This is Anton Chuvakin original blog (pre-Gartner) that I will now use to backup my Medium blog content (2023+)
Monday, March 26, 2007
On " Vista: Where UNIX was in the 1980s"
Enjoy "Vista: Where UNIX was in the 1980s"
On Security vs Convenience vs Embarassment
Besides the above quote, I was actually quite impressed that "log management was cited [as a funding priority] by 23 percent of respondents"
But all this murks in comparison to the good old some-say-myth-some-say-truth that "everybody is 0wned." Specifically, Alan Paller said: "Federal systems are deeply penetrated, by hackers and other hostile interests."
On "Know your Enemy: Web Application Threats"
Future Innovations
Anton Security Tip of the Day #9: But He "Wasn't Logged!"
Following the new "tradition" of posting a security tip of the week (mentioned here, here ; SANS jumped in as well), I decided to follow along and join the initiative. One of the bloggers called it "pay it forward" to the community.
So, Anton Security Tip of the Day #9: But He "Wasn't Logged!"
The idea for this tip originated when my presentation on log analysis was rejected by one of the high-profile security conferences on the grounds that "logs don't matter since advanced attackers never leave traces in logs [or erase them before anybody can get to them] ." Indeed, some of my security friends of a more "offensive orientation" :-) have long developed this snobbish attitude about logs.
So, imagine a network that has fallen victim to a 0day-wielding "uber-haxor" :-), who kicked the door open (or snuck in), grabbed the crown jewels and took off like a bat out of hell :-) When, much too late as usual, the "good guys" rushed in to pick up the pieces, only there was seemingly nothing much to pick: the server logs were erased and the network IDS didn't make a peep (and, no, Richard, NSM was not deployed). What do you do now?
So, let's list some uncommon (and some common, but often untapped for the task at hand!) sources of log data and provide a few log analysis tips:
- firewall logs: boring they might be, but it is less likely that those are erased by the attacker (even though firewall logging can sometimes be jammed). And it is hardly possible to "not be logged" by the firewall (the analyst's challenge is in analyzing the huge volume of data to find the attacker's traces and to tell them from normal traffic). What is critical in making these logs useful is logging allowed connections, not only blocked ones.
- router logs and netflow records: same as firewalls logs - they are less likely to be erased, but huge log volumes make their use problematic. And, last but not least, these types of logging are more likely to be turned off completely ("routers should route, not log," grumble many network types)
- application logs: was it a "legacy" network attack or something application-level? If the latter is true, there might be logs found in unusual places. Is there anything in the webserver logs? Websphere made a peep? MySAP recorded something? PHP app logged something fun?
- various client logs: in one old case FTP client logs were extremely helpful, even though the entire syslog directory was blown away and no remote logging was ongoing; look for other client logs (yeah, even a web browser history is kind of a log...) to look for things missed by the attacker
- other systems' logs: was there anything that the attacker did that affected other systems? Might have they logged it? Even an attempted SSH connection or a scan from a compromised machine has a high chance of leaving traces elsewhere - cleaning all of such traces is a major challenge for an attacker (in any case, much harder than erasing logs and stopping logging on the compromised host)
- any remote or centralized logging: was any log saved from destruction by being copied to another system?
To conclude, while there is no "logwatch" pattern for "advanced attacks," logs are still very useful in such circumstances if you prepare by setting up a broad scope of log collection (I suspect using a log management system will be your only choice as log volumes will be pretty bone-crashing) and then combing through the logs after the incident. And remember the less common sources of log data, such as database logs.
I am tagging all the tips on my del.icio.us feed. Here is the link: All Security Tips of the Day.
Thursday, March 22, 2007
On "Top Ten Investigative Boo-Boos"
Just one example:
"2) Investigators destroy evidence because they didn't follow their own procedures. [...]"
More Fun Stuff on Security vs Security
Check out the current results here and vote here.
So far, it seems like we do like to violate security rules which - I am guessing here - we perceive as 'stupid.' But how can we then complain that users break the rules that they think are stupid?
Something is deeply amiss here... help me out!
Review of my Database Logging Paper
Wednesday, March 21, 2007
A Fun Question to Ponder ...
Tuesday, March 20, 2007
Security vs Security: Who Wins?
So, my esteemed readers of security profession, have you ever knowingly circumvented a security measure?
PCI Book Out Soon!
Again and Again on Compliance vs Security
However, what is missed in the above adage are all those areas of compliance and IT governance that have little to do with security: proper change control (which admittedly helps security immensely), documenting controls, SLAs, and a bunch of other stuff that ITIL, COBIT and others are made of.
So, compliance might not lead to security, but security doesn't lead to [full] compliance as well ...
Dumb and Dumber ...
He continues: "1st generation SIM [you know who you are...] is pretty much dead, and those that want to survive need to either focus on log management or more real-time network detection (which means they need to bring in NBA data)"
And then closes with: "But of course, lots of folks were lining up to get briefing slots to tell me how great they are. Without even hearing their pitch, it's a load of crap."
Sorry for that much quoting, but there is just no better way to say it - some companies in this segment have certainly overstayed the market's welcome...
Doing a Media Interview for Security Vendors
A quote:
"The Players
Interviewees generally come in threes. There’s the Main Guy, the Other Guy, and the PR Bodyguard."
"Main Guys can build a 20-slide Powerpoint around a single trivial feature upgrade that is entirely 100% identical to something their competitors introduced and briefed you on three weeks ago.""...At this point, you need to show that you’re paying attention. So ask, “What are your target verticals?”. The answer is “healthcare and financial services”."
"The sixth slide has a diagram with some boxes on the left, some people typing on the right, and a cloud in the middle."
"The tenth slide has the name of an analyst you can call if you’re a fresh-out-of-college rookie or just totally fucking clueless and lost."
etc, etc, etc
Fun Read: "Bad News Is Good"
Let's Play a Fun Game Here ... A Scary Game
So, let's suppose somebody who is involved with incident response at a typical US public University has collected a few recent malware samples from the compromised machines and then submitted all the samples to VirusTotal for scanning with pretty much ALL current anti-virus and anti-virus-like products.
What do you think the average detection rate (i.e. a malware sample was identified as "something bad") was?
Any guesses? Here are a few numbers to help you choose:
- 100%
- 94%
- 90%
- 70%
- 50%
- 33%
- 22%
- 14%
- 2%
- Something else?
Let the games begin!
UPDATE: answer postedUPDATE2: after much deliberation, I finally replaced anti-virus on my own systems with another technology. Read the details here.
Sunday, March 18, 2007
Build A Better ... Top Influencers List :-)
Update: any "list watcher" :-) must read the comments over at Matasano and have fun while doing it. Ability to not take oneself too seriously is critical in our biz :-)
Thursday, March 15, 2007
On Ego Feasts and Top Lists :-)
And why not? After all, why do we blog? I am thinking ...
- To share knowledge with the community
- Because it is easier than writing a book :-)
- To generate F&G
- Because we need to generate awareness about our favorite technologies
- To vent and rant
- Whatever other reasons ...
Finally, I am honored to occupy a spot #4 in the sub-list of "Chief Blogging Officers" (I never thought I am one, BTW)!
Tuesday, March 13, 2007
Discounted Passes for CSI NetSec 2007 Anyone?
Since I am speaking there on mistakes of log management, I can give out a few of those discount codes that reduce the conference admission price by almost a $1000: "The discount passes cover the entire two-and-half-day conference for only $795 until May 11th (after which the discounted passes will be $995)--a regular conference pass is $1,645. "
To make use of the pass code go to CSI NetSec 07 Registration.
Update: just as I suspected :-) No takers so far...
Discounted Passes for CSI NetSec 2007 Anyone?
Since I am speaking there on mistakes of log management, I can give out a few of those discount codes that reduce the conference admission price from by almost a $1000: "The discount passes cover the entire two-and-half-day conference for only $795 until May 11th (after which the discounted passes will be $995)--a regular conference pass is $1,645. "
To make use of the pass go to CSI NetSec 07 Registration.
Discounted Passes for CSI NetSec 2007 Anyone?
Since I am speaking there on mistakes of log management, I can give out a few of those discount codes that reduce the conference admission price from by almost a $1000: "The discount passes cover the entire two-and-half-day conference for only $795 until May 11th (after which the discounted passes will be $995)--a regular conference pass is $1,645. "
To make use of the pass go to CSI NetSec 07 Registration.
Tuesday, March 06, 2007
On Database Logging and Auditing (Teaser + NOW Full Paper)
Here is a excerpt from a fun paper on database logging that I just wrote:
"Database security have been capturing more and more attention in recent years, even though most of the security issues surrounding the databases existed since the first day commercial database systems were introduced in the market.
Nowadays, database security is often seen as containing the following principal components:
• access control to database software, structures and data
• database configuration hardening
• database data encryption
• database vulnerability scanning
It is interesting to see that logging and auditing underline all of the above domains of database security. Indeed, the only way to verify what access control decisions are being made and who views what data from the RDBMS is to look at the authentication logs. Database configuration hardening includes enabling and increasing the auditing levels. Similarly, data encryption might be verified by log and configuration review. And, vulnerability exploitation usually leaves traces in logs despite what some say (the challenge is more often with understanding what the log said and not with having the logs)
In recent years, insider attacks gathered more attention than periodic outbreaks of malware; and database logging happens to be in the forefront of this fight against insider attacks. Database systems are usually deployed deep inside the company network and thus insiders are usually has the easiest opportunity to attack and compromise them, and then steal (or “extrude” as some would say) the data..."
Read more here if you are a CSI Member. If you are not, the only way to get my paper is to ask me (sorry, copyrighted stuff)
UPDATE: another similar paper by me is posted here.
UPDATE2: full paper mention above is posted, finally! Enjoy my "Introduction to Database Log Management" at InfosecWriters!
So WHAT Is He Doing Right?!
"43. Mikko H. HypponenDirector of antivirus research, F-Secure
F-Secure's security news blog, written by director of antivirus research Mikko H. Hypponen, is one of the Internet's go-to places for learning about the latest security threats."Yes, I do get that Bruce Schneier is on the list (how can he NOT be?), but this puzzles me to no end. Well, I have much to learn about personal marketing, it seems...
Friday, March 02, 2007
On Temptation ...
Don't companies that try to suppress security research understand that if you do this to a security researcher, even the most ethical guy in the world will be tempted to JUST LEAK IT.
If you corner a rat, it bites. Don't corner security researchers :-) they have bigger teeth... much bigger. You want to suppress the legitimate security research? You think you just did? Go suppress the entire underground now!