Posts

Ten Years After Leaving the Air Force

Image
Ten years ago today was my last official day as an active duty officer in the United States Air Force. I left the Individual Ready Reserve in June 2002, but I don't count that extra time since I worked as a civilian full-time. I find it ironic that the "Officer In Charge" (OIC) of "Career Enhancements" signed my Honorable Discharge! Leaving the service can be quite a "career enhancement" when you want to continue defending Air Force data assets but the service feels its time to "career broaden." :) To this day I am grateful for the colleagues, training, experiences, missions, and responsibilities of my time in the Air Force. At the same time, I remain amazed that I spent almost 11 years of my life wearing the uniform. It seems so long ago now, but I am always pleased to run across people in the security and intelligence worlds who remember working with "Captain Bejtlich." I've greatly enjoyed the last ten years out of uni...

Comparing Microsoft's Communication Methods

Image
Today is Microsoft Patch Tuesday, which means if you so choose you can read posts by the Microsoft Security Response Center like February 2011 Security Bulletin Release . The advisory states "we have 12 bulletins addressing 22 vulnerabilities in Microsoft Windows, Office, Internet Explorer, and IIS (Internet Information Services). Three bulletins are rated Critical." Microsoft communicates information about these vulnerabilities using two graphics. The first is "Severity and Exploitability Index": The second is "Bulletin Deployment Priority": I'm not even going to start a discussion about why the first chart shows "risk" and then "impact" (isn't impact a component of risk?) I'm also not going to dwell about how the first column of the second chart has been "overloaded" to include only a small bit of information on the code affected, rather that prominently communicating that data in a column of its own. Instead,...

Wanted: Incident Handler in Michigan

Image
Do you know how to detect and respond to intruders in a multinational organization? Do you want to join a team with that mission? Are you an experienced information security professional who is looking for a challenge? If your answer to these three questions is yes, please consider applying for the last open Incident Handler role in GE-CIRT . In this role you will mentor intermediate and junior CIRT members and work with some of the best detection and response staff in the world. The role is located at our Advanced Manufacturing & Software Technology Center in located at Visteon Village, Van Buren Township, Michigan. By the end of the month, 19 of my team (about half of GE-CIRT) will be located there. (I have 2 new hires arriving within the next two weeks.) In addition to normal operations there, our extended team meets at the AMSTC facility regularly for training and planning sessions. If you would like more information on the role, apply for job 1259804 and I will revi...

Seven Cool Open Source Projects for Defenders

Image
Long-time blog readers should know that I don't rely on tools to defend my enterprise. I rely on people first, followed by tools, then processes. However, today I took a moment to consider the myriad of really cool work happening (mainly) in the open source tool community. When I started counting, I found about seven projects that are likely to help you defend your enterprise. Most of these require some commitment of brainpower and willingness to learn, but I am nevertheless very pleased to see this much innovation on the defensive side. Collectively these projects do not "solve" any problems (nor should they), but I am certain they can help address one or more problems you may encounter -- especially regarding visibility. In other words, these are the sorts of tools (with one or two exceptions) that will help you detect and respond to intruders. These are numbered for reference and not for priority. Charles Smutz recently announced his Ruminate IDS , whose goal is...

More on Chinese Stealth Fighter and APT

Image
Since my 27 December post Courtesy of APT , featuring the new Chinese stealth fighter, Aviation Week writer Bill Sweetman wrote more about the development of this aircraft and the support from APT: One question that may go unanswered for a long time concerns the degree to which cyberespionage has aided the development of the J-20. U.S. defense industry cybersecurity experts have cited 2006—close to the date when the J-20 program would have started—as the point at which they became aware of what was later named the advanced persistent threat (APT) , a campaign of cyberintrusion aimed primarily at military and defense industries and characterized by sophisticated infiltration and exfiltration techniques. Dale Meyerrose, information security vice president for the Harris Corp. and former chief information officer for the director of national intelligence, told an Aviation Week cybersecurity conference in April 2010 that the APT had been little discussed outside the classified realm, up to...

Happy 8th Birthday TaoSecurity Blog

Image
Today, 8 January 2011, is the 8th birthday of TaoSecurity Blog . I wrote my first post on 8 January 2003 while working as an incident response consultant for Foundstone. 2739 posts (averaging 342 per year) later, I am still blogging. I don't have any changes planned here. I plan to continue blogging, especially with respect to network security monitoring, incident detection and response, network forensics, threat-centric security, and FreeBSD when appropriate. I especially enjoy reading your comments and engaging in informed dialogues. Thanks for joining me these 8 years -- I hope to have a ten year post in 2013! Don't forget -- today is Elvis Presley 's birthday. Coincidence? You decide. The image shows Elvis training with Ed Parker , founder of American Kenpo . As I like to tell my students, Elvis' stance is so wide it would take him a week to react to an attack. Then again, he's Elvis . I studied Kenpo in San Antonio, TX and would like to return to p...

The "IT as a Business" Train Wreck

Image
I just read this year-old article by InfoWorld's Bob Lewis titled Run IT as a business -- why that's a train wreck waiting to happen . It reminded me of comments on a CIO article I posted in 2008 as The Limits of Running IT Like a Business . Here I would like to emphasize a few of Bob's points via excerpts from the 2010 article. When IT is a business, selling to its internal customers , its principal product is software that "meets requirements." This all but ensures a less-than-optimal solution, lack of business ownership, and poor acceptance of the results... Tim Hegwood, CIO of MRI Companies, is trying to steer his company's mindset away from a focus on software delivery. "We're still struggling to institute the concept that ' there are no IT projects -- only projects designed to solve business problems ,'" he reports... Larry Sadler, IT service manager at ONFC, experiences similar difficulties. "The 'customer' concept i...