Tuesday, February 8, 2011

Know Thyself -> Subtitle: Is DIY always a good idea?


A recent presentation I did at work for management about justifying hosted SIEM (Security Information & Event Management) and some follow-up questions from leadership got me thinking about the do it yourself ethos. I think IT in general and InfoSec specifically are big on DIY and this is for the most part a good thing in my opinion.

Products/solutions like Snort/Wireshark/Metasploit/etc. would not be what they are today without the roll up your sleeves, pour yourself another cup of caffeine, get down to the bits and bytes or hex command line foo.

(You knew the but was coming.) But when does trying to be all ninjas to all people become your achilles heel? If you are in a small IT shop is it realistic to think I (or perhaps you the reader) can be a master of all [CISSP] domains? Could trying to do it all lead to missing important stuff while trying to figure out whether or not to worry about a particular IDS event that may or may not be important.

Maybe this is about trying to reassure myself that the insecurity devil that occasionally sits on my left shoulder saying "YOU ARE A NOOB AND A POSER AND YOU WILL NEVER BE A NINJA" is just a figment of my imagination. Or perhaps I am taking a look in the mirror and trying to have an honest self assessment and admit that I am better off finding a good consulting shop to help me tune my IDS/IPS or perhaps hiring out some security functions such as log/event analysis ala SIEM.

Everyone has different gifts/talents/abilities. Knowing yours and admitting which hats do not fit is sometimes painful but can also be a liberating experience and lead to focusing on what gets you fired up.

Sources:
- This post was inspired in part by a radio program I heard featuring Christian author/speaker Chip Ingram about doing a sober self assessment - identify your 3 greatest strengths and 3 biggest weaknesses, there was more to the talk but this to me was the crux.
- The thinking chimp photo is just something I thought about after watching a Nature episode on monkeys - did you know some monkeys have learned to lie and they also have squabbles between groups which lead to injury and death?

Friday, December 31, 2010

My 2011 prediction = more of the same


Since I am not able to predict the future and I don't have enough big picture expertise in InfoSec to make intelligent and plausible predictions, I am going to take the easy way out. I know it isn't exactly exciting and you might even call it lame, but I predict 2011 will bring more of the same. (I am not a poet, and I know it.)
  1. Increasingly frequent financial data breaches ala TJX and Heartland
  2. Malware, malware, and STILL MORE malware - and likely even more crafty varieties
  3. Finally, the one that freaks me out most of all - more SCADA/Control System activity ala Stuxnet. Even without (alleged ;) government involvement, no doubt the bad guys took careful notes of the possibilities. The terrorists and government sponsored groups are likely pulling down additional copies of Siemens, Schneider, Rockwell, Modicon et al softwarez and likely also buying a representative bunch of PLCs to increase their mad skillz in pawning pumps, valves and variable frequency drives.
Best wishes to you and yours for 2011, and for those of us wearing the InfoSec white hats - as they used to say on Hillstreet Blues: "Let's be careful out there."

Thursday, December 16, 2010

More Amusing Malware




So this one really cracked me up. My friend and co-worker Matt are chatting about this and that with an infected client sitting behind us running a virus scan when BOOM the computer came to life with another of your garden variety fake AV. It was funny and sad at the same time.

It gets better, after pulling the Ethernet plug out and watching to see what Matt calls the bad mojo was going to do next (several minutes passed, not much happening) then all of a sudden the following warning about an attack/threat from a specific IP.

If the bad guys can block threats even when the computer is offline, that is simply cool and yet unfortunately impossible. I love my job.

Monday, December 13, 2010

InfoSec FUD Marketing



I received this email recently and I think it hit on my last good nerve. C'mon people, do we really need this kind of crap going around in 2010?

If this email works to drum up business for a telecom/security/whatever consulting group, I would really like to find out who the people are biting on this particular fish hook. I would call them myself under the guise of Doug's Ninja Service LLC as I think I could also sell them some DLP snake oil or perhaps a bit of magic pixie dust that stops all future malware variants - in the cloud.

Thursday, December 2, 2010

Censorship be damned


December in Michigan began with a snowstorm and a chill in the air that seems to be stuck inside my bones. While it does not seem to have affected my lukewarm heart, the jury is still out.

I thought that I would begin the last month of the year by posting a PDF of my absolute fave blog post of 2010. I can say that now because there is no possible way to upstage this gem.

Matt Olney of Sourcefire VRT fame posted a somewhat inflammatory but 100% spot on rant that was shortly thereafter removed. I made a PDF from the ever useful Google cache version and am posting it here until the ever witty and sharp tongued Mr. Olney asks me to remove it himself.

The Rise of the Citizen Cyberwarrior by Matt Olney

Monday, November 29, 2010

Cloudy with a chance of better security


I have been mulling over cloud computing a little bit lately. My thoughts (as usual) are pretty simplistic so far. I work in the small/medium environment where good InfoSec is rare as hens teeth. IMHO, the issues are primarily time and expertise. Small IT shops tend to be reactive and spend a lot of time firefighting. Proactive security is just plain hard, and when you are doing InfoSec as a sideline or a hobby within your daily work it is a million baby steps to reach a decent security posture ala 2010. Can it be done? Yes. Do I feel like I am there yet? Not even close, but moving in the right direction.

So take virtualization and then take cloud computing aka using somebody else's virtual infrastructure by way of the Internets. I am all about that. If it is possible for say Google Apps or Microsoft's "Cloud Power" to serve up COTS applications and protect data in a way that prevents people from the usual bad habits i.e. emailing themselves that spreadsheet full of PII, what is the downside? Plus if cloud computing means that we can move to a thin client desktop approach where few applications need to be installed after the inevitable malware infection(s), then my good friend Matt the desktop guy has a reduced suck factor. That's a win-win in my book.

At the risk of over-statement, do I really believe I can do security better than say Google, Microsoft or Amazon AWS? I guess it depends on how arrogant and/or delusional I am. Enough said.

There is some good reading on Lenny Zeltser's blog around how the risk factors in the Cloud are not all unique in comparison to other disruptive technologies. As for me, I can't wait to stick my head and hands in the cloud(s) - and keep them there.

Wednesday, November 17, 2010

Fake AV - Phunny Fail


If you are in IT these days you likely see your fair share of fake/rogue antivirus malware, be it @ work or home (or your beloved Aunt Edna - you know the one who always forwards you the Nigerian 419 scam emails wanting to know when to expect the big payoff.)

Last week at work a co-worker received a drive-by 'gift' of goodness on his XP box. We use WSUS for the Microsoft patches and Symantec Endpoint Protection for client side I'net 'security'/AV and your mileage probably sucks as bad as ours. We're still trying to win the battle on Adobe / Apple patching, not there yet but moving along.

Anywho, this particular fake AV crapware does something really quite hilarious - it changes your desktop wallpaper to a FUD factor alarmist litany of bad things that can happen if you disregard the pleas of the badware to detach yourself from your hard earned $50 which will be guaranteed to do nothing but lead to someone spending more money (with your card number.)

If you believe the above warning - all those movies/MP3s you deleted are STILL THERE and "could break your life!" It is too bad the author's English was not up to par. Some days you just gotta laugh, 'cause the crying gets old after a while. And while I hate malware as much as the next guy, no one I know of has ever died from an infection.

Image courtesy of the Rogue Antispyware blog, a great resource for all the latest Fake AV news.