Wednesday, May 21, 2008

Security Metaphors: The Good, The Bad, and the Ugly

Security analysts try to explain security concepts via metaphors on a daily basis - putting our technical language into a more approachable form is part of the job. Sometimes we manage to do a great job, and our audience picks up the idea easily. At other times, we either confuse them, or worse, we create more issues than our metaphor was intended to solve.

"But, why doesn't the security guard hear the burglar?" "Well, hackers don't make noise when they're breaking in and..."

Many security metaphors are overused, or are poor representations of the actual concept. How often do you see a lock used as a security metaphor? Security - particularly IT security, is rarely conceptually equivalent to a lock, yet almost every security program uses a lock as a visual metaphor. Some even use an unlocked lock. Should we be concerned that we are subliminally suggesting that security isn't there to our audience?

Another over used comparison is one that Anton Chuvakin complained about last year: our overuse of the castle metaphor. His points are very valid - we're not building castles, and we need to explain what we're doing more carefully. Defense in depth is relatively easy to explain - but how do you explain more complex concepts effectively? Often, we attempt to come up with a spur of the moment comparison, and sometimes we fail. In at least a few circumstances, this habit has become a running joke in organizations I've worked with.

The habit of creating spur of the moment metaphor can be ugly. Metaphors can fail quite horribly, as shown by this recent example quoting a police officer talking about fake checks and check fraud in an article in the South Bend Tribune:
"Fake checks are like that chainsaw.

"There’s always got to be that one guy that says, "I don’t hear the chainsaw, I don’t feel the chainsaw,’" he said. "Trust me, it’s there. Don’t open that door."

When you do, you’re putting others at risk.

"You’re allowing (a) whole bank to be susceptible," Zultanski said. "And our whole banking industry."
So what is your favorite security metaphor? Have you seen any huge successes, or any huge failures?

Creative Commons licensed Flickr credit to: AMagill

Reminder: Your Third Part Certificates May Need Replaced

If you have certificates issued from one of the major Certificate Authorities, you may have received an email as a follow-up to the ongoing issue with Debian and Ubuntu OpenSSL certificate generation.

Per Verisign's letter:

If you are running Debian operating systems and derivatives (such as Ubuntu) released between September 17, 2006 and May 12, 2008 you should deploy a recently replaced Debian patch and revoke and replace all SSL and Code Signing certificates for which the keys were created on these operating systems.
It looks like Thawte and Verisign are replacing certificates at no charge - and Comodo is using it as an opportunity to attract more customers by offering to replace other's certificates free of charge.

Tuesday, May 20, 2008

Twenty Encryption Devices In Pictures

Oobject has a great pictorial collection of twenty encryption devices - everything from an Enigma machine to a wheel cipher. Well worth a look if you're a cryptography fan.

If you're interested in crypto machines, you can build an electronic Enigma machine, or you can go the paper Enigma route.

Friday, May 9, 2008

Acceptable False Positive Rates: Sky Marshalls on the No Fly list?

Bruce Schneier linked to a Washington Times article about Sky Marshalls whose names match names on the No Fly list. The first thing that came to mind for me was "Well, what is the acceptable false positive rate?".

The system currently primarily causes issues for individuals, rather than groups. When you take a Sky Marshall off of a plane, one would tend to believe that you increase the risk to the entire plane - they're there as another layer of security. Most security analysts would first get a good chuckle, then start worrying if they found out that their security system was actually stripping away a different layer.

What happens when we get pilots on the No Fly list?

Tuesday, April 29, 2008

Secure Computing announces VM based security gateway devices

Secure Computing, who recently renamed their Sidewinder line of firewalls as Secure Firewalls has announced that they will be making their security gateway appliances available as VMs - something I've been waiting for vendors to start doing for a while. In Secure's case, this makes even more sense, as their hardware has historically been relatively standard server hardware with a highly customized and hardened base OS.

From the release:

Through its relationship with VMware, all of Secure Computing's security gateway appliances can be deployed as preconfigured virtual appliances onto new or existing hardware without the cost and space required of traditional security implementations. Customers can deploy different Secure Computing appliances, each on its own virtual machine, on a single server.
This also allows competition with products like Cisco's FWSM and other vendors' products that support in-device virtual firewalls.
For example, customers or managed service providers can deploy up to 32 separate firewalls, each running on its own virtual machine on a single server, and manage all of them from a single point.
It will be interesting to see how quickly other vendors match this announcement - virtual datacenters in a few hosts using virtual switches, virtual appliances, and VM servers are just around the corner.

Wednesday, April 16, 2008

A FIPS certified thumbdrive: Kingston's Blackbox drives

Electronista reports that Kingston has announced FIPS certified thumbdrives in 2, 4, and 8 GB capacities. Specifications include 256 bit AES, 20 MB/s write, and 24 MB/s read speeds. More details are available on Kingston's Blackbox page.

Monday, April 14, 2008

Panda: Boot Sector Viruses Set For A Comeback?

Ars Technica recently covered Panda's malware report for Q1 2008 - and they note that Panda makes a surprising prediction that boot sector viruses will become more popular again.

Panda's list is interesting - they mention mobile phone and device viruses, a market which has had AV solutions for quite a while, but which hasn't seen a real widespread threat. They also cover the Storm worm, which has been one of the most visible and largest of the recent widespread viruses. Then, surprising to both myself and the Ars Technica writing staff, they spend quite a few pages covering boot sector viruses.

Many newer IT workers likely haven't dealt with boot sector viruses - they haven't been a serious mainstream threat in almost a decade. We're used to seeing worms, and email borne viruses, and even those haven't been a major threat to most organizations since company wide AV, mail server malware filtering, and firewalling became common.

Will we see boot sector viruses make a comeback? My feeling is that it won't make a significant comeback in most organizations. Social networks, browser exploits, and social engineering seem likely to remain our highest threats, as widespread AV use and better network layer protections are making user interaction a more common requirement for the spread of malware. I also expect to see more viruses spread by removable devices and via wireless, both 802.11 and Bluetooth.