Senin, 29 Maret 2004

OpenBSD Funding Highlights Open Source Development Issues

In mid-March the OpenBSD Journal featured a story on funding OpenBSD SMP development. I found it interesting to get a glimpse into the workings of the open source community when it comes to making important advances in operating systems. The story was really a post of a message Theo made to a mailing list, but the commentary was interesting. It reminded me of the donations to Colin Percival's Freebsd-update project.

New Utilities for Investigating Systems

I've come across a few interesting utilities that deserve a look. PyFlag is a Web-based forensic analysis suite written in Python. It's a complete rewrite of the original FLAG tool.

Microsoft released portrptr.exe recently. Port Reporter runs as a service on Windows 2000/XP/2003 systems, logging sockets used to the c:\winnt\system32\logfiles\portreporter directory. Here are sample records:

04/3/29,9:38:18,TCP,21,10.10.10.3,24898,192.168.50.2
04/3/29,9:38:25,TCP,1163,10.10.10.3,,0.0.0.0
04/3/29,9:38:25,TCP,1163,10.10.10.3,24899,192.168.50.2
04/3/29,9:38:50,TCP,1166,10.10.10.3,24900,192.168.50.2
04/3/29,9:38:55,TCP,1167,10.10.10.3,24901,192.168.50.2

The first is an FTP control channel. The last three are FTP data channels. I am not sure about the second entry but the source port is the same as that used for the first FTP data channel.

Online Debian Book

I decided to move my old Pentium 90 from Red Hat 6.2 to Debian. I installed 3.0r2 using the 2.2 kernel boot floppies. The P90 doesn't support booting from the blazingly fast 2X speed Sony CD-ROM, which also requires a the CDU31A driver. I couldn't find support for this driver in the 2.4 kernel boot floppies. I also had to load the 8390 and smc-ultra kernel modules to support a Linksys ISA NIC.

Along the way I found The Debian Universe, which "aims to become a complete guide to installing, managing and running Debian GNU/Linux." This is great because the last published book on Debian arrived in 2001 and described the 2.2r release.

I was able to update my kernel to 2.4.18 using the apt tools. This command showed me what was available:


apt-cache search kernel-image-2.4


Next I installed the 2.4.18 image:


apt-get install kernel-image-2.4.18-1-386


I added 'initrd=/initrd.img' to /etc/lilo.conf as prompted by the install process. When I rebooted I was running 2.4.18.

I intend to try upgrading to a 2.6 kernel using the packages provided by Debian Backports.

Jumat, 26 Maret 2004

Draft Cover Art for my Book

I received draft cover art for my upcoming book The Tao of Network Security Monitoring: Beyond Intrusion Detection. That's a praying mantis on the cover. I first studied a form of praying mantis kung fu ten years ago in the town where I grew up. The school is still going strong as the Michael Macaris Kung Fu Academy in Billerica, Massachusetts.

Rabu, 24 Maret 2004

The Applicability of Corporate Fraud to Digital Security

I've been on the lookout for Corporate Fraud: Case Studies in Detection and Prevention by John D. O'Gara. I thought it might contain insights useful for intrusion detection. Looking at the sample excerpt, (.pdf), it seems more suited to corporate types. However, I found this statement to be fascinating:

"Effective prevention depends on the probability of detection and prosecution more than on any other single factor, because management fraud typically involves override rather than taking advantage of control weaknesses."

This ties in to my idea that prevention eventually fails, for whatever reason. I also found the emphasis on recognition of indicators to be completely in line with my ideas:

"All competent professional internal auditors should have the ability to recognize the red flags and symptoms that indicate the possible existence of management fraud, and they should also be able to perform diagnostic procedures to assess the probability of occurrence. Investigation of cases of more complex management fraud beyond determining whether fraud probably occurred normally requires specialized experience and skills. Nevertheless, we cannot overemphasize the importance of recognition. Simply put, recognition must occur before investigation can start.

According to the Institute of Internal Auditors (IIA), 'The internal auditor should have sufficient knowledge to identify the indicators of fraud but is not expected to have the expertise of a person whose primary responsibility is detecting and investigating fraud.' Furthermore, the IIA maintains that '[d]etection of fraud consists of identifying indicators of fraud sufficient to warrant recommending an investigation.'"

That's similar to my description of Network Security Monitoring:

"NSM is the collection, analysis, and escalation of indications and warnings to detect and respond to intrusions. NSM tools are used more for network audit and specialized applications than traditional alert-centric 'intrusion
detection' systems."

Jumat, 19 Maret 2004

New Sguil Installation Guide Released

I just released a new Sguil install guide using Sguil 0.3.1, FreeBSD 5.2.1 REL, Snort 2.1.1, Barnyard 0.2beta2, MySQL 4.0.18, and other updates. It's available in text form at http://sguil.sourceforge.net/downloads/sguil_guide_0-3-1_02.txt. The packages for FreeBSD 5.2.1 mentioned in the guide are available at sguil_0-3-1_f5-2-1_pkg.tar.gz (24 MB).

I wanted to get this out to accompany the article in Sys Admin magazine. The new guide is a text version, which I felt was more appropriate for the Sguil user community.

I composed the guide in vi, which didn't wrap the lines to 80 columns. I used fold -s to create the formatted result.

Rabu, 17 Maret 2004

TheJemReport.com Publishes Benchmarking Results

TheJemReport.com published several good articles on FreeBSD recently. I was impressed by the author's attention to detail for each report, but I am not in a position to try to confirm or refute his claims. With a three word summary, they are: