Wednesday, April 20, 2016

Looking for a security job? SANS Cybertalent Fair 5/19/16

The SANS CyberTalent Fair For both employers and job seekers, it's the most efficient and effective way to take the next employment step. It is an innovative virtual meeting place for the top cybersecurity employers and cybersecurity jobseekers in the United States. This May, 34 unique employers will be present to connect those with skills and experience in cybersecurity with top employers in this growing field.

To register: https://app.brazenconnect.com/events/sans-cybertalent-fair-may2016#!eventLanding;eventCode=sans-cybertalent-fair-may2016


For complete information, contact mshuftan@sans.org


Tuesday, April 19, 2016

Improve Detection using HoneyCreds

Perhaps you have heard of the MIT CSAIL AI2 program and the claim of detecting 85% of attacks. According to Wired, the program uses logs, which means the attack has already happened. It will probably be a while before we can download Open AI2, so until then we need a strategy to better detect attacks. Increasing defenders are turning to variations of a HoneyCred system.  According to an excellent GIAC Gold paper authored by Scott Smith:

"Honey credentials (or HoneyCreds, Honey Hashes, and/or Canary Credentials, 
depending on whom you ask) are a relatively new application of the Honeytoken concept
that has gained traction in web-facing login security.  As the frequency and sophistication 
of brute-force attacks has increased, network administrators have taken to including faked logins and passwords within lists of legitimate credentials.  They are mixed with 
legitimate credentials, salted and hashed, and made readable by root only."

Another advantage is privileged accounts:

HoneyCreds may also be used to prohibit remote access from super/elevated 
privilege users.  Since root or administrator accounts should never be able to login via 
web services, an attempt of their logging in is a likely an indicator of attack.  A DenyAll 
ruleset can be written in these cases, with logging of all attempted passwords for later 
review. 

 Much of the material in Scott's paper is based on an Internet Storm Center blog post by Mark Baggett, (Twitter:@markbaggett) using the runas command:

First, I ran the following command to create a fake microsoft.com administrator record:
runas /user:microsoft.com\administrator /netonly cmd.exe

Then, when prompted for the microsoft.com administrator I can provide any password that I want.  In this example I typed "superpass".

Here is what you type to create those credentials.
runas /user:linux.org\root /netonly cmd.exe

Once again, when prompted for the root user's password, I can enter anything I want.  For this example I choose "notreallythepassword".   NOTE: You will need to leave those command prompts running on your system to keep the credentials in memory.

Then Mark ran a tool called Mimikatz to dump clear text passwords from memory. The middle arrow is the admin account he created with admin and superpass.



You can learn more about Mimikatz and hash passing by watching Raphael Mudge's Youtube video on the topic.

If you are interested in learning how to automate this and other common tasks with Python then keep your eyes open for Mark's course, SEC 573, Python for penetration testers, it will run in Berlin in June and Vegas in September.  Attackers and Defenders will learn the essentials of Python, networking, regular expressions, interacting with websites, threading and much more.  This will prepare you to run and modify tools like OpenCanary. Plus, I have an inside tip Mark is planning to add a 6th day to the course to give even more tips for defenders.



HoneyCreds are an example of threat hunting. Rob Lee will be giving a talk on Threat Hunting August 2 at SANS Boston. Stephen Northcutt is an advisor for the SANS Technology Institute, a cyber-security graduate school and chair of the upcoming SANS Boston 2016, August 1 - 6 where he will be teaching MGT 512, Security Leadership Essentials.

Sunday, April 17, 2016

Youtube How to install Crimepack - includes free malware

WARNING: Professional Cybersecurity stunt man with a safe browser: Authentic8 Silo. Don't try this at home, (or at work).

You can learn how to install the Crimepack software using a Youtube video, but it *might* not be a good idea. Mast3rTeam, who uploaded the video said to visit root.gb.net to "download this amazing kit!"

So, I did, (please don't), but something odd happened :)

Finally got the page to load:


Clicked on one of the images, I knew I should have learned Chinese. I wonder what this screen means?

ShadowDragon - Social media and other monitoring company

Years ago, I was asked to speak at a military conference in Germany.  One of the other speakers gave a talk about using social media in Russia to look at the patterns of communications between various hacker/malware author etc type. Who connected to who? Who was the center of some of the larger networks of these types of people. A lot of the work was done manually, he had a bunch of sla^H^H^Hgrad students that were fluent in Russian and other Eastern European languages and they fed the posts and identifiers into a graphing program. I remember thinking, "If this could be automated then smart people would have to be pretty careful how they use social media".

So I reached out to Daniel Clemens of ShadowDragon and Packet Ninjas and asked for his thoughts on what is possible and the direction things are going.

So Daniel, is ShadowDragon different than Packet Ninjas?

Since 2005 we had been running Packet Ninjas. It is still running and great for consulting. In the context of consulting we had been pushed into many strange cases that had typically involved some form of corporate espionage in countries where the rule of law may not be as robust as the US. Attribution was needed and our clients starting around 2006 started asking for attribution. Obviously, this was strange and we started to look for "where can we buy data" versus engineer things. This moved us to creating tools. The first being SocialNet. (( attached ). SocialNet helped us and our clients start correlating the who behind the what and has served well over the years as an output to many platforms, specifically Maltego



We have over 900 transforms and cover some of the strangest platforms for attribution and the OSINT workflow. 

"Open-source intelligence (OSINT) is intelligence collected from publicly available sources. In the intelligence community (IC), the term "open" refers to overt, publicly available sources (as opposed to covert or clandestine sources); it is not related to open-source software or public intelligence."


Is this similar to Threat Hunting, I have been hearing that term a lot recently? And does it work?

I would caveat with OSINT or what the industry now calls "Threat Intelligence" there should be an expectation that 60% success is a good day and normal scientific process of theory and questions should be posed and practiced. I also have to warn that some people might not be ready for this type of work even though it sounds cool. Any investigation as you know is usually intriguing, but with attribution and an industry we are close to where we the country was pre-National Security act in the 40s. 

So ShadowDragon is the Social Network company?


We also created 4 other tool sets for different workflows, OIMonitor - monitoring many different things. For us "situational awareness", collection and analysis is different for many different verticals. Stix/Taxii 

Let me stop you for a second, I think I remember reading about STIX a year ago or so, ah yes, according to Blue Coat's Brett Jordan:
"A new language, designed to define and describe a broad swath of threat activity, is beginning to take shape. This language, known as STIX, and its transport method, called TAXII, offers security firms, industry, and government the promise of better and faster cyber threat intelligence sharing.

STIX and TAXII have been getting key support and backing from groups as diverse as the Department of Homeland Security, The MITRE Corporation, and members of various information security groups and vendors, including Blue Coat Systems.

For the past 6 months, I have been heading up Blue Coat's participation in this effort.
STIX (Structured Threat Information eXpression) is a language used to communicate a set of cyber threat intelligence idioms, including:
  • Threat Actors
  • Campaigns
  • Techniques, Tactics, and Procedures
  • Exploit Targets
  • Indicators
  • Incidents
  • Cyber-Observables
  • Courses of Action
TAXII (Trusted Automated eXchange of Indicator Information) is the preferred delivery mechanism for STIX data. Technically, TAXII is a lightweight XML-over-HTTP transport protocol, specifically designed to deliver STIX data. TAXII allows publishers to share STIX data with (and, optionally, get STIX data from) subscribers, or for peers to share STIX data with other peers.

The STIX and TAXII standards have matured well beyond their initial drafts and first release in 2013. In fact, major vendors are lining up to announce support and governments, incident responders and CERTs, the Financial Services Information Sharing and Analysis Center (FS-ISAC), and the Industrial Control Systems Information Sharing and Analysis Center (ICS-ISAC) (to name a few) have already started using STIX and TAXII in their production environments."

In my experience STIX/TAXII, whatever really isn't even a discussion item even though many people want it to be.  Something like Unicode, collection, context and scalability should be thought of first before some type of weak community sharing model.

You might be right, I will admit I just groan sometimes at Mitre's handling of CVE, so where does your information come from? Are you monitoring in strange places? 

Not as strange as you would think, but it is always entertaining. There obviously are some restrictions, but I can share where it started. The end of 2010 we had been asked to monitor Anonymous. Not for attribution but for something very different. That being analysis of tools, techniques, targets and analysis of tools. This resulted in the creation of OIMonitor for this workflow but really acted as a platform for robust collection as a lead gen and historical context. We had used OIMonitor to monitor for tools and even had great success with identifying Sabu and "Murder" much earlier than others. We produced over 50 signatures for the tools and capabilities of everyone involved and at one time had monitoring of ALL of the IRC servers based on some oversights the operators had made in clustering.


I just read a recent article on active defense. Isn't attribution essentially an unsolvable problem?

Attribution can happen, but it relies on process and tools based on the foundation of investigative principles. For instance the latest naming and shaming of qcf in Iran/ME... It was our opinion they named the wrong folks. Attribution can go wrong or right and either way there can be repercussions that are unforeseen in the optic of typical right and wrong western perspectives. In short, a bad report or blogging in the public world may be interpreted differently in a different culture and people can die. I hate to be dramatic but this seems to be a turning point for those who want to make a name for themselves as bloggers and those who are quietly doing the work. All within the context that no one is doing this for a government.  But, government workers read blogs too so be careful. 

I will do my best to be careful Daniel, thank you for sharing your thoughts!


Experienced Cybersecurity Leader Looking in Los Angeles Area

John R. Tooley, CISSP, CISM, CCSP

Lake Balboa, CA 91406 || (818) 398-9764 || i_security@hotmail.com || LinkedIn: John Tooley, CISSP, CISM. CCSP


Vice President of Information Security

Strategic Planning & Execution || Information Security Management || Security Architecture, Design & Engineering
Global Security & Privacy Regulations || Threat & Vulnerability Management || Cross-Functional Team Leadership

Accomplished, outcome-driven Information/Cyber Security Leader with more than 20 years of established management expertise across all aspects of security disciplines: information security, cyber-risk and vulnerability management, threat modeling/analysis, and security intelligence. Proven record of success in providing strategic direction and oversight for enterprise information security and IT risk and compliance policies, principles, procedures, and practices.

Repeated success in leading and collaborating with cross-functional teams of IT experts, senior management, board-level executives, and key stakeholders in identifying corporate policy improvement opportunities, evaluating technical and business risk, and leading security related initiatives―across all risk categories; operations, compliance, IT, legal, and financial. Solid knowledge of compliance (PCI-DSS, HIPAA, ISO, SOX, etc.), and security governing bodies.

CORE COMPETENCIES

Security Strategy & Design || Secure Development || Incident Response || Virtualization Security || Compliance Oversight
Global Policy Development || Cloud Strategy & Governance || Data Loss Prevention (DLP) || Security Analytics || BYOD Security
Security Information Event Management (SIEM) || Secure Agile Development || Identity & Access Management (IAM/PIM)
Compliance Frameworks (PCI, SOX, HIPPA, SOC1&2) || Security Frameworks (NIST, ISO2700x, 20 Critical Controls)


PROFESSIONAL EXPERIENCE

ENTERTAINMENT PARTNERS, Burbank, CA                                                                                                                                  3/2010‒3/2016
Vice President of Information Security

       Played an instrumental role in providing leadership direction, guidance, and strategy for the Information Security Office; liaised between cross-functional teams, bringing groups together to share information and resources, and creating superior outcomes and process for Entertainment Partners.
       Offered guidance and counseling to the CEO and a 12-member leadership team, working closely with the legal and technology leaders, in defining objectives for information security. Assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies.
       Designed and implemented an enterprise-wide Information Security program, from the ground up, that consistently met business objectives and exceeding expectations for leadership and market valuation. Provided Due Diligence support and integration strategy for corporate mergers and acquisitions.
       Acted as primary control point during significant information security incidents and provide leadership for breach response and notification actions for the company. Represented Entertainment Partners on committees and organizations, including all client-facing collaborations.
       Delivered 40% overall program reduction, successfully eliminating non-value-add programs by streamlining capital and operational expenses, redefining structures, processes, and ROI-based resource alignment.
       Established annual and long-range security and compliance goals, define security strategies, metrics, and program services; and create maturity models and roadmaps for continual program improvements.

WARNER MUSIC GROUP, Burbank, CA                                                                                                                                               9/2007‒3/2010
Global IT Security Manager

       Designed Strategic Roadmap for Information Security. Key objectives focused on a defense-in-depth Security Architecture including implementation of a global Intrusion Protection strategy and advanced end-point defenses.
       Identified and assessed Information Security risks and exposures through the creation of a structured Vulnerability Assessment program encompassing application, database, and infrastructure components.
       Performed operational monitoring of critical enterprise resources and managed security project architecture to include allocation and assignment of resources, oversight of consulting, and signoff of security requirements.
       Developed and maintained Global Information Security policies.
       Coordinated Security Awareness program and materials to support information security standards and procedures related to specific business objectives, security product implementations and best practices.

Continued…
John R. Tooley, CISSP, CISM                                                                   2/2

Lake Balboa, CA 91406 || (818) 398-9764 || i_security@hotmail.com || LinkedIn: John Tooley, CISSP, CISM. CCSP



PROFESSIONAL EXPERIENCE

HARVARD-WESTLAKE SCHOOL, Studio City, CA                                                                                                                          6/1997‒4/2006
Network and Security Manager

       Led the Information Security group charged with handling all aspects of corporate compliance and information security efforts; including vulnerability and threat assessment, remediation, and virus mitigation.
       Audited enterprise security infrastructures and successfully established and implemented procedures and toolsets for conducting network, operating system and application vulnerability identification and testing. Documented the identified security gaps and performed remediation efforts.
       Served as active lead in the Campus Information Security Committee. Committee activities included an oversight function to ensure consistent Security focus and execution across all of the divisions along with reviewing new Security technologies and techniques.
       Managed and supervised Systems Administrators for all Windows, Unix, and Networking activities; leveraging in-house expertise; and provided Security and Network services resulting in significant cost savings to the divisions.
       Instituted a dependable corporate-wide, centralized backup system.
       Negotiated and managed Vendor contracts associated with the Enterprise Network and Security functions.
       Attained consistent 99.999% up-time by implementing disaster recovery and fault tolerance strategies.


EDUCATION, TRAINING & CERTIFICATIONS

CALIFORNIA STATE UNIVERSITY, Northridge, CA
Bachelor of Applied Science in Computer and Information Systems Security/Information Assurance

PHILLIPS COLLEGE / EDISON TECHNICAL COLLEGE, Northridge, CA
Associate of Science in Computer Science

ISC2, Los Angeles, CA (2002‒Present)
Certification―CISSP―Certified Information Systems Security Professional # 39513
Certification―CCSP―Certified Cloud Security Professional, Expected 2016

ISACA, Las Vegas, NV (2011‒Present)
Certification―CISM―Certified Information Security Manager # 1117598

SANS INSTITUTE (2001‒2015)
Certification―Network Penetration Testing and Ethical Hacking
Certification―Virtualization and Private Cloud Security
Certification―Top 20 Controls, Implementation and Audit
Certification―Law of Data Security and Investigations

Certification―Security Strategic Planning, Policy and Leadership

Saturday, April 16, 2016

UC Davis Pepper Spray historical revisionism

Today Slashdot had a story from The Verge that UC Davis spent at least 175k trying to bury a story about spraying students with pepper. Many of you know I was the information warfare officer of the Missile Defense Agency and I have seen a lot of historical revisionism. According to the Sacramento Bee,  "UC Davis contracted with consultants for at least $175,000 to scrub the Internet of negative online postings following the November 2011 pepper-spraying of students and to improve the reputations of both the university and Chancellor Linda P.B. Katehi, newly released documents show.
The payments were made as the university was trying to boost its image online and were among several contracts issued following the pepper-spray incident."


So, in the spirit of keeping the truth alive here is the Wikipedia account as of 4/16/16:

The UC Davis pepper-spray incident occurred on November 18, 2011, during an Occupy movement demonstration at the University of California, Davis. After asking the protesters to leave, University police pepper sprayed a group of demonstrators as they were seated on a paved path in the campus quad. The video of UC Davis police officer Lt. John Pike pepper spraying demonstrators spread around the world as a viral video and the photograph became an Internet meme.[3] Officer Alex Lee also pepper sprayed demonstrators at Pike's direction.[4]

In October 2013, a judge ruled that Lt. John Pike, the lead pepper sprayer, would be paid $38,000 in worker's compensation benefits, to compensate for his psychological pain and suffering. Apart from the worker's compensation award, he retained his retirement credits. As of August 2014, Lee's name no longer appeared in a database of state workers.[5]



Wednesday, April 13, 2016

Trusting trust

There is a big problem with trust. It is because people are involved.

I wrote a LI post on the root key for DNS. One of the comments was by Jason Andress:
I thought this bit from the cloudflare article was interesting:

"the reason you can trust the root DNS servers is because you can trust the people signing it. And, the reason you can trust the people signing it is because of the strict protocols they follow while doing so."


So the reason I can trust the root DNS servers, is because I can trust the people who signed them. And the reason I can trust these people is because they developed a rather theatrical and quasi-religious ceremony (their word, not mine) that says I can trust them? This is something akin to me presenting a driver's license as proof of my identity.

When I worked for the Navy lab at Dahlgren I was involved in standards, Fibre Channel and PKI. PKI was funny. These mathematicians from Entrust and Verisign would get up and scribble formulas all over huge whiteboards. Everybody would nod as if they understood, my math stopped at integral calculus so it was all Greek to me, (literally). Then they questions started and they all came down to one thing and it had nothing to do with the math, (thankfully). It was all about, why should we trust you? 

Think about it for a minute. It is a bit of smoke an mirrors, Entrust says, "It all starts with something called a root certificate. The root certificate is generated by a certification authority (CA) and is embedded into software applications. You will find root certificates in Microsoft Windows, Mozilla Firefox, Mac OS X, Adobe Reader, etc. The purpose of the root certificate is to establish a digital chain of trust. The root is the trust anchor."

Great, but why do we trust the root?

Update May 3, 2016 NewsBites carried a story:
--Threat Information Sharing Will Help Protect Critical Infrastructure
(April 29, 2016)
The Undersecretary of the US Department of Homeland Security's (DHS)
National Protection and Programs Directorate told an audience at a
conference in Washington, DC last week that cyberthreat information
sharing between private companies and government would help reduce cyber
risks to critical infrastructure. Suzanne Spaulding also said that
within organizations, cybersecurity should not be isolated within the
IT department, and that "it has to be part of that broader conversation
about functionality within those critical infrastructure sectors."
[Editor's Note (William Hugh Murray): DHS is learning at great expense what the
intelligence community would have told them for free:  trust is
essential for intelligence sharing; trust is fragile and does not scale.]

UPDATE: 6/7/16

Prof Nigel MacLennan points out that we tolerate, even expect a certain amount of duplicity. This is in a leadership context.

"Can a person lead if people do not trust them? It appears to be a simple question, but alas, the answer is not.

To illustrate, can you trust a politician to lie? Yes, you can count on it.

Even though we all accept that lying is part of politics, we still elect them to lead. Thus, sadly, it seems, that it is possible to lead without trust… in that context."