Posts

Risk, Threat, and Vulnerability 101

Image
In my last entry I took some heat from an anonymous poster who seems to think I invent definitions of security terms. I thought it might be helpful to reference discussions of terms like risk, threat, and vulnerability in various documents readers would recognize. Let's start with NIST publication SP 800-30: Risk Management Guide for Information Technology Systems . In the text we read: " Risk is a function of the likelihood of a given threat-source 's exercising a particular potential vulnerability , and the resulting impact of that adverse event on the organization. To determine the likelihood of a future adverse event, threats to an IT system must be analyzed in conjunction with the potential vulnerabilities and the controls in place for the IT system." The document outlines common threats: Natural Threats: Floods, earthquakes, tornadoes, landslides, avalanches, electrical storms, and other such events. Human Threats Events that are either enabled by or caused...

OCTAVE Properly Distinguishes Between Threats and Vulnerabilities

You may have heard of Carnegie Mellon's Software Engineering Institute . Within SEI's Networked Systems Survivability program is the Survivable Enterprise Management group. Members of this group developed the Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) method. OCTAVE is "a self-directed approach for assessing and managing information security risks . OCTAVE allows an enterprise to identify the information assets that are important to the mission of the organization, the threats to those assets, and vulnerabilities that may expose the information assets to the identified threats." Already you should notice that the OCTAVE crew is using the terms risk, asset, threat, and vulnerability properly. In fact, a look at the OCTAVE Threat Profiles (.pdf) document reveals additional understanding of the differences between threats and vulnerabilities: "Below is an expanded classification of threat actors. non-malicious employees: ...
Image
There's more coming out of the Forum of Incident Response and Security Teams (FIRST) these days now they've updated their Web page! I just read an announcement that the Department of Homeland Security has named FIRST the custodian of the Common Vulnerability Scoring System (CVSS). CVSS is a way to quantify the severity of a vulnerability using three groups: a base metric group, a temporal group, and an environmental group. The sample scoring shows some of the values for recent vulnerabilities. The definitive documents on CVSS are available on the FIRST CVSS site. I think this system will have some legs, so keep an eye on it. My only concern is that some documents which explain CVSS confuse threats with vulnerabilities -- a common theme on this blog. Consider the following: "Current scoring systems, in use by the Computer Emergency Response Team/Coordination Center (CERT/CC), Symantec, Internet Security Systems, Cisco Systems, and others, rate vulnerabilities ac...

TaoSecurity Announces Network Security Operations Class

img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6lGDGMBN3aDxHOSV7VhW96AX8XBcA6sf2fefZOZciBiTYW6-ezP3P26uSCxPrfbqPydrVZGITLaqxgB7MDPXPfrEVElSLBfFnDXwXaj2DhEGQrYltOKZZONrMNLbC_e6CKrL0/s1600/taosecurity_s.png" align=right>I am proud to announce that flyers are available for my new four-day class Network Security Operations . You can view either the color .pdf or the grayscale .pdf formats. The course offers four sections: Network Security Monitoring Network Incident Response Network Forensics Live Fire Exercises For more information, please refer to the flyers, and email richard at taosecurity dot com. Thank you!

Report from the CISSP Exam

No, I did not take the CISSP test again -- thank goodness. A friend of mine just did, however. He agreed to share his story with you. "I attended the Intense School CISSP bootcamp last week and took the test last Sunday. I received my test result today and I passed! It was the hardest and most obscure test I have ever taken. I was convinced I did not pass. Usually, I perform well on test, but this was a monster. I never want to take it again and wouldn’t wish my version of the test on anyone! It took me two hours and 50 minutes. I guess that is fast compared to the average. I can’t imagine sitting there for six hours staring at those questions. I just answered/guessed and moved on and didn’t go back and change any answers. I think I was the first CISSP test taker done in the room. I am so relieved." I had the same experience almost four years ago, except I finished in 90 minutes. The room was so cold, I just wanted to be done and get out of there as fast as pos...

Reviews of VoIP Security, The Internet and Its Protocols Posted

Image
I refused to let April end without finishing and reviewing these two books kindly provided by Elsevier Press . The first was a disappointment. Amazon.com just posted my three star review of VoIP Security . From the review : "I decided to read VoIP Security because I thought it would describe VoIP protocols and ways to secure them. The table of contents looked very strong and the preface seemed to meet my goals: "For one to truly understand Internet telephony, the reader must have a solid understanding of digital voice, telephony, networking, Internet protocols, and, most important of all, how all of these technologies are put together." Unfortunately, the book is confusing at times and is not an improvement over earlier VoIP security books. So-called 'reviewers' who write that this book 'goes heavily into explaining the low level mechanics of VoIP' reveal they don't read the books they purport to review." Thankfully, I was very pleased to re...

FreeBSD 5.4-RC4 Imminent

Image
As I guessed recently , we should see FreeBSD 5.4 RELEASE arrive next week or very soon thereafter. Scott Long posted an update on the release status of 5.4 this morning. He says: "As you probably noticed, we are a bit behind on the 5.4 release. There was a major stability problem reported several weeks ago in a particlar high load, high profile environment, and we decided that it was in everyones best interest to get it resolved before the release. Well, thanks to the tireless efforts of Doug White and Stephen Uphoff and several others, the bug has been found, fixed, and verified. As soon as it and a few other fixes get merged in, we will start the RC4 build process and hopefully release it for testing late this weekend. After that, unless another show-stopper comes up, we expect to build and release 5.4-RELEASE next weekend." I hope to test 5.4-RC4 this week, assuming it arrives tomorrow. Thanks FreeBSD release team!