Tuesday, January 13, 2009

Prediction Number 1 for 2009

A major company will suffer losses due to stolen intellectual property.

(I've been trying to come up with all my predictions but I think I will just post them 1 at a time as I think of them. Here is the first.)

If you have been fortunate to attend any of my recent presentations, have read my blog or have gotten caught in a lift (elevator) with me then you'll know all about my Perfect Storm prediction.

I have no idea if it will happen in 2009 or 2010 but it is coming. It may have happened already and we just don't know about it. Briefly - there is a major underground economy happening right now. They are focused on payment card information (PCi) and personal information (PPI) that can be used for identity theft. There is a glut in the availability of this information and it is not worth so much. Either the underground economy will collapse in on itself or (more likely) it will start to trade intellectual property (IP).

IP is worth a lot more than either PCi and PPI but it is harder to find a buyer who can use it and the information is less standardised. But tough times call for tough measures and these are tough times.

I'd like to think that companies would reject offers of stolen information but this is very naive.

The reason that it may happen and we will not find out about it is that companies tend not to report these things to the media or anyone else. And since the information stolen does not belong to anyone else then they don't really have to report it.

The only time they'll have to report it is if it has the potential to make a massive change in their earnings. They'd still be able to fudge the numbers.

So, my prediction is that there will be a growing trend of theft of IP in amounts too small for companies to report until one company is rocked by atheft so big that it can't hide it.

This will happen - the question is whether it will happen 2009 or 2010.

Monday, January 5, 2009

[OT] Helen Suzman (1917-2009)

The times has a moving picture of Helen Suzman being laid to rest in the typical Jewish way, in a plain, ugly, boxy coffin. Everyone is equal in death - it is how we live our lives that defines us. And Ms Suzman certainly lived hers as a shining light to all.

I would say "Rest In Peace" but something tells me that Helen Suzman would not find that very easy. The Jewish nation in South Africa have always had an uneasy relationship with the Government, cordial but uneasy. The Nationalist Apartheid government tolerated Jews as they were "Whites" and were afforded the benefits that Whites were given. Most Jews were appalled at the treatment of Blacks and other race groups under apartheid but were too afraid to rock the boat.

Not so Ms Suzman. She will always be remembered as someone who spoke up.

More than that - she was never a loose cannon - she knew she was right and she had an amazing way of upsetting anyone who was doing wrong but in such a way that she gained their respect.

I have a lot of respect for the likes of Nelson Mandela and the other great leaders of the anti-apartheid revolution. But I have more respect for those that had not much to gain and lots to lose by their support. The ones who just saw what was good and what was not and decided to do something about it. It brings to mind the Edmund Burke quote about evil triumphing because of good men doing nothing. We are lucky in this world to have people such as Helen Suzman who see the evil around them and do something. Well, the world has lost one of those people, hopefully there will be others to take her place.

Finally, two quotes -

"I stand for simple justice, equal opportunity and human rights. The indispensable elements in a democratic society - and well worth fighting for." [Helen Suzman]

"...I don't pull my punches"
[Helen Suzman]

Wednesday, December 31, 2008

Happy 2009

In what will most likely be my last posting for 2008, here is a bit of advice for all.

I read somewhere that news is never really all that useful. Its interesting. But its not useful. The stuff that you need to know about to go about your daily life is not going to make news.

To get some more perspective on this, I highly recommend that you visit The Onion online newspaper and browse a bit especially at the "Area" reports. (It is humour and is intended for 18+)

One of the interesting news stories of 2008 that I can think of the Dan Kamisky DNS issue that made headlines for all sorts of reasons. DLP made headlines. TJX made headlines.

What is more interesting is what didn't.

Here are some bits of news that you won't see:

"Company patches all servers"
"Awareness given at Company. Stronger passwords result"
"Good user management led to less options for Hackers"
"Antivirus updated led to viruses being blocked"

What did made the headlines today (thanks to Amrit and Dominic for alerting me to this... everyone will be talking about it soon) is the attack on MD5 certificates that makes trusting Web Certificates less of a good idea. The information is here, but this is a big deal so expect this to make the news.

The thing is, that this yields big rewards for the hackers but is also a lot of work. Social engineering methods such as bogus email, phishing, fake antivirus etc are so much easier to do and have big enough rewards as it is. So too do worms and the like that attack old vulnerabilities that should already be patched.

My though for the year is thus:

Hackers are mostly successful by exploiting the boring holes and really do not have to work hard at all. By using tools that are already available such as Firewalls, IPS, Antivirus and doing the boring bits such as choosing strong passwords, updating patches, updating antivirus patterns and being aware at what mails we should not open - we win 90% of the battle already.

I think next year will be very very interesting for us. I hope everyone reading this has a great 2009!

Tuesday, December 23, 2008

Merry Christmas, Happy Hanukkah, etc

In typical Security Thoughts style, here is an Information Security story that relates to the holidays.

It seems that, in Germany, a company sent a Stollen, which is a traditional German Christmas cake to a newspaper via a courier company. Two subcontractors decided that they wanted the cake so they took it and replaced it with another parcel.

This parcel just happened to be confidential data with banking transaction details and it managed to find its way to the newspaper in place of the cake. Obviously, the newspaper was happy with their Christmas present and printed the story. The bank was not so happy.

I think that the theme for 2009 will be "Third Party Security" but in the mean time I wish you all a pleasant holiday and please be responsible if you decide to have a drink or two.

Friday, December 19, 2008

Egg on face

In the interests of showing the world that I am not perfect, I just had to Blog about this incident.

I sent an email with an attachment out to the wrong person. Its the classic case autocomplete messing up - typing some letters and recognising the person's first name. Click send and then realise your mistake when the wrong Jason (it wasn't Jason in this case...) sends back an email asking "huh?!"

Its one type of "oops" that DLP is supposed to prevent.

The interesting part of it all was that the email went out (of all the people in the world) to the sales rep I've been dealing with who has been trying to sell me DLP...

I guess this just makes it more difficult to say "no".

Wednesday, December 17, 2008

Automatic Networks (Part 1)

If you are like me and like to know how the future of IT will impact Information Security then one Blog that you have to read is Rational Survivability by Chris Hoff.

He has a rather "interesting" writing style but his content is amazing. He is a strong voice of reason in how Virtualization, Cloud Computing, etc etc which are all the new buzz words can seriously impact Information Security unless controls are built in.

His latest post is about a new concept where latency of network flows are measured. If a Service is suffering from latency then the Virtual Machine that the Service runs on is moved closer to the User of the Service. Latency is gone. It is an interesting concept and obviously has Security implications which Chris goes into.

I pretty much agree with most of the post but I would like to introduce a new angle on it:

In my last post I introduced a concept that I gave a lot of names. The one I liked the most is Context Sensitive Information Protection (CSIP). I didn't invent the idea but I think I outline it quite nicely in that post. Basically the concept is that everything on the network is aware of what Information is being accessed and acts accordingly. Add this to the concept in Chris's post and your solution becomes secure again.

I think I need to come up with an example. Watch this space.

Friday, December 12, 2008

The future of DLP (DLP is dead, long live DLP)

DLP is made up of two main parts - the "knowing" part and the "watching/blocking" part.

The "knowing" part is built up over time and is generally an understanding of what a piece of information is. Generally, the systems look at a document and label it but it is becoming apparent that the meta-information is also very important. Who is sending it, where is it going, why would someone be using documents at midnight, etc etc.

In an earlier post of of mine I wrote that what we now know as Information-centric Security (and I fully support this) will develop into what I called "Process-centric Security". I think I'm going to trademark BCS (also Business-process protection (BPP) and Business Process Security (BPS) and Context Sensitive Information Protection (CSIP)). This the ability for some system (lets call it DLP) to know what is happening to a document and why.

DLP as we know it today then takes this information and implements some action - block, report, log, etc based on whether the action is allowed to perform the action or not.

Recent developments in the DLP world (See Dominic's comment and Securosis comment) have changed this for the better. Now, DLP does the first bit ("knowing") and passes on the second bit ("blocking") to another tool - a DRM tool. The blocking bit can be done by all sorts of systems and this is where it gets interesting - set up the switch to block, the firewall to block, the mail server to block (and send a "sorry but..." mail), the IPS to block, the PC to block, the application to block, etc etc.. essentially everything can be set to block access to some sort of functionality for documents based on what the DLP Server tells them to do.

Further, all these systems can be set to inform the DLP System what is happening too.

Your network and everything on it becomes aware of how the business works and helps it along, preventing what shouldn't be happening.

The box that makes the ultimate decisions and keeps the database of "good" processes (call this the DLP brain) will not go away. The part of the DLP that enforces and monitors will become part of the network infrastructure and will become a feature of everything from switches to software applications.

DLP as we know it today as a product and fully enclosed system will die off and DLP as a ubiquitous system with tentacles into everything will be born.