Tuesday, June 16, 2015

The Florentine Deception by Symantec's Carey Nachenberg

Carey Nachenberg is the chief engineer at Symantec Corporation  (one of the original inventors of Norton Antivirus) and the author of a new cyber-security-themed thriller entitled The Florentine Deception.  Carey is using the novel as the basis of a charity effort to support charities benefitting underserved students and veterans (including KIPP.org, Success Academy, and NPower.org, among others). As such, he is looking for partner organizations to help get the word out. He has already pledged $4,300 from sales, but am trying to reach a target of $10,000. So any exposure from the security community will go a long way toward helping his charities.

So what is the novel about? The Florentine Deception is, at its heart, an edge-of-your-seat cyber-security adventure that combines the action elements of Da Vinci Code with the technology elements of CSI: Cyber. It follows twenty-something Alex Fife has he hunts for an elusive object known as the "Florentine," and inadvertently stumbles upon an Iranian effort to decimate the US's computing infrastructure. The cyber-security aspects of the story are actually feasible, and in fact the book’s foreword was written by Dr. Eugene Spafford, PhD of Purdue’s CERIAS, (and one of my role models), who corroborates the technical elements of the story.


For background on Carey's book, his biography, his charities, etc., please see: www.florentinedeception.com


Tuesday, May 12, 2015

If you are in Virginia consider Mach 37

I received the following by email:


Mentors and Friends of MACH37,

We could use your support in spreading the word to startups working on promising new security products (or technologies that you'd like to see in the market) that MACH37 is preparing for the Fall 2015 (F15) cohort . Please let them know about MACH37 or feel free to introduce us to them. 

The soft application deadline for the upcoming F15 Cohort (September 8 - December 8) is June 1st... just around the corner!

Please let anyone you know that we are excited to chat with them about MACH37 or feel free to introduce us to them and recommend they reach out to us and apply for the F-15 program... soon.

Below are some details about the MACH37 F15 cohort and the application link that you can cut and paste.

Thank you for helping to make MACH37's F15 cohort a great success.

----------------------------------
Apply Here

Soft Deadline
June 1, 2015
*** We highly encourage all interested entrepreneurs  to apply by this date.  The MACH37 team will start reviewing and extending invitations to interview in June and will be extending offers to accepted applicants, to the F15 Cohort, in July. 

Fall 2015 Start and End Date
September 8th - December 8th

Basic Deal
$50K for 8% and active (full) participation in the 90 day on-site program at the MACH37 facilities in Herndon, VA.

Website

About MACH37
Twice a year, MACH37 invests in a class of 5-8 security startups, each of which participates in an intensive 3-month (90 day) program that allows entrepreneurs to validate their disruptive cybersecurity concepts and prepare their companies for investment. The program brings together domain experts, successful cybersecurity entrepreneurs, as well as focused mentorship from our extensive network of visionaries, practitioners, and successful security entrepreneurs as well as investors familiar with the security market. The MACH37  program is designed to propel graduating companies into the marketplace, equipped with the skills to grow and compete for funding and market share.  At the end of 3 months there is a Demo Day presentation to an ever growing investor community.

Please Contact Us With Questions
Ledger West - ledger.west@mach37.com
Rick Gordon - rick.gordon@mach37.com
Bob Stratton - bob.stratton@mach37.com
Dan Woolley - dan.woolley@mach37.com
----------------------------------
Copyright © 2015 MACH37, All rights reserved. 
You are receiving this email because you are a friend of Mach37. 

Our mailing address is: 
MACH37
2214 Rock Hill Road, Herndon, VA, United States
Suite 270
Herndon, VA 20170

Wednesday, May 6, 2015

Whoops, (Little Snitch, Mac, Safari, infoRisk TODAY)

Yesterday, I was teaching using GoToTraining. I run an outbound firewall called Little Snitch. You would not believe how many outbound connections that product requires and worse many of them to not resolve.

Fortunately I started preparing almost an hour before the training and finally realized allowing each connection wasn't going to work. So, I finally decided to disable outbound filtering.

This morning, I had an email from a group called infoRisk TODAY. Not sure how I got it, guessing they bought a mailing list. One of the articles, an interview with the CEO of BB&T looked interesting. So I clicked on that link. Ghostery showed the usual suspects, so these people do want to track you.

After a minute the screen darkened and a little box popped up. I killed the tab. And realized outbound filtering was still disabled. Whoops. I used Safari Preferences to clear cookies and website data, (I have Safari set to always block cookies, but some stuff gets in anyway). Then I killed Safari and ran CCleaner to get the stuff Safari doesn't take care of.

Then I went back. The popup still got through everything. Time for me to revisit how I harden my general purpose browsing. Screenshot with partially successful popup is below.


Then it was time to unsubscribe from infoRisk TODAY. That took me to a screen that said my first name was Suzy, funny, I thought it was Stephen. Sigh, it is sad when you can't tell the good guys from the bad guys.

Wednesday, April 1, 2015

Using Sysmon to increase Security Onion effectiveness

Author Josh Brower did a great job in this research project. From the paper's abstract, "With more network traffic being encrypted, as well as the persistence of advanced adversaries, it is becoming increasingly imperative that there is greater visibility at the host-level. With this greater visibility comes the ability to more efficiently detect and respond to threats. This paper highlights the use of Sysmon to enrich existing Windows host visibility capabilities in Security Onion, as well as how to use this increased visibility in detection and incident response."

 

New GIAC Cert GCHQ

Global Intelligence Acquired Covertly, (GIAC), is please to announce our newest certification, the GCHQ. The GCHQ is your opportunity to demonstrate your mastery of the Zero Knowledge Reproof, (ZKR).

GIAC's Hero's Quest, (GCHQ), is the highest level of IntelWars. All Your SIMs Belong to Us, (AYSBU) is an automated adventure game/role-playing game hybrid, designed by a joint unit consisting of operatives from the NSA and its British counterpart Government Communications Headquarters, or GCHQ, (recursion alert), and available in both tournament mode and continuous play. Feedback from beta testers give it credit for being a genre-defining test of skill mixing graphical adventure gaming with role-playing-like elements such as statistic building (cryptoanalysis, Intel microcode hijacking, or electricity sinewave manipulation for remote access) that would actually have an impact on the ability to accomplish certain parts of the simulation. Candidates have 72 hours to locate and acquire the private keys from Geppetto, an international digital security company providing smart cards, tokens and the world's most secure Subscriber Identify Module, (SIM).

About GIAC: GIAC is a software engineering company with over 20 years experience acquiring crypto keys. We are known for creating "factory smooth" performance software with exceptional power and reliability. Our software replaces the security software in your organization's perimeter devices.

GIACs development team employs proprietary GIAC software and a variety of debuggers, emulators and scopes to tackle the most complex cryptoanalysis problems. Our dedicated research facilities just outside of Fort Meade, Maryland, houses the world's fastest Deconfibulator and state of the art tools for developing and testing software. Expertise in software and circuit design, combined with an understanding of embedded technology, enable us to offer a broad range of tuning solutions.

Our motto is: "No more secrets except for ours".

About AYSBU.com: Sitemize üye iseniz, giriş yapmak için; lütfen E-posta ve Şifrenizi girdikten sonra Giriş butonuna tıklayınız. Sitemize üyelik ücretsizdir. Eğer kayıt yaptırmadıysanız birkaç dakika içinde sitemize üye olup giriş yapabilirsiniz. Alış veriş yapabilmek için sitemize üye olmanız gereklidir. Üye olma işlemini sipariş verme aşamasında da yapabilirsiniz!

References:
https://firstlook.org/theintercept/2015/02/19/great-sim-heist/
http://www.networkworld.com/article/2170988/security/new-giac-certification-advances-industrial-cyber-security.html
HQ: http://en.wikipedia.org/wiki/Quest_for_Glory:_So_You_Want_to_Be_a_Hero

(Happy April 1st)

Practical El Jefe, (Windows process monitoring), by Charles Vedaa

The continuing threat increase is leading to something considered impossible ten years ago, a host based, OS monitoring solution. Author Charles Vedaa describes how to implement El Jefe, a fairly lightweight and economical solution. See the paper here.

Thursday, August 15, 2013

Shame on you Doctor Ponemon

Gosh, I always respected the Ponemon institute. However today, I got the same SPAM for the second time; no way to unsubscribe, "take me off your list" resulted in an undeliverable response. How much did you sell out for Doctor P?

When I was growing up, the black sheep of my family told me to never break the law or risk ruining my reputation for anything less than a million and that would have been 1965 dollars.

By the way, you probably are not the "pre-eminent" research center dedicated to information security policy, that would be either Information Shield ( Charles Cresson Woods/David Lineman) , Princeton, or SANS (Michelle Guel/Stephen Northcutt). Google doesn't lie; type in "Information Security Policy" and see if you make the top slot. And guess what; none of us at the top brag and Shield and SANS make efforts to help one another, ( and I would be honored to work with Princeton).

Doctor, I think you owe the information security community an apology. Don't do it on my account. Don't even do it because your partnership SPAMed me ( twice). Do it to preserve your reputation and fly straight from now on. Stephen
============================================================
SPAM is pasted below:
Security training has long been criticized for being boring, unengaging and lacking the ability to measure success. Organizations have found it difficult and are often reluctant to invest in unproven programs.

Today there is a better option - an innovative security education solution that is proven to get results.

The Ponemon Institute, the pre-eminent research center dedicated to privacy, data protection and information security policy, released the Executive Summary of a research study evaluating the effectiveness of SecurED®.

Key findings include:

SecurED outperforms the alternative training intervention by 300% in long term gains
Subjects perceive SecurED as more relevant to their job functions than the alternate
Subjects perceive SecurED as more enjoyable than the alternative intervention
Additionally, the research provided interesting findings specific to gender, age, employee role, industry and more.



To download the summary report CLICK HERE!


Final report will be available mid-August.