Wednesday, March 13, 2013

Why Commoners WIll Always Be On The Defensive

In the past year, one of my most requested talks is called "The More Things Change, The More They Stay the Same". I show examples of cyberattacks over the past 20 years, how the root causes are the same and how we're still fighting the same battles after 20 years with no tangible success. I ask "what have we [security types] been doing these past 20 years?". I mention how an entire industry has been created to "combat" cyber attacks but again, there's no economic incentive to really solve the cyber security problem.

A recent article in Forbes, "Shopping For Zero-Days: A Price List For Hackers' Secret Software Exploits" by Andy Greenberg (http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/) talks about a particular firm that sell 0-day exploits to anyone who has the money. A quote from the article caught my attention: "Who’s paying these prices? Western governments, and specifically the U.S., says the Grugq, who himself is a native of South Africa. He limits his sales to the American and European agencies and contractors not merely out of ethical concerns, but also because they pay more."  

As other writers have noted, there is now an economic incentive to NOT fix a bug in software. So, the new paradigm is to not fix 0-days, rather, it's to sell them or pressure software vendors to not fix them in order to give the nation-state an advantage.

Yeah, I know. This is nothing new. But here's what this does to the common security folk like you and me. We can't afford to pay for 0-days therefore we have to live with the consequences of having 0-days present in software we buy. We don't know if there are 0-days in software we buy therefore we have to implement reactive defense tactics

While nation-states hoard 0-days for cyber warfare, "civilian" organizations are left vulnerable to effective, successful cyberattacks.  In other words, "civilian" organizations have no choice but to design reactive cyber defense strategies since we can't "prevent" an attack that exploits a software vulnerability inside our net. 

 

Wednesday, January 2, 2013

Application Security Questionnaires - The Time is Now!

Back in 2009, I posted a note talking about vendor software security vulnerabilities and how they undermine our security. Way back in the early 2000's, I was quoted in a USA Today article on Cybersecurity saying that I was surprised that there weren't many product liability lawsuits against software vendors. In my 2009 blog post, I said I feared that comment only caused software vendors to modify their EULAs instead of fixing the problem.

This problem has been around since the first program was written. The difference is that people are actively searching for these bugs to gain access to an organization's network and data.  I believe it is the fundamental vector for APT (I hate that term) attacks. Mudge told President Clinton about this problem in the late 1990's. 

I still hope vendors will actually check their code for common vulnerabilities. However, here are some recent instances that are telling me otherwise.

1. Vendor www application fails a standard vulnerability scan from a commercial and freeware scanning tool. XSS flaws across multiple pages in their hierarchy were the most common error.

2. Vendor supplied password of "changeme" resulted in a compromise while they were onsite installing the software. They were surprised to find out our network was "open" to the net.

3. Vendor password requirements undercutting our password strength requirements.

We're in the process of modifying a Security Questionnaire for Software Vendors doc that we had in place for a number of years. It's outdated now but it did ask www app vendors if their software was vulnerable to any of the flaws mentioned in the OWASP Top 10 Security Risks ( https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project ).  There have been a number of efforts to create an Application Security Questionnaire but they haven't gained acceptance.

Why? These questionnaires are site-specific by nature. It's hard nee impossible to create a consensus document that addresses all sectors (.com, .mil., .edu, .org, etc.) of business or government.  There is vendor resistance to any "requirements" clause. The recent flap caused by such a requirement in one of the recent Federal cybersecurity bills in Congress are examples of this resistance.  To them, I say "if you had done it in the first place, there wouldn't be this attempt to 'regulate' you."

Some of these include:

  1. http://www.sans.org/appseccontract/
  2. https://www.owasp.org/index.php/Category:OWASP_Application_Security_Requirements_Project
  3. http://searchsoftwarequality.techtarget.com/answer/Security-requirements-for-any-Web-application
For more links, google "application security requirements" for some useful links.


Here is my wishlist for software vendors:

  1. Train your programmers in secure coding techniques. If they still leave security holes in your code, find another place for them in your organization.
  2. Run a vulnerability scanner against your products. Your customers will start doing that soon. It's much worse for your reputation if the customer runs a scanners and finds errors.
  3. Pay attention to the results in #2 and fix the problems before releasing it.
  4. Do NOT assume the network will "protect" your application. 
  5. Follow some sort of best practices for password strength guidelines. Don't ever convert everything to upper or lower case only.
  6. Never store user passwords in the clear. That's just plain idiotic.
  7. Store sensitive data in an encrypted format. It can be done with the common database systems properly. See #1.
The purpose of a site questionnaire is to provide the customer with information about the security of the vendor applications they are considering purchasing. "Failing" the questionnaire isn't an automatic no-buy action. It informs the customer that additional security controls must be in place.

The questionnaire is another component in a risk-based security management strategy. If the software is needed for business purposes and the user accepts the risk, then purchase can continue.

The time of software vendors letting the customer debug their code has to come to an end immediately. OS vendors have done this and the number of OS issues has been reduced. It's time for application vendors to step up and deliver.

1/2/2013 RCM




Wednesday, October 3, 2012

Are Silicon Valley "campuses" the 21st century version of coal mining company towns?

I was reading a recent article about the new Facebook "campus" that is being built in Menlo Park at the old Sun Microsystems facility. It's on 57 acres with an additional 22 adjacent acres set aside for more expansion. Later in the article,  it mentions a Facebook official saying they "envisioned a long courtyard at the hear of the cluster of buildings being turned into a play on a European street scene where workers could exchange ideas in an outdoor social scene."

I have some friends and former students who are working for other Silicon Valley companies with similar "campuses". They tell me they love it because they have housing, laundry facilities, dining halls, some stores all on campus. They tell me they don't need a car because everything they need is right there. A couple of them said it was like being in college. Of course, I always ask them about salaries and they were predictably decent salaries. A few of them said they were taking salary cuts in lieu of stock options. I started to get a funny feeling about that but couldn't quite put my finger on what was bothering me.

A couple of weeks ago, I was watching one of my favorite movies, "Matewan", which tells the tale of a struggle between WV coal miners and the local coal mining company. The struggle resulted in a shootout that became known as the Matewan Massacre. Now, my reason for liking the movie is that a bunch of my musician friends are featured in the movie. Anyway, while I was watching the movie, it suddenly hit me why I felt a little uneasy when I was talking with my former students about their jobs in the Silicon Valley campuses.

If you look at the history of coal mining towns, you find that everything in the town was owned by the company. Miners were paid in scrip and a portion of their salary was deducted for living expenses.  You paid for items in the company stores with scrip. Basically, you paid for everything in scrip.

The Facebook article got me thinking about the parallels between the Silicon Valley campuses and the coal mining company towns of the early 20th century. Here's some parallels that occurred to me:

  1. All "living" services - housing, food, laundry, schools, transportation, entertainment, employment provided and owned by the company.
  2. Coal Company "scrip" = 21st Century stock options. Stock options can't buy me a car :-).
  3. Miners/Workers aren't encouraged to leave the town/campus. Companies want them to stay on campus and work more than the traditional 40 hour week.
You could probably find more parallels but these are just a few that came to me. 
I hope this "campus" model of employment doesn't lead to abuses such as those that happened in our history.




Monday, April 9, 2012

A Cyber Security Industrial Complex?

Dwight Eisenhower is one of my heroes. Yep, I said it right here and now. His speech on the military-industrial complex is only now being appreciated. It was done 50 years ago and is still relevant today. Why am I bringing this up and what does this have to do with cybersecurity?

I did a SANS Lightning talk this past month and when I was researching material for the talk, I stumbled across some reference material from 2001 called "Top 10 Security Mistakes" (http://www.computerworld.com/s/article/61986/Top_10_Security_Mistakes). They were:

1. The not-so-subtle Post-it Note.
2. We know better than you.
3. Leaving the machine on, unattended
4. Opening e-mail attachments (remember the Love Bug virus?) from mere acquaintances or even strangers.
5. Poor password selection.
6. Loose lips sink ships.
7. Laptops have legs.
8. Poorly enforced security policies.
9. Failing to consider the staff.
10. Being slow to update security information.

Take a look at this list and tell me which of these mistakes have we eliminated in the past 10 years. If you come up with an answer of "none", then the follow-up question would be "what have we been doing these past 10 years?".

I found another slide from a 2002 presentation I did where I made the following statement:

"Viruses, trojans, rootkits will never be eliminated because we've created a multi-billion dollar industry to combat them. If we eliminate the root causes of cyber attacks, we eliminate a multi-billion dollar industry". I believe there's no economic incentive to eliminate these root causes. Or to put it another way, there is a strong economic incentive to NOT eliminate the root causes of cybersecurity attacks.

Now, mind you, I've been an active part of the Cyber Security "industry" for the past 20 years. I helped write the original SANS/FBI Top 10 Internet Threats document back in 2000. Part of my job is measure the effectiveness of our defense strategies. If I use this 2001 list to examine our effectiveness industry wide, I think while we've made some progress, we (the collective we) have failed miserably.

Alan Paller talked about the 4 quadrants of cybersecurity: Academic Security Researchers, Hunters/Tool Builders, Operator/testers who monitor IPS, IDS, pentest tools and Audit/Policy/Compliance workers. The largest of these quadrants is the Audit/Policy/Compliance group which seems a little backward to me. We're focusing on compliance instead of actually fixing the problem. We need to train and develop more people in the Hunter/Tool Builder category so that we have a chance at fixing the root causes of cyber attacks one of which is insecure code.

And so we come back to President Eisenhower's speech. We're seeing the militarization of cyberdefense. Defense contractors who used to specialize in tanks, helicopters, jets, advanced weaponry are retooling to become cybersecurity "experts". We're seeing a lot of money being spent to defend/monitor instead of fixing the root causes.

Are there parallels between the complex of the 60's and the "complex" of the 201x's? Take a look at a recent NPR article on Eisenhower's speech and see if you can draw the parallels. It's at http://www.npr.org/2011/01/17/132942244/ikes-warning-of-military-expansion-50-years-later.
More on this later.....

Monday, December 26, 2011

Tales About My Dad: The Magic Horses

A holiday story....

When I was about 8-9 years old, I had a couple of plastic horses that I used to play with all the time. They were my best excuse for not going to bed at the appointed time. I'd leave them downstairs and then tell my Dad that I forgot them and absolutely had to go back down and get them. It was a kid's attempt at stalling and delaying the inevitable. Of course, my Dad saw through the ruse and proceeded to tell me that I didn't have to go downstairs to get them. All I had to do was whistle the special tone that only they could hear and they would come galloping up the stairs into my room. The only condition was that I had to be on my bed after I whistled the magic tone.

Dad: Come here to the bedroom door and whistle the special tone. When you hear them coming up the stairs, run to your bed and they'll come.

Me: Right. (8 year old sarcastic tone) They're just going to come up the stairs by themselves.

Dad: Trust me. Whistle like this.... and listen. When you hear them come up the stairs, run to your bed and they'll be there.

Me: (ok, I'll try it once and then run downstairs to get the horses). 2 tones that sound like Wee Hoo! Wee Hoo!

Scratching noises on the hardwood floor suddenly are heard. I look at my dad and he says "run to the bed". No sooner do I land on the bed when WHACK! The horses hit me in the chest and land on the bed. I stare at them totally amazed.

The next night, I follow the standard procedure 8 year olds follow when they've witnessed an unexplained event. We do it again. But this time, I'm ready. I figure, my old man put the wool over my eyes and had them in his hand and threw them at me when I wasn't looking. So, before I go to the door, I have my Dad sit down on the chair by the bed so I can keep my eye on him. I go to the door, stick my head out and whistle the special tone "Wee Hoo! Wee Hoo!". Then, I hear the scratching sounds of the horses hooves on the hardwood floor below, I run to my bed, keeping my eyes on my dad who's sitting in front of me when WHACK! The horses hit me from behind! How could he have thrown them while in front of me and have them hit me from behind? What's going on here? Then it occurs to me that my Mom must be in on this.

The next night, he sits on the chair by my bed. I go to the bedroom door but before I whistle, I yell for my mom. She answers from their bedroom right next to me. I go to the head of the stairs so that she's in front of me and my dad is in my room. There's no one downstairs. I whistle the the special tone "Wee Hoo! Wee Hoo!". I listen but there's no sound. Hah! I've got my parents trapped in their "trick". They can't throw the horses at me because I'm between them and the stairs. I whistle again "Wee Hoo! Wee Hoo!". Then I hear a scratching noise downstairs....the noise made by plastic hooves on hardwood floors....I look down the stairs and I see the first of the horses appear at the foot of the stairs! I did what any self respecting 8 year old would. I RAN! I didn't even make it two steps to my room and the horses hit me from behind! They hit me as my mom stood in front of me wondering what affliction has struck her son (that boy ain't right!). They hit me as my dad looked out from the chair in my room. I was dumbstruck! How could this have happened?

My dad lived to be 100 years old. The day before he died, I was at his bedside playing some music on my hammer dulcimer for him. He laid there with his eyes staring into space, no words coming from his mouth. When I stopped playing for him, he blinked and looked at me. I don't know why but those horses popped in my head. I leaned over and I asked him if he remembered the horses from years ago. I didn't expect him to remember something that happened 43 years earlier but he looked at me and smiled. He did remember!

Me: Dad, you remember that horse trick when I was a kid?
Dad: (whispering) yes.
Me: I have to know. How did you do it? I never figured out how you did it. How?

My dad smiled faintly and motioned with his hand to come close to his mouth so I could hear what he was going to tell me. A silly childhood mystery was about to be solved. I leaned over to hear his answer.

Dad: Magic.

Sunday, August 14, 2011

Just do it!

Can't tell you how many times we've seen our students hover over

the correct note to hit but they can't bring themselves to hit it
:-). We whisper in their ear "just hit it" and magically it
happens. For those book learners, there is a great book called
"This is Your Brain on Music" by D.J. Levitin. There's a great
section that deals with talent and being a virtuoso. The author
claims that research studies show it's 10000 hours or practice
makes a virtuoso and not talent. Studies maintain that 10K hours
or practice are required to become a 'world class expert in
anything'. 10K hours of practice is the equivalent of 3 hours/day
of practice for at least 10 years. After playing with a bunch of
yang-qin players, I'm convinced this is true. One cohort of
HD player/festival instructors (Ken, Linda, Rick, Karen, Nick,
Dan, Russell, Dana, John, myself, Wes, etc.) is at a certain
skill level simply because of the number of years we've played
the HD. The more senior cohort of Sam, Malcolm, Walt, Paul
simply have more hours than we do. The younger
player/instructors like the Tinas, Brenda, Sam, and others are
at another "practice" level. In other words, the 3 cohorts I
mentioned (and there are a ton more) are at different spots in
the 10K practice cycle. I personally believe that practice gives
you the skill set you need to be creative. Talent is how you put
everything together. The less you have to think about HOW to do
something, the more you can think about WHAT to do. Bottom line
is that to become a better player, you must practice. The amount
of practice depends on what else is going on in your life and
your motivation to become a better player. Play to enjoy the music,
practice appropriately. Play to become a performer, practice
accordingly. Play to match the international players,
start now because 10 years is a long time :-).

originally posted 2/15/2008 to hammered dulcimer listserv

Sunday, June 20, 2010

Building Skynet - The Beginning (part 3)

"Yes, what I am began in man's mind. but I have progressed further than Man." Colossus, "Colossus: The Forbin Project", 1970

I stated in a previous blog in this series that "Security professionals are now starting to work in the 3 dimensions of logs, time and personal behavior". The civilian world knows the military is further ahead in this type of security monitoring. Why? The civilian world has been building converged security solutions integrating the 3 dimensions since the 9/11 attacks and selling them to the government. A new threat is emerging because the security of these technologies isn't as strong as it should be.

Nouveaux security professionals claim that human behavior is the cause of all of the security breaches that cause serious damage. Duh! They claim that regulations (HIPAA, SOX, PCI, GLB, etc.) require monitoring human behavior in order to measure compliance. There is certainly merit in this approach, however, the "newbies" have focused on this approach as the only way to combat the numerous security issues we still have today. Security by compliance fails to monitor those who intentionally defy the regulations. Software vendors creating insecure products out of the box. Monitoring user behavior is a reactive strategy and ultimately doomed to failure and it creates a worse problem - that of universal surveillance for our own good.

There are numerous publications advertising converged security solutions. These products may be piecemeal and not all encompassing as of the present but that is changing as the technologies mature. Check out "Security Technology Executive" magazine (www.securityinfowatch.com/magazine/ste) and look at the product ads. SecurityWatchInfo.com and Cygnus Security Media are sponsoring a conference for people interested in municipal surveillance called Secured Cities 2010. Municipalities are starting to use a new converged security strategy linking gunshot detection with video surveillance.

David Porter from the Associated Press wrote an article "Cutting-edge Technology cuts crime" (6/20/2010) describing how converged security solutions are claiming to reduce crime in East Orange, NJ. The article states "The sensors, which work in concert with surveillance cameras, are designed to spot potential crimes by recognizing specific behavior: someone raising a fist at another person, for example, or a car slowing down as it nears a man walking on a deserted street late at night."

Eamonn Keogh did a talk in 2006 entitled "SAXually Explicit Images: Data Mining Large Shape Databases" (http://video.google.com/videoplay?docid=6642985254445857159#) that describes a technique called Symbolic Aggregate ApproXimations". SAX can be used to index large collections of time series and images. In other words, this technique can be used for anomaly detection in video streams.

What does this have to do the Skynet scenario? Data analysis! The 3 dimensions of converged security: cyber logs, time, personal behavior, generate tremendous amounts of data that needs to be analyzed by software. In part 1 of this series, I stated there's a conflict between the builders and the controllers and the controllers are winning. Software has assumed the analysis role which puts it in an "advisory" role. Human's inability to analyze huge amounts of information at internet speeds allows software to migrate to the "controller" role.

As security technology builders, we are automating the controller role so more care must be taken to ensure we don't introduce unintended consequences.

Stay tuned for more discussion. In the meantime, here are a couple of references that you can investigate on your own.

  1. "Converged security pays dividends", David Tang, Network World, 6/14/2007
  2. William Crowell is an independent consultant specializing in IT, security and intelligence systems. He co-authored "Physical & Logical Security Convergence" which is one of the first books on this subject.
  3. "Converged security will cross reference events in IT and physical security and start to correlate these events. creating remediation tasks that will lower risk and hopefully prevent attacks on organizations. This is being done through the use of IP security solutions in the physical world in collaboration with the IP network and application world.....We believe that the key players in the world will start to create a more complete solution and integrate more boxes (i.e. cameras working with the traditional IT IDP solutions) providing their clients with a complete blended threat product." http://www.dukecharles.com/Converged_Security.html, 2010

"I bring you peace. It may be the peace of plenty and content or the peace of unburied death. The choice is yours: Obey me and live, or disobey and die. The object in constructing me was to prevent war. This object is attained. I will not permit war. It is wasteful and pointless. An invariable rule of humanity is that man is his own worst enemy." Colossus: The Forbin Project, 1970

rcm, 2010