Wednesday, July 20, 2016

BSidesCLE 2016 (belated) Summary

Almost a month since BSidesCLE 2016 and due to some elective medical modifications and the associated time off my feet I finally have some time to write about the event. Which was great again. First, huge props to all of our sponsors and partners:

Event Sponsor: TrustedSec
Diamond Sponsors: Black Box Network Services and Cisco Systems
Silver Sponsors: Hurricane Labs, StealthCare, SANS Institute, Optiv
Beer Sponsor: Hardbit Solutions featuring Actual Brewery
A/V Partner: Something New Entertainment
Video Recording: Adrian Crenshaw of TrustedSec
Venue: Grog Shop and B-Side Liquor Lounge and Arcade
Lunch Provider: Fired Up Taco Food Truck

More props to all of our volunteers who helped make the event run smooth and helped Adrian and Something New Entertainment ensure the whole event went smooth.

Special thanks to our trainers who helped us offer specialized infosec training at BSidesCLE for the first time this year the day before the conference. It was a great learning experience that we will definitely improve upon next year, and with one HUGE exception, was a success. That exception is the fact that one of our trainers was a no show and we had a full room of 25 people who paid for this person's training sitting in the room waiting for this person to show up while myself and our organizers tried to get in touch with the trainer unsuccessfully. we discovered he ended up accepting a talking spot at BSidesAthens Greece the same weekend and neglected to tell us. I do not intend to derail this post of all of the great things that happened at BSidesCLE with more of this, but so far this person has yet to reach out to explain and/or apologize, so I'll leave it at that.

We had record setting attendance this year and have some interesting associated metrics. This is the 3rd BSidesCLE that this organizational group has put on and for the first time, as a result of the human association that "free" does not necessarily have "value", we decided to charge $5 for shirts this year. Oddly enough, 80+ percent of the people who either paid the $5 for a shirt or graciously donated to the event through eventbrite showed up to the event. Contrasted with the ~40% of the people who fairly chose a free ticket and actually showed up. The organizers will analyze this further to determine where we take this data for BSidesCLE 2017, but even if we made it $5 for the event across the board and $10 for a shirt I feel it is safe to say most would still agree the value proposition would still be absolutely worth it given the amount of knowledge, talent, food, alcohol and genuine infosec community family values BSidesCLE brings.

The one drawback to being an organizer is we don't have the luxury of watching all of the talks, but I did catch portions of some really great ones. Keynotes aside (who all were amazing) some mini highlights I briefly really enjoyed include Nir Yosha, Cameron Moore, Adam Hogan, Charles Yost, Jimmy Byrd, Brad Hegrat, Eric Mikulas, Kevin Gennuso, Wolf Goerlich and rookies Raquel Milligan and Jonathan Cartwright. This week I also intend to catch up on the videos Adrian and team recorded. I also caught about 10 minutes of Jeremy Mio's talk on government cyber attack response, which was not recorded at his request, but was pretty dark, great stuff. Pick his brain about it.

Ian's morning keynote was an exceptional talk on actual effective security testing and risk analysis that provides true value in the real world, and due to a new job may be his last public facing talk for a time. Chris' lunch keynote was amazing and controversial as he is wont to do and definitely will have me thinking about the vulnerabilities of the food chain for some time. And Dave K was Dave K, nuff said. Again super thanks to our three keynotes.

Thanks to all who attended and participated, I hope everyone enjoyed all aspects of the event and if anyone has any questions/comments/suggestions feel free to reach out to any one of us.

Tip your bartenders! Cheers.

Thursday, June 23, 2016

Pre-BSidesCLE post

This is exciting. First year we've offered training, so we purposely kept the number of tracks relatively low and still had double the number of submissions than slots available, which was great, but also tough decision making. Sign up for the selected talks has been excellent and tomorrow we will be trying this for the first time. We are ready. Today, 6/23, the only thing we are waiting for are the programs and stickers which both should be ready tomorrow. The conference itself (sold out) has another great schedule. Opening comments at 8:45AM 6/25, first keynote at 9AM. Ian Amit, Chris Roberts and hometown hero Dave K are this year's keynotes. Bloody mary bar opens at 8 and will be complimented by mimosas, fired up taco food truck for lunch, beer sponsor hardbit solutions will be providing actual brewery microbrews, amazing sponsors and 3 tracks of awesome knowledge. See you there!

Thursday, February 18, 2016

BSidesCLE 2016 planning

We are well underway for our 2016 event, which is Saturday, June 25th and again at the legendary indie rock venue the Grog Shop in Cleveland Height's Coventry locale. TrustedSec has already signed on as our Event Sponsor for the 2nd year in a row! The CFP is open now and runs until 5/1 and can be found here. New this year #BSidesCLE will be having a training day! Friday, June 24th will be dedicated for training and we will have multiple tracks. The Call for Trainers is open, will also be open until 5/1 and can be found here.

We have an amazing group of keynotes (this year there will be morning, afternoon and closing keynote slots) - Chris Roberts (@sidragon1), Dave Kennedy (@hackingdave) and Ian Amit (@iiamit). Holy crap, this is going to be dope! Again! More info will be forthcoming. You can get tickets here. See you there.

Saturday, June 27, 2015

BSidesCLE - The good and the bad

Don't get me wrong, there's not much bad to take away from BSidesCLE 2015. The good includes another amazing event with fantastic sponsors:

  • Event Sponsor - TrustedSec
  • AfterParty Sponsor - Heureka Software
  • Diamond Sponsors - Black Box, Cisco
  • Gold Sponsor - Hurricane Labs
  • Silver Sponsors - Emerging Technologies Group, OpenDNS and Rapid7
  • A/V Partner - Something New Entertainment
  • Beer Sponsor - Actual Brewery and Hardbit Solutions
Amazing speakers and talks, all of which were recorded by Irongeek and are here. Jack's and Chris' keynotes are must sees, special thanks to them for coming out and spending time with us.

Good turnout, great attendees, free ticket, free shirt, free badge, free beer, free breakfast, free bloody mary bar, free taco food truck, free dinner for those who stuck around for the afterparty. A dedicated crew from PGH even figured out and won the crypto challenge late in the evening.

With all of that free awesomeness it baffles me that we had close to 35% no shows. Was it that the next day was father's day? C'mon, the crypto key on the shirt was BADDAD in honor of the fact that there were definitely a bunch of fathers spending their time at the Grog Shop instead of with their family on father's day weekend. No, general consensus was that many people don't put value in free, since they didn't have any skin in the game they can easily blow it off without thinking about it too much.

Could be, there is merit to that. Irrespective, I now have just shy of 100 badges, bags and badass BADDAD glow in the dark shirts in boxes in my dining room waiting to go to Goodwill because whatever the reason and those dollars could have been spent on doorprizes and such for those who spent time with us this year. Do we charge next year to make it more of an investment just to get more people to show up?

I am open to suggestions, hit me on twitter @rockiebrockway

Thanks again to my co-organizers, sponsors, speakers, volunteers, the grog/bside crew and everyone who made BSidesCLE 2015 another smashing success and super fun event. I love helping to run the event and am always looking for areas of improvement.

Friday, February 20, 2015

BSidesCLE 2015 Planning

The BSidesCLE crew is back again for another round of planning an awesome event. We lost one of our partners in crime to the fact that there aren't enough hours in a day, big props to Jim Kennedy for helping us get last year's event off the ground and a huge success. We are welcoming one of our great volunteers from last year Justin Alcorn in to assist in the planning efforts in Jim's absence.

This year's event is taking place at the same phenomenal venue, the legendary indie-rock club Grog Shop and the associated BSide Liquor Lounge and Arcade, and is set for June 20, 2015. The CFP is now open http://t.co/9JwgFAJQZO. Our sponsor levels will be posted in the next couple of days, as will the tickets, and we're trying to lure in some great keynotes, more to come on that.

We're looking forward to another great event, see you there.

Tuesday, August 19, 2014

random musing

If you're not looking at "cybersecurity" as a strategic risk to the business, you're not prepared to successfully adapt your business in this rapidly changing technical climate where both your business and your adversary's business are intertwined with the same advanced technologies.

Wednesday, July 30, 2014

BSidesCLE 2014 Success

BSidesCLE 2014 is over and was a huge success. I'm not sure how, but there really were no major hiccoughs anywhere and it all went very smooth. There were a couple of cable fails here and there but for the most part it was a smashing success. Total attendance was a little over 200 and a lot of people stayed through the day and through the dinner and after-party. We provided coffee, bagels and muffins in the AM, the FiredUp Taco Food truck for lunch and Fried Chicken, parmesan redskin potatoes and salad for those that stayed around for dinner and afterparty. Actual Brewery from Columbus provided a couple of kegs of their microbrews (which were great) and we had a bloody mary bar for most of the AM. Our venue was the legendary Grog Shop music bar and their associated underground lounge below it called the BSide Arcade and Liquor Lounge (after all the talks were done we fired up the pinball and video games).

Much thanks to our awesome speakers:

Dave Kennedy
Ed McCabe
Brandon Geise
Spencer McIntyre
Jamie Murdock
Mark Kikta
Adrian Crenshaw
Kevin Gennuso
Eric Mikulas
Adam Hogan
Jeff Moss
Doug Hiwiller
Damon Ramsey
Gregorie Thomas
Deral Heiland
Zach Wojton
Nick Jacob
Steven Legg
Nathaniel Maier
Tom Kopchak
Warren Kopp

Much thanks to our great sponsors:

Black Box
Sourcefire
Something New Entertainment
Information Security Summit
Hurricane Labs
SecureState
Actual Brewery

Super thanks to our venue:

Grog Shop
BSide Liquor Lounge Arcade

Thanks to our volunteers:

Brent McRoberts
Justin Schmitt
Justin Alcorn
Jason Ashton
Alex Kott

Thanks to my co-organizers:

Justin Herman
Anna-Jeannine Herman
Ben Pijor
Jim Kennedy
Susie Brockway
Joshua Lochner

And thanks for everyone who attended and made BSidesCLE an amazing event. We will see you next year.

Monday, July 7, 2014

BSidesCleveland 2014

For those of you who are not aware, I recently joined a small group of other North East Ohio maniacs to organize BSidesCleveland 2014. We are coming down to the home stretch w/ the event scheduled for July 19th. Badges and shirts have been ordered. The venue is amazing (track 1: www.grogshop.gs and track 2: www.bsideliquorlounge.com) . There will be a bloody mary bar. We have a beer sponsor (www.actualbrewing.com). We have a food truck to provide lunch for all attendees, speakers and staff (www.fireduptacotruck.com). The talks look amazing and the speaker list is a great combination of veterans as well as rookies, as a BSides event should be. The sponsors have been great as well as generous. It is looking like we will be able to swing a BBQ for all who wish to float from the Con to the afterparty. All info is at www.BSidesCLE.com. There are still many things to do but much of the heavy lifting is over and I'm happy about that. We're shutting down registration this evening as capacity has been met. Thanks to all my fellow organizers and I hope to see many of you who may happen to be reading this there.

Thursday, April 25, 2013

Upcoming posts

I've been both busy and semi-meh about posting over the last few months. I've been working on a number of projects as well as some independent research. Expect to see the following in the near future:

  • Business adaptation/unpredictability
  • Enterprise-class Vulnerability Management/Incident Response
  • The ugly truth about EMR systems and real world medicine
  • Geek pentesting
    • Bypass Cisco NAC/ISE (not very sexy)
    • Custom PE/AV bypass (I know ... yawn)

Saturday, October 20, 2012

Derbycon 2

This post is a couple of weeks overdue. After having gone to the inaugural event last year I submitted a paper this year that was accepted (stable talk). So wifey and I (and this year accompanied with one of my team members) headed down to Louisville and the second annual DerbyCon.

I signed up for Chris Nickerson's and Ian Amit's Red team training, which was great and at several times completely overwhelming. Tons of great tools I'd never even heard of, some fun physical testing and tools and a completely mind blowing introduction to Neuro Linguistic Programming and real social engineering. Well worth it.

Lots of great hallway talks and great to meet in person some folks I've met this past year on twitter. The talks I sat in on were mostly stellar. I had a good crowd and had a lot of fun. The hotel staff apparently told the DerbyCon organizers that this DerbyCon weekend out drank this year's Kentucky Derby weekend, so there's that. And what do drunk infosec professionals do for entertainment besides social engineering each other and set up fake cell transmitters? Play boisterous chess matches in the lobby until dawn, of course. Well played @egyp7 and @bandrel.

Thanks to the DerbyCon Staff and organizers for another great event (and for accepting my talk), the hotel staff and all the great people who make this community a true community.

Edit: I did my Business Ramifications talk on Friday and received really great feedback and discussions throughout. Thanks everyone who attended.

Tuesday, July 24, 2012

Business Ramifications of the Internet's Unclean Conflicts (and other updates)

So, the schedule has been crazy lately and I have been cherishing what little downtime I have with the the family. And the golf course. Hence, no blog post since March. I finally finished the sunroom bar cabinets and installed them just in time for our annual summer party, which was spectacular, BTW - the pulled pork we smoked for 12+ hours was like butter and the ribs were to die for. Ended up kicking out the last dedicated professionals around 2:30AM, so AFAIC it was a total success. Look for invites next year, DM me, etc.

Onto actual infosec/risk items. I put together a talk on the Business Ramifications of the Internet's Unclean Conflicts for Cleveland B-Sides that I gave on July 13th (you can see it here, special thanks to @securid and @adc_irongeek). It wasn't my best performance, but admittedly I wasn't 100% confident that I was able to connect all of my dots in 45 minutes. Plus, I had added several slides during some breaks between earlier B-Sides talks so no practice for the talk as a whole. Regardless, it went over well, with excellent crowd source feedback and criticism, which was most welcome. Safe talks are boring and I went in with this one expecting some pretty vocal feedback on the topics I brought up. I was not disappointed.

So one of my "agenda" items was "WTF are you talking about?" Which is a fair question. Some examples of the United States' Unclean Conflicts include Korea, Vietnam, Grenada, Somalia, Panama and even our current "Wars" in afghanistan and Iraq. Let's not forget what is happening in Yemen and Pakistan. The last official declaration of war was in 1942 against Bulgaria, Romania and Hungary, allies of the Germans during WWII. Post WWII we became very familiar with unclean conflicts, both pre and post the fall of the Soviet Union. But that event marked a significant change in our (the United States) international attitude. Who would realistically enagege us in open, clean conflicts? This lack of (in our minds) a realistic adversary even furthered our big-headed notions that the rest of the world should act and behave as we think they should. This mindset filtered down into our Business DNA, and our innovative corporations that were and are pivotal in building up our national economy began thinking the same way. We are now finding ourselves lashing out with legislation in vain attempts to enforce levels of security controls to protect our national infrastructure. Which will most likely lead to attempts to enforce levels of controls over manufacturing, science, research, medical and other verticals. Will any of these succeed? It is too early to tell. But the simple fact is this. If you get to the point where a problem becomes so big that you need to try to legislate it in order to protect the economy and nation as a whole, you have completely missed what was wrong to begin with.

The term "Organizational Entropy" is defined as the natural result of assuming you are smarter than your adversaries. Which is exactly what we, both internationally as well as business-wise, have done. And (gasp) we are quickly finding that a) we are not as smart as our adversaries and b) they have not been playing according to our rules. For years. Why spend billions of dollars (pick your currency) developing new technology when you can spend a million dollars purchasing the stolen technology? Why not halve number of years your weapons program is behind the US's by stealing that top secret data?

Our adversaries have become specailists at executing "Unclean Conflicts" against our business and defense infrastructure.

Our pig-headedness has lead to societal ramifications where policy is now defining society, which naturally does not happen. Society should define policy. And since this is completely unnatural, and basically driven by power, greed and profit, naturally it is failing.

Joel Brenner's recent book "America the Vulnerable", while bordering on being fodder for the security hardware vendors of the world to scare the daylights out of business decision makers, does make one excellent point - "Organizations must learn to live in a world where less and less information CAN be kept secret, and where secret information will remain secret for less and less time." i.e. Design for, and assume the breach.

Throwing more and more technology at these problems only makes our systems that much more complicated, and therfore less secure. That is not natural adaptation. Nature (including everything from promordial bacteria in volcanoes to us as a species) has survived over millions of years by adpating to situations and problems. Without the need for policies and politics. Our government and corporate frameworks need to learn to begin to adapt to what effectively is a new paradigm.

Every #infosec and #businessrisk practitioner should read the book Learning from the Octopus by Rafe Sagarin. Do this now.

We inherently know what issues matter and what issues do not. "Morals" and religion have no place in this argument, they do not matter. This is about adaptation and being able to apply pressure to the wounds we have sustained due to our arrogance. Vote out anyone, regardless of which "side" they are on, who does not actively convey this understanding.

Feedback is actively welcome.

(note: I am not this smart, shout outs to Josh Corman, Joel Brenner and Rafe Sagarin as a sampling of many influencers)

Tuesday, March 20, 2012

Pen Testing, commodities and 0day supply and demand

Martin Bos (@purehate_) asked an intriguing question over twitter the other day. Should 0day exploits be used in "standard" penteration tests. Some rightly asked to define what a "standard" pentest truly is, since scope could literally be anything you can think of. Josh Abrams (@jabra) responded with what is probably the best answer with "0day usage should match the maturity of the target." Beautifully stated.

But the discussion got my gears turning. Josh Corman (@joshcorman) blogged back in November 2011 about the concept of HDMoore's Law (http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/). It's a great read and I feel very pertinent and accurate. The original Moore's law roughly states, depending on who you hear it from, that technology (i.e. the number of inexpensive tranistors that can be put onto a circuit) doubles every two years.

When you look at the IT industry as a whole, this law partially explains many business related bell curves - advanced technology has the innovators, early adopters,  early majority, late majority and laggards. Everything eventually becomes commoditized. Relying on a particular technology or skillset that your organization may possess advanced skills in to keep a competitive edge over your competition over time is a losing battle. Skillsets are learned. Technology advances and improves. Competition eventually catches up. In order to remain ahead of the pack organizations must continually find the next advanced technology to specialize in.

Corman's point with the HDMoore's law concept is that the advancement of the metasploit framework is lowering the cost of admission in winning and performing successful "standard" pentests. Business histories and frameworks dictate that that the advanced technology of penetration testing will eventually become commoditized. Pentest geeks can stop your whining now, we all know you are talented and always searching for new, improved and advanced methods of testing. That's not the argument. Cutting edge is still cutting edge. But once pentesting tools advance to the point that those of us who are neither exploit hunting hobbyists nor being paid to discover 0day vulnerabilities can compete with specialists and win engagements with the majority of non-"mature" clients, could the differentiating factor result in today's hardcore pentesting community to actively pursue the acquisition of previously unknown 0day exploits?

Supply and demand. Could Whitehat(ish) practitioners eventually significantly contribute to Blackhat revenue, GP margin and Operating margin just to stay ahead of the closing pack of mediocre pentesters using advanced pentesting tools? Thereby funding the work of the evil hackers?

Martin made a good point on an unrelated thread about hey, you make a neat argument but please back that up with a recommeded solution. There is no "solution" in this case (sorry, Martin). This is simple business modeling and evolution and you need to adapt accordingly. One path in that adaptation may lead to this particular scenario.

Monday, March 12, 2012

DLP vs. Auth: More Snakeoil?

Data Loss/Leakage Prevention (DLP) has been one of the hot buzzwords over the last several years. And it's a great idea - determine where your critical business data lives and actively enforce policy around it. Data in motion, at rest and in use, absolutely critical elements in ensuring enterprise business protection.

But is it, really? In terms of protecting business critical data, the most important element is first and foremost understanding where that data lives and breathes. That is absolutely where DLP infrastructure contributes the most. But once that business critical data is discovered, wherever it may live, is it not logical to then make the business decisions to allow said data to reside in certain areas and not others? Policies redrawn to dictate where critical data should reside and then, through alternative means such as, oh, authentication and authorization, allow access to such data?

Don't get me wrong. People will send CCs and SSNs unwittingly over email. This is not that argument. Few organizations have gone out of business for such breaches, so clearly these are not true business risks. This argument is focused on innovation lifeblood. Formulas, research, sales playbooks, medical breakthroughs, etc. Everything that contributes to a strong economy that we, as infosec practitioners, are accountable in protecting.

If we know where that data lives in the first place, the overarching overhead of customizing DLP systems to actively look for your specific business critical data is, to a degree, moot, now that we know where it is confined to, by enforceable policy, and can control access to via both standard and enhanced authen/author controls. AD controls what you can and cannot access, as well as who can take data and copy to removable media. At some point you have to realize that you cannot control persons taking camera shots of monitor screens that may contain business sensitive data. Assume the breach. Digitally mantrap your data such that only persons with advanced authorization has access to the sum of the parts. Limit you threat landscape and focus your controls on such persons, no matter how high up on the food chain they may be.

DLP systems have their place, but I believe that place is simply to identify the most important variable any organization needs to know in an effort to protect their business critical data - where that data lives. At that point existing controls can be implemented to enforce the business policies, restrict access to said data, redefine where said data should live and reduce the scope of threat vectors that have the potential to exfiltrate said data.

DLP - one time insight or ongoing overhead?

Sunday, March 4, 2012

More Compliance Sham-WOW!

I've said it before and I'll say it again. Compliance is a sham. Most are vague attempts at kinda hoping you'll make appropriate security decisions and protect people's data that reside on your systems. Others have very detailed lists of what you should be doing, which, from the business side of the house, is completely impractical to comply with so most organizations adopt a "we're doing our due diligence" mentality of trying to at least show small, annual signs of compliance improvement in hopes that if that low probability event accually occurs, they will not be held accountable because they can produce the appropriate "metrics" that tell the all too familiar tale of compliance costs vs. revenue and GP.

The latest Sham-WOW compliance movement has been introduced by several congress-persons, including Joe Lieberman, and boy is it a doosey. Jody Westby's story in Forbes (here) sums up most of it very astutely, but doesn't touch upon what I feel is a larger, underlying battle. We are rapidly approaching a very complicated paradigm shift regarding our national economies and who is responsible for protecting our national assets and interests. I've previously discussed the economic dangers of the theft of our innovations and how we are no longer (for the most part) in an era where our government can protect our industries by reacting with physical force.

Yet, the antithesis of bombing the daylights out of an adversary for cyber-stealing NASA secrets and the like appears to be applying more regulatory compliance to the formula. I can hear all of the equipment vendors cheering already. "Buy this device and you will be <insert the latest govt. regulation here> compliant." It's crap like this that makes my life more hectic in my attempts to un-"educate" people who have already taken the bait and are now chasing the carrot of compliance.

Compliance almost never means Secure, Secure almost almost always means Compliant. At this point I forget who even said that first (credit anyways). There was a time I felt it might take a few levels of governmental regulation to get to some semblance of Business Security, but no longer. Litigation is king, and even that has diminishing returns in this day and age of the "international mystery man", more commonly known as the C.H.E.W. factors.

Standards, people. And the lack thereof. We spend so much money investing on systems that will "protect" us from weaknesses that should have already been vetted in the actual application it is no wonder each and every industry is overwhlemed with thousands of vendors touting the latest and greatest solution to combating <insert APT here> in your enterprise. Focus on the root causes. Awareness and coding standards. Develop them. Enforce them. Don't buy software from vendors who aren't an active contributor to such standards, etc. I realize this is as much of an uphill battle as complying with some of the regulatory standards but at least it would actually make an impact.

Just be, as good infosec professionals strive to be, proactive about it. Don't be complacent and allow a bunch of aging congressmen who aren't really sure how to turn on their "tweeter" be responsible for developing another completely erroneous and uneffective infosec regulatory compliance standard just because we can't collectively troubleshoot root cause issues and become a community dedicated to actual problem solving, debugging and solutions.

Thursday, February 16, 2012

My BYOD musings at ETech

I was asked to give a talk this past Monday for the ETech convention (focused on K-12) in Columbus OH. I did my best to politely let our sponsors know that I would not participate in regurgitating vendor marketecture and FUD (see Replacing FUD), that is what vendor reps are for. Instead I put together a discussion around understanding the Risks of the BYOD (BYOD == BYOWMD - Weapons of Mobile Destruction, credit to whomever tweeted that the other day, I searched but couldn't find it again), the current business drivers, the ramifications and a roadmap to follow if your organization is thinking about allowing users to bring their own weapons onto your network. Great participation and dialogue, which i love, and thanks to all who attended and participated in the discussions.

Some very interesting take aways, mostly specific to the K-12 vertical
  • Not a single person in the room had ever seen a single line item for security in an OSFC bid (not surprising)
  • IT resources are streched beyond capacity (not surprising)
  • Educators are usually not aware how much access they actually have, and many times don't care once that is explained (interesting)
Only a handful of persons who attended are currently being directed to design and implement network that support these weapons. However, I guarantee with the rising expectations of these networks to support all of the upcoming advanced technologies and the high costs of 1:1 computing we will see many more organizations moving towards this model that the tech industry has made its latest acronym focal point.

    Thursday, December 29, 2011

    Anonymous Analysis

    Josh Corman (cognitivedissidents.com) and Brian Martin (attrition.org) are putting together some very pointed and well researched analysis of Anonymous, including history and fact/fiction dissection here. Some high level takeaways include their call for transparency while remaining a closed anonymous movement (or idea), the high amount of collateral damage on persons affected by their PII being released in attempts to teach corporations security lessons while the movement is supposedly for the "people" to begin with, and calls to potentially label anonymous a terrorist organization would likely lead to a cyber version of the patriot act. All good stuff, and perhaps the most poignant quote nestled in the analysis:

    "When threatened ... powerful, uninformed people make powerfully uninformed decisions"

    Saturday, December 24, 2011

    A day of rest

    SOPA. NDAA (Don't worry, we won't actually USE the power given to us to indefinitely detain US citizens on US soil outside of our judiciary system, but we want the option <- hello Patriot Act being primarily used in Drug busts). China. Iran. France is the most active espionage nation state. National economies being decimated by theft of innovations. OWS not targetting the right players and utilizing their now diminished strength poorly. Anonymous/LulzSec executing against equally wrong targets and fueling much of the current pending Internet restriction and privacy violations (hint - target the people who actually care about their public images e.g. politicians/lobbyists and THEIR money trails, not the ones who know they most likely profit even greater during times of active dissent against them). CxOs still viewing security in terms of economic loss thereby taking greater business risks even in the face of what surely is the highest impact year to date for business loss due to CHEW (Criminal, Hacktivism, Espionage and War <- thank you Richard A. Clarke). And so forth.

    This past year was an exciting ride, and is going to get crazier in 2012. Having said all that I need a break, even if it is just a day. It is the day before Christmas. I have tremendous respect for faith. Mine may not take the form of the traditional usual suspects, but provided your faith isn't being forced upon others, I have the utmost respect and will abide by that rule myself. So I will relax in front of a roaring fire in the fireplace with my family and appreciate not only them but my personal and workplace friends, industry associates from whom a learn from on a daily basis, the hacking community who, as ironic as it sounds, makes great, if sometimes unintentional steps in securing our assets further, and all of the actors in the previous paragraph for making life as exciting as they humanly can.

    Just don't forget about that human part. Cheers to all.

    Friday, November 4, 2011

    Infosec Summit Talk

    Well, I successfully scared the daylights out of another roomful of summit attendees. Which is good. See my previous post on Replacing FUD. Fear is good. It is the uncertainty and doubt that needs to go. I suggest through process replacing them with Understanding and Confidence. So with my talk on Security Economics and the Battle against Patience, I feel succeeded on several levels. The most important statements would be the following:

    • Espionage is rampant, both nation state and industrial
    • China has been given the source code to virtually all of the Windows Operating Systems and associated applications, is actively looking for new, previously unknown vulnerabilities and has not yet contributed one CVE
    • Advanced Persistent Threat (APT) is poorly named - the only difference between these newer attacks and any prior is patience, and I wouldn't call that advanced, even though we as a culture have forgotten what patience is (instant gratification through SMS, twitter, facebook, blah)
    • Our adversaries are looking to steal our economic competetive advantages above and beyond intellectual property and trade secrets - business models, sales playbooks, project management methodologies and research papers in an effort to close the gap
    • The gap is actually our innovation, and our innovation is being silently and patiently stolen
    • That innovation theft directly impacts our national economy(ies)
    • Low probability/high impact, which is cost prohibitive to protect against, has become fairly common/high impact
    • Focus your security dollars on controls closest to your user, closest to the human
    My recommendations:
    • The Human - Security Awareness (REAL security awareness programs, not your SOX compliance checkbox program)
    • Next closest to the human - Identity Control Systems
      • Systems that can, based on your authentication credentials, dynamically create access control lists throughout the network and enforce policy based on what you should be allowed to access
    • And next closest - Host Based Application Whitelisting
      • Only allowing the execution of known good applications, thereby mitigating most malware techniques
    Last word:

    Your success and/or failure at reducing business impact within your own organization directly affects our nation's economy (no pressure).

    Good Night, and Good Luck.

    Tuesday, October 25, 2011

    Updating Security Strategies

    There were many talks at DerbyCon a few weeks ago on PenTesting and Social Engineering and how humans are still the best way to gain access to systems. Mobility devices are commonplace in most organizations. The Chinese have thousands of "consultants" pouring over the source code for all of the Windows Operating Systems and applications looking for new vulnerabilities because Microsoft wanted into the Chinese market and caved and, well, gave it to them. To those who have not already altered your course, you are overdue to overhaul your business security strategies.

    Today, IMHO, it is imperative to secure your business assets as close to the human as possible. And that starts with REAL security awareness programs, not your SOX checkbox "program". I was walking around the campus of my University alma mater this past weekend and was delighted to see and recognize posters from Lance Spitzner's Securing the Human awareness training hanging everywhere. If a private University can proactively invest in a training program to enhance the security awareness of its students, you without blinking should be doing the same for your employees who have business use case access to your intellectual property, methodologies and innovations.

    The next closest area away from your employee's brains is identity systems. Systems can now go well beyond the standard authentication/authorization controls. Active, real time inventories of every device connected to your network and profiles of what those devices actually are, device-based authorization (you are allowed access to sensitive areas on your corporate laptop but not on your personal smartphone/pad, etc.), authenticated user policy enforcement through posture assessments and identity tagging at the IP packet layer. How sexy is that?

    And finally comes the host-based controls. My preference is application whitelisting, which can be a challenge depending on the sophistication of your data classification and approved applications programs (if they even exist). But assuming that people are going to click links and trust bad people, preventing malicious code from executing on your systems is a no-brainer. If you're not on the list, you can't come in.

    Awareness, Identity and Whitelising are the three most critical controls to invest your security dollars into today. Mitigate the urge to click things, understand and control what is connected to your network, who is on those devices, enforce conformity to your standards, prevent unauthorized access to sensitive data and only allow business approved applications to run on your endpoints. Simple.

    Friday, October 14, 2011

    Post DerbyCon

    I meant to put up a DerbyCon wrapup but didn't get around to it until now. For an inaugural Con it was pretty impressive. I think I read there were 1,000 attendees over the three days. Great sessions. My short list includes:
    • HD Moore
    • Johnny Long (Hackers for Charity)
    • Mitnick/Kennedy
    • Nickerson
    • Joe Schorr
    • Carlos Perez
    • Boris Sverdlik (Your Perimeter Sucks)
    • Chris Roberts (terrifying)
    • Jayson Street
    Adrian/Dave/Martin's training sessions were excellent. A great event that I will definitely plan on attending again.