Showing posts with label 2011. Show all posts
Showing posts with label 2011. Show all posts

Monday, March 14, 2011

SecurityBSides San Francisco at RSA 2011 Presentation

My account of RSA 2011 cannot be complete without-  yes! - SecurityBSides San Francisco. I was holding this post hoping to include links to videos, but – despite the power of Google – I was not able to figure out where AND whether the video are posted.  So, you have to enjoy my new fun SIEM presentation (below) without my voice and an image of me pointing at the sky Smile

Enjoy!

Possibly related notes:

Monday, January 31, 2011

My Security Predictions for 2011

Now that I have checked my  2010 predictions (see here) and “reflected and mused” on 2010 (here), I am allowed to proceed to 2011 predictions  Smile

My past experience predicting shows that I am a cowardly, extrapolating predictor – and can get a lot of easy, obvious stuff right. Great!  I will do some of it  now as well since  there is nothing wrong with extrapolation and “Feynman prediction methodology” [=predicting that whatever is there now will stay the same in the future]), but will try to be a bit more wild, like I was in my 2020 (!) security predictions. Also, I noticed I’ve been a bit too verbose in the past, so this year I ‘d rather be brief (since I am busier).

So:

  • PCI DSS 2.0 marches on: this is the year when PCI DSS gets even BIGGER (if you can  imagine it!). And smaller too – more smaller business will “get” PCI. Great news! On the not so good side of PCI, I predict that  a few of “validated compliant” companies will be found abysmally non-compliant and insecure: after the breach or otherwise. Maybe some QSA heads will roll as a result, especially those “remote-assessing” “easy-graders.” The challenges of compliance in non-traditional environments (virtual, cloud, mobile devices, non-traditional payment methods, etc) will rise to prominence as well.
  • HIPAA teeth: yes, this is one of those things that people has been predicting since 1996 (yes, really!), but somehow I feel like this time – in 2011 – HIPAA/HITECH enforcement will be for real.  OK…you can call me an idiot in a year, if I am wrong here.
  • Application security – and application security monitoringGunnar paradox on firewalls+SSL might finally start to break in 2011. I do predict that not just web application security, but also many internal “enterprise” application will get in scope for SIEM, correlation, near-real-time monitoring, etc. And not just at “adventurous” security leader companies, but more like in early mainstream.
  • Still no mobile malware deluge: enough about this one. Enough! Enough!! For sure, there will be isolated (and possibly pretty bad) malware incidents, but not “Slammer for iPhone” or “Blaster for Android” in 2011.  I suspect that PCs will still have more “money” and more holes and so this is what the bad guys will continue to steal.
  • Mainstream security in the cloud: yes, Qualys and a few others have been doing it since 1999 and a few cloud security providers has been absorbed into large entities (latest, sort of), but I suspect that in 2011 we will see much more of “<XYZ> approach to security of <ABC>… now in the cloud.” BTW, I mean REALLY using SaaS/PaaS/IaaS cloud options and not “press-release cloud” like many do today.
  • “New” types of incidents: going on limb, I predict a few large  (and very damaging) breaches, NOT involving regulated PII, but good old secrets. Wikileaks mentality + cybercrime resources = a fun year!
  • SIEM for dummies: OK, this is another risky one. As you know, there is no leader in the SMB/SME SIEM market and I am really looking for somebody to climb on that hill. The world needs a penultimate “SIEM for dummies.” As of today, SIEM is decidedly not.  At the very least….I am predicting the arrival of “a log toaster” Smile
  • Security vendors: despite the silly 2007 predictions by RSA CEO, there will still be hundreds of security companies around. However, some of the players will definitely feel like they”overstayed market’s welcome” (e.g. some legacy SIEM vendors) and will either die or go firesale.
  • Risk “management”:  every past year, I predicted that we will remain dazed and confused about how to apply risk to information security in an objective manner (objective, not necessarily quantitative). This year…. drumroll… I am laying these dark thoughts to rest – at least for a while. Maybe, just maybe, we are starting to see both data and approaches that will eventually give us something to work with. And not just whine about it Smile

Enjoy!

Possibly related posts:

Monday, January 17, 2011

11 Log Resolutions for 2011

FYI, this piece has been specially created for LogManagementCentral (original post), an awesome site about logs, log management and SIEM. It is reposted here for posterity.

 

So, behold 11 log resolutions for 2011!!

1. I will turn logging on the systems I manage: this resolution is about the very first step one must take to using log data for many purposes inside and outside of IT – actually having logs. Start 2011 by committing to enabling logging across the systems you manage or oversee. And, yes, “log everything” is not the answer in most environments (and as all oversimplifications, it is often downright silly – e.g. log every SELECT on a database will lead to your DBAs killin’ ya Smile) – further resolutions help with figuring out how to do it without killing your systems

2. I will create log policy: this resolution helps you to make a commitment to understanding what you need to log on each system and how to do it. Logging policy starts from reviewing compliance requirements and other “use cases” for log data.

3. I will check for when logging stops: one of the simplest ways to commit to having logging in 2011 (and all years thereafter) is to commit to monitoring when logging stops. Apart from being a violation of a few regulatory compliance mandates, termination of logging – whether due to an attacker all by mistake – is something you need to know right when it happens.

4. I will use compliance intelligently: this resolution draws a line between being a checkbox-following “compliance monkey” and being convinced that “compliance is evil.” Regulation such as PCI DSS contain not just motivation but also some useful advice on how to do logging right (some ideas).

5. I will learn what the logs mean: committing to logs is not simply committing to having logs –you have to know what the log messages actually mean and what they are trying to tell you. In 2011, make sure who that you seek to understand what your systems are trying to tell you in their logs and learn to tell routine messages from critical “system-busting ” alerts.

6. I will at least check logs for intrusions, system and account changes and major errors: one cannot make a resolution to analyze logs without starting small first – if you have to look for some will things first, at least commit to check your logs for intrusions, system and account changes and major errors (this checklist can help)

7. I will review logs: generating, centralizing and storing logs is important. These practices a bed of sensible and mandatory (prescribed by many regulatory mandates). However, main log value lies in interpreting, understanding and then acting upon the information present in the logs. You cannot commit to logging excellence without committing to log review – using automated tools (lots of ideas on log review)

8. I will make sure that I have logs preserved after an incident: leads rarely matter more than in a hectic post-incident environment where every bit of data can help understand the origin and impact of the intrusion. Commit to using logs for incident response in 2011! (useful tips on that)

9. I will train my developers to create useful logs: making – and keeping!-a resolution to collect and review logs is impossible if logs do not exist – as it is often the case for your custom applications. In order to gain benefits of logging in such case, you must make a resolution to train your application developers to create useful logs inside their applications. Use emerging standards such as CEE to guide them towards proper logging practices

10. I will stop complaining about how bad logging is at most organizations: everybody starts somewhere, and many organizations start from a truly abysmal state in regards to logging. Start logging – and stop complaining. Go from log ignorance to near-real-time log enlightenment using a process similar to this

11. Finally, I WILL REMEMBER THESE RESOLUTIONS FOR THE ENTIRE YEAR: unlike some security technologies, logging, log review and log monitoring is a lifetime commitment. To get something useful out of log data, you have to log and review data all the time.

Any other logging resolutions you are making for 2011?

Dr Anton Chuvakin