Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Sunday, November 23, 2008

Bad Blogger

Okay I'm just going to admit it and stop being in denial: I'm a bad blogger! There I feel better now. With that said I offer the following jem.

How Security Became an Issue

It is interesting to pick up various computer books and see that there is usually a history section that sets the stage for where society is today pertaining to computing and data processing. Unlike histories that tell of times long past, the history of computing typically begins in the 1960s. A lot has happened in a short period of time, and computer security is just starting to reach its time in the limelight.

Roughly twenty-five years ago, the only computers were mainframes. They were few and far between and used for specialized tasks, usually running large batch jobs, one at a time, and carrying out complex computations. If users were connected to the mainframes, it was through “dumb” terminals that had limited functionality and were totally dependent on the mainframe for their operations and processing environment. This was a closed environment with little threat of security breaches or vulnerabilities being exploited. This does not mean that things were perfect, that security vulnerabilities did not exist, and that people were in a computing utopia. Instead, it meant there were a handful of people working in a “glass house” who knew how to operate the computer. They decided who could access the mainframe and when. This provided a much more secure environment, because of its simplicity, than what we see in today’s distributed and interconnected world.

In the days of mainframes, web sites describing the steps of how to break into a specific application or operating system did not exist. The network stacks and protocols being used were understood by very few people relative to the vast number of people that understand stacks and protocols today. Point-and-click utilities that can overwhelm buffers or interrogate ports did not exist. This was a truly closed environment that only a select few understood.

If networks were connected, it was done in a crude fashion for specific tasks, and corporations did not totally depend on data processing as they do today. The operating systems of that time had problems, software bugs, and vulnerabilities, but not many people were interested in taking advantage of them. Computer operators were at the command line and if they encountered a software problem, they usually just went in and manually changed the programming code. All this was not that long ago, considering where we are today.

As companies became more dependent on the computing power of mainframes, the functionality of the systems grew and various applications were developed. It was clear that giving employees only small time slices of access to the mainframes was not as productive as it could be. Processing and computing power was brought closer to the employees, enabling them to run small jobs on their desktop computers while the big jobs still took place within the “glass house.” This trend continued and individual computers became more independent and autonomous, only needing to access the mainframe for specific functionality.

As individual personal computers became more efficient, they continually took on more tasks and responsibilities. It was shown that several users accessing a mainframe was inefficient and that some major components needed to be more readily available so that users could perform their tasks in an efficient and effective way. This thinking led to the birth of the client/server model. Although many individual personal computers had the processing power to compute their own calculations and perform their own logic operations, it did not make sense that each computer held information that was needed by all other computers. Thus, programs and data were centralized on servers, with individual computers accessing them when necessary and accessing the mainframes less frequently.

Tuesday, April 01, 2008

Money, It's a Gas...

I can say that for the most part INFOSEC continues to be an "after thought" as a reaction to OMG we just lost 40,000 PII records and now we have to go before a congressional committee explaining why we lost Senator "X" PII.

The key problem isn't the lack of laws, technology, or even smart IT Security folks to make it work. The problem is that the stupid people out number the smart people on a grossly, and frightening, scale.

To compound that problem the people who control the money are not the smart people but the stupid people in the accounting offices. Most of whom are, you guessed it, accountants who do not understand the fuzzy logic of IT Security.

My mother is a CPA, and god bless her I love her very much, but if even so much as a cent is out of place she goes nuts finding it and find it she does. That is her job and what she understands.

When I try and help her with IT issues the same binary thought process kicks in. She will complain that "my computer is slow" and the response is to buy a new one because binary logic says that if the computer is slow it is because the computer is old and should be replaced.

To an IT Security person we would look at the system from a holistic perspective and not from the single variable. The main reason her laptop, which was only 1 year old, was slow is that she loaded it with junk programs and the operating system did what it always did and filled up with Cr@p. So over time the system kept tracking down a death spiral until it started blue screening.

In that there lies the other problem we face to get budget needed to meet the objectives outlined by the stupid people. The level of complexity of information security issues can't be solved by buying a new shinny widget (laptop). The business must be understood and the impact to the business must be made clear if the IT assets supporting the business are negatively affected in any way.

Yet the stupid people, who control the money, don't understand that this level of detail isn't a nice thing to have it should be a required thing. But seriously look at who is really running your show (business) and ask yourself "would they know how to get to grep?" or "do they understand what happens when they ask to run a network scan at 2 pm on Thursday before payroll gets sent out the next day?" or, and my personal favorite "I need an exception to Proxy rules for one person.... to which I say why? and the response is "because" and I say this will mod the Proxy for the entire agency... and the response is "So?"

Just remember who we are all dealing with. I'm not saying these people are bad or even malcious in their intentent. It's just that dumb and dumber are running the show and those of us who have a clue are out in the cold wondering how we got locked out of the warm cabin again.

Proving to the dumb and dumbers that money spent on IT Security is worth while will never be an easy chore because we will always be a cost center.
What do CFOs love to do most and most often? Seek and Destroy cost centers! It is there mission in life and forget trying to explain that not upgrading an network intrusion sensor will leave them vulnerable because the requirement states they have to have NIDs in place.

It falls back to the CPA that says I have NIDS so I am good to go. When in reality the NIDS in place are worthless beacuse the are end of life and can't upgrade to cover the lattest IDS signatures.

But the CPA that lives in every CFO and manager says I'm covered so why worry?

Sunday, January 20, 2008

Transparency Arrived Today

I see the disconnection between the user and what is really going on under the hood in the same way we see people on the freeway disconnected from the chaos just a few inches away. I think the way to break the "hamster wheel of pain" is to stop treating risk as a model that all things form into. Rather we need to factor risk as a "driver" in a machine we'll call the Automated Processing Environment (APE).

The APE is essentially stupid slow and constantly vulnerable to attack from smaller, faster, and more agile life forms. The ape isn't simply a collection of hardware, software and security controls. It is physical, human, and logical. I believe that we have to move on from the SDLC, CIA, and all models that have been crafted before this time because the complexity of attacks that we see in our environments simply can not be captured with current thinking in a way that helps us move forward.

If we shift the paradigm and factor in that, at the most basic level, we have human, physical, and logical assets all interacting with one another in a constant state of flux it becomes next to impossible to authentically predict, or better yet, assess the risk posture of the APE. The piece meal approach to providing a “cure” to the information security challenges simply will not make muster any more. We must address all components at once. Why? If all pieces of the APE triad (Human, Physical, or Logical) are not addressed at the same time, and with the same vigor, than the triad will collapse, and once again become vulnerable from the segment that was not equally bolstered. I've talked about transformation before in previous posts but I think that trying to improve one section at a time will never work because we will always be chasing the "tail of the dragon".

The same is true for mitigating risk to data. All too often I have seen huge efforts to implement technical solutions that do yield "a result" but that result is never fully understood. Manufacturers love to show dashboards showing all the security data that has been collected but in the end the dashboard serves no tangible purpose to understanding what is going on in the APE.

To break the cycle we must change the way business is done. We must become more closed and bring more sensitive data closer to home. This could be done by "purging" all sensitive data from systems that are in the wild and bring the data literally inside the walls of the Data Center. We need to move to a use of both the client/server and the more feudal approach of thin client architecture that pulls data processing into centrally managed activities in order to strike a risk based cost balanced approach. An awareness of who, what, where, and when sensitive data is being processed will help reduce the threat of loss of the data into the wild. Just like a diamond on display in a museum is protected but shared through the exhibition.

But by far the greatest weakness in the APE triad is the human factor. Behaviors must be modified and addressed immediately upon discovery. When I worked the flight line I saw folks sent home immediately after any kind of accident. One case sticks out in my mind at SFO where the tug driver ran a container into the side of an aircraft. He immediately was sent for a drug test and ordered to take a week without pay. Hence I would say the level of intensity and focus during a turn around was extreme. The danger was present and the risks real. That fear does not exist in the mind of the average user but should in those APE users that roam in a hostile world.

To be truly transparent means not only to report the control failures but to have visibility into any area of the enterprise allowing issues to be fully and freely expressed before they manifest themselves into security events.

Wednesday, October 24, 2007

Three Laws Strong - Rules to Live by

Rules that all Information Security practitioners should follow.

1. An Cyber Security Professional (CSP), or anyone one assigned information security responsibilities, may not injure a human being or, through inaction, allow a human being to come to harm.

2. A CSP must obey orders given by customer, client, or senior manager except where such orders would conflict with the First Law.

3. A CSP must protect its own existence as long as such protection does not conflict with the First or Second Law.

If it's good enough for AI then it's good enough for me; eh?

Friday, October 12, 2007

Seperate but equal?

I delivered a paper this week to help define the
relationship between operational security and our friends in the IA
security world. I believe because my "gut" tells me that the truthiness
(http://en.wikipedia.org/wiki/Truthiness) that we as information
security practitioners are growing in the way of doctors and lawyers.
After all you don't send a Trial Lawyer to sort out the settlement of an
estate and you don't send a Proctologist to deliver a baby; eh? We have
specialists and generalist, coders and admins, and yes the dark side
wonkers.

In my paper I proposed that information security should be a synergy
between three components; security engineering, information assurance
(policy & procedures), and security operations (NOC/SOC/CSIRC). Just as
the space shuttle has multiple redundant systems organizations should
have checks and balances (speed bumps) to ensure that technology isn't
put into production until the risks that the technology will induce are
mitigated. I'm wondering if this approach is too theoretical or am I
stretching the concept of least privilege and separation of duties too
far? I contend that those principals are applicable to not only systems
and individuals but on an organizational level as well. Integration is
a great thing but isn't it possible to take integration too far to the
point where the lack of complexity becomes a vulnerability unto itself?

SYOP Malware?

Here is a thought: Put some code on your company laptops that fires up in the middle of the night and plays an mp3 or wav file with what ever message you like? You could "program" you employees to be more security aware and hopefully not expose your network, company assets, or personal records to malicious attackers.

A dark side application could be the infection of your competions computers such that subtle but disturbing sounds are played during the night so as to disrupt normal sleep but not awaken the target fully. Thus over a short period of time the target company would grow fatigued from sleep deprivation and thus your team would have the advantage of being better rested.

I wonder if this has been done?

Think before you click G@D dammit...

I recently saw an incident where an employee at an agency component told her staff to send emails to her at home. No big deal if she was using government equipment all the way. Trouble is that this person was responsible for buying things and reimbursing people so she had names, credit cards, etc. What made it an incident was that she directed these folks to send the information to her Yahoo account. "It's MY email account and no one else can get to it because I use a good password". I can't say what happened to her but in my opinion it wasn't harsh enough.

We can have the best written policies, outstanding detection and prevention technology, and leaders who understand that risk management is the way forward but if we don't have tangible disciplinary discretion how can we wake people up to the fact that we are only one click away from undoing every security measure that we put in place?

It's not like we don't design training programs to get the word out. My feeling is that 90% of the people that come to work are borderline zombies. For them it's just a matter of showing up getting the bare minimum done to collect a paycheck so they can sit in traffic for 3 hours only to go indoors, sit more, watching television with mindless drool flowing out of the screen and completing more chores. Followed by wash, rinse, repeat. An endless cycle of routine and work. I think I heard on the HBO fictional show "Oz" one of the characters talking very much in the same way about prison life.

I look into the eyes of the people I see on the street and what I see is blinding ignorance. I was at one of the better pizza places here in Denver and was chatting up the hostess. (yes with the mostest and I was wearing my ring) She asked me what I did and got into a discussion on my favorite topic "personal security" to which she replied as I have heard a hundred times before "I don't care" and "what would anyone want with my information" going on she said "what's the difference anyways I'm broke they can take it all."

I don' know how long this has been going on but I am certain that we live in a culture of indifference. Indifference to one another and to ourselves. American's don't seem to care about the "how" just the "now". Living for the next "Mocha - Latte - frothy - soy - Ventti" sugar buzz to the next instant download followed by hours of mindless cr@p instantly accessible on a DVR while continuing the ongoing festival of gluttony consuming the latest iteration of the deep fried "corn chip" that unto itself is the same corn chip that was consumed a year ago but has a "new and exciting" packaging that makes it easier to inhale these chips with one hand only while in the other hand wash all of those chemicals and preservatives down with a high fructose corn syrpe beverage loaded with enough caffeine to kill a small cow which incidentally is the next generation of slaughter house product.

So before you click and send that next email or click on the next ballet please for the love of all that is still good in this world think about it. Are you just buying some repackaged, rebranded, piece of c#ap? Are you about to expose your entire organization or even your family to risks that you don't even fully understand yourself? So please people think, I know it's hard and all you want to do is curl up on the couch and "relax" but don't do it. Don't give up and choose to spend the rest of your life as the walking dead. Don't do it for me, don't do it for your family, don't even do it because living a full life is better than living an empty one, choose to think because if you don't you might as well be dead now and you're not helping anyone else by choosing that.

Tuesday, May 22, 2007

Confessions of a WONK Part 1

Another day has dawned in the information security salt mines. I'm throwing up a couple of quick posts to create a lattice for future development and expansion. I want to open a discussion about all those people who don’t understand information security. Let’s call them WONKS.

I’ll talk about what that is latter but for now I wanted to share an experience I had where a information security project manager could not process that an incident that was being called out from outside an organization was less important than a vulnerability report that was due. The issue really came down to limited resources and only one engineer to get NIDS up and running so as to allow the capability to see what was going on at least from the network perspective. By the way note I said "get the NIDS up and running" as they were racked but not operational.

I think it is a not so secret dirty fact that most organization don’t have a clue what is going on inside the perimeter!!!! These are critical issues we have in our industry. We have too many people who claim to be part of information security but in reality just feel into this area of Information Technology (IT) or were doing something else and then got the dual hat of information security and the job they were doing which had little to nothing to do with information security. So in the follow up to this post “Confessions of a Wonk” I’ll talk about the various breeds of WONKS and the overarching need to mitigate there presence in our field.

I’ll put it another way in the form of an experience I had when I was working in the Aerospace Industry as an FAA Certified Airframe & Powerplant (A&P) technician. At the time I was working L-1011 “C” checks for American Trans Air out of Indianapolis, IN and was working with a guy who some how passed his A&P exam and got hired in as one of the other contractors. (We were all contractors at the time.) I saw him beating on a part of the airplane and immediately stopped him. I asked what he was doing and he proceeded to tell me a story. I asked him a few questions and then got into a “conversation” with him about professionalism and what it meant, for me at least, to be to be privileged to be able to work as an A&P and bear the responsibility of certifying airworthiness of the aircraft that I was entrusted with.

To which his response was I am just doing this because “It’s just a Job”. My response to that was then you need to think about another line of work before you kill yourself, maybe not a bad thing given his attitude towards his chosen profession, or worse, he kills a lot of other people. The same holds true for the WONKS. You need to seriously evaluate if this is the place you want to be.

If you want to be here, GREAT! Welcome! But understand that with that choice to be here you need to accept the responsibility of your choice and get that this is not just a job anymore. You can not just punch in and punch out when you feel like. As Information Security Professionals we, in some cases, literally hold the responsibility of life, property, and for the privileged few the very security of our nation. We are all part of a very young and immerging profession and believe it when I say that we have everything to prove and everything to lose right here and right now. The very core of the IT industry has begun shifting to ever cheaper and ever less experienced labor.

I saw the exact same thing happen in my previous life as an A&P technician. What amazes me is how fast the IT industry is shifting. What took the Airlines 40 years to do the IT industry has done in 10 years. That being that once, about 15 years ago, if you were in IT you could feel good about your work with some level of job security. We still have a chance to turn things around for information security. We need to codify ourselves beyond what ISC and other organizations are offering.

Yes I believe that organizations like ISC and SANS are doing great things but if we don’t take it to the next level and standardize what it means to be an information security practitioner and the various levels and areas of what that title means then we risk loosing control over our own destiny. When I was an active A&P technician I was privileged to be able to have advanced training that in essence type rated me to specific technologies. In Europe type rating means you can only work on a specific aircraft and be able to have the legal authority to return that specifc tpye of aircraft to service.

For example I have, although out of date, a Boeing 757 General Familiarization. This means that I have specialized training on the Boeing 757 and all the systems on that aircraft. Another type rating that I was privileged to hold was Category (CAT) II/III [AUTOLAND] Avionics certification. This meant that I was authorized under the carriers CAT II/III certificate to maintain, repair, test, and most importantly have the legal responsibility to return the system to service through signature authority for the autoland capabilities of the *MD-11 that I was certified on.

We need a similar system of controls on ourselves to escalate our profession. We need to consolidate and have an authority that won’t be shifted, moved, or corrupted at all to hand out certifications. We need to also have a system in place where the work that a person does as a security professional is held accountable to that person for life. I’m not saying anything that I am not already on the line for. For all I know there is a airplane parked in the desert somewhere with my signature on it.

I will be legally responsible for that aircraft and the people that fly on it until another A&P does the same work I did and signs off on it or until the airframe is destroyed. We need that level of accountability now. Sadly just about anyone with a normal IQ and enough money can get a CISSP by going to enough boot camps. That doesn’t mean the person knows anything about how information technology works. It simply means they had a lot of money and can pass the exam.

When I sat for my CISSP exam I met a lady who was taking the exam not because she involved in information security but because her company mandated that she have the certification as her sales department worked with the information security elements of companies and agencies that bought her product. So she was a sales rep taking the exam purely to look good to clients and for no other reason.

In all fairness and at the core of the “confession” is that I too was a WONK and only by understanding my inner WONK am I able to accept what I was and move on to be the security practitioner I know I am. So to all the folks who falsely claim the title of “Information Security Professional” but who just don’t get it please understand that there is nothing personal in this but that it is time for you, as I did, to wake up smell the burning data center, get smart or get out.

The world that we manage from the digital perspective is just too important for you to stay ignorant any longer. We need every single person who is working in the field of information security to be dedicated to one universal principal of transforming this industry to beyond everything that we know today if we are ever to have the hope of moving from detection and reaction and away from being hunted to being the hunters.

*[For those who don’t know most of the time when weather and visibility is poor the airplane lands itself. Also for the general public airline pilots don’t actually fly the plane most of the time. The onboard Flight Management Systems (FMS) do all the heavy lifting and pilots are trained not to fly the plane but let the FMS do it as the FMS can fly the plane with higher levels of fuel efficiency. Also another feature of FMS is that central maintenance control can see in real time what the airplane is doing and more importantly from a cost perspective what the engines are doing through the Full Authority Digital Engine Controls (FADEC). ]