Two days ago I gave the keynote at an industry event, reflecting on the changing
role of traditional security controls in the age of virtualization and the
cloud. As this was an updated version of the stuff distributed in the conference
proceedings, some people have asked for it. Voilà,
here we go.
At several occasions we’ve been asked to provide some background on the
Rapid Risk Assessment (RRA)
methodology we frequently use for a transparent (and documented) understanding
of risks in certain situations and to deliver structured input for subsequent
decision taking. As I had to write down (in another context) some notes on risk
assessments and – from our perspective – practical, reasonable ways of
performing them, I take the opportunity to lay out a bit the underlying ideas of
the RRA approach. Which, btw, is no rocket science at all. Honestly, I sometimes
wonder why stuff like this isn’t practiced everywhere, on a daily basis 😉
Once again, in some customer environment the question of allowing/prohibiting
split tunneling for (in this case: IPsec) VPN connections popped up today. Given
our strict stance when it comes to “fundamental architectural security
principles” the valued reader might easily imagine we’re no big fans of allowing
split tunneling (term abbreviated in the following by “ST”), as this usually
constitutes a severe violation of the “isolation principle”, further aggravated
by the fact that this (violation) takes place on a “trust boundary” (of
trusted/untrusted networks).
Still, we’re security practitioners (and not everybody has such a firm belief
in the value of “fundamental architectural security principles” as we have), so
we had to deal with the proponents’ arguments. In particular as one of them
mentioned additional costs (in case of disallowed ST forcing all 80K VPN users’
web browsing through some centralized corporate infrastructure) of US$
40,000,000.
[yes, you read that correctly: 40 million. I’ve still no idea where this – in
my perception: crazy – number comes from]. Anyhow, how to deal with this?
Internally we performed a
rapid risk assessment (RRA)
focused on two main threats, that were:
… which was, as in the years before, an awesome event.
Great talks, great people, great fun.
Bruce Potter gave a keynote
which did exactly what a good keynote should do: make the audience think and
entertain it at the same time.
[Those readers familiar with ERNW’s security model will certainly notice that
we do not necessarily agree with everything he said. We still think that – in
particular in times where infosec resources are scarce anyway – putting your
bets on prevention provides a better cost/[security] benefit ratio than going
for extensive detection capabilities.
Fix the doors first, then think about installing a CCTV.
Still, human nature tends to exchange “good security with low visibility” for
“poor security with potentially good visibility” quite easily… as can be noted
every day in many environments.]
Today we dare to (mis-) use the blog for a shameless self promotion 😉
We’re happy to announce that ERNW will contribute to a government sponsored
research project called ASMONIA (which stands for the
German title of the project that is Angriffsanalyse und Schutzkonzepte für
MObilfunkbasierte Netzinfrastrukturen unterstützt durch kooperativen
InformationsAustausch [Attack analysis and Security concepts for MObile
Network infrastructures, supported by collaborative Information exchAnge].
those readers familiar with that kind of projects will have an idea of the
importance of such acronyms ;-).
Just a short notice today on some recent presentations from our team. As some of
you might know we regularly give talks at conferences. This not only encompasses
highly sophisticated security events like Black Hat or
Troopers. Additionally – on our mission for a safer
world – we try to spread the (security) word at various industry events that are
usually focused on some aspect of the large and ramified IT world, not
necessarily equipped with a strong focus on information security.
A number of such events took place in the last few weeks and here’s some links
on presentations given there. While not being as technically deep as the average
Black Hat or Troopers attendee might expect, we still
hope that one or another valued reader finds them useful (pls note that some
parts are in German).
One of the four vulnerabilities rated “critical” from yesterday’s MS patchday,
that is
MS10-063,
has an interesting “Workarounds” section as for MS Internet Explorer. There it’s
stated:
“Disabling the support for the parsing of embedded fonts in Internet Explorer
prevents this application from being used as an attack vector.”
which, according to the advisory, should/can be done by setting the “Font
Downloading” parameter to “Disable”.
Which is exactly what
this document
suggests. So taking a preventive approach, once more, might have saved some
concerns (“Will we be targeted by this one”) and patch/testing time…
Recently I noticed
this news
titled “New email worm on the move”. At roughly the same time I received an
email from a senior security responsible from a large customer asking for
mitigation advice as they got “hit pretty hard” (by this exact piece of
malware).
Given I’m mainly an infrastructure and architecture guy usually I’m not too
involved in malware protection stuff (besides my continuous ranting that – from
an architectural point of view – endpoint based antivirus has a bad security
benefit vs. capex/opex ratio). So I’m by no means an expert in this field. Still
I keep scratching my head when I read the associated announcements (like
this,
this
or
this)
from major “antivirus”, “malware protection” or “endpoint security” vendors – to
save typing, in the remainder of the post I call them SNAKE vendors (where
“SNAKE” stands for “Smart Nimble APT Kombat Execution”… or sth equally ingenious
of the valued reader’s choice… 😉
This is currently the most frequent search term leading Internet users to the
Troopers website.
Probably Sheran Gunasekera’s great presentation “Bugs & Kisses – Spying on BlackBerry users for fun”
is the piece they are after. Whatever they look for, this search term may help
to shed light to an aspect that seems a bit overlooked in the ongoing debate
about governments (U.A.E., Saudi Arabia, India) trying to get their hands on
communication acts performed with BlackBerries in their countries.
[For those interested in that discussion
this blog entry of Bruce Schneier
may serve as a starting point.]
For those of you who missed it: Microsoft released the
associated advisory
yesterday, together with a hotfix
introducing a new registry key that allows users to control the DLL search path
algorithm. For a detailed explanation of the problem we refer to
the excellent article on Ars Technica.
For the record: no, AV (anti-virus software) will – in most cases – not protect
you from security problems related to this one. And, no, there is no easy patch
for this one either.