Posts

Showing posts with the label afcert

Twenty Years of Network Security Monitoring: From the AFCERT to Corelight

Image
I am really fired up to join Corelight. I’ve had to keep my involvement with the team a secret since officially starting on July 20th. Why was I so excited about this company? Let me step backwards to help explain my present situation, and forecast the future. Twenty years ago this month I joined the Air Force Computer Emergency Response Team (AFCERT) at then-Kelly Air Force Base, located in hot but lovely San Antonio, Texas. I was a brand new captain who thought he knew about computers and hacking based on experiences from my teenage years and more recent information operations and traditional intelligence work within the Air Intelligence Agency. I was desperate to join any part of the then-five-year-old Information Warfare Center (AFIWC) because I sensed it was the most exciting unit on “Security Hill.” I had misjudged my presumed level of “hacking” knowledge, but I was not mistaken about the exciting life of an AFCERT intrusion detector! I quickly learned the tenets of network...

A Brief History of Network Security Monitoring

Image
Last week I was pleased to deliver the keynote at the first Security Onion Conference in Augusta, GA, organized and hosted by Doug Burks. This was probably my favorite security event of the year, attended by many fans of Security Onion and the network security monitoring (NSM) community. Doug asked me to present the history of NSM. To convey some of the milestones in the development of this operational methodology, I developed these slides  (pdf). They are all images, screen captures, and the like, but I promised to post them. For example, the image at left is the first slide from a Webinar that Bamm Visscher and I delivered on 4 December 2002, where we presented the formal definition of NSM the first time. We defined network security monitoring as the collection, analysis, and escalation of indications and warnings to detect and respond to intrusions. You may recognize similarities with the intelligence cycle and John Boyd's Observe - Orient - Decide Act (OODA) loop. Tha...

Lessons from NETOPS vs CND

Image
Volume 13 Issue 2 of IATAC's IA Newsletter features an article titled Apples and Oranges: Operating and Defending the Global Information Grid by Dr Robert F Mills, Maj Michael Birdwell, and Maj Kevin Beeker. The article nicely argues for refocusing DoD's "NETOPS" and "CND" missions, where the former is defined currently as activities conducted to operate and defend the Global Information Grid and the latter is defined currently as actions taken to protect, monitor, analyze, detect, and respond to unauthorized activity within DoD information systems and computer networks. After spending years to "converge" the two missions, the authors argue DoD needs to separate them (as I understand the Air Force has done, bringing back the AFCERT for example). I'd like to present selected excerpts with my own emphasis. Cyberspace is a contested, warfighting domain, but we’re not really treating it as such, partly because our language and doctrine have not ...

Answers Regarding Military Service

Image
Once in a while I'm asking my Thoughts on Military Service . An anonynous blog reader sent the following questions. It's been a while since I wore the uniform, but at least some of you readers might care to offer your own thoughts? I'll try to answer what I can. I got into IT after graduating from college with non-technical majors and decided that I was actually interested in areas of practical science, such as: physical computing, engineering (mechanical, electrical, and design), robotics, aerospace, and programming. IT was a great primer for some practical work experience, but after my stint with [a security company] I'm evaluating if I want to acquire more direct technical training with the things I'm passionate about. So, here's my barrage of questions; please feel free to answer however you want, I'm simply organizing the thoughts rumbling around in my head. If I left anything relevant out, which I'm certain I did, then please mention it. 1) W...

Historical Video on AFCERT circa 2000

Image
I just uploaded a video that some readers might find entertaining. This video shows the United States Air Force Computer Emergency Response Team (AFCERT) in 2000. Kelly AFB, Security Hill, and Air Intelligence Agency appear. The colonel who leads the camera crew into room 215 is James Massaro, then commander of the Air Force Information Warfare Center. The old Web-based interface to the Automated Security Incident Measurement (ASIM) sensor is shown, along with a demo of the "TCP reset" capability to terminate TCP-based sessions. We have a classic quote about a "digital Pearl Harbor" from Winn Schwartau, "the nation's top information security analyst." Hilarious, although Winn nails the attribution and national leadership problems; note also the references to terrorists in this pre-9/11 video. "Stop the technology madness!" Incidentally, if the programs shown were "highly classified," they wouldn't be in this video! I was trave...

Review of Martin Libicki's Cyberdeterrence and Cyberwar

Image
Amazon.com just posted my three star review of Martin Libicki's Cyberdeterrence and Cyberwar . I've reproduced the review in its entirety here because I believe it is important to spread the word to any policy maker who might read this blog or be directed here. I've emphasized a few points for readability. As background, I am a former Air Force captain who led the intrusion detection operation in the AFCERT before applying those same skills to private industry, the government, and other sectors. I am currently responsible for detection and response at a Fortune 5 company and I train others with hands-on labs as a Black Hat instructor. I also earned a master's degree in public policy from Harvard after graduating from the Air Force Academy. Martin Libicki's Cyberdeterrence and Cyberwar (CAC) is a weighty discussion of the policy considerations of digital defense and attack. He is clearly conversant in non-cyber national security history and policy, and that knowl...

24th Air Force to be Headquartered at Lackland AFB

Image
Congratulations to Lackland AFB in San Antonio, Texas for being chosen to host the headquarters for 24th Air Force , a "cyber numbered Air Force." Lackland is home to the AF ISR Agency (previously AIA), the AF Information Operations Center (previously AFIWC), and the 33rd Network Warfare Squadron (previously the 33 IOS, and before that the AFCERT). It's been six years since I visited the place, but I think it's a great choice for the 24th. Richard Bejtlich is teaching new classes in Las Vegas in 2009. Regular Las Vegas registration ends 1 July.

Thoughts on Air Force Blocking Internet Access

Image
Last year I wrote This Network Is Maintained as a Weapon System , in response to a story on Air Force blocks of blogging sites. Yesterday I read Air Force Unplugs Bases' Internet Connections by Noah Shachtman: Recently, internet access was cut off at Maxwell Air Force Base in Alabama, because personnel at the facility "hadn't demonstrated — in our view at the headquarters — their capacity to manage their network in a way that didn't make everyone else vulnerable," [said] Air Force Chief of Staff Gen. Norton Schwartz. I absolutely love this. While in the AFCERT I marvelled at the Marine Corps' willingness to take the same actions when one of their sites did not take appropriate defensive actions. Let's briefly describe what needs to be in place for such an action to take place. Monitored. Those who wish to make a blocking decision must have some evidence to support their action. The network subject to cutoff must be monitored so that authoriti...

Proposed Air Force Cyber Badge

Image
The Air Force published New cyberspace career fields, training paths, badge proposed earlier this month. I found the proposed cyber badge to be interesting. From the story: The badge features: lightning bolts to signify the cyberspace domain; center bolts taken from the navigator badge and the Air Force Seal to signify cyberspace's worldwide power and reach and its common lineage and history of electronic warfare officers; and orbits to signify cyberspace's space-related mission elements. And, like other specialty badges, it will identify skill (certification) levels. Final approval and specifics of the wear criteria is under review at the air staff. For comparison I've posted the intelligence badge I used to wear. Wikipedia's Badges of the US Air Force is a nice reference. The Air Force also published a proposed Cyberspace Training Path for Operators and Specialists . Since we're talking military cyber operations, a blog reader asked for my opinion of the new...

Wireshark 1.0.0 Released

Image
I'd like to congratulate the Wireshark team for releasing Wireshark 1.0.0 . As the news item says, it's been nearly 10 years in the making. I started using Ethereal in 1999 at the AFCERT with data collected from our ASIM sensors. It's a great time for network security monitoring right now! With Sguil 0.7.0 released there's a lot of attention from high level players. It's cool.

Network Security Monitoring for Fraud, Waste, and Abuse

Image
Recently a blog reader asked the following: You frequently mention "fraud, waste, and abuse" in your writing ( for example ), most often to say that NSM is not intended to address FWA. One thing I've been wondering though--why is fraud in there? I can see waste (employee burning time/resources on ESPN.com or Google Video) or abuse (pornography, etc), but Fraud seems to be in a different class. If someone is using the network to commit a crime, why shouldn't that be in scope? Indeed, preventing loss (monetary, reputational, of intellectual property) is really the bottom line for a strong security program, correct? My stance on this question dates back to my days in the AFCERT. Let me explain by starting with some definitions from AFI90-301 (.pdf): Fraud: Any intentional deception designed to unlawfully deprive the Air Force of something of value or to secure from the Air Force for an individual a benefit, privilege, allowance, or consideration to which he or she is n...

Max Ray Butler in Trouble Again

Image
In my first book I wrote the following on p 170: WHO WROTE PRIVMSG? The author of Privmsg served one year in prison after pleading guilty in a U.S. District Court to a single count of computer intrusion. In May 1998 he compromised numerous government, military, and academic servers running BIND and installed back doors on those systems. He was caught thanks to skillful use of session data by analysts at the AFCERT and by Vern Paxson from Lawrence Berkeley Labs. See http://www.lbl.gov/Science-Articles/Archive/bro-cyber.html for more information on Paxson’s use of Bro and the “boastful and self-justifying” e-mail the intruder sent to Paxson. For details on the intruder, see Wired’s account at http://www.wired.com/news/culture/0,1284,54838,00.html . Kevin Poulsen’s story at http://www.securityfocus.com/news/203 has more details. The bottom line is it does not pay to infiltrate government machines -- especially Air Force servers or computers monitored by IDS researchers. I didn...

Goodbye AIA

Image
A friend from my AFCERT days left a comment indicating that the 33 IOS split into two different squadrons, the 33 NWS (the old AFCERT) and the 91 NWS. This prompted me to look at the organizational structure of my old Air Force units. I realized that last month what used to be Air Intelligence Agency is now Air Force Intelligence, Surveillance and Reconnaissance Agency , according to this story . AFISR now works as a field operating agency for AF/A2 , the Deputy Chief of Staff for Intelligence, Surveillance and Reconnaissance, Lt. Gen. David A. Deptula . AIA was part of 8th Air Force , but that experiment has been reversed. It looks like AFISR has lost information operations duties since it's now an "ISR" agency. According to Air Force ISR Agency , the AF/A2 says: "Air Intelligence Agency was traditionally focused on a particular intelligence discipline, signals intelligence," said General Koziol. "Now we are expanding our capabilities into geo-spatia...

Thanks for the Memories Sys Admin Magazine

David Bianco clued me in to the fact that, after 15 years, Sys Admin magazine is shutting down. (I was on the road this week and found the issue in my mail when I returned.) The August 2007 issue, pictured at left, is the last. Appropriately for the digital security community, the issue topic is Information Security. I bought my first issue of Sys Admin in the fall of 1999, at the point where I was finally coming to grips with my work at the AFCERT. I had spent the previous year-plus climbing the steep learning curve associated with becoming a network security analyst and I was ready to learn more about system administration. Looking at the copy in my hands, I see where I underlined (using a straight edge, a practice I continue to this day) content I believed was useful. That issue featured articles like: Maintaining Patch Levels with Open Source BSDs by Michael Lucas Landmining the Cracker's Playing Field by Amy Rich Hardening a Host by Dave D. Zwieback Intrusion Detect...

One Review, One Pre-Review

Image
Amazon.com just published my four-star review of Exploiting Software . From the review : I read Exploiting Software (ES) last year but realized I hadn't reviewed it yet. Having read other books by these authors, like McGraw's Software Security and Hoglund's Rootkits, I realized ES was not as good as those newer books. At the time ES was published (2004) it continued to define the software exploitation genre begun in Building Secure Software. However, I don't think it's necessary to pay close attention to ES when newer books by McGraw and Hoglund are now available. I'm looking forward to reading Network Warrior by Gary A. Donahue. This book has the second-best subtitle of all of the technical books on my shelves: Everything you need to know that wasn't on the CCNA exam I quickly skimmed this book at USENIX and I think it will be valuable. I like books that take nontraditional look at networking issues. If you're wondering what my favorite subtitle is...

Management by Fact: Flight Data Recorder for Windows

Whenever I fly I use the time to read ;login: magazine from USENIX . Chad Verbowksi 's article The Secret Lives of Computers Exposed: Flight Data Recorder for Windows in the April 2007 issue was fascinating. (Nonmembers can't access it until next year -- sorry.) Chad describes FDR: Flight Data Recorder (FDR) collects events with virtually no system impact, achieves 350:1 compression (0.7 bytes per event), and analyzes a machine day of events in 3 seconds (10 million events per second) without a database. How is this possible, you ask? It turns out that computers tend to do highly repetitive tasks, which means that our event logs (along with nearly all other logs from Web servers, mail servers, and application traces) consist of highly repetitive activities. This is a comforting fact, because if they were truly doing 28 million distinct things every day it would be impossible for us to manage them. Ok, that's cool by itself. However, the insights gained from these lo...

Network Security Monitoring History

Image
Recently a network forensics vendor was kind enough to spend some time on a WebEx-type session describing their product. I try to stay current with technology so I can offer suggestions to clients with budgets for commercial products. During the talk the presenter was very excited by his company's capability to collect all traffic and examine it later for troubleshooting and security purposes. He implied this was a "new capability in this space," so I asked if he had read any of my books. He said no, but he did read my blog. It occurred to me that it might be helpful to reprint the history of NSM I wrote for Tao of Network Security Monitoring . I'm doing this for three reasons. First, I want people to know that the ideas I've been publicly evangalizing since 2002 actually date back 10, perhaps 13 years earlier. I take credit for paying attention to smart people with whom I worked when I first started in this field. I don't take credit for inventing the...

Ubiquitous Monitoring on the Horizon

In January I wrote The Revolution Will Be Monitored . Today I read Careful, the Boss Is Watching : Recently, software vendor Ascentive LLC installed its new BeAware employee monitoring application on all the PCs at one of its new corporate clients. The corporation notified its employees that their Web surfing habits -- as well as their email, instant messaging, and application usage -- were now being monitored and recorded. "Internet usage at the corporation dropped by 90 percent almost overnight," recalls Adam Schran, CEO of Ascentive. "As soon as employees knew they were being monitored, they changed their behavior." Wow, what a bandwidth saver. Who needs to upgrade the T-3 when you actually take measures to enforce your stated security policy? The story continues: While tools for tracking employee network usage have been available for years, emerging products such as BeAware take monitoring to a whole new level. The new BeAware 6.7 lets managers track workers...

Air Force Cyberspace Command

According to Air Force Link , 8th Air Force will become the new Air Force Cyberspace Command. This appears to be the next step following the creation of a Air Force Network Operations Command structure in August. That came on the heels of the Air Force Information Warfare Center being redesignated as the Air Force Information Operations Center . That was a result of the Air Force Tactical Fighter Weapons Center being redesignated as the Air Force Warfare Center . In a related move, the former 67th Information Operations Wing is now the 67th Network Warfare Wing . Follow all that? It also appears the Air Force is centralizing control of network operations and security centers, according to this article : All Air Force network operations security centers, which were previously decentralized among the major commands, will consolidate under the 67th with the stand-up of two integrated network operations and security centers, or I-NOSCs, located at Langley AFB, Va., and at Peterson AF...

DoD CyberCrime Conference Wrap-Up

I attended two conferences last week. The first was the 2006 DoD Cybercrime Conference in Palm Harbor, FL. I spoke there in 2000 while still a captain at the AFCERT, and in 2005 as a civilian. This year I delivered presentations on network incident response and network forensics . I started the conference on Tuesday afternoon by listening to Alan Paller from SANS. His talk included a "hacking demo" showing a firewall compromised by an IMAP vulnerability, followed by a Red Hat 4.2 box allowing a direct root login with no password, thanks to an unspecified exploit. He also displayed a screen shots of rootshell.com, warforge.com, and NetBus 1.6. What do all of those items have in common? How about the fact that they all went out of style prior to 2000? In reality, I'm not sure which of the following worries me more: Seeing Alan present a demo where an OS from 1997 is 0wn3d. Seeing law enforcement, military, and government audience members taking notes as if somethi...