
Saturday, November 10, 2007
Impact of NetFlow on Routers

Thursday, November 08, 2007
Must-Read Snort 3.0 Post

Tuesday, November 06, 2007
More Unpredictable Intruders

Many intruders are unpredictable.
Two posts by pdp perfectly demonstrate this:
- Bugs in cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Browser: Firefox’s DATA URL Scheme Vulnerability
- Web Mayhem: Firefox’s JAR: Protocol issues
How many of you who are not security researchers even knew that data: or jar: protocols existed? (It's rhetorical, no need to answer in a comment.) Do you think your silver bullet security product knows about it? How about your users or developers?


RNA and, from this point of enlightenment, ongoing network analysis via NSM and, ideally, ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r forms of instrumentation (logs, etc.) facilitates impact assessment. Who cares if cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sky is falling somewhere else, as reported in whatever online news story -- is your sky falling? If yes, what's cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 damage? How best can we mitigate and recover? These are cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 sorts of questions one can answer when some data is available, enabling management by fact and avoiding management by belief.
Monday, November 05, 2007
Deflect Silver Bullets

I don't mention this to criticize ISS, specifically. Racá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r, I'd like to emphasize cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 importance of proper frames of reference when considering security.
Maybe this story will help explain my point. In cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 early 1990s as a cadet at camp USAFA I took at least 14 technical classes, including math, science, and engineering subjects. These core classes are cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 reason every cadet graduates with a BS and not a BA, regardless of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 field of study. Remember, I was a history and political science double major, preparing for a career in Air Force intelligence. One of my fellow history majors asked our astronautical engineering professor why we had to sit through his class. I still remember his answer:
One day you'll meet with a defense contractor trying to sell you a new satellite system. He'll promise cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 world, saying things like "We can park that satellite right over Moscow in geosynchronous orbit to provide you imagery."
When you hear that I want you to ask "How is that possible? What is going to keep cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 satellite cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365re?"
I want you to know how to think properly about that problem, even though you may have forgotten all cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 details by cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365n.
(For those of you who forget your astronautical engineering, it's not possible to park a satellite in geosynchronous orbit anywhere except cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 equator, unless you're taking extreme measures to actively keep cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 device in place beyond what's required for normal station-keeping.)
I find that many of those performing digital security work, most generic IT managers, and nearly all nontechnical managers do not know how to think about security properly. They think it's possible to park a satellite over Moscow, Russia as easily as Quito, Ecuador. They have no conceptual framework for digital security. They are looking for digital security silver bullets even though no analog silver bullet has ever killed cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 pirates, petty bandits, organized criminals, foreign intelligence services, or any of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r threats who have plagued humanity for hundreds of years.
Sloppy thinking is our greatest vulnerability. Forget about user education; I recommend management education. Deflect silver bullets.
Bejtlich Teaching at Black Hat DC 2008 Training

Saturday, November 03, 2007
Russ McRee on Argus and NSM

Snort Report 10 Posted

Snort 2.8.0 was recently published with several features long desired by Snort veterans. These new features include IPv6, port lists, packet performance monitoring and control of actions enabled by preprocessor or decoder events. This edition of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 Snort Report provides details on IPv6 and port lists that VARs and systems integrators can use to optimize cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365ir use of cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 open source intrusion detection system.
In cá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365 next Snort Report I plan to look at ocá cược thể thao bet365_cách nạp tiền vào bet365_ đăng ký bet365r features in Snort 2.8.
Subscribe to:
Posts (Atom)