Thursday, February 08, 2007

This Doesn't Sound Right, Does It?

Eric Fitzgerald: "I get asked the question pretty regularly how to determine from the security log whether a user logged on using a smart card or not.

The short answer is, you can't be absolutely certain. The longer answer is, well, you can be pretty certain for the time being, especially if you're not running any non-Microsoft Kerberos code."

Esoterica indeed.

Wednesday, February 07, 2007

At RSA 2007 Today

BTW, I am wandering around RSA today. Want to meet? Drop me an email ...

Monday, February 05, 2007

So, Is Security An Art?

Now, I realize that for some this question will sound like "Is plumbing an art?" or even "Is accounting an art?"  However, I think now is not a bad time to ponder this one, again. You might recognize this post as being of the type "written_while_flying" :-) only more so since it is actually of a type "written_while_flying_from_Europe." :-)

It started from a CrateMaster 2000 joke about a CVSS. And then this comment came in: "CVSS is the same way. It tries to reduce something to a single number (or set of numbers) that is inherently complex. It gives the appearance of scientific legitimacy to something that is as arbitrary as a game or movie review. ("I give this vuln two thumbs  up!!!")."

And then this: "The fundamental problem with cyber-security metrics is that the things we can
easily quantify are rarely interesting, and the things that are interesting are hard to quantify..."

On the other hand, many folks in our profession are sitting on huge piles of checklists and counting the days when security becomes a formal if unexciting discipline, reduced to a set of simple, and, well, not so simple, rules that everybody would need to follow (and some actually would). A science of sorts. Or a least a management discipline.

As I put it in my landmark :-) post on "Will Security Ever Be Done?" (also some discussion here) I find this complete transition rather unlikely. However, I think vuln scoring is picking a wrong battle for the "security is an art" types. Say whatever you want, but a well-define vuln scoring seems perfectly doable, even if not trivial. And CVSS is a quality effort to get there, with some results to show.

Now, on the other hand, something like incident response will never become formal and will not be reduced to just following a checklist (even though incident response checklists are immensely useful!), just as - analogy alert! - police investigative work will never be reduced to following a formalized procedure ...

How about making the next step along this road: are those parts of infosec which are akin to art immeasurable by definition (kinda like poetry)? This question should be left unanswered for now (esp. given that I am finishing this post at Mini MetriCon 2007)

Sunday, February 04, 2007

LogLogic Party at RSA 2007

LogLogic Party at RSA!!!

"Fancy a free beer, some good company and a bit of fun at this year's RSA conference. We'll be celebrating a year of stunning growth for LogLogic and the market as a whole at TWO - a hot new bar, two blocks from Moscone at..... We'll be throwing in some door prizes...

Last year LogLogic doubled our customers year-on-year, grew revenue three times, and increased customer traction both in the U.S. and abroad across a wide range of industries -- especially financial services, banking, healthcare, and retail. With major news in the works, we are entering 2007 with a bang and are in the mood to invite you to our celebration just before the kickoff of the RSA Conference.The market is moving to LMI, find out why. If you want to have a serious conversation about LMI, great. If you just want to come by and have a beer, we'll raise a glass with you. Attendees will have the chance to mingle with hackers, log gurus, security geeks, and us loggies!

On Monday, February 5th, starting at 6 PM, LogLogic will be hosting a cocktail reception at TWO. TWO is between 3rd and 2nd off Howard, very easy walking distance from the Moscone Center.

Sign up for the event with an RSVP to rsvp@loglogic.com

Here are directions to TWO (the restaurant formerly known as Hawthorne Lane). (http://www.two-sf.com/about/directions.html)."

Monday, January 29, 2007

Saturday, January 27, 2007

NBS Log Analysis Tricks Live On!

A long, long, long time ago (eh, like, in 1997 :-)) Marcus Ranum said in his post "artificial ignorance: how-to guide": "... you build a file of common strings that aren't interesting,  and, as new uninteresting things happen, you add them  to the file." And then you watch for other log records, which are then presumably interesting.  This introduced the concept of "negative" filtering i.e. looking NOT for what you know to be "good."

This technique is indeed extremely effective for finding "interesting" (i.e. unusual + actionable; see more, for example, here [PDF]) events in logs.  I even wrote a few prototype tools myself - including filters such as "new log record type for this port", "new for this network segment", "new for this sensor", "new for this IP range", etc or even two-dimensional ones such as "new for this port and destination IP address" which worked really well. All approaches had adjustable timeout after which the tool would consider an event to be new (e.g. "new for this week", "new for this month", etc). However, few vendors chose to incorporate such analysis approach in their products (bizarre, isn't it?).

And now, 10 years later (!) somebody finally did. In his post on 'Finding Events that have "Never Been Seen" Before' Ron Gula (with Marcus Ranum standing over his shoulder, no doubt :-) ) talks about implementing this in his product. What took you so long? :-)

They say "Regardless if your event logs are from UNIX systems, router access control violations, wireless access DHCP logs, intrusion detection systems or so on, after a certain period of time, the same events tend to repeat themselves. This is because most of our networks run controlled and automated processes. With this in mind, finding out when something "new" occurs could indicate a security or administration problem. " Right on! There is more fun stuff in the follow-up post 'More on "Never Before Seen" Log Events'.

Book Review: ”Understanding Voice over IP Security"

Book Review: ”Understanding Voice over IP Security" by Dave Piscitello and Alan Johnston

Now, VOIP security has been talked about for a few years; it started even before organizations started to deploy VOIP in greater numbers. Many folks like to say that “VOIP security is a disaster,” but usually they don’t explain how or why.

Dave Piscitello does. In his excellent book “”Understanding Voice over IP Security” he provides excellent coverage of both VOIP technology basics as well as internet security fundamentals (which are admittedly more useful to the security beginners) Then he fuses the above information into a comprehensive coverage of VOIP security issues, from protocols to call fraud.

VOIP and NAT? Security analysis of SIP protocol? VOIP and honeypots? PSTN gateway security? Public VOIP vs private VOIP? Is VOIP spam inevitable? Yes, all those and much much more are covered in the book.

On the negative side, I had to skip through some of the security basics (yes, even a castle metaphor is there …), but I am conscious of the fact that such content is indeed useful to people with networking background. At the same time, some of the esoterica of phone networks was completely new to me and thus exciting to read.

I enjoyed the book; I liked that it is written to be useful to both security folks – who need to learn about VOIP - and network folks – who often need to acquire better security education.


Friday, January 26, 2007

Authentication: I Just Love This ...

Quoting from here:

"There are three types of authentication:
  1. Something you've lost,
  2. Something you've forgotten, and
  3. Something you used to be."

Security Cartoons

Run, not walk, while having your RSS reader with you, to this site. Then prepare to ROFLMAO.

Thursday, January 25, 2007

"Risk House" Model

Just an interesting, information-dense picture of enterprise risk.

One Fun Prediction: Virtualization

A bold prediction indeed: "Yep, in 2007 virtualization and app-security will be the NAC of 2006 so get ready."

Interesting ...

ROI on Not Getting Your Ass Whooped

So, what is the ROI on not jumping off a building? Do you, like, compute it before performing a "not jumping off a building act." Obviously, that is stupid.

Fine, let's try this one next - what is the ROI of not going to jail (and sharing a cell with whatever Bubba)? Well, most if not all people know that they must not go to jail, without doing an ROI computation, not even an ad-hoc one :-)

Then, why oh why, you are doing an ROI on compliance? If you have a well-defined regulation with a clear track record of pursuing its offenders, you don't just comply because whatever semi-intelligent "ROI computation" tells you to. You comply because you have to! You don't use a formula, you do it because you have no choice.

You can argue with the law and try to influence whatever lawmakers to make a new or a better one, but you follow it while it stands ...

Logs Are Everywhere!

Given that I am closely involved in a log management business, I sometimes have those moments that I see logs everywhere. But guess what? Logs are everywhere! From a server under your desk to satellites to ship systems to personal electronics to telecom equipment to building control systems - logs are indeed omnipresent.  

And, at present, such logs are never looked at. How often do you - or, even worse, a typical computer user -  look at your Windows (Linux?) workstation logs?  I am guessing: when something goes wrong. It is pretty much the same for most of the above logs. And that is how it always was - from the olde times of "The Cuckoo Egg" (and probably even from  the times of the ENIAC) to today.

But - and here is the point! - it is changing now. My natural flow of log management shows us that people start looking at common firewalls and servers before they look at operational logs from, say, an elevator in their building, such log sources are out there. However, the time when people will start looking at most of the above logs - and not only after a problem rears its ugly head - is coming ...

Yes, I am being somewhat philosophical here at 21,456 ft, flying back from  DoD Cybercrime 2007...

Technorati tags: , ,

On Fruit, Low Hanging and Those Hanging Elsewhere

Here is an insightful post from Jeremiah Grossman blog. As he says, often people recommended fixing the simple glaring vulnerabilities - low-hanging fruit - after a vulnerability assessment.

And then he makes this bold claim: 'eliminating the low-hanging fruit doesn't really do much for website security.' He then explains that this is because the role of 0days is much higher in web hacking compared to platform hacking and removing simple problems just means that complicated ones are sure to be exploited ...

It does seem to make sense! So, in this case "better than nothing" strategy gives you just about the same stuff "nothing" strategy aka "close your eyes and go."

Those doing risk assessments should definitely pay attention to this!

On Failures ...

It is always sad when a good security company fails, but sometimes it seems somewhat justified: I was deeply underwhelmed by their positioning whenever I saw them at conferences in the past few years.

Also, as pointed out in the paper, "no one vendor is solving it [insider problem]in an end-to-end fashion" has something to do with it ... And no one vendor will.

And, here is my del.icio.us feed for security failures; feel free to check it out once in a while.

Sunday, January 21, 2007

On Math

Kinda one of'em "no comment" thingies...

Log Management Cloud

Here is a log management tag cloud, build by clusty. Notice something interesting?

Logs and Compliance: Married for Life

Despite this cheesy title, I am talking about something serious here. Many security solutions are being sold as "compliance solutions" nowadays (and there is nothing wrong with that). However, sometimes I can't help but chuckle (or, less often, roll on the floor laughing :-)) when I see a vendor make an especially tenuous connection between their offering and whatever compliance mandate or regulation (e.g. "our firewall is really a ... khmmm ... yes!  a compliance solution, because it ... eeeeh ... helps you, you know, be compliant and stuff" :-))

However, there is one technology that has "compliance" written all over it:  log management. Why am I saying this? Is it because LogLogic pays me?  No, this post is actually inspired by this paper here. Two quotes illustrate  my point:

1.  "By reviewing the logs, data center managers can record specific kinds of activities to show auditors that controls are in place." Yes, one can try to look at the configurations to see the controls, but only logs show how those controls manifest in real life.

2. "The other function of log data in compliance is to report on exceptions -- explicit log events that represent issues requiring investigation [...]" Indeed, logs provide an objective (subject to known caveats ...) trail of activity and should be used pretty much in all investigations.

The paper further mentions the role of logs in SAS 70 audits; while some people make jokes about it as a means to "prove security", it seems to be the choice of some companies that seem to streamline their audit processes.

More on Why Passwords Will Stay

He asks: "Fine, but what happens when we have dozens of key fobs to manage?" He also proposes a solution here. But guess what? It ain't. And biometric creds cannot be changed, which is pretty bad. Who do we have left standing? Passwords ...

Still, this "password series" is meant to incite, but nobody bit so far. What's the story?

Got a "Second Life" Office?

Some security companies do.

Now and Zen :-)

So, can someone pray tell me, how is this SONAR thing different from "Use Heuristics" in their standard anti-virus? The claims look pretty much the same, if you look carefully ...

The only explanation that seems reasonable is that the "old way" was kinda ... fake ;-)

Friday, January 19, 2007

Security vs Networking

" Simply put, the networking group should maintain and configure network devices, and the security group should maintain and configure security devices."

Ah,
I also sometimes lament that this world should be a simpler place :-) So, pray tell me, what is a firewall: a network or a security device?

Got this one? How about a switch firewall blade in a switch?

Oh, got the above OK? Here is a tougher one: a firewall code in a router?

Got my point!?

On "Eight daily steps to a more secure network"

So, yeah, in light of this, why am I posting this. :-) Because folks who currently don't do anything, will certainly benefit from reading this list of daily security tasks.

And, of course, logs are there en masse :-)

"Look at your antivirus logs: Did a virus hit your e-mail system last night? Are the antivirus signatures up to date?" [I'd add: check AV logs for failed updates and scans as well as other AV failures and even AV software uninstallations and terminations]

"Read the security logs on your domain servers:
Did the system lock out any accounts last night? Pay special attention to any accounts with administrator access. Verify that lockouts were human error—and not part of a breach attempt." [I'd add - look for configuration changes, service restarts, various failures as well as resource issues - all might be indicative of attacks, failed or successful.]

"Check more logs: Take an in-depth look at IDS and firewall logs. Who on the Internet is knocking on your door? What are they looking for? Who on the inside of your network is doing something they shouldn't be?. If you find unauthorized and/or illegal activity, report it immediately, and take action to stop it." [I'd add look for NEW events from your IDSs which were never seen before]

Of course, if you happen to own a log management system, doing the above tasks would be a breeze :-)

Dr Anton Chuvakin