Friday, May 22, 2009

NAC and DLP - lets break them and put them together again

[NAC and DLP can be so effective together, they just need to be trimmed down]

So, Art Coviello's company (RSA) arranges the biggest and certainly the most important Information Security conference. And so he gets to give the Keynote. But, to his credit he is either brilliant or has brilliant people around him because his keynote is always interesting, ground breaking even. I believe that RSA certainly has the best vision in terms of Security.

But enough of that... lets get back to the topic of this blog. (Btw, if anyone from RSA is reading this - contact me for my details to send whatever SWAG you have to give me for the above... cash is best ;)...

Coviello's main points (in my opinion) are that Security tools are point solutions and don't play nicely together. This needs to change and they need to be more open. Following that, they can then start to specialize.

I guess this is sortof what Check Point were trying to achieve with OPSEC. You have "smart machines" that understand policy.

Think - Firewall Policy server, Anti virus server, IPS. Traffic is sent to these machines and they work out what needs to happen to the traffic - allow, block, log, etc. This is communicated to a dumb device like a firewall node which just follows orders.

Coviello names the functions as follows:

  • PolicyManagement
  • PolicyDecision points
  • PolicyEnforcement
  • PolicyAudit
So, assuming I am reading a file on how my company makes its secret widgets. I download the file from the server and the following information is available to the different systems around me:

My username,
The time,
My location by network
My location by GPS (not usually but why not?)
My PC's latest patches and antivirus level (From NAC)
MY PC's installed software
My PC's hardware (including USB devices)
Any IPS triggers

This information is in many separate databases that don't really interact but imagine if they did.

It would allow the system to make a decision to allow/block based on any of the above conditions or all of the above together. So, if I try to access a file from my desk but it is 1AM then maybe I am denied the file. If my antivirus is old then tough, no files are available.

Every piece of network equipment (including workstations and servers) can be PolicyEnforcement machines. Which means that if I try to access a file that I'm not supposed to then the Server will block the connection, the switch will block it too and my laptop will block it too. This may be over-protection, but it may not be.

So, you may have a DLP server and a NAC server and a centrally controlled personal firewall policy but really the enforcement for all of these is "Allow" or "Block" and network switches can do that already. So, all your systems need to talk and when they all agree on "Allow" then the traffic flows.

Exciting times ahead.

Monday, May 18, 2009

ITWeb Security Conference

[Our heroic writer gets interviewed by the Press and gets ready to knock some socks off at ITWeb Security Summit]

In the run-up to the ITWeb Security Summit, I have been interviewed about my Information-centric Security speech.

I'm looking forward to the conference. It will the first time that I am presenting and I think that this year is going to be great. There are a lot of new technologies and concepts that are going to make this year exciting.

At work I have been working hard at planning my next year and I am very excited about that too.

There is some Information-centric Security in there but lots of other stuff. It is going to be a busy year.

Thursday, April 30, 2009

Sneaky Twitter Tweeting

Ok, so I was bored. And then I saw the challenge -

It came, ironically enough via Twitter.

It is a Twitter client that looks like Excel. If you boss walks past then he doesn't spot you wasting time.

Nice idea but lets see if we can take it further.

Twitter inside Excel. No tricks, no fake screens. Just the real deal. Create one sheet for work and one for play.

Ok, so how?

Step 1
Open Excel

Step 2
Click "data" then "xml" then "import" and put in the following URL:

http://twitter.com/statuses/friends_timeline/[userid].rss

UserId is your userID which you can get by logging into twitter, going to twitter.com and hovering your mouse over the RSS logo on the right.

Step 3
It will ask you for your twitter username and password (unless you are logged in) and pull the information into excel. As a bonus you can right click, select XML and refresh the information.

Step 4
Different versions of Excel will work slightly differently.

Note that the information doesn't just magically appear in Excel, it is loaded via your browser (running in the background with no window) so if your employer has a proxy server (they should) with logging on (it should be) and they have suspicions about you (I hope not) they can still see your twitter browsing even if your boss can't see it by glancing over your shoulder.

Thank you Dominic for the challenge.

PS. using the Twitter API, it should be possible to post to twitter and see DMs and @ messages and your own status etc etc but I didn't feel like playing with it that much. Maybe I will. At the moment, you only get your personal stream, unsorted. In Excel.

Do I live the first suburb in the world to be smurfed?

So, strange reports started coming in to the media this week about neighbors whose gate remote controls and car remote controls had stopped working. It was across my neighborhood but not those around us. It didn't affect us thank goodness. No-one knew what was causing it.

It turns out that new special meters that have been installed are to blame. They consist of the bit that measures the electric usage and a bit that reports it back to the electricity company. They communicate with each other using the same frequency that gate and car remotes use.

Somehow they have been "over-communicating". This has led gate remotes and car remotes to stop working due to all the signal-noise. It made the press because in South Africa a non-working gate remote on a dark night can lead to some pretty ugly crime.

The electricity department denied that it was their machines until it was proven otherwise with signal measuring tools. Now they claim that it was a third party device that caused their meters to start shouting to the world at large. They have a 'patch' for the machines that can stop this issue.

Exact details are sketchy but it sounds like someone managed to launch either a smurf attack or a DoS attack on the machines which in turn made things like electric gates, garage doors and cars not work. Parts of the neighborhood were essentially shut down. So, I'm claiming to live in the first suburb to be smurfed.

Friday, April 17, 2009

Analogy vs analogy. Let the games begin!

[Enforcement or Awareness? Whats best?]

Since my posting about how seatbelt legislation improved the use of seatbelts was very popular, I like the idea of traffic rules being used as an analogy for Information Security. So it was quite exciting to see some Gartner thinkers copying me (obviously they read my blog religiously, debate it at length and then copy it. I am that good).

So, the first one was about traffic light cameras causing more accidents than stopping them. And how the government won't remove them because they make some good money from them. Enough said there. The other was about how traffic speed signs have been around for years but not very effective but speed cameras are very effective.

Reading between the lines, it seems to me that the article puts down the idea of awareness in total as being not effective. Which is fair enough. In Information Security you can preach for hours but unless you actually capture the hearts of those in the room then you are lost. They will not listen. One way to go is to use a combination of things including awareness and enforcment.

Taking Then you've won.

Monday, April 6, 2009

The Issue With Cloud Computing

I really like the way The Hoff puts things sometimes:
We’re told we shouldn’t have to worry about the underlying infrastructure with Cloud, that it’s abstracted and someone else’s problem to manage…until it’s not.
I think that sums up in one line the problem with Cloud Computing. You are essentially making your job easier by dumping the responsibility for Security (and Availability) onto someone else's plate. Which is fine until they post a note saying "Sorry" and you are left with no service.

Or worse - data that has gone off somewhere that you don't want it going!

The Conficker Eye Chart - Really!

This Conficker Eye Chart is brilliant!

Information Security can get a bit drab and boring. Especially when the auditors start poking around and you are arguing about the minutiae of your security policy. And especially when you look at the designers with their Apples and the programmers pumping out new Web 2.0 frontiers.

But sometimes, someone out there comes up with something so silly but effective that it just has to be blogged about.

The Conficker Eye Chart is simple - it tries to download images from Sites that Conficker blocks. If you can't see them then it could be that you are infected.

But you really have to see it. I wish I had come up with that one!