Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, July 16, 2010

Risk Assessment

Risk management, or really risk mitigation, is a relatively new science, but one that has real value if handled properly.  The goal of managing risk is to ensure that the confidentiality, availability and integrity of your assets is intact regardless of the situation.  The fundamental first step in managing risk is to first thoroughly identify what all of the risks are, without turning a blind eye to anything through a risk analysis.  There are many aspects to performing a risk analysis for your assets, and one of the most widely used methods that can capture those aspects in a meaningful way is to perform a qualitative risk assessment. This method is scenario driven, and ranks the seriousness of risks and also the sensitivity of assets into easy to understand classes or grades.


Score Damage Trigger Time Potential Impact
High Critical Minutes to Hours Loss of life, failure of business, legal charges
Medium Disruptive Hours to Days Bad PR, loss of customers,loss of prestige, loss of income
Low Moderate Days to Weeks Requires workaround, reduction in output

It is important to assign a subjective assessment of risk to specific assets.  To do this, a group should participate in the process, and the person responsible for maintaining the asset should be involved. This can be conducted through meetings, brainstorming sessions or a thorough questionnaire that can help protect anonymity and therefore enable complete openness. 

Basic steps for performing an assessment should include;
1.  List all of the organization's critical assets in a spreadsheet.
2.  Specify threats and vulnerabilities for that asset.
3.  Develop a consistent exposure severity scale to cover all assets
4.  Organize the list based on the priority of most critical to the least.
5.  Prioritize funds to mitigate risks based upon the critical nature of the asses and threat.
6.  Ensure that the assets achieve a much lower exposure.

Often, it seems easier to handle events as they arise, since the frequency of negative events is very low and does not seem to justify the costs.  The value proposition here is to reduce the possibility of impact to the business. If is helpful to avoid situations by understanding;
         -What is at risk
         -The value that is at risk
         -The kind of threats that could occur and their annualized financial consequences
         -What can be done to reduce risks and the acceptable costs of doing so

Risk assessment also enables a strategic approach to risk management, and could produce critical decision support information when changes or upgrades to the existing infrastructure are being considered.  Only when the risks are fully understood can mitigation of risk take place.  It is possible to put in safeguards that can protect against more than one threat, but the best safeguards cannot be accurately chosen without careful analysis of the challenges and threats.

Enhanced by Zemanta

Monday, July 5, 2010

What in the world is a Bot?

How a botnet works: 1. A botnet operator sends...Image via Wikipedia

The computer vernacular has given us many terms, but Botnet describes something that everyone should be aware of. Also known as Ghostnets or Zombie Farms, Botnets are used for malicious activity, the types of which this blog usually talks about. Individual computers are infected with a virus that is under a command and control structure, turning them into 'Bots', short for robots. This virus can be as simple as in an email or code on a website, and once installed can be very difficult to detect and eradicate. The bot is then grouped together with other bots to perform malicious activity, such as sending out spam email or 'Denial of Service' attacks.
Now while all of this seems harmless, consider what is happening. Someone with bad intentions owns your machine more than you do, and uses it to attack the livelihood of others. These people can rent out their botnets to other criminals to send out spam, or use them for direct attacks on companies as they demand ransom. These endeavors can be lucrative, so the practice continues.
Also consider that sometimes it can be state sponsored terrorism or spying. The attack on the Dalai Lama started out among supporters of Tibet through an email hack and wound up infecting over 12,000 computers in many different countries' embassies and consulates. The Dutch police found a 1.5 million node botnet, and the Conficker virus created over 10 million bots around the world. Many of these networks have scaled back to elude detection to below 20,000 machines, but big networks still exist and operate.
Aside for the things such as spam and credit card fraud that these systems are often used for, there are other implications which also bear looking at. The attack on the Pentagon in 2007 created immense collateral damage to machines around the world, mostly here in the US as botnets ramped up and attacked the firewalls of the Pentagon. This created an immense slowdown of the internet as vulnerable systems were converted into soldiers in the attack. The spike in traffic went well over the normal 60TB of data that is moved on the internet each day, creating a global slowdown and disruption of everything from commerce and banking to every other use the internet has.
These can be avoided quite simply for now with some basic maintenance to the average computer and user:
1. Patches and Updates. Seems simple, but so often either overlooked or just not done.
2. Firewalls (Hardware and Desktop) are configured correctly and monitored.
3. Anti-virus is everywhere.
4. Policies, guidelines and procedures, and then education about those same items. It is helpful to write in a manual that a user should not pick up a found USB key and insert into their company desktop. It's more helpful if the employee is instructed that the policy exists and why.
Another simple fix is to outsource your security. Many of the attacks that are well documented are inside jobs. Rio Tinto in 2009, Societe Generale in 2008 were both billion dollar losses because the people inside the company had access, knowledge and privileges. By finding a trusted partner to handle either the total security defense, or to provide oversight of the internal resources, a savvy businessman can ensure that all threats inside and out are being carefully handled.
Enhanced by Zemanta

Friday, June 4, 2010

DNSSEC

A Cisco 7301 router, part of the AMS-IX mirror...Image via Wikipedia

DNSSEC stands for DNS Security Extensions, and is designed to add security to the Domain Name System. As of May 5th, the last root server went through a a transitional milestone in the deployment of this protocol across the root DNS servers. As a resultall root servers are now serving up longer responses for DNSSEC requests. Full implementation of this new and major upgrade to the security of DNS at the root server level is expected to be finished by Mid-July. This will protect the DNS function from certain attacks, and all major DNS systems will be required to provide full or partial DNSSEC functionality within the next few years.
Specific functions that take place between a multi-campus company, or business transactions that use HTTPS(SSL), can now provide more security and integrity to transactions that take place using DNSSEC. It can provide for better origin authentication, data integrity, and authenticated denial of existence. One of the easy transition methods is the deployment of a DNSSEC appliance, which serves as a DNS signer for DNS zones. This can be a large, several thousand dollar appliance; or as inexpensive as a several hundred dollar, more portable device like a card or USB token.

In addition to accelerating DNSSEC compliance, These devices, known as Hardware Security Modules (HSM) provide support for other applications as well.

The applications are many, but are commonly deployed for such things as
1> Card Payment Systems
2> PKI Environments
3> Automated Teller Machines
4> POS Terminals

For these and other types of systems, the HSM provides an aid to securely encrypting data in a relatively unsecure database, verifying the integrity of the data in a database, and aids in verifying digital signatures.
The HSM provides FIPS 140-1 and 140-2 validation, and uses widely accepted algorithms for the most part. It is much more preferable to find a system that does not use a proprietary algorithm, so that the HSM can provide proven functionality for all necessary functions.

This is just one of many types of systems that can aid in an overall security solution. Providing that proper security processes, such as risk analysis, testing and careful administration of the device can ensure a better security posture for mid-sized businesses or greater integrity for financial transactions.
Enhanced by Zemanta

Monday, May 31, 2010

Remote Access

I love remote access. It lets anyone from a company connect from anywhere with an internet connection and access company resources. It enables a workforce to tend to business matters without coming into the office. In my opinion and experience, this is one of the greatest things from IT that makes people's lives better. The manager is happy because his work is getting done, the worker is happy since they can finish projects without a care to the time of day, where they physically are at that moment or the weather outside. I live just outside Philadelphia, where the snow can be deep sometimes, especially last winter. Remote access enabled me to keep working, right after I shoveled out.
There are some distinct security benefits and drawbacks to a workforce that uses remote access, and if it is properly implemented could create a happier, and more productive workforce.
Some of the drawbacks include greater difficulty managing patches and updates, and the opening of a portal through the firewalls into the heart of the organization. And although it is completely necessary to let systems administrators connect remotely for maintenance and administration, this is where the greatest security hole is, when someone with intrinsic back door access connects to critical machines.
For benefits, the workforce is enabled to work with more flexibility for time to time, and will often spend more hours working than if they were in the office every day. The company can maintain a smaller office with a mobile workforce, and doesn't need to have dedicated workspace for every worker. From a security standpoint, remote access gives great resiliency in the event of a disaster, since many processes are location neutral and the workforce just needs a connection to perform their duties.
I think about the benefits from my own experience working on the road, and I'm a huge fan of properly implemented remote access.
1. Management must support the reality of workers connecting from on the road. Sometimes the amount of backlog on paperwork (virtual, of course) or other work gets so great that I would sequester myself in my office at home to catch up. If a worker can do that from home or on the road, not only will their happiness and morale improve, but so will their mobile workforce's productivity if management supports this kind of activity, and ultimately this leads to greater profits.
2. The workspace must be viable. The home worker needs to have their configuration verified by the IT department to ensure some level of security. The workspace must also be free from distractions. I have been working at home for so long now that my children leave me alone, but it took time and effort to get that aspect of remote access from home solid.
3. The security process must be included from start to finish. User verification, secure connection protocols, patch management, virus protection updates and notifications, and access control all have to be implemented and managed for successful remote access to be truly effective. What's the point of having people connect from hotels in several different cities if one of them brings havoc to your core systems.
4. Regular review must take place of the time that users spend working from home and their effectiveness. Logs of connection times can serve as great records to verify production. Most workers will not take advantage, and the ones who will are often kept in line by a procedure that keeps them on the right path.
5. Training on time management and discipline should be given on a regular basis. Most of your workers will do just fine from home, and this kind of regular support is often welcomed. I personally am a fan of tricks and tips to help me manage my time since I apply them across the board.
If properly deployed, remote access can offer some serious improvements to the lifestyles of the workers as well as great benefits to the company.

Tuesday, May 25, 2010

Virus Defense for Small Business

I still remember clearly the morning the first virus got through. It was a pain, having to hit every machine and eradicate the infection, but it was also an alarm that our network security posture had to improve immediately. That particular virus had a payload which deleted pictures, and at the time the company I was working for used pictures heavily on the sales side to help with quotes. The viruses that attack now are much more malicious, and are intended to gather information, take over your PC or network and send information back to the source. I have tracked some attacks to some former eastern bloc countries, but many times there are computers relaying information and instructions so it can appear as if the attack is a mile away.
The threat has evolved, and if you have not taken this into account when looking at your small business then disaster awaits. Not IF, but WHEN, and usually quite soon. Back when I had Comcast, I decided to hook a PC straight to the internet, without a firewall, just to see what happened. Within 10 minutes the PC was rendered unusable. I also watched, while it still worked, the probing of the machine and was amazed at how many different sources were attacking. Automated programs use lists of IP addresses for Comcast and relentlessly try passwords, ports, and various techniques to try to gain entry. If your machine were to get infected, sometimes the only thing it would do is run the automated programs and further the infection, and your PC or server just became a 'zombie.' As far as you could tell, your laptop just seems to run slower.

Basic defense against this type of attack is simple, and very cost effective.
1. Implement a firewall solution. Get a good firewall that does Intrusion Prevention (IPS) right at the edge. This allows for most attacks to be stopped before they take root. Some large companies use layers of firewalls and other techniques so that traffic is filtered several times, both entering and leaving the enterprise.
2. Implement a good Anti-virus solution on every machine in your enterprise, and make sure updates are regularly applied. Automate as much of this process as possible so that you don't have to remember to update. Many threats can be stopped before they affect you just by having up-to-date virus signatures.
3. Keep current with Microsoft patches, and other patches for your applications. Often, viruses and malware exploit vulnerabilities in code, and software manufacturers are constantly updating their programs. There are methods of automating this for any business, and this process should be regular in nature.
4. If your company has the resources, then an Intrusion Detection System (IDS) is also something to consider. These types of systems watch for threats to show up, or watch for activity that indicates a breach.
5. Educate your employees. If someone calls on the phone looking for the IT department and asks a ton of questions about your infrastructure, make sure that they don't give freely all of the information. Make sure your employees don't use their business email as their sole email for all things personal and private, and that they should not click on everything in their inbox. (people still do it!) This training needs to happen in a formalized setting, and be a part of the policy handbook, new employee training, and reiterated on a regular basis. Many, many times the virus will come in because of user error.

The cost of the IT department running around fixing the problems on every machine was just one part of that original infection. Also was the lost data and time for sales that now needed to replicate their efforts, and put together quotes based on memory or hand drawings alone. Now the threat could sneak in and take all of your customer information, credit card numbers or any of the other 100 or so proprietary types of data that you safeguard, and use that information in ways that it is not intended. Once you have been breached, and this information is leaked, then permanent damage to your business is certain. Your customers trust you, and aside from all other civil and criminal ramifications of a breach, if their information is exposed that trust will never come back. Many large name companies are no longer in existence after the scandal, because their customers took their business elsewhere.