Last week at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 RSA Conference, I spoke to several vendors about cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir challenges offering products and services in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security arena. One mentioned a problem I had not heard before, but which made sense to me. The same topic will likely resonate with security researchers, academics, and developers.
The vendor said that his company needed access to large amounts of realistic computing evidence to test and refine cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir product and service. For example, if a vendor develops software that inspects network traffic, it's important to have realistic network traffic on hand. The same is true of software that works on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 endpoint, or on application logs.
Nothing in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 lab is quite cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 same as what one finds in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 wild. If vendors create products that work well in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 lab but fail in production, no one wins. The same is true for those who conduct research, eicá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r as coders or academics.
When I asked vendors about cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir challenges, I was looking for issues that might meet cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 criteria of Allan Friedman's new project, as reported in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Federal Register: Stakeholder Engagement on Cybersecurity in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Digital Ecosystem. Allan's work at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Department of Commerce seeks "substantive cybersecurity issues that affect cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 digital ecosystem and digital economic growth where broad consensus, coordinated action, and cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 development of best practices could substantially improve security for organizations and consumers."
I don't know if "realistic computing evidence" counts, but perhaps ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365rs have ideas that are helpful?
Tweet
Thursday, April 30, 2015
Tuesday, April 28, 2015
Will "Guaranteed Security" Save cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Digital World?
Thanks to a comment by Jeremiah Grossman on LinkedIn, I learned of his RSA talk No More Snake Oil: Why InfoSec Needs Security Guarantees. I thought his slide deck looked interesting and I wish I had seen cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 talk.
One of his arguments is that security products and services lack guarantees, "unlike every day 'real world' products," as shown on slide 3 at left.
The difference between cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 products at left and those protected by security products and services, however, is that security products and services are trying to counter intelligent, adaptive adversaries.
Jeremiah does include a slide showing multiple "online security guarantees" for financial services. Those assets do indeed face challenges from cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sorts of adversaries I have in mind. I need to hear more about what Jeremiah said at this point, and also I need to learn more about this individual guarantees.
It may be useful to look at what physical security companies offer by way of guarantees. I did not see this angle in Jeremiah's slides, although he may have talked about it.
Taking a tentative step in this direction, I visited cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 ADT web site. You've seen cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir ads for protecting homes, and you might even be a customer. This is cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sort of company that faces at least some threats who are intelligent and/or adaptive. What guarantees does ADT offer?
The screen capture below shows cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 answer. I am particularly interested in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 "Theft Protection Guarantee."
Can you imagine cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 equivalent conditions for a digital security service or product? Could you imagine a customer being able to prove it met cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 requirements?
It would be interesting to see how many times ADT has paid out this guarantee money.
Wait, you might say, Jeremiah showed a car in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 slide at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 top of this post. What do car security guarantees look like? I'm glad you asked. Here's one of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 top results I found online, for Viper.
Here is cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 fine print:
"Qualifications:
The qualifying system was sold, installed, and serviced by an authorized dealer for DIRECTED, remains in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 car in which cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 system was originally installed, and owned by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 original purchaser of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 qualifying system. Window decals must have been in place on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 vehicle at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 time of installation.
The cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft occurred less than one year after cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 date of purchase of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 qualifying Viper system.
This GPP claim is made within sixty (60) days of settlement of your claim with your insurance carrier. (90 days in New York state)
The warranty registration card was completely filled out and mailed to DIRECTED within 10 days of purchase.
The vehicle was stolen as a result of alarm system failure and cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 automobile was not left in an inactive/disarmed mode for whatever reason, even if left at a service station.
A police report must be filed and a copy submitted with your GPP claim.
Vehicle must be insured against cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 time vehicle was stolen.
The insurance company must accept and pay cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 claim.
A DIRECTED starter kill device must have been installed on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 vehicle and cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sales receipt must show starter kill installation.
Your claim MUST meet all of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 criteria as stated above to be eligible to file a claim for reimbursement of your comprehensive deductible...
A product's warranty is automatically void if its date code or serial number is defaced, missing, or altered. GPP does not cover vandalism, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft of vehicle parts, contents, damage to vehicle and/or towing charges. Furcá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365rmore, vehicles that are consigned or displayed for sale are not covered by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 GPP program. GPP is not available to employees, agents, friends or relatives of Directed or of its dealers.
GPP does not extend to or cover motorcycles or vehicles without lockable doors, ignition systems and/or engine compartments." (emphasis added)
Again, I ask, can you imagine cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 equivalent conditions for a digital security service or product? Could you imagine a customer being able to prove it met cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 requirements?
Given cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se examples of security guarantees in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 physical work, I don't think we will see much progress in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 digital world, perhaps beyond paying insurance deductibles.
I believe cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 heavy work on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 economic side will be done by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 insurance companies, as is indicated by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se physical security examples.
We are likely to see more insurance on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security vendor side, as we are already seeing (as noted in Jeremiah's talk) much more insurance in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security consumer (enterprise) arena.
Quick addendum: It just occurred to me that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security services mentioned earlier are primarily means to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 following:
Tweet
One of his arguments is that security products and services lack guarantees, "unlike every day 'real world' products," as shown on slide 3 at left.
The difference between cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 products at left and those protected by security products and services, however, is that security products and services are trying to counter intelligent, adaptive adversaries.
Jeremiah does include a slide showing multiple "online security guarantees" for financial services. Those assets do indeed face challenges from cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sorts of adversaries I have in mind. I need to hear more about what Jeremiah said at this point, and also I need to learn more about this individual guarantees.
It may be useful to look at what physical security companies offer by way of guarantees. I did not see this angle in Jeremiah's slides, although he may have talked about it.
Taking a tentative step in this direction, I visited cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 ADT web site. You've seen cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir ads for protecting homes, and you might even be a customer. This is cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sort of company that faces at least some threats who are intelligent and/or adaptive. What guarantees does ADT offer?
The screen capture below shows cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 answer. I am particularly interested in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 "Theft Protection Guarantee."
A cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft protection guarantee is like a "hack prevention guarantee." As you can see, if your home is burglarized while under ADT monitoring, you get up to $500 paid toward your insurance deductible.
The fine print is even more interesting:
"The Customer presenting ADT with this ORIGINAL CERTIFICATE will be eligible to receive a reimbursement of up to five hundred dollars ($500) of Customer’s homeowner’s insurance deductible (if any) if, and only if, ALL of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 following requirements are met to ADT’s reasonable satisfaction:
(i) cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 property loss was cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 result of a burglary that took place while cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security system installed at Customer’s protected premises was in good working order and was “on,” and while all of Customer’s doors and windows were locked; and
(ii) cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 intruder entered cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 residence through a door, window or ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r area equipped with an ADT detection device, and such detection device was not “bypassed”; and
(iii) Customer is not in any way in default under cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 ADT Residential Systems Customer’s Order; and
(iv) Customer files a written claim with cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir homeowner’s insurance company, and such claim is not rejected or ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365rwise contested by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 insurer; and
(v) Customer reports cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 burglary loss to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 appropriate police department and obtains
a written police report; and
(vi) Customer provides ADT with copies of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 insurance claim report, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 police report within six
ty (60) days of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 property loss and proof of settlement by insurance carrier; and
(vii) Customer certifies in writing to ADT (by signing this ORIGINAL CERTIFICATE and presenting it to ADT within sixty [60] days of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 property loss) that all of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 foregoing requirements have been satisfied.
Customer understands that presentation of this ORIGINAL CERTIFICATE signed by Customer is required and understands that ADT reserves cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 right to reject any application for reimbursement that does not comply with ALL of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 requirements." (emphasis added)
It would be interesting to see how many times ADT has paid out this guarantee money.
Wait, you might say, Jeremiah showed a car in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 slide at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 top of this post. What do car security guarantees look like? I'm glad you asked. Here's one of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 top results I found online, for Viper.
Here is cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 fine print:
"Qualifications:
The qualifying system was sold, installed, and serviced by an authorized dealer for DIRECTED, remains in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 car in which cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 system was originally installed, and owned by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 original purchaser of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 qualifying system. Window decals must have been in place on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 vehicle at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 time of installation.
The cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft occurred less than one year after cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 date of purchase of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 qualifying Viper system.
This GPP claim is made within sixty (60) days of settlement of your claim with your insurance carrier. (90 days in New York state)
The warranty registration card was completely filled out and mailed to DIRECTED within 10 days of purchase.
The vehicle was stolen as a result of alarm system failure and cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 automobile was not left in an inactive/disarmed mode for whatever reason, even if left at a service station.
A police report must be filed and a copy submitted with your GPP claim.
Vehicle must be insured against cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 time vehicle was stolen.
The insurance company must accept and pay cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 claim.
A DIRECTED starter kill device must have been installed on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 vehicle and cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sales receipt must show starter kill installation.
Your claim MUST meet all of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 criteria as stated above to be eligible to file a claim for reimbursement of your comprehensive deductible...
A product's warranty is automatically void if its date code or serial number is defaced, missing, or altered. GPP does not cover vandalism, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft of vehicle parts, contents, damage to vehicle and/or towing charges. Furcá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365rmore, vehicles that are consigned or displayed for sale are not covered by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 GPP program. GPP is not available to employees, agents, friends or relatives of Directed or of its dealers.
GPP does not extend to or cover motorcycles or vehicles without lockable doors, ignition systems and/or engine compartments." (emphasis added)
Again, I ask, can you imagine cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 equivalent conditions for a digital security service or product? Could you imagine a customer being able to prove it met cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 requirements?
I believe cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 heavy work on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 economic side will be done by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 insurance companies, as is indicated by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se physical security examples.
We are likely to see more insurance on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security vendor side, as we are already seeing (as noted in Jeremiah's talk) much more insurance in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security consumer (enterprise) arena.
Quick addendum: It just occurred to me that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 security services mentioned earlier are primarily means to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 following:
- Decrease insurance premiums.
- Deter attackers.
- If deterrence fails, increase cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 changes of more rapid police response.
These ideas have some relevance in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 digital security world, although I think "stickers" saying "protected by product X and service Y" may have cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 opposite effect, as cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y may give intruders ideas on how to bypass cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 defenses. Then again, that might already happen with cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 house and car alarm examples.
Tweet
Monday, April 13, 2015
Example of Chinese Military Converging on US Military
We often hear of vulnerabilities in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 US military introduced by net-centric warfare and a reliance on communications network. As cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Chinese military modernizes, it will introduce similar vulnerabilities.
I found anocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r example of this phenomenon courtesy of Chinascope:
PLA Used its Online Purchasing Website for its First Online Purchase
Written by LKY and AEF
Xinhua reported that on, April 7, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA announced that five manufacturers won cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 bidding, totaling 90 million yuan (US$14.48 million), to supply general and maintenance equipment to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA. The article said that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se were cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 first purchase orders that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA received since it launched its military equipment purchasing website in January. The site is at http://www.weain.mil.cn/.
The PLA claimed that it saved close to 12 million yuan (US$1.93 million) compared to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 list price. The purchase order consisted of items such as containers for maintenance equipment and tools, gas masks, carrier cases, and army field lighting. The article said that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA equipment purchasing website was launched on January 4. On February 25, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA General and Maintenance department made a public announcement on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 website calling for bids. On March 19, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 public bidding was held at Ordnance Engineering College in Shijiazhuang City of Hebei Province.
Over 20 manufacturers submitted bids and 5 of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365m, including some privately owned companies, won cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 bidding.
Source: Xinhua, April 12, 2015
http://news.xinhuanet.com/info/2015-04/12/c_134143641.htm
(emphasis added)
You can imagine cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sorts of opportunities this story presents to adversaries, including impersonating cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Chinese Web site, phishing eicá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r party (supplier or purchaser), and so on.
I expect ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r militaries to introduce similar vulnerabilities as cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y modernize, presenting more opportunities for cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir adversaries.
Tweet
I found anocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r example of this phenomenon courtesy of Chinascope:
PLA Used its Online Purchasing Website for its First Online Purchase
Written by LKY and AEF
Xinhua reported that on, April 7, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA announced that five manufacturers won cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 bidding, totaling 90 million yuan (US$14.48 million), to supply general and maintenance equipment to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA. The article said that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365se were cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 first purchase orders that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA received since it launched its military equipment purchasing website in January. The site is at http://www.weain.mil.cn/.
The PLA claimed that it saved close to 12 million yuan (US$1.93 million) compared to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 list price. The purchase order consisted of items such as containers for maintenance equipment and tools, gas masks, carrier cases, and army field lighting. The article said that cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA equipment purchasing website was launched on January 4. On February 25, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 PLA General and Maintenance department made a public announcement on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 website calling for bids. On March 19, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 public bidding was held at Ordnance Engineering College in Shijiazhuang City of Hebei Province.
Over 20 manufacturers submitted bids and 5 of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365m, including some privately owned companies, won cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 bidding.
Source: Xinhua, April 12, 2015
http://news.xinhuanet.com/info/2015-04/12/c_134143641.htm
(emphasis added)
You can imagine cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sorts of opportunities this story presents to adversaries, including impersonating cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Chinese Web site, phishing eicá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r party (supplier or purchaser), and so on.
I expect ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r militaries to introduce similar vulnerabilities as cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y modernize, presenting more opportunities for cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir adversaries.
Tweet
Network Security Monitoring Remains Relevant
Cylance blogged today about a Redirect to SMB problem found in many Windows applications. Unfortunately, it facilitates credential cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ft. Steve Ragan wrote a good story discussing cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 problem. Note this issue does not rely on malware, at least not directly. It's a problem with Microsoft's Server Message Block protocol, with deep historical roots.
(Mitigating Service Account Credential Theft on Windows [pdf] is a good paper on mitigation techniques for a variety of SMB problems.)
Racá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r than discussing cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 technical problem, I wanted to make a different point. After reading about this technique, you probably want to know when an intruder uses it against you, so you can see it and preferably stop it.
However, you should be wondering if an intruder has already used it against you.
If you are practicing network security monitoring (described most recently in my newest book), cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365n you should already be collecting network-based evidence of this attack.
Whenever you see a discussion of a new attack vector, you will likely think "how do I stop it, or at least see it?"
Don't forget to think about ways to determine if an attacker has already used it against you. Chances are that certain classes of intruders have been exercising it for days, weeks, months, or perhaps years before it surfaced in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 media.
PS: This post may remind you of my late 2013 post Linux Covert Channel Explains Why NSM Matters.
Tweet
(Mitigating Service Account Credential Theft on Windows [pdf] is a good paper on mitigation techniques for a variety of SMB problems.)
Racá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r than discussing cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 technical problem, I wanted to make a different point. After reading about this technique, you probably want to know when an intruder uses it against you, so you can see it and preferably stop it.
However, you should be wondering if an intruder has already used it against you.
If you are practicing network security monitoring (described most recently in my newest book), cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365n you should already be collecting network-based evidence of this attack.
- You could check session data and infer that outbound traffic on using traditional SMB ports like 139 or 445 TCP are likely evidence of attack.
- You could review transaction data for artifacts of SMB traffic, looking for requests and replies.
- Best of all, you could review full content data directly for SMB traffic, and see exactly what happened.
Whenever you see a discussion of a new attack vector, you will likely think "how do I stop it, or at least see it?"
Don't forget to think about ways to determine if an attacker has already used it against you. Chances are that certain classes of intruders have been exercising it for days, weeks, months, or perhaps years before it surfaced in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 media.
PS: This post may remind you of my late 2013 post Linux Covert Channel Explains Why NSM Matters.
Tweet
Sunday, April 12, 2015
Please Support OpenNSM Group
In August 2014, Jon Schipp started cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Open (-Source) Network Security Monitoring Group (OpenNSM). Jon is a security engineer at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 National Center for Supercomputing Applications at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 University of Illinois at Urbana-Champaign. In his announcement on cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 project's mailing list, Jon wrote:
The idea for this group came from a suggestion in Richard Bejtlich's most recent book, where he mentions it would be nice to see NSM groups spawn up all over much like ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r software user groups and for cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 same reasons.
Network security monitoring is cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 collection, analysis, and escalation of indications and warnings to detect and respond to intrusions. It is an operational campaign supporting a strategy of identifying and removing intruders before cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365y accomplish cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir mission, cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365reby implementing a policy of minimizing loss due to intrusions. At cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 tactical and tool level, NSM relies on instrumenting cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 network and applying hunting and matching to find intruders.
Long-time blog readers know that I have developed and advocated NSM since cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 late 1990s, when I learned cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 practice at cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Air Force Computer Emergency Response Team (AFCERT).
I am really pleased to see this group holding weekly meetings, which are available live or as recordings at YouTube.
The group is seeking funding and sponsorship to build a NSM laboratory and conduct research projects. They want to give students and active members hands-on experience with NSM tools and tactics to conduct defensive operations. They outline cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir plans for funding in this Google document.
I decided to support this group first as an individual, so I just donated $100 to cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 cause. If you are a like-minded individual, or perhaps represent an organization or company, please consider donating via GoFundMe to support this OpenNSM group and cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir project. You can also follow cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365m @opennsm and Facebook, and check out cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir notes at code at GitHub. Thank you!
Tweet
Subscribe to:
Posts (Atom)