<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>seki</title>
	<atom:link href="http://www.spinlock.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spinlock.com</link>
	<description>Spinlock Technologies LLC</description>
	<lastBuildDate>Tue, 16 Feb 2010 13:29:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Measuring DNS health, security</title>
		<link>http://www.spinlock.com/2010/02/dns-health-security/</link>
		<comments>http://www.spinlock.com/2010/02/dns-health-security/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 13:20:24 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=278</guid>
		<description><![CDATA[In early February, about fifty top DNS experts, engineers and practitioners assembled at <a href="/events/2010-dns-ssr-symposium">an invitation-only symposium</a> in Japan to talk about an esoteric but significant challenge to the future of the Internet: measuring the health of the domain name system (DNS). Determining the status of critical infrastructure of any kind can be difficult, but DNS is doubly so because it is a distributed infrastructure not run by one or even a handful of operators - there are thousands of "important" DNS operators.]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-279" style="margin-right: 20px;" title="Kyoto University Logo" src="http://www.spinlock.com/wp-content/uploads/2010/02/kyodai-logo-100px.png" alt="" width="100" height="100" />In early February, about fifty top DNS experts, engineers and practitioners assembled at <a title="2nd Annual Symposium on DNS Security, Stability and Resiliency" href="/events/2010-dns-ssr-symposium" target="_self">an invitation-only symposium</a> at <strong>Kyoto University</strong> in Japan to talk about an esoteric but significant challenge to the future of the Internet: measuring the health of the domain name system (DNS), which is responsible for converting human readable names into computer-usable network addresses.  Determining the status of critical infrastructure of any kind can be difficult, but DNS is doubly so because it is a distributed infrastructure not run by one or even a handful of operators &#8211; there are thousands of &#8220;important&#8221; DNS operators.  Together with the domain name registries and registrars, they provide an important element of what makes the Internet work.<span id="more-278"></span></p>
<p>The Symposium, held during February 1-3, 2010 under the sponsorship of <a title="ICANN Security Group (opens new window)" href="http://www.icann.org/en/security/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.icann.org/en/security/?referer=');">ICANN&#8217;s Security Group</a> and <a title="Domain Name System Operations Analysis Research Center (opens new window)" href="https://www.dns-oarc.net/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.dns-oarc.net/?referer=');">DNS-OARC</a>, provided an opportunity to exchange ideas among people from all parts of the DNS community about what it means for the DNS to be &#8220;healthy,&#8221; and how the community should go about measuring its health. Co-sponsoring the symposium were Kyoto University and Nara Advanced Institute of Science and Technology.</p>
<p>According to the conference keynote speaker, Andrew Sullivan [of <a title="Shinkuro, Inc. website (opens in new window)" href="http://www.shinkuro.com/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.shinkuro.com/?referer=');">Shinkuro, Inc.</a>], one of the big challenges in defining health is that health of a large ecosystem such as a forest often supports &#8212; even encourages &#8212; locally unhealthy conditions. In other words, health is not a universal term that applies equally to all parts of a system at once; it implies a value of health that is relative to the entire system. Drawing a similar kind of parallel between the DNS and human health, many of the speakers and participants grappled with notions of measurement, privacy preservation, pattern analysis and, notably, the ongoing challenge posed by searching for unknowns in large data sets.</p>
<p>The <a title="2nd Annual Symposium on DNS Security, Stability and Resiliency" href="http://www.spinlock.com/events/2010-dns-ssr-symposium/concept-paper/" target="_self">conference website</a> contains all of the symposium background material, and will also contain the final report, due to be published in March 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2010/02/dns-health-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Responding to network attacks</title>
		<link>http://www.spinlock.com/2010/01/net-attack-response/</link>
		<comments>http://www.spinlock.com/2010/01/net-attack-response/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 18:49:40 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[information security management]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[mitigation]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=121</guid>
		<description><![CDATA[Though they&#8217;re not going away anytime soon &#8212; and every security geek in the IT department knows it &#8212; distributed denial-of-service (DDoS) attacks still cause great panic in most organizations hit by them. This being the case, it bears underscoring the importance of planning ahead so that you don&#8217;t get caught flatfooted when the next [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spinlock.com/wp-content/uploads/2010/01/20100130-ddos.gif"><img class="alignright size-medium wp-image-122" title="DDoS meets pop culture" src="http://www.spinlock.com/wp-content/uploads/2010/01/20100130-ddos-300x256.gif" alt="" width="300" height="256" /></a>Though they&#8217;re not going away anytime soon &#8212; and every security geek in the IT department knows it &#8212; distributed denial-of-service (DDoS) attacks still cause great panic in most organizations hit by them. This being the case, it bears underscoring the importance of planning ahead so that you don&#8217;t get caught flatfooted when the next attack comes, whether it&#8217;s a DDoS or something even bigger.<span id="more-121"></span></p>
<h2>1. Activate your response plan</h2>
<p>Rather than responding to the waves of panic that are likely circulating around the sales and executive teams, the most productive thing to do is to rely on your advance planning to start the response process rolling.  Remembering that the key to solving problems is usually communications, you should focus on providing company executives with regular updates. Then you can focus on the technology issues without undue badgering.</p>
<p>This is, I think, the right time to remind that one of the best antidotes to security crises is to have an computer security incident response team (CSIRT) capability.  This resource, whether in-house or contracted out, can save countless amounts of downtime. You can learn more about incident response from places like the <a title="FIRST.org (opens in a new window)" href="http://www.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.first.org/?referer=');">Forum of Incident Response and Security Teams (FIRST)</a>.</p>
<h2>2. Set up a war room</h2>
<p>When Skype suffered a major outage &#8212; which, though not a DDoS, had some of the massive but temporary service disruption characteristics of a DDoS &#8212; we set up two war rooms: one near the company executives and one in the heart of the engineering center. This kind of arrangement not only allows &#8220;the right people&#8221; to come together face-to-face, it also allows for a focal points to form for network operations, media/PR, and the executive team.  This location is focused on communication, so be sure to have redundant means at your disposal in case your chosen system (phone line, Jabber, Skype, etc.) is itself impacted by the attack.</p>
<h2>3. Think tactically</h2>
<p>Your first general priority is limiting downtime, so you have to quickly assemble the data available to you to identify the cause of the problem and its target. Work with your ISP or network peers to maximize your options within the terms of your service contract, and preferably without incurring additional costs.</p>
<p>While you can have traffic shunted or blackholed, do keep in mind that such measures as having new network addresses assigned to critical resources may likely cause lasting secondary effects, such as the invalidation of IP-bound digital certificates. For lengthy attacks, it may be worth the effort to have a plan for a temporary customer notice website, which can keep customers informed of the company&#8217;s efforts to restore service.</p>
<p>For small businesses, these kinds of services can often be arranged ad hoc, but it&#8217;s best to have a planned service with a specified DDoS service level agreement. In addition, cutover of these services may require coordination with your domain registrar or your ISP.</p>
<h2>4. Think strategically</h2>
<p>Your next general priority is preventing further downtime. This requires more thought and more research; you need to identify the rationale for the attack. In other words, why did someone target <em>your</em> infrastructure to attack today? Is there a pot of gold at the end of the attack?  Is the attack you&#8217;re experiencing merely cover for another, separate attack whose aim is to steal valuable customer data?</p>
<p>There are many possibilities here, but the point to make is that the CISO of the organization needs to be well aware not only of the technology in play, but also of the risk matrix relating to data available on the network and even things like public perception of the company. Many otherwise mundane companies have been hit by hackers or so-called hacktivists merely due to the public position of a single member of the company&#8217;s board of directors.</p>
<h2>5. Document, review and train</h2>
<p>If there&#8217;s one silver lining to an attack, it&#8217;s that the event can serve as a crucible for learning for the entire staff, including people far outside the technical teams. Take notes as the event unfolds, including the time that decisions (even mundane ones) were made. Also take time to understand the cost impact of the attack and its remediation. During a post-mortem, these notes will serve better than any cockamamie exercise could to develop better processes and procedures for the next time.  The bad news is that there probably will be a next time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2010/01/net-attack-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding business, Asian style</title>
		<link>http://www.spinlock.com/2009/07/business-asian-style/</link>
		<comments>http://www.spinlock.com/2009/07/business-asian-style/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 07:00:10 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[information security management]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[Japan]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=115</guid>
		<description><![CDATA[I gave a keynote speech at the 2009 annual conference of the Forum of Incident Response and Security Teams (FIRST) in Kyoto, Japan, that talked about my observations of Japanese business operations, highlighting the differences that become barriers to communication. This morning, I had the privilege of seeing a write-up of the talk in IT [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-119" style="margin-left: 2px;" title="No setbacks!" src="http://www.spinlock.com/wp-content/uploads/2009/07/zasetsuikenai.gif" alt="zasetsuikenai" width="132" height="132" />I gave a keynote speech at the <a title="2009 FIRST annual conference (opens in new window)" href="http://www.first.org/conference/2009/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.first.org/conference/2009/?referer=');">2009 annual conference</a> of the Forum of Incident Response and Security Teams (FIRST) in Kyoto, Japan, that talked about my observations of Japanese business operations, highlighting the differences that become barriers to communication. This morning, I had the privilege of seeing a write-up of the talk in <a title="IT Media news [Japanese] (opens in separate window)" href="http://www.itmedia.co.jp/enterprise/articles/0907/11/news003.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.itmedia.co.jp/enterprise/articles/0907/11/news003.html?referer=');">IT Media</a> that faithfully captured the entire talk. I think it&#8217;s always interesting to see how one&#8217;s own words wind up in translation; this time, though, the differences don&#8217;t seem to be very severe.</p>
<p>It was a little bit unnerving to give a talk about Japanese language and business culture to an audience that included a large number of Japanese. After all, they would all have much more experience than I do in Japanese business settings. But I tried to make the case that the differences&#8211;things that lead to misunderstandings&#8211;are extremely important, too. I was really excited to get positive feedback not only from the overseas audience, but also from the Japanese audience. That so many people enjoyed the talk made me very pleased indeed.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/07/business-asian-style/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Communication, culture and information security</title>
		<link>http://www.spinlock.com/2009/06/culture-infosec-ties/</link>
		<comments>http://www.spinlock.com/2009/06/culture-infosec-ties/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 14:12:17 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[trends]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=93</guid>
		<description><![CDATA[Since my earliest days working in Silicon Valley, I have been involved in computer security incident response management. And so it was with great pleasure that I accepted a keynote speaking opportunity at the upcoming annual meeting of the Forum of Incident Response and Security Teams (FIRST) during 28 June-3 July 2009 in nearby Kyoto, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://conference.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/conference.first.org/?referer=');"><img class="alignright size-full wp-image-94" title="2009 FIRST Conference (Kyoto, Japan)" src="http://www.spinlock.com/wp-content/uploads/2009/06/20090306-firstconfspeaker.png" alt="2009 FIRST Conference (Kyoto, Japan)" width="190" height="95" /></a>Since my earliest days working in Silicon Valley, I have been involved in computer security incident response management. And so it was with great pleasure that I accepted a keynote speaking opportunity at the upcoming annual meeting of the <a title="FIRST - the Forum of Incident Response and Security Teams" href="http://www.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.first.org/?referer=');">Forum of Incident Response and Security Teams</a> (FIRST) during 28 June-3 July 2009 in nearby Kyoto, Japan. The conference team asked if I could convey some of my observations about Japan, because I’ve been living here for just over a year now, and talk about how they relate to information security.  The talk, entitled <em>Information security: one character at a time</em> uses aspects of the Japanese language as a way to discuss the role of communication in incident handling and, more generally, in information security management.</p>
<p><span id="more-93"></span>I remember going to my very first FIRST annual conference in Monterrey, Mexico, back in 1998. At that time, I was an an official representative for Sun Microsystems to the organization and was amazed by the level of international participation. Since then, interest in computer security incident handling has grown exponentially, and therefore the breadth of the audience has become far more diverse, both in geography and in mission, than it was even ten years ago. I think that this change speaks volumes about the information security business, and I think it’s a trend to which we should pay close attention.</p>
<p>My goal for this keynote is to set out what I think incident handling will mean in the context of cultural changes in the information security handling profession. After all, even the smallest of organizations is investing — willingly or not — in response measures to security threats. In the face of the present economic downturn, it will be very interesting to see how many companies will remain interested in computer security.  But because even the most Luddite of company executives sees the risk that comes along with ignoring the perils of information security, I doubt the lights in the IT security department will be going out anytime soon.</p>
<p>If you’re in the information security industry, I highly recommend the <a title="FIRST Annual Conference" href="http://conference.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/conference.first.org/?referer=');">FIRST annual conference</a>.  If you can make it, by all means please attend!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/06/culture-infosec-ties/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Electricity Industry looking for cyberthreats</title>
		<link>http://www.spinlock.com/2009/06/nerc-searching-cyberthreats/</link>
		<comments>http://www.spinlock.com/2009/06/nerc-searching-cyberthreats/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 08:03:26 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[trends]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[smart grid]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=89</guid>
		<description><![CDATA[The electric power utility industry is planning to start looking for cyberthreats against the power grid, and especially components that would wind up being the cornerstone of the Smart Grid project. According to the article, officials at the North American Electric Reliability Corporation (NERC) are planning to start a pilot investigation of cybersecurity risks to [...]]]></description>
			<content:encoded><![CDATA[<p>The electric power utility industry is planning to start looking for cyberthreats against the power grid, and especially components that would wind up being the cornerstone of the <a title="US Department of Energy Smart Grid" href="http://www.oe.energy.gov/smartgrid.htm" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.oe.energy.gov/smartgrid.htm?referer=');">Smart Grid project</a>. According to the article, officials at the North American Electric Reliability Corporation (NERC) are planning to start a pilot investigation of cybersecurity risks to the power grid while simultaneously retaining a large defense contractor to examine the problem over a longer term.</p>
<p>Although there have been previous reports of foreign-sponsored cyber-penetration attempts against the US power grid, this initiative by NERC represents the first tangible acknowledgment of the scope and complexity of the problem.</p>
<p>The <a title="Electricity Industry to Scan Grid for Spies, WSJ (opens in new window)" href="http://online.wsj.com/article/SB124528065956425189.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/online.wsj.com/article/SB124528065956425189.html?referer=');">original article</a> is available from the Wall Street Journal online.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/06/nerc-searching-cyberthreats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The botnet peril</title>
		<link>http://www.spinlock.com/2009/03/botnet-peril/</link>
		<comments>http://www.spinlock.com/2009/03/botnet-peril/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 13:11:22 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[trends]]></category>
		<category><![CDATA[botnets]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=55</guid>
		<description><![CDATA[For as many times as we have heard that e-commerce is at risk due to the actions of sophisticated cyber-criminals, it is astounding how little has been done to protect against wholesale attacks against users and, more importantly, against the major retailers who are more and more dependent upon commercial trade over the Internet. It [...]]]></description>
			<content:encoded><![CDATA[<p class="firstLetter">For as many times as we have heard that e-commerce is at risk due to the actions of sophisticated cyber-criminals, it is astounding how little has been done to protect against wholesale attacks against users and, more importantly, against the major retailers who are more and more dependent upon commercial trade over the Internet. It is this very dependency that accounts for the high value of so-called asymmetric attacks, and today&#8217;s nemesis in this regard is the <em><a title="botnet, defined (Wikipedia)" href="http://en.wikipedia.org/wiki/Botnet" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/Botnet?referer=');">botnet</a>,</em> ad hoc confederations of unsuspecting users&#8217; computers that have been coopted by cybercriminals through the use of malicious software.</p>
<p class="firstLetter">The Hoover Institution recently published a <a title="eWMDs: the botnet peril (Hoover Institution)" href="http://www.hoover.org/publications/policyreview/35543534.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/publications/policyreview/35543534.html?referer=');">call-to-arms about botnets</a>, provocatively declaring that botnets should be called &#8220;electronic weapons of mass destruction&#8221;, given the fact that critical infrastructure can be easily put at risk by botnet operators.<span id="more-55"></span> And this point is driven home in the fact that major power and telecommunications utilities are already highly interconnected with the public Internet, thus allowing for the asymmetric leveraging of tens or hundreds of thousands of mundane home computers &#8212; via the illicit introduction of malware &#8212; into attacks on such things as <a title="SCADA, defined (Wikipedia)" href="http://en.wikipedia.org/wiki/SCADA" target="_blank" onclick="pageTracker._trackPageview('/outgoing/en.wikipedia.org/wiki/SCADA?referer=');">SCADA</a> (supervisory control and data acquisition) elements that manage critical infrastructure.</p>
<p class="firstLetter">As a case study, the article&#8217;s authors explore the case of the April 2007 cyberattack against Estonia, both in terms of what was put at risk as well as how the world should respond to such cases. Although we still find it a stretch to make the parallels with military conflicts too concrete, the point is well taken that such forms of asymmetric warfare put the advantage in the corner of the attacker, whether that attacker is a sophisticated nation-state or a ring of profiteering cyber-criminals. Both of these groups are abetted by the same lack of security on the Internet.</p>
<p class="firstLetter">Although the article is long on observation and short on prescription (aside from advocating a very active form of defence), it is a very well-reasoned summary overview of the threats that exist today on the Internet. In short, it explains why we need a call-to-arms and what might happen if we don&#8217;t heed the warning.</p>
<p class="firstLetter">
<p><em>The article entitled </em><a title="eWMDs: the botnet peril (Hoover Institution)" href="http://www.hoover.org/publications/policyreview/35543534.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/publications/policyreview/35543534.html?referer=');">eWMDs: the botnet peril</a><em> by John J. Kelly and Lauri Almann appears in </em><a title="Policy Review (Hoover Institution)" href="http://www.hoover.org/publications/policyreview/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/publications/policyreview/?referer=');">Policy Review</a><em>, No. 152, Dec. 2008/Jan. 2009 b</em>y<em> <a title="The Hoover Institution (main website)" href="http://www.hoover.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.hoover.org/?referer=');">The Hoover Institution</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/03/botnet-peril/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AREVA bug puts power systems at risk</title>
		<link>http://www.spinlock.com/2009/02/areva-scada-flaw/</link>
		<comments>http://www.spinlock.com/2009/02/areva-scada-flaw/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 11:21:46 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[product vulnerabilities]]></category>
		<category><![CDATA[SCADA]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=58</guid>
		<description><![CDATA[Critical power infrastructure is once again under threat of attack due to vulnerabilities discovered in a popular brand of SCADA equipment that is used to monitor and control power distribution. According to a string of CVE [1] notices cited in a February 2009 notice circulated by US-CERT, multiple vulnerabilities were found in the e-Terra Habitat [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-59" title="AREVA corporate logo" src="http://www.spinlock.com/wp-content/uploads/2009/03/20090311-areva-corporate-logo.jpg" alt="AREVA corporate logo" width="129" height="109" />Critical power infrastructure is once again under threat of attack due to vulnerabilities discovered in a popular brand of SCADA equipment that is used to monitor and control power distribution. According to a string of CVE [1] notices cited in a February 2009 notice circulated by <a title="US-CERT Vulnerability Note VU#337569" href="http://www.kb.cert.org/vuls/id/337569" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.kb.cert.org/vuls/id/337569?referer=');">US-CERT</a>, multiple vulnerabilities were found in the <strong>e-Terra Habitat</strong> system by the French energy products company AREVA. Habitat is a core component of its Energy Management System (EMS), the centerpiece of which is a proprietary database that stores real-time SCADA data.</p>
<p>The flaws highlighted by US-CERT include a buffer overflow, several denial of service risks and the possibility of privilege escalation.<span id="more-58"></span> These are serious enough, but once again incident response teams are faced with a challenge in finding information about remediation for the vulnerability or even a reliable point of contact at the vendor for obtaining further information.</p>
<p>According to the US-CERT circular, the flaws affect version 5.7 (and earlier) of its Habitat software, and AREVA has released a security patch that addresses the flaws. It is worth noting that the bugs are serious, allowing a knowledgable attacker to crash monitoring systems and, in the most serious instance, to execute arbitrary commands remotely, without the need for access credentials. For this reason, US-CERT highlighted the importance of network monitoring and of ensuring isolation of networks containing SCADA control and measurement components. Unfortunately, even the more security conscious of infrastructure operators is more and more likely to have planned or unplanned points of connection to public networks.</p>
<p>It is unfortunate that SCADA equipment vendors are often less than transparent about the risks in their products, for commercial reasons.  And because of the unique nature of the SCADA industry, there is far less independent and non-government-funded scrutiny of these network components. In this line of business, there seems to be an unhealthy degree of what appears to be security through obscurity.</p>
<p>Notes:<br />
[1] CVE is the <a title="CVE - Common Vulnerabilities and Exposures" href="http://cve.mitre.org/index.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/cve.mitre.org/index.html?referer=');">Common Vulnerabilities and Exposures database</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/02/areva-scada-flaw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure web site certificate vulnerability</title>
		<link>http://www.spinlock.com/2009/01/web-certificate-vulnerability/</link>
		<comments>http://www.spinlock.com/2009/01/web-certificate-vulnerability/#comments</comments>
		<pubDate>Sat, 24 Jan 2009 14:20:38 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[trends]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[PKI]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=49</guid>
		<description><![CDATA[In December 2008, a group of computer security researchers attending a security conference in Berlin gave a practical demonstration of a serious security vulnerability related to the public key infrastructure (PKI) that allows for secure web browsing used for online banking, e-commerce and other sensitive transactions. In short, they were able to show the possibility [...]]]></description>
			<content:encoded><![CDATA[<p>In December 2008, a group of computer security researchers attending a security conference in Berlin gave a practical demonstration of a serious security vulnerability related to the public key infrastructure (PKI) that allows for secure web browsing used for online banking, e-commerce and other sensitive transactions. In short, they were able to show the possibility of mimicking any website on the internet.</p>
<p>The vulnerability is tied to a cryptographic weakness related to the MD5 cryptographic hash function. The practical effects to web security based on this weakness is serious, but can be corrected by replacing vulnerable server certificates with ones not yet known to be vulnerable to attack.</p>
<p>In January 2009, Govcert.nl published a very useful fact sheet on these vulnerabilities <span id="more-49"></span>that provides both a basic primer on the problem and the pros and cons of the available remedies.  Although there is no doubt that sites using MD5 hashes need to take action, these guidelines are intended to help IT decision-makers more easily choose the best course of action available for their individual circumstances. [The following is based upon Govcert.nl Factsheet FS-2009-01, which is available from their website, and subject to a <a title="Creative Commons Attribution-Share Alike 3.0 Netherlands License" href="http://creativecommons.org/licenses/by-sa/3.0/nl/deed.en" target="_blank" onclick="pageTracker._trackPageview('/outgoing/creativecommons.org/licenses/by-sa/3.0/nl/deed.en?referer=');">Creative Commons by-sa 3.0 license</a>.]</p>
<hr />
<h2>Vulnerabilities in the Internet PKI caused by the use of MD5</h2>
<p>On 30 December 2008 a group of researchers at the &#8216;Chaos Communication Congress&#8217;, an annual security conference held in Berlin, gave a practical demonstration that the &#8216;Public Key Infrastructure&#8217; (PKI) on the internet has some serious weak spots.They demonstrated that they had been successful in creating a rogue certificate that was trusted by all common browsers.</p>
<blockquote><p><strong>An overview of the facts:</strong></p>
<p>Researchers have created a rogue certificate that can be used to impersonate any website in the world.</p>
<ul>
<li>This rogue certificate is automatically trusted by all the common browsers.</li>
<li>The researchers achieved this by making use of weaknesses in MD5, a cryptographic hash function.</li>
<li>Even though the weaknesses of MD5 have been known for many years, it is still used to sign certificates on the internet.</li>
<li>If you still make use of certificates that are signed using MD5, then you need to replace it as soon as possible.</li>
</ul>
</blockquote>
<p>In this factsheet you can read a short explanation of the research, the risks in the short term and the actions that need to be undertaken both by yourself and by other concerned parties. We conclude this factsheet with two paragraphs with background information on digital signatures, hashes, collisions and the shelf life of cryptography in general.</p>
<h3>The research in brief</h3>
<p>This research has an impact on the use of certificates to set up secure connections between a browser and a website. This concerns an &#8216;HTTPS&#8217; or &#8216;SSL/TLS&#8217; connection. Such a connection can be recognised within browsers by means of a padlock or in some cases by a coloured address bar.</p>
<p>The research demonstrates that when a certificate has been signed (or appears to have been signed) by a competent authority (a Certificate Authority or CA for short), this no longer offers any guarantee that this certificate was also verified by this authority. This means that there is no longer any guarantee that the certificate actually belongs to the correct party. In other words: in the past you had a large degree of certainty with a secure connection that you were dealing with the right website (after checking the certificate). Now it has been demonstrated that this security can be compromised by a practical attack.</p>
<blockquote><p>Certificates and secure connections</p>
<p>A certificate is the basis of two functionalities of a secure connection. These functionalities are most of all important for applications where personal or financial data are transmitted to another party, for example in the case of telebanking, egovernment services and online shopping.</p>
<ol>
<li>The encryption of data exchanged between the browser and the website. The result is that data can no longer be read by third parties.</li>
<li>The possibility of monitoring whether a connection has really been made to the correct website.</li>
</ol>
<p>The research to which we refer in this factsheet has an impact on the second function of a certificate.</p></blockquote>
<p>Because there are still CAs that sign certificates with MD5, an obsolete cryptographic method, the researchers succeeded in creating a rogue certificate that appeared to have been signed by an official Certificate Authority (a root CA). As a result this rogue certificate is automatically trusted by all common browsers. What is even worse is that the rogue certificate itself can act as a Certificate Authority.</p>
<p>As a result, the researchers are in a position to create and sign a certificate themselves for any random web server in the world, which cannot be distinguished from a real one and which is trusted automatically. They can therefore impersonate any random other party without the visitor to a website being able to discover this on the basis of the certificate.</p>
<h3>What are the risks in the short term?</h3>
<p>The researchers admit themselves that it is unlikely that another person is going to be able to implement such an attack on the internet PKI in the short term. GOVCERT.NL has also not detected any attacks at the time of writing and more or less discounts that there are already rogue certificates in circulation at this time.</p>
<p>In order to carry out such an attack one needs specialised knowledge of the weaknesses in MD5, the obsolete cryptographic method still used by some CAs for signing certificates. In addition, the researchers themselves developed methods to create a rogue certificate in a short time. They believe that the CAs in question that still<br />
make use of obsolete digital signatures will have enough time to move over to new methods.</p>
<p>In conclusion, the researchers have taken some measures to prevent the certificate they have created from being misused. The researchers have nonetheless made it known that they will eventually publish their methods, probably in a few months.</p>
<blockquote><p>If it was not already clear following the previously publicised attacks in 2005 and 2007, there is not the slightest doubt now that it is irresponsible to continue to use MD5.</p></blockquote>
<h3>Protection against vulnerability and the actions you can undertake yourself</h3>
<p>The researchers demonstrated with their research that the internet PKI contains weak spots because some CAs still make use of obsolete means of creating a digital signature. As a consequence the entire PKI is at risk, not just those persons who have dealings with the CAs in question. The following analogy will clarify this to a certain extent: if it turned out that it was very easy to obtain a real passport in a certain municipality in the Netherlands under false pretences, then that would be a problem not only for the residents of that one municipality but would also undermine confidence in the value of every passport for everyone who came into contact with passports.</p>
<p>The foregoing makes it clear that individual end users and owners of certificates can do very little to protect themselves against this vulnerability, let alone solving these. In an ideal situation the following would now happen:</p>
<ol>
<li>Every CA that still makes use of MD5 would stop doing so as quickly as possible and would migrate to a better hash function.</li>
<li>Everyone who still has a certificate that has been signed with MD5 will replace this as soon as possible (see also: ‘Replace MD5 … but with what?’ on the following page).</li>
<li>If the above two requirements are met (or that much earlier as is considered necessary), the browser vendors can withdraw support for MD5.</li>
</ol>
<p>The most important parties in the above process are the CAs and the browser vendors. CAs bear a responsibility to make use of sensible cryptographic methods on the basis of their task as a trusted organisation that is permitted to sign certificates within a PKI. It is necessary to evaluate on a regular basis whether a cryptographic method is (still) reliable. It is the case that cryptographic methods that are reliable now may not be reliable for various reasons at a later time.</p>
<p>Browser vendors can exercise a great deal of indirect influence on CAs, because they determine which certificates—and therefore also the type of certificates—they include and trust in their browsers as standard. In this way they can serve as an extra motivation. If browser makers stop supporting MD5 (the weak hash function), then this would have immediate consequences for the certificates signed using MD5 that are still in circulation. These will stop working or generate warning messages, depending on the choices made by the browser vendors.</p>
<p>All this does not mean that you should not undertake a number of actions yourself:</p>
<ol>
<li>As an end user there is almost nothing you can do to reduce the risks of this proven threat. At this time there are still so many certificates with a MD5 signature in circulation that rejecting such certificates completely is not really a practical solution. There is an extension in circulation for Firefox5 that alerts the user to signatures based on MD5, but in practice this normally generates false positives. This is only an option for home users with expert knowledge.</li>
<li>It is important within organisations to keep track of which and what type of certificates are in use, even if you have your own internal PKI with a root certificate. This includes certificates from your official websites, your internal websites, client certificates and other solutions that make use of SSL certificates, such as SSL VPNs.</li>
<li>If you are still signing certificates internally on the basis of MD5 then make plans to phase this out. If you make use of certificates that are signed on the basis of MD5 then you need to replace these as soon as possible with certificates signed on the basis of a more recent algorithm. You can read more in the following paragraph about your options.</li>
</ol>
<h3>Replace MD5 … but with what?</h3>
<p>The researchers&#8217; motivation in publishing this research was to demonstrate that it has for a long time been irresponsible to use MD5 to sign certificates and they have been very successful in this. You therefore need to migrate now, but the question is: “To what, if MD5 is no longer satisfactory?”</p>
<p>The successor to MD5 is SHA-1, but an even newer variant has been available for some time, namely SHA-2 (a collective name for SHA-224, SHA-256, SHA-384 and SHA-512). It has also been demonstrated that SHA-1 has some weak spots and it is expected that SHA-1 will in the not too distant future disappear as a result of practical attacks. The US National Institute of Standards and Technology (NIST) goes even further. It requires American government organisations to abandon SHA-1 and move over to a SHA-2-variant before the end of 2010.</p>
<p>You have two options at the moment:</p>
<ol>
<li><strong>Transition to SHA-1.</strong> This is the easiest option. SHA-1 is supported by practically all CAs and all software. It is therefore relatively easy and cheap to make the transition. The disadvantage of this option is that SHA-1 already includes known vulnerabilities. Although this is not yet a practical threat, the strength of SHA-1 may soon come under pressure. If this is the case then it will be necessary to make a new transition, which will involve fresh costs.</li>
<li><strong>Transition to SHA-2.</strong> This option is less simple. Support for SHA-2 is far from being a matter of course for all CAs and all software. Before you migrate to SHA-2 you will need to find out if you are also going to have to upgrade your software. This of course entails additional costs. Moreover, the use of such a certificate can also create a problem for some visitors to your website if their browser does not support SHA-2. There is also an advantage to migrating to SHA-2. It is by far the most future-proof option at this time because SHA-2 is expected to last another ten years before any practical attacks will be possible.</li>
</ol>
<p><em>[The <a title="Factsheet FS-2009-01 (PDF) (Govcert.nl)" href="http://www.govcert.nl/download.html?f=124" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.govcert.nl/download.html?f=124&amp;referer=');">original factsheet</a> was published by Govcert.nl and is available in PDF format from their website.]</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/01/web-certificate-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Millennials: the new workplace threat</title>
		<link>http://www.spinlock.com/2008/11/millenials-in-the-workplace/</link>
		<comments>http://www.spinlock.com/2008/11/millenials-in-the-workplace/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 13:04:39 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[trends]]></category>
		<category><![CDATA[millenials]]></category>
		<category><![CDATA[mobile devices]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=30</guid>
		<description><![CDATA[Younger employees are taking their own technology and mobile devices into the workplace, confounding attempts to protect internal networks, reports Information Week.  The so-called Millennial generation, Under-28s who are increasingly connected to others using social networking software, are basing their choice of employer partly on how accommodating the company is to personal technology preferences, according [...]]]></description>
			<content:encoded><![CDATA[<p>Younger employees are taking their own technology and mobile devices into the workplace, confounding attempts to protect internal networks, reports <a title="IT Security's Next Big Threat: Young People (InformationWeek)" href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=212100952" target="_self" onclick="pageTracker._trackPageview('/outgoing/www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=212100952&amp;referer=');">Information Week</a>.  The so-called Millennial generation, Under-28s who are increasingly connected to others using social networking software, are basing their choice of employer partly on how accommodating the company is to personal technology preferences, according to a recent survey conducted by Accenture.</p>
<p><a href="http://www.spinlock.com/wp-content/uploads/2008/11/accenture-logo.jpg"><img class="size-medium wp-image-41 alignleft" title="accenture-logo" src="http://www.spinlock.com/wp-content/uploads/2008/11/accenture-logo.jpg" alt="" width="140" height="45" /></a>According to the survey, nearly two-thirds of Millenials are either unaware of their companies&#8217; information technology policies or are simply not inclined to follow them. It also highlighted the acceleration of a trend among younger workers that shows a bias toward using technology to connect with colleagues, peers, family and friends, instead of relying on telephone calls or face-to-face contact.  In other words, young workers&#8217; habits are underscoring the difference between the technology that organizations provide their workforce and how young workers actually want to use technology to communicate and collaborate.</p>
<p><span id="articleBody">&#8220;The message from Millennials is clear: To lure them into the workplace, prospective employers must provide state-of-the-art technologies,&#8221; says Gary Curtis, managing director of Accenture Technology Consulting. &#8220;And if their employers don&#8217;t support their preferred technologies, Millennials will acquire and use them anyway. In order to acquire and retain the best talent, organizations must understand the technologies that the new workforce expects &#8212; and then find a way to support their employees without compromising enterprise security.&#8221; </span></p>
<p>The Accenture survey is the latest in a long string of studies in workforce behavioral analysis that points to employees as the weak link in the security chain.  While social networking software has long been the bane of CISOs, the evidence seems clear that information security and human resource policies must take modern technology into account or risk becoming obsolete.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2008/11/millenials-in-the-workplace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Underground digital economy spotlighted</title>
		<link>http://www.spinlock.com/2008/11/underground-digital-economy/</link>
		<comments>http://www.spinlock.com/2008/11/underground-digital-economy/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 11:58:16 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mitigation]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=26</guid>
		<description><![CDATA[In October 2008, the Symantec Corporation published its Report on the Underground Economy, which is the culmination of a year-long effort to observe and record the behaviors of bad actors in the cybercrime arena. By watching the activities of malicious botnets over a long period of time, Symantec&#8217;s researchers were able to identify likely interaction [...]]]></description>
			<content:encoded><![CDATA[<p>In October 2008, the Symantec Corporation published its <em><a title="Report on the Underground Economy (PDF)" href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf" target="_blank" onclick="pageTracker._trackPageview('/outgoing/eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf?referer=');">Report on the Underground Economy</a>,</em> which is the culmination of a year-long effort to observe and record the behaviors of bad actors in the cybercrime arena. <a href="http://www.spinlock.com/wp-content/uploads/2008/11/200811-sym-underground.png"><img class="alignright size-full wp-image-27" style="margin: 2px;" title="200811-sym-underground" src="http://www.spinlock.com/wp-content/uploads/2008/11/200811-sym-underground.png" alt="" width="154" height="91" /></a>By watching the activities of malicious botnets over a long period of time, Symantec&#8217;s researchers were able to identify likely interaction strategies for trading stolen digital cargo and services.</p>
<p>What&#8217;s most interesting about this report is not the specifics of any particular set of cybercriminals, but instead in the number of channels used to convey the goods as well as the pedestrian style of commerce, including several online How-To guides, used to entice would-be sellers to peddle their stolen goods.</p>
<p>Although this report is heavily biased toward reporting numbers and statistics, by enumerating price lists for stolen data and of the number of command-and-control networks used on a daily basis by cybercriminals, CISOs can put a much more firm opportunity cost estimate for failure to apply proper controls to sensitive customer data. In addition, in an appendix to the report, Symantec offers readers its recommendations for mitigation strategies to shore up data security risks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2008/11/underground-digital-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

