Thursday, January 26, 2012
Thinking About Vectors
I find it interesting how most clients ask me to help them write reports or alerts to monitor their enterprises for various different threats. This is, of course, to be expected in my line of work. What I often ask them is "What vectors into (and out of) the enterprise are you concerned with/do you want to monitor for?" Clients often find this to be a surprising question, but when you think about it, the question isn't really all that surprising. The most advanced analytic, the fanciest report, or the coolest detection technique aren't worth much if they aren't relevant to the enterprise they're being applied to, right?
It's important to conceptualize and understand what it is you'd like to monitor for based on the vectors into (and out of) the enterprise you're concerned with. Once that is done, implementing those concepts is usually fairly straightforward. That's all well and good, but what if you don't know what vectors you ought to be concerned with? To that, I say, know your network! Study and analyze the data transiting the network and let it guide you towards an understanding of the vectors you might want to concern yourself with.
Wednesday, January 11, 2012
Boiling The Ocean
Boiling the ocean is one of my favorite phrases. As the phrase connotes, boiling the ocean is a process that will likely never converge to success, nor end. I am reminded of this phrase as I attend FloCon this week. The vast majority of people I work with professionally understand the need to make compromises and accept some imperfections in order to make progress operationally. In my experience, operational progress, though often imperfect, still leads to improved network security monitoring and security operations in infinitely more cases than taking a "boil the ocean" approach. In other words, an 80% solution at least gets you 80% of what you want and need, while waiting for everything to be 100% perfect will always get you nowhere. There are a few in attendance at FloCon for whom the compromises that operational personnel must make is lost on them. I can't think of a way to show them the other side, other than to put them in an operational environment for a year (or perhaps longer)....
Tuesday, January 10, 2012
And Then What?
I am at FloCon this week and enjoying the conference tremendously. I always enjoy FloCon, as it's a unique opportunity to catch up with peers in the community. It's also a great place to learn about different techniques and methods that people are using to analyze network security data.
There was a presentation this morning from US-CERT that discussed some interesting analytical work US-CERT is currently doing. The presentation described some of the architecture, systems, processes, and procedures that US-CERT is using to perform analysis of various different types of data. The presentation was interesting, but it made me ask the question, "and then what?". All that analysis is great, but at the end of the day practitioners (like myself) need actionable intelligence and information that we can use to defend the networks we are responsible for. Unfortunately, we're not getting much in the way of actionable information and intelligence from US-CERT. As our national CERT, this is disappointing.
My intention here is not to pick on or harass the analysts who work hard in service of our nation day in and day out. Rather, I'm hoping that the leadership in our government, and particularly the leadership within DHS will get a clue sometime soon. If I had a minute with the leadership I would ask them why they can't find some way to cut through the bureaucratic red tape and share information with a nation (and world) so desparate for it. After all, the security of our nation's most critical infrastructure depends on it, right?
Analysis is great, but I am reminded this morning that analysis is not for analysis' sake. Analysis should serve some productive end, namely producing actionable information and intelligence for those who so desperately need it. Come on DHS -- get with the program.
Friday, December 23, 2011
SOC/IRC Building
Over the last decade, I've had the privilege to help build multiple different Security Operations Centers (SOCs)/Incident Response Centers (IRCs). This is a line of work that I'm truly passionate about and have had a good amount of success in. The good news is that this skill appears to be moving from a niche line of work to a more mainstream endeavor. I see this as a tremendous positive for the world -- proper network security monitoring and a successful SOC/IRC are an integral part of helping organizations combat the security threats of today. Onward!
Time
Time is an extremely interesting concept analytically. It's a dimension that's often overlooked when performing network traffic analysis. On this blog, I've discussed the concept of looking for anomalous or unexpected traffic/behavior on an enterprise network quite a bit. But what about traffic that may be completely normal/expected at 14:00 on a weekday, but not at 02:00 on a Sunday? By considering the dimension of time analytically, one can look for normal traffic that because of the time window it occurs in is considered abnormal.
Consider the example of the administrative assistant who sends emails and calendar invites (amidst performing a variety of other tasks) all day long. If we study the mail logs, there is nothing particularly interesting or unusual about this. But what if that same administrative assistant sends a bunch of emails and calendar invites between 02:00 and 03:00 on Sunday? Perhaps he/she is dedicated and catching up on work while dealing with a bout of insomnia. Or, perhaps he/she is about to become a pawn in a spear phishing campaign that will await targeted personnel when they arrive to work Monday morning....
Consider the example of the administrative assistant who sends emails and calendar invites (amidst performing a variety of other tasks) all day long. If we study the mail logs, there is nothing particularly interesting or unusual about this. But what if that same administrative assistant sends a bunch of emails and calendar invites between 02:00 and 03:00 on Sunday? Perhaps he/she is dedicated and catching up on work while dealing with a bout of insomnia. Or, perhaps he/she is about to become a pawn in a spear phishing campaign that will await targeted personnel when they arrive to work Monday morning....
Tuesday, November 22, 2011
Money Shot
Finding the money shot is key to successfully containing an emerging threat. What do I mean by the money shot? That would be the point at which the point of no return is passed in a security incident. In most malicious code incidents, this is where a binary reaches a system (via HTTP download, email, or some other means) and successfully executes. It's fairly common nowadays to see 2, 3, 4, or more re-directs from one compromised or malicious site to another before finally reaching the money shot. But trying to keep up with blocking/containing all the stage 1, stage 2, etc. re-direct domains is an exhausting and futile process. On top of that, it's an extremely false positive prone undertaking that could have a fair bit of collateral damage as well (in terms of blocking traffic necessary for business operations). Focus on the money shot first. That's where the most containment bang for the buck is to be found. It's the only chance we as practitioners have at keeping up with the ever-changing landscape. It's all about the money shot.
Message Clarity
Message clarity is a common sense concept that, unfortunately, is not always so common. In the practice of network security monitoring, clearly communicating a simple and straightforward message is often necessary in order to conduct proper security operations. In other words, clearly communicating and leveraging data about new tactics, infection vectors, indicators of compromise, command and control channels, and other important data can help organizations successfully contain and remediate new campaigns, rather than falling victim to them.
I've so often seen cases where the message is garbled or over-complicated (for whatever reason -- be it a lack of knowledge, lack of communication skills, or some other reason). This helps no one. I've often been told that one of my greatest strengths is being able to clearly and effectively communicate what I find through detailed analysis in an easy to understand manner. There is elegance in simplicity -- I firmly believe that. And an elegant, clear, concise, and simple message can often facilitate network security monitoring and security operations.
I've so often seen cases where the message is garbled or over-complicated (for whatever reason -- be it a lack of knowledge, lack of communication skills, or some other reason). This helps no one. I've often been told that one of my greatest strengths is being able to clearly and effectively communicate what I find through detailed analysis in an easy to understand manner. There is elegance in simplicity -- I firmly believe that. And an elegant, clear, concise, and simple message can often facilitate network security monitoring and security operations.
Subscribe to:
Posts (Atom)
