Tips on Improving IT Security and System Administration from Castle Ventures Corporation.
Wednesday, February 13, 2013
Varonis Data Governance Awards
With so many data breaches and negative stories coming out of the information security world, it is nice to see some positive news. A new thing that Varonis Systems introduced this year was the "Data Governance" awards for customers that made outstanding use of the the DatAdvantage platform and improved the security processes around their unstructured data. I was proud to be a judge and see the wonderful progress that many organizations are making. See the award winners here.
Tuesday, February 12, 2013
Symantec Study Says Many Employees Steal Data
Symantec has published a study related to employee theft of data; which was conducted by the Ponemon Institute.
Symantec Press Release
They offer several recommendations which include:
The Varonis DatAdvantage suite of solutions should be one of the cornerstone's of an organization's strategy to protect and better manage access to data at its source.
Symantec Press Release
They offer several recommendations which include:
- Employee education
- Enforce non-disclosure agreements
- Implement Monitoring technology
The Varonis DatAdvantage suite of solutions should be one of the cornerstone's of an organization's strategy to protect and better manage access to data at its source.
Friday, December 28, 2012
User Account Management in Varonis
One of the core benefits of Varonis DatAdvantage is that System Administrators can make better decisions regarding access permissions and folder management because of the excellent visibility that the product supplies. Since they can see an entire tree with permissions and other file server metadata, they are more likely to appropriately permission folders. However, that requires that the System Admin have the system open and is regularly using it.
With the newest release of Varonis, 5.7.68, there is even more incentive for system administrators to use Varonis on a daily basis. The product now allows the Varonis user to perform an number of activities involving individual user accounts directly from the IDU GUI.
The following tasks can be performed through DatAdvantage by right-clicking on a user:
From the User / Group panel the Varonis admin can also filter users and groups whose accounts require attention, such as identifying locked accounts.
If you have not already done so, upgrade your system to the latest release.
With the newest release of Varonis, 5.7.68, there is even more incentive for system administrators to use Varonis on a daily basis. The product now allows the Varonis user to perform an number of activities involving individual user accounts directly from the IDU GUI.
The following tasks can be performed through DatAdvantage by right-clicking on a user:
- Creating a new user
- Editing a user's AD properties
- Copy a user
- Resetting a user's password
- Unlock a user account
- Delete a user account
- Enable or disable an account
- Move an account
From the User / Group panel the Varonis admin can also filter users and groups whose accounts require attention, such as identifying locked accounts.
If you have not already done so, upgrade your system to the latest release.
Friday, July 27, 2012
Net Neutrality and The Master Switch
I have been on the fence about “net neutrality”, but after reading Timothy Wu’s book on the information industries, The Master Switch: The Rise and Fall of Information Empires (Borzoi Books). I am firmly in support of net neutrality. This is a great background read on the economics behind these industries. Wu cogently explains the long-held concept of a “common carrier”, and how allowing Internet Service Providers to discriminate against certain customers, the opposite of net neutrality, can only lead to the stifling of innovation. He covers the growth of the telephone industry, radio, movies, television, and the Internet.
The book provides a history of the development of those industries and the economic and political forces that lead to the establishment of large centralized firms, such as AT&T, NBC, CBS, and Paramount Picture, in each of those markets. These consolidations ended up slowly progress in those industries, with the prime example being AT&T and how it stopped answering machines, fax machines, and other innovations that could have come decades before they were finally introduced. Wu provides very strong arguments as to how any efforts to stop net neutrality would inevitably lead to unknown, but clearly bad, results.
The book provides a history of the development of those industries and the economic and political forces that lead to the establishment of large centralized firms, such as AT&T, NBC, CBS, and Paramount Picture, in each of those markets. These consolidations ended up slowly progress in those industries, with the prime example being AT&T and how it stopped answering machines, fax machines, and other innovations that could have come decades before they were finally introduced. Wu provides very strong arguments as to how any efforts to stop net neutrality would inevitably lead to unknown, but clearly bad, results.
Sunday, July 1, 2012
Spear-Phishing
On June 28, 2012, The US-CERT (United States Computer Emergency Readiness Team) released the ICS-CERT Advisory "ICS-CERT Incident Summary Report." The report provides a summary of their incident response activities from 2009 - 2011.
The most common attack vector for was spear-phishing emails with malicious links or attachments. This accounted for 7 out of 17 incidents. They surmised that "Sophisticated threat actors were present in 11 of the 17 incidents, including the actors utilizing spear-phishing tactics to compromise networks."
Brian Krebs analyzed email threat data from the University of Alabama at Birmingham and across the sample set the anti-virus solutions on the market were not very effective, with an average detection rate of 24.7 percent and median detection rate of 19 percent.
One cannot survive on anti-virus solutions alone, which tend to rely on signatures and heuristic analysis of the payloads. We recommend a defense in depth strategy here that relies on analyzing the behavior of the PCs as well, so that once an attack has passed through the AV solution, there is another barrier to detect anomalies. Invincea provides an isolated environment to handle links and PDF attachments. An internal IDS/IPS system could identify unusual behavior. Please reach out to me if you would like more information on our recommendations.
The most common attack vector for was spear-phishing emails with malicious links or attachments. This accounted for 7 out of 17 incidents. They surmised that "Sophisticated threat actors were present in 11 of the 17 incidents, including the actors utilizing spear-phishing tactics to compromise networks."
Brian Krebs analyzed email threat data from the University of Alabama at Birmingham and across the sample set the anti-virus solutions on the market were not very effective, with an average detection rate of 24.7 percent and median detection rate of 19 percent.
One cannot survive on anti-virus solutions alone, which tend to rely on signatures and heuristic analysis of the payloads. We recommend a defense in depth strategy here that relies on analyzing the behavior of the PCs as well, so that once an attack has passed through the AV solution, there is another barrier to detect anomalies. Invincea provides an isolated environment to handle links and PDF attachments. An internal IDS/IPS system could identify unusual behavior. Please reach out to me if you would like more information on our recommendations.
Sunday, June 24, 2012
America The Vulnerable
America The Vulnerable, “Inside the New Threat Matrix of Digital Espionage, Crime, and Warfare” by Joel Brenner provides a broad picture of the issues of cybersecurity in the early part of the 21st century. In many cases, the facts presented are not new but Joel Brenner has the ability to put them in context and provides an excellent look at the big picture implications of those facts.
Joel Brenner, is a former senior counsel at the National Security Agency and has extensive experience in counterintelligence. This background allows Brenner to describe in detail the structural and procedural challenges that the US government and industry face in dealing with the threats.
The book roams across the entire cybersecurity landscape. Brenner describes the economic and political motivations of other nations and they are leading them to do the things that they do. He details the Chinese, providing documented sources describing their objectives, motivations, and tactics.
Brenner presents a speculative case study on how a cyberattack from China might be used for increased strength in a diplomatic standoff around Taiwan. Very interested take that is different from many fear-mongers predicting cyber apocalypse, but offers a practical description as to how our weaknesses could realistically be used against us.
One of the key points made is that the increasing transparency due to electronic information leads to reduced secrecy for governments and reduced privacy for individuals.
In addition to the excellent survey of the challenges related to information security, Brenner offers prescriptions that both the government and the private sector can take to deal with the threats.
Joel Brenner, is a former senior counsel at the National Security Agency and has extensive experience in counterintelligence. This background allows Brenner to describe in detail the structural and procedural challenges that the US government and industry face in dealing with the threats.
The book roams across the entire cybersecurity landscape. Brenner describes the economic and political motivations of other nations and they are leading them to do the things that they do. He details the Chinese, providing documented sources describing their objectives, motivations, and tactics.
Brenner presents a speculative case study on how a cyberattack from China might be used for increased strength in a diplomatic standoff around Taiwan. Very interested take that is different from many fear-mongers predicting cyber apocalypse, but offers a practical description as to how our weaknesses could realistically be used against us.
One of the key points made is that the increasing transparency due to electronic information leads to reduced secrecy for governments and reduced privacy for individuals.
In addition to the excellent survey of the challenges related to information security, Brenner offers prescriptions that both the government and the private sector can take to deal with the threats.
These include for the U.S. government:
The recommendation for the private sector include:- Use federal purchasing to enforce higher security standards.
- Forbid federal agencies from doing business with ISPs that are hosts for botnets, publish list of companies.
- Remove anti-trust considerations to allow US firms to collaborate and share information on security.
- Require Internet service providers to notify customers whose machines have been infected by a botnet.
- Use regulations to stop utilities from connecting industrial control systems to public networks.
- Use tax code to change behavior.
- Increase research into attribution techniques and identity standards.
- Increase research into verifiable software and firmware, and the benefits of moving security directly into hardware.
- Increase research into an alternative Internet architecture.
- Require disclosure of risks for utilities in bond documents.
- Toughen public audit standards for cybersecurity.
- The US should engage like-minded democratic governments in a multilateral effort to make Internet communication open and secure.
- Clean up your act.
- Control what’s on your system.
- Control who’s on your system.
- Protect what’s valuable.
- Patch rigorously.
- Train everybody.
- Audit for operational effect.
- Manage overseas travel behavior.
Saturday, June 9, 2012
Tackling ArcSight Express Configuration
The ArcSight SIEM platform is extremely powerful and capable of correlating an amazing amount of information. This information can overwhelm some people in getting starting to get value out of the solution. Here are some general thoughts on how to approach this challenge.
- Decide on what use cases you want like to implement first. Try proceeding one use case (I am using the term generically not in the ArcSight specific way) at a time so that you are not trying to boil the ocean.
- Decide what event sources are necessary for that use case to be sent to Express / ESM.
- Configure the SmartConnector software to send all of the data from those devices to the Logger or straight to Express depending on your architecture.
- When the events are sent to Express set up an Active Channel and review the event types that you are getting from those sources and determine:
- What is irrelevant and filter them out on the connector and/or logger.
- Figure out what is just as useful if you aggregate them and set up aggregation rules on the connector (Firewall connections for example).
- Check those event sources are categorized correctly and can utilize the standard content from ArcSight.
- Now that filtering and aggregation is in place for those event sources, work on rules and content to deal with that use case.
Subscribe to:
Posts (Atom)