Now that I've gotten into the groove so to speak, I can reflect on what I've seen in the new position. Here are some of the projects I'm working on.
I have started to build out a security awareness program. This program is going to focus heavily on phishing, but will also include a monthly email, a blog, and an internal site to check email addresses against data breach datasets. The monthly emails will feature a unique topic on information security as a method to educate the users. I started a blog to post information security stories that the user base can learn from and to read about non-mainstream stories. As for phishing, we'll be making heavy use of PhishMe.
I'm also starting to build a vulnerability management program. Right now, there are no internal vulnerability scans performed on the user-space. And really, from what I've seen, the external scans (performed by a managed service) are sorely lacking. For low-hanging fruit, I've purchased a Nessus license and will start working on internal assesses. I will also start working on the servers, but I know what I will find, and I know it will be very hard to change the culture of non-patching. I'm afraid of what it will take to make the changes to install a regular patch management program.
The results of my mini-gap assessment have shown me where there are many opportunities to get better. I plan on using the SANS Top 20 Controls in order clip the low hanging fruit and make improvements.
Right now my most tangible success has been the creation of a "security server" where I'll be able to stage vulnerability scans, pen tests, and other security tasks. I'm also in the process of building a "scanning" account to be used by the tools such that we should ONLY see this account used during security engagements...any other use may indicate an incident.
Finally, I'm working on information sharing. I firmly believe that the sharing of information by the Good Guys helps us combat the Bad Guys. To that end, I started working as our company's representative to one of the sharing resource centers. Down the line, I hope to get involved with Infraguard as well.
It's been a busy two months....and I only see it getting busier.
Wednesday, December 18, 2013
Tuesday, December 3, 2013
New (In)Secure Magazine
I just received notification that the new issue of (In)Secure magazine has been published.
You can get it here.
You can get it here.
Sunday, November 10, 2013
Blocking Dynamic DNS sites
Going through proxy and DNS logs, I noticed that (as a whole) the company has not been blocking sites categorized as "Dynamic DNS." I discovered this while reviewing a "security" report that lists the various site activity that would fall into the generic "security" report. Interestingly enough, no Dynamic DNS sites were blocked.
Dynamic DNS is hosting for sites that do not have static IP address. Mostly, it is used by three types of users: hobbyists who do not want to pay for a static IP address for their site; spammers and scammers; and sites that are out rightly malicious. Bot herders prefer to use Dynamic DNS sites as they can rotate servers in and out of rotation in order to make it more difficult to track down and mitigate. Further, many times the registrar information for suspicious sites is obfuscated in order to make it harder to find the owners. There is rarely a business case to allow Dynamic DNS sites.
With those points in mind, I presented the case to block all Dynamic DNS-hosted sites. If there are truly legitimate sites that users need to access, we can re-evaluate on a case-by-case basis and adjust the filters. So far, it looks like the decision has been favorable.
Dynamic DNS is hosting for sites that do not have static IP address. Mostly, it is used by three types of users: hobbyists who do not want to pay for a static IP address for their site; spammers and scammers; and sites that are out rightly malicious. Bot herders prefer to use Dynamic DNS sites as they can rotate servers in and out of rotation in order to make it more difficult to track down and mitigate. Further, many times the registrar information for suspicious sites is obfuscated in order to make it harder to find the owners. There is rarely a business case to allow Dynamic DNS sites.
With those points in mind, I presented the case to block all Dynamic DNS-hosted sites. If there are truly legitimate sites that users need to access, we can re-evaluate on a case-by-case basis and adjust the filters. So far, it looks like the decision has been favorable.
Tuesday, November 5, 2013
Learning Python post updated
Just a quick post: I've updated my post on Learning Python thanks to the great suggestions from the SANS DFIR list.
The updated post can be found here.
The updated post can be found here.
Monday, November 4, 2013
First Day
Today was a great first day, I'm glad I made the move to the new company. So far, I've learned that most of the security controls are outsourced, managed by many of the big providers. I think one of our tasks will be to aggregate data from those outsourced providers.
And, it looks like I'll get to go to my first conference, as we will be going to RSA in February. I'm psyched as I've never really gone to a security conference before.
And, it looks like I'll get to go to my first conference, as we will be going to RSA in February. I'm psyched as I've never really gone to a security conference before.
Friday, October 25, 2013
When the change was made uptown...
Actually, I work downtown. Or worked. I'm glad to say that I'm moving on. While I don't regret the time spent in my current location, the job did not work out. My co-worker said it best when she was cornered by our Vice President on why I'm leaving: "Expectations were not met." Clearly, I learned a lot while I've been here, it has been a rewarding experience. And, I'd do it again, because you learn from every opportunity. But, I could not see myself here in any number of years.
So, I'm moving on. I've taken a position where I will be building out a security department for a company. Basically, I'm on the ground floor. They have a bunch of controls in place, but very disparate, and not centrally managed. And, I'm sure when I start gap analysis, I'll find a whole lot missing. But that's ok, as there will be opportunity to grow and put a stamp on things. It will good to see the company move in a positive security direction.
Will there be challenges? I expect it. I'm sure that there will be lots of pain implementing some of the controls. And, while I know that there is (some) management buy-in (heck, they created this position) I'm sure there will be tons of operational pushback.
I hope that this means I will be posting more. Certainly, I will not be posting specifics. But, I will chronicle the process of building out security in the enterprise. I'll tell of what works and what does not. I'll post some reviews of success, and I'm sure there will be plenty of lessons learned. Finally, you will probably see posts looking for advice or recommendations.
So, I'm moving on. I've taken a position where I will be building out a security department for a company. Basically, I'm on the ground floor. They have a bunch of controls in place, but very disparate, and not centrally managed. And, I'm sure when I start gap analysis, I'll find a whole lot missing. But that's ok, as there will be opportunity to grow and put a stamp on things. It will good to see the company move in a positive security direction.
Will there be challenges? I expect it. I'm sure that there will be lots of pain implementing some of the controls. And, while I know that there is (some) management buy-in (heck, they created this position) I'm sure there will be tons of operational pushback.
I hope that this means I will be posting more. Certainly, I will not be posting specifics. But, I will chronicle the process of building out security in the enterprise. I'll tell of what works and what does not. I'll post some reviews of success, and I'm sure there will be plenty of lessons learned. Finally, you will probably see posts looking for advice or recommendations.
Monday, September 16, 2013
Feedly is the feedreader at the moment
I wanted to upgrade a post from a while ago. When Google Reader went dark, many went scurrying to find a new reader to replace the feed curation that Google Reader provided. For a while, I started using CommaFeed, which seemed to be pretty good replacement for Google Reader. The only real issue I had was that it did not seem to update as fast as other readers. I was continuously hearing about posts that I should read, only to find them in CommaFeed a day or two later. Otherwise, I really liked it, as it was SO similar to Google Reader.
However, I gave Feedly a try, and I have to say, I'm impressed. Sure, it's just a tad different from Google Reader, but it was easy enough to get the hang of it. I've been using it a couple of months now, and I really do not see myself changing. The only nag I have is that I cannot search my feeds for a particular topic/post. I do see that now with Feedly Pro, you can pay to get a couple of extra benefits. But, since I don't search the feeds "that" often, I'll wait until there is a pressing need.
However, I gave Feedly a try, and I have to say, I'm impressed. Sure, it's just a tad different from Google Reader, but it was easy enough to get the hang of it. I've been using it a couple of months now, and I really do not see myself changing. The only nag I have is that I cannot search my feeds for a particular topic/post. I do see that now with Feedly Pro, you can pay to get a couple of extra benefits. But, since I don't search the feeds "that" often, I'll wait until there is a pressing need.
Friday, September 13, 2013
Unix Antivirus software
I know, it has been a long time since I last posted. That's a post for another day. I'll get to that, but at a later date.
However, I was given a task today, and I didn't know where it would lead. Specifically, a customer wanted some information on antivirus software for Unix/Linux servers. Why I was given the task is another mystery, but it was up to me to provide an answer to the customer. (I'm not a *nix guy, I'm "ok" with it, but I don't work much in that environment.)
I fully admit, I did not know anything about the unix/linux antivirus space. But, doing some digging I learned a couple of things. There are plenty of antivirus software packages to choose from. And, they fall all over the spectrum for services. Of course, the heavy hitters of antivirus software include offerings for *nix machines. I was surprised that there were as many others as I found. Some filled specific niches, like a mail server. At least one was target ONLY to the *nix environment. Prices were all over the place, and service differed greatly depending on who you were looking at. I'm including the list below as a note so that if I have to do this research again, I'll know where to start.
F-Prot
Symantec Endpoint Protection
Cyber
Sophos
Bitdefender
McAfee
F-Secure
Software not listed here is only not listed because I did not know about it, or it did not immediately meet my customer's needs. If I blatantly missed something, leave it in the comments.
However, I was given a task today, and I didn't know where it would lead. Specifically, a customer wanted some information on antivirus software for Unix/Linux servers. Why I was given the task is another mystery, but it was up to me to provide an answer to the customer. (I'm not a *nix guy, I'm "ok" with it, but I don't work much in that environment.)
I fully admit, I did not know anything about the unix/linux antivirus space. But, doing some digging I learned a couple of things. There are plenty of antivirus software packages to choose from. And, they fall all over the spectrum for services. Of course, the heavy hitters of antivirus software include offerings for *nix machines. I was surprised that there were as many others as I found. Some filled specific niches, like a mail server. At least one was target ONLY to the *nix environment. Prices were all over the place, and service differed greatly depending on who you were looking at. I'm including the list below as a note so that if I have to do this research again, I'll know where to start.
F-Prot
Symantec Endpoint Protection
Cyber
Sophos
Bitdefender
McAfee
F-Secure
Software not listed here is only not listed because I did not know about it, or it did not immediately meet my customer's needs. If I blatantly missed something, leave it in the comments.
Monday, May 27, 2013
Testing out CommaFeed to replace Google Reader
In order to replace Google Reader, I've been looking at different platforms and companies. I had been set on migrating to Feedly until I saw this come across my desk. CommaFeed is an open source web application that comes pretty close to replicating Google Reader. Actually, it has a couple of features I did not see in Google Reader (like showing feeds that are non-existent in another color.) I'm not very social with my news, I use the reader to aggregate it for me.
So far, I'm impressed with CommaFeed; I like it a lot. The proof will come in the next couple of weeks as I put it through it's paces. This appeared to be a light weekend, without an influx of many posts; so it is tough to gauge. But we'll see. Should I move on to another reader, I'll update this post.
So far, I'm impressed with CommaFeed; I like it a lot. The proof will come in the next couple of weeks as I put it through it's paces. This appeared to be a light weekend, without an influx of many posts; so it is tough to gauge. But we'll see. Should I move on to another reader, I'll update this post.
WhiteHat Security's interview with a Blackhat
These links came through my blogreader over the last couple of days. WhiteHat Security ran an interview with a reformed/converted blackhat hacker. The interviews give a good insight as to what some companies are not doing right, and help show what should be done to tighten the defenses. Be warned, some of the language might not be work-safe.
Part 1
Part 2
Part 3
Part 1
Part 2
Part 3
Subscribe to:
Posts (Atom)