Wednesday, August 22, 2007

On Awards

Think this (and more here) doesn't happen in enterprise security land? He-he, think again ...

UPDATE: which security publication is known for such reviews?

Tuesday, August 21, 2007

Fun "Most ..." List from A "Secret" Gartner Blog

"12 Security Features and Rules Most Likely to Mess Up" from a "secret" Gartner blog. Examples

"1. Most likely to be written down
2. Most likely to be left active
3. Most likely to be ignored
4. Most likely to already be in use, without most users' knowledge"

Monday, August 20, 2007

Another Presentation: Logs for Information Assurance and Forensics @ USMA

Here is my old presentation "Logs for Information Assurance and Forensics" that I gave at USMA, West Point last year when I was giving a lecture there.

On BSOFH

BSOFH? ROFL! Very funny indeed.

Esp this: "... Our CFO needed a new office chair after seeing THAT one on his screen" or this: "I can turn my 5-year-old’s artwork into a PowerPoint slide and make the management think it’s the newest ITIL model. Then I can rotate it 90 degrees, flip it 180, and sell it to them the following month all over again."

Thursday, August 16, 2007

Fun Paper: "Malicious Web Servers"

A very fun paper by The Honeynet Project!

In this paper "we examine these client-side attacks and evaluate methods to defend against client-side attacks on web browsers. First, we provide an overview of client-side attacks and introduce the honeypot technology that allows security researchers to detect and examine these attacks. We then proceed to examine a number of cases in which malicious web servers on the Internet were identified with our client honeypot technology and evaluate different defense methods. "

New tools are also released.

Wednesday, August 15, 2007

Nobody Is That Dumb ... Oh, Wait! - V

Another day, another stellar "Nobody Is That Dumb ... Oh, Wait!" case, number V is the series. ... So, will you file for an IPO under such circumstances? :-) Mike adds some hilarious details: "Their income statement showed a loss of about $10 MILLION on revenues just over $2 MILLION."

Ha-ha-haaaaaa. Ha-ha-ha! Haaaa :-)

Tuesday, August 14, 2007

Is Your PCI Auditor a Scammer?

So, we know from the Gartner folks that sometimes the same company can be used for PCI assessments and then for remediation services or prescribed products. Specifically, they say: "The assessor - which is also a vendor of security services - tells you you need a scanning service for all your nodes and servers, since they’re all somehow connected to the servers holding your cardholder data. Oh, and by the way, they can sell you the scanning service. [...] Well, the card companies may not learned anything from the Enron and accounting/audit firm debacles of the past few years, but we have. That’s why Gartner strongly recommends that you hire an assessor that doesn’t try to sell you security software or services."

OK, this makes sense, even though I believe that one can handle this gracefully and ethically. This is a conflict of interest to carefully resolve and not a scam.

However, I recently came across the opposite situation, which smacks of scam so strongly that you will need to hold your nose for a loooong time :-) Namely, a PCI assessor is saying the following: "Pay my [possibly increased ...] assessment fee and I will make the findings look  like you already have all the technologies needed to comply and you will save tons of money on all this 'unneeded' security gear! If auditors come, my assessment results documentation will look so good, that they will not fine you a dime."

Just how outrageous is that? Just as people grew cynical of compliance spending for security, somebody came up with an idea to spend on compliance and decrease security... Kewl stuff :-)

Anybody knows of any way to report the fucker so that PCI Security Standards Council will revoke his license and ram a big one up his ...?

Technorati tags: , ,

Fun One: "10 claims that scare security pros"

A fun piece "10 claims that scare security pros." Examples are "IT security is information security here", "Our managers have copies of all passwords" and "We sent the firewall rules out to ..."

On Plasma Shields

The bizarre part is that this stuff was all over Russian (then Soviet) tech hobbyist magazines back in the 80s ... All this "controlled plasmoid" stuff isn't new at all, even though some say it never quite worked right, if at all.

UPDATE: the patent does seem to give some credit to works of some Mr Leonov, which seems to be related to reducing air friction using artificially generated plasma cloud around the plane.

Monday, August 13, 2007

On Application Logging for Security

A fun one (Note to self: OMG, how did I miss it when it was published...): "This article examines the dismal state of application-layer logging as observed from the authors’ years of experience in performing source code security analysis on millions of lines of code. "


On "Auditing Security Events 'Best Practices'"

Here is dated, but still insightful doc on "Auditing Security Events 'Best Practices'." It covers event log collection and analysis, as recommended by Microsoft (the list is sadly incomplete - there is certainly much more stuff to look at in the Event Log). Example recommendations:
  • Audit success and failure events in the system event category

  • Audit success events in the policy change event category on domain controllers

  • Audit success events in the account management event category

  • Audit success events in the logon event category

Want more? Read the doc.

Friday, August 10, 2007

Build vs Buy for Log Management

My favorite SANS presentation that I gave a few times was "Choosing Your Approach to Log Management: Build, Buy, Outsource" (e.g. see here). This story that I just posted to LogBlog makes this build vs buy distinction painfully clear. Enjoy!

Thursday, August 09, 2007

On Conferences

I find it deeply troubling that there are still plenty of conferences that charge speakers for speaking (!). Yes, it is indeed that fucked up! I understand how some prestigious conferences can get away with only giving speakers free conference passes and still attract good talent. Still, the best conferences out there don't stop there: they also cover your travel expenses and sometimes give a small honorarium, which is great. It works wonders to increase the quality of presentations and overall conference experience!

Now, vendor speaking ops are a bit of a different story; a vendor might sponsor a conference and get a speaking slot, clearly marked as such.

However, think what kind of speaker a "pay for play" conference will attract? This automatically means that all people attending a pay-to-speak conference are scammed out of their hard-earned dollars. So, it boggles my mind why would someone ever attend a conference where the only speaker selection criteria is: "Got 3 grand? You ARE an expert here!"

Before signing up for that next security conference, think: is it a pay-to-play scam?

Wednesday, August 08, 2007

Just A Reminder ...

"The creativity and ambition of cybercriminals all but ensure for years to come there will be a market not only for security technology but for individual security components provided by a multiplicity of vendors."

Another fun quote: ""the security market will therefore remain for the foreseeable future in a steady state which is 'always consolidating but never consolidated.'"

Indeed, this thing I wrote a while ago is still valid.

Possibly related posts:

Free PCI Compliance Book Chapter: On Logging!

Wow! Syngress/Elsevier has released one chapter from our "PCI Compliance" book: and it is my chapter on logs in PCI! Enjoy! [PDF]

Fun PCI Article ...

... which makes a good, if somewhat obvious, point: "Rather than making excuses about how difficult or costly PCI is, companies need to step up to the plate and start taking security seriously. [...] PCI is the best thing that has happened to consumer data protection in the payment industry in many years. "

In other words, stop bitching and start working on things which were useful even before PCI came to bite you in the ass! :-)

Possibly related posts:

If you don’t secure your data, is it unauthorized access?

Interesting: If you don’t secure your data, it’s not unauthorized access?

A quote:
"A recent court opinion out of Eastern District of Pennsylvania in Healthcare Advocates Inc. v. Harding Earley Follmer & Frailey, No. 05-3524, is worthy of note. Law.com reports: 'A law firm did not violate copyright and computer anti-hacking laws when it used a Web archive search tool to recover old Web pages of its client’s adversary, says a federal judge.'

Dedicated to Conspiracy Buffs Everywhere ...

The FBI Can’t Link Bin Laden to 9/11? Why Is This Not News? This does seem to confirm it, kind of.


WSJ-inspired Poll Results In

Poll results are in - no surprises for me here (you can till take the poll here).

Will you break a security policy if you know it is neither enforced nor monitored AND that there can be no repercussions whatsoever (and YOU personally don't think it is sensible)?

Yes, if I REALLY need to do something (53%)

Yes, sure! No enforcement - no compliance. (17%)

No (17%)

No, not if I created the policy (7%)

Other - leave comments (3%)
28 total votes

What it means - to me - is that security people are people too :-) This pretty much rhymes with what I said in my first WSJ post here: if users feel that they need (and CAN!) bypass security to do their work, they will ...

UPDATE: the entire WSJ "blood trail" is tagged here. Especially fun bits are here, here and here.

On Crossing the Chasm

Fun post from Andy on "crossing the chasm." Be careful, if your success is only due to early technology adopters, you can run out of them :-) And then, if you cannot sell to "normal people," you are f*cked ...

More On LASSO and Windows Logging

Here is a small blurb that I did for CNET on LASSO (our open-source agentless Windows-to-syslog collector) and Windows log collection. BTW, a new version of LASSO is out.

One thing to keep in mind is that you don't need LogLogic appliances to use LASSO: it can forward events to syslog-ng or other syslog destinations. However, if you do need more than a syslog server, LASSO works perfectly with the appliances as well.

Monday, August 06, 2007

Anton Security Tip of the Day #12: Proxy Log Fun - Proxy Logs vs Information Leakage

Following the new "tradition" of posting a security tip of the week (mentioned here, here ; SANS jumped in as well), I decided to follow along and join the initiative. One of the bloggers called it "pay it forward" to the community.

So, Anton Security Tip of the Day #12: Proxy Log Fun - Proxy Logs vs Information Leakage

You probably know that web proxies (such as Squid, BlueCoat SG, BlueCoat Netcache and others) produce a lot of fun logs. Indeed, they are fun since they can be used for a whole range of things, from routine monitoring for AUP compliance to malware detection as well as possibly looking for the security scourge of 2007 - web client attacks.

Specifically, in this tip we will learn how proxy logs can be used for detection of file uploads and other outbound information transfers vie the web. First, think what is the legitimate use of file upload functionality for your web users. If web mail is allowed, then sending an attachment will include an upload. What else? The rest will be considered at least suspicious...

In addition to file uploads, some spyware application will also use similar methods to steal data. Looking for methods and content-type in combination with either known suspicious URL  or user-agent (i.e. web client type) can often reveal spyware infections, actively collecting data. Admittedly, a well-written spyware can certainly fake the user-agent field so it is clearly not reliable, but still useful to add to our query above.  Here are some of the criteria we will use to look for uploads in Squid and BlueCoat SG proxy logs:

  • HTTP method (logged as "cs-method" by BlueCoat) = POST  (as opposed to the usual GET, used to retrieve web content).
  • For information uploads: content type (logged as "RS(content-type)" by BlueCoat) = anything but "html/text" (which is the type used for uploading  web form contents) - especially try content types  "application/octet-stream", "application/msword", "application/powerpoint", "application/vnd.ms-excel", "application/pdf" and a few others to look for common file uploads
  • For spyware and application data transfers: user-agent set to anything but the common ones (i.e. not Mozilla, iTunes, LiveUpdate, etc) or even to "unknown." One can also try user-agent containing your favorite messaging app (e.g. "MSN Messenger", etc)

(if you feel adventurous, other interesting content-types to try are "application/x-javascript" and "text/javascript")

Here are the examples of the above, including some "classics" (while spyware specimen are a bit dated, this method of  detecting them via logs is relevant):

  1. 1124376766.026 RELEASE -1 FFFFFFFF 4734C557F9315105CA6BE0FA56B94D55 200 1124276674 -1 -1 unknown -1/0 POST http://reports.hotbar.com/reports/hotbar/4.0/HbRpt.dll
  2. 1124392388.975 RELEASE -1 FFFFFFFF 810FFBF233584C330353CF0A8C31F5D2 503 -1 -1 -1 unknown -1/813 POST http://log.cc.cometsystems.com/dss/cc.2_0_0.report_u
  3. 2007-05-19 03:55:12 160 10.1.1.3 - - - OBSERVED "Spyware/Malware Sources;Spyware Effects;Web Advertisements" - 200 TCP_NC_MISS POST text/html;%20charset=utf-8 http bis.180solutions.com 80 /versionconfig.aspx ?did=5342&ver=1.0 aspx - 10.1.1.2 273 175 - - none - -
  4. 2007-05-21 03:10:40 4 10.1.1.3 Joanna- authentication_redirect_to_virtual_host PROXIED "Search Engines/Portals" - 307 TCP_AUTH_REDIRECT POST - http storage.msn.com 80 /storageservice/schematizedstore.asmx - asmx "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; MSN Messenger 7.5.0324)" 10.1.1.2 791 2566 - - none - -

Here are some other signs that will make the above log entry extra-suspicious is:

  • A dead giveaway: upload happens to a "known bad" URL (e.g containing "gator" and others above) 
  • Upload happens to an unresolved IP address (do a "whois" on it!)
  • Uploads happens to a port not equal to 80 (i.e. the URL contains a port such as http://10.1.10.10:31337)
  • Upload has confidential file name in the log entry (e.g. somebody dumb emailing a sensitive file to himself - as discussed here)

Overall, this log analysis method is good for casting a broad net to catch not just spyware-infected systems, but also unauthorized applications (e.g. method=POST and user-agent=iTunes), instant messaging (e.g. method=POST  and then by user-agent, content or URL), simple forms of data theft and document handling policy violations (emailing files to self via web mail: method=POST and sensitive file name present in the entry; also content type set to popular file types) as well as other abuses of web access. As a result, proxy logs provide an extremely rich AND readily available source of data about threats that users face!

To top it off, one promising direction of future research is using web proxy logs to detect client-side exploits by malicious web servers (more on this in the near future!)

Possibly related posts:

Also, I am tagging all the tips on my del.icio.us feed. Here is the link: All Security Tips of the Day.

Technorati tags: , , ,

Friday, August 03, 2007

A "Deep" Thought on WSJ Debacle

Remember this poll I did a while ago? I asked about the willingness to break various security policies. And the results were indeed fun! So, this WSJ debacle made me think about policies and enforcement; thus a new poll:

Will you break a security policy if you know it is neither enforced nor monitored AND that there can be no repercussions whatsoever (and YOU personally don't think it is sensible - EVEN THOUGH you might not be an authority on all risks ...)?

Here is the poll on that! Vote away!!!

Wednesday, August 01, 2007

Hello, Mr Darwin!

"Hello, Mr Darwin!" - "Hi there."

IT user "gene pool" will probably lose some of its stupidest critters as a result of reading this WSJ article, which is making round in the security community: "Ten Things Your IT Department Won't Tell You."

It starts like fun for some and like utter nightmare for others: "we use our office PCs to keep up with our lives. We do birthday shopping, check out funny clips on YouTube and catch up with friends by email or instant message."

Niiiice. It gets better:

"There's only one problem with what we're doing: Our employers sometimes don't like it." :-) Geee, I guess "some-other-times" they do :-)

OK, great, now what? This:

"To find out whether it's possible to get around the IT departments, we asked Web experts for some advice. [...] How to surf to blocked sites without leaving any traces, for instance, or carry on instant-message chats without having to download software."

And then it all rolls neatly downhill from there; check out such fun items as "6. HOW TO STORE WORK FILES ONLINE" (A "no-brainer" (indeed you are...): "Use an online-storage service") and "8. HOW TO ACCESS YOUR WORK EMAIL REMOTELY WHEN YOUR COMPANY WON'T SPRING FOR A BLACKBERRY" (Wonder how? Eeeeeasy: "Just set up your work email so that all your emails get forwarded to your personal email account." :-)). Even such gems as "7. HOW TO KEEP YOUR PRIVACY WHEN USING WEB EMAIL" (answer: encrypt it!) are there.

But you know what? There is nothing wrong with publishing this; such violations are clearly not rocket science. In fact, there are three possible outcomes:
  1. Users do this and are caught, then fined, fired, tortured, shot and otherwise abused. Awesome! :-)
  2. Users do this and are NOT caught since you don't really enforce your policy banning such activities. In fact, you - the security pro - don't even know that they are breaking the rules. Sorry, you suck! You need to get another job before your company is sued ...
  3. Users do this and are NOT caught since they manage to bypass the deployed security controls. Ah, this is a fun one; that is what makes security a "calling, not just a job" for so many. Go back and deploy, tune, log (yes, logging all such activities is important, especially when HR wakes up and swings the ax...) and have fun. 0days and mafia hackers might be more challenging to fight, but users are surely more numerous :-)
Overall, I expect more security bloggers to jump and dropkick this paper. Let the fun begin!

Worm vs Thief: Take Your Pick

At a recent security conference (as many mentioned, presentations are not even half the value of such events!), I had this eye-opening chat with a guy who manages security at a large "natural resource extraction" company (to avoid specifics ...). The conversation moved towards "data security" vs "IT infrastructure security," which I always thought to be a somewhat artificial distinction (they are kinda the same since the sole purpose of IT infrastructure is to process and move data around). However, for this guy the difference was very real; in fact, he said: "I'd rather have all my critical systems fell to a worm than have the details of my mining process stolen and possibly disclosed! We will go out of business the next year." I argued that surely his company has more assets and "crown jewels" than that, but he explained that there are key pieces that, if purposefully stolen, will cause the worst case scenario to manifest ...

This doesn't sound like a super-deep insight, but it is! Days of people shaking in their boots while thinking of the next ILOVERYOU and Slammer are over. Even though anti-malware defenses aren't perfect and worms are not truly dead (although less relevant), it seems that the threat can be considered manageable rather than overwhelming. Notice that "manageable" is not the same as "gone" or "non-existent."

However, data theft is very real, and that is what makes security managers of today shake in their boots (and those who don't - MUST! :-)): having your very key data stolen, sold, possibly disclosed and you - the guardian of such data! - not even knowing how and by whom. We can blab about how hard data classification and sensitive information discovery are, but just do this simple exercise (and consult with your peers, if unsure): theft of which piece of data will make your company go away?! Afterwards, go to the system where such data resides and make pretty darn certain that you log every tiny "fart" :-) that such system and all of its components produce ... You'd be glad you did - your employer's future and thus your job may depend on it!

Possibly related posts:

Dr Anton Chuvakin