Thursday, August 8, 2013

Wrapping up another Class

As i've stated recently I am currently in a class called current trends in cyber security.  The quarter is over and each of us have worked through a process model.  The point here is to:

1. Describe a threat matrix for a company.
2. Make recommendations on fixing those threats.
3. Present that information to management.
4. Make sure everyone understands the concepts.

That all seems simple enough, but let me give a brief run down of how it all works.  After all what good is cyber security if we can't take something perfectly simple and make it complicated!

I started by thinking through these issues.

1. Where does the analysis fit in the company goals?
2. What hardware and software assets are present?
3. What sources of information can be used to asses threats at H&M.
4. Create an ongoing information gathering process?
5. Gather Analyze and store threat information.
6. Document systems information.
7. Gather Existing H&M Policies
8. Evaluate currently existing threats, and make recommendations.
9. Evaluate impact of controls and reduce threat to acceptable levels.
10. Review and improve the system.
 
Next, I broke the threats present into categories   It was important to note that this was a high level assessment.  Since this process is ongoing the first time you do it you should only show major issues.

Once this is completed I had to put the issues into families.  I chose people, policy, and technology threats.  This seemed logical since most issues can be carved up this way.

Lastly we come up with controls and how to implement them.  

This is a high level overview of what I did for class.  The lessons learned here will apply daily as I consider threats and issues in the Cybersecurity space.


Sunday, July 28, 2013

Security Action Plans

As a Security professional I've spent a lot of time considering security problems.  Action plans I suppose are all about what you can do with those problems.  This week I wrote an imaginary action plan.  If you recall I've been working on developing plans for an imaginary company.  This company has no polices or procedures which reference security.  So I proposed some changes.  I am not really going to rehash those changes in this post.  I don't actually think that would be interesting to read.  However, I do want to take a moment to talk about this process.

From my perspective companies are generally accepting of the way things are done.  If a plan for something doesn't exists it means the leadership of the company hasn't acknowledge a need for it.  As a security professional how do you convince a company to spend lots of money and time on solving problems they aren't concerned about?  Obviously you can go to the stand by FUD, but there has to be a better way!  Understanding the risks a business has and proposing solutions is not an IT practice.  This is a business practice.  My imaginary company only engaged services for its security problems after a breech.  That is what it took for them to see the need.  Wait though, we are back to FUD again.  I mean I don't want to constantly try to convince people to do things because bad things can and have happened.

So, here is what I've learned from writing an imaginary action plan.  As a professional, writing an action plan gives you an idea what must happen to solve problems.  It means that you can clearly articulate what is wrong and how to fix it.  Given the correct forum you can argue for the needed changes.  I suppose the question is, how do you get someone to ask the question you have an answer for?  I don't think this is something I can even get close to answering.

Sunday, July 21, 2013

Threats, Vulnerabilities, and Risks, Oh MY!

While these terms don’t seem tragic of difficult on their own they are often misunderstood.  To be honest I often use them interchangeably.  So what is the problem right?  I mean why do we have to be exact on this, is the name of the game semantics? 

The reason these terms matter is because they are central to mine and all security professionals understanding of how business, security, and technology intersect.
Threats are things that you don’t want to happen.  They are present in the world around us.  There is a threat you may get into a car accident on the way to work.  There is also a threat that someone may hack into a system at your office.  Of course, there is also a threat a meteor will wipe out your office.  Not all threats are credible.  In other words all decisions can’t be threat driven.

Vulnerabilities are problems which exist.  The fact the breaks in your car may be out is a vulnerability.  The reality that you don’t patch workstations and servers on a business network is vulnerability.  Lastly, the fact that we only watch a small fraction of the space surrounding earth is yet another vulnerability.  Just as you can’t remove all the threats you can’t remove all the vulnerabilities either.
Now enters risk.  Risk is the likelihood that a vulnerability will be realized.  In other words will a threat take advantage of an existing weakness?  So will someone force you to slam on your breaks thus taking advantage of the weakness in your cars break?  Or, will some worker click a Facebook link taking advantage of the lack of patches on their system?  Lastly will some meteor in the area of space we weren’t observing smash into the earth?

So what do you do with this information?  The goal of course is decision making.  You look for the union of Threats, Risks, and Vulnerabilities.
 


The union of these three ideas are the threats, risks and vulnerabilities information security professionals should focus on.  The problem is determining which things fall into which categories and why.

Sunday, July 14, 2013

Imaginary Threat Analysis... Who knew it could be helpful.

So how do you analyze a threat from an imaginary company?  That doesn't seem like something that people concern themselves with on a consistent basis.  However, it was something I found myself doing this week.

The part of this I found interesting was after reading all the data from the company I had to come up with a likely scenario.  See the imaginary company had been breached.  They let client credit card numbers into the open.  In my likely scenario, the were breached due to an e-mail scam.  That scam then attached them to a bot net.  Once that happened the people running the bot net were able to determine that CC data was present within the system.  You see where this is going right?  It got be think, how can an organization do anything about this?

 In my opinion most security problems in companies boil down to one of three things.
1. A Policy problem
2. A People Problem
3. A technology problem

Policy Problems
So, my recommendations in the magic scenario mirrored this.  Policies you see can be fixed if the will is present to do so.  The real issue here is that they must originate from the top.  They must explain the will of a corporation to the stakeholders and employees.  A good example of this would be an acceptable use policy.
People problems
These types of problems are solved by hiring qualified candidates.  This may mean background checks and extensive interviews.  It will also mean continuous peer based review.  In addition it will mean that people may need to be let go.  This also takes into account people who mean to do an organization harm.  Controls must be put in place to limit that harm.  The policies should also reflect the reality of employees and harm seekers.

Technology Problems.
These problems are typically solved by people following policies.  Sometimes a new piece of technology may be needed, but sometimes an old piece of technology must simply be utilized.  In my imaginary company the issue here was lack of updates.

As IT and security professionals it is very easy to attempt to fix all problems with technology.  While I am still deciding what I think about all of this, I am attempting to appreciate how difficult fixing security problems can be.

Sunday, July 7, 2013

Threat Analysis Sources

I am currently taking a class on current trends in Cyber Security.  One of the question's I’m being asked is to review a list of sources I created.  This list of sources is intended to provide an overview of the numerous threats to the Confidentiality, Integrity, Availability, and Accountability of an information system.  On June 21st of this year I created a post entitled, "Identifying Credible Resources, a how to!”.  This is the list of resources I am currently drawing from.  All of that sounds incredibly formal.  In fact I simply check these sites and resources during the course of my day.  So the question is, can I use these sources in a formal manner?

For the purpose of this post I will discuss my listed sources as they relate to an imaginary company.  So, in this imaginary company I check Bruce Schnier’s cryptogram newsletter.  It focuses heavily on the ongoing saga of Snowden.  Interestingly enough, the Security Now podcast I watched did the same.  This information re-iterates the need to do several things.

1. Train Employees, this ensures employees know the proper whistle blowing techniques.  It also ensures they know what they should have access to.
      
2. Monitor Employees, Look, you can’t trust people.  No matter how well trained they are they can decide to make confidential information public.  This means you have to monitor them.
     
3. Communicate issues with lax access controls to management.  They may decide they do not want to act on recommendations, but they must be informed.

So how does that relate to an imaginary company?  Well in my scenario a company X shall we say needs to justify spending money on a IDS or DLP system.  They have determined that the risk to lost data is high, and that the impact of the loss would be catastrophic.  Reading this newsletter and listening to this blog help me articulate that.

This week I also reviewed Microsoft’s TechNet newsletter.  It would appear that MS13-050 will be coming out this month.  This update will interact with the print spooler.  So, company X uses mostly Microsoft systems.  These systems all print on a frequent basis.  Due to this warning I am able to communicate with the local admin’s in company X about the possible disruption to printing services.  In fact due to this update more extensive testing will be done.  If you haven’t  figured it out at this point, I’m obviously writing this post for an assignment.  The reality of all the sources I listed on June 21st is that I use them frequently.  My I believe however that the list could improve.  As I review specific threats it is likely that I will build a keyword list of resources.  This will enable me to research specific threats as they pertain to various topics.

Sunday, June 30, 2013

The Sans Top 20 Control 5 Malware defense

Check this link:
http://www.sans.org/critical-security-controls/control.php?id=5

     Everyone knows they should have Anti-Virus software.  Well, I would hope most people do.  Anecdotal evidence aside, why should people have Malware defense?  Well like anything else I think a discussion of definitions needs to occur.  Now hold on, this isn't going to be some boring list of words.  It's going to be an exciting one!  Malware is really just a catchall term for any piece of bad software.  It's all the viruses, spyware, Trojans, logic bombs, ad-ware, and spyware that exists.  Think of it as software that wants to hurt you and your PC.
   Ok, now that we have defined it what can we do to stop it?  Well the short answer is... not much.  The people who are creating advanced malware are working very hard to do so.  They have access to all the latest software and antivirus software.  In fact they have kits which are intended to help them do this.  You can actually lease time on cloud based services designed to create and distribute sophisticated attacks.  https://blog.damballa.com/archives/tag/cloud.  So if you are still reading you may be thinking, "well that's a lot of doom and gloom."  Well hang in there.

   While sophisticated attacks do exists many of the attacks being used are not.  In fact many of the attacks which occurred last year were unsophisticated. http://blog.trendmicro.com/trendlabs-security-intelligence/how-sophisticated-are-targeted-malware-attacks/  This article discusses this idea.  In addition, for a far more detailed analysis you can check to he Verizon Data Breach Investigation report.  So if the attacks are using known vulnerabilities why can't we just fix them?  In some cases this is due to the vendor not being able to re-work a difficult issue.  However, in some cases it is because the end users need the functionality that is being exploited.  Or, it may be that the flaw is not in public view.

   The answer to all of these concerns is Malware defense.  In a corporate environment have an automated anti-virus solution, monitor that antivirus solution, act on the reports it gives you, update the system, and most importantly educate users about it.  This type of protection can also be integrated into firewalls.  Network monitoring tools can look for known viruses, and bad behavior on a network.  Most importantly have a plan.  What will you do if a system becomes compromised?  Who will you call, where will a replacement PC come from?  More importantly how will you rebuild a server?  How long will it take?  Will you invest in a cleanup and evidence preservation effort?  If you don't have the answers to all of these questions you are like most people.  If you are looking for a place to start read SANS control 5.

   The secret to malware defense is understanding the risk present, proper protection, and a recovery plan.  

Sunday, June 23, 2013

Why on earth would I use Microsoft Visio

This week I decided to write about a feature in Visio that I until recently was unaware of.  For those of you who don’t know Microsoft Visio allows users to create and map.  You can map a city, office, network, even a process or idea.  This is very useful.  Interestingly enough it also allows its users to show relationships graphically.  If any of you have ever needed to explain how authentication works on a network the picture will certainly inform the topic.  Here is an example.
______________________________________











____________________________________
In addition to this functionality the product also allows you to diagram a website.  This is a new function I was unaware of until recently.  While documentation is an obvious need in security website diagrams are more directly related.  In order to use this functionality one must select a new Visio document, got to software and database, then select website. (http://office.microsoft.com/en-us/visio-help/generate-a-web-site-map-HP001209112.aspx).  Once that is complete simply follow the import dialogue.  You will put the URL you are looking for in place.  At that point you just hit OK and wait.  Here is an example.
I chose to use Altoro Mutual.  This is demo site setup by IBM.  Security professionals use it to test this type of tool.  http://www.testfire.net/default.aspx
____________________________________





















___________________________________

This tool allows the user to map the links and relationships in a website.  From my perspective it shows me hidden links as well as possibly forgotten pages.  This is something anyone who designs web pages should take full advantage of.  It also allows you to graphically illustrate website design.

Sunday, June 16, 2013

Identifying Credible Resources, a how to!

     So we are living in the information age, so they say.  In Cybersecurity we constantly find ourselves attempting to defend systems and ultimately information.  One of the ways we do that is by getting intelligence.  It’s kind of like the Maginot Line.  The Maginot Line was designed for use during World War Two using a World War One mindset.  The line consisted of numerous tunnels, walls, and forts which ran along the border of France and Germany.  It was thought that these fortresses would be superior to the trenches experienced in World War I.  However, the world changed!  While the Germans were not able to route the occupants of these fortresses they were able to bypass them and take France.  Ok, so intelligence or information informs our decisions.  It enables us to focus on what we are trying to protect and more importantly the best way to go about it.  I’ve divided information gathering in this context into a few categories.

      1.  Blogs or internet Media
      2. Vendors
      3.  People, Conferences, and Groups

     Since we have decided to get more information how do we know what to trust?  The place to start is finding out what other people are doing.  For example check out a blog.  I like Krebs on Security.  This blog is run by a veteran in the field.  He will tell various stories from a unique perspective.  In addition he has invested significant time in creating online personas which have access to the darker side of the web.  I also like to check on Bruce Schneier.  Bruce is less involved but more academic.  Reading his work will help you understand concepts.  Lastly check out some security podcasts.  These will typically contain up to date information.  I typically check on Security Now.

     That covers blogs and current events.  You can also subscribe to the vendors for the systems you protect.  The most obvious example would be Microsoft TechNet.  Many people realize that Microsoft has a patch Tuesday, but not everyone realizes they send out messages about those updates a week before.  You can even sign up to get them via e-mail and notifications via twitter if you sign in with a live ID.  HP is another good example.  When you register products they will notify you via E-mail of important driver and system updates.

     Lastly, talk to people.  Take a class at a lowly university.  If you can get there go to a conference.  You can also join some other organization like Infragard.  The key to all of this is talk to people!  People have experiences and may have considered methods you have not.  They may also recommend programs, products, software, and other people!

     While all of these ideas are a good place to start they can’t be the end.  One of the reasons it is important to develop and grow a security intelligence network is threats are ever present.  As a professional you must design, document, and tailor your own network.  As always trust what you hear buy verify the veracity.

Sunday, June 9, 2013

The SANS Top 20 Control 4, Continuous Monitoring

I need to take a moment to not it has been a few years since my last blog post.  That being said, the controls have changed numbers.  Since I already discussed inventory previously, I’m going to go ahead and jump in sequence with a control I missed before.  Here is a link to the Top 20 in case anyone is interested http://www.sans.org/critical-security-controls/

What is continuous monitoring?  I recall hearing about this a few years ago, more aptly it should be called continuous automated monitoring.  This type of work usually involves some sort of product scanning an information system in an ongoing capacity.  The system then reports back to a central database.  That information is then read and reported on.  Hopefully that information can then be used to drive changes within an organization.  Some examples of free versions of this are OpenVAS http://www.openvas.org/.  While I have used this before I must admit most of my experience is with a Tenable product called Nessus.  This product does provide a free download.  However, if used in a business a license should be purchased.  Without this license automatic updates will not work.  In addition new features like passive vulnerability scanning will not become available.  Another product commonly used for this is Nexpose.  This product works in concert with backtrack or Kali Linux.  It is also quite popular. http://www.rapid7.com/products/nexpose/

Ok now I've listed a few of the possible products which can be used for this type of work.  So, how do they work?  The high level view here is they collect data about patch updates, common vulnerabilities, virus update definitions, and many other small issues.  These devices then scan networks and look for these issues.  People can then log into the system, view the result, update the systems, and confirm the result is gone.  One of the key programmatic elements here is that these scans can become part of business as usual.  For example, before a system goes into production a scan should be run.  This can ensure the system is being updated.

So what about additional features?  Many of these systems allow custom definitions or audits to be created.  These files can allow companies to look for a specific detail on systems.  I once created a file to search the registry for a specific key.  This key referenced an application which my company was using.  While these systems all find vulnerabilities they do not fix them.  In addition, they do not explain the consequences of system changes.  I recommend that these systems are viewed as a part of a larger vulnerability mitigation plan.

Saturday, November 19, 2011

Week 10, what we’ve covered so far.

Up until this point we've covered about half of the SANS top 20. For those of you who don't know I tend to reference the SANS information security reading room. This is where you can locate information on the top 20. I occasionally will bring in some experience or talk about a product I've used. When it comes to that I may reference a specific vendor. Ok, onto the specific review.

We've covered, why you need to know what you have. Why it's important to define how you setup systems. How to protect your border network, and analyze logs of all types, and lastly controlling who get's administrative privileges. The main idea is focusing on the things you can control. Most I.T. Security professional don't want to mention some of the more nasty truths out there. There is a really good chance that if someone wants to get into your network they can. However, the SANS top 20 isn't about that. It is about stopping the majority of attacks that are using well known and understood vectors. Furthermore, it's about limiting and understanding the damage post incident. I recently read the Verizon Report for 2011. This report shows that from the time of penetration to the time data is harvested, you have a sizable window to find out. Depending on the type of attack this could be anywhere from weeks to months. This means that if you are doing what SANS recommends you can minimize the impact! Furthermore, you will know what the impact was!

Next week I will be back with an exciting new topic… Malware prevention… Until then.

Sunday, November 13, 2011

The SANS Top 20 Week 9

    This week we will be discussing controlled access. Most people are thinking, you mean like permissions on files? While this is certainly a large part of the picture, it is not the only part of it! Controlled access starts with asking who needs to know? I have often found myself in the position to decide who should have access to information. For the last few years I have fought this freely given power. When someone sends me a message which says, "I can't get into file x" I will typically respond with a few questions. These questions in my mind are the keys to controlling access to information.

    Questions I ask myself.

  1. Who is in control of this data?
    1. Does the user already have access to this data? Many times the answer is yes.
    2. Do I need to ask HR or a department head about this?
    3. Is the data even being stored in the correct place? Is the user trying to share a personal directory?
  2. What level of access is needed?
    1. In windows this is fairly straightforward
    2. Is this access permanent?


     

Questions I ask the user.

  1. When do you need this by?
  2. Does anyone else need access
  3. Who is requesting this?
  4. Have you opened a ticket or sent an e-mail (paper trail people, paper trail)

Ok, so I've made a point of giving out some basic information about what should be asked. This is what I've done in most situations which are not ideal. However, ideally what should happen is the following.

  1. DFS should be used. This gives data redundancy and availability.
  2. All shares should be hidden. While this isn't the end all be all of security it does stop casual browsing.
  3. Knowledge owners should be identified. In other words someone needs to approve these changes.
  4. When possible, setup shares by work area
  5. Drives should be universally understood and applied via script
  6. Access based enumeration should be used
  7. Make sure a process is known to request changes

While access to data is important, remember, just because you have the keys doesn't mean you should open the door!

Sunday, November 6, 2011

The SANS Top 20 Week 8

    This week we will be discussing… Controlled use of administrative privileges. This idea begins with a discussion on what accounts have administrative access. Ok, after a few weeks of reading these I would expect most people to already be saying, "How can I know what I'm limiting if I don't know what I have?" That of course is a great question. When it comes to PC's, I recommended using group policy. You can actually set restricted groups. This will make sure that no matter what when a PC is rebooted only the list groups have admin access. This means that if an admin wanted to give a user rights and then forgot, they would be gone when the PC rebooted. Another recommendation I have is checking who in active directory is part of the admin users group. This can be accomplished with a power shell script or even a manual glance at the group. Additionally, you can do some research. You should spend time finding out when the last time the admin password for any system was changed. I recommend beginning to document some of this in a spreadsheet or something. If you need to change an admin password go ahead and do it. After that, I would recommend finding out which processes i.e. backups, websites, services, etc… are dependent on admin passwords. Once you find this out you can begin the process of making sure those accounts are using service accounts. The big picture here is making sure that admin accounts are used by administrators only, only used when needed, and are relatively secure. In my experience the issue with changing admin passwords is the unpredictable things which break in a network upon doing so. Documentation and planning are truly the keys to this week's topic.

Sunday, October 30, 2011

The SANS Top 20 Week 7

    This week focuses on application security. This is an interesting dilemma. Let's say we have well maintained and managed operating systems. We watch our logs, and know what is coming in and out of our network. We even know what devices and software are on our network. However, what do we know about some of those applications? How do those apps work? Do they have patches, what about security flaws? Many of these questions need to be answered for off the shelf products. It gets even more interesting when we begin to consider home grown products.

    I used to work for a company that had an in house software developer. He would take care of most of the behind the scenes database work as well as the main business analytics pieces. All of that to say he was creating code that gathered data which in turn ran the business. SANS's recommends that software have a development life cycle. In other words, much like hardware or other off the shelf products, a plan needs to be in place. We state that we are creating a piece of software for a task and we plan on how to implement it and take it out of the enterprise. This also means knowing what pieces of software are developed in house, and who is responsible for them.

    I will be honest; I don't have a lot of experience with this. However, it is clear to me that having software developers involved in ongoing education and being a part of a community of practice would help a lot. In the end, people need to understand what is going on and have a process in place. This should ensure that an account can be made of all locally developed products.

Sunday, October 23, 2011

The SANS Top 20 Week 6

    Control 6 on the Sans Top 20 is something near and dear to my heart. That's right Logging. Ok, before we get too far into this I have to be honest. There is absolutely nothing fun, exciting, or interesting about logging. Most of the great solutions out there are very expensive. The primary example of what comes to my mind is Logrythm. However, the guys who made the 2011 Verizon report have a great point! They stated that if someone had a basic idea of how many logs entries they have in a given time, and could tell when they increased they would be ahead of a large portion of the people who were mentioned in their report. While this is a bit beyond the scope of this entry here is a link.

    I worked for a restaurant chain not too long ago. We had a PCI compliance issue and we needed to do some logging. So here is what I did. I found a solution to this called Splunk. Splunk will index up to 500MB of logs per day for free. What this means is that you can take logs from just about anywhere and index them! Ok, so what I did is took all of our point of sale systems, the Cisco logs for our firewall, and a few choice others. That information was then collected into a flat file database. Splunk then offered me a great browser which I could type queries into, but where this solution really shined was the modules. Someone had a already designed a PCI module. I was able to have it do the searching for me!

    In the end, logging comes down to two things. First, you have to hold onto logs for a fixed amount of time. Second, you need to have a way to look at them. In the end logging efficiently depends on the size of the organization, the amount of data, and how important it is to the organization. In my mind with a little bit of hard disk, and a few hours, you can get a lot of great data!

Sunday, October 16, 2011

The SANS Top 20 Week 5

    This week we will be talking about Border defense in networks. Lately I have heard some negative press on this topic. Not because people are opposed to border defense, but because many IT people over emphasize this aspect of network security. While I tend to agree that border defense is important, I would like to point out that it is not a total defensive strategy in and of itself. If you remember back in week one we talked about hardware inventory. This is going to come into play heavily this week.

    Ok, so how do we define our border? In general I would state that it is the end of possible total control in our LAN networks. Most often this is characterized by a firewall, router, or both. Let's say we feel pretty good about our network and router configs. We reviewed them thoroughly because of Week 4. So the next question we have to ask is who is changing them. SANS recommends and I agree that logs of this type of information must be kept. Those logs should be e-mailed to whoever is responsible for security within an organization.

    So what type of tools can do this? NIST recommends a Linux distribution called Security Onion. I have also seen this done with Splunk. Providing you are capturing logs, it's not too much effort to determine who is logging into a system. Those logs could be sent out daily, or weekly. In the end I see this week's topic as a matter of two things. 1. IS change management, while 2. Is maintaining control over access.

Sunday, October 9, 2011

The Sans Top 20 and you Week 4

Last week we discussed creating default setups for software. This week we will be discussing secure configurations of Network Devices. You guessed it firewalls, routers, and switches. This topic is something near and dear to my heart. I've spent a considerable amount of time over the last few weeks studying for a CCNA exam, but enough about my free time or lack thereof. Ok, so how do we configure network infrastructure securely. The first thing we can do establish a process for changes on the network. The next thing we can do is refer to that inventory of devices that we created earlier. We can then make sure that we know what versions of equipment software we are using. At this point we can check with our manufacturers and see if issues are present. After that we can make copies of all the configuration files. We can then review the files. I like to look for things like no console passwords, or unencrypted passwords in the config. Next, make sure you are using SSH or HTTPS for all management. This may not always be possible, but do your best. Lastly, and this is the most important, make sure you review the configs annually. As a bonus, while I realize this can get expensive find a way to log firewall and switch data. I recommend using Splunk for this!

Sunday, October 2, 2011

The SANS top 20 and you, Week 3

    Week 3 of the SANS top 20 covers creating secure default setups for software, servers, and end user systems. The tricky part here is defining what is standard, safe and secure. However, if you have a good idea of the hardware and software present, which you should at this point, this becomes a lot simpler of a task. You can start by asking questions about what is present on your network. In my opinion you should know generally who and uses what software and why. I'm not advocating knowing the ins and outs of all software present on your network, but merely being aware of the primary users are. Secondly do some research! You can go to sites such as the Center for Internet Security and the NSA to look for details on configurations of some systems. The great thing here is that once you get a template you can copy it! Microsoft also has a built in base line security analyzer. This allows you to know the status of your Microsoft systems. In addition if you are using Spiceworks or another tool to monitor your network, you can scan for new software or hardware! You can also set switches and wireless access points up to deny unknown mac addresses. I also recommend an annual review of the corporate firewall. In addition develop a process for making changes. This can be as simple as a log that states when the change was made, who made the change, and why! Lastly Sans has intrusion detection worksheets, these sheets allow the creation of an automated baseline of systems. It gives you something to compare systems to if an issue occurs.

Sunday, September 25, 2011

The Sans Top 20 and you Week 2

Last week I wrote about the SANS top 20 security recommendations for small business, I focused on the first point, know what you have hardware. I decided this week I would focus on the second point. Know what you have software. In brief software is all of the stuff on your computer which allows you to do things. I would like to make a point here that while the Computers Operating System is software, it's not what I'm referencing this week.

Ok, I work in I.T., and more than once I've been called to someone's desk with a comment on, "My program doesn't work!", To which the typical I.T. response is, "What program?" Part of the issue is as I.T. professionals we don't often go through the trouble of limiting what people can put onto their PC's. After all, people want games, cool fonts, screen saver packages, etc… In this day and age many of those things are done on the internet using flash, but that's not something I'm looking to go too far into this week either!

I remember in one particular case I had a MAC user. Let's go ahead and call him user X. I was doing some traffic analysis on our network using OPENdns. Open DNS allows filtering and metrics on DNS data from networks. It's free and can be checked out at opendns.org. I noticed a lot of traffic going to a series of IP addresses. I did some reputation checking using mxtoolbox, and reputation authority. I found out that these IP's had a nasty reputation for being associated with botnets. I then found out after using the built-in MAC OSX firewall that the traffic was being placed on the net by you guessed it, a screen saver!

This covers why we need to know what programs are on PC's and a little bit of how you can track programs which are negative, but a better approach would be proactive! Spiceworks can check which programs are on your network. It can do this by scanning for .exe's. Spiceworks as I mentioned last week is free, and great to use! You can also use Microsoft's built-in software policies. I most recently used these on a terminal server to force programs to only run from one directory and then locked it down. This also stops people from accidently installing things. I next recommend restricting local admin rights on PC's. This limits the amount of damage that can occur. The last step with things like this is rescanning PC's. No matter how hard you try someone will typically find a way to get unwanted programs onto PC's. Remember, a non-technical solution to this could be a policy which states what is acceptable on a local network. For starters, NO non-approved software!

Sunday, September 18, 2011

The SANS top 20 and you Week 1

    I came across some very interesting information the other day. Apparently the SANS institute (System Administration Networking and Security), has a list of 20 items that a business can implement at no cost. I realize that time is money too. Soooo, even if there is no direct monetary value attached to the ideas, someone still has to put them in place. If I was naming this list it would say 20 good ideas for security (definitely a cheap way to get it done). While I won't be covering this whole document right now, I plan to dive into it more over the next few weeks. Here is the link to the article if someone get's to jumpy and can't wait (http://www.sans.org/reading_room/whitepapers/hsoffice/small-business-budget-implementation-20-security-controls_33744)

    Ok, so the real question is why do we care about securing networks? How effective are the ideas listed in this article? According to SANS, the adoption of this program in 2009 resulted in an 88% drop in vulnerabilities. In other words the number of systems which were vulnerable went down a lot. It bears reminding that a vulnerability is a weakness which may be exploited in a system. It is like locking a window in your house. Just because a windows is open doesn't mean a thief will break into it. So, onto the vulnerabilities, let's start with item one on the list.

  1. Inventory of authorized and unauthorized devices.

Small bushiness's are notoriously busy doing everything in their power to make money. When a computer is broken they buy a new one. When they network goes down they call a guy to fix it. That guy buys some equipment and puts it into place. The problem is solved and business as usual goes on. This happens over a long timeline. No one considers any of it, after all things are working. At some point in this a company get's to a size where they need a little more formal I.T. help. The company may hire an MSP (managed service provider). This MSP may make their network more complicated. They may host the e-mail for the company, or offer to take care of the Anti-Virus system. However, and I can only speak from my experience, they will not document what happens. They won't serialize the PC's on the network and list the MAC (Media Access Control) number. As an interesting aside you can tell a lot by one of these. Most likely what kind of equipment it is or where it came from. Check these links out for further information. (http://www.coffer.com/mac_find/ , http://en.wikipedia.org/wiki/MAC_address). That is because while these things are helpful, they are not vital to the immediate need of a business. However, they are vital to the integrity of a business's information.

    I mentioned some of this in last week's post. I won't belabor the point, but if I knew what the good items on the network were, I could have isolated the bad one by Mac address. So, how does one go about getting this inventory going? There are certainly many ways to accomplish this. However, for free, I would start with spice works. This piece of software will scan your network and figure out what you have on it. If you have managed switches, you can also check the ARP tables (Address Resolution Protocol) on those switches. If you are in a domain environment, and you have a file server, you can check the ARP table there as well. You can even check your DHCP server. This will have the same information. In order to track ongoing changes, SANS recommends sourcefire RNA, this will make alerts when a new device is added. However, I was unable to find any information about getting Sourcefire for free. Spiceworks will do this. While the notification will be less automatic, it will help you notice when something new shows up.

    While this doesn't cover everything in a hardware inventory, I hope it does point out some simple steps.

    
 

     

Tuesday, September 13, 2011

Documentation is not a four letter word

I have recently found myself in a position where I have begun to appreciate the importance of documentation. A few years ago I worked in a small help desk, most of the time my duties included password resets and some of the smaller minutiae of IT. I remember thinking to myself, "why would I take time to write down what happens?" As luck would have it, I'm no longer working in that role or environment. Information Technology exists for most businesses to keep things running. However, as I've learned recently IT becomes vital to an organization when it exists to help that organizations meet goals. Technology is about making things happen in ways that enhance those it serves.

OK, so I recently found myself in a situation. I was working on a network and found that several PC's were getting rogue DHCP address. I began to wonder if there was an issue. I asked myself, "where is the AP?" I then wondered if documentation of all the WAP's around was available. After a search I found out that it wasn't. So I did what anyone would do. I figured out the IP of the DCHP server. I ended up checking MAC address tables and figuring out which switch it was connected to. Then since I knew where the WAP was relatively, I used a Wi-Fi analyzer to track down the offending AP and disabled it. It turns out this AP wasn't malicious, but it was something a previous admin had left in place and forgotten about.

While the WAP I found wasn't malicious in nature, I did learn several valuable lessons from the experience.

  1. Know what is on your network. If you don't have documentation, create it.
  2. Disable unused ports in rooms. Document
  3. Make sure you have the capability to track down rogue AP's. This can be as easy as an APP on a phone. WiFi analyzer for android worked for me. (Document what you use and how you use it)

While there are numerous other things which can be done, the list I provided is the bare minimum. It is my hope that this article illustrates some simple documentation, and the benefits of having it.