<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>Network Security</title><link>http://bmonday.com/category/2.aspx</link><description>Network Security</description><managingEditor>Beau Monday</managingEditor><dc:language>en-US</dc:language><generator>.Text Version 0.95.2004.102</generator><item><dc:creator>Beau Monday</dc:creator><title>This might become my new email signature</title><link>http://bmonday.com/archive/2008/05/24/4663.aspx</link><pubDate>Sat, 24 May 2008 00:32:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/05/24/4663.aspx</guid><wfw:comment>http://bmonday.com/comments/4663.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/05/24/4663.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4663.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4663.aspx</trackback:ping><description>&lt;P&gt;Mike Rothman, of &lt;A href="http://www.pragmaticcso.com/"&gt;Pragmatic CSO&lt;/A&gt; fame, laid down one of the best one-liners of all time in a &lt;A href="http://securityincite.com/TDI-2008-05-12#TBP2"&gt;recent blog post&lt;/A&gt;:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;It's about serving the business, NOT THE AUDITORS. If you protect information effectively (which is a key imperative for the business), then the auditors should be kept reasonably happy. And if not, screw them and fight them. Yes, the auditor can make your life a bit harder, but you don't work for them. Keep that in mind.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;OK, technically, that's a five-liner, but you get the point.&lt;/P&gt;
&lt;P dir=ltr&gt;I can't tell you how many companies I've seen spend a million dollars a year on auditors, yet spend 1/10&lt;SUP&gt;th&lt;/SUP&gt; of that on actual security improvements.&lt;/P&gt;
&lt;P dir=ltr&gt;That's bass ackwards.&amp;nbsp; If you have your ducks in a row, security-wise (it *is* a key imperative of your business), the auditors should be in and out.&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4663.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>Even a broken clock is right twice a day</title><link>http://bmonday.com/archive/2008/05/24/4662.aspx</link><pubDate>Sat, 24 May 2008 00:01:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/05/24/4662.aspx</guid><wfw:comment>http://bmonday.com/comments/4662.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/05/24/4662.aspx#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4662.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4662.aspx</trackback:ping><description>&lt;P&gt;I'm a rather pragmatic security practitioner.&amp;nbsp; If I think something is dumb, even if it's on someone's &amp;#8220;Best Practices&amp;#8220; list, I'm not above calling it out.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Some examples:&amp;nbsp; I think, in the majority of cases, antivirus on a server is dumb.&amp;nbsp; I think renaming your Administrator account is dumb (almost all tools that attack Admin now do so using the SID).&amp;nbsp; I think account lockouts are dumb (they are a crutch for weak passwords).&amp;nbsp; I think writing down a strong, complex password is better than using a weak password&amp;nbsp;if that's all&amp;nbsp;you can reliably remember (no, don't then stick it to your monitor, that *is* dumb).&lt;/P&gt;
&lt;P&gt;I also think &lt;STRONG&gt;Disaster Recovery is not a security function&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Yeah, I said it.&amp;nbsp; Out loud.&amp;nbsp; I've been saying it for years actually.&lt;/P&gt;
&lt;P&gt;&amp;#8220;But Beau,&amp;#8221; I hear you saying, probably in an exasperated voice, &amp;#8220;*availability* is one of the Holy CIA Trinity (Confidentiality, Integrity, Availability)!&amp;#8221;&lt;/P&gt;
&lt;P&gt;Yeah, and?&amp;nbsp; Step carefully or I'll punt those other 2 legs out of Security too.&lt;/P&gt;
&lt;P&gt;I've long held the belief that the Operations side of the house has far more responsibility when it comes to Availability than Security does.&amp;nbsp; Hell, most IT operations teams are measured by their availability, and not a lot else.&lt;/P&gt;
&lt;P&gt;If a disaster strikes, who is going to be putting the pieces back together?&amp;nbsp; Security?&amp;nbsp; Nope.&amp;nbsp; Operations, and maybe some Network guys if the recovery site is raw.&amp;nbsp; Security will be *involved*, of course, but only peripherally.&lt;/P&gt;
&lt;P&gt;Security's role is making sure disaster planning is getting done by the appropriate people, and implementing supporting policies and controls.&lt;/P&gt;
&lt;P&gt;Actually, that describes Security's role in the other 2 domains too.&amp;nbsp; The people in the trenches on Confidentiality is the Privacy team (read: the lawyers).&amp;nbsp; The auditors are the leads on Integrity.&lt;/P&gt;
&lt;P&gt;Now is usually the time most security people get all woozy and I have to start passing out smelling salts.&lt;/P&gt;
&lt;P&gt;So, imagine my surprise when one of the most respected security guys I know, Richard Bejtlich (he's the &lt;A href="http://taosecurity.blogspot.com/"&gt;TaoSecurity&lt;/A&gt; link at the bottom of my BlogRoll to the right), posted pretty much my standing belief in this regard.&amp;nbsp; From his post on Wednesday, entitled &lt;A href="http://taosecurity.blogspot.com/2008/05/security-whose-responsibility.html"&gt;&amp;#8220;Security: Whose Responsibility?&amp;#8221;&lt;/A&gt;:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;I assume readers of this blog are familiar with the "CIA" triad of information security: confidentiality, integrity, and availability. Having spent time with many companies in consulting and corporate roles, it occurred to me recently that two or even all three of these functions are no longer, or may never have been, the responsibility of the "security" team. &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;He demonstrates his vision using this graphic, which I have not previously seen:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;&lt;IMG src="/images/cia-circles.jpg"&gt;&lt;/IMG&gt; 
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;He goes on to define what he feels Security's role is:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;I believe this state of affairs leaves the Security team as the one group that has the proper mindset, subject matter expertise, and ability to implement defensive operations to preserve CIA. This mission is not one the Security team accomplishes by itself, if that ever were possible. Rather, Security will (if not already) need to pair itself with IT, Audit, and Privacy in order to be effective. One could say the same for and Compliance groups, Governance officers, and/or Physical Security teams, although I'm less worried about those ties right now.&lt;BR&gt;&lt;BR&gt;It should be clear at this point that it doesn't make sense for the Security team to work for IT, given the role it must play. A Security team working for IT is likely to be stuck supporting the Availability aspect of "security" at the expense of the other CIA elements. Furthermore, it could be difficult for Security to build the necessary bonds with Audit and Privacy if those groups see the Security team as "just part of IT," or "technologists." &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;This second&amp;nbsp;part is very interesting, because building those bonds with the CIA-supporting organizations is precisely what Gene Kim's new book, Visible Ops Security addresses.&amp;nbsp; And it surely is a gap today, which is why I'm glad someone's making efforts to highlight it.&lt;/P&gt;
&lt;P dir=ltr style="MARGIN-RIGHT: 0px"&gt;OK, give me back my smelling salts now.&amp;nbsp; I'm going to go freak out some lawyers.&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4662.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>Identifying Stale Machine Accounts</title><link>http://bmonday.com/archive/2008/05/09/4636.aspx</link><pubDate>Fri, 09 May 2008 14:51:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/05/09/4636.aspx</guid><wfw:comment>http://bmonday.com/comments/4636.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/05/09/4636.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4636.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4636.aspx</trackback:ping><description>&lt;P&gt;I'm sick of googling for this&amp;nbsp;the few times per year I need it, so putting it here for future reference:&lt;/P&gt;
&lt;P&gt;To identify stale computer account in your Active Directory, you can look at the last time they changed their passwords.&amp;nbsp; Windows 2000 and later machines will change their computer accounts every 30 days by default.&amp;nbsp; Machine accounts that have gone more than 30 days without changing their account passwords are probably no longer in use (or they have a problem preventing them from communicating with the domain controller(s)).&lt;/P&gt;
&lt;P&gt;The easiest way to enumerate machine account password age is a free tool called &lt;A href="http://www.systemtools.com/free.htm"&gt;NetPWAge&lt;/A&gt; by the folks over at SystemTools.com.&amp;nbsp; Once downloaded, the syntax is simple:&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;
&lt;P&gt;&lt;FONT face="Courier New"&gt;NetPWAge /machines /domain:YOURDOMAINHERE /tabs &amp;gt; MachineAccts.txt&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;You can paste or import the results into Excel and do some fancy sorting to find out which machines need to get the boot.&lt;/P&gt;
&lt;P dir=ltr&gt;Edited to add:&amp;nbsp; I should mention that domain controllers themselves do not follow the 30-day rule, so don't go deleting them based on this scan.&amp;nbsp; You know not to go deleting your domain controllers though, right?&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4636.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>Scars of 9/11</title><link>http://bmonday.com/archive/2008/04/15/4623.aspx</link><pubDate>Tue, 15 Apr 2008 23:28:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/04/15/4623.aspx</guid><wfw:comment>http://bmonday.com/comments/4623.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/04/15/4623.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4623.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4623.aspx</trackback:ping><description>&lt;P&gt;I've never told this story, not even to my family.&lt;/P&gt;
&lt;P&gt;9/11 is why I'm in the security business.&amp;nbsp; Corny as it sounds, when 9/11 happened, I decided that the way I could contribute to&amp;nbsp;making the world a better place&amp;nbsp;was to apply my IT knowledge to securing the world's Windows networks.&amp;nbsp; I had flown out of Logan airport in Boston the day prior to the attacks.&amp;nbsp; I was galvanized.&amp;nbsp; I quit my job, put myself through a number of SANS courses, and focused my 15+ year old IT career towards security.&lt;/P&gt;
&lt;P&gt;I even traded my BMW in for a Jeep, in a semi-rediculous gesture of patriotism (Jeep was subsequently acquired by Germany's Daimler Corporation, ironically).&lt;/P&gt;
&lt;P&gt;To say that 9/11 was a defining moment for me would be an understatement.&lt;/P&gt;
&lt;P&gt;Now the weird part:&lt;/P&gt;
&lt;P&gt;Since 9/11, I've had a little &amp;#8220;twitch&amp;#8221;.&amp;nbsp; A day rarely goes by when I don't look at a clock when it hits 9:11.&amp;nbsp; Either in the morning or at night, my subconcious rarely misses the opportunity to note the passing of 9:11 by drawing my attention to a nearby clock at that hour.&amp;nbsp; It's fucking creepy.&lt;/P&gt;
&lt;P&gt;So tonight, as I fed &amp;#8220;I Am Legend&amp;#8221; into the DVD player, I glanced down at the clock and was surprised to see it read 9:12.&amp;nbsp; Holy Christ, I made it through an entire day without&amp;nbsp;marking&amp;nbsp;9:11.&amp;nbsp; A rare thing.&lt;/P&gt;
&lt;P&gt;A couple hours later, I logged into a computer in Seattle to service some&amp;nbsp;waiting firewall tickets.&amp;nbsp; Look down at the clock on the computer in Seattle, and guess what it reads.&lt;/P&gt;
&lt;P&gt;Nine fucking eleven.&lt;/P&gt;
&lt;P&gt;Sigh.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Never forget.&lt;/P&gt;
&lt;P&gt;Now if you'll excuse me, I've got some firewall changes to make.&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4623.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>RSA Connections</title><link>http://bmonday.com/archive/2008/04/11/4619.aspx</link><pubDate>Fri, 11 Apr 2008 21:31:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/04/11/4619.aspx</guid><wfw:comment>http://bmonday.com/comments/4619.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/04/11/4619.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4619.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4619.aspx</trackback:ping><description>&lt;P&gt;RSA is 50% learning and 50% networking.&amp;nbsp; At roughly 17,000 attendees, it is far and away the largest gathering of information security practitioners and vendors.&amp;nbsp; You make professional connections here that you cannot otherwise make.&lt;/P&gt;
&lt;P&gt;The Peer-to-Peer sessions are networking gold.&amp;nbsp; You have 20 people all struggling with some particular aspect of the business, and you generally leave with the personal contact information from at least half of them.&amp;nbsp; The world's information gets more secure as a result of these short sessions, and the&amp;nbsp;relationships we build&amp;nbsp;after the event is over.&amp;nbsp; Unfortunately, due to the small number of people permitted into them, they fill up quickly.&lt;/P&gt;
&lt;P&gt;The Virtualization Security peer-to-peer session is a great example.&amp;nbsp; I talked to one guy who told me about a network problem causing all his VM hosts to shut themselves down.&amp;nbsp; I chuckled and said &amp;#8220;Yeah, we made that mistake too.&amp;#8221;&amp;nbsp; I then told him about another hitch we had implementing VMotion that caused a similar problem, and by the fact that his eyes went wide when&amp;nbsp;I described it to him, I'm guessing he's probably vulnerable to that too.&amp;nbsp; Those are the little things that don't get discussed in the technical sessions.&lt;/P&gt;
&lt;P&gt;Another great contact I made during the show was Gene Kim, author of one of my favorite books of all time, The Visible Ops Handbook.&amp;nbsp; I saw him sitting at the book store, doing signings, purely by chance.&amp;nbsp; I introduced myself, and told him we'd bought&amp;nbsp;30 copies of his book for&amp;nbsp;our staff, and that I had won a corporate award for implementing a change management program based on his work, and he just gushed and said I made his entire week.&amp;nbsp; He shouted over to one of his partners &amp;#8220;Hey they gave this guy an&amp;nbsp;award due to Visible Ops!&amp;#8220;&amp;nbsp; I bought copy #31 from him on the spot so he could sign it (he wrote that my kung fu was awesome), along with his latest release Visible Ops Security, which I have not yet read.&amp;nbsp; Gene's nervous about his new book, since he's not a security practitioner and is anxious about how the community will react.&amp;nbsp; So he asked me to give him an honest review of it after I've had time to read it.&amp;nbsp; Then he gave me his card, and wrote his cell phone number on it.&amp;nbsp; Dude, I have Gene Kim's CELL PHONE NUMBER.&amp;nbsp; How cool is that.&amp;nbsp; Where the hell else would that have happened, but at RSA?&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4619.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>RSA Random Links</title><link>http://bmonday.com/archive/2008/04/11/4618.aspx</link><pubDate>Fri, 11 Apr 2008 20:57:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/04/11/4618.aspx</guid><wfw:comment>http://bmonday.com/comments/4618.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/04/11/4618.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4618.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4618.aspx</trackback:ping><description>&lt;P&gt;Here are some interesting links that I noted during RSA.&amp;nbsp; These are mostly for my own benefit, but I won't tell anyone if you click on them.&amp;nbsp; I'm not the boss of you.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Symantec Threat Report - 2nd Half of 2007: &lt;A href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_exec_summary_internet_security_threat_report_xiii_04-2008.en-us.pdf"&gt;Executive Summary&lt;/A&gt;, &lt;A href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_internet_security_threat_report_xiii_04-2008.en-us.pdf"&gt;Full Report&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-05.pdf"&gt;US Government's&amp;nbsp;Trusted Internet Connection Initiative&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://blogs.oracle.com/maryanndavidson/2008/04/08#a286"&gt;Oracle's call for better secure coding education at the university level&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://nvd.nist.gov/fdcc/index.cfm"&gt;Federal Desktop Core Configuration&lt;/A&gt;, which is the secure configuration that the goverment uses by default, and has recently mandated that any off-the-shelf software product must operate properly with before being considered for purchase.&amp;nbsp; Site includes MS Virtual Server images of the FDCC configuration for testing purposes.&amp;nbsp; Good stuff.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.google.com/search?q=Idaho+National+Laboratories+research+scada+vulnerabilities"&gt;Google search for Idaho National Lab's research&lt;/A&gt; into vulnerabilities in the SCADA systems that control much of the nation's power grids and other critical infrastructures.&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://blogs.csoonline.com/basic_guide_to_days_of_risk"&gt;Days of Risk discussion&lt;/A&gt; on CSO Online&lt;/LI&gt;
&lt;LI&gt;Mark Cox's &lt;A href="http://www.redhatmagazine.com/2008/02/26/risk-report-three-years-of-red-hat-enterprise-linux-4/"&gt;recent report on Red Hat EL4's risk profile&lt;/A&gt; for the 3 years it has been shipping&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.awe.com/mark/blog/"&gt;Mark Cox's Blog&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://blog.scottlowe.org/"&gt;Scott Lowe's blog&lt;/A&gt; (virtualization security)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://rationalsecurity.typepad.com/"&gt;Chris Hoff's blog&lt;/A&gt; (virtualization security)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.google.com/search?q=gartner+neil+macdonald"&gt;Google Search for Neil MacDonald&lt;/A&gt;, one of the few Gartner analysts saying some smart things&lt;/LI&gt;
&lt;LI&gt;CNet's &lt;A href="http://www.news.com/RSA-2008-Blanketing-security/2009-7355_3-6236457.html?tag=cd.lede"&gt;RSA coverage&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4618.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>RSA Random Stats</title><link>http://bmonday.com/archive/2008/04/11/4617.aspx</link><pubDate>Fri, 11 Apr 2008 20:06:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/04/11/4617.aspx</guid><wfw:comment>http://bmonday.com/comments/4617.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/04/11/4617.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4617.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4617.aspx</trackback:ping><description>&lt;P&gt;Going through my notes from the week, and just wanted to throw out some interesting things I learned during the course of the week, in addition to the items in my previous posts:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;It is currently estimated that 40% of computers attached to the Internet are members of one or more botnets&lt;/LI&gt;
&lt;LI&gt;The US government recently reduced its time-to-patch from 57 days to 72 hours, and is striving for 24 hours&lt;/LI&gt;
&lt;LI&gt;Oracle is asking US&amp;nbsp;universities to mandate secure coding courses in the curriculum of computer science majors&lt;/LI&gt;
&lt;LI&gt;Despite some of the high visibility projects at the federal level, information security spending is at an all-time low federally.&amp;nbsp; The main culprit is&amp;nbsp;last year's&amp;nbsp;expiration of the Cybersecurity R&amp;amp;D Act.&lt;/LI&gt;
&lt;LI&gt;In the month of January, 88% of Barack Obama's campaign donations came from online sources.&amp;nbsp; Security of candidate web sites, and the potential for spoofing them,&amp;nbsp;is not getting enough attention.&lt;/LI&gt;
&lt;LI&gt;There were 23 critical vulnerabilities patched by Red Hat in 2007, versus 17 on Windows Vista.&lt;/LI&gt;
&lt;LI&gt;2 out of every 3 hackers exploiting virtualized environments are explicitly targeting the command and control infrastructure, not the VM hosts themselves.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4617.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>RSA Recap</title><link>http://bmonday.com/archive/2008/04/11/4616.aspx</link><pubDate>Fri, 11 Apr 2008 19:55:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/04/11/4616.aspx</guid><wfw:comment>http://bmonday.com/comments/4616.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/04/11/4616.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4616.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4616.aspx</trackback:ping><description>&lt;P&gt;Show's over.&amp;nbsp; Algore just left the stage after preaching to the crowd about global warming, and how &amp;#8220;you IT people&amp;#8221; can use his Intarwebs to help the fight.&amp;nbsp; He was heckled a number of times during the course of his speech, but security people pounced on the hecklers fairly quickly and hustled them out of the forum.&amp;nbsp; I don't remember Colin Powell getting heckled last year, but I might be repressing it.&lt;/P&gt;
&lt;P&gt;The irony of Algore coming to a security conference and spreading his apocalyptic FUD was not lost on many of us.&amp;nbsp; Hey, spreading fear uncertainty and doubt is our shtick, pal, and we've been doing it for DECADES.&lt;/P&gt;
&lt;P&gt;OK, enough of that.&amp;nbsp; I can feel my blood pressure rising, and I've recently noticed a direct correlation with my blood pressure and the number of times I use the f-bomb in my blog posts, and I'm trying to keep this one PG-rated, for christ's sake.&amp;nbsp; OK, NC-17.&lt;/P&gt;
&lt;P&gt;I gave up fairly quickly on the daily posts.&amp;nbsp; There were only 15-20 minutes between sessions, which generally left you just enough time to walk from one session to the other.&amp;nbsp; As luck would have it, I managed to plan things out just right so I had to walk from one end of Moscone to the other between each session.&amp;nbsp; I don't know how that happened.&lt;/P&gt;
&lt;P&gt;The small breaks that I did have were consumed by my actual day job, which I did not have the luxury of abandoning completely for the week.&amp;nbsp; Thankfully the RSA folks provided a really nice room for people to do work in between sessions, and it had about 80 powered and wired workspaces where we could sit and&amp;nbsp;jack in our laptops and get some work done.&amp;nbsp; They were also&amp;nbsp;piping in video&amp;nbsp;of current sessions, or ones recorded earlier in the day.&amp;nbsp; Really thoughtful.&lt;/P&gt;
&lt;P&gt;Day 1, while a real&amp;nbsp;slog with keynotes starting at 8am and sessions going as late as 6:30pm, was probably the most informative.&amp;nbsp; I attended a few duds, but there were a couple gems too&lt;/P&gt;
&lt;P&gt;Here's a few notes from the week:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Threats to 2008 Presidential Elections - I was disappointed in this one.&amp;nbsp; The presenter covered some work he had done with typo domains with respect to presidential candidates.&amp;nbsp; While there is some exposure here with regards to people errantly giving money to the wrong candidates, I don't think that's an effective election subversion technique.&lt;/LI&gt;
&lt;LI&gt;How to Win the Botnet Battle - Probably my favorite session of the entire show, mostly due to Ira Winkler calling his fellow panelists morons repeatedly throughout.&amp;nbsp; I agree with Ira in many aspects of his opinions about how we're conducting the War on Botnets, but I have some fundamental disagreements with him as well.&amp;nbsp; I'll be blogging about this one in the future.&lt;/LI&gt;
&lt;LI&gt;National Cyber Security Readiness - This was a pretty interesting discussion about the state of cyber security at the federal level.&amp;nbsp; On the panel was Rhode Island's own James Langevin, who is truly doing God's work at the legislative level to get cybercrime bills introduced.&amp;nbsp; Rhode Island owes this guy a statue or something.&amp;nbsp; We gave him a Public Policy&amp;nbsp;award for his efforts on the hill.&amp;nbsp; For those who aren't aware, the federal government is undergoing a massive effort to reduce the number and types of connections it has to/from the Internet.&amp;nbsp; Currently numbering in the thousands,&amp;nbsp;the goal is 50 or less.&amp;nbsp; They are also recruiting security people like mad, trying to enable an infosecurity capability into each agency within the federal government.&lt;/LI&gt;
&lt;LI&gt;Michael Chertoff spoke on Tuesday as well, and if you followed the news you saw that he announced a new initiative at the federal level to feed attack intelligence to the private sector, since the federal networks tend to see attacks before anyone else does.&amp;nbsp; We'll see how that pans out, I wish him well.&amp;nbsp; His recent pick for Cybersecurity Czar is making a lot more sense now.&lt;/LI&gt;
&lt;LI&gt;Security Information Visualization - Oy, was I pissed that I dragged myself out of bed early to catch this 8am dud.&amp;nbsp; Highly technical content, first thing in the morning, 90% of attendees nursing head-cracking hangovers from the first night of vendor afterparties.&amp;nbsp; These guys were dead on arrival in conditions such as those, but I admire their moxy.&amp;nbsp; The session was more about visualizing how data is protected using various encryption or DRM mechanisms.&amp;nbsp; I was expecting a talk about metrics.&lt;/LI&gt;
&lt;LI&gt;Linux vs Windows Security - This was a fairly lively debate between a guy at MS and a researcher from a Florida university.&amp;nbsp; They had done some studies revolving around vulnerability severity and numbers.&amp;nbsp; The MS guy made a pretty compelling case, demonstrating that by criticality, time of exposure, and time to patch, &lt;a title="Microsoft Corporation" href="http://www.microsoft.com" target="_blank"&gt;Microsoft&lt;/a&gt; had a very good year last year compared to Red Hat, the Linux of choice for the debate.&amp;nbsp; However, they ultimately called it a draw due to the ambiguity of the current vulnerability rating systems.&lt;/LI&gt;
&lt;LI&gt;Securing Virtualization peer-to-peer session - Great session, too short by half.&amp;nbsp; Peer to peer sessions are limited in size (20-ish people), and everyone sits in a circle singing kumbayah.&amp;nbsp; Or something.&amp;nbsp; No, the singing came after, now I remember.&amp;nbsp; Seriously though, there was a circle of attendees, and we had a very frank and open discussion about the challenges we're all facing with virtualization in our datacenters.&amp;nbsp; Reps from VM and Citrix were both in attendance, as well as a couple researchers, but the rest of the table was filled with practitioners like myself, struggling with the new security paradigm that comes with virtualization.&amp;nbsp; What I learned:&amp;nbsp; My company is farther along than most, everyone is facing the same set of issues, and there is not much of a consensus about how to handle security in this new environment.&lt;/LI&gt;
&lt;LI&gt;Virtualization and Security - A Technical Forecast -&amp;nbsp; Dud.&amp;nbsp; Basically this was 2 guys, one from VMWare and one from Citrix, expousing what they are doing to secure their respective virtualization products, and that we shouldn't worry about all the fud being put out by researchers right now.&amp;nbsp; The Citrix guy actually came out and said it was impossible for data to leak from one VM image to another, which reminded me or Oracle's &amp;#8220;Unbreakable&amp;#8220; gaffe from years past.&amp;nbsp; They also didn't get some of the questions, like when one attendee commented on the fact that hackers are using VMs to cover their tracks and subvert forensic investigations on their attack platforms, and the panelists went on to talk about how you can snapshot images as frequently as 30 times per second if you needed to.&amp;nbsp; Why would an attacker snapshot his own VM image, if the entire point is to dump the evidence by reverting the image, or simply throwing it out, after the deed is done?&amp;nbsp; There was also very little in the way of forward-looking information.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;You will note that my session selection tended towards security issues surrounding virtualization. There is great work being done in that space (finally), and there were no fewer than a dozen sessions devoted to virtualization issues.&amp;nbsp; The increased pressure to reduce power and cooling consumption in datacenters is driving adoption of virtualization technologies, at a rate that most people are not yet ready for.&amp;nbsp; This is one area where&amp;nbsp;the security&amp;nbsp;community&amp;nbsp;is behind the curve in a big way.&lt;/P&gt;
&lt;P&gt;More later.&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4616.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>RSA 2008 - Day 1 Morning</title><link>http://bmonday.com/archive/2008/04/08/4612.aspx</link><pubDate>Tue, 08 Apr 2008 12:27:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/04/08/4612.aspx</guid><wfw:comment>http://bmonday.com/comments/4612.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/04/08/4612.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4612.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4612.aspx</trackback:ping><description>&lt;P&gt;I'm at RSA all week, and I figured I best blog about it, seeing as how I maneuvered my way into the Security Blogger Meetup tomorrow night based on the premise that I do, at least occasionally, blog about information security issues.&lt;/P&gt;
&lt;P&gt;I'm taking a break from the morning keynotes, choosing to observe the &lt;a title="Microsoft Corporation" href="http://www.microsoft.com" target="_blank"&gt;Microsoft&lt;/a&gt; keynote from afar, via closed circuit TV, while I get some thoughts down on virtual paper.&lt;/P&gt;
&lt;P&gt;The first 2 talks were by EMC (parent company of RSA), and then Symantec.&lt;/P&gt;
&lt;P&gt;The show opened with the obligatory cheesy dance number, which this year was a bastardized version of the song &amp;#8220;Brick House&amp;#8221;, with an information security slant to the lyrics.&lt;/P&gt;
&lt;P&gt;After that nonsense was over, EMC's CEO came onstage (no, he wasn't one of the dancers) and talked about the transition security practitioners need to make to go from villain to hero within their respective organizations.&amp;nbsp; To go from the people that say No all the time, to being a business enabler.&amp;nbsp; It was an interesting talk, but we've been talking about that for years, and haven't figured out how to achieve that goal.&lt;/P&gt;
&lt;P&gt;Next up were a couple folks from Symantec, who talked a bit about this morning's release of the 13th installment of their &lt;A href="http://www.symantec.com/business/theme.jsp?themeid=threatreport&amp;amp;inid=us_ghp_staticpromo_threatreport"&gt;Internet Security Threat Report&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Things learned during this morning's sessions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;80% of the companies surveyed during a recent EMC/RSA study admitted that they had shied away from potential business innovations or strategic acquisitions due to concerns over information security.&lt;/LI&gt;
&lt;LI&gt;65% of new software delivered to the average consumer is malicious.&amp;nbsp; For the first time, 2007 saw development of malicious software outpace normal consumer software.&lt;/LI&gt;
&lt;LI&gt;50 million IDs were exposed in 2007 due to various breaches, which is 3 per second, and a 300% increase over 2006&lt;/LI&gt;
&lt;LI&gt;Stolen identities are the 3rd most common item being advertised on the information black market (yes, there's an &amp;#8220;information&amp;#8220; black market)&lt;/LI&gt;
&lt;LI&gt;Stolen credit card numbers sell for an average of 40 cents on the black market&lt;/LI&gt;
&lt;LI&gt;Stolen World of Warcraft accounts sell for 100 times more than stolen credit cards&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;I've only just downloaded Symantec's report, and will post later about that once I've had a chance to review the report in it's full 105-page glory.&lt;/P&gt;
&lt;P&gt;Homeland Security's Michael Chertoff, who blew us off last year to testify in front of Congress, was a last-minute addition to&amp;nbsp;today's keynote schedule.&amp;nbsp; He speaks at 11:30, and I'll post again after I have had a chance to hear what he has to say.&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4612.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Beau Monday</dc:creator><title>And now for something completely different</title><link>http://bmonday.com/archive/2008/03/23/4582.aspx</link><pubDate>Sun, 23 Mar 2008 01:57:00 GMT</pubDate><guid>http://bmonday.com/archive/2008/03/23/4582.aspx</guid><wfw:comment>http://bmonday.com/comments/4582.aspx</wfw:comment><comments>http://bmonday.com/archive/2008/03/23/4582.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://bmonday.com/comments/commentRss/4582.aspx</wfw:commentRss><trackback:ping>http://bmonday.com/services/trackbacks/4582.aspx</trackback:ping><description>&lt;P&gt;I have updated the Conferences list on the right-hand nav frame to just list the 2 conferences on my schedule for this year, both happening in April, as luck would have it.&lt;/P&gt;
&lt;P&gt;Speaking of RSA:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="/images/security_bloggers_meetup_2008.jpg"&gt;&lt;/P&gt;
&lt;P&gt;I've&amp;nbsp;received an invitation to attend the &lt;A href="http://www.rsaconference.com/Security_Topics/Developing_with_Security/Blog_Security_Bloggers_Meet_up_2008.aspx"&gt;2nd annual Security Bloggers Meetup&lt;/A&gt; during the RSA show.&amp;nbsp; There may have been a little whining on my part immediately preceding the invite, I can't be responsible for remembering the exact sequence of events.&amp;nbsp; The important thing, I think you'll all agree,&amp;nbsp;is that&amp;nbsp;I'll be there.&lt;/P&gt;&lt;img src ="http://bmonday.com/aggbug/4582.aspx" width = "1" height = "1" /&gt;</description></item></channel></rss>