Showing posts with label Musings. Show all posts
Showing posts with label Musings. Show all posts

Thursday, January 3, 2013

Incident response and insider threats

I mentioned yesterday that I was sorting out what I wanted to accomplish and where I would like to focus my activities in the coming year.  Heck knows, I am nowhere near ready to make a break and start something new or in a different direction.  However, during some of my free time (walking the pooch or driving to work) I've had a chance to mull over additional areas of this niche in computer security. 

One area that fascinates me to no end is the management of the insider threat to the organization.  And I think, to some degree, I want to move into an area where I have the ability to help mitigate and protect from that threat.  By doing so, I'll get to leverage my passion for incident response and to some extent, digital forensics.  At least, it is something to look forward to.

I noticed a post go through my blog reader today that the CERT Insider Threat team released another great resource.  I've just downloaded it:  The Common Sense Guide to Mitigating Insider Threats, 4th edition.  I haven't read it yet (I think I saw it is 144 pages.)  I'll get on it shortly.  But, if it is like their book, The Cert Guide to Insider Threats, then I'm sure it will be great.

Something else that is somewhat nagging at me is that I know my technical skills are starting to slip.  (Heck, many many years ago, my first coding forays were in COBOL, I don't know how much I could write in that language.)  I know that the DFIR community works a lot in Perl and Python.  I had started to teach myself Python early last year, but without having an active project to work on, I find that I can't keep the skills sharp.  So, I plan to remove rust, and get myself as technical as practical.

Finally, one of the tools I really want to get better aquainted with is the Security Onion, a tool that I think has plenty of value for incident responders, and network defenders in general.  I just saw today in a post that version 12.04 has been released.

Wednesday, January 2, 2013

A new year

Happy New year!

I wanted to call out the top posts of the years, and maybe throw in some other cool stats.  But I can't figure out how to see my stats for just the calendar year.  I see week, month, and all-time options.  I just want year.  If you know how to get those stats, leave it in the comments.

I'm sure it is going to be a busy year in the IA world.  The DoD is always changing, and we seem to be picking up new clients and ACA offices to work with.  So, I'm sure that there will be new DoD/IA posts in the future.

My passion still lays in the IR/Forensics realm, and I hope to get into that realm full-time in the future.  How that will happen remains to be seen.  And, in the DFIR realm, I'm looking to focus more on one aspect.  The DFIR space has been expanding over the last couple of years, there is so much more to do than there used to...so I'm looking for something to get more specialized.  I like timeline analysis, I log log analysis; but there are other areas that while I'm not the most proficient in them, it's something I'd like to try.  So, as the new year progresses I'll try to update where I'm going.

May you realize your hopes and dreams in the new year....and you're not spending all of your time fighting the bad guys.

Monday, October 11, 2010

SCAP-based process

It's been a while since I posted anything.  For one, we were waiting for the fiscal year to end to see what proposals we would be awarded.  Two, after weeks of slowness, I just got back from a big audit.  It was interesting because it was as if they did not want us there.  We were holed up in a back conference room, our contacts went out of their way to ignore us, and we found lots of different machines/technologies/platforms that we were not expecting.  (At least, they didn't tell us about them before we got there.)  I know, shocking.  I don't know if it is because they don't want to pay for more work, or they are just ignorant about their network.  Granted, there was virtually no documentation, and we STILL do not have a network diagram.

While working this contract, we are working on updating our testing process.  I don't think it is a secret that DISA is getting out of the business of producing Gold Disks.  Personally, I think they want to get out of the tool development process all together.  I foresee DISA maintaining the STIGS and requirements, but I do not see them developing tools to test those requirements.  To that end, we've been working on how we will test those controls in the future; and we're looking at SCAP-based products.  We'll see how this goes.

Thursday, December 31, 2009

Looking forward to the new year

I don't usually prognosticate or give thoughts about plans for the new year. I don't make New Years resolutions. However, since I have some time today, I thought I would organize some thoughts for the new year. They're not necessarily in any order, just the order that I thought of them.

1. I'd really like to grow my business. Especially in the forensics arena. It's what I love. I like the IR side, but I want to to grow the forensics business.

2. I think I'll be busy with the government side of work. I like it; and I've embraced the DoD, and I think I'm finally figuring out all the DoD regs. Whatever that means, I can count on the regs changing. I have a great boss there, and I work with a great team. But, I'd be lying if I said I wouldn't want to work in a federal capacity doing forensics. Something like the FBI. But, it would take a lot to move me in that direction.

3. I suspect I'm going to have to take the CISSP. I really don't have anything against it, it's just not a cert that I'm really thrilled to get.

4. I don't think the threatscape will change, I suspect it will only get "worse." And in that regard, I suspect that all of us, as IT Security warriors will stay busy and challenged through out the year.

Happy New Year!

Thursday, October 8, 2009

CSI

It's one of my favorite shows; and I've seen every episode. But, I think the actions of Mr. Nick Stokes and Ray Langston might not hold up in court. Not grabbing volatile memory might be forgiven and certainly isn't a crime. But it certainly might have garnered more evidence. However, actually using the computer while imaging the drive seems to me to be a bit more egregious.

I know, it's just a show. And the plot has to move to fit the hour timeslot. But still. It's a little tough to watch the obvious gaffes. I'm sure the other forensic professions see the issues particular to their discipline.

Sunday, April 19, 2009

To do, to do....

I haven't written much lately. Partly, I haven't had the time. As I've alluded to, I've been busy on a huge project; working to help certify applications that are moving from the local fort to wherever they are going. It is very time consuming because there just are not enough resources to run the project smoothly. My manager decided to hire a bunch of employees to help with the workload. Not a bad idea, except they are all new to the security field. (One guy has his CISSP, yet has never worked in a security domain, and has ZERO security experience.) I believe it is just a case of the company bidding on a contract that would bring in much revenue without really thinking about how we would accomplish it. (And, one of the tools that is central to our testing is not the best; I almost say it's not ready for prime time; and it is not one of ours.)

So, we're continuously behind the proverbial eight-ball. Working long hours. And dealing with clients that are less than enthusiastic to have us there.

But then, I've been thinking of going in a different direction. Forensics has been the siren song in my head for a very long time. It's part of the reason that I left the old company; I wanted to work in computer forensics on my own. (To say nothing of the LACK of security at my old job.) Where I'm at now does not have a forensics group. They don't have an incident response group. Besides the IA we perform, there is a small group that does commercial testing, more of a pen-testing group.

What to do? What to do?

If I move towards forensics I could attempt to push forensics into the company. But, are their DoD engagements where they would need CF? Or, do I push to create a forensics group that would be internal to the company and only serve the company? Is there even a need? (I suspect "yes", but would it get funded? The ultimate question.) Or, do I start casting an eye elsewhere?

And, further at issue, I should really make a push for the CISSP. I'm not really a huge fan of it. Not that it is a bad certification. If I stay in the company I'm at, I'll probably need it sooner or later as the DoD somewhat worships it. But does it align with MY goals? I'm not sure. It certainly wouldn't hurt.

You could say I'm Lost In The Flood. At least Bruce has been putting on some great shows.

Writing is therapeutic. I might scribble some more in order to clearly think about my options, goals, and ambitions.