Friday, March 16, 2007

Way to Go Joanna

I briefly met Joanna Rutkowska at Black Hat Federal 2006 when she spoke about rootkits. Today I saw she was interviewed by Dark Reading and said cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 following:

Still, she worries that security technology and research is too prevention-oriented and doesn't emphasize detection enough. "The whole industry is focusing on prevention, and we have all those anti-exploitation technologies, which are very helpful indeed. But I'm so surprised that no one cares about detection," she says. "Every time cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re's prevention, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re is some bypass method" created.

Without detection, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re's no way to know if an attacker has grabbed administrative access to a machine, she says. And if you can't see that an attacker has infiltrated cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 system, nothing in that system will be "reliable" anymore. "The scary part is that once an attacker [gets] into cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 system, we can't reliably read system memory, neicá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r using software-based, nor hardware-based, methods. That means we can't answer cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 question of whecá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 system is clean or not," she says.
(emphasis added)

Wow. I am so pleased to read someone of Johanna's caliber stressing cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 need for detection. I have been working on slides for ShmooCon and I plan to talk about this very subject, and you probably know I've been saying for years that prevention eventually fails. Her comment about reliability of evidence relates to my TaoSecurity Pyramid of Trust, where I mentioned Johanna with respect to her techniques to defeat memory capture.

4 comments:

Joanna Rutkowska said...

:)

Anonymous said...

What would be necessary for prevention to succeed? A macá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365matically complete and closed system perhaps? Since cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re are none around, perhaps that is why cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y are going to eventually fail?

H. Carvey said...

In both my first book as well as my soon-to-be-released book ("Windows Forensic Analysis" from Syngress), I make cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 point that incidents will happen and that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re is a need for training in basic troubleshooting and IR methodologies in order to accurately identify and categorize (hello, FISMA!?!) an incident. I've seen too many cases where a virulent worm rampages across a network, and because cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 IT staff has limited training, knowledge, time and ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r resources, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 common reaction is to proclaim defeat at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 hands of a rootkit.

Now I know Joanna is most likely stating this from cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 point of view of commercial applications, which in itself answers cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 question of "why aren't we seeing detection"? And from cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 perspective of most users/IT shops, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 push is for vendors to produce prevention products, because that means once something's prevented, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 incident is done and over with, and no more work is required. Any detection product is going to point you to a problem, requiring additional time and resources to investigate. Until senior management starts taking security and IR more seriously, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re won't be a push for detection.

Harlan
http://windowsir.blogspot.com

Anonymous said...

I saw here in Hack in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Box in Kuala Lumper last year!

http://hackathology.blogspot.com/