Wednesday, December 22, 2010
Time to Reflect
Things have slowed a bit around the workplace of late. It's kind of nice, as it gives me a chance to reflect. Yesterday, I was thinking about how far the network monitoring/network traffic analysis community has come in the past decade. Ten years ago, large portions of the information security community were content to implement signature-based detection methods and believe they were covered. Nowadays, people en masse are awakening to the reality that the traffic transiting a network needs to be examined with an analytical eye. This is a wonderful thing, as us die hard analysts can now share our passion with an audience that is ready to hear the message.
Tuesday, October 26, 2010
Abusing Standards
This morning I presented at the Techno Forensics conference. I had a great audience and tried to share my thoughts on analysis and network forensics with them. I think the talk went well. The audience asked some great questions on abusing IP protocol standards, which is one of my favorite artifacts to look for analytically. See, that's the nice thing about network traffic analysis -- network traffic conforms (or should conform) to IETF standards. Looking for cases when it doesn't (for example, TCP packets of less than 48 bytes) can turn up some very interesting finds!
Wednesday, September 22, 2010
Truth
The past few days I've been pondering what truth is. This may seem like an odd thing to think about. If you really think about it though, how often do we know what absolute truth is in a situation? Unfortunately, not often. This is the case in both the analog and digital worlds. We are only as good as our data in the digital world. Over the course of my career, I've seen situations where the data tells a very bizarre story, only to be found later to have been collected in error.
Thursday, September 2, 2010
More Proxy Fun
This morning I met a friend of mine for coffee. He is a bright guy and also a talented cyber security analyst. We had a good discussion on a number of different topics. At one point, we got into a discussion of blind proxying of DNS requests with no logging (an earlier topic I had blogged on). He decided to check his proxy, which was a different one than the one I had blogged about earlier (I am keeping both anonymous here). Same issue. Yup -- the proxy just blindly forwards DNS requests with no logging. I am beginning to think that this is a fairly common behavior with proxies. Have you checked yours lately?
Monday, August 30, 2010
Success
The other day, I was having a conversation with someone who used some of my jumping off points on one of the large, enterprise networks they monitor. They were shocked that the jumping off points were able to identify some truly sketchy traffic on that network (serious compromises). They said to me, "your theory really works!". To which I replied, "it's not a theory -- it's been tested and proven repeatedly." Another believer.
Monday, August 16, 2010
Elegance in Brevity
It seems to be a common misconception that in order for a solution to be value-add and useful, it must be cumbersome and complex. I'm not sure why this is, as in practice, I've found this to be quite the opposite. There is elegance -- and usefulness -- in brevity. For example, many cyber security teams struggle with what information they should share/pass around to other teams to be good netizens and collaborators. Well, for starters, why not pass around malicious domain names and malicious code MD5 hashes? True, this is not the whole kit and caboodle and doesn't tell the whole story, but if we all shared even just those two pieces of data, wouldn't we be better off as a community?
Some interesting food for thought.
Some interesting food for thought.
Monday, August 2, 2010
Spotting a True Anomaly
The other day, I was boarding an 8 AM flight with a cup of coffee (purchased after the security checkpoint) in my hand. If you've ever taken an 8 AM flight, you know that you're probably leaving for the airport around 6 AM. Wanting to take a cup of coffee on the flight with you is not such an anomaly. In other words, it's a very expected type of behavior. Nonetheless, TSA pulled me aside as I was waiting to board, in their words "because you want to board the plane with a cup of coffee, we will need to vapor test your coffee". They proceeded to hold what looked like litmus paper over the coffee. They then sprayed the paper with some clear liquid and pronounced my coffee free of harmful vapors. I was then free to board the plane.
There are few issues with this logic:
1) One is allowed to purchase liquids after the security checkpoint and bring them on board the aircraft. This is an accepted behavior that is seen frequently and has been identified as legitimate by TSA authorities. Functionally, this is a white listed behavior. So why waste precious TSA personnel cycles on it?
2) If I wanted to mix something into the coffee to produce some sort of harmful vapor, I would wait until I was on the plane to do so. Why would I waste precious vapors before boarding?
3) I could just as easily order coffee on the plane, mix something into it, and have the same effect without TSA being able to vapor test my coffee. The TSA test is easily avoided.
So, you're probably asking yourself what relevance this has to this blog? In the above example, the TSA inspector (the analyst in this example) pulled me aside for what he considered an anomalous behavior. The problem is that my behavior was routine, legitimate, widely accepted, and easily explained behavior. It wasn't a wise use of precious analyst cycles.
It works the same in the cyber realm. We need to make sure we optimize analyst workflow so that analysts spend most of their day chasing down true anomalies that have no easy explanation, aren't routine, aren't legitimate, and aren't widely accepted. There are a lot of ways to generate fruitless leads for analysts to chase down. The challenge is generating actionable, focused leads. That's where taking an analytical approach can help.
Moving back to the physical realm, I hope the good folks at TSA will take a good look at the value-add of some of these procedures. TSA personnel's time is valuable and limited. They should be focused on procedures with high value-add.
There are few issues with this logic:
1) One is allowed to purchase liquids after the security checkpoint and bring them on board the aircraft. This is an accepted behavior that is seen frequently and has been identified as legitimate by TSA authorities. Functionally, this is a white listed behavior. So why waste precious TSA personnel cycles on it?
2) If I wanted to mix something into the coffee to produce some sort of harmful vapor, I would wait until I was on the plane to do so. Why would I waste precious vapors before boarding?
3) I could just as easily order coffee on the plane, mix something into it, and have the same effect without TSA being able to vapor test my coffee. The TSA test is easily avoided.
So, you're probably asking yourself what relevance this has to this blog? In the above example, the TSA inspector (the analyst in this example) pulled me aside for what he considered an anomalous behavior. The problem is that my behavior was routine, legitimate, widely accepted, and easily explained behavior. It wasn't a wise use of precious analyst cycles.
It works the same in the cyber realm. We need to make sure we optimize analyst workflow so that analysts spend most of their day chasing down true anomalies that have no easy explanation, aren't routine, aren't legitimate, and aren't widely accepted. There are a lot of ways to generate fruitless leads for analysts to chase down. The challenge is generating actionable, focused leads. That's where taking an analytical approach can help.
Moving back to the physical realm, I hope the good folks at TSA will take a good look at the value-add of some of these procedures. TSA personnel's time is valuable and limited. They should be focused on procedures with high value-add.
Subscribe to:
Posts (Atom)
