Posts

Bringing FreeBSD to InstantNSM

Last week David Bianco announced his InstantNSM project. The purpose is to automate Sguil distribution. At the moment InstantNSM works on Red Hat Enterprise Linux 3 and 4, and geek00l has been blogging on InstantNSM using CentOS 4.2 . I told David this afternoon that I plan to help him get InstantNSM working with FreeBSD. I plan to let InstantNSM be the means by which I build FreeBSD Sguil sensors. This will eliminate the need for me to test and write a separate Sguil installation guide . I hope to integrate the proposed sguil-server , sguil-sensor , and sguil-client ports, and the existing SANCP and barnyard ports. Paul has a sguil-client port waiting on acceptance of his new iwidgets port. Sguil 0.6.0p1 was announced recently. This is the version to deploy if you're starting a new Sguil project and want to the latest and greatest. Incidentally, this is my 1200th post. This blog will be 3 years old in 20 days. It began on 8 January 2003 .

Two New Pre-Reviews

I would like to thank publisher Syngress for sending me two new books that I plan to read in 2006. They sent others, but they are outside my Wish List and therefore well beyond the reach of my reading list . First is Securing IM and P2P Applications for the Enterprise by Paul Piccard, et al, with Marcus Sachs as technical editor. I want to read this book because it addresses the sort of inside-out security problems I wrote about in Extrusion Detection . This appears to be a technical book with lots of helpful advice. The second book is Insider Threat by Dr. Eric Cole and Sandra Ring. This appears to be a largely non-technical book, dealing more with case studies and general advice. I still think a book like this is helpful, if only to focus people's minds on what the word "threat" means. A flawed version of SSH running inside a company is not an "insider threat," but a disgruntled system administrator certainly is!

FreeBSD Release Schedule

Image
Scott Long posted the latest FreeBSD release schedule . We will see FreeBSD 6.1 near 20 March 2006 and FreeBSD 5.5 near 3 April 2006. FreeBSD 5.5 will be the last 5.x release, with security fixes continuing through 2007 or perhaps 2008. FreeBSD 7.0 is not planned until some time in 2007. If you follow the thread from Scott's post, some in the community have problems with the pace of releases. I think expectations were formed with the 4.x tree. FreeBSD 4.0 arrived in March 2000, and the end of the line appeared with FreeBSD 4.11 nearly five years later in January 2005. In contrast, FreeBSD 5.0 arrived in January 2003, and by April 2006 the 5.x tree will end with 5.5. Given that FreeBSD 5.x wasn't considered STABLE until FreeBSD 5.3 in November 2004, I understand why some people are concerned. I am already using the amd64 port of 6.0 in production, but I have several systems still running 5.4. Incidentally, within the release thread Peter Jeremy made a stunning comme...

Defense Seldom Wins Wars

In preparation for my career as an Air Force intelligence officer, I studied history at the US Air Force Academy . Since then I have enjoyed lectures produced by The Teaching Company , like Famous Romans . One of the lessons I have taken from this course is that defense seldom (if ever) wins wars . I was reminded of this lesson when I read Tom Ptacek's post " The Only Defense Is A Good Defense." Tom is replying to my post where I said the following: "I also do not agree [with SANS.edu] that 'knowledge... is the only defense to the growing threat.' The best defense is a strong offense. That means hunting down and prosecuting threats. No amount of defense can sufficient protect any moderately complex enterprise against determined intruders." Tom disagrees and says that "Firewalls", "IT and Network Security teams", and "Vulnerability Research" have "done the most to improve security over the last 5 years." If w...

Thoughts on Monoculture

Tom Ptacek and friends have been blogging at a furious pace, and I noticed he recently argued against Dan Geer 's latest article (.pdf) which supports software diversity as a means of "improving security." Tom also found a friend in Halvar Flake . Now, Halvar may be really smart, but it doesn't mean Halvar's argument makes sense in the context that most people share when software monoculture is debated. Halvar writes exploits. That is his mindset and worldview. Here is the scenario he outlines: "[T]ake a useful piece of information (for example, a source tarball) and distribute it randomly on a small subset of the computers in the organisation. In the monoculture example, I would need an exploit for the monocultureOS. In the diversity example, I need an exploit for any of the OSs on which the information that I want is stored. Joy. Please diversify!" According to this reasoning, Halvar thinks software monoculture improves security. By operating a ...

Thoughts on Recent Microsoft Common Criteria News

Through Slashdot I hunted down this story about certain Microsoft products being awarded Common Criteria (CC) Evaluation Assurance Level (EAL) 4 Augmented with ALC_FLR.3 certification. They include: Microsoft Windows Server™ 2003, Standard Edition (32-bit version) with Service Pack 1 Microsoft Windows Server 2003, Enterprise Edition (32-bit and 64-bit versions) with Service Pack 1 Microsoft Windows Server 2003, Datacenter Edition (32-bit and 64-bit versions) with Service Pack 1 Microsoft Windows Server 2003 Certificate Server, Certificate Issuing and Management Components (CIMC) (Security Level 3 Protection Profile, Version 1.0) Microsoft Windows XP Professional with Service Pack 2 Microsoft Windows XP Embedded with Service Pack 2 Achieving this certification is important to Microsoft, because of certain laws : "[E]ffective 1 July 2002... departments and agencies within the Executive Branch shall acquire, for use on national security systems, only those COTS products or crypt...

Non-Technical Means Unearth Best Intrusions

Thanks again to the latest SANS NewsBites , I learned of an interesting trade secret theft case . From the CNET News story : "John O'Neil, former CEO of Business Engine Software, pleaded guilty in a San Francisco federal court on Wednesday to conspiracy to download and steal the trade secrets of software competitor Niku over a 10-month period... From October 2001 until July 2002, Business Engine used the passwords to gain unauthorized access to Niku's systems more than 6,000 times and downloaded over 1,000 confidential documents containing trade secrets, the complaint alleged. The stolen documents included technical specifications, product designs, prospective customers, customer proposals, client account information and pricing. Niku discovered the break-in after a Business Engine salesman made an unsolicited call to one of Niku's prospective clients, a Nike employee who happened to be related to Niku's chief information officer, Warren Leggett. The call raised...