Sunday, June 24, 2012

America The Vulnerable

America The Vulnerable, “Inside the New Threat Matrix of Digital Espionage, Crime, and Warfare” by Joel Brenner provides a broad picture of the issues of cybersecurity in the early part of the 21st century. In many cases, the facts presented are not new but Joel Brenner has the ability to put them in context and provides an excellent look at the big picture implications of those facts.
Joel Brenner, is a former senior counsel at the National Security Agency and has extensive experience in counterintelligence. This background allows Brenner to describe in detail the structural and procedural challenges that the US government and industry face in dealing with the threats.
The book roams across the entire cybersecurity landscape. Brenner describes the economic and political motivations of other nations and they are leading them to do the things that they do. He details the Chinese, providing documented sources describing their objectives, motivations, and tactics.
Brenner presents a speculative case study on how a cyberattack from China might be used for increased strength in a diplomatic standoff around Taiwan. Very interested take that is different from many fear-mongers predicting cyber apocalypse, but offers a practical description as to how our weaknesses could realistically be used against us.
One of the key points made is that the increasing transparency due to electronic information leads to reduced secrecy for governments and reduced privacy for individuals.
In addition to the excellent survey of the challenges related to information security, Brenner offers prescriptions that both the government and the private sector can take to deal with the threats.
These include for the U.S. government:
  • Use federal purchasing to enforce higher security standards.
  • Forbid federal agencies from doing business with ISPs that are hosts for botnets, publish list of companies.
  • Remove anti-trust considerations to allow US firms to collaborate and share information on security.
  • Require Internet service providers to notify customers whose machines have been infected by a botnet.
  • Use regulations to stop utilities from connecting industrial control systems to public networks.
  • Use tax code to change behavior.
  • Increase research into attribution techniques and identity standards.
  • Increase research into verifiable software and firmware, and the benefits of moving security directly into hardware.
  • Increase research into an alternative Internet architecture.
  • Require disclosure of risks for utilities in bond documents.
  • Toughen public audit standards for cybersecurity.
  • The US should engage like-minded democratic governments in a multilateral effort to make Internet communication open and secure.
The recommendation for the private sector include:
    Clean up your act.
  • Control what’s on your system.
  • Control who’s on your system.
  • Protect what’s valuable.
  • Patch rigorously.
  • Train everybody.
  • Audit for operational effect.
  • Manage overseas travel behavior.
This is a very good overview for people outside the Information Security world, in addition to being an excellent reference for practitioners, as Brenner does not dive into the weeds yet provides a compelling view of the world today.

Saturday, June 9, 2012

Tackling ArcSight Express Configuration

The ArcSight SIEM platform is extremely powerful and capable of correlating an amazing amount of information. This information can overwhelm some people in getting starting to get value out of the solution. Here are some general thoughts on how to approach this challenge.
  1. Decide on what use cases you want like to implement first. Try proceeding one use case (I am using the term generically not in the ArcSight specific way) at a time so that you are not trying to boil the ocean.
  2. Decide what event sources are necessary for that use case to be sent to Express / ESM.
  3. Configure the SmartConnector software to send all of the data from those devices to the Logger or straight to Express depending on your architecture.
  4. When the events are sent to Express set up an Active Channel and review the event types that you are getting from those sources and determine:
    • What is irrelevant and filter them out on the connector and/or logger.
    • Figure out what is just as useful if you aggregate them and set up aggregation rules on the connector (Firewall connections for example).
  5. Check those event sources are categorized correctly and can utilize the standard content from ArcSight.
  6. Now that filtering and aggregation is in place for those event sources, work on rules and content to deal with that use case.
When you are correctly dealing with the security issues handled by that use case, then move on to the next use case and repeat the process.

Tuesday, April 3, 2012

Identifying Disabled Users

Great question came up today in Varonis training. How can we identify when a user account was disabled and who performed the operation? For those of you running Varonis' DA for Directory Services module the answer can be gathered from the Directory Services log. The key items to select are the user account that you want to investigate and select select the Change Description filter with the operation Like and using the text field:

Property "User Account Control" modified: 514


This is a good candidate to set up as a monthly report to audit all of the user accounts that were disabled during the last month; something that will keep the auditors happy. If you would like the XML for the template please email me and I will send it to you.

Saturday, March 31, 2012

Network Access Control Vendors Reviewed

One of the core principles of Information Security is that organizations should have preventive, detection, and corrective controls in place to protect their infrastructure and data. If one looks at annual spending in Information Security it is dominated by preventive controls such as firewalls, anti-spam, and anti-virus solutions. One thing that those solutions have in common is that they all fail. In dealing with many clients we see a lack of detective and corrective tools and processes in place to respond to the inevitable breakdowns that occur because of user errors, zero-day attacks, or sophisticated adversaries.

To get a quick overview of your environment, can you answer questions such as these:
  • What devices are on your network?

  • Are they compliant with current policies?

  • Are there any unauthorized devices (such as tablets and mobile phones) on the network?

ForeScout Technologies has a great solution, CounterACT, that is marketed as a NAC (Network Access Control) but provides much more functionality that helps organizations deal with the device on their network. It provides an internal intrusion detection system to identify devices that have gone “rogue” (are trying to spread malware or viruses) through a dynamic “honeypot” solution.

In addition, it can inventory devices to detect when they are not compliant with companies policies, such as not running and AV solution or not encrypted. It also provides corrective controls to warn users and administrators of a potential issue, automate remediation through scripting interfaces, and it can quarantine devices and/or processes that are not supposed to be running.

The Tolly Group has issued a report on behalf of ForeScout that compares the main competitors in the NAC marketplace across 34 different criteria. To access this report please click here. If you would like more information, please reach out to us.

Tuesday, February 28, 2012

Varonis's new DatAdvantage for Directory Services

The job of securing information continues to get harder. The technology that we are managing is becoming more complicated, the threat vectors are increasing through new channel such as mobile devices, and the adversaries are getting more sophisticated.

One of the most difficult areas to protect is the unstructured data on file servers. I like to use the analogy of bank vaults to describe the file server world. We buy these very expensive bank vaults to store all of our confidential data and we deploy safe deposit boxes (think folders) to allow users to organize and protect that data. The Active Directory groups and passwords are the keys we hand to users to give them access to the safe deposit boxes.

However, with the current technology from the storage vendors the analogy breaks down. Here are some of the challenges:


  • We have no log of who goes in and out of the bank vault or safe deposit boxes.

  • If someone adds an additional keyhole to a safe deposit box, we rarely know who else is holding keys that will let them in.

  • We have no idea how big the boxes are and what is stored in inside of them.

  • Companies continue to buy new vaults because there is no easy way to manage the data in the existing vaults.

  • And every once in a while, IT people take a door off the safe deposit box to give someone access and because the vault is in the dark, we have no idea that this has taken place.


The Varonis DatAdvantage solution gives us the visibility into who access to the safe deposit boxes, audits what they do with the data stored in them, and provides the tools to increase the security of the vault.

What Varonis is bringing to the table with its new DatAdvantage for Directory Services product is the ability to monitor the people who build and assign the keys to the boxes in the bank vaults. When a new key holder (a user) is created we know that. When a user is assigned keys we have a record of who gave them to him. Varonis has provided the IT professional with a comprehensive set of tools to protect and manage their organization’s unstructured data.

Sunday, December 18, 2011

LinkedIn Needs to Add a Warning to its Connection Emails

Like most of us, I receive invitations from random folks on the Internet asking me to connect with them via LinkedIn. In some cases they are from accounts with no connections and no reasonable profile. They are clearly looking for information for nefarious purposes. Yet when the email comes in, this is all that LinkedIn says:

"WHY MIGHT CONNECTING WITH SHAMSODIN KARIMI LASAKI BE A GOOD IDEA?
shamsodin karimi lasaki's connections could be useful to you
After accepting shamsodin karimi lasaki's invitation, check shamsodin karimi lasaki's connections to see who else you may know and who you might want an introduction to. Building these connections can create opportunities in the future."

What is LinkedIn thinking? Why encourage me to connect with a potential hacker?
Social networks lose their effectiveness when people lose trust in the overall experience and it is LinkedIn's best interest overall the long run to discourage people from connecting with people they do not have a relationship with.

Let's encourage LinkedIn to add a warning to those emails as well. Here is one potential idea.

"WHY MIGHT CONNECTING WITH SHAMSODIN KARIMI LASAKI BE A BAD IDEA?
If you have no freaking idea who LASAKI is, he might be trying to gather personal information from you as part of a plan to launch a spear-phishing attack against you or one of your connections. Building these connections with people you do not know can create risks and privacy concerns in the future."

Saturday, November 19, 2011

Tracking AD Groups Changes with Varonis

Varonis DatAdvantage tracks changes in Active Directory group membership by comparing the results of the nightly AD walks. If we want to see the changes that have been made to a user we can use the "1a - User Access Log report." The key filter to remember is that we want to show data from the "History of Differences." This shows the changes that have been picked up by the nightly jobs. Then we need to select the date range that we want to look at.

Then select the "Operation Type" filter. There are two operation types that we can select depending on what we are trying to track:

  • Membership Removed

  • Membership Added
Add the filter to look only at "Groups" for the Object Type.
The final piece is that the user affected by the change is identified in the "Change Description" field. Use the "Like" operator and remember to enter in the domain name before the start of the user name.

Run the report and you have the answer you were looking for.



Note: Starting in Version 5.6 of Varonis DatAdvantage we also have the "3e - Historical Group Membership" which will display the groups a user belonged to on a specific date. Great report for answering those tricky audit questions.