Posts

Showing posts with the label sans

The Value of Branding and Simplicity to Certifications

Image
At the risk of stirring the cyber pot (item 3, specifically) I wanted to post a response to a great mailing list thread I've been following. A reader asked about the value of the CISSP certification. Within the context of the mailing list, several responders cited their thoughts on SANS certifications. Many mentioned why the CISSP tends to be so popular. I'd like to share my thoughts here. In my opinion, the primary reason the CISSP is so successful is that it is easy to understand it , which facilitates marketing it. It is exceptionally easy for a recruiter to search LinkedIn profiles, other databases, or resumes for the term "CISSP." If you encounter a person with the CISSP, you basically know what the person had to do to get the certification. Before continuing, answer this quick question: what are the following? 1) SSCP, 2) CAP, 3) CSSLP? Let me guess -- you didn't recognize any of them, just like I did? Now, let me see if you recognize any of the fo...

Brief Thoughts on SANS WhatWorks Summit in Forensics and Incident Response 2010

Image
Last week I spoke at the third SANS WhatWorks Summit in Forensics and Incident Response in DC, organized and led by Rob Lee. As usual, Rob did a wonderful job bringing together interesting speakers and timely topics. I thought my presentation on "CIRT-level Response to Advanced Persistent Threat" went well and I enjoyed participating on the "APT Panel Discussion." I wanted to share a few thoughts from the event. This is just the sort of event I like to attend. It's almost more about the participants than the presentation content. I found plenty of peers interested in sharing leading practices. I hope to continue a relationship with several other CIRT leaders I met (or saw again) at SANS. Props to Kris Harms and Nick Harbour for starting their talk with a printed handout as reference for an in-class IR exercise , during a 1 hour talk! I kid you not. What a great way to make a point about the need for OpenIOC . Kevin Mandia called existing IR report wri...

Blocking Port 53 TCP

Image
I just read Experimental Storm Worm DNS Blocklist at SANS. The result of such a scheme looks something like this: richard@neely:~$ host basic1.threatstop.com ;; Truncated, retrying in TCP mode. basic1.threatstop.com has address 221.208.208.28 basic1.threatstop.com has address 221.208.208.27 basic1.threatstop.com has address 221.208.208.26 basic1.threatstop.com has address 221.208.208.25 basic1.threatstop.com has address 221.208.208.24 basic1.threatstop.com has address 221.208.208.23 basic1.threatstop.com has address 221.208.208.22 basic1.threatstop.com has address 221.208.208.21 basic1.threatstop.com has address 221.208.208.20 basic1.threatstop.com has address 221.208.208.19 basic1.threatstop.com has address 221.208.208.18 basic1.threatstop.com has address 221.208.208.17 basic1.threatstop.com has address 221.208.208.16 basic1.threatstop.com has address 221.208.208.15 basic1.threatstop.com has address 221.208.208.14 basic1.threatstop.com has address 221.208.208.13 basic1.threatstop.co...

Help SANS with Security Career Stories

The latest issue of the SANS @Risk (link will work shortly) newsletter contains this request: Project In Which You Might Contribute: Career models for information security. If you know of someone who has accomplished a lot in security by exploiting deep technical skills, and moved up in their organizations, please write is a little note about them to apaller [at] sans [dot] org. We have been asked by five different publications for articles or interviews on how to make a successful career in information security. A couple of the editors have heard that security folks with soft skills are no longer in demand and they want to hear about models of success for people with more technical backgrounds. No names or companies will be disclosed without written permission. If you can share a story, please email Alan Paller as indicated above. This is another opportunity for the technical people of the security world to make our mark.

SANS Software Security Institute

Today I attended a free three-plus-hour seminar offered by the new SANS Software Security Institute . This is part of SANS dedicated to software security. I recommend reading their press release (.pdf) for the full scoop, but basically SANS is introducing a Secure Programming Skills Assessement, additional training (eventually), and a certification path . Other people will summarize the program, so I'd like to share a few thoughts from the speakers at today's event. Michael Sutton from SPI Dynamics said that the idea of assembling a team of security people to address enterprise vulnerabilities worked (more or less) for network and infrastructure security because the team could (more or less) introduce elements or alter the environment sufficiently to improve their security posture. The same approach is not working and will not work for application security because addressing the problem requires altering code. Because code is owned by developers, the security team can...

Nail in the TCP Options Coffin

Image
I just listened to the relevant part of a recent SANS Webcast that mentioned my response to their conspiracy theory on SYN ACK and other packets with weird TCP options. At first all I wanted to do with this post was link to Michal Zalewski's Museum of Broken Packets and say that SANS ISC is wasting time on a non-issue. Then I started reading some of the MOBP entries. I nearly fell out of my chair when I read this. Exhibit 7: DoS tool changes into DoS exploit Internet Protocol Version: 4 Header length: 20 bytes Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00) Total Length: 48 Identification: 0x6fbb Flags: 0x04 (DF) Fragment offset: 0 Time to live: 127 Protocol: TCP (0x06) Header checksum: 0x63b6 (correct) Source: 64.190.25.48 (64.190.25.48) Destination: XXX.XXX.XXX.XXX (XXX.XXX.XXX.XXX) Transmission Control Protocol, Src Port: 1113 (1113), Dst Port: 490 (490), Seq: 269484601, Ack: 0 Source port: 1113 (1113) Destination port: 490 (490) Sequence number: 26...

Bejtlich Teaching at SANSFIRE 2007

I'll be teaching a special one-day course, Enterprise Network Instrumentation , at SANSFIRE 2007 in Washington, DC on 25 July 2007. ENI is a one-day course designed to teach all methods of network traffic access. If you have a network you need to monitor, ENI will teach you what equipment is available (hubs, switch SPAN ports, taps, bypass switches, matrix switches, and so on) and how to use it effectively. Everyone else assumes network instrumentation is a given. ENI teaches the reality and provides practical solutions. Please register while there are still seats available. Thank you.

Nothing to See Here

Recently I noticed a posting at the SANS Internet Storm Center titled Deformed TCP Options - Got Packets? The story featured packets like the following: 07:11:45.781421 IP (tos 0x0, ttl 113, id 9433, offset 0, flags [DF], proto: TCP (6), length: 48) 129.250.128.21.1256 > www.xxx.yyy.zzz.1229: S, cksum 0x5ed4 (correct), 2627126762:2627126762(0) ack 257795 6091 win 1460 0x0000: 4500 0030 24d9 4000 7106 4944 81fa 8015 E..0$.@.q.ID.... 0x0010: wwxx XXYY 04e8 04cd 9c96 c5ea 99a8 7cfb ...{..........|. 0x0020: 7012 05b4 5ed4 0000 0204 05b4 0102 0403 p...^........... 07:11:51.517325 IP (tos 0x0, ttl 113, id 21659, offset 0, flags [DF], proto: TCP (6), length: 48) 129.250.128.21.1252 > www.xxx.yyy.zzz.1070: S, cksum 0xa40c (correct), 1381904945:1381904945(0) ack 2301854615 win 1460 0x0000: 4500 0030 549b 4000 7106 764c 81fa 8015 E..0T.@.q.vL.... 0x0010: wwxx XXYY 04e4 042e 525e 3231 8933 8397 ........R^21.3.. 0x0020: 7012 05b4 a40c 0000 0204 05b4 0102 0403 p............... In Eng...

Certified Malware Removal Expert

I read the following in the latest SANS NewsBites (link will work shortly): Does anyone on your staff do an excellent job of cleaning out PCs that have been infected by spyware and other malicious software. We are just starting development of a new certification (and related training) for Certified Malware Removal Experts and we are looking for a council of 30 people who have done a lot of it to help vet the skills an dknowledge required for the certification exam and classes. Email cmre@sans.org if you have a lot of experience. This must be the easiest SANS certification of all! The safest way to remove malware is to reinstall from trusted original media (not backups which could be compromised). That doesn't even account for BIOS or other hardware rootkits, but hardly anyone cares about that problem yet. Hopefully SANS will come to the same conclusion that Microsoft already did and drop this idea.

Further Thoughts on SANS Top 20

It seems my earlier post Comments on SANS Top 20 struck a few nerves, e.g. this one and others. One comment I'm hearing is that the latest Top 20 isn't "just opinion." Let's blast that idea out of the water. Sorry if my "cranky hat" is on and I sound like Marcus Ranum today, but Marcus would probably agree with me. First, I had no idea the latest "Top 20" was going to be called the "SANS Top-20 Internet Security Attack Targets" until I saw it posted on the Web. If that isn't a sign that the entire process was arbitrary, I don't know what is. How can anyone decide what to include in a document if the focus of the document isn't determined until the end? Second, I love this comment: Worse still, Richard misses the forest completely when he says that “… it’s called an ‘attack targets’ document, since there’s nothing inherently ‘vulnerable’ about …”. It doesn’t really matter if it’s a weakness, action item, vulnerabilit...

Comments on SANS Top 20

You may have seen that the latest SANS Top 20 was released yesterday. You may also notice I am listed as one of several dozen "experts" (cough) who "helped create" the list. Based on last year's list , I thought I might join the development process for the latest Top 20. Maybe instead of complaining once the list was published, I could try to influence the process from inside? First let me say that project lead Rohit Dhamankar did a good job considering the nature of the task. He even made a last-minute effort to solicit my feedback, and some of my comments altered the categories you now see in the Top 20. I thank him for that. As far as the nature of the list goes, it's important to realize that it's based on a bunch of people's opinions. There is no analysis of past vulnerability trends or conclusions based on real data, like the Vulnerability Type Distribution I mentioned earlier . At the point where I realized people were just going to w...

SANS Network IPS Testing Webcast

I'm listening to a SANS Webcast on Trustworthy IPS Testing and Certification . Jack Walsh from the Network Intrusion Prevention section of ICSA Labs spoke for about 45 minutes on his testing system. Jack spent a decent amount of time discussing the Network IPS Corporate Certification Testing Criteria (.pdf) and vulnerabilities set (.xls). The vulnerabilities set was just updated a week ago, after being criticized in July. At present only three products are ICSA Labs certified, according to the ICSA Web site and this press release . ICSA Lab certification is a pass/fail endeavor; there are no grades. ICSA does not release the name of the companies whose products fail. Looking at the members of the NIPS Product Developers Consortium , you can make some guesses about who participated. Vendors pay for testing. They do so by paying for a year-long testing period, during which time they will receive at least one "full battery" of testing. Tests are rerun when the ...

Thoughts on Latest SANS Whitepaper

I read about the new SANS paper IT Security Industry Changes: Trouble on the Horizon (September 2006) (.pdf) in this NewsBites issue. Here are some excerpts and my reactions. Over the past six months, SANS Technology Institute's Stephen Northcutt has been gathering data and stories from security managers in more than 100 US organizations searching for patterns in job changes of security managers and the consultants who support them. The research was triggered by multiple emails from security managers who were facing reorganizations. His conclusions, albeit preliminary, paint a worrisome picture of job prospects for ill-equipped security managers, but also offer promise of some opportunities for success and advancement. That's an interesting project. Let's read more. [S]enior executives began to feel more comfortable voicing their frustration that they were wasting money paying for hugely expensive people and compliance reports that probably were not needed and that ofte...

Bejtlich Returns for SANS CDI East 2006

It's been three years since I spoke at at SANS conference; I last presented at SANS NIAL in 2003. After some friendly discussions with SANS staff at the recent SANS Log Management Summit , we've arranged for me to present a special event for SANS Cyber Defense Initiative East -- a two evening course called Enterprise Network Instrumentation (ENI). I developed ENI for a private client, but no public class has ever seen the material. I will be presenting ENI for two evenings, 14 and 15 December, 2006, from 6 to 9 pm at the Hilton Washington & Towers in Washington, DC. ENI is all about solving the difficult problems associated with gaining access to network traffic. It seems every book (with a few exceptions ) assumes it's easy to deploy sensors to observe packets. In reality, achieving visibility in modern networks can be extremely difficult. ENI will share recommendations and concrete solutions for the most taxing enterprise network instrumentation issues seen...

Upcoming SANS Webcast on SCADA Attacks

If you don't have one of the ten billion email addresses registered with SANS , you might not have heard of their upcoming Cyber Attacks Against SCADA and Control Systems Webcast . I didn't have to register for the event since my SANS login works. I plan to be listening on 7 Sep though. I'm interested to see what SCADA guru Dale Peterson has to say about this.

The Old Man Still Has It

Last week you may have seen this Packet Analysis Challenge posted by at the SANS Internet Storm Center . I downloaded the trace and looked at it using Tcpdump. After about five minutes I recognized the pattern as one I wrote about in late 1999 and presented that paper at SANS 2000. I submitted a link to my paper as an explanation, and Lorna wrote back Yes, this traffic falls into the category of the one you discuss in "A Final Case". The traffic I posted was sumitted to us by a university. You are the first person to get this right! Nicely done! I also wrote about this patten in the DNS chapter in The Tao of Network Security Monitoring . If you want to read SANS' explanation of the trace, please read today's solution .

SANS Log Management Summit

Last week I paid for and attended the SANS Log Management Summit . I'd like to share a few thoughts about what I saw. First, I think Alan Paller did a great job as host. He kept the presentations moving and unflinchingly kept to his schedule. Talks started at 8 am, period. I thought his "yellow card" system for questions worked very well. (If you wanted to ask a question, you wrote it on a yellow card. SANS staff collected the cards then handed them to the speaker or Alan, who answered the question.) The system prevented the "speeches" one usually sees in large crowds with open microphones. Alan started the conference by presenting his "faces of cybercrime" presentation, based on his testimony ( .pdf ) in late 2005. He reminded the audience of the advice to learn hacking given by soon-to-be-executed Bali bomber Imam Samudra . Alan claimed at least one organized crime group has moved two hackers to Africa and forced them to compromise targets...

Comments on SANS CDX Briefing

One of the benefits of paying for this week's SANS Log Management Summit was attending a briefing last week on the latest Cyber Defense Exercise conducted by the NSA . SANS organized a panel with a USAFA cadet, a USNA midshipman, a USMA-grad Army 2LT, and several NSA or ex-NSA representatives, along with their boss, Tony Sager. Although I've known of CDX for several years , this was my first real insight to how these exercises are conducted. The NSA organizer, or "white cell leader," is Bruce Rogers. He explained that competitions can be conducted either as capture-the-flag style events or purely defensive affairs. CDX is purely defensive. When I asked Mr. Rogers if he had spoken to any organizers of other cyber competitions, like those of Def Con or ShmooCon, he said no. Mr. Rogers has 20 white controllers overseeing the exercise, which includes 6 targets (the six defending teams -- USAFA, USNA, USMA, USMMA, AFIT, and NPS). The attackers are split into two gr...

Holy Cow, I'm Going to SANS

I just signed up to attend the SANS Log Management Summit , 12-14 July 2006 in Washington, DC. I think this is a great opportunity to hear some real users and experts talk about log management. Given that it's located near me, I decided I could afford to pay my own way to this conference. Is anyone else attending? If yes, register by tomorrow for the cheapest rates.

Notes from Airplane Reading

Image
Last week I read several magazines on the way to DoD Cybercrime. Here are a few thoughts on what I read. From the threat and vulnerability definition department, we have the article DHS offers $765M in risk-based grants from Federal Computer Weekly : The Homeland Security Department has made $765 million available in fiscal 2006 for 35 urban areas to guard against terrorist threats, DHS Secretary Michael Chertoff announced today. The Urban Areas Security Initiative (UASI) this year follows a new, risk-based formula that allots funding according to threat, vulnerability and consequence, Chertoff said... In assigning the grants, DHS also for the first time used threat analysis from the intelligence community to look at different kinds of threats, such as transient populations, Chertoff said. Replace the word "consequence" with "cost of replacement" in the second paragraph and you have the common risk equation found in my books and elsewhere. Nice reporting, Michae...