Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Tuesday, June 4, 2013

Slideshow: A Practical Example to Using SABSA Extended Security in Depth Strategy


A Practical Example to Using SABSA Extended Security-in-Depth Strategy from Allen Baranov

Following on from my last post, this is a practical way of using the extensions I proposed for the Security in Depth part of SABSA.

It gives an example of creating a Firewall Standard using the extensions.

I found this to be easier to do with a presentation than explaining it on the Blog so there you go.

Please let me know if you have any comments on this process.

Also, note that I am still looking for a job preferably in Information Security Management, Compliance or Information Security Architecture. Have a look at my linkedin profile for more information - http://au.linkedin.com/in/allenbaranov

- Allen Baranov

Thursday, May 5, 2011

Miscellaneous Ramblings - Irony, Security Summit etc

I've been doing a lot of thinking recently about the last year. I basically run my professional year from ITWeb Summit to ITWeb Summit and around this time I think back over the last year about what has changed and what is new.

I find that InfoSec is cyclical and this year is the unexciting one. Last year we were dealing with iPads and their ilk and Cloud and SaaS and all that good stuff was starting to hit us. This year - we are dealing with iPads and their ilk and Cloud and SaaS and all that good stuff is starting to hit us - again.

I'm still looking very forward to the Summit and I always leave with at least one very worthwhile thought that will determine my next year. The international speakers are most worthwhile to see as they bring a perspective that we, at the bottom part of Africa don't usually get. The Internet makes the World smaller but seeing someone talk is so much more useful (powerful) than reading.

While looking through my blog list for some juicy nuggets for my talk I noticed two bits of irony that came through -

1. The DBIR was published with the first line mentioning how it seems that the hacker community has gone more underground and less big hacks with large amounts of data being stolen. Boom, a couple of weeks later and Sony is hit by just one such hack.
2. Brian Krebs publishes how it may be overkill but it is a good idea to use a non-Windows system to do online banking especially for small businesses because there are no trojans aimed at these systems. His next post is all about how someone is developing a trojan crafting tool aimed at these systems.

My speech this year is finally completed (albeit in draft for now) and is a mostly updated speech that I presented 2 years ago at a smaller conference. It is still very relevant and I will enjoy presenting my insights to a larger audience.

Please look for my talk in the program and support me if you are attending.

I have committed to the organisers to post at least 1 blog post per day of the event and 1 to sum up what good stuff I got out of the conference so look out for these.

Btw, Brian Krebs is at Krebs On Security , the DBIR is at Verizon Business Security Blog and the of course - ITWeb Security Summit 2011 . Reporting on Sony's Playstation Network hack is all over the Internet.

Friday, April 1, 2011

I cheated....

[... at Sudoku]

When I first started with Sudoku puzzles my interest was "how do I reduce these to an algorithm?" I wrote some code that would solve the puzzles and then started to try do it in my head.

I got better and better and the simpler puzzles started to get very boring and the harder ones became easy. Then, recently I got hold of an advanced Sudoku book and I was hooked once again.

But there was one puzzle that I just couldn't do. I would stare at the thing like it was a novel I could not put down. Hours went by and I was starting to see blocks in my sleep. So I decided to re-visit some of the online Sudoku solver sites I had used to help build my Sudoku solver. (Why not use my own solver? Its on a disk, somewhere!)

I found a good site that shows "hints" (because after all, I want to know how to solve it. If I wanted the answer, I could have just flipped to the end of the book but then I would have learnt nothing from the experience)

I typed the puzzle into the site and *boom*... a hint... yay. I was well on my way to solving the puzzle. I actually just really wanted one number and the rest all fell into place.

[The actual point of this long blog is here ;) -] Once I knew what the next number of the Sudoku was then I could work out how I should have gotten to it. But the PC showed me how it would have gotten to it and it was a totally different method altogether. Its obvious but not always on top of our mind, Computers and Humans inhabit the same world but our world view is very different.

This is why Spam gets through. This is why passwords don't work. This is why brute force does work. This is why Web-filters don't work.This is why DLP is partially effective.

Using technical controls for human created problems is what Information Security is all about. Its also something doomed to fail. Whats better? I wish I knew.

Friday, January 14, 2011

The CIA, the lead box at the bottom of the ocean and the sacred cow.

[Where does Availability sit?]

So, the first thing you'll learn when doing Networking is the OSI stack even though everyone uses TCP/IP which doesn't fit neatly into the OSI concept. The first thing you'll learn in InfoSec is the CIA triangle. This is our sacred cow even though we don't really work towards it. Or do we? Should we?

I really respect the guys at Securosis and admire the way they dust off the sacred cows and relook at them arguing first that availability is not for InfoSec to bother with, then that it is most important.


If you speak to those that know me professionally, you'll know my feeling of how Information Security should treat The A. I sit in the IT building and my favorite saying is "everyone else in the building is making sure availability happens. I look after the C and the I"

The problem is that protecting Availability is very broad. It is actually easier to define the opposite - lack of availability:

If a server disk crashes who gets called in? Its not me.
If a service stops on a server?No me.  
If the Firewall blocks a business website? Yep, me. 
If a virus crashes the mail server or slow it down? Me.

So, I do manage availability to a point but not all of it. And, in fact I seem to manage more Availability than I should. The point is that Availability is an easy sell. IT is full of it. Check you agreements with vendors - they all have something like "99.9...% uptime" SLAs. There are no "99.9...% integrity" or "99.9..% confidential docs will not be moved". Availability can be measured - its there or it is not. Integrity and Confidentiality - not so much. Another favourite phrase of mine is "The A in SLA stands (not for agreement but stands) for availability - where is the SLI and SLC?"

The problem is that because InfoSec is traditionally based in IT - some of the Need For Availability (NFA?) seeps into our area. The tools we find easiest to sell to business - firewalls, IPS, antivirus all are there to primarily protect availability. Tools like web-filters are also very easy to sell because they stop abuse of network (think availability) and time (same). Tools like DLP are a tougher sell because they don't touch availability (and can cause issues there). Backups and DR have been the cause for some really bad C and I episodes. Yet every company does them - availability. This is not to say that backups and the other software we have are bad. Backups are essential for one but availability is king. When last did you audit all of the excel documents that people use to make business decisions for integrity?

The thing is that that C and I are opposed to A. The safest network is one that is not connected to the Internet but what use that? The way to properly secure a document is to put it in a safe, cover the safe in lead and then in concrete, chain it up for good measure and then dump it at the bottom of the ocean. But, again, what use is that? So, there is an arm wrestle between C and I on one side and A on the other and that is a good thing.

IT will always fight on the side of the "A" and so should InfoSec but we also have to fight for the C and I and ultimately get a good balance between all three. 

Monday, June 21, 2010

Quick Thought: Information Classification Like Creative Commons

[Stealing the CC Ease of Use Icons for Info Classification]

When something is complicated then it usually is quite wrong. I learnt this lesson with Firewall Rules. Usually when something was twisted around and not easy to understand it was because the Firewall was being used for a purpose ti was not designed for.

Information Classification is usually pretty easy to understand. It is logical. There is stuff you want the public to know about, stuff you don't mind them knowing about, stuff that you don't quite want them to know about and stuff they most certainly shouldn't know about.

There is also stuff that can't be shared outside of the company with out breaking the law or some "governance" and stuff that can't be shared overseas.

Finally, there is stuff that shouldn't be shared outside of a department such as "strategy stuff" or "HR stuff".

What you call these is just semantics and what you do to keep these where they should be is where the fun comes in.

Information Security is accused of being overly complex and it really shouldn't be. Much like copyright is (generally) complex. So, the good people of the Creative Commons worked out just how to separate the tricky-to-understand bits from the easy-to-understand stuff and get people using CC without having to read law at Harvard or some such. You choose the pretty pictures that show you what you want and voila.

So, can we do the same with Information Classification?

Monday, July 20, 2009

If you only read one article on Information Security...

[... this is it]

Actually, this is a bit unfair because after reading this one article, you'll be compelled to read more.

Richard Bejtlich's article sums this up nicely. He links to another blog post by Verizon Business.

I have some issues with Verizon Business's annual report but it is probably the most important document on Information Security to be published.

My one criticism of the Verizon Business Breach Report is that it shows credit card data to be more at risk than anything else. I was never sure if this is because it is easier to abuse than other data (such as Intellectual Property) or is just easier to detect when it is abused. According to the article, it is the latter. IP is leaving our companies, we just don't know it.

When a whole bunch of credit card information is stolen then the banks track which credit cards are abused. They are good at this and they slowly work out where all the credit cards were used together. So, if 5 credit cards were all used at a specific shop and then end up being abused that points to that shop having had an information breach. In the case of IP, there is no bank tracking abuse so you have to track it yourself... and companies are really bad at that.

The other point which I found quite amazing is that very few times when a PC is lost, is it used for fraud. End point encryption is cheap and easy to apply so it should be done, but most information is lost, not through assets being lost but through network attacks.

Friday, May 22, 2009

Happy Birthday Important Blog Post

I just realised that its been a year since I posted a blog post - Information-centric Security is Dead.

Ironically enough, next week I am presenting at a Security Summit on, well, Information-centric Security.

The article, I believe is one of my most important ones. Information-centric security is not really dead. But it is a stepping stone. Read my last blog post and the one linked above together and you will see what I believe is the most exciting and important development in our industry, probably since Firewalls.

If you aren't busy next week Tuesday then maybe come see me talk. It'll be fun, I'll make jokes. Promise.

NAC and DLP - lets break them and put them together again

[NAC and DLP can be so effective together, they just need to be trimmed down]

So, Art Coviello's company (RSA) arranges the biggest and certainly the most important Information Security conference. And so he gets to give the Keynote. But, to his credit he is either brilliant or has brilliant people around him because his keynote is always interesting, ground breaking even. I believe that RSA certainly has the best vision in terms of Security.

But enough of that... lets get back to the topic of this blog. (Btw, if anyone from RSA is reading this - contact me for my details to send whatever SWAG you have to give me for the above... cash is best ;)...

Coviello's main points (in my opinion) are that Security tools are point solutions and don't play nicely together. This needs to change and they need to be more open. Following that, they can then start to specialize.

I guess this is sortof what Check Point were trying to achieve with OPSEC. You have "smart machines" that understand policy.

Think - Firewall Policy server, Anti virus server, IPS. Traffic is sent to these machines and they work out what needs to happen to the traffic - allow, block, log, etc. This is communicated to a dumb device like a firewall node which just follows orders.

Coviello names the functions as follows:

  • PolicyManagement
  • PolicyDecision points
  • PolicyEnforcement
  • PolicyAudit
So, assuming I am reading a file on how my company makes its secret widgets. I download the file from the server and the following information is available to the different systems around me:

My username,
The time,
My location by network
My location by GPS (not usually but why not?)
My PC's latest patches and antivirus level (From NAC)
MY PC's installed software
My PC's hardware (including USB devices)
Any IPS triggers

This information is in many separate databases that don't really interact but imagine if they did.

It would allow the system to make a decision to allow/block based on any of the above conditions or all of the above together. So, if I try to access a file from my desk but it is 1AM then maybe I am denied the file. If my antivirus is old then tough, no files are available.

Every piece of network equipment (including workstations and servers) can be PolicyEnforcement machines. Which means that if I try to access a file that I'm not supposed to then the Server will block the connection, the switch will block it too and my laptop will block it too. This may be over-protection, but it may not be.

So, you may have a DLP server and a NAC server and a centrally controlled personal firewall policy but really the enforcement for all of these is "Allow" or "Block" and network switches can do that already. So, all your systems need to talk and when they all agree on "Allow" then the traffic flows.

Exciting times ahead.

Monday, May 18, 2009

ITWeb Security Conference

[Our heroic writer gets interviewed by the Press and gets ready to knock some socks off at ITWeb Security Summit]

In the run-up to the ITWeb Security Summit, I have been interviewed about my Information-centric Security speech.

I'm looking forward to the conference. It will the first time that I am presenting and I think that this year is going to be great. There are a lot of new technologies and concepts that are going to make this year exciting.

At work I have been working hard at planning my next year and I am very excited about that too.

There is some Information-centric Security in there but lots of other stuff. It is going to be a busy year.

Thursday, April 30, 2009

Sneaky Twitter Tweeting

Ok, so I was bored. And then I saw the challenge -

It came, ironically enough via Twitter.

It is a Twitter client that looks like Excel. If you boss walks past then he doesn't spot you wasting time.

Nice idea but lets see if we can take it further.

Twitter inside Excel. No tricks, no fake screens. Just the real deal. Create one sheet for work and one for play.

Ok, so how?

Step 1
Open Excel

Step 2
Click "data" then "xml" then "import" and put in the following URL:

http://twitter.com/statuses/friends_timeline/[userid].rss

UserId is your userID which you can get by logging into twitter, going to twitter.com and hovering your mouse over the RSS logo on the right.

Step 3
It will ask you for your twitter username and password (unless you are logged in) and pull the information into excel. As a bonus you can right click, select XML and refresh the information.

Step 4
Different versions of Excel will work slightly differently.

Note that the information doesn't just magically appear in Excel, it is loaded via your browser (running in the background with no window) so if your employer has a proxy server (they should) with logging on (it should be) and they have suspicions about you (I hope not) they can still see your twitter browsing even if your boss can't see it by glancing over your shoulder.

Thank you Dominic for the challenge.

PS. using the Twitter API, it should be possible to post to twitter and see DMs and @ messages and your own status etc etc but I didn't feel like playing with it that much. Maybe I will. At the moment, you only get your personal stream, unsorted. In Excel.

Friday, April 17, 2009

Analogy vs analogy. Let the games begin!

[Enforcement or Awareness? Whats best?]

Since my posting about how seatbelt legislation improved the use of seatbelts was very popular, I like the idea of traffic rules being used as an analogy for Information Security. So it was quite exciting to see some Gartner thinkers copying me (obviously they read my blog religiously, debate it at length and then copy it. I am that good).

So, the first one was about traffic light cameras causing more accidents than stopping them. And how the government won't remove them because they make some good money from them. Enough said there. The other was about how traffic speed signs have been around for years but not very effective but speed cameras are very effective.

Reading between the lines, it seems to me that the article puts down the idea of awareness in total as being not effective. Which is fair enough. In Information Security you can preach for hours but unless you actually capture the hearts of those in the room then you are lost. They will not listen. One way to go is to use a combination of things including awareness and enforcment.

Taking Then you've won.

Monday, April 6, 2009

The Issue With Cloud Computing

I really like the way The Hoff puts things sometimes:
We’re told we shouldn’t have to worry about the underlying infrastructure with Cloud, that it’s abstracted and someone else’s problem to manage…until it’s not.
I think that sums up in one line the problem with Cloud Computing. You are essentially making your job easier by dumping the responsibility for Security (and Availability) onto someone else's plate. Which is fine until they post a note saying "Sorry" and you are left with no service.

Or worse - data that has gone off somewhere that you don't want it going!

The Conficker Eye Chart - Really!

This Conficker Eye Chart is brilliant!

Information Security can get a bit drab and boring. Especially when the auditors start poking around and you are arguing about the minutiae of your security policy. And especially when you look at the designers with their Apples and the programmers pumping out new Web 2.0 frontiers.

But sometimes, someone out there comes up with something so silly but effective that it just has to be blogged about.

The Conficker Eye Chart is simple - it tries to download images from Sites that Conficker blocks. If you can't see them then it could be that you are infected.

But you really have to see it. I wish I had come up with that one!

Monday, March 23, 2009

Scareware

My mother-in-law runs a small craft shop (with lovely craft products, sold very cheaply and with good friendly advice ;) and her business relies a lot on the Internet. Queries come in via email, she has an online store and a website.

Yesterday she got sent an email telling her that due to some unsavory use of the Internet, she would be disconnected. The email had an attachment which was (pretending to be) some sort of log of her activities.

Now, the more savvy of us may think - scam. But she is not "the more savvy of us" and this email freaked her out. She imagined her Internet presence being shut down. And, of course, she was always careful about her browsing.

Fortunately for her, her ISP's antivirus recognised the attachment as being a trojan and deleted it. But she may have been stressed into opening the attachment to see what the accusations were.

I have written this post to tell people about this type of trickery and to just remind those out there that are maybe not so Internet savvy - NEVER open attachments that you are not expecting. If you are concerned about your Internet connectivity being taken away then contact your ISP directly.

And always have an up-to-date antivirus.

The Victorian Police Have Issues (Ironic Post)

[The irony in this article is so lovely, it has to be shared]

The Age newspaper reports that a leaked memo from inside the Victorian Police (Australia) department says that their IT systems are risky.

The article lists a whole bunch of "Availability" risks such as backups failing and the like. It doesn't really go into details about how information security can be compromised although it does list the kind of information that the police have on hand which is very confidential.

The wonderful part is that the article says: 'A police spokeswoman said the force believed its IT applications were secure and there was a "full back-up regime across all our services as well as disaster recovery for core applications".'

My question is ... if the Victorian Police are secure, as they claim to be, how did a highly confidential memo with the ability to cause massive amounts of embarrassment to the department get leaked to the press?

Friday, March 20, 2009

More Fame... Where is the Fortune?!

[The Highly Esteemed Author Presents At ITWeb Conference]

I applied and my presentation was accepted to be presented at the ITWeb Security Conference.

If you have read my Blog posts then there will be very little new information in the presentation. However, I do tie my thoughts together in one big "this is where you should be going" session. It will be on the management track so I should be expecting some high level thinkers and, yes, the presentation is very high level.

Even though I am now involved, I highly recommend this conference for all that can make it. I missed out in 2007 but the twice that I attended (2006, 2008), I certainly came out with some mind blowing insights.

I also highly recommend that management don't have the mindset: "we need to think about this security stuff" and then send their IT Guy but rather that they make the effort to send someone who can make business decisions. Even better - send both. That is why there is a management stream and a technical stream.

The reason I promote this event (and I really don't get commission) is that it is the only major event in South Africa with an Information Security focus. I believe that management at any company should make an effort to stay in touch with what is happening in Information Security.

Unless you don't use information or none of your information is private.

Tuesday, March 3, 2009

Pepsi is not desperate.

[The other side to my prediction. Why I still believe it will happen but why it hasn't happened just yet.]

As per usual, the Securosis guys are smack bang on the pulse and deliver some interesting reading.

The take-away quote from the article is this:

[J] ust because the employee walked out with the information does not necessarily mean that the company suffered a loss. That data has to be used in some manner that affects the value of the company, or results in lost sales.
The Securosis blog entry links to an article about a Coke employee trying to sell Intellectual Property (IP) to Pepsi. Pepsi said "no thanks" and helped Coke who tipped off the FBI who made 3 arrests.

My feeling is that cyber criminals (hackers) are getting desperate. The average price of a credit card on the black market has dropped to the point where it is not worthwhile trading in credit cards anymore. The new currency will be intellectual property. The problem with IP as opposed to credit card data is that credit cards are easy - there are any number of buyers and the consequences are still not too harsh.

Intellectual Property really would only benefit the competitors of a company so there are not so many buyers for the information. And that company would need to act on the information that they get, otherwise it is not worthwhile.

The Coke/Pepsi example is not very technical - it sounds like the employee stuffed files in her bag but it is still a breach. The thing is that there are few companies that would benefit from Coke's private documents. There are fewer that would take the risk in acting on stolen information. Pepsi was not interested in taking the chance.

I think that my prediction still stands but it requires a desperate employee who has access to valuable information. And a desperate competitor that will use the information offered to them. There will probably be a middle-man orchestrating the transaction. Big money will be paid out for the information and the original company will suffer in some way - market share, share price, loss of tender, etc.

I don't think it will be widespread but it may get ISOs around the world thinking "that could be my CEO with egg on his face apologizing to shareholders about losing IP"

Monday, February 2, 2009

Sometimes a piece of bread is just a piece of bread

I really like Andy the IT Guy but sometimes he goes overboard...

Andy the IT Guy is, of all the bloggers I read, the most practical. He isn't an analyst like the Securosis guys or a salesperson like most of the others. Or a ninja-type like the Hoff. He is a hands-on security person. Like me.

I find sometimes, I will be sitting in the traffic or walking down the street or shopping or whatever and thinking "there must be some Information Security parallel to this" and I get ready to blog about whatever it was. You can equate just about everything with Information Security. I'm sure that bloggers of all types go around thinking "...ooo..must blog about that..". There should be a support group. Maybe there is. Maybe it has a blog. I hope not.

By the way, Andy's advice about Information becoming "mixed" is really good advice and all companies should take note. I am about to start an Information Classification program and I shudder to think what it is that I will find. If everything was done right from the beginning ("pffft...") then it would be a simple thing to perform.

Andy, I totally agree with your observation, mate. But, sometimes just switch off and enjoy your breakfast. Even if it does taste slightly generic. I could use my own advice too. Maybe we should just give in to the addiction...

Now, what do fishpaste sandwiches have to do with Information Security? They smell funny but they are really good for you? Hmmmm....

Wednesday, December 31, 2008

Happy 2009

In what will most likely be my last posting for 2008, here is a bit of advice for all.

I read somewhere that news is never really all that useful. Its interesting. But its not useful. The stuff that you need to know about to go about your daily life is not going to make news.

To get some more perspective on this, I highly recommend that you visit The Onion online newspaper and browse a bit especially at the "Area" reports. (It is humour and is intended for 18+)

One of the interesting news stories of 2008 that I can think of the Dan Kamisky DNS issue that made headlines for all sorts of reasons. DLP made headlines. TJX made headlines.

What is more interesting is what didn't.

Here are some bits of news that you won't see:

"Company patches all servers"
"Awareness given at Company. Stronger passwords result"
"Good user management led to less options for Hackers"
"Antivirus updated led to viruses being blocked"

What did made the headlines today (thanks to Amrit and Dominic for alerting me to this... everyone will be talking about it soon) is the attack on MD5 certificates that makes trusting Web Certificates less of a good idea. The information is here, but this is a big deal so expect this to make the news.

The thing is, that this yields big rewards for the hackers but is also a lot of work. Social engineering methods such as bogus email, phishing, fake antivirus etc are so much easier to do and have big enough rewards as it is. So too do worms and the like that attack old vulnerabilities that should already be patched.

My though for the year is thus:

Hackers are mostly successful by exploiting the boring holes and really do not have to work hard at all. By using tools that are already available such as Firewalls, IPS, Antivirus and doing the boring bits such as choosing strong passwords, updating patches, updating antivirus patterns and being aware at what mails we should not open - we win 90% of the battle already.

I think next year will be very very interesting for us. I hope everyone reading this has a great 2009!

Tuesday, December 23, 2008

Merry Christmas, Happy Hanukkah, etc

In typical Security Thoughts style, here is an Information Security story that relates to the holidays.

It seems that, in Germany, a company sent a Stollen, which is a traditional German Christmas cake to a newspaper via a courier company. Two subcontractors decided that they wanted the cake so they took it and replaced it with another parcel.

This parcel just happened to be confidential data with banking transaction details and it managed to find its way to the newspaper in place of the cake. Obviously, the newspaper was happy with their Christmas present and printed the story. The bank was not so happy.

I think that the theme for 2009 will be "Third Party Security" but in the mean time I wish you all a pleasant holiday and please be responsible if you decide to have a drink or two.