NOTE: I have zero financial relationship with Arbor, don't even hold their stock. However, I have seen them in the field for 20 years, they must be doing something right. DDoS is becoming a significant issue and it is a thorny problem. Worse, it takes money and outside resources to deal with it. Worse again, if you ignore it and they come down on your organization so that customers cannot interact with you, your organization may be seriously damaged in terms of revenue and customer relationship; and that is sugar coating it. So, it is time to go to school to get your arms around the problem. I found this easy to watch set of videos. As you watch them, think about how to take the key points and share them with management at your organization.
History of DDoS. How did we get in such a mess?
One size does not fit all with DDoS, what are the basic forms and their implications?
DDoS has been around for at least 30 years, how could it possibly be an advanced attack?
Can you give me an example of a potential solution that does not require solely counting on a cloud provider?
Tuesday, August 25, 2015
Monday, August 24, 2015
Draft Course Layout - SANS Boston 2016 - Feedback requested
This is subject to change, but this is what the program committee is leaning towards for the courses. I am still trying to channel the evening program. Please tell me what you think.
We have 3 rooms that can seat over 200 if they are set theater style. Obviously many of the SANS faculty have their own keynotes and evening talks, but I would like to find some local cybersecurity thought leaders that are "outside of the SANS family".
We are getting close to a solid course line up for Boston 2016 August 1 - 7 at the Omni Parker House. We are a bit conflicted about SEC 575. We have limited qualified instructors and the course is popular, but it is early still. There is still time to make a substitution for 575 as needed. If you think there is a course that would be a better fit for the needs of the New England area please leave me a comment and I will try to get back with you.
Day course matrix
SEC 503 Intrusion Detection In-Depth
Evening program
Don't miss the Tea Party, no not politics, tea.We have 3 rooms that can seat over 200 if they are set theater style. Obviously many of the SANS faculty have their own keynotes and evening talks, but I would like to find some local cybersecurity thought leaders that are "outside of the SANS family".
Saturday, August 22, 2015
White Paper: Using Network Based Security Systems to Search for STIX and TAXII Based Indicators of Compromise
This paper does a pretty good of highlighting tools to detect that an organization has been breached and hopefully that will be caught very early in the process.
First we meet Mandiant led, Common Indicators of Compromise, (IOCs). Not rocket science, but really helpful: hashes of known malicious files, IP addresses or DNS names, and much more. The next piece of the puzzle are Uber competitors, STIX and TAXII. Well actually, they are an NIST standard that looks like they will stick. Mostly you read some high level mumbo jumbo about them, but this is your chance for a deep dive, or at least a 3 atm free dive. These are real, concrete examples.
If you are a senior cybersecurity manager, you eyes will glaze over when you get to the good stuff. But before you close the paper, scan down, find an example or two you are comfortable with. Copy them off and keep them in a folder. When you are part of a job interview for a senior security engineer position, the kind of person that commands a $140k salary, bring out the folder and ask them to tell you about it.
I encourage you, your employer encourages you, to at least speed read the paper which is available here.
Wednesday, August 5, 2015
David Longnecker's post on reducing the risk of StageFright
The content below was written by David Longnecker, who graciously gave me permission to post:
Zimperium just released details and POC code for the StageFright
vulnerabilities:
https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/
I've put together a quick how-to for "friends and family" to disable
auto-retrieve of multimedia messages in the native Android Messages app,
and in Google Hangouts, here:
http://www.securityforrealpeople.com/2015/08/avoid-stagefright-by-turning-off-auto.html
It doesn't cover every scenario, but it at least protects against the 100%
unaided attack.
Regards,
David Longenecker
Connect: Blog <http://securityforrealpeople.com> | @dnlongen
<https://www.twitter.com/dnlongen> | LinkedIn
<https://www.linkedin.com/in/dnlongen/>
PGP key: https://keybase.io/dnlongen
Zimperium just released details and POC code for the StageFright
vulnerabilities:
https://blog.zimperium.com/stagefright-vulnerability-details-stagefright-detector-tool-released/
I've put together a quick how-to for "friends and family" to disable
auto-retrieve of multimedia messages in the native Android Messages app,
and in Google Hangouts, here:
http://www.securityforrealpeople.com/2015/08/avoid-stagefright-by-turning-off-auto.html
It doesn't cover every scenario, but it at least protects against the 100%
unaided attack.
Regards,
David Longenecker
Connect: Blog <http://securityforrealpeople.com> | @dnlongen
<https://www.twitter.com/dnlongen> | LinkedIn
<https://www.linkedin.com/in/dnlongen/>
PGP key: https://keybase.io/dnlongen
Tuesday, June 16, 2015
The Florentine Deception by Symantec's Carey Nachenberg
Carey Nachenberg is the chief engineer at Symantec Corporation (one of the original inventors of Norton Antivirus) and the author of a new cyber-security-themed thriller entitled The Florentine Deception. Carey is using the novel as the basis of a charity effort to support charities benefitting underserved students and veterans (including KIPP.org, Success Academy, and NPower.org, among others). As such, he is looking for partner organizations to help get the word out. He has already pledged $4,300 from sales, but am trying to reach a target of $10,000. So any exposure from the security community will go a long way toward helping his charities.
So what is the novel about? The Florentine Deception is, at its heart, an edge-of-your-seat cyber-security adventure that combines the action elements of Da Vinci Code with the technology elements of CSI: Cyber. It follows twenty-something Alex Fife has he hunts for an elusive object known as the "Florentine," and inadvertently stumbles upon an Iranian effort to decimate the US's computing infrastructure. The cyber-security aspects of the story are actually feasible, and in fact the book’s foreword was written by Dr. Eugene Spafford, PhD of Purdue’s CERIAS, (and one of my role models), who corroborates the technical elements of the story.
For background on Carey's book, his biography, his charities, etc., please see: www.florentinedeception.com
Tuesday, May 12, 2015
If you are in Virginia consider Mach 37
I received the following by email:
|
|||
|
Wednesday, May 6, 2015
Whoops, (Little Snitch, Mac, Safari, infoRisk TODAY)
Yesterday, I was teaching using GoToTraining. I run an outbound firewall called Little Snitch. You would not believe how many outbound connections that product requires and worse many of them to not resolve.
Fortunately I started preparing almost an hour before the training and finally realized allowing each connection wasn't going to work. So, I finally decided to disable outbound filtering.
This morning, I had an email from a group called infoRisk TODAY. Not sure how I got it, guessing they bought a mailing list. One of the articles, an interview with the CEO of BB&T looked interesting. So I clicked on that link. Ghostery showed the usual suspects, so these people do want to track you.
After a minute the screen darkened and a little box popped up. I killed the tab. And realized outbound filtering was still disabled. Whoops. I used Safari Preferences to clear cookies and website data, (I have Safari set to always block cookies, but some stuff gets in anyway). Then I killed Safari and ran CCleaner to get the stuff Safari doesn't take care of.
Then I went back. The popup still got through everything. Time for me to revisit how I harden my general purpose browsing. Screenshot with partially successful popup is below.
Fortunately I started preparing almost an hour before the training and finally realized allowing each connection wasn't going to work. So, I finally decided to disable outbound filtering.
This morning, I had an email from a group called infoRisk TODAY. Not sure how I got it, guessing they bought a mailing list. One of the articles, an interview with the CEO of BB&T looked interesting. So I clicked on that link. Ghostery showed the usual suspects, so these people do want to track you.
After a minute the screen darkened and a little box popped up. I killed the tab. And realized outbound filtering was still disabled. Whoops. I used Safari Preferences to clear cookies and website data, (I have Safari set to always block cookies, but some stuff gets in anyway). Then I killed Safari and ran CCleaner to get the stuff Safari doesn't take care of.
Then I went back. The popup still got through everything. Time for me to revisit how I harden my general purpose browsing. Screenshot with partially successful popup is below.
Then it was time to unsubscribe from infoRisk TODAY. That took me to a screen that said my first name was Suzy, funny, I thought it was Stephen. Sigh, it is sad when you can't tell the good guys from the bad guys.
Subscribe to:
Posts (Atom)
