Sunday, February 26, 2012

Week 11

So much information in so little time. I decided to post a bit of the discussions we had in CYBR 610: Risk Management. It really got me thinking. I will be paraphrasing here, but several of my peers brought up some good points as to why risk management and internet security isn't really taken seriously yet.


  • Human beings are animals and won't respond until danger is eminent.
  • People buy security software and think that is enough to secure their devices
  • People assume there will be people out their to "fix" their problems when something does go wrong
  • People don't like change.
  • People like convenience and just want everything to work easily
I started thinking about it. I remember my interview with the Human Resources guy and he noticed that I was getting my Master's in Cybersecurity and he assumed the base was going to want me. It made me realize, he didn't understand what cybersecurity was. I'm not saying he's stupid, I just think he is part of the majority that thinks cybersecurity is a military or DoD thing. It's a big word that actually works from the home office to the FBI.

So, the question became, should we teach risk management and information security at the junior high and high school level? I started thinking about that and realized that risk management is already being taught in other topics such as PE and Science. In PE, kids stretch and warm up before vigorous exercise, managing the risk of injury for training on muscles that have not been warmed up. Science requires safety instruction in regards to how to handle scalpels for dissections or how to handle acid and water. 

It would make sense to put something that simple into the computer classes, I'm sure. After all, risk management or security should just be something that happens, not a separate job. It should be a habit, much like warming up before exercising or learning the importance of making sure the scalpel is properly cleaned and taking care of specimens to be dissected. Computer classes could begin in junior high with basic importance of strong passwords, Internet safety, and the importance of backing up your data. Start small and easy. As you get into the high school areas, they can do things such as assess the assets in their computer labs or even their homes to develop risk mitigation plans, showing them real world applications to risk management. 

Cybersecurity is not a national security issue. It's actually something that can be applied at home and should start in the home. The question is, how do we make people aware that security is more than just software? Again, people typically don't respond until they are the victims of ID theft or bank fraud. There is nothing telling the public that the security software they buy is good, but it's not 100%. Much like there are car mechanics that are not trustworthy, there are also computer techs that are just as dishonest. If you don't know your devices, how do you know you are getting quality repair work? And finally, what can be done, to get people to change their habits.

I would like to ask you a few questions to get you started:

  • How many passwords do you have?
  • If you only have one or two, are they used on all your accounts from banks to e-mail?
  • If your job requires your account at work to have a long and complicated password, did you write it down and put someplace that you think is hidden but could potentially still be found?
  • Is your WiFi at home broadcasting its SSID?
  • Is your WiFi password protected to allow only those who know the password onto your network?
  • Is your security software updated?
  • Are your OS patches updated?
All these are things you can fix at home to reduce your risk of attack and secure your home office. All those things are cybersecurity.

Sunday, February 19, 2012

Week 10

I don't really have much to offer in regards to links this go around except this week's reflections of the events of the past couple of weeks.

This week's assignment for CIS 608 regarded the different forms of biometric security. In doing this assignment, I realized that in the last two weeks, I have been exposed to many forms of biometric security ranging from security questions on my bank's website to taking a CBEST test. We were asked which form of biometric would be more acceptable to the average person, so to speak.

Believe it or not, we are exposed to biometric security all the time. If you don't have your ID on you when you go the bank, the bank has several standard questions for you such as the last four of your social or mother's maiden name. Unfortunately, if you are divorced, your ex-spouse knows the answers to all those questions. Which means that you need to change those questions to something that only you would know.

Another is signature recognition when you sign that schnazzy terminal at the bank. I don't feel this is accurate because I can't sign that stupid thing anyways and my signature never matches my driver's license. Not to mention, forgery was a problem with checks, why would that be any different?

In the recent weeks, I got hired on to the local school district. One of the requirements was for me to be fingerprinted by Live Scan. That wasn't too painful, although the machine can be picky in regards to your fingerprints and if your finger slides, you have to do the whole thing over again. But it was handy and I was glad to find out that my Information Warfare research and resulting paper did not put me on the terrorist list for the FBI or Department of Justice!

Finally, I was asked to take the CBEST because the school district wanted to know if I would be a substitute teacher. Sure. I visited Pearson VUE to take the CBEST. When I got there, they took my picture, and then had my right palm scanned, left palm scanned, right palm scanned again, and the left palm scanned again. What was wild was that I could not carry my phone in with me to the testing area (OK, smart phones, I can see that) and they kicked my husband out of the building!!!! My phone and water bottle were placed in a locker in the lobby. When I went into the testing station, they checked my driver's license and then scanned my palms again. If I wanted to take a break (the test is almost 5 hours long), then I would show my driver's license and scan my palm again to exit the testing area. I was not allowed to use my phone or anything electronic. When I went into the testing center, I would have to show ID again and scan my palms again. Oh! and I was being video and audio recorded which really sucked because tests make me nervous and my stomach was making a whole lot of noise (hence my need for the water bottle which I was denied)!!!!

Anyways, when I finished the test, I was escorted out of the testing area, showed ID, scanned my palm, got a copy of the unofficial test scores, went to the front desk, scanned my palms again and was released.

Who would have thought that taking a test was SOOOO serious and required so much security!!!!!

It really made me ponder, if security is this tight for a test, what would be like working for the government! HOLY COW!!!

Monday, February 6, 2012

Week 9

This week, I got to post a blog for CYBR 610: Risk Management taught by Ronald Woerner aka "Coach." Some of the articles I found, I thought would be appropriate here. The EC-Council is recommending that CISOs change how they do risk assessments by "wargaming" and  the Financial Times state that organizations are still blind to the importance of information security. I have included a link to the EC-Council's White Paper regarding wargaming below. Enjoy.

In one of Coach's blogs, he mentioned that 2011 was the "Year of the Breach" and as risk management professionals, we should do what we can to make 2012 the "Year of Security" (Jan 4, 2012). However, according to Financial Times, that may be easier said than done (Risk Managers' Uphill Task).

"The importance of risk management will increase in 2012, said more than 90 per cent of risk managers in a survey, but the biggest challenge they have is demonstrating the value of risk management."

This means that if you are in risk management or information security, you are simply an adviser. In reading "IT Risk: Turning Business Threats Into Competitive Advantage, the authors stated that risk management is not just one department's job, but should be integrated into the organizational culture of an organization so it is merely part of the job. The Financial Times seems to agree:

"The risk managers agreed the single most important development for risk management would be a change in organizational cultures that led to a better defined risk appetite."

Another article also stressed the importance of CISOs to impress on their organizations that security is no minor concern (EC-Council Encourages CISOs To Adopt A New Risk Management Process To Prevent Information Security Breaches).

"The damage created by the highly publicized security breaches in 2011 has many Chief Information Security Officers (CISOs) seeking alternative ways to create strategies to manage risk. A new risk management process called Business Wargaming will help the CISO forecast future scenarios and build better proactive and reactive strategies."

Business wargaming allows a CISO to not only prevent the most common breaches, but enables the CISO to predict and prevent future breaches. This is because with the new technology such as smart phones, iPads, Cloud technology, and such, the conventional way of risk management is no longer as effective.

Want to know more about wargaming? Click here: Wargaming For Chief Information Security Officers.

While it may take some upper management outside the realm of IT some convincing that information security is as important as customer satisfaction and sales, the one thing that I have run into isn't that kind of apathy, but rather ignorance of information security all together.

When working with Sears, the owner didn't even know that information security existed and became the victim of refund fraud. During a recent job interview, I was almost not hired because the interviewer thought that cybersecurity was for organizations like the military and DoD and thought the base would snatch me up. He did not know that cybersecurity was for everyone from the PC at home to government top secret classified information.

Perhaps information security's worst enemy is ignorance, not apathy. One thing is for sure, both is a recipe for disaster for any organization. It's our job to hit these organizations with the 2 x 4 of truth before the 2 x 4 of reality hits. We do this by closing the language barrier and segregation of positions. Upper management needs to be tightly connected to IT and IT tightly connected to upper management so that security becomes an organizational culture. While they are connected, they can both focus on the same objective of that organization, but instead of competing for resources, they become cohesive and aiming at the same objective in their own ways.

References:

Grene, Sophia. (2012, February 4). Risk Managers' Uphill Task. Retrieved from http://www.ft.com/cms/s/0/8926d1b0-4e5b-11e1-aa0b-00144feabdc0.html

PRWeb. (2012, February 6). EC-Council Encourages CISOs To Adopt A New Risk Management Process To Prevent Information Security Breaches. Retrieved from http://www.prweb.com/releases/prweb2012/2/prweb9169249.htm

Westerman, George and Hunger, Richard. (2007). IT Risk: Turning Business Threats Into Competitive Advantage. Boston, Massachusetts: Harvard Business School Press

Thursday, February 2, 2012

Week 8

Another crazy week. I have finally figured out that when you have family, ALWAYS expect emergencies, particularly when you are busiest! Which means, I will soon be duct taping my youngest son up to prevent any more "Superman" accidents.

It's funny how people associate Information Security with hacking, viruses, hard drive crashes, and other such crazy disasters. Not many associate it with politics. As the Internet expands in how it is used, it was only a matter of time before politics got involved. After taking the Information Warfare class, I seriously began to ponder about if physical war would become obsolete. Will  World War III be conducted by buttons and joysticks in a virtual battleground? Over where I live, they are conducting many experiments on unmanned airplanes and stuff.

On top of it all, there are laws being passed left and right. One set protects privacy, another states that privacy only creates a national security risk. It's enough to drive a person insane!

In Letter To Congress, Google Defends Privacy Changes

In case you don't know, sites like Google.com, Facebook, Myspace, and other social networks and search engines are watching you. They track what you say on your updates, what your likes and dislikes are, and what you search on a regular basis. They are collecting data on your surfing habits. This allows for the sites to put up ads that you might be interested in. It also creates privacy issues as sometimes that information is sold to third parties which could inundate you with lots of spam.

Google is changing its privacy policies which has people in an uproar. Google claims that the privacy of their users will still be protected and the same data that was collected before would be the same after the new policies are implemented, but others aren't quite sure. Remember, Google is still being sued for their packet sniffing in the States of unprotected WiFi routers in private homes. Internet privacy still is yet to be determine.

Let's face it, the minute you log in, you might as well be naked to the world. Because in Cyberspace, privacy is nonexistent.

My next story I kind of found amusing. For me it was a no brainer. Information is currency. The more information you get, the more money you can make. It was about time the creators of malware started their own business! Zeus Trojan for sale! Come and get it!

For 'Malware as a Service' Merchants, Business Is Booming

Bet you were wondering where those Script Kiddies were getting their hacking software from, huh?

They are malware merchants; in the business of helping others steal from legitmate businesses and innocent consumers. And they have evolved to the point where they operate much like the legitimate software industry. It is possible to buy malware from what amounts to an app store, or to contract for Malware as a Service (MaaS). 
 Well, shoot, if they are being that open about it, why aren't they getting caught? Well, apparently, most of the people selling these services are using an "Onion Router." Not knowing what the heck that is, I decided to hit the button on the article and it took me here:

Researchers Show How Attackers Can Crack Onion Router

With that in mind, the only to get caught is if you honk them off and they tell on you...or your typical adage, "No honor among thieves."

Pretty interesting stuff.



Monday, January 23, 2012

Week 7

I am getting an early start. I am doing a midterm project for Risk Management, so this is one of the assignments I am getting behind me so I can focus on my midterm.

I found this article interesting:

Supreme Court: GPS Tracking Needs Court Warrant

A GPS was installed on a suspect's car and that data was used as evidence to convict a man of drug trafficking. Because it was installed on private property and there was no warrant obtained, the Supreme Court ruled that such collection of data on a person's vehicle is considered a violation of the 4th Amendment. The Department of Justice (DoJ) argued that the suspect had "no reasonable expectation of privacy" because the suspect drove his Jeep on private roads. It did not convince the Supreme Court.

Which kind of reminds me of Google's lawsuit regarding packet sniffing and sniffing packets on unsecure WiFi signals.

Going through several classes and meet many different students all over the country/world has been a fun experience. However, I noticed that some of my classmates talked about a database called Oracle. Until attending Bellevue, I had never heard of the software. I am very familiar with Access, but what is Oracle? In my job hunts, I have also noted that some employers would like potential employees to be familiar with Oracle. Hmmm...ok.

So, if you know anything about Oracle or you work for an organization that uses Oracle, you might be interested in this article:

The Oracle Flaw: Clarifications and More Information

Apparently, there is a bug in the System Change Number (SCN).

The patch will indeed prevent a database from accepting an elevated SCN that could cause that database to hit the soft limit during normal processing and cause problems ranging from lost transactions to a database shutdown. But it may also interfere with normal operations if the calling database has an elevated SCN acquired through a bug or other means. This means that a database with a sufficiently elevated SCN may not be able to link with patched databases until enough time has elapsed to push its SCN below the new, second limit.
Sounds pretty gnarly and with more and more companies using Oracle for their databases, this could quickly become a serious problem that CIOs need to address before it ends up costing organizations a lot of money.

Depending on time constraints, I may add more for Week 7, particularly if I find something really interesting.

Well! I did find something interesting!!!

How To Prevent Thumb Drive Disasters

For such a small device, the plastic, handheld USB flash drive can cause big security headaches. 
Because of the security risks involved with USB flash drives, it has been suggested that an organization should go around and 

Use clear silicone caulk and fill every USB port on every PC to prevent USB attachments.

That's...ummm...pretty severe! But perhaps necessary. Everyone is tempted to "personalize" their computers at work. Makes it "their own" at the job. However, when you bring in those personal photos or MP3 music from home and your computer is not virus free, this can create a huge problem in the workplace. There is also the point that in the private sector (military does not allow USB thumb drives and has already sealed the ports), USB drives are sometimes vital when an employee needs to do their job.

The articles gives four examples as to how organizations are dealing with USB thumb drives. But the author makes this point at the end that unless you seal your USB ports:

Whether the chosen security approach is to allow only one approved thumb drive, prompt users for the reasons they need to copy data, allow only Microsoft Office transfers, or classify files for approved transfers, each technique addresses one simple reality: Employees will use thumb drives, and they will find ways to continue using them.
I couldn't have said it better myself.


Sunday, January 22, 2012

Week 6

In researching for Information Security Training Programs, I found this website because one of the sites had a hyperlink to it. Of course, since the topics piqued my interest, I did more searching and found these two articles:

Government Engineers Actively Plan For Cyberwar

and

Managing Information Security In An Innovation Void

A while back, I did some research on RFID and found the information rather disturbing. I was excited for the find and posted it on the same forum that I mentioned. Of course, there are always people that will tell you that you are paranoid and the sky is not falling.

While this is not about RFID, Cyberwar is just as touchy a subject but the word gives it a menacing feel. Is the government overreacting?

In doing research for CIS 610: Information Warfare, I found that China has been our biggest attacker in regards to cyberwarfare and it has been that way for years.

If governments start launching large-scale electronic responses to attacks, such as unleashing viruses and worms meant to neutralize an attack, or conducting denial-of-service attacks designed to knock adversaries offline, enterprises had better brace for the potential for collateral damage. "Once released, no one really knows what the impact could have on certain systems and networks," [says Pete Lindstrom].
 This goes back to last week's blog. While viruses are used to "fix" what other viruses "broke", it is only a matter of time before those "helpful" viruses are turned to cause more problems. The thing is, with this article being written just a few days ago, hasn't our government been working on these years to prepare for cyberwar? Isn't that why President Obama wanted to institute an "Internet Kill Switch"? Is our country, our government, prepared for a cyberattack that is inevitable? Will we be defeated in Cyberspace or conquer in Cyberspace?

The second story I chose was based on its title only. Security management in an innovation void? The phrase innovation void is what got my attention. I had to read it just to see what the article was talking about!

Peter Kuper says,

 In 2012 we will see an increase in network intrusions from disparate parties trying to create IT infrastructure chaos for a variety of reasons primarily political, financial and economic. An easy prediction perhaps given the trend and yet while I fully trust CSOs and CISOs and security teams are doing all they can to prevent breaches; I am deeply concerned that they still lack the technology to adequately protect IT infrastructure from malicious attacks.
  That's a pretty bold statement. After all, isn't installing patches for their OS and updating their security software enough? He further explains,
There are several reasons for this state of unpreparedness. Budget constraints certainly continue to be an issue even as the U.S. economy plods along in recovery mode. However, the more disconcerting limiting factor is beyond the direct control of infosec executives:the scarcity of innovation in the information security industry.
 Ok, budget constraints I can buy, but "scarcity of innovation"? I'm not sure about that. However, he redeems himself with me when he states that we should be innovators of our own security. I can buy that.

Resources such as The Honeynet Project  offer challenges that help us think outside the box when it comes to security. After all, our attackers are doing whatever they can to either make money or to take over. This means, that we have to outhink them and we can only do that if we utilize the tools that others make available to us to allow us to do that.

Another site is Hackers Thirst which is a site used at educating people on how to make their systems more secure.

Finally, just because you attend a DEF CON conference, doesn't make you an evil hacker. While hackers of the malicious kind do attend, such conferences help educate people involved in Information Security regarding various techniques. Also, it helps to be a hacker to understand how to prevent your system from being hacked. The next DEF CON conference is July 26 - 29. I intend to be there!!!

Sunday, January 15, 2012

Week 5

You wanna know what makes me really grouchy? When government thinks it can control or fix anything and everything. This seems to further expand on last week's blog.

I listen to Air 1 every morning and Thursday morning I heard it announced that President Obama wants to create Internet ID. Seriously??? So, I looked it up and found it here:

Obama Eyeing Internet ID for Americans


Grrrr.

Inter-agency rivalries to claim authority over cybersecurity have existed ever since many responsibilities were centralized in the Department of Homeland Security as part of its creation nine years ago. Three years ago, proposals were circulating in Washington to transfer authority to the secretive NSA, which is part of the U.S. Defense Department.
So, now we have government agencies bickering about who's going to be in charge of this project, people screaming the private sector should be in charge of the project, and I'm trying to figure out who to thwap with my large trout.

Last week, I talked about Martin Libicki's these that Cyberspace cannot be conquered. This is because ti cannot be owned by anyone. He lists four reasons why Cyberspace cannot be conquered or owned.


  1. Cyberspace is a replicable construct. 
  2. To exist in cyberspace, your interactions must be recognized there.
  3. Some aspects of cyberspace nevertheless tend to be persistent (ie mathematics)
  4. Cyberspace has separate layers, the conquest of each of which has vastly different meaning
Let's face it, what is the point is wasting time with such a silly (and expensive project at the taxpayers dollars) project? 

Also, while Iran has similar applications (why are we even considering such an idea from a country like THAT!?), this is because Iran and even China has limited access to certain areas of the Internet already. Is this one step closer to controlling information???

On a lighter note, Symantec is being sued. Apparently, someone has created a new phrase for certain type of software called "scareware" where a reputable company "scans" your computer and tells you how badly your computer is infected and then you buy their product to fix it. Apparently, some dude didn't like being scared! 


Sometimes you just have to shake your head and laugh and the silliness of people. 

Gross' beef with Symantec involves the free scans conducted by PC Tools Registry Mechanic, PC Tools Performance Toolkit and Norton Utilities.
He was tricked into paying about $30 to correct the issues that the scans revealed, even though the lawsuit alleges the scans didn't really check for anything, and the resulting product he bought served no purpose.
All I have to say to that is, "Dude, get a second opinion!"