Tuesday, August 25, 2015

DDOS Arbor Style

NOTE: I have zero financial relationship with Arbor, don't even hold their stock. However, I have seen them in the field for 20 years, they must be doing something right. DDoS is becoming a significant issue and it is a thorny problem. Worse, it takes money and outside resources to deal with it. Worse again, if you ignore it and they come down on your organization so that customers cannot interact with you, your organization may be seriously damaged in terms of revenue and customer relationship; and that is sugar coating it. So, it is time to go to school to get your arms around the problem. I found this easy to watch set of videos. As you watch them, think about how to take the key points and share them with management at your organization.

History of DDoS. How did we get in such a mess?

One size does not fit all with DDoS, what are the basic forms and their implications?

DDoS has been around for at least 30 years, how could it possibly be an advanced attack?

Can you give me an example of a potential solution that does not require solely counting on a cloud provider?

Monday, August 24, 2015

Draft Course Layout - SANS Boston 2016 - Feedback requested

This is subject to change, but this is what the program committee is leaning towards for the courses. I am still trying to channel the evening program. Please tell me what you think.

We are getting close to a solid course line up for Boston 2016 August 1 - 7 at the Omni Parker House. We are a bit conflicted about SEC 575. We have limited qualified instructors and the course is popular, but it is early still. There is still time to make a substitution for 575 as needed. If you think there is a course that would be a better fit for the needs of the New England area please leave me a comment and I will try to get back with you.

Day course matrix




Evening program

Don't miss the Tea Party, no not politics, tea.

We have 3 rooms that can seat over 200 if they are set theater style. Obviously many of the SANS faculty have their own keynotes and evening talks, but I would like to find some local cybersecurity thought leaders that are "outside of the SANS family".

Saturday, August 22, 2015

White Paper: Using Network Based Security Systems to Search for STIX and TAXII Based Indicators of Compromise


 This paper does a pretty good of highlighting tools to detect that an organization has been breached and hopefully that will be caught very early in the process.

First we meet Mandiant led, Common Indicators of Compromise, (IOCs). Not rocket science, but really helpful:  hashes  of  known malicious  files,  IP  addresses  or  DNS  names, and much more. The next piece of the puzzle are Uber competitors, STIX and TAXII. Well actually, they are an NIST standard that looks like they will stick. Mostly you read some high level mumbo jumbo about them, but this is your chance for a deep dive, or at least a 3 atm free dive. These are real, concrete examples.

If you are a senior cybersecurity manager, you eyes will glaze over when you get to the good stuff. But before you close the paper, scan down, find an example or two you are comfortable with. Copy them off and keep them in a folder. When you are part of a job interview for a senior security engineer position, the kind of person that commands a $140k salary, bring out the folder and ask them to tell you about it.

I encourage you, your employer encourages you, to at least speed read the paper which is available here.



Wednesday, August 5, 2015

David Longnecker's post on reducing the risk of StageFright

The content below was written by David Longnecker, who graciously gave me permission to post:

Zimperium just released details and POC code for the StageFright
vulnerabilities:

https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/

I've put together a quick how-to for "friends and family" to disable
auto-retrieve of multimedia messages in the native Android Messages app,
and in Google Hangouts, here:

http://www.securityforrealpeople.com/2015/08/avoid-stagefright-by-turning-off-auto.html

It doesn't cover every scenario, but it at least protects against the 100%
unaided attack.

Regards,
David Longenecker

Connect: Blog <http://securityforrealpeople.com> | @dnlongen
<https://www.twitter.com/dnlongen> | LinkedIn
<https://www.linkedin.com/in/dnlongen/>
PGP key: https://keybase.io/dnlongen

Tuesday, June 16, 2015

The Florentine Deception by Symantec's Carey Nachenberg

Carey Nachenberg is the chief engineer at Symantec Corporation  (one of the original inventors of Norton Antivirus) and the author of a new cyber-security-themed thriller entitled The Florentine Deception.  Carey is using the novel as the basis of a charity effort to support charities benefitting underserved students and veterans (including KIPP.org, Success Academy, and NPower.org, among others). As such, he is looking for partner organizations to help get the word out. He has already pledged $4,300 from sales, but am trying to reach a target of $10,000. So any exposure from the security community will go a long way toward helping his charities.

So what is the novel about? The Florentine Deception is, at its heart, an edge-of-your-seat cyber-security adventure that combines the action elements of Da Vinci Code with the technology elements of CSI: Cyber. It follows twenty-something Alex Fife has he hunts for an elusive object known as the "Florentine," and inadvertently stumbles upon an Iranian effort to decimate the US's computing infrastructure. The cyber-security aspects of the story are actually feasible, and in fact the book’s foreword was written by Dr. Eugene Spafford, PhD of Purdue’s CERIAS, (and one of my role models), who corroborates the technical elements of the story.


For background on Carey's book, his biography, his charities, etc., please see: www.florentinedeception.com


Tuesday, May 12, 2015

If you are in Virginia consider Mach 37

I received the following by email:


Mentors and Friends of MACH37,

We could use your support in spreading the word to startups working on promising new security products (or technologies that you'd like to see in the market) that MACH37 is preparing for the Fall 2015 (F15) cohort . Please let them know about MACH37 or feel free to introduce us to them. 

The soft application deadline for the upcoming F15 Cohort (September 8 - December 8) is June 1st... just around the corner!

Please let anyone you know that we are excited to chat with them about MACH37 or feel free to introduce us to them and recommend they reach out to us and apply for the F-15 program... soon.

Below are some details about the MACH37 F15 cohort and the application link that you can cut and paste.

Thank you for helping to make MACH37's F15 cohort a great success.

----------------------------------
Apply Here

Soft Deadline
June 1, 2015
*** We highly encourage all interested entrepreneurs  to apply by this date.  The MACH37 team will start reviewing and extending invitations to interview in June and will be extending offers to accepted applicants, to the F15 Cohort, in July. 

Fall 2015 Start and End Date
September 8th - December 8th

Basic Deal
$50K for 8% and active (full) participation in the 90 day on-site program at the MACH37 facilities in Herndon, VA.

Website

About MACH37
Twice a year, MACH37 invests in a class of 5-8 security startups, each of which participates in an intensive 3-month (90 day) program that allows entrepreneurs to validate their disruptive cybersecurity concepts and prepare their companies for investment. The program brings together domain experts, successful cybersecurity entrepreneurs, as well as focused mentorship from our extensive network of visionaries, practitioners, and successful security entrepreneurs as well as investors familiar with the security market. The MACH37  program is designed to propel graduating companies into the marketplace, equipped with the skills to grow and compete for funding and market share.  At the end of 3 months there is a Demo Day presentation to an ever growing investor community.

Please Contact Us With Questions
Ledger West - ledger.west@mach37.com
Rick Gordon - rick.gordon@mach37.com
Bob Stratton - bob.stratton@mach37.com
Dan Woolley - dan.woolley@mach37.com
----------------------------------
Copyright © 2015 MACH37, All rights reserved. 
You are receiving this email because you are a friend of Mach37. 

Our mailing address is: 
MACH37
2214 Rock Hill Road, Herndon, VA, United States
Suite 270
Herndon, VA 20170

Wednesday, May 6, 2015

Whoops, (Little Snitch, Mac, Safari, infoRisk TODAY)

Yesterday, I was teaching using GoToTraining. I run an outbound firewall called Little Snitch. You would not believe how many outbound connections that product requires and worse many of them to not resolve.

Fortunately I started preparing almost an hour before the training and finally realized allowing each connection wasn't going to work. So, I finally decided to disable outbound filtering.

This morning, I had an email from a group called infoRisk TODAY. Not sure how I got it, guessing they bought a mailing list. One of the articles, an interview with the CEO of BB&T looked interesting. So I clicked on that link. Ghostery showed the usual suspects, so these people do want to track you.

After a minute the screen darkened and a little box popped up. I killed the tab. And realized outbound filtering was still disabled. Whoops. I used Safari Preferences to clear cookies and website data, (I have Safari set to always block cookies, but some stuff gets in anyway). Then I killed Safari and ran CCleaner to get the stuff Safari doesn't take care of.

Then I went back. The popup still got through everything. Time for me to revisit how I harden my general purpose browsing. Screenshot with partially successful popup is below.


Then it was time to unsubscribe from infoRisk TODAY. That took me to a screen that said my first name was Suzy, funny, I thought it was Stephen. Sigh, it is sad when you can't tell the good guys from the bad guys.