Posts

Simpler IP Range Matching with Tshark Display Filters

Image
In today's SANS ISC journal, the story IP Address Range Search with libpcap wonders how to accomplish the following: ...how to find SYN packets directed to natted addresses where an attempt was made to connect or scan a service natted to an internal resource. I used this filter for addresses located in the range 192.168.25.6 to 192.168.25.35. The proposed answer is this: tcpdump -nr file '((ip[16:2] = 0xc0a8 and ip[18] = 0x19 and ip[19] > 0x06)\ and (ip[16:2] = 0xc0a8 and ip[18] = 0x19 and ip[19] I am sure it's clear to everyone what that means! Given my low success rate in getting comments posted to the SANS ISC blog, I figured I would reply here. Last fall I wrote Using Wireshark and Tshark display filters for troubleshooting . Wireshark display filters make writing such complex Berkeley Packet Filter syntax a thing of the past. Using Wireshark display filters, a mere mortal could write the following: tshark -nr file 'tcp.flags.syn and (ip.dst > 192.168.25.6 ...

Effective Digital Security Preserves Long-Term Competitiveness

Image
Yesterday I mentioned a speech by my CEO, Jeff Immelt. Charlie Rose also interviewed Mr Immelt last week. In both scenarios Mr Immelt talked about preserving long-term competitiveness. Two of his themes were funding research and development and ensuring the native capability to perform technical tasks. It occurred to me that digital security is reflected in both themes. In Crisis 0: Game Over I asked I'm sure some savvy reader knows of some corporate espionage case that ended badly for the victim, i.e., bankruptcy or the like? I got a few interesting cases, but I believe the net result is that it is difficult to find examples where an intrusion or breach was so devastating that it ended up destroying the victim organization. This makes sense once you reflect on it. Why would a mature, thoughtful intruder seek to destroy his victim, if the purpose of his mission is to conduct espionage on behalf of a competitor or intelligence service? Destroying the victim renders it us...

Posts to Read Elsewhere

Image
I'm not a big fan of just publishing links to other people's stories, but there's a few that I really like this week. Please consider checking these out: Nate Richmond wrote Building an IR Team: People and Building an IR Team: Organization . These posts are gold for anyone trying to build an IR team on their own, or trying to benchmark against an expert's recommendation. Keep writing Nate! Alec Waters caught my attention with his post Prevention Eventually Fails, part one . Anyone who read my first book recognizes my catchphrase "Prevention eventually fails." Alec's posts look interesting! My CEO delivered a great speech this week, viewable at American Renewal: Immelt addresses Detroit Econ Club and readable at Text of Immelt's Speech . This caught my eye: In some areas, we have outsourced too much. We plan to "insource" capabilities like aviation component manufacturing and software development . These are the things we will be work...

Black Hat Budgeting

Image
Earlier this month I wondered How much to spend on digital security . I'd like to put that question in a different light by imagining what a black hat could do with a $1 million budget. The ideas in this post are rough approximations. They certainly aren't a black hat business plan. I don't recommend anyone follow through on this, although I am sure there are shops our there who do this work already. Let's start by defining the mission of this organization, called Project Intrusion (PI). PI is in "business" to steal intellectual property from organizations and sell it to the highest bidders. In the course of accomplishing that mission, PI may develop tools and techniques that it could sell down the food chain, once PI determines their utility to PI has sufficiently decreased. With $1 million in funding, let's allocate some resources. Staff. Without people, this business goes nowhere. We allocate $750,000 of our budget to salaries and benefits to hi...

Being a Critic Is Easy, So What Would I Do?

Image
After my last post, some of you are probably thinking that it's easy to be a critic, but what would I suggest instead? The answer is simple to name but difficult to implement. Operate a defensible network architecture . Hardly anyone does. I don't need to explain all of the reasons why here; they could occupy a series of posts, or maybe even a book. Once the DNA is operating, detect and respond to failures. The nice aspect of operating a DNA is that the number of failures should be lower but of higher complexity. Unfortunately at the moment almost all of the world's detection and response teams have to deal with the entire spectrum of security incidents. These range from the most mundane to the most complex. Too often the mundane hide the complex, or at the very least divert resources and attention. Use the knowledge learned from failures (either caused by adversaries or adversary simulation) to guide the next version of the DNA. Since most enterprises are not...

Ugly Security

I read Anton Chuvakin's post MUST READ: Best Chapter From “Beautiful Security” Downloadable! with some interest. He linked to a post by Mark Curphey pointing out that Mark's chapter from O'Reilly's new book Beautiful Security was available free for download in .pdf format. O'Reilly had been kind enough to send me a copy of the book, so I decided to read Mark's chapter today. I found the following excerpts interesting. Builders Versus Breakers Security people fall into two main categories: Builders usually represent the glass as half full. While recognizing the seriousness of vulnerabilities and dangers in current practice, they are generally optimistic people who believe that by advancing the state they can change the world for the better. Breakers usually represent the glass as half empty, and are often so pessimistic that you wonder, when listening to some of them, why the Internet hasn’t totally collapsed already and why any of us have money left unpilfe...

SANS Forensics and Incident Response 2009

Image
The agenda for the second SANS WhatWorks Summit in Forensics and Incident Response has been posted. I am really happy to see I am speaking on Tuesday, because I will not be available Wednesday. Day 1 appears mainly technical, and day 2 is mainly legal. Please consider registering for the two-day conference. It's the best incident response event in the US this year! Richard Bejtlich is teaching new classes in Las Vegas in 2009. Regular Las Vegas registration ends 1 July.