Posts

Showing posts with the label verizon

Verizon Incident Sharing Framework

Image
Earlier this month Verizon Business announced their Verizon Incident Sharing Framework (VerIS framework). This document is a means to describe digital security incidents, using four main groupings: 1. Demographics, 2. Incident Classification, 3. Discovery and Mitigation, and 4. Impact Classification. The idea is to provide a framework that incident investigators can complete for every digital security incident. Using the output, security teams can better identify trends and make recommend improved security strategies and tactics. For example, Verizon builds their Data Breach Investigation Report using data from their incident responses as formatted using the VerIS framework. Verizon asked me to participate on a "board" affiliated with this project, so you can expect to hear more from me. Verizon started a Zoho Forum to discuss the framework, but I think a Wiki would better facilitate collaboration and development of the document. At work we are working on our next ge...

Must-Read Verizon Post Demolishes More Myths

Image
I'm a big fan of the 2009 Verizon Data Breach Report . Today I read Compromised Assets & Data: But our company doesn’t handle credit cards... by Verizon's Bryan Sartin. It's an excellent post. I'd like to post several excerpts, emphasizing and expanding on certain points. I find it fascinating that no matter where in the world you go, what type of company you talk to, public or private sector, you find two very common beliefs: 1. All data stolen in security breach is a result of lost assets, not systems-related intrusions. 2. I don’t handle payment cards (credit or debit) - so this stuff does not apply to me. If you could only understand how outrageous these sound from the standpoint of the computer forensic investigator. Both thought processes couldn’t be more wrong. I hear these refrains as well, or at least I see the effects of devoting resources to other projects. Bryan continues: Pretty much everyone I speak to firmly believes that in the real worl...

Highlights from 2009 Verizon Data Breach Report

Image
Last year I posted Verizon Business Report Speaks Volumes , providing excerpts that resonated with me. Verizon released another edition last month, with plenty of commentary on their blog and elsewhere. I wanted to record a few highlights here for my own reference but also to counter arguments I continue to see elsewhere about the so-called prevalence of insider threats. This is a polite way of trying to demolish the most deeply entrenched urban myth in security history. This shows the 2009 results. This is an historical way to look at breach source data. The following chart is the one that insider threat proponents will try to use to justify their position. It shows that, on average, a breach caused by a single insider will result in many more records being stolen than one caused by an outsider. Incidentally, this is what I have said previously as well! However, when looking at the problem in aggregate, outsiders cause more damage . If the big red dot doesn't say it all, I ...

Verizon Study Continues to Demolish Myths

Image
I just read Patching Conundrum by Verizon's Russ Cooper. Wow, keep going guys. As in before, I recommend reading the whole post. Below are my favorite excerpts: Our data shows that in only 18% of cases in the hacking category (see Figure 11) did the attack have anything to do with a “patchable” vulnerability. Further analysis in the study (Figure 12) showed that 90% of those attacks would have been prevented had patches been applied that were six months in age or older! Significantly, patching more frequently than monthly would have mitigated no additional cases. Given average current patching strategies, it would appear that strategies to patch faster are perhaps less important than strategies to apply patches more comprehensively... To summarize the findings in our “Control Effectiveness Study”, companies who did a great job of patching (or AV updates) did not have statistically significant less hacking or malicious code experience than companies who said they did an average ...

Verizon Business Report Speaks Volumes

Image
This morning I attended a call discussing the new Verizon Business 2008 Data Breach Investigations Report . I'd like to quote the linked blog post and a previous article titled I Was an Anti-MSS Zealot , both of which I recommend reading in their entirety. First I cite some background on the study. Verizon Business began an initiative in 2007 to identify a comprehensive set of metrics to record during each data compromise investigation. As a result of this effort, we pursued a post-mortem examination of over 500 security breach and data compromise engagements between 2004 and 2007 which provided us with the vast amount of factual evidence used to compile this study. This data covers 230 million compromised records. Amongst these are roughly one-quarter of all publicly disclosed data breaches in both 2006 and 2007, including three of the five largest data breaches ever reported. The Verizon Business 2008 Data Breach Investigations Report contains first-hand information on actual ...