Archive for May, 2009

Modifying Conciliatory Stance, South Korea Pushes Back Against the … – New York Times

Sunday, May 31st, 2009

MiamiHerald.com
Modifying Conciliatory Stance, South Korea Pushes Back Against the
New York Times, United States
South Korea has also lobbied China and Russia to take a unified stance against the North, and supported calls at the United Nations Security Council for new sanctions. The assertive moves by South Korea's right-leaning and generally pro-American
Video: Gates: N. Korea Nukes a Grave Threat The Associated Press
Eyes Are on North Korea As Journalists Go on Trial Wall Street Journal
US, allies prepare for tougher response to N.Korea Reuters
The Associated Press - Boston Globe
all 5,860 news articles

Brief: U.S. issues revised e-voting standards

Sunday, May 31st, 2009

U.S. issues revised e-voting standards

Information Security Incident Rating

Sunday, May 31st, 2009


I’ve been trying to describe to management how close various individual information assets (primarily computers — desktops, laptops, etc.) are to the doomsday scenario of sensitive data exfiltrated by unauthorized parties. This isn’t the only type of incident that worries me, but it’s the one I decided to tackle first. I view this situation as a continuum, rather than a “risk” rating. I’m trying summarize the state of affairs for an individual asset rather than “model risk.”

In the far left column I’ve listed some terms that may be unfamiliar. The first three rows bear “Vuln” ratings. I list these because some of my businesses consider the discovery of a vulnerability in an asset to be an “incident” by itself. Traditional incident detectors and responders don’t think this way, but I wanted to include this aspect of our problem set. For these first three rows, I consider these assets to exist without any discoverable or measurable adversary activity. In other words, assets of various levels of vulnerability are present, but no intruder is taking interest in them (as far as we can tell).

The next four rows (Cat 6, 3, 2, 1) should be familiar to those of you with military CIRT background. About 7 or 8 years ago I wrote this Category Descriptions document for Sguil. You’ll remember Cat 6 as Reconnaissance, Cat 3 as Attempted Intrusion, Cat 2 as User Intrusion, and Cat 1 as Root/Admin Intrusion. I’ve mapped those “true incidents” here. These incidents indicate an intruder is taking interest in a system, to the degree that the intruder gains user or root level control of it. In the event the intruder doesn’t need to gain control of the asset in order to steal data, you can simply jump to the appropriate description of the event in the final three rows.

The final three rows (Breach 3, 2, 1) are what you might consider “post exploitation” activities, or direct exploitation activities if no control of the asset is required in order to accomplish the adversary’s data exfiltration mission. They loosely map to the reinforcement, consolidation, and pillage phases of compromise I outlined years ago. I’ve used the term “Breach” here to emphasize the seriousness of this aspect of an intrusion. (Gunter’s recent post Botnet C&C Participation is a Corporate Data Breach reinforced my decision to use the term “breach” in situations like this.) Clearly Breach 3 is a severe problem. You might still be able to avoid catastrophe if you can contain the incident at this phase. However, intruders are likely to quickly move to Breach 2 and 1 phases, when it’s Game Over.

If there has to be an “impact 0″ rating, I would consider that to be the absence of an information asset, i.e., it doesn’t exist. Any asset whatsoever has value, so I don’t see a 0 value for any existing systems.

At the other end of the spectrum, if we have to “crank it to 11,” I would consider an 11 to be publication of incident details in a widely-read public forum like a major newspaper or online news site.

I use the term “impact” in this sense: what is the negative impact of having the individual asset in the state described? In other words, the negative impact of having an asset with impact 1 is very low. We would all like to have assets that require an intruder to apply substantial effort to compromise the asset and exfiltrate sensitive data. At the other end of the spectrum we have the “game over” impact — the intruder has exfiltrated sensitive data or is suspected of exfiltrating sensitive data based on volume, etc. Even if you can’t tell exactly what an intruder exfiltrated, if you see several GBs of data leaving a system that houses or access sensitive data, you can be fairly confident the intruder grabbed it.

I listed some sample colors for those who understand the world in those terms.

I’ve reproduced the text below for future copying and pasting.

  1. Vuln 3 / Impact 1 / Intruder must apply substantial effort to compromise asset and exfiltrate sensitive data
  2. Vuln 2 / Impact 2 / Intruder must apply moderate effort to compromise asset and exfiltrate sensitive data
  3. Vuln 1 / Impact 3 / Intruder must apply little effort to compromise asset and exfiltrate sensitive data
  4. Cat 6 / Impact 4 / Intruder is conducting reconnaissance against asset with access to sensitive data
  5. Cat 3 / Impact 5 / Intruder is attempting to exploit asset with access to sensitive data
  6. Cat 2 / Impact 6 / Intruder has compromised asset with access to sensitive data but requires privilege escalation
  7. Cat 1 / Impact 7 / Intruder has compromised asset with ready access to sensitive data
  8. Breach 3 / Impact 8 / Intruder has established command and control channel from asset with ready access to sensitive data
  9. Breach 2 / Impact 9 / Intruder has exfiltrated nonsensitive data or data that will facilitate access to sensitive data
  10. Breach 1 / Impact 10 / Intruder has exfiltrated sensitive data or is suspected of exfiltrating sensitive data based on volume, etc.

What do you think of this rating system? I am curious to hear how others explain the seriousness of an incident to management.


Richard Bejtlich is teaching new classes in Las Vegas in 2009. Regular Las Vegas registration ends 1 July.

Top 4 Tips to Fight Off Botnet Denial of Service Attacks

Sunday, May 31st, 2009

In case you haven’t been paying attention Botnet DDoS attacks passed the 40 Gigabits/sec mark in 2008 according to Arbor Networks. The shear size of today’s Botnets has reached into the mind-boggling realm of 1.9 million bots in a single Botnet. Couple that with the fact that Botnet DDoS attacks are one of the hardest assaults to defend against and you have a real nightmare scenario on your…

ASEAN leaders meet amid tight security – Inquirer.net

Sunday, May 31st, 2009

Washington Post
ASEAN leaders meet amid tight security
Inquirer.net, Philippines
SEOGWIPO, SOUTH KOREA—South Korea imposed heavy security on Sunday for a summit with Southeast Asian leaders following North Korean nuclear and missile tests that frayed nerves across the region. The summit was planned months ago, but North Korea's
Video: Gates: N. Korea Nukes a Grave Threat The Associated Press
US, allies prepare for tougher response to N.Korea Reuters
South Korea, Thailand criticize North over tests The Associated Press
Boston Globe - San Francisco Chronicle
all 5,950 news articles

Iran Beefs Up Security Ahead Of June 12 Elections After Bombing … – AHN

Sunday, May 31st, 2009

Earthtimes (press release)
Iran Beefs Up Security Ahead Of June 12 Elections After Bombing
AHN
Tehran, Iran (AHN) – Iran has beefed up security after officials defused a home-made bomb found in a toilet on a domestic passenger plane on Sunday, just 12 days ahead of the nation's crucial elections. The flight, carrying 131 passengers,
Iran foils plane bomb plot Tehran Times
Bomb found on plane Gulf Daily News
Iranian officials defuse bomb in plane toilet AFP
CNN International - The Associated Press
all 457 news articles

NYC temples to get security upgrade grants – Newsday

Sunday, May 31st, 2009

NY1
NYC temples to get security upgrade grants
Newsday, NY
NEW YORK – The two synagogues targeted in a bombing plot this month will be able to improve their security thanks to federal grants. Gov. David Paterson announced Sunday the Riverdale Temple and the Riverdale Jewish Center in the Bronx will each
Grants For Security For Synagogues Targeted In Terrorists Plot Hudson Valley Press
Bronx Synagogues To Get Security Upgrade Grants New York’s PIX11 / WPIX-TV
Targeted Synagogue, Jewish Center To Receive Security Grants NY1
all 18 news articles

Peace, co-op issues dominate Asia Security Summit – Xinhua

Sunday, May 31st, 2009

Boston Globe
Peace, co-op issues dominate Asia Security Summit
Xinhua, China
SINGAPORE, May 31 (Xinhua) — The eighth Asia Security Summit, also known as the Shangri- La Dialogue, concluded here Sunday with defense ministers and senior officials from 27 countries calling for peaceful and cooperative solutions toward security
Asians talk of peace, haggle over arms Reuters
Asia-Pacific security summit ends CCTV
Gates Delivers Keynote Address to Open Asia Security Conference Elites TV
VOVNews.vn - Xinhua
all 49 news articles

Central Africa: Regional Security Better – UNSC – AllAfrica.com

Sunday, May 31st, 2009

ONU (Communiqué de presse)
Central Africa: Regional Security Better – UNSC
AllAfrica.com, Washington
Kigali — Following a week-long official visit to Africa by the United Nations Security Council representatives, the delegation has announced that regional security has improved. "From all the meetings in the Democratic Republic of the Congo and the
Central Africa: Peace in Great Lakes Region – Time for a Paradigm AllAfrica.com
all 13 news articles

Burma, Other Asian Nations Defend Security Actions – Voice of America

Sunday, May 31st, 2009

Voice of America
Burma, Other Asian Nations Defend Security Actions
Voice of America
By Daniel Schearf Burma has defended its prosecution of democracy leader Aung San Suu Kyi at an Asian security summit in Singapore. Delegates to the summit have urged her release along with 2000 other political prisoners in the military-ruled country.

New Utah school district may opt out of Social Security – Salt Lake Tribune

Sunday, May 31st, 2009
New Utah school district may opt out of Social Security
Salt Lake Tribune, United States
By Kirsten Stewart and Christopher Smart Talk that the new Canyons School District may opt out of Social Security has stirred up more questions than answers about the risks and benefits to employees. As the new district considers its options,
Setting Social Security straight gains urgency Dallas Morning News
5/31 SOCIAL SECURITY: New workers: Know your SSN number Lufkin Daily News
Social Security Q&A: If you lose your card, don't forget number NewsOK.com
OregonLive.com - fwdailynews.com
all 13 news articles

Informant's role questioned in US security probes – Reuters

Sunday, May 31st, 2009
Informant's role questioned in US security probes
Reuters
By Edith Honan NEW YORK (Reuters) – The arrests of four men in a suspected plot to bomb two New York synagogues have drawn fire from critics who say US law enforcement relies on informants who infiltrate extremist groups that otherwise would be

FACTBOX-Palestinian security forces in the West Bank – Reuters

Sunday, May 31st, 2009

Times Online
FACTBOX-Palestinian security forces in the West Bank
Reuters
May 31 (Reuters) – A raid on a Hamas hideout on Sunday by forces loyal to Palestinian President Mahmoud Abbas followed White House talks last week at which the Western-backed leader won praise for security steps in the occupied West Bank.
Video: 6 Dead in Battle With Hamas, Palestinian Police The Associated Press
6 Die as Palestinian Authority Forces Clash With Hamas New York Times
Police raid sparks West Bank clash Aljazeera.net
Ha’aretz - Jerusalem Post
all 661 news articles

US, allies prepare for tougher response to N.Korea – Reuters

Sunday, May 31st, 2009

Telegraph.co.uk
US, allies prepare for tougher response to N.Korea
Reuters
By Bill Tarrant SINGAPORE (Reuters) – The United States and its Asian allies could look at tougher responses should diplomacy fail to get North Korea to abandon its nuclear program, officials at a security conference said at the weekend.
Video: Gates: N. Korea Nukes a Grave Threat The Associated Press
South Korea, Thailand criticize North over tests The Associated Press
US and China must stand up to N. Korea Boston Globe
San Francisco Chronicle - The Hill
all 5,713 news articles

Global security challenges need networked solutions: British official – Xinhua

Sunday, May 31st, 2009

Reuters
Global security challenges need networked solutions: British official
Xinhua, China
SINGAPORE, May 31 (Xinhua) — The global security challenges that the world is facing place a greater reliance on networked solutions at all levels, a British official said here on Sunday. Speaking at the 8th Asia Security Summit (Shangri-La Dialogue),
Asians talk of peace, haggle over arms Reuters
Gates Delivers Keynote Address to Open Asia Security Conference Elites TV
Asia Security Summit ends CCTV
Philippine Star - Straits Times
all 41 news articles

FACTBOX-Security developments in Iraq, May 31 – Reuters

Sunday, May 31st, 2009
FACTBOX-Security developments in Iraq, May 31
Reuters
HASWA – A roadside bomb struck a car and killed the driver and wounded three others on Saturday near a police station in Haswa, 50 km (30 miles) south of Baghdad, police said. SAMARRA – A roadside bomb targeting a police patrol killed two policemen and

Iranian officials defuse bomb in plane toilet – AFP

Sunday, May 31st, 2009

ITV.com
Iranian officials defuse bomb in plane toilet
AFP
TEHRAN (AFP) — Iranian security officials defused a bomb planted on a domestic passenger plane, officials said on Sunday, the latest incident of violence ahead of next month's presidential election. The attempted bomb attack occurred on Saturday on a
Iranian officials defuse bomb found on plane CNN International
Iran: Guards Foil Hijack Attempt on Plane FOXNews
Bomb found in toilet on Iran plane BBC News
Ynetnews - Fars News Agency
all 194 news articles

Setting Social Security straight gains urgency – Dallas Morning News

Sunday, May 31st, 2009
Setting Social Security straight gains urgency
Dallas Morning News, TX
By BOB MOOS / The Dallas Morning News Social Security has some grim news for John Ansbach of Dallas and other members of Generation X. If the system continues on its current course, it won't have enough money to pay full benefits by the time they
Working senior may repay $250 Social Security bonus Orlando Sentinel
5/31 SOCIAL SECURITY: New workers: Know your SSN number Lufkin Daily News
Social Security Q&A: If you lose your card, don't forget number NewsOK.com
The Plain Dealer – cleveland.com - OregonLive.com
all 20 news articles

Access to Top-Secret Papers at Issue in Wiretapping Case – Washington Post

Sunday, May 31st, 2009

PRESS TV
Access to Top-Secret Papers at Issue in Wiretapping Case
Washington Post, United States
The department cited national security concerns for its position. Its filing said that President Obama has authorized access to classified information on a "need-to-know" basis, and argued that the government "cannot be sanctioned for its determination
Obama Administration Refuses to Turn Over Warrantless Wiretapping AllGov
Obama Justice Department Continues Bush's 'State Secrets' Argument ABC News
Gov't refuses to release documents in wiretap case The Associated Press
The Washington Independent - CNN
all 260 news articles

US and China must stand up to N. Korea – Boston Globe

Sunday, May 31st, 2009

Washington Post
US and China must stand up to N. Korea
Boston Globe, United States
The key to moving beyond the current impasse is coordinated action by the United States and China in the Security Council and beyond. Washington holds what Pyongyang most wants and China has the most direct leverage on North Korea.
Video: Gates: N. Korea Nukes a Grave Threat The Associated Press
UN vs. North Korea – only time will tell San Francisco Chronicle
Gates: NKorea nuke progress sign of `dark future' The Associated Press
AFP - Focus News
all 5,625 news articles