Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, June 28, 2011

Security & Cybercrime Symposium

Slides from my presentation at the Security & Cybercrime Symposium are up.

I had a bit of a hectic day, having hosted the ISACA Scotland AGM in the morning, but I made it to Napier University in time to catch the majority of the speakers, as well as to present my piece on where we need to fix the problems with IT and Information Security.

Bill Buchanan and team did a grand job of organising the day - it was an excellent networking opportunity and had some thought provoking presentations.





  • Not with eductaion security professionals - we know this stuff - and not with developers - in general developers want to get this right...


  • It's persuading the business owners to give a **** about it, to sponsor it, to require secure code, to budget for it etc.



  • And to do this we need to get much better at talking their language. No-one in business is going to learn to speak IT Security, so we need to talk business risk, operational risk, real impact to the organisation.
Especially with the more technical approach the other speakers took (and the expectation that I too would go into technical detail) this talk went down very well :-)

The list of speakers was:

Tony Mole - Head of the Scottish Drug Enforcement Agency (SCDEA)
Ian Bryant - Principal Information Security specialist at HM Government
Fred Piper - Royal Holloway
Don Smith - Dell SecureWorks
Tabassum Sharif - Flexiant
Rory Alsop - Alsop Consulting
Mike Dickson - SCDEA
Alan Moffat - Scottish Information Assurance Forum.
Russell Scott - Scottish Police
Nigel Jones - 2Centre
Martin Borrett - Director of the IBM Institute of Advanced Security in Europe
John Howie - Head of Cloud Services within Microsoft plc

Friday, February 18, 2011

B Sides San Francisco

Day 1 of B-Sides San Francisco

The awesome guys at Security Stack Exchange got me 8000 miles across the world to blog B-Sides San Francisco, and it was an amazing opportunity to mix with Infosec professionals from various industries.

All my photos from this trip are on my Picasa page.

My highlights from Day 1:

Gone in 60 keystrokes:Dr Mike Lloyd:Red Seal
Sure, this was a vendor presentation, designed to point out a problem which his product solves well, but Mike didn't ram that point home. His presentation was solidly grounded in real world experience. Mike listed common errors which creep in on even the simplest firewall rulesets - incorrect netmasks, a user readable label for an IP address not matching the actual address etc.

In a small ruleset, a visual inspection - going over the printout with a highlighter may
be enough, but for an enterprise firewall, not only do you come across much larger rulesets, but the risk or impact may also be higher.
Mike's guidance - instead of trawling the ruleset manually, focus on outcomes to understand what is happening - what does the network do? Where does information flow? Where is authentication used? Where do 3rd parties connect?

Security, Supply Chains and You:Hart Rossman:SAIC
Another good real world talk. Hart provided excellent detail on a variety of areas where supply chain errors will impact a business - nothing new, but solid examples of what goes wrong.

Screw The TSA - I'll Be Where I Want And Get Credit For It:Ray Kelly:Barracuda Networks
Location based social networking - how does it work, how can we exploit it?
Examples include 4square, MeetMoi (a seriously creepy stalking location based dating tool) and Ratio Finder (an app which uses 4square - checks where most women and men are...)

The problem with these apps is the same old one: they trust the browser to send correct data. As an example, 4square sends a variable called VID, along with location coordinates. The only check on 4square seems to be a quick validation on speed (eg if I check in in the UK, and then check in in the US 5 minutes later it won't believe I am there. It will let me check in, but not credit me with really being there)

So why is this interesting?

To provide an alibi? Maybe.
To create a perception of your lifestyle? Possible.
To get free stuff? Definitely: More and more retail outlets provide freebies and giveaways to people who check in - simple win: google for a 4square giveaway, check in and collect.


Letting Someone Else's Phone Ring At 3am: Building Robust Incident Management Frameworks:Andy Ellis:Akamai

As Akamai has an extremely large network, and a vast number of clients depending on uptime and performance, managing outages or loads quickly and efficiently is important. The key, according to Andy, is to minimise those things which can impact the response - human error, tiredness, lack of knowledge, lack of understanding, lack of key contacts etc.
Initial thoughts

Automate tools in advance
Be prepared for things to break
Get to the best person as quickly as possible
Segregate response functions to avoid neural congestion
Design to scale up and down
Learn from your mistakes

3 'standing' conference bridges are used for incidents so main one does not get clogged.
To get the best people on the incident, Akamai encourage self-reliance and delegated responsibilities by training throughout. All development managers are given responsibility for fixing their own area, and are provided training to support this.
During an incident, crisis managers are allowed to bypass controls in order to solve the problem quickly.
Common context has been defined, so all can understand severity (4 severity levels)
4 phases are also used:

it's broken (minutes count)
it's bandaged (hours count)
it's fixed (days count)
learn from it

Each incident has Noc technician. They get platform exec or SME. Each team has to provide a list of folks to call, and the order to call them in.
Multiple roles are avoided. Roles are handed off after 4-9 hours to allow team members to rest. Unnecessary team members are dismissed from the team.
Vulnerabilities and projects are tracked and measured.
Learning at all levels - system owner (what do I fix), directors (How do I stop this sort of thing happening again), c-level (What trends need to be dealt with)

The Afterparty was also a great success, with DualCore keeping the crowd entertained until the early hours.

After that, the hardcore crowd ended up at Denny's, talking security, politics, gun control and the early hacking scene, as well as the Security Stack Exchange concept and my band's nomination for an award (we ended up coming 2nd in the Metal category of the Scottish Alternative Music Awards)

Day 2 of B-Sides SF (pictures all up now on my Picasa page)

After very little sleep, headed over to Zeum early and as one of the volunteers was missing presumed sick I volunteered to be a Roamer for the day. Red T-shirt (would this mean I wasn't going to return to the Enterprise?), earpiece and simple duties (keep an eye out for people going where they shouldn't.)

There were so many good speakers on Day 2 I found myself dotting between them to try and pick up content, but I did enjoy Anton Chuvakin's talk on SIEM. Key point he made was that you need to plan resource for it. I quote "If you only have an hour a month to do SIEM, stick to log management. Dedicate at least 50% of someones time"

Andrew Hay, Richard Bejtlich and Travis Reese's talk on Cyber Security Marketecture was well received as well. Some arguments about particular points, but in a generally productive spirit. I think they focused a little too hard on APT to the exclusion of all else, but they did cover APT in a rational way, unlike the usual FUD. I like the comment about Stuxnet - not very advanced or persistent but definitely a cyber warfare threat.

I also managed to get brief interviews with Jack Daniel of Astaro and Jon Speer of Tripwire to find out what sponsors get out of BSides. They both had remarkably similar viewpoints. They see value from:

  • Connecting with security professionals
  • Learning from and teaching the security community
  • Meeting potential employees
  • Having fun
For those companies not sure, just get involved. Sponsor as little or as much as you can, and be part of the community.

After lunch I managed to win The Manga Guide to Databases in the raffle (Excellent Prize) before the BSidesSF Carousel ride!

Dave Shackleford and Andrew Hay's "A Brief History of Hacking" was also very entertaining, including along the way the good and bad hacker films.

Robert Zigweid of IOActive then spoke about a topic quite close to our hearts here at 7 Elements - Threat modelling taxonomy. He splits out into the following types:

  • spoofing
  • tampering
  • repudiation
  • information disclosure
  • denial of service
  • privilege escalation

And these impact categories:

  • damage potential
  • reproduceability
  • exploitability
  • affected users
  • discoverability

Damon Cortesi's talk on Developers also included Threat Modelling - it is becoming pervasive.

The EFF panel were very well received but I only caught a small piece of it: key usage of end to end encryption to avoid compromise from threat sources as well as to avoid misuse by governments and their view that subject lines and text messages are definitely content, and email addresses and IP addresses may be in certain circumstances.

Raffael Marty's log analysis and visualisation in the cloud. This is an area which is likely to become all too important as more and more services are pushed to the cloud. Loggly have the concept of logging as a service, and Raffael's talk included an important piece on the need for visibility of dynamically scaling virtualised environments and the hypervisor, as well as availability.

I then said my goodbyes to the wonderful BSidesSF folks and volunteers - Banasidhe, MikD, djbphaedrus, Duckie, CindyV etc and headed east for the Owasp meet, where we had very worrying discussion around the security of critical national infrastructure...

Day 3 - RSA, ISACA and IISP

After all the B-Sides fun and games, I managed to get an Expo pass for RSA (thanks to the Damballa folks) so thought I should pop in, chat to a few key folks and grab some swag to take home.

Highlights:

  • I got to take apart a real Enigma machine at the NSA booth!
  • Almost won a kindle at the M86 quizshow
  • Had a good chat with the Australians at the Cryptsoft booth
  • Learned all about splunk
  • Had to sit through a very content free Kaspersky talk
  • Gal Shpantzer gave me a good Becrypt run through
  • Had far too many burgers at the Qualys bar
Made it back to the hotel in time to try and repack my bags with all the swag before heading off to the airport. Fairly uneventful trip the 8000 miles back home and arrived in Edinburgh just in time to host a talk by Louise Behan of the Specialist Fraud Squad on behalf of ISACA Scotland and the Scottish branch of the Institute of Information Security Professionals. It's been a long week :-)

Tuesday, January 18, 2011

Improvement and Education in the Security Community

Those of you who know me will know how keen I am on helping the continued professionalisation of information security, and in providing training, guidance and steer back to the community. I get a lot of queries from individuals in IT or Information Security roles asking for more ways to get information, improve their skillset or even just to learn from others.

Many of you may be familiar with the Stack Exchange family of websites - a question and answer site using reputation weightings to help individuals find answers that they can trust.

We have been working with a new one - Security Stack Exchange - near the end of its public beta - that aims to provide security professionals with a forum thttp://www.blogger.com/img/blank.gifo ask or answer questions around security, risk, governance etc.http://www.blogger.com/img/blank.gif

Some examples to show the range of questions already on the site:

Securing the security guy's home office: what should we do?
http://www.blogger.com/img/blank.gif
Although Incident Response is often handled well in larger organisations, it is very relevant for smaller companies

Establishing routines on what to do if a PC gets stolen?

Security around database password hashing:

If I hash passwords before storing them in my database, is that sufficient to prevent them being retrieved by anyone?

If you deal with information or IT security, governance or risk your input could be very valuable, or if you have questions in these areas someone on the forum could help you out. Either way, have a look and see what you think.

Monday, December 20, 2010

Working from home - securing your environment

More and more people are working from home, and since an article I wrote for the Financial Times a few years back I have had more and more people ask about what can be done to make their home environment a little more secure without breaking the bank.

After some of the discussion on IT Security Stack Exchange, and especially this question, I thought it would be worthwhile popping the link up here, as it is likely to generate a fair amount of traffic, whether it be opinion, fact or discussion.

Go have a look.

Wednesday, November 17, 2010

Security in Scotland

A topic very dear to me is the development of the Information Security profession, but specifically in Scotland, and I thought it would be worthwhile posting some information on initiatives in Scotland that help with this aim, as well as discuss areas where stronger involvement from the wider industry would be welcomed. We have selected a few of the key organisations and events, but if you feel we another is key, please let us know and we'll update this post.

The Institute of Information Security Professionals, of which Rory Alsop is the Scottish chair, is providing support and guidance to universities and companies across the UK through the Graduate Development Scheme, Academic Partnerships, the Accredited Training Scheme and the IISP Skills Framework. The IISP's mission is to be the authoritative body for information security professionals, with the principal objective to advance the professionalism of the industry as a whole. Whilst the existing IISP membership in Scotland is strong I would encourage individuals and companies to visit the website or speak to representatives to understand what they can get out of membership (at all levels from student through to full membership) and more importantly for the industry what they can offer in return from their own experience or skills. The IISP always welcomes speakers who have a story to tell in the information security space, so please get in touch if you would like to present at one of our quarterly events.

Similarly, ISACA aims to define the roles of information systems governance, security, audit and assurance professionals. Through close links with local industry, ISACA Scotland provides guidance, benchmarks and effective tools for organisations in Scotland. The majority of members in Scotland have the CISA certification so here there is a very strong focus on audit and control, but we are seeing increasing numbers in security management, governance of enterprise IT and risk and information systems control. Like the IISP, ISACA Scotland would welcome guest presenters or new members - the global knowledge base and information flow are extensive and the opportunities for networking are invaluable.

The Scottish Universities, under the guidance of Professor Buchanan have created the framework for a Centre of Excellence in Security and Cybercrime in Scotland - with strong links already forming between academia, law enforcement, industry and professional bodies such as the IISP. One goal is to provide academia with a greater awareness of real world security issues and activities through a number of avenues including volunteer work, summer placements, guest lecturers etc. From the perspective of your organisation, if you find that when hiring software developers, for example, you need to give them additional training in secure development or spend resource remediating vulnerable code, the argument for providing a small amount of resource to help develop coursework in these subjects, or to provide the odd guest lecture is a very strong one. As an industry we can make great improvements by simply providing the new entrants with the benefits of at least some of our years learning the hard way.

The e-Crime Scotland website was officially launched at the Scottish Financial Crime Group Conference on the 28th of October. Currently this has been set up with support from, and using the framework developed by the Welsh Assembly, demonstrating an excellent level of sharing of expertise and resource. This website provides a portal of information on e-crime, a reporting mechanism and is planned to develop as Scotland takes greater ownership of content.

The Scottish Financial Crime Group, under the ownership of the Scottish Business Crime Centre, has been working with law enforcement and clearing banks for the last 35 years, but more recently through the annual conferences and an active presence in many forums has been in a good position to draw on expertise from a wide range of specialist individuals and organisations to develop opportunities to disrupt the criminal element in our society. Membership of the SFCG or at the very least, attendance at the annual conference is invaluable both from a learning perspective and an opportunity to influence discussion relating to financial crime.

The National Information Security Conference is held in St. Andrews each summer and provides speakers renowned within their field, education and an excellent networking opportunity to meet like minded individuals from industry and security experts. This three day residential event attracts many security professionals who are trying to drive the industry forwards and should not be missed!

On the more technical front, the Scottish OWASP chapter, headed up by Rory McCune is a growing group of individuals from across various industries focused on improving web application security. Join the mailing list to find out about meetings, initiatives etc. The scope of interest includes everything from SCADA to online banking and from smart meters to social networking.

Wednesday, September 22, 2010

Life changing moments:

After 9 1/2 years as Scottish Security Lead with Ernst & Young I've just started a new role as a Director at 7 Elements. Along with two other notable names in Information Security in Scotland we will provide technical security consultancy and penetration testing services.

As part of that we've started up a blog here to talk through some of the ideas we've got for approaching security and testing in a pragmatic way.

There may be the odd post here, but all industry focused stuff will be on the 7 Elements blog or cross posted to twitter.