Friday, January 20, 2012
Anonymous
I don't understand the hacker group anonymous. They take down websites to make a statement (usually big ones). If the really wanted to affect the organization they would understand that most large organizations usually run servers on a different network than employees. Thus if you figure out the employee network and attack it you reduce the productivity and give the organization a much larger headache due to employees sitting idle. A organization is going to be much more upset with paying idle employees than having a few hours of downtime. Now I also understand that the website may take orders etc and even a half hour can result in lots of money lost. My point is about anonymous though. It seems they only want to be in the news for taking down a website (which is trivial and extremely common). Wouldn't it be much more effective to attack the bottom line?
Saturday, October 22, 2011
Security+ Topic - Firewalls
Lets talk firewalls. It used to be that if you had a firewall
then you were basically protected against a lot of the threats that
are in the world today. While yes it is true that having a firewall
in place will help mitigate a lot of threats it is still not the only
thing you need on your network or servers. Ok, now that the
disclaimer is out of the way, lets move onto the firewall subject at
hand. From a security standpoint they can help by letting you (the
good guy) see different things on your network while keeping others
(possibly bad people) from fingerprinting your network. Even with a
wealth of types of firewalls including packet filtering, proxy
firewall, and stateful inspection firewalls I would like to cover the
approach of utilizing a firewall to hide behind.
Why would you want to hide? Or what do I gain from being invisible?
Think about it for a second from the mind of a malicious person. Actually, lets take the standpoint of an inside threat. As a disgruntled employee you are wanting to take down something on the network on your last day of work. You just don't give a crap anymore and you wont see any of these people after you leave your little present anyway. You, as a network administrator had previously decided to try and mitigate some risk by setting up some firewalls. Each department is blocked from other departments and each department only has access to the areas of the network that they need access to.
Sounds simple enough right? Wrong.
I have seen quite a few networks where the network administrator will simply setup the network to allow everyone access to each part of the network as it makes their job easier. Having firewalls in place throughout your INTERNAL network is just as important as having firewalls block threats from outside your network. The biggest thing that keeps people from doing this is cost. As a disclaimer, I am a big Cisco guy and so my networks are usually segregated by Cisco routers. In any vendor network there will almost always be some sort of method to control traffic. Your setup could be a router on a stick or a 50+ internal router setup but it all boils down to the firewall rules that you put into place.
I will cover a couple brief methods of firewalls so I don't leave you hanging in the wind. The previously mentioned one was with Cisco gear. ACL's can work wonders. These little things on gear you already have can be your first line of defense for keeping people in Customer Support from getting to the Accounting computers. Another option is the use of transparent Linux firewall/proxy. It acts just like a switch on your network passing data like normal but inspects the packets to make sure they are allowed to be there. Again on the Cisco side but more expensive is your (older) PIX and (new) ASA firewalls. If you have the money for an ASA, go for it!
What it boils down it is protection. Firewalls are there as a layer of security and that is what you are looking for. Layers. In a drive-by scan you want to be hidden so they don't dig deeper. In a targeted internal or external attack you want to provide as many road-blocks as possible.
-- Joe McShinsky
Why would you want to hide? Or what do I gain from being invisible?
Think about it for a second from the mind of a malicious person. Actually, lets take the standpoint of an inside threat. As a disgruntled employee you are wanting to take down something on the network on your last day of work. You just don't give a crap anymore and you wont see any of these people after you leave your little present anyway. You, as a network administrator had previously decided to try and mitigate some risk by setting up some firewalls. Each department is blocked from other departments and each department only has access to the areas of the network that they need access to.
Sounds simple enough right? Wrong.
I have seen quite a few networks where the network administrator will simply setup the network to allow everyone access to each part of the network as it makes their job easier. Having firewalls in place throughout your INTERNAL network is just as important as having firewalls block threats from outside your network. The biggest thing that keeps people from doing this is cost. As a disclaimer, I am a big Cisco guy and so my networks are usually segregated by Cisco routers. In any vendor network there will almost always be some sort of method to control traffic. Your setup could be a router on a stick or a 50+ internal router setup but it all boils down to the firewall rules that you put into place.
I will cover a couple brief methods of firewalls so I don't leave you hanging in the wind. The previously mentioned one was with Cisco gear. ACL's can work wonders. These little things on gear you already have can be your first line of defense for keeping people in Customer Support from getting to the Accounting computers. Another option is the use of transparent Linux firewall/proxy. It acts just like a switch on your network passing data like normal but inspects the packets to make sure they are allowed to be there. Again on the Cisco side but more expensive is your (older) PIX and (new) ASA firewalls. If you have the money for an ASA, go for it!
What it boils down it is protection. Firewalls are there as a layer of security and that is what you are looking for. Layers. In a drive-by scan you want to be hidden so they don't dig deeper. In a targeted internal or external attack you want to provide as many road-blocks as possible.
-- Joe McShinsky
Tuesday, September 13, 2011
Security+ Topic - Cabling
We all know that fiber is the ideal choice for cabling security
for obvious reasons. Here I would like to beyond the textbook answer
of being light instead of electrical impulses. In order to get the
full picture there must be an understanding of how the signal travels
through the wires. In our day-to-day cabling we use copper and that
does great for our needs. If we were to run fiber to all of our
nodes then it would get extremely expensive. These electrical
signals flying down the wire have some inherent problems that must be
addressed though. What you learn about in school is the need to not
have these wires around light fixtures and other items that would be
a problem for your electrical signals.
The TEMPEST project is where the United States Government worked on methods to be able to shield cabling against the loss or interference to/from outside sources. Having top secret data on your network leaking out would be a very bad thing and so these standards were developed to help mitigate data leakage. The TEMPEST program is now the standard for shielding protection against levels of EMI or RFI and any product wishing to claim they are compliant must go through rigorous testing. Generally speaking, the cabling cost almost double to regular cabling.
How can the shielded cabling help your network?
In a sabotage example there are clear benefits to be had with shielded cables. Take for example a company that has a shared server room. Many of the cables that run to the internet service provider will run outside of isolated caged sections or locked server cabinets. If an attacker were able to identify a power over ethernet run they could tap into it and place a small motor near your uplink lines. This type of denial of service would distort the signals going to and from the ISP leaving you with minimal throughput and possibly taking out the connection all-together. While this attack would be very hard to mitigate it is also something that is very specific and very hard to put into place. I would say to worry about other parts of your network before going down to your server room everyday to check the wires.
I want to focus here on the wireless side of “cabling” also. Many internet service providers are transmitting their uplink connection to businesses via wireless access points. These are not the same access points you have in your house but are very similar in nature. They still run on 2.4Ghz or 5Ghz meaning they are still susceptible to a large range of interference. In the example above with uplink sabotage, say the business is running a wireless internet service provider connection. As a competitor, I could easily place something near your uplink bridge that would interfere with your signal. I could be in a van in the parking lot or near the tower that you make a connection to. Either way it would be very difficult to detect where the problem is coming from.
Wireless connections have their place and I am not saying to rule them out completely. Wired connections will be king for a very long time due to security and speeds available. Keep these in mind if your company is in the position to have to worry about mitigating attacks on the physical level.
-- Joe McShinsky
The TEMPEST project is where the United States Government worked on methods to be able to shield cabling against the loss or interference to/from outside sources. Having top secret data on your network leaking out would be a very bad thing and so these standards were developed to help mitigate data leakage. The TEMPEST program is now the standard for shielding protection against levels of EMI or RFI and any product wishing to claim they are compliant must go through rigorous testing. Generally speaking, the cabling cost almost double to regular cabling.
How can the shielded cabling help your network?
In a sabotage example there are clear benefits to be had with shielded cables. Take for example a company that has a shared server room. Many of the cables that run to the internet service provider will run outside of isolated caged sections or locked server cabinets. If an attacker were able to identify a power over ethernet run they could tap into it and place a small motor near your uplink lines. This type of denial of service would distort the signals going to and from the ISP leaving you with minimal throughput and possibly taking out the connection all-together. While this attack would be very hard to mitigate it is also something that is very specific and very hard to put into place. I would say to worry about other parts of your network before going down to your server room everyday to check the wires.
I want to focus here on the wireless side of “cabling” also. Many internet service providers are transmitting their uplink connection to businesses via wireless access points. These are not the same access points you have in your house but are very similar in nature. They still run on 2.4Ghz or 5Ghz meaning they are still susceptible to a large range of interference. In the example above with uplink sabotage, say the business is running a wireless internet service provider connection. As a competitor, I could easily place something near your uplink bridge that would interfere with your signal. I could be in a van in the parking lot or near the tower that you make a connection to. Either way it would be very difficult to detect where the problem is coming from.
Wireless connections have their place and I am not saying to rule them out completely. Wired connections will be king for a very long time due to security and speeds available. Keep these in mind if your company is in the position to have to worry about mitigating attacks on the physical level.
-- Joe McShinsky
Subscribe to:
Posts (Atom)