Posts

Showing posts with the label detection

Radiation Detection Mirrors Intrusion Detection

Image
Yesterday I heard part of the NPR story Auditors, DHS Disagree on Radiation Detectors . I found two Internet sources, namely DHS fudged test results, watchdog agency says and DHS 'Dry Run' Support Cited , and I looked at COMBATING NUCLEAR SMUGGLING: Additional Actions Needed to Ensure Adequate Testing of Next Generation Radiation Detection Equipment (.pdf), a GAO report. The report begins by explaining why it was written: The Department of Homeland Security’s (DHS) Domestic Nuclear Detection Office (DNDO) is responsible for addressing the threat of nuclear smuggling. Radiation detection portal monitors are key elements in our national defenses against such threats. DHS has sponsored testing to develop new monitors, known as advanced spectroscopic portal (ASP) monitors. In March 2006, GAO recommended that DNDO conduct a cost-benefit analysis to determine whether the new portal monitors were worth the additional cost . In June 2006, DNDO issued its analysis. In October 2006, ...

Experts: IDS is here to stay

Image
Imagine my surprise when I read Experts: IDS is here to stay : Conventional wisdom once had it that intrusion prevention systems (IPS) would eliminate the need for intrusion defense systems (IDS). But with threats getting worse by the day and IT pros needing every weapon they can find, the IDS is alive and well. "IPS threatened to hurt the IDS market but IDS is better equipped to inspect malware," said Chris Liebert, a security analyst with Boston-based Yankee Group Research Inc. "IPS specializes in blocking, so each still have their own uses, and that's why IDS is still around." IDS is now part of a larger intrusion defense arsenal that includes vulnerability management and access control technology. In fact, one analyst believes standalone IDS products will still be in demand five years from now while IPS technology will likely be folded in firewall products. "In the long term, I do not think IPS devices will remain as separate products," said Eric M...

No Undetectable Breaches

PaulM left an interesting comment on my post NORAD-Inspired Security Metrics : ...what if the enemy has a stealth plane that we cannot detect via radar, satellite, wind-speed variance, or any other deployed means? And what if your intel doesn't tell us that such a vehicle exists? Then we have potentially millions of airspace breaches every year and our outcome metrics are not helping. I'm not disagreeing with you that outcome metrics are ideally better data than compliance metrics. However, outcome metrics are difficult to identify and collect data on, and it can be difficult to discern how accurate your metrics actually are. At least with compliance metrics, we can determine how good we are at doing what it is we say that we do. It has little relevance to operational security, but it's easy and the auditors seem to like it. For the case of a single breach, or even several breaches, it may be possible for them to happen and be completely undetectable. However, I categoric...

Training an IDS

Image
Thanks to the newly named Threat Level I read Women at Love Field 'Acting Suspiciously' and Airport Watch Figure Confirms Terrorist Tie . You can obviously make up your own mind about these two, but I'm glad the police were alert enough to grab them. Here's a few choice quotes. I promise to tie this to digital security. "I'm a trained sniper and proud of it," Ms. Al-Homsi said in an interview Thursday after first refusing to comment on whether she has any terrorism ties. She then said no. Unless this is a lie, I doubt this lady received training in the US military. So where else would she be trained to be a sniper? She said that she practices her rifle skills at the Alpine Shooting Range in Fort Worth. An employee confirmed that she's been going there for years. "In all the Muslim garb, shooting an assault weapon, it seemed at first like she was trying to draw attention," said Dave Rodgers. " But then she came out so much, it bec...

Bro Basics Follow-Up

In my post Bro Basics I outlined the steps I took to install Bro . Since Friday I've taken a few more steps to get reports working. First, I re-ran make brolite-install as root. Next, I noticed errors in mail from bro: Date: Sat, 7 Apr 2007 00:10:01 -0400 (EDT) From: analyst@cel433.taosecurity.com (Cron Daemon) To: analyst@cel433.taosecurity.com Subject: Cron <analyst@cel433> ( nice -n 19 +/usr/local/bro-1.2.1/scripts/site-report.pl ) X-Cron-Env: <BROHOME=/usr/local/bro-1.2.1> X-Cron-Env: <SHELL=/bin/sh> X-Cron-Env: <HOME=/home/analyst> X-Cron-Env: <PATH=/usr/bin:/bin> X-Cron-Env: <LOGNAME=analyst> X-Cron-Env: <USER=analyst> Can't locate Bro/Config.pm in @INC (@INC contains: +/usr/local/bro/perl/lib/perl5/site_perl /usr/local/lib/perl5/5.8.8/BSDPAN +/usr/local/lib/perl5/site_perl/5.8.8/mach /usr/local/lib/perl5/site_perl/5.8.8 +/usr/local/lib/perl5/site_perl /usr/local/lib/perl5/5.8.8/mach +/usr/local/lib/perl5/5.8.8 .) at /usr...

Bro Basics

When I wrote The Tao of Network Security Monitoring I discussed Bro , another open source intrusion detection system frequently ignored by other authors (at least back when I wrote Tao ). I haven't used Bro in production but blogging by my friend Geek00l about Bro convinced me I needed to take a second look at Bro. In this post I'd like to document what I needed to do to get Bro running on a test sensor. I made a directory called /usr/local/bro-1.2.1 owned by user analyst. Then I acted as follows: cel433:/usr/local/src$ fetch ftp://bro-ids.org/bro-1.2.1-devel.tar.gz ...edited... cel433:/usr/local/src$ tar -xzvf bro-1.2.1-devel.tar.gz ...edited... cel433:/usr/local/src/bro-1.2.1$ which flex /usr/bin/flex cel433:/usr/local/src/bro-1.2.1$ which bison /usr/local/bin/bison cel433:/usr/local/src/bro-1.2.1$ ls -ald /usr/local/bro-1.2.1 drwxr-xr-x 2 analyst analyst 512 Apr 6 19:42 /usr/local/bro-1.2.1 cel433:/usr/local/src/bro-1.2.1$ ./configure --prefix=/usr/local/bro-1.2.1 ....

NSM and Intrusion Detection Differences

We had a good discussion this morning in the #snort-gui channel on irc.freenode.net. I was on my usual soap box complaining that no commercial tools provide all of the data I need to implement Network Security Monitoring, while developers and employees of a certain well-known intrusion detection system didn't understand why their product didn't meet my needs. Sguil author Bamm Visscher cut through the argument with a very astute summary. He basically said that IDS developers want "Immaculate Detection" while NSM practitioners want "Immaculate Collection." Bamm is exactly right. From my experience I know that no detection product is 100% accurate, and that even good alerts require investigation to see what is happening and what else might be happening. IDS developers are rightly trying to improve the quality of their products, but many people interpret their avoidance of NSM collection as a sign it isn't necessary. In other words, detection can ...

Intrusion Detection RFCs

It's been three years since I think I blogged on this topic, but I noticed three RFCs on intrusion detection were published this month: RFC 4765: The Intrusion Detection Message Exchange Format (IDMEF) RFC 4766: Intrusion Detection Message Exchange Requirements RFC 4767: The Intrusion Detection Exchange Protocol (IDXP) Is anyone using these? I think Prelude does, but how about commercial products?

Way to Go Joanna

Image
I briefly met Joanna Rutkowska at Black Hat Federal 2006 when she spoke about rootkits. Today I saw she was interviewed by Dark Reading and said the following: Still, she worries that security technology and research is too prevention-oriented and doesn't emphasize detection enough. "The whole industry is focusing on prevention, and we have all those anti-exploitation technologies, which are very helpful indeed. But I'm so surprised that no one cares about detection," she says. "Every time there's prevention, there is some bypass method" created. Without detection, there's no way to know if an attacker has grabbed administrative access to a machine, she says. And if you can't see that an attacker has infiltrated the system, nothing in that system will be "reliable" anymore. "The scary part is that once an attacker [gets] into the system, we can't reliably read system memory, neither using software-based, nor hardware-bas...

Why Prevention Can Never Completely Replace Detection

So-called intrusion prevention systems (IPS) are all the rage. Since the 2003 Gartner report declaring intrusion detection systems (IDS) dead, the IPS has been seen as the "natural evolution" of IDS technology. If you can detect an attack, goes a popular line of reasoning, why can't (or shouldn't) you stop it? Here are a few thoughts on this issue. People who make this argument assume that prevention is an activity with zero cost or down side. The reality is that the prevention action might just as easily stop legitimate traffic. Someone has to decide what level of interruption is acceptible. For many enterprises -- especially those where interruption equals lost revenue -- IPS is a non-starter. (Shoot, I've dealt with companies that tolerated known intrusions for years because they didn't want to "impact" the network!) If you're not allowed to interrupt traffic, what is the remaining course of action? The answer is inspection, followed ...

Pool IDS

Image
By now you've probably heard the story about the 10-year-old girl in Wales who was saved by the Poseidon computer-aided drowning detection system . According to the vendor: "[Poseidon] uses advanced computer vision technology to analyze activity in the pool, captured by a network of cameras mounted both above and below the surface of the pool. Poseidon helps lifeguards monitor swimmers' trajectories, and can alert them in seconds to a swimmer in trouble." While reading comments at Slashdot , several of them reminded me of the value of digital intrusion detection systems. This one by a Poseidon user is very helpful if you want to know more about how Poseidon works. For example, some critics complain about "false positives," meaning Poseidon sounds the alarm although no one is drowning. Poseidon alarms when a swimmer stops moving below the water for more than a few seconds. If the Poseidon programmers tell the device to alert when people appear to be ...

Comments on Network Anomaly Detection System Article

Image
I was asked to comment on Paul Proctor 's new article in the August 2005 Information Security magzine, titled A Safe Bet? . Paul is an analyst at Gartner now, but years ago he wrote an excellent book -- The Practical Intrusion Detection Handbook , which I reviewed five years ago. Paul's article introduces network anomaly detection systems, shorted by the wonderful acronym NADS. Paul describes NADS thus: "NADS are designed to analyze network traffic with data gathered from protocols like Cisco Systems's NetFlow, Juniper's cFlow or sources that support the sFlow standard. Data is correlated directly from packet analysis; and the systems use a combination of anomaly and signature detection to alert network and security managers of suspicious activity, and present a picture of network activity for analysis and response." I find Paul's opinions to be sound: "Despite vendor claims to the contrary, NAD is primarily an investigative technology. While it...

Credit Card Intrusion Detection

I just received a call from a computer at Citicards, the company that issued one of my credit cards. Twice in the past few years that card was stolen by credit card number thieves. I found the exchange with the computer interesting. First it announced that it was calling from the Citicards fraud department. Next it asked if I was "Richard Bejtlich," using the best pronounciation of my last name a computer could muster. (It's "bate-lik", by the way.) Then it asked me to verify the zip code of the billing address for the credit card. At this point I figured providing a zip code was a low-risk activity, in the event this was a sophisticated social engineering attempt. Once I "authenticated" via zip code, the computer asked if I had made a purchase of $6.37 yesterday at "fast food" something-or-other. I recognized this as the dinner I bought at the incredibly high-brow Chick-fil-A drive-thru window at 9 pm last night. I pressed "...

Will Compromises at Universities Aid Security Research?

Last year I reported my experiences attending the 2003 International Symposium on Recent Advances in Intrusion Detection , also known as RAID. Many briefers complained that their security research suffered due to lack of good data. For example, intrusion detection analysts usually relied on the 1999 DARPA Intrusion Detection Evaluation data . Data like this may be sanitized for analysis by researchers but it pales in comparison to watching live traffic from production networks. Several recent events may give security researchers the data they need. For example, UC Berekely suffered an intrusion on 1 Aug 04 which jeopardized a database containing names, addresses, telephone and Social Security numbers collected by the California Department of Social Services (CDSS). According to Carlos Ramos, assistant secretary at CDSS, the compromise "was discovered on Aug. 30 by Berkeley IT staff using intrusion detection software." I wonder if the IDS was Vern Paxson's Bro ,...

Improving Windows Baselining with Tlist.exe

Several people provided feedback on my Simple Post-Installation Baselines on Windows Blog entry. First, Beau Monday reminded me of his FirstOnScene incident response scripts. I haven't tried these out but you might want to see if they make life easier for your first responders. Second, Harlan Carvey pointed out the program tlist.exe shipped with the Debugging Tools for Windows . This is apparently not the same tlist.exe found on some Windows systems. You can obtain tlist.exe by downloading and installing the debugging tools, and then copying the tlist.exe binary elsewhere. I tested the independence of tlist.exe by running it on a system where no special debugging tools were installed, and where I did not have administrator privileges. Here is an excerpt of tlist.exe output. This tool is especially helpful because it shows the full path for executables. This allows you to differentiate between a 'svchost.exe' started from "C:\WINDOWS\system32" (whe...

Senator Kennedy No-Fly Watch List and IDS "False Positives"

Image
It struck me today that Senator Kennedy's no-fly watch list troubles are very similar to our digital security woes. Recently Kennedy said "he was stopped and questioned at airports on the East Coast five times in March because his name appeared on the government's secret 'no-fly' list." The Washington Post reported "a senior administration official, who spoke on condition he not be identified, said Kennedy was stopped because the name 'T. Kennedy' has been used as an alias by someone on the list of terrorist suspects." "T. Kennedy" reminds me of a content matching IDS rule. Is this a "false positive"? If you consider that airline personnel were making decisions based on the rules they were given -- stop anyone using the name "T. [Ted, in the senator's case] Kennedy," this is not a false positive. Perhaps with more context, like personal recognition that the individual at hand is one of the most famou...