Posts

Information Security Jobs in GE-CIRT and Other GE Teams

Image
I'm hiring for my team (GE-CIRT) again. The following summarizes open positions: Information Security Incident Handler (1145304); serious skills required Information Security Incident Analyst (1147842); intermediate skills required Information Security Event Analyst (1147849); extreme willingness to learn required Security Assurance Team Senior Analyst (1147811); intermediate skills required Security Assurance Team Analyst (1147853); extreme willingness to learn required Information Security Infrastructure Engineer (1147859); serious Unix and open source system and database administration skills required Roles 1-3 involve incident detection and response. Roles 4-5 involve threat analysis, Red-Blue teaming, and internal consulting. Role 6 supports team systems. All roles have a bias towards hiring into our beautiful Advanced Manufacturing and Software Technology System in Michigan. I already have five guys working there and expect to have at least a dozen more on our team work...

Reaction to Cyber Shockwave

Image
I just finished watching Cyber Shockwave, in the form of a two hour CNN rendition of the 16 February 2010 simulation organized by the Bipartisan Policy Center (BPC). The event simulated, in real time, a meeting of the US National Security Council, with former government, military, and security officials role-playing various NSC participants. The simulation was created by former CIA Director General Michael Hayden and the BPC’s National Security Preparedness Group, led by the co-chairs of the 9/11 Commission, Governor Thomas Kean and Congressman Lee Hamilton. The fake NSC meeting was held in response to a fictitious "cyber attack" against US mobile phones, primarily caused by a malicious program called "March Madness." For more details, read the press releases here , or tune into CNN at 1 am, 8 pm, or 11 pm EST on Sunday, or 1 am EST on Monday. In this post I'd like to capture a few thoughts. Others have already criticized the technical realism of this exer...

Review of Intelligence, 4th Ed Posted

Image
Amazon.com just posted my five star review of Intelligence: From Secrets to Policy, 4th Ed by Mark Lowenthall . From the review : I was an Air Force military intelligence officer in the late 1990s. I've been working in computer security since then. I read Intelligence, 4th Ed (I4E) to determine if I could recommend this book to those who doubt or don't understand the US intelligence community (IC). I am very pleased to say that I4E is an excellent book for those with little to no intelligence experience. I also found I4E to be a great way to catch up on changes in the IC, particularly since Congress passed the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA). I4E is a great book -- check it out!

Offshoring Incident Response

Image
A blog reader emailed the following question. We recently had a CISO change, and in the process of doing an initial ops review and looking at organizational structure, one of the questions the new CISO has is about the viability of offshoring incident response... I would be very interested in your views on this matter, and would appreciate any feedback you can offer. As background, I've been involved in incident response in many different capacities: top-level military CERT, managed security services provider, fly-away consultant, government contractor, independent consultant, and top-level corporate CIRT. In other words, I've worked in insourced and outsourced environments. I strongly advocate insourced or internal, professional incident response teams. Many technical people fixate on the technical aspects of security, as you might expect. While technical expertise is critical, it is also critical to understand the client. Depending on the size and complexity of the clien...

Advice for Academic Researchers

Image
A blog and book reader emailed the following question: I am an info sec undergrad and have been granted a scholarship to continue my studies towards a phd with the promise of DoD service at the other end. It is critical for me to research and select the most important area of security from the Defense Department's perspective. My question to you is this: Drawing upon your knowledge, what specific area(s) of information security do you feel will be most critical in the next several years (especially in the eyes of the Dept. of Defense)? I post this question because I'm sure blog readers will contribute interesting comments. For my part, I'm really interested in the following: characterizing network traffic. In other words, develop tools and techniques to describe what is happening on the network . (I'm sure a few commercial vendors think they are doing this already, but nothing approaches the level that we really need.) Without understanding what is happening, we ca...

Answers Regarding Military Service

Image
Once in a while I'm asking my Thoughts on Military Service . An anonynous blog reader sent the following questions. It's been a while since I wore the uniform, but at least some of you readers might care to offer your own thoughts? I'll try to answer what I can. I got into IT after graduating from college with non-technical majors and decided that I was actually interested in areas of practical science, such as: physical computing, engineering (mechanical, electrical, and design), robotics, aerospace, and programming. IT was a great primer for some practical work experience, but after my stint with [a security company] I'm evaluating if I want to acquire more direct technical training with the things I'm passionate about. So, here's my barrage of questions; please feel free to answer however you want, I'm simply organizing the thoughts rumbling around in my head. If I left anything relevant out, which I'm certain I did, then please mention it. 1) W...

Max Ray Butler Sentenced (Again)

Image
In late 2007 I blogged Max Ray Butler in Trouble Again . Please see that post and Kevin Poulsen's June 2009 story for details. According to ComputerWorld , you don't want to be Max Ray Butler: A former security researcher turned criminal hacker has been sentenced to 13 years in federal prison for hacking into financial institutions and stealing credit card account numbers. Max Ray Butler, who used the hacker pseudonym Iceman, was sentenced Friday morning in U.S. District Court in Pittsburgh on charges of wire fraud and identity theft. In addition to his 13-year sentence, Butler will face five years of supervised release and must pay US$27.5 million in restitution to his victims, according to Assistant U.S. Attorney Luke Dembosky, who prosecuted the case for the federal government. Dembosky believes the 13 year sentence is the longest-ever handed down for hacking charges. Butler, also known as Max Vision, pleaded guilty to wire fraud charges in June last year. In an odd coinc...