are important but they do not cover 100% of all risk and users need to know that they must not assume total protection but need to take some of their own precautions.

Backups are even worse.. they are not magical but they are assumed to be.

Wednesday, December 31, 2008

Happy 2009

In what will most likely be my last posting for 2008, here is a bit of advice for all.

I read somewhere that news is never really all that useful. Its interesting. But its not useful. The stuff that you need to know about to go about your daily life is not going to make news.

To get some more perspective on this, I highly recommend that you visit The Onion online newspaper and browse a bit especially at the "Area" reports. (It is humour and is intended for 18+)

One of the interesting news stories of 2008 that I can think of the Dan Kamisky DNS issue that made headlines for all sorts of reasons. DLP made headlines. TJX made headlines.

What is more interesting is what didn't.

Here are some bits of news that you won't see:

"Company patches all servers"
"Awareness given at Company. Stronger passwords result"
"Good user management led to less options for Hackers"
"Antivirus updated led to viruses being blocked"

What did made the headlines today (thanks to Amrit and Dominic for alerting me to this... everyone will be talking about it soon) is the attack on MD5 certificates that makes trusting Web Certificates less of a good idea. The information is here, but this is a big deal so expect this to make the news.

The thing is, that this yields big rewards for the hackers but is also a lot of work. Social engineering methods such as bogus email, phishing, fake antivirus etc are so much easier to do and have big enough rewards as it is. So too do worms and the like that attack old vulnerabilities that should already be patched.

My though for the year is thus:

Hackers are mostly successful by exploiting the boring holes and really do not have to work hard at all. By using tools that are already available such as Firewalls, IPS, Antivirus and doing the boring bits such as choosing strong passwords, updating patches, updating antivirus patterns and being aware at what mails we should not open - we win 90% of the battle already.

I think next year will be very very interesting for us. I hope everyone reading this has a great 2009!

Friday, October 5, 2007

The Conscious Competence Security Model

A while back I learned of the Conscious Competence Learning Model (we'll get to exactly what it is) and I knew I had to blog about it and then I forgot but I was reminded of it again when I read this article by Richard Bejtlich.

He in turn is discussing CIO Magazine's Fifth Annual Global State of Information Security which is worth a read especially if you are in the Information Security field.

It was these two quotes that reminded me of the Learning Model -

You're undergoing a shift from a somewhat blissful ignorance of the serious flaws in computer security to a largely depressing knowledge of them.
and

As [Ron] Woerner puts it, "When you gain visibility, you see that you can't see all the potential problems. You see that maybe you were spending money securing the wrong things. You see that a good employee with good intentions who wants to take work home can become a security incident when he loses his laptop or puts data on his home computer. There's so much out there, it's overwhelming."
This sounds very depressing and sounds like we should just throw in the towel but I think it is more positive then that.

The Conscious Competence Learning Model has many different names and versions but the concept is as follows:

  1. At first you are blissfully unaware of how much you don't know.
  2. Then you start learning and get overwhelmed once you learn just how much you don't know.
  3. Then you learn some more and you struggle along learning all the time.
  4. Then you become a professional and know everything without having to think very much.


My Information Security spin on this is:
  1. At first you have firewalls and antivirus and you feel safe. You don't know what is really happening on your network but you are sure that everything is fine.
  2. Then, for some reason you take Information Security seriously and spend some more money on what is really important. You realise just how unsafe your network and information really is.
  3. You work at it, struggling all the time to get a proper plan in place and back it up with all the good stuff you can such as technological solutions, training, awareness, processes etc all the time refining and updating the process to get more secure. At the same time new projects have security built in from day 1. All the time you are finding new issues to fix but these are getting less and less and you know that you are getting more secure.
  4. All your systems are secured as much as they need to be. All new threats have action plans in place. New projects, users, systems all have procedures that make them as secure as possible. All risks are dealt with in the way Business expects them to be. There may be incidents but there are no surprises.
From the CSO article and Richard's blog post I think that most companies in the survey are at step number 2 moving (hopefully) to step 3.

My feeling is that most companies are at stage 1 with a resistance to move to stage 2. Companies that are at stage 1 would (probably) not be a part of the CSO magazine community. I think that very few companies would be at step 4 but many companies would be battling along at step 3.

Obviously the size of the company and what sector the company is in would help determine what step they are on. As well as the amount of leadership the Top Brass have and the enthusiasm of the Security Department.

Friday, September 21, 2007

Seven Habits of Highly Effective Security Plans [Part 3]

In this post we deal with habit 1: Be Proactive

Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]

This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.

Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.

It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.

Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.

IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.

Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.

It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.

I think this is lot more productive than playing each part of the business off against each other.

Monday, April 23, 2007

Allen Baranov is alive, well and living a State of Fear (Part One)

"Is something wrong, she said
Well of course there is
You're still alive, she said
Oh, and do I deserve to be?
Is that the question?" - Pearl Jam, "Alive"


Yes. I am still about.

The last few weeks have been mad. My folks are visiting from Australia, blogger has been doing funny things, work has been hectic and I'm trying to work out what to do with my life. Lots of excuses why I have not posted in a long while...however...

... I am reading "State of Fear" by Michael Crichton. It is a really good book and worth reading as are all his books. The basic story behind it (besides all the fast paced action you should expect from his novels) is that Global Warming is junk invented by Earth Rights groups to get money that should go to starving kids in Africa and not some theory that may or may not be true.

So, what does this mean for us security professionals? This IS (sorta) an info-sec blog.

Well, he takes it further near the end of the book. He says that there are always issues facing mankind. The press and interested parties (in each case) just blow them up for their own gain. Interested parties so that they can get funding and the press so they can sell their media.

I know I get excited every time some bit of security news makes the papers (sometimes front page) even if once I dissect it, it is really some arbitrary news. It puts what I do in the spotlight and I can get a warm fuzzy feeling. I can also (maybe one day) tell people exactly what I do instead of "I'm in IT". And maybe more companies will take Information Security more seriously and spend more and some of that will trickle down into my usually empty pockets.

Bruce Schneier seems to think about this issue a lot and I like the title of his book "Beyond Fear" because that sums up where I think we should be going. Manage your systems correctly and don't worry.

Still, there are the Fear-mongers - buy security (and then even more) because you may go to jail if you don't secure your company down to the last little screw.

There are also...hmmm... the naive ones... who believe everything can be put into black and white. I always thought I was missing something because even in all my (too many) years in security I have no idea what numbers to use in a risk assessment.

Recently I posted to a security list asking "is a firewall really necessary?" and one answer was "do a risk assessment". I wasn't talking about an external firewall but the answer came from someone who didn't know that.

I can't see how my time would be best spent trying to (research/invent) numbers to prove that a firewall is needed. Its just plain sense (at least on the border) - I think.

Maybe there is a fine line between State of Fear and State of Risk. I hope that I am there.

Thursday, March 8, 2007

Rushing to Catch up with the 70s (Part 3) - The Big Picture

This posting is in response to Andy the IT guy's blog posting which in turn is about a Dark Reading article.

In summary the article blames all the problems we have today on the way the Internet was designed.

In my first (serious) post on my blog I discuss how secure we were back in the 70s (well..not me..I was still a kid) because computers were designed to not trust their users. With the advent of DOS computers were all trusting and it has taken time to get back to how it was in the 70's. We are still on our way.

Add the two together and you get - strict, secure PCs and open networks. Sounds good to me.

Maybe one day PCs will be so tight that they can sit out on the Internet and we will not have to worry about them. Maybe we will be able to know who is connecting to our network and be happy in the knowledge that their PC can't possibly be in dire need of patches. Maybe viruses will become a thing of the past.

Social engineering will always be with us until we can build better people. Maybe our kids are already learning. We grew up in a world where you don't talk to strangers, they are growing up in one where you don't blog with them or instant message them. The wolf is still there, he is just online. And maybe this will make our kids more infosec aware.

I don't see us ever getting rid of Firewalls but it would be nice if the work of keeping PCs safe was done on the boxes and not on the network. Like it was in the 70s.