<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>seki &#187; FIRST</title>
	<atom:link href="http://www.spinlock.com/tag/first/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spinlock.com</link>
	<description>Spinlock Technologies LLC</description>
	<lastBuildDate>Tue, 16 Feb 2010 13:29:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Responding to network attacks</title>
		<link>http://www.spinlock.com/2010/01/net-attack-response/</link>
		<comments>http://www.spinlock.com/2010/01/net-attack-response/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 18:49:40 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[information security management]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[mitigation]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=121</guid>
		<description><![CDATA[Though they&#8217;re not going away anytime soon &#8212; and every security geek in the IT department knows it &#8212; distributed denial-of-service (DDoS) attacks still cause great panic in most organizations hit by them. This being the case, it bears underscoring the importance of planning ahead so that you don&#8217;t get caught flatfooted when the next [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spinlock.com/wp-content/uploads/2010/01/20100130-ddos.gif"><img class="alignright size-medium wp-image-122" title="DDoS meets pop culture" src="http://www.spinlock.com/wp-content/uploads/2010/01/20100130-ddos-300x256.gif" alt="" width="300" height="256" /></a>Though they&#8217;re not going away anytime soon &#8212; and every security geek in the IT department knows it &#8212; distributed denial-of-service (DDoS) attacks still cause great panic in most organizations hit by them. This being the case, it bears underscoring the importance of planning ahead so that you don&#8217;t get caught flatfooted when the next attack comes, whether it&#8217;s a DDoS or something even bigger.<span id="more-121"></span></p>
<h2>1. Activate your response plan</h2>
<p>Rather than responding to the waves of panic that are likely circulating around the sales and executive teams, the most productive thing to do is to rely on your advance planning to start the response process rolling.  Remembering that the key to solving problems is usually communications, you should focus on providing company executives with regular updates. Then you can focus on the technology issues without undue badgering.</p>
<p>This is, I think, the right time to remind that one of the best antidotes to security crises is to have an computer security incident response team (CSIRT) capability.  This resource, whether in-house or contracted out, can save countless amounts of downtime. You can learn more about incident response from places like the <a title="FIRST.org (opens in a new window)" href="http://www.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.first.org/?referer=');">Forum of Incident Response and Security Teams (FIRST)</a>.</p>
<h2>2. Set up a war room</h2>
<p>When Skype suffered a major outage &#8212; which, though not a DDoS, had some of the massive but temporary service disruption characteristics of a DDoS &#8212; we set up two war rooms: one near the company executives and one in the heart of the engineering center. This kind of arrangement not only allows &#8220;the right people&#8221; to come together face-to-face, it also allows for a focal points to form for network operations, media/PR, and the executive team.  This location is focused on communication, so be sure to have redundant means at your disposal in case your chosen system (phone line, Jabber, Skype, etc.) is itself impacted by the attack.</p>
<h2>3. Think tactically</h2>
<p>Your first general priority is limiting downtime, so you have to quickly assemble the data available to you to identify the cause of the problem and its target. Work with your ISP or network peers to maximize your options within the terms of your service contract, and preferably without incurring additional costs.</p>
<p>While you can have traffic shunted or blackholed, do keep in mind that such measures as having new network addresses assigned to critical resources may likely cause lasting secondary effects, such as the invalidation of IP-bound digital certificates. For lengthy attacks, it may be worth the effort to have a plan for a temporary customer notice website, which can keep customers informed of the company&#8217;s efforts to restore service.</p>
<p>For small businesses, these kinds of services can often be arranged ad hoc, but it&#8217;s best to have a planned service with a specified DDoS service level agreement. In addition, cutover of these services may require coordination with your domain registrar or your ISP.</p>
<h2>4. Think strategically</h2>
<p>Your next general priority is preventing further downtime. This requires more thought and more research; you need to identify the rationale for the attack. In other words, why did someone target <em>your</em> infrastructure to attack today? Is there a pot of gold at the end of the attack?  Is the attack you&#8217;re experiencing merely cover for another, separate attack whose aim is to steal valuable customer data?</p>
<p>There are many possibilities here, but the point to make is that the CISO of the organization needs to be well aware not only of the technology in play, but also of the risk matrix relating to data available on the network and even things like public perception of the company. Many otherwise mundane companies have been hit by hackers or so-called hacktivists merely due to the public position of a single member of the company&#8217;s board of directors.</p>
<h2>5. Document, review and train</h2>
<p>If there&#8217;s one silver lining to an attack, it&#8217;s that the event can serve as a crucible for learning for the entire staff, including people far outside the technical teams. Take notes as the event unfolds, including the time that decisions (even mundane ones) were made. Also take time to understand the cost impact of the attack and its remediation. During a post-mortem, these notes will serve better than any cockamamie exercise could to develop better processes and procedures for the next time.  The bad news is that there probably will be a next time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2010/01/net-attack-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Communication, culture and information security</title>
		<link>http://www.spinlock.com/2009/06/culture-infosec-ties/</link>
		<comments>http://www.spinlock.com/2009/06/culture-infosec-ties/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 14:12:17 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[trends]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=93</guid>
		<description><![CDATA[Since my earliest days working in Silicon Valley, I have been involved in computer security incident response management. And so it was with great pleasure that I accepted a keynote speaking opportunity at the upcoming annual meeting of the Forum of Incident Response and Security Teams (FIRST) during 28 June-3 July 2009 in nearby Kyoto, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://conference.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/conference.first.org/?referer=');"><img class="alignright size-full wp-image-94" title="2009 FIRST Conference (Kyoto, Japan)" src="http://www.spinlock.com/wp-content/uploads/2009/06/20090306-firstconfspeaker.png" alt="2009 FIRST Conference (Kyoto, Japan)" width="190" height="95" /></a>Since my earliest days working in Silicon Valley, I have been involved in computer security incident response management. And so it was with great pleasure that I accepted a keynote speaking opportunity at the upcoming annual meeting of the <a title="FIRST - the Forum of Incident Response and Security Teams" href="http://www.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.first.org/?referer=');">Forum of Incident Response and Security Teams</a> (FIRST) during 28 June-3 July 2009 in nearby Kyoto, Japan. The conference team asked if I could convey some of my observations about Japan, because I’ve been living here for just over a year now, and talk about how they relate to information security.  The talk, entitled <em>Information security: one character at a time</em> uses aspects of the Japanese language as a way to discuss the role of communication in incident handling and, more generally, in information security management.</p>
<p><span id="more-93"></span>I remember going to my very first FIRST annual conference in Monterrey, Mexico, back in 1998. At that time, I was an an official representative for Sun Microsystems to the organization and was amazed by the level of international participation. Since then, interest in computer security incident handling has grown exponentially, and therefore the breadth of the audience has become far more diverse, both in geography and in mission, than it was even ten years ago. I think that this change speaks volumes about the information security business, and I think it’s a trend to which we should pay close attention.</p>
<p>My goal for this keynote is to set out what I think incident handling will mean in the context of cultural changes in the information security handling profession. After all, even the smallest of organizations is investing — willingly or not — in response measures to security threats. In the face of the present economic downturn, it will be very interesting to see how many companies will remain interested in computer security.  But because even the most Luddite of company executives sees the risk that comes along with ignoring the perils of information security, I doubt the lights in the IT security department will be going out anytime soon.</p>
<p>If you’re in the information security industry, I highly recommend the <a title="FIRST Annual Conference" href="http://conference.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/conference.first.org/?referer=');">FIRST annual conference</a>.  If you can make it, by all means please attend!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2009/06/culture-infosec-ties/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
