Posts

Review of The Design and Implementation of the FreeBSD Operating System Posted

Image
Amazon.com just posted my five star review of The Design and Implementation of the FreeBSD Operating System . I was excited to see this update of the 1996 classic The Design and Implementation of the 4.4BSD Operating System finally published. From the review: "I have been administering FreeBSD systems for four years, and I read 'The Design' to get a better understanding of the system 'under the hood.' This book is definitely not for beginners, and intermediate users like myself can become quickly overwhelmed. Nevertheless, I am very glad FreeBSD developers like McKusick and Neville-Neil took the time to document the kernel in this book." You can access the authors' works at Addison-Wesley or at McKusick.com and Neville-Neil.com .

What is the Ultimate Security Solution?

I received an email asking certain questions about digital security. Since the author said I could post my reply in my Blog, here is an excerpt from his email: "I have read of many ways that hackers obtain access. But, I am uncertain what is comprehensive protection. Clearly, there are firewalls, anti-virus, anti-spyware, IDS, IPS, and many other three letter acronym tools available. I have read of your use/support for Sguil. Do you feel that is the ultimate solution? There are other tools out there like eEye Blink, Pivx Qwikfix, and Securecore type products. I like them, but am uncertain if they do an adequate job at providing security. And I really don't know which would be considered the best of these. So, I appeal to you for your insight. Would really appreciate any feedback - here or on your blog." This is an interesting question, because at least one reader of my recent Focus-IDS post thought I was a "detection-only" advocate. Since I believe pro...
Image
Showing the FreeBSD Release Engineering Team is on schedule , FreeBSD 5.3-BETA2 is now available . Relating to my earlier post on GIANT, the announcement states "debug.mpsafenet (multi-processor safe network stack) is still turned off by default for BETA2 but will be turned on for BETA3."

GIANT-free Networking in FreeBSD 6.0 CURRENT and Upcoming 5.3 STABLE

Image
I've been watching Robert Watson 's work on removing the GIANT lock from the FreeBSD kernel. This is an aspect of the FreeBSD SMP project (aka SMPng). Robert's posts on 24 Aug 04 and 28 Aug 04 explain what is affected by these developments. The aspects I care about include the following: - Those using KAME IPSec will not be able to disable the GIANT lock, and least not yet. - FAST IPSEC does work with GIANT removed. - The ath (802.11g), bge, dc, em (Intel gigabit), ep, fxp (Intel 10/100), rl, sis (Soekris Net4801), xl, and wi (802.11b Prism2) network interface drivers work with GIANT disabled. You can see how the GIANT lock appears when enabled in the dmesg output from a Dell PowerEdge 750 running FreeBSD 5.3-BETA1. John Baldwin's Locking in the Multithreaded FreeBSD Kernel explains what the GIANT lock does.

My Book on Slashdot

Image
My book made Slashdot . Let's see how well this site and TaoSecurity.com hold up! Thank you to Anton Chuvakin for a positive review. Update: Here's how the Slashdot effect looked to TaoSecurity.com : Here's how the Slashdot effect looked to this Blog: My Barnes and Nobles sales rank has dropped from the 40,000 range to 20 -- I've passed Bill Clinton and Harry Potter. :) My Amazon.com sales rank has dropped from the 20,000 range to 119. Slashdot is absolutely amazing. If you find the Amazon price too high, remember Bookpool has the best deal going -- $27.25 plus shipping. I'd been tracking the Amazon rank to see if I could make any sense of it. You can watch the Slashdot effect kick in between 5 and 6 pm EDT: Fri Aug 27 17:00:02 EDT 2004 Amazon.com Sales Rank: 20,998 Fri Aug 27 18:00:01 EDT 2004 Amazon.com Sales Rank: 9,363 Fri Aug 27 19:00:02 EDT 2004 Amazon.com Sales Rank: 1,256 Fri Aug 27 20:00:02 EDT 2004 Amazon.com Sales Rank: 614 Fri Aug 27 2...

Senator Kennedy No-Fly Watch List and IDS "False Positives"

Image
It struck me today that Senator Kennedy's no-fly watch list troubles are very similar to our digital security woes. Recently Kennedy said "he was stopped and questioned at airports on the East Coast five times in March because his name appeared on the government's secret 'no-fly' list." The Washington Post reported "a senior administration official, who spoke on condition he not be identified, said Kennedy was stopped because the name 'T. Kennedy' has been used as an alias by someone on the list of terrorist suspects." "T. Kennedy" reminds me of a content matching IDS rule. Is this a "false positive"? If you consider that airline personnel were making decisions based on the rules they were given -- stop anyone using the name "T. [Ted, in the senator's case] Kennedy," this is not a false positive. Perhaps with more context, like personal recognition that the individual at hand is one of the most famou...

Fascinating .gov and .mil Docs

Perhaps "fascinating" is too strong a word, but I've come across several intriguing government reports and documents which security professionals might find interesting. First, the CERT/CC and the Secret Service released a joint report titled Insider Threat Study . It's based on "23 incidents carried out by 26 insiders in the banking and finance sector between 1996 and 2002. Organizations affected by insider activity in this sector include credit unions, banks, investment firms, credit bureaus, and other companies whose activities fall within this sector. Of the 23 incidents, 15 involved fraud, four involved theft of intellectual property, and four involved sabotage to the information system/network." One of the incidents, mentioned in the beginning of the report, was the case prosecuted by the DoJ on behalf of UBS . The major findings include: "- Most of the incidents in the banking and finance sector were not technically sophisticated or complex. ...