Thursday, May 3, 2007

The importance of secondary routes

Network World is reporting that a fire caused when a homeless man threw a lit cigarette onto a mattress under a bridge has taken down Internet2 access between Boston and New York.

Yes. A burning mattress took down an important link for a major high speed network. No, this probably wasn't specifically covered in their design and operations risk assessment.

While high speed networks are expensive, this does demonstrate the vulnerability that purpose built dedicated links suffer from. If you only have one link, either because of cost or because of specialization, you need to have plans in place for when it goes down. Copper and fiber aren't invulnerable, and even when you think you're safe you can still get hit. Just when you think it is safe to cross your physical paths, someone will go dig there with a backhoe and cut your fiber.

Two stories come to my mind in which relatively unlikely events threatened or took down Internet access.

In the first, a semi hauling a backhoe went underneath a bridge that was lower than the backhoe's retracted and stored arm. The high speed impact with the bridge severed the fiber running underneath it, cutting off Internet access to a large chunk of Michigan.

In the second, a crew working on a a sewer line hit a gas line. In the process of attempting to fix the gas line, they dug and hit a fiber conduit. Fortunately, the slack in the fiber allowed it to pull just enough to remain operational, but a series of unfortunate events might have resulted in loss of Internet access for a major institution - in addition to a pretty nightmarish repair scenario with fiber and gas lines both broken.

Lessons learned? Always ask about single points of failure, identify alternate routes if possible and financially reasonable, and make sure you have an outage handling and recovery plan.

Phishes and loathes...

This post by Pascal Meunier over at CERIAS is well worth reading if you use a Visa credit card to make purchases online and the vendor uses the "Verified by Visa" program. The basic problem is that Visa's program presents itself like more of a phishing attempt than a legitimate fraud prevention tool. Worse than that, I think, is the fundamental implementation problems that Pascal notes in the update at the bottom of the article. Does anyone even test this stuff?

Update:
On the subject of phishing, it seems that banks and credit card companies still don't get it. I can find countless examples of unexpected emails from my banks that, from what I can tell are completely legitimate, but are full of "click here" and "login" links - the kinds that train the not-so-careful users to fall for phishing attacks in the first place. Maybe it's time I jumped on the ASCII ribbon campaign..

Tuesday, May 1, 2007

Erasing drives: This drive will self destruct in 1...2...3...

Drive wiping techniques are a frequent point of discussion in the information security community. Most IT staffers know about DBAN and there are plenty of both freeware and commercial tools out there.

If you need something different - either because the drive isn't in a system, or you want to centralize it, there are dedicated drive wiping systems like Ensconce's Digital Shredder . On the other end of the drive wiping spectrum are degaussers like these which are great for wiping drives that are no longer working, but still contain data, or for drives that you don't have interfaces for for your wiping system.

Yes, sometimes somebody shows up with a pile of Fiber Channel drives, or a Bernoulli disk, or some other for of media that you don't have a handy USB adapter for.

You can also have your drives physically destroyed - shredding and destruction companies will do this and will provide a receipt to demonstrate that they've been properly destroyed.

And then there's the drive that Ensconce Data Technology is promising. Sign me up for a self destructing hard drive!

How do you choose what is appropriate for your organization? As always, ask questions.

  1. Do you have to follow any legal or statutory requirements? If so, make sure your strategy satisfies them.
  2. Do you have internal policy requirements? If not, why don't you?
  3. What are the security requirements of your data? Check your data handling guidelines.
  4. What would exposed data cost your organization? Data recovery tools are available, and are easy enough to use that even those without significant technical knowledge can recover data from a drive if it hasn't been securely wiped.
With these answers in hand, you should be able to create policy - if you don't already have it, then create procedures and select appropriate technologies to support them.

Sunday, April 29, 2007

High value higher ed and compromise profiles

Dave G from Matasano Chargen posted about "Mac Punditry and the Office Paradox". My higher ed focused ears perked up when he asked "How are educational environments high value targets?".

Higher ed security folks know that we're major targets - and attractive targets too. Here's why:

  1. Open networks - large public IP spaces, often with relatively loose border controls.
  2. Open systems - frequently systems are not centrally supported, and there can be a wide separation between system security postures across the network.
  3. High bandwidth - universities have bandwidth that many commercial entities and ISPs would be jealous of. Internet 2 connections are typically at least a gigabit, and some universities connect to things like the TeraGrid's 10 - 40 gig research backbone or other specialized high speed networks.
  4. High value data - Social Security numbers, research data, personal data on students, faculty, staff, and donors, and credit card operations are all on the list for most higher ed institutions.
Historically, educational institutions have had relatively open borders. This has changed over the past few years with universities implementing border firewalls and other protections. Universities are still in a somewhat unique position - many have residential networks that act as ISPs for their students and have standards for academic and research freedoms that make a corporate style security architecture difficult, if not impossible.

Watching vendors and other security professionals react to statements along the lines of "well, no, we can't presume that it will be firewall protected" or "we have a class B, and everything we own is on a public IP" can be fun if you enjoy looks of sheer terror.

With attractive and relatively exposed systems - and a population that is often less formally controlled than those in the corporate world (at least in similarly sized institutions), compromises will occur. What do they look like?

Higher education security staff tend to see three attack profiles on systems - and I think that these three attack profiles show the three types of value that compromised systems have for attackers. They are:

1. Zombies - low value systems with no real useful data, smaller hard drives, and low to middling bandwidth. Often these are student machines on residential networks, or standard employee desktops. These systems tend to participate in botnets, and are valuable simply because of numbers and the fact that many are either not detected, or are not cleaned up properly if they are.

2. Storage and bandwidth - these systems are characterized by larger hard drives and bigger pipes. Universities often have relatively large pipes, either thanks to an Internet2 link, a research network link, or simply large commodity Internet upstream connections. Systems that are compromised by an attacker who actually cares about system profiles and that do have bigger drives or more bandwidth continue to be used as storage and distribution points.

3. Jumping off points - every organization has hosts that have sensitive data or that can be used to move through other systems. Your local IT support staff machines are a great jumping off point, and so is a dean's machine, or a business office system. Normally, you will want to focus your forensic efforts on these systems, as they are more likely to have sensitive data - or the keys to the kingdom. A single critical IT worker's machine can let attacks romp through your infrastructure. Most hacks of these machines tend to be detected via system monitoring software - AV and anti-spyware, via user notification, or via one of the methods above.

So how do you deal with these compromise profiles? Your detection and response tactics will likely vary due to your level of control and access.

Zombies can often be found by by monitoring outbound IRC connections or by using netflows and other monitoring technologies to keep track of known bad hosts on the outside. Most normal systems on campus won't be talking to your friendly neighborhood C&C. Since these systems are often outside of the normal support infrastructure for business or academic computing organizations, you have to work with your residential network support or enforce your AUP (you do have an acceptable use policy, don't you?)

Storage and bandwidth oriented hacks may not be reporting into a central C&C - although more and more do dial home. Use your border flows to check for hosts that have very high bandwidth usage - a good tactic is to check your top 10 or top 20 hosts on a daily basis, then filter out the known good hosts, check into the rest, rinse, and repeat. Yes, that public FTP mirror will be high, but why is a grad student's desktop machine in the top 10 for outbound traffic?

Jumping off points are the security analyst's bad day - follow your IR procedures, and make sure you understand what the system had on it, and what access the people who used the system have to other resources. The chain can be long, but following it can help ensure that further compromises don't occur.

The final analysis - at least from my perspective is that higher ed does have high value hosts. Educational institutions cover the spectrum of sensitive data from research data to SSNs and credit card data. In addition, most are highly concerned about their image, meaning that a data breach can cause significant damage to reputation, even if financial losses are smaller.

Where does that leave us? I'll write more about some of the directions that universities are moving in to handle both intrusion and extrusion detection in a coming post.

Thursday, April 26, 2007

What's old is new again: email extortion and urban legends

Much like fashion, the Internet makes old things new again at a startling pace. Dark Reading is carrying an article courtesy of Information Week about a "new" email scam - assassins have been hired to kill you, and if you bribe them, they won't. Unfortunately...this isn't really a new scam. In fact, Snopes has references back to 2006, and an FBI recommendation from December of 2006 - which the article does note. What is newer is that the mailing lists harvested for it seem to target professionals. Not quite spearphishing, but definitely more targeted than your daily allotment of prescription drug and enhancement spam.

Moral of the story? Keep Snopes, ScamBusters, and the CIAC's Hoaxbusters sites handy, and don't panic. If you do know somebody who has succumbed to the scam, point them to law enforcement and the Internet Crime Complaint Center (IC3).

Wednesday, April 25, 2007

If you're still shopping here, do you mind if we lose your data again?

There's a post at Emergent Chaos about how many customers you may lose if you lose their data more than once. I recently asked if you would still shop at a company that lost your data. These statistics are interesting, as they show that at least in some populations, there is a direct churn rate effect from repeated data loss. The question remains: what about institutions that you're not a customer of, but instead belong to a population that they service.

How is that different? Well, there are organizations like universities and the VA that will retain records on you long after your a bank, credit card company, or other institution would have hopefully destroyed your data. You will always be a graduate of your alma mater, and you will always be a veteran - and they will retain your data. Another group that we have little choice in dealing with is credit monitoring and reporting agencies - a breach of one of the major agencies could have serious repercussions. We've already seen third party processors announce compromises.

How can you protect yourself in this case? The responsibility lies with the data holder, and that is what should concern us - in some of these cases, there is no motivation to retain customers, we have no way to remove our data from their databases, and in many cases, there are few penalties for losing data that isn't protected via legislation. We may at least hear about it thanks to legislation that requires reporting- and that's a start.

Tuesday, April 24, 2007

Security deals: Free for life PKWare SecureZIP for Windows

PKWare has SecureZIP available as a free for life download. SC Magazine reviewed it, and seemed to like it. It looks worth checking out if you're looking for something that integrates into Outlook and other software for free.