Security Ripcord


EDU: Making It Through The Rapids (a.k.a. Who Needs Security?)

October 9th, 2007 cutaway Posted in Education, Security 2 Comments »

The school I work for just does not seem to get it when it comes to running a good secure infrastructure by following security standards. The administrators have done a good job of piecing together a few things to help secure individual assets. They do make changes when they see a threat to a particular resource that they have not addressed. But, as a security professional, it is like watching a boat full of tourists rowing full steam ahead into category 5 rapids. I yell and wave my arms, “No….stop….we want to do this…..don’t go that way.” But they don’t hear me over the roar of the rapids and their jolly cheering as they head towards the challenge. It takes everything I can muster to not roll out of the raft and swim for shore.

So today, while I was driving to work, I had a thought. Why is it that we have not seen college, high school, or any other school close their doors because of security breaches or just plain being totally owned? We hear about the breaches. We hear about whole departments being closed down, reimaged, and then placed back on the network. But nobody actually goes way. People keep going to school and paying tuition. Teachers keep teaching. Sure, one or two people might loose their jobs, but the school keeps moving forward. Or, rather, the raft makes it through the rapids. Those that survived climb back on board, a few new people replace those that didn’t make it, and then they start rowing for the next category 5 rapids.

What does this say about security? It is more cost effective to just let everything slide, address it after the fact, and drive on without over thinking the situation? If you secure just a few assets really well you will be able to weather the storm?

Then I start thinking about businesses. How many have closed their doors because of security incidents? A few SOHOs and SMBs, maybe, because they sustained too much loss of revenue due to down time? Is it really cost effective to address security when you can just go bankrupt and start a new business? Does security only make sense for government and big business?

It kind of makes you feel like picking up an paddle, joining the reveller’s cheering, and stroking for the next set with abandon. Damn the torpedos, full steam ahead!!! Certainly we’ll get dumped but it will be fun and we can just climb back in at the end of the ride. Maybe we’ll make it through these or the next set unscratched. Yeeeehaw!!!!

Go forth and do good things,
Cutaway

Technorati Tags , ,

Considerations for an Information Assurance Laboratory

September 21st, 2007 cutaway Posted in Education, Hacking, Patch Management, Penetration Testing, SANS, Security 1 Comment »

I find it interesting what professors will say and do when it comes to providing an educational experience to their students. On one hand I can understand that the professor is trying to discover the best way possible to quickly train their students about a specific topic. On the other hand I am concerned about the, at times, lack of intelligent thought process on how it is going to affect other students, faculty and staff that also use and maintain the same resources and network environment.

One of these situations arose in my organization the other day. A college is in the processes of providing computer security courses that will train the students in subjects such as risk assessment, programming, networking, and defensive and offensive tactics (to name a few). Because it is a new program the college faculty and staff are still gathering resources, deploying them in labs, and creating the teaching platforms. All of this while the courses are being taught.

When the college decided to start providing the students with this type of course work they did approach the university’s networking team to let them know what was happening. After a few meetings it was determined that it was necessary to operate any labs that would be doing offensive tactics from a lab that was completely isolated from the university network as well as the Internet. Although very good in theory, completely isolating a network in this manner really brings forward some interesting problems. Problems that require a lot of planning, coordination, work and money.

The following is a list of a few things that should be taken into consideration as you are developing security courseware.

1. Because of the types of network and other computer activities associated with information security the details on any lab deployments must be handled just like any other system development and bringing together all of the people and organizations involved and follow a life cycle. By doing this you will determine issues and identify problem areas in the design phase and before classes start. As with any system design, it is much harder to change or address issues during production. The whole “fixing the plane while it is flying” issue.

2. Labs that will be conducting offensive operations or monitoring must be completely isolated from the school’s network and the Internet. There are many reasons for this.

  • Network traffic will contain plain text personal information related to other students, faculty, and staff. I used the gmail attack tools developed by Robert Graham and presented at DefCon 15 as an example to drive this point home.
  • Student attack tool activities are hard to distinguish from malicious attack tool activities. Many tools are designed this way to avoid network and other protections.
  • Being convicted, or even just accused, of hacking a resource without permission could ruin the career of the student and any teachers involved with the incident. Each student is trying to learn and grow. The majority of them are youths who want to test their boundaries and skill levels. Sometimes the temptation is just too much, not to mention the potential for improper configuration, and they might scan or attempt to exploit a vulnerability. The school administrators and teachers must help protect their students from this.
  • The reputation of a school is involved. If the school’s students and professors are accused of attempting to hack computers connected to the Internet then the school is going to see a serious reduction in the amount of students attending the security courses and the rest of the school’s curriculum.

3. When you are building your labs be sure to take into considerations that students operating on an isolated network are still going to need access to the Internet. They will need this to obtain tools, read manuals and howtos, and interact with their Facebook/MySpace accounts. Although having a few computers off to one side is a good quick fix, it is not the optimal situation and you will be reading complaints about this in the class evaluations. Perhaps a better solution is to have dual input monitors that can be quickly switched back and forth by the students. Each system should have different backgrounds or operating systems so that the students are aware which system they are using. Considering thin clients is also a viable solution and would prevent network cables from being swapped around.

4. Create separate networks for security classes and regular classes. Nothing is more frustrating for a student or a teacher to come to a lab they have been working on most of the semester only to find that somebody has modified its configuration or hacked their resources. This is detrimental to the learning experience and will lead to finger pointing and bad blood.

5. Create update serves that can be a repository for OS and application patches. With properly document procedures these servers can be kept on the campus’ main network in order to retrieve updates via the Internet and then reconfigured to provide service to the isolated network. Updating in this manner is a great learning experience for the students and will prepare them better for real world experiences.

6. Start a tool repository to version control tools. Many tools change rapidly and also disappear. Maintaining this repository is a good way to show students product evolution. It is also a good way to monitor these for malicious activity. This helps keep developers honest. Let’s face it, eventually some tool will be updated with malicious intent. It is only a matter of time, and think of the publicity your school will get if you are the first to identify it.

7. Network isolation is a common practice in the security research field. Ed Skoudis developed his SANS GCIH class to be an isolated environment. The SANS Integrated Cyber Exercise (ICE) is conducted in an isolated environment. And the RootWars at Learn Security Online are conducted in an isolated environment. It can be done but it requires planning.

8. Finally, listen to and leverage the experience of the information security professionals within your organization. Teaching security courseware is one thing, but working as a security professional is completely different. There are different goals and different mindsets. If the information security professionals within your organization are good they will get you what you need while also maintaining an acceptable level of security for the entire organization.

Remember, you are training the future information security professionals of the world. You should show them that security is necessary as well as implementable. Circumventing a schools security and infrastructure policies and procedures just to provide additional or “real world training” to the students is not setting a good example. It is, in fact, sending the wrong message.

If you have any additional concerns or recommendations, please leave a comment sot that others can take it into consideration.

Go forth and do good things,
Cutaway

Technorati Tags , , , , , , ,