Securosis

Research

Network Security Podcast, Episode 81

Martin is on the road starting up his new job as a PCI auditor for Trustwave so I made my best attempt to record the podcast. More than a few technical difficulties later, we finally completed recording. Sorry about the extra reverb, I’m still figuring out my setup and accidentally left it a little high. For the record, Audio Hijack Pro rocks and I regret trying to record without it. The show is shorter tonight to account for Martin’s travel. We spend a fair bit of time talking about Apple products due to the upcoming release of OS X 10.5 and happenings in the world of the iPhone. I also chastise Martin for being in Denver and thinking the Rockies are just the big pointy things in the distance. I lived in Boulder for 16 years, and although I’m in Phoenix now I still tend to root for the old home teams. Except the Nuggets. Now if you’ll excuse me, I need to go pre-order Leopard for my Mac… Show Notes: OS X Leopard release and security features The Apple Store Rich’s commentary on Leopard iPhone Metasploit package HD Moore: Cracking the iPhone part 2.1 Rich’s commentary on the iPhone exploit Apple opening iphone, still scared of evil hax0rs Russian Business Network Citrix flaws or bad configuration Blame bad Citrix admins for poor site security, experts say Citrix; Owning the legitimate backdoor Sorry, no music tonight Network Security Podcast, Episode 81, October 17, 2007 Share:

Share:
Read Post

When Software Bugs Kill: Robotic Cannon Kills 9

No, this isn’t science fiction. According to Wired’s Danger Room, an automatic defense system went out of control in South Africa during a live fire exercise. Nine soldiers lost their lives, and fourteen were injured. I’m not going to make any jokes about this one, since we’ve crossed from the theoretical to the real, with a tragic loss of life. There’s not much else to say. Share:

Share:
Read Post

Product News And Two Misjudgments I’ve Made On DLP (Reconnex and Vontu)

One of the reasons I spend so much time talking about DLP around here is that it’s one of the first markets I covered as an analyst and I’ve been able to watch it grow from the start. It also means that over 5-6 years of coverage the odds are pretty high I’ve made some mistakes. The Usual Disclaimer: There are a lot of good DLP products on the market and I work with some of the companies. This post isn’t an explicit endorsement, and i’ll likely be highlighting competitors in future posts as they come out with their own product updates. Just keeping you informed, and you need to run through a full selection process to pick the best tool for your circumstances. With the strong rumors about the acquisition of Vontu, and since it was my first big mistake in this space, it’s a good time to come clean. Way back when Vontu was first coming to market they stopped off to meet me for lunch at the Walnut Brewery in Boulder, Colorado. I think I had a turkey burger because it’s only available at lunch, and I really like it. They described their key differentiator- using real database data to detect leaks, what they call Exact Data Matching (EDM). I wasn’t impressed, and informed them that Vericept could do it all with regular expressions. I walked away thinking I’d never see them again. A combination of factors proved me wrong. For the next 2 years Vericept didn’t recognize the value of the DLP market, continued to focus on acceptable use enforcement, and got their clocks cleaned by Vontu. A combination of aggressive execution, some key client references, and tight focus on leak prevention put Vontu in the top spot in the market. For the record, Vericept later brought in some new management that turned the company around, putting them in second place in terms of revenue by last year. Nice thing about an early market, you can afford some mistakes. Most customers still don’t use EDM, but that’s not the point. I thought, at the time, that a general platform would be more successful, but it was the focused solution that clients were more interested in. Even if the Symantec deal doesn’t happen, that laser focus on the business problem has already paid off. The next example of poor judgement concerns Reconnex. Reconnex is unique in the DLP market in that they can collect all traffic, not just policy violations. I used to call this full forensics since it was essentially structured network forensics. Back when they released the first versions of the product this feature wasn’t an advantage for DLP. There was no reason to collect all that traffic; sure, it might be helpful in an investigation, but few DLP clients were interested. Management at the time (since changed) focused so much on that feature that they let the user interface and performance slack. With their new release, I may be changing my mind. They’ve now turned the capture capability from a forensics tool into a data mining and policy validation tool. Aside from still being useful in investigations, you can now generate a DLP policy and run it on old data. Instead of having to tune a policy in production as you go, you can tune it offline and play with changes without affecting production. They’ve also added data mining so you can use the tool to help identify sensitive data that’s not currently protected by a policy by looking at behavior/history. I haven’t talked to any references about this yet, but it looks promising. They’ve also revamped the user interface and it’s much more usable with better workflow. I know some of the other DLP vendors are working up their next releases and it will be interesting to see what pops. I’ve already heard some good things about the endpoint capabilities of one of them, although they haven’t briefed me. Share:

Share:
Read Post

Apple Opening iPhone!!! Still Scared Of Evil Hax0rs.

Honey? My Blackberry broke. What? I don’t know, it just stopped working. Yeah, I know it looks like it fell off the roof, but I don’t know how that could have happened. Okay, I’ll still probably wait for a 3G version since I really like my Blackberry Pearl, but this is an awesome move. I will, however, call bubkis on this next part: Apple “[is] excited about creating a vibrant third party developer community around the iPhone and enabling hundreds of new applications for our users,” but they are taking the time to do it properly “because we’re trying to do two diametrically opposed things at once – provide an advanced and open platform to developers while at the same time protect iPhone users from viruses, malware, privacy attacks, etc.” Wait, last time I checked the Mac was an open platform, relatively safe from “viruses, malware, privacy attacks, etc.”? And doesn’t the iPhone run on OS X? Last time I asked those questions the response was… a little chilly. Updated: Glenn over at TidBITS predicted this last week. Great scoop! Share:

Share:
Read Post

Up On Twitter

As rmogull. Adam Engst got me started with this article. Seems more useful than I expected. I’ve added it to the contact links on the home page of the blog. Share:

Share:
Read Post

An Optimistically Fatalistic View Of The Futility Of Security

Hoff (and some others) have been talking a lot about hope and the future. Chris has dedicated most of his recent posts to making us think differently about security. To drop our archaic models of the past and look towards solutions for the future. It’s a noble goal, one I support completely. Dr. Eugene Spafford, a seminal figure in information security, is also dedicating effort to the cause. I’m firmly in their camp and believe that while we don’t need an entirely new model for security, we definitely need to evolve. Information Security has been little more than basic network security and antivirus ever since Code Red and Melissa hit. But that’s not important right now. The essential questions are, “will we win?” And “do we make a difference?” These questions are non-trivial and endemic to the human condition. Anyone, in any occupation, who is invested in what they do will frequently use these questions to position themselves in the world. For some an occupation is merely a way to pass the hours and pay the bills; these automatons contribute to the status quo, but don’t help society evolve. For the rest of us our occupation is an essential component of our identity. We define ourselves by our occupation, and define our occupation as we want to define ourselves. I’ve worked in public safety my entire adult life, and spent most of my childhood, purposefully or not, preparing for my strange career. Over the years as I worked in different positions throughout public safety, from physical security, to emergency medicine, to information security, I was challenged by difficult questions of conscience. When I started in emergency medicine, I had to reconcile the thrill of the job with the fact that I achieved professional satisfaction only through the pain and suffering of others. As much as I wanted to try that new procedure, or be on that big call, I had to accept that for me to exercise my skills, someone needed to suffer injury or illness. I reconciled such a potentially twisted mentality by realizing that it wasn’t that I wanted someone else to suffer, but I wanted to do my job and do it well. People will get hurt, sick, and die with or without my involvement; I was a professional and wanted to do the job I was highly trained for. If something was going to happen, I wanted to be the one to be there. As my experience and confidence grew, I also began to believe that the better I was at my job, the less that victim (or the family) would suffer. Physical security was similar, but involved some slightly more complex mental gymnastics, which every cop and (I expect) soldier experiences. While as a medic you relieve pain and suffering, in physical security you often inflict it. We all loved the rush of breaking up a fight or catching a bad guy. There is an undeniable thrill in being authorized to use physical force on another human being- not a thrill of sadism, but the same emotions evoked by the sports we use to sublimate physical combat. In those cases my goals became to use as little force as possible and de-escalate situations verbally. Violence was not the objective; it was the last tool available to protect others. I’d like to call it altruism, but the truth is there are visceral thrills and deep satisfaction in managing the challenges of emergency medicine, rescue, and physical security. I learned to accept this motivation without guilt, since the goals of safety and security called for such commitment. When safety and security become excuses to do bad things, that’s when a very bad line is crossed. But back to security. In information security we may not be faced by the prospects of blood and guts, but those of us “in the industry” need to accept that we make our money off the pain of others. There’s nothing wrong with this so long as we don’t take advantage of our clients. I’m not just talking about vendors; we in internal security also provide a service to a client. My personal philosophy around this is that I won’t lie or try to frighten just to enhance my own income, but I’ll tell the truth and charge what I think is fair value for my services. I also still perform some volunteer work for those who need the help but can’t afford it. Security professionals earn our daily bread from fear and pain (sometimes very abstract pain, but pain nonetheless). There’s nothing wrong with that, but it does convey a responsibility not seen in other occupations. The big question I haven’t addressed, one that underlies pretty much any occupation, is, “Do I make a difference?” Psychologically I believe all humans fundamentally need to make a difference. It’s hard wired into our brains. If we’re not making a difference, we have only one of a few possible reactions. We can disengage from that activity and find fulfillment in other parts of our lives, or disengage from life completely. As sad as that sounds, we all know people who don’t see the meaning of their life and instead turn to a never-ending trail of distractions. We can also deceive ourselves and create illusions that we matter; I suspect many mountains of bureaucracy have been built on such falsehoods. We can also seek satisfaction elsewhere; actively finding a new job or career. We can also do the absolute best job possible, fight the good fight, and try to rise above any limiting circumstances. As a paramedic I may have been the one who saved a few lives and reduced a little suffering, but the reality is that if I hadn’t been there, someone else would have been. In mountain rescue we operate as a team and it’s a group of 40 or so people, not some lone hero, that makes the save. But although I personally wasn’t essential, and the rescue would have happened

Share:
Read Post

Flashback To 2005- Home Depot and Iron Mountain Lose Laptops And Tapes; Another Encryption Rant

This is such a straightforward problem to solve it’s annoying that it still makes the headlines. Laptop and tape encryption are the low hanging fruit of data security. Not that they are click-box easy, but it’s pretty straightforward for most organizations to protect this stuff. Home Depot lost a “password protected” laptop when it was stolen from a car, and 10,000 employee records with it. Iron Mountain lost a case of backup tapes with a decade’s worth of Social Security Numbers from college applicants in Louisiana. Their proactive strategy to protect their customers? “We certainly don’t want to create any panic. But people should be aware and take the necessary steps,” Amrhein told the AP. “This is backup data off of a mainframe that contains sensitive personal information.” Darn, it’s my fault for applying to college and not being aware. Silly me. I do take umbrage at some of the misguided advice at the end of the article: “If you buy encryption you need to work with the company’s legal department and top executives on a process where you can prove data on a stolen device can’t be tampered with,” he said. “A cradle-to-gave transaction record on the server is one way to provide an inventory on the current state of all your drives. Another, more difficult approach is to write everything down.” He said it helps if a company can show it is using a reputable vendor to put a barrier around stored data, and mentioned Seagate Technology as an example. The Scotts Valley, Calif.-based hard drive maker said this week it will roll out enterprise-class drives with full disk encryption in 2008 and will push to make hard-drive encryption standards a reality to reduce complexities that could hinder adoption. Like a cradle to grave transaction record and an inventory of all you hard drives is realistic. Also, while encrypted drives will play a role in data security they are far from a panacea! First of all, the software solutions today, especially for whole drive, are effective without requiring you to install new drives. Second, the encryption on those drives is managed by software, so now you’ll have to buy both the encrypted drive and the software to manage it. More often than not, non-laptop encrypted drives are totally unnecessary and don’t improve security. I like how Seagate designed their drives, but it’s not like they’re the right choice in all cases, nor will they put us (or software encryption) out of business. Remember the Three Laws people. Use your encryption well. Share:

Share:
Read Post

Mac Security Updates In OS X 10.5

Apple has finally released the full list of updates in the next version of the Mac operating system, including a section detailing all the security updates. A couple of features look pretty interesting. The biggest is the inclusion of “Library Randomization”, or what we call layout randomization (ASLR) in Vista. System functions are randomized in memory to make exploitation more difficult. I don’t have a Leopard seed to check it out, and I suspect some of the researchers out there will dig in and let us know how good (or bad) the implementation is. Mac OS X already supports Data Execution Prevention, one of the other key Windows XP, Server, and Vista anti-exploitation technologies. Another good feature is tagging of downloaded applications. Any downloaded executable is tagged by the OS and requires the user to approve it on first launch (it doesn’t mention if it’s a password prompt or just clicking an OK box). It appears to list the app name, what tool downloaded it, and (if possible) the URL it came from. Regular users probably won’t pay attention, but this will be nice for those of us who do. Apple also (finally) improved the Mac OS X firewall to include some level of application control. The description makes it look like it only controls inbound connections, which would be too bad. I think the user interface for this one will be pretty important, and maybe outbound control is hidden in the capabilities somewhere. Anyone up to date on ipfw that can let us know if Apple is sticking with that? There’s a new sandboxing feature for some default applications, including Bonjour, Spotlight, and Quick Look. I highly suspect this is a way of limiting the potential exploitation via file and network fuzzing, considering the applications they picked. Most of the rest of the updates are fairly straightforward and good to see. Application signing, 256 bit AES for file encryption, better VPN support, SMB packet signing for Windows compatibility, multiple user certificates, and some updates to access control lists for file sharing (I think, although they don’t say, driven by Windows compatibility issues). There’s increased smart card support designed to meet the needs of the feds, but I might give it a shot (for fun) if the readers are added to default Macs (unlikely). And let’s not forget the biggest security feature in Leopard that didn’t make the list- Time Machine. Getting users to do differential backups will do more to assure the availability of their data than any other security feature. I’m really looking forward to seeing how this all holds up once the security researchers get their hands on it. On paper it looks great, maybe even getting Mac OS X up to the level of Vista (for security- usability on Vista still sucks). But I don’t believe anything until people smarter than me start banging on it and seeing where the cracks are. Share:

Share:
Read Post

The Irish Government Needs Database Activity Monitoring

Over at BoingBoing they have a couple of articles describing how Irish government employees are abusing their access to government systems for personal gain. Everything from idle curiosity about a neighbor, to aiding and abetting burglary. I normally scoff at vendor press releases that jump on the latest media exploitations stories, but in this case I’m going to do it for them. This is, flat out, the poster child for database activity monitoring. As I described in my introduction to the technology, one of the use cases is to create separation of duties by allowing someone to do their job while looking for unusual activity. If nothing else, you could create audit reports that allow managers (or security administrators) to see all the records a particular employee accessed in a given day/week. Perfect? No. Effective? Yep. You’ll need a Database Activity Monitoring tool, and not something that just collects access logs, since you want to see the actual SQL transactions. If the application uses connection pooling to connect to the database, you’ll either need one of the tools that monitors application activity and correlates it with the database, or some sort of identifier in queries to trace which user is submitting the query (something I’ll talk more about in a later post). I’m more than happy to give the Irish government discounted rates if they’d like me to fly over and help fix this problem. My email is posted on the blog. Share:

Share:
Read Post

Understanding And Selecting A DLP Solution: Part 6, Central Administration, Policy Management, and W

Welcome to the second to last post in my series on DLP. You can find the other parts here: Part 1, Part 2, Part 3, Part 4, Part 5. In this post we’ll be covering the major features of the central management server. Our final post will cover recommendations for evaluating and selecting the best tool for your environment. As we’ve discussed throughout this series, all current DLP solutions include a central management server for administering enforcement and detection points, creating and administering policies, incident workflow, and reporting. These features are frequently the most influential in the selection process. There are a lot of differences between the various products on the market; rather than trying to cover every possible feature, we’ll focus on the baseline of functions that are most important. User Interface Unlike other security tools, DLP/CMP tools are often used by non-technical staff ranging from HR, to executive management, to corporate legal and business unit heads. As such the user interface needs to account for this mix of technical and non-technical staff and should be easily customized to meet the needs of any particular user group. Due to the complexity and volume of information a DLP solution may deal with, the user interface can make or break a DLP product. For example, simply highlighting the portions of an email in violation of a policy when displaying the incident can shave minutes off handling time. A DLP user interface should include the following elements: Dashboard: A good dashboard will have user-selectable elements and defaults for technical and non-technical users. Individual elements can be enabled or restricted based on user and group. The dashboard should focus on the information valuable for that user, and not be just a generic system-wide dashboard. Elements should include number and distribution of violations based on severity and channel and other top-level information to summarize the overall risk to the enterprise. Incident Management Queue: The incident management queue is the single most important component of the user interface. This is the screen incident handlers will use to monitor and manage policy violations. The queue should be concise, customizable, and easy to read at a glance. Due to the importance of this feature we will detail recommended functionality later in this post. Single Incident Display: When a handler digs into a single incident, the display should cleanly and concisely summarize the reason for the violation, the user involved, the criticality, the severity (criticality is based on what policy is violated, severity on how substantial the violation is), related incidents, and all other information needed to make an intelligent decision on incident disposition. System Administration: Standard system status and administration interface. Includes user and group administration. Hierarchical Administration: Status and administration for remote components of the DLP solution, such as enforcement points, remote offices, and endpoints. Reporting: A mix of pre-built reports and ad-hoc reporting. Policy Creation and Management: Next to the incident queue this is the most important element of the central management server. It includes the creation and management of policies. Because it’s so important, we’ll cover it in more detail later. A DLP interface should be clean and easy to navigate. That may sound basic, but we’re all far too familiar with poorly designed security tools that rely on the technical skills of the administrator to get around. Since DLP is used outside of security, possibly even outside of IT, the user interface needs to appeal to a wider range of users. Hierarchical Management, Directory Integration, and Role Based Administration DLP policies and enforcement often need to be tailored to the needs of individual business units or geographical locations. Hierarchical management allows you to establish multiple policy servers distributed throughout the organization, with a hierarchy of administration and policies. For example, a geographic region can have its own policy server slaved to a central policy server. That region can create their own specific policies, ignore (with permission) central policies, and handle local incidents. Violations are aggregated on the central server while some policies are always enforced centrally. The DLP tool must support the creation of global and local policies, assign policies for local or global enforcement, and manage multi-regional workflow and reporting. DLP solutions also integrate with enterprise directories (typically Microsoft Active Directory) so violations can be tied to users, not IP addresses. This is complex when you realize you’re dealing with a mix of managed and unmanged (guest/temporary) employees without assigned IP addresses. The integration should tie DHCP leases to users based on their network login, and update to avoid accidentally tying a policy violation to an innocent user. For example, one product in an earlier version would keep a user associated with an IP address until that address was assigned to another user in the directory. One reference almost fired an employee because a contractor, not in Active Directory, was the next person to use that IP and committed a policy violation. The tool tied the violation to the innocent employee. The system should also allow internal role based administration for both internal administrative tasks, and monitoring and enforcement of users. Internally, users can be assigned to administrative and policy groups for separation of duties. For example, someone can be given the role of enforcing any policy assigned to the accounting group, but not administer the system, create policies, see violations for any other group, or alter policies. Since your Active Directory might not fully represent how you’d like to divide up monitored users, the system should also support groups and roles for dividing up employees for monitoring and enforcement. Policy Creation and Management Policy management and creation is a critical function at the heart of DLP solutions; it’s also (potentially) the most difficult part of managing DLP. The policy creation interface should be accessible to both technical and non-technical users, although heavily customized policies will nearly always need technical skills to define. For policy creation, the system should let you identify the kind of data to protect, a source (if needed)

Share:
Read Post

Totally Transparent Research is the embodiment of how we work at Securosis. It’s our core operating philosophy, our research policy, and a specific process. We initially developed it to help maintain objectivity while producing licensed research, but its benefits extend to all aspects of our business.

Going beyond Open Source Research, and a far cry from the traditional syndicated research model, we think it’s the best way to produce independent, objective, quality research.

Here’s how it works:

  • Content is developed ‘live’ on the blog. Primary research is generally released in pieces, as a series of posts, so we can digest and integrate feedback, making the end results much stronger than traditional “ivory tower” research.
  • Comments are enabled for posts. All comments are kept except for spam, personal insults of a clearly inflammatory nature, and completely off-topic content that distracts from the discussion. We welcome comments critical of the work, even if somewhat insulting to the authors. Really.
  • Anyone can comment, and no registration is required. Vendors or consultants with a relevant product or offering must properly identify themselves. While their comments won’t be deleted, the writer/moderator will “call out”, identify, and possibly ridicule vendors who fail to do so.
  • Vendors considering licensing the content are welcome to provide feedback, but it must be posted in the comments - just like everyone else. There is no back channel influence on the research findings or posts.
    Analysts must reply to comments and defend the research position, or agree to modify the content.
  • At the end of the post series, the analyst compiles the posts into a paper, presentation, or other delivery vehicle. Public comments/input factors into the research, where appropriate.
  • If the research is distributed as a paper, significant commenters/contributors are acknowledged in the opening of the report. If they did not post their real names, handles used for comments are listed. Commenters do not retain any rights to the report, but their contributions will be recognized.
  • All primary research will be released under a Creative Commons license. The current license is Non-Commercial, Attribution. The analyst, at their discretion, may add a Derivative Works or Share Alike condition.
  • Securosis primary research does not discuss specific vendors or specific products/offerings, unless used to provide context, contrast or to make a point (which is very very rare).
    Although quotes from published primary research (and published primary research only) may be used in press releases, said quotes may never mention a specific vendor, even if the vendor is mentioned in the source report. Securosis must approve any quote to appear in any vendor marketing collateral.
  • Final primary research will be posted on the blog with open comments.
  • Research will be updated periodically to reflect market realities, based on the discretion of the primary analyst. Updated research will be dated and given a version number.
    For research that cannot be developed using this model, such as complex principles or models that are unsuited for a series of blog posts, the content will be chunked up and posted at or before release of the paper to solicit public feedback, and provide an open venue for comments and criticisms.
  • In rare cases Securosis may write papers outside of the primary research agenda, but only if the end result can be non-biased and valuable to the user community to supplement industry-wide efforts or advances. A “Radically Transparent Research” process will be followed in developing these papers, where absolutely all materials are public at all stages of development, including communications (email, call notes).
    Only the free primary research released on our site can be licensed. We will not accept licensing fees on research we charge users to access.
  • All licensed research will be clearly labeled with the licensees. No licensed research will be released without indicating the sources of licensing fees. Again, there will be no back channel influence. We’re open and transparent about our revenue sources.

In essence, we develop all of our research out in the open, and not only seek public comments, but keep those comments indefinitely as a record of the research creation process. If you believe we are biased or not doing our homework, you can call us out on it and it will be there in the record. Our philosophy involves cracking open the research process, and using our readers to eliminate bias and enhance the quality of the work.

On the back end, here’s how we handle this approach with licensees:

  • Licensees may propose paper topics. The topic may be accepted if it is consistent with the Securosis research agenda and goals, but only if it can be covered without bias and will be valuable to the end user community.
  • Analysts produce research according to their own research agendas, and may offer licensing under the same objectivity requirements.
  • The potential licensee will be provided an outline of our research positions and the potential research product so they can determine if it is likely to meet their objectives.
  • Once the licensee agrees, development of the primary research content begins, following the Totally Transparent Research process as outlined above. At this point, there is no money exchanged.
  • Upon completion of the paper, the licensee will receive a release candidate to determine whether the final result still meets their needs.
  • If the content does not meet their needs, the licensee is not required to pay, and the research will be released without licensing or with alternate licensees.
  • Licensees may host and reuse the content for the length of the license (typically one year). This includes placing the content behind a registration process, posting on white paper networks, or translation into other languages. The research will always be hosted at Securosis for free without registration.

Here is the language we currently place in our research project agreements:

Content will be created independently of LICENSEE with no obligations for payment. Once content is complete, LICENSEE will have a 3 day review period to determine if the content meets corporate objectives. If the content is unsuitable, LICENSEE will not be obligated for any payment and Securosis is free to distribute the whitepaper without branding or with alternate licensees, and will not complete any associated webcasts for the declining LICENSEE. Content licensing, webcasts and payment are contingent on the content being acceptable to LICENSEE. This maintains objectivity while limiting the risk to LICENSEE. Securosis maintains all rights to the content and to include Securosis branding in addition to any licensee branding.

Even this process itself is open to criticism. If you have questions or comments, you can email us or comment on the blog.