<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>seki &#187; mitigation</title>
	<atom:link href="http://www.spinlock.com/tag/mitigation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spinlock.com</link>
	<description>Spinlock Technologies LLC</description>
	<lastBuildDate>Tue, 16 Feb 2010 13:29:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Responding to network attacks</title>
		<link>http://www.spinlock.com/2010/01/net-attack-response/</link>
		<comments>http://www.spinlock.com/2010/01/net-attack-response/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 18:49:40 +0000</pubDate>
		<dc:creator>kurt</dc:creator>
				<category><![CDATA[information security management]]></category>
		<category><![CDATA[CSIRT]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[FIRST]]></category>
		<category><![CDATA[mitigation]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=121</guid>
		<description><![CDATA[Though they&#8217;re not going away anytime soon &#8212; and every security geek in the IT department knows it &#8212; distributed denial-of-service (DDoS) attacks still cause great panic in most organizations hit by them. This being the case, it bears underscoring the importance of planning ahead so that you don&#8217;t get caught flatfooted when the next [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spinlock.com/wp-content/uploads/2010/01/20100130-ddos.gif"><img class="alignright size-medium wp-image-122" title="DDoS meets pop culture" src="http://www.spinlock.com/wp-content/uploads/2010/01/20100130-ddos-300x256.gif" alt="" width="300" height="256" /></a>Though they&#8217;re not going away anytime soon &#8212; and every security geek in the IT department knows it &#8212; distributed denial-of-service (DDoS) attacks still cause great panic in most organizations hit by them. This being the case, it bears underscoring the importance of planning ahead so that you don&#8217;t get caught flatfooted when the next attack comes, whether it&#8217;s a DDoS or something even bigger.<span id="more-121"></span></p>
<h2>1. Activate your response plan</h2>
<p>Rather than responding to the waves of panic that are likely circulating around the sales and executive teams, the most productive thing to do is to rely on your advance planning to start the response process rolling.  Remembering that the key to solving problems is usually communications, you should focus on providing company executives with regular updates. Then you can focus on the technology issues without undue badgering.</p>
<p>This is, I think, the right time to remind that one of the best antidotes to security crises is to have an computer security incident response team (CSIRT) capability.  This resource, whether in-house or contracted out, can save countless amounts of downtime. You can learn more about incident response from places like the <a title="FIRST.org (opens in a new window)" href="http://www.first.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.first.org/?referer=');">Forum of Incident Response and Security Teams (FIRST)</a>.</p>
<h2>2. Set up a war room</h2>
<p>When Skype suffered a major outage &#8212; which, though not a DDoS, had some of the massive but temporary service disruption characteristics of a DDoS &#8212; we set up two war rooms: one near the company executives and one in the heart of the engineering center. This kind of arrangement not only allows &#8220;the right people&#8221; to come together face-to-face, it also allows for a focal points to form for network operations, media/PR, and the executive team.  This location is focused on communication, so be sure to have redundant means at your disposal in case your chosen system (phone line, Jabber, Skype, etc.) is itself impacted by the attack.</p>
<h2>3. Think tactically</h2>
<p>Your first general priority is limiting downtime, so you have to quickly assemble the data available to you to identify the cause of the problem and its target. Work with your ISP or network peers to maximize your options within the terms of your service contract, and preferably without incurring additional costs.</p>
<p>While you can have traffic shunted or blackholed, do keep in mind that such measures as having new network addresses assigned to critical resources may likely cause lasting secondary effects, such as the invalidation of IP-bound digital certificates. For lengthy attacks, it may be worth the effort to have a plan for a temporary customer notice website, which can keep customers informed of the company&#8217;s efforts to restore service.</p>
<p>For small businesses, these kinds of services can often be arranged ad hoc, but it&#8217;s best to have a planned service with a specified DDoS service level agreement. In addition, cutover of these services may require coordination with your domain registrar or your ISP.</p>
<h2>4. Think strategically</h2>
<p>Your next general priority is preventing further downtime. This requires more thought and more research; you need to identify the rationale for the attack. In other words, why did someone target <em>your</em> infrastructure to attack today? Is there a pot of gold at the end of the attack?  Is the attack you&#8217;re experiencing merely cover for another, separate attack whose aim is to steal valuable customer data?</p>
<p>There are many possibilities here, but the point to make is that the CISO of the organization needs to be well aware not only of the technology in play, but also of the risk matrix relating to data available on the network and even things like public perception of the company. Many otherwise mundane companies have been hit by hackers or so-called hacktivists merely due to the public position of a single member of the company&#8217;s board of directors.</p>
<h2>5. Document, review and train</h2>
<p>If there&#8217;s one silver lining to an attack, it&#8217;s that the event can serve as a crucible for learning for the entire staff, including people far outside the technical teams. Take notes as the event unfolds, including the time that decisions (even mundane ones) were made. Also take time to understand the cost impact of the attack and its remediation. During a post-mortem, these notes will serve better than any cockamamie exercise could to develop better processes and procedures for the next time.  The bad news is that there probably will be a next time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2010/01/net-attack-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Underground digital economy spotlighted</title>
		<link>http://www.spinlock.com/2008/11/underground-digital-economy/</link>
		<comments>http://www.spinlock.com/2008/11/underground-digital-economy/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 11:58:16 +0000</pubDate>
		<dc:creator>news</dc:creator>
				<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mitigation]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://www.spinlock.com/?p=26</guid>
		<description><![CDATA[In October 2008, the Symantec Corporation published its Report on the Underground Economy, which is the culmination of a year-long effort to observe and record the behaviors of bad actors in the cybercrime arena. By watching the activities of malicious botnets over a long period of time, Symantec&#8217;s researchers were able to identify likely interaction [...]]]></description>
			<content:encoded><![CDATA[<p>In October 2008, the Symantec Corporation published its <em><a title="Report on the Underground Economy (PDF)" href="http://eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf" target="_blank" onclick="pageTracker._trackPageview('/outgoing/eval.symantec.com/mktginfo/enterprise/white_papers/b-whitepaper_underground_economy_report_11-2008-14525717.en-us.pdf?referer=');">Report on the Underground Economy</a>,</em> which is the culmination of a year-long effort to observe and record the behaviors of bad actors in the cybercrime arena. <a href="http://www.spinlock.com/wp-content/uploads/2008/11/200811-sym-underground.png"><img class="alignright size-full wp-image-27" style="margin: 2px;" title="200811-sym-underground" src="http://www.spinlock.com/wp-content/uploads/2008/11/200811-sym-underground.png" alt="" width="154" height="91" /></a>By watching the activities of malicious botnets over a long period of time, Symantec&#8217;s researchers were able to identify likely interaction strategies for trading stolen digital cargo and services.</p>
<p>What&#8217;s most interesting about this report is not the specifics of any particular set of cybercriminals, but instead in the number of channels used to convey the goods as well as the pedestrian style of commerce, including several online How-To guides, used to entice would-be sellers to peddle their stolen goods.</p>
<p>Although this report is heavily biased toward reporting numbers and statistics, by enumerating price lists for stolen data and of the number of command-and-control networks used on a daily basis by cybercriminals, CISOs can put a much more firm opportunity cost estimate for failure to apply proper controls to sensitive customer data. In addition, in an appendix to the report, Symantec offers readers its recommendations for mitigation strategies to shore up data security risks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spinlock.com/2008/11/underground-digital-economy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
