Life notes and ideas from a security pro who lives in the mountains and does a lot of cycling, skiing, dirt biking, writing, coding, and thinking. Twitter @k3strel
The silent speed of a bike.
The bike is what I need it to be - a place of peace, a place of pain, a place of peace through pain.
It moves me.
There is something about the act of balancing on two wheels that brings about a sense of well being.
It is the most elegant machine man ever made.
It takes me places I wouldn't otherwise go.
Cyclists are just good people.
The rhythm of riding.
Drafting a car down 224 at 48 mph.
The easy access to endorphins a bike provides.
It gets me close to nature.
It makes me feel good.
The camaraderie of riding with friends.
The speed of a good pace line.
The climb up Wolf Creek Pass on an August evening.
The absolute heavenly feeling of coasting down an empty road with no hands and eyes closed.
The youthful, playful feeling it evokes.
The pain.
The peace.
The joy.
My thoughts on what a top-notch security professional looks like. Contact me if you think you are this professional, or you want to become this professional :-)
Is expert in the field of threat intelligence and response, deeply knowledgable of a wide range of technologies and methods for collecting and acting on threat intelligence. Is expert in networking protocols. Is capable of rapidly crafting custom detection signatures to detect attacks for which no signatures exist. Is capable of creating custom threat intelligence and response systems to fill gaps where commercial systems are sub-optimal or non-existent. Is expert in identifying attacks within network traffic, effectively filtering signal from noise such that false positives and false negatives are very low. Expert in navigating complex enterprise computing and network environments. Is able to discern the magnitude of threats. Is competent in analyzing large amounts of data and building software to automate analysis.
Is self-motivated, requiring only high-level strategic direction. Does not require day-to-day instruction. Knows what needs to be done based on the strategic objectives and actions of the threat actors and changes occurring in the environment. Initiates projects to progress the effectiveness of the threat intelligence program, inventing and enhancing threat intelligence systems and methods. These systems and methods serve as the foundation through which others fulfill collection, detection, analysis, and response work. Is a source of strong program and technical influence to others in the team. Mentors others in the team in the craft of threat intelligence and response. Has strong connections in the financial threat intelligence industry and leverages those connections to gain better intelligence and to learn better methods of threat intelligence and response. Is an effective communicator, both verbal and written.
Is highly productive in detecting and responding to threats and in creating frameworks that improve the effectiveness and efficiency in which others detect and respond to threats. Capability to rapidly context switch a must.
Typically has 10+ years in information security, with a three or more years in threat intelligence and response. Is highly competent in skills necessary for effective threat intelligence, including network routing, network protocols, system engineering, protocol analysis, attack signature development, coding, and data analysis.
Information Security professionals commonly define risk in one of two ways:
The expected loss over a given period of time
Risk = threat * vulnerability * impact
Compare this to the way risk is explained in Wikipedia. "Risk is the potential of losing something of value, weighed against the potential to gain something of value." It is the old adage "nothing ventured, nothing gained." Andy Ellis, the CSO of Akamai Technologies, describes it this way. "Our businesses are in the business of taking risks. That's what we do for a living. We spend money in hopes of making more money."
Do you see the problem with the InfoSec risk definition? InfoSec risk is focused on loss - analyzing and minimizing bad outcomes. Real risk is focused on the difference between expected gain and the expected loss. Too often Information Security minimizes bad outcome potential to the extent that it causes greater harm to the gain potential. Have you heard this before? "We can't move to the cloud. Too many unknowns. Too risky." I've heard the same said about SaaS, outsourcing, mobile applications, employee mobility, web services. Really? Were these the same people who said that we can't use email a couple decades ago or that we can't offer online banking?
If Information Security truly internalized a new risk definition that properly balanced the loss potential and the gain potential, we would be more effective in supporting our businesses. Maybe it would cause us to shift to being enablers of rapid adoption of better / faster / cheaper business technology models. Yes, there is profit to be made by properly reducing loss potential. There is also profit to be made on maximizing upside potential. Let's be a proper voice for that equation. If we do, then we'll probably see ourselves march in to some unknowns faster and probably see some traditionally moderate and high residual risk systems go in to production because the gain possibility is so great.
So lets adopt the wikipedia risk definition. Besides, it is what everyone else is using anyway.
"Risk is the potential of losing something of value, weighed against the potential to gain something of value."
And hey, who wants to work at a shop that doesn't run email or a web site anyway?
BTW - I took the risk of jumping off a cliff into the Pacific Ocean today and the reward was great.
In Information Security, the rapidly escalating and innovating threat actors coupled with the ever changing business technology architecture have changed the security game forever. Preventative controls are increasingly less effective in mitigating threats and they are too cumbersome to keep up with the pace of technology change. This shift necessitates a shifting of balance from preventative control focus to rapid security intelligence and response.
A friend of mine who is a world-class security intelligence engineer, pointed me to a paper - Twenty-Eight Articles - Fundamentals of Company-level Counterinsurgency, by David Kilcullen. He also wrote a book, "Counterinsurgency" that I read. My friend's point in directing me to this article was that Information Security is, in many ways, a counterinsurgency operation. Stated my Mr. Kilcullen,
"...counter insurgency is at heart an adaptation battle: a struggle to rapidly develop and learn new techniques and apply them in a fast-moving, high-threat environment, bringing them to bear before the enemy can evolve in response, and rapidly changing them as the the environment shifts." (Counterinsurgency page 2).
The Twenty-Eight Articles was written by Mr Kilcullen at the U.S. State Department and DoD and is based on his extensive experience as a senior advisor on the ground in the Iraq and Afghanistan wars. His Articles are what he observed to be essential to successful counterinsurgency. Here is what I took away. All quotes are from the book, which also contains the 28 Articles.
Article 1: Know your turf.
"Your task is to become the world expert on your district. If you don't know precisely where you will be operating, study the general area. Read the map like a book: study it every night before sleep and redraw it from memory every morning, until you understand its patterns intuitively." (Counterinsurgency page 30).
In Information Security, this is knowing your network and your systems and your applications. What they are, what they store, how they communicate, what their accessibility is, who is accessing them, and so forth. It is Nmap coupled with net flow data coupled with the asset risk catalog coupled with vuln scan information coupled with firewall logs and security event logs and fraud activity.
Article 2: Diagnose the problem
"Who are the insurgents? What drives them?....This means you need to know your real enemy." (Counterinsurgencey page 31)
This is threat analysis based on real data and reliable intelligence. It isn't a physics class, hypothetical, assume a vacuum scenario. It is real and the decisions are made in the real world. It is the root of good security decisions. It is the process of deterring the likelihood of harmful things occurring to your assets - who will do what to the systems. This information, coupled with the value of each of your systems, forms the basis for making sound security decisions.
Article 3: Organize for intelligence
"Your operations will be intelligence driven, but intelligence will come mostly from your own operations, not as a produce prepared and served up by higher headquarters. So you must organize for intelligence."
In post earlier this year, I wrote that your environment has all the data you need to answer your security questions.
Mixed together properly, the DNS logs, web logs, firewall logs, endpoint events, malware events, AD data, and net flow holds rich treasures to finding your weaknesses and ferreting out your enemy.
Article 4: Organize for interagency operations
"Almost everything in counterinsurgency is interagency." David continues, "Train the company in interagency operations -- get a briefing from the State Department, aid agency, and the local police or fire brigade. Train point me in each squad to deal with the interagency." (Counterinsurgency page 32)
In InfoSec, the interagency is the business and your IT associates to support the business objectives. It is being able to work effectively across organizational boundaries to secure and collect data from networking infrastructure and systems, working with the development team to write secure code and integrating security test cases in the QA cycle. It is working with all of these organizations and Public Relations to effectively respond to events.
It is working with product teams to understand their objectives and to quickly develop security solutions to enable them to move quickly. It is being solution-ready for emerging technologies that will enable the company to more efficiently and effectively serve the customer.
Article 5: Travel light and harden your Combat Service Support
"Unless you ruthlessly lighten your load and enforce a culture of speed and mobility, the insurgents will consistently outrun and outmaneuver you." (Counterinsurgency page 33)
This is about having an adaptable security architecture that can be quickly adjusted to address threat. These are inherently solutions that are intelligence centric systems that can learn themselves and learn from the engineer operating them.
Article 6: Find a political/cultural adviser
Be "able to speak the language and navigate the intricacies of local politics." (Counterinsurgency page 33)
Information Security serves the organization that employs it. This is about being connected to the business and enabling the business strategy. It is about bringing the Executive team to the proper level of understanding of threats and risks to their organization in their language.
Article 7: Train squad leaders, the trust them
"Ruthlessly replace leaders who do not make the grade." (Counterinsurgency page 34)
Article 8: Rank is nothing: talent is everything
"Rank matters far less than talent - a few good men under a smart junior NCO can succeed in counterinsurgency, where hundreds of well-armed soldiers under a mediocre senior office will fail." (Counterinsurgency page 34)
This applies to vendors as much as it does people. I've seen talented small teams dramatically cut costs because the commercial software solutions were really just a poor patch for lack of talent. This video illustrates it well....
Article 10: Be there
"If you are not present when an incident happens, there is usually little you can do about it. So your first order of business is to establish presence." (Counterinsurgency page 35)
This is security intelligence and event monitoring so that you can minimize the gap between the time of the initial incident and the response. Wait too long, and the data or the money is gone. Sadly, Mandiant reported that for incidents they were involved in handling the threat groups were present on the systems a median of 229 days.
This is also about being integrated in to the businesses plan, build, operate cycle so that you can influence direction early in the process rather than complaining and scrambling after the products are built.
Article 16: Practice deterrent patrolling
"Establish patrolling methods that deter the enemy from attacking you." (Counterinsurgency page 39)
I've seen it done so well, that banking trojan campaigns and associated fraud has fallen off for weeks because the best proactively lure and take down the miscreants. This is also about advanced threat intelligence so that you are resilient to even the newest attack campaigns. This means being in the enemy camp gathering intel and being trusted professionals with your business competitors such that you can share information quickly and without friction of legal qualifications.
Article 17: Be prepared for setbacks
Compromises happen. Projects fail. Managers make mistakes. It happens. It is human. Diagnose. Learn. And move forward.
Article 20: Take stock regularly
"Use metrics intelligently to form an overall impression of progress - not in a mechanistic "traffic light" fashion. (Counterinsurgency page 41)
Metrics that matter. The metrics that matter here are those that inform you about the enemy and your capability in resisting them and where controls are worth it and where they are not. They also measure how well you are serving the business. I'll do a post on this in the near future.
Two words to describe this trail - steep and rocky. I saw a few guys on 4-wheelers. No dirt bikers. This is indicative of what you are riding. Long and steep and rocky. I stalled a few times here. Lots of weight on the rear tire is required.
This is looking down a steep rocky, switchback section. I have yet to ride this without dumping my bike. This time it cost me my front brake lever. A while ago, it cost my friend a hole in his crank case. Goal: ride this without stalling and without dumping.
The top has some fun stuff where you can spend a bit of time in 4th gear. Trust me, you'll never hit 5th.
After getting back down, I buzzed up Beaver Creek, just across the highway. Finally, 5th gear.
This paper is a threat report derived from the 31 information security threat reports published in 2014. Basically, I read all of the
2014 threat reports so you don’t have to. This document contains the best parts of the threat reports. I’ve also listed all
the reports included in the review and enumerated the best reports incase you want to read some of them yourself.
Though the threat reports are bent in the direction of the author’s commercial interests, they are worth reading. A big
“thank you” to the vendors who spend the resources to put these out. I hope this summary is useful to you. Download a PDF of The Best of the 2014 InfoSec Threat Reports here
Theft of user credentials and personal data will continue. (Dell)
Compared to PC-based threats,
the number of mobile malware is miniscule.(F-Secure)
Risky behavior begets other
risky behavior. (Lookout)
...organizations should not ignore a
solution as straightforward as anti-virus since it can reduce virus threats by
almost 50%. (NTT Group)
The catachresis of
malware is being carried out by both state and non-state players where the
objectives vary from monetization to creation of espionage networks and
stealing of information. (Quick Heal)
Windows XP
will still be targeted while its support life cycle is ending in year 2014. (Dell)