Sabtu, 09 Juni 2012

Whither United States Air Force Academy?

From TaoSecurity
Thomas Ricks' post Does the Air Force Academy have ‘the least educated faculty’ in the country? inspired me to write this post. Mr. Ricks cited a story by Jeff Dyche, a former USAFA professor who cited a litany of concerns with the USAFA experience. I graduated from the Air Force Academy in 1994, ranked third in my class of 1024 cadets, and proceeded to complete a master's degree at Harvard in 1996. In my experience, at least in the early 1990s, USAFA faculty were as good, or better, than Harvard faculty. I considered the nature and volume of my graduate courses to be simple compared to my USAFA classes. When several fellow graduate students broke into tears after learning what the Harvard faculty expected of them, I couldn't believe how much easier the classes were going to be!

Rather than address points made by Ricks and Dyche, I prefer to focus on a theme that appears every few years: "why does the nation need service academies?" To provide one answer to this question, I'm going to draw on some lessons from a biography I'm reading called Grant by Jean Edward Smith. As you probably know, US Grant was a West Point graduate. According to Smith, during Grant's time as a cadet, West Point was one of only two schools in the nation that trained graduates as civil engineers. According to West Point in the Making of America,"

Following the example of the famous French engineering and artillery schools that the army had sent him to study, [Superintendent] Thayer made West Point America's national engineering school. West Point combined officer training with a highly technical undergraduate education...

Engineering itself became the army’s elite branch of service, the first choice by those who ranked highest in a graduating class. Lower-ranking cadets went to the cavalry, infantry, and other branches. West Point also became the nation's major source of civil engineers and of engineering educators. In the three decades before the Civil War, West Pointers as teachers, writers, and practitioners fostered science and engineering at Cornell, Harvard, Yale, and other colleges.

So, beyond just producing professional military officers, West Point met the country's exploding demand for civil engineers. As Smith says:

[A]s the nation moved westward, the demand for engineers grew steadily. For that reason, few of the young men who went to West Point did so with the intention of making the Army a career. It was no disgrace to resign from the service to take a better civilian position, and of the 1058 cadets who graduated from the academy between its inception in 1802 and 1839, only 395 remained on active duty.

I believe West Point's experience in the early 1800's could serve as an example for USAFA in this century. Few would advocate closing USAFA if it produced graduates with skills seldom found elsewhere, meeting another exploding demand. It seems to me that the skill most needed to help grow the nation is digital defense. This requirement takes many forms, including secure coding, infrastructure design/construction/operation, incident detection and response, forensics, threat intelligence and adversary characterization, malware analysis and reverse engineering, counter-threat operations, and related fields. With the proper leadership, faculty, and determination, USAFA could differentiate itself as the nation's premiere "cyber school," with an integrated curriculum focusing on securing cyberspace -- both in the military and government or private sectors.

This change doesn't require shifting all Academy resources to the cyber mission, but I would admit far greater numbers of cyber-affiliated candidates and radically beef up the Academy's cyber program. There is a precedent: in 1990 when I was admitted, I was one of the approximately 150 freshmen (out of about 1,500 total freshmen) who lacked 20/20 vision. 90% of my class was "pilot qualified" because the demand for pilot training was projected to be high by 1994.

If USAFA became known as "the" school for cyber, accepting that not all graduates intend to serve a twenty year Air Force career, I doubt the school would suffer so many questions of relevance and cost.

Charting ordered Hash Data from the Security Event Log







# RMF Network Security Friday, June 08, 2012  PS CTP3V2
# See http://thinking-about-network-security.blogspot.com/2012/03/evtsys-actually-auditpol-and-auditusr.html for auditpol configuration to accumulate (Security) Kernel counters.
# where do.txt:
# New Process Name:
# Destination Address
# See MS Charting derived Function 'Chart-hashdata'

if ($HashData) {rv HashData}; if ($ArrayData) {rv ArrayData};
[array[]]$ArrayData=get-winevent -log Security -max 1000 |`
   where-object  {$_.ID -eq 4688 -or $_.ID -eq 5156 -or $_.ID -eq 5157}`
   | Select Timecreated,RecordID,ID,@{Name="MessageString"; Expression = {($_.Message |findstr /G:do.txt)}}
foreach ($i in ($ArrayData)) {$HashData+=[ordered]@{$i.RecordID=$i.ID}}
Chart-hashdata line 500 500 "Security Log Audits: New Process and Destination Address Events" Events "EventIDs 4688 or 5156 or 5157"

PS C:\ps1\CTPv3> $Arraydata[0..10] | ft -auto

TimeCreated          RecordId   Id MessageString
-----------          --------   -- -------------
5/30/2012 2:11:35 PM 44766425 4688     New Process Name:    C:\Windows\SysWOW64\auditpol.exe
5/30/2012 2:11:35 PM 44766424 4688     New Process Name:    C:\cygwin\bin\bash.exe
5/30/2012 2:11:26 PM 44766423 5156     Destination Address:    127.0.0.1
5/30/2012 2:11:26 PM 44766422 4688     New Process Name:    C:\Windows\SysWOW64\auditpol.exe
5/30/2012 2:11:26 PM 44766421 4688     New Process Name:    C:\cygwin\bin\bash.exe
5/30/2012 2:11:25 PM 44766420 5156     Destination Address:    ff02::1:2
5/30/2012 2:11:19 PM 44766418 5156     Destination Address:    192.168.0.1
5/30/2012 2:11:19 PM 44766417 5156     Destination Address:    192.168.0.1
5/30/2012 2:11:19 PM 44766416 5156     Destination Address:    192.168.0.1

PS C:\ps1\CTPv3> $ArrayData.ID | group | Sort -desc -property Count

Count Name                      Group
----- ----                      -----
  824 5156                      {5156, 5156, 5156, 5156...}
   23 4688                      {4688, 4688, 4688, 4688...}
    7 5157                      {5157, 5157, 5157, 5157...}

PS C:\ps1\CTPv3> ($Hashdata | more)[0..10]

Name                           Value
----                           -----
44766425                       4688
44766424                       4688
44766423                       5156
44766422                       4688
44766421                       4688
44766420                       5156
44766418                       5156

foreach ($i in $ArrayData){$i | export-csv -notype -append ArrayData.csv}

PS C:\ps1\CTPv3> more ArrayData.csv
"TimeCreated","RecordId","Id","MessageString"
"5/30/2012 2:11:35 PM","44766425","4688","      New Process Name:       C:\Windows\SysWOW64\auditpol.exe"
"5/30/2012 2:11:35 PM","44766424","4688","      New Process Name:       C:\cygwin\bin\bash.exe"
"5/30/2012 2:11:26 PM","44766423","5156","      Destination Address:    127.0.0.1"
"5/30/2012 2:11:26 PM","44766422","4688","      New Process Name:       C:\Windows\SysWOW64\auditpol.exe"
"5/30/2012 2:11:26 PM","44766421","4688","      New Process Name:       C:\cygwin\bin\bash.exe"
"5/30/2012 2:11:25 PM","44766420","5156","      Destination Address:    ff02::1:2"


Kamis, 31 Mei 2012

5000th Tweet

Today I posted my 5000th Tweet. I've apparently been a Twitter user since 1 December 2008. I remember not Tweeting anything until 15 July 2009, when I attended a Webcast about "security monitoring." The speakers were using Twitter to gather questions, so I decided it was a good time to try participating.

With the advent of Twitter I've blogged a lot less. It's tempting to think that I've been sacrificing long, thoughtful blog posts for short, mindless Tweets. It turns out that a decent portion of my blogging volume, especially in my early blogging years (say 2003-2006) involved short posts. I recently reviewed a lot of my earlier blog posts, and noticed many of them looked just like Tweets. They may not have fit within the 140 character limit, but they were short indeed.

For me, Twitter is a very compelling medium. It's more interactive, more frequently updated, and just easier to use. I have only ever blogged from a laptop. I use Twitter a lot on my phone and increasingly on my tablet. The ability to send a Tweet while reading a Web page is especially compelling.

On the down side, Twitter surely lacks the "institutional memory" of a blog. I can easily search my blog for past content, navigate via time or label, and read fairly complete thoughts in a narrative format. I can build a new book around ideas on my blog; I can't do that with old Tweets.

Note: can anyone remember who posted the analysis of blogging vs Tweeting output? I was listed in that post but I don't remember who wrote it. Also, thanks to activating a setting on the blog, I now get an email whenever a visitor posts a comment for moderation. Expect faster response times now!

Selasa, 22 Mei 2012

Whistleblowers: The Approaching Storm for Digital Security

Last week in my post SEC Guidance Is a Really Big Deal I mentioned the potential significance of whistleblowers with respect to digital security. I came to this conclusion while participating in a panel for those involved with Directors and Officers insurance. This post provides a few more details.

This morning I reviewed slides by Frederick Lipman, author of Whistleblowers: Incentives, Disincentives, and Protection Strategies, pictured at left. Mr Lipman spoke about whistleblowers at the same conference, but I didn't see his presentation.

You can read Mr Lipman's slides on this shared Google drive in .pdf format.

To briefly summarize Mr Lipman's work, Dodd-Frank, the False Claims Act, IRS rules, and other regulations have created an environment more favorable to those who wish to report wrongdoing within their organizations. Bounties for whistleblowers can amount to tens of millions of dollars. Yes, that's right: individuals have received millions of dollars after reporting violations by their employers. If that weren't enough, following penalties levied by the government against companies, the private sector also joins the fray through shareholder law suits.

I'm predicting that due to the increase in regulation during the last decade, whistleblowers will begin to report digital risks or incidents to their boards and/or outsiders.

Consider the following scenario: a publicly traded firm targeted by the APT suffers a major loss of intellectual property. The loss will likely result in decreased revenues for a particular product line because foreign companies will clone and sell the technology, undermining the victim's competitiveness and qualifying as a material event.

The firm decides to not report the event in its SEC disclosure documents. Frustrated with the cover-up, members of the security team act as whistleblowers. If the firm is lucky the whistleblowers use the firm's reporting process to notify the audit committee of the board. If the firm is not lucky, or if the whistleblowers don't feel their concerns are addressed, they report to the SEC or other outside entities.

I could imagine many permutations of this scenario to make it better or worse for all parties involved. The bottom line is that I expect this aspect of additional regulations to be a new driver for disclosure, once it becomes more widely recognized and understood.

For fun, imagine a different scenario where hacktivists compromise the same victim and publish its email. Regulators read the email (or learn via those who read the email) that the hacktivism victim is also failing to report material losses due to APT compromise...

Thank you to Mr Lipman for agreeing to let me post his slides publicly. I plan to check out his book too.

Minggu, 20 Mei 2012

Comparing IEDs and Digital Threats

Two weeks ago Vago Muradian from This Week in Defense News interviewed Army Lt Gen Michael Barbero, commander of the Joint IED Defeat Organization. I was struck by the similarities between the problems his command handles regarding improvised explosive devices (IEDs) and those involving digital security professionals.

In fact, you may be aware that papers and approaches like Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains by Eric M. Hutchins, Michael J. Cloppert, and Rohan M. Amin, Ph.D. were inspired by the desire to move "left of boom" regarding IEDs.

In this post I will highlight elements from the interview which will likely resonate with those working digital security problems.

  • The threat "shares information globally," and engages in an "arms race" with defenders, sometimes by "sitting in front of a computer" devising the latest tools and techniques.
  • The adversary can introduce changes to tools and techniques in weeks and months, not years or decades as was the case with conventional or strategic weapons.
  • For a "meagre expenditure," the adversary can impose "huge costs on defenders."
  • The goal of the security program (i.e., JIEDDO) is to provide commanders freedom of maneuver to conduct operations (business) in an IED environment.
  • "If you're worrying about the device, you're playing defense." Don't focus only on the device, put pressure on the networks (of adversaries who design, build, and operate the weapons.)
  • Intelligence plays a key role in defeating adversaries. Winning involves applying "lethal pressure, "along with government techniques. "It takes a network to defeat a network."
  • Defeating the device attracts the most attention and funding, but training users and attacking the network must also be pursued. Training involves ensuring that operators are using countermeasures effectively and appropriately.
  • JIEDDO shares threat intelligence in unclassified form so industry partners can devise countermeasures. The unclassified documents are backed by a classified appendix that describes how troops deploy countermeasures in operational settings.
I find the first four minutes of that interview, then comments about unclassified intel sharing at the seven minute mark, to be fascinating. It's clear to me that "malware" is the equivalent to IEDs in this context. Sure enough, just as in the IED world, defeating malware attracts a log of "attention and funding," but training users and "attacking the network" are just as, if not more, important.

If you'd like to see examples of the IEDs encountered in the field and some US countermeasures, check out the first segment.

Cooking Banana Bread in a Rice Cooker



One thing I have noticed in China is that I have had to be a bit more creative here when it comes to cooking. I can't use a full size oven, so I have to make due with a toaster oven. I have been on a banana bread craze and while looking for better ways to cook it I came up with a pretty neat method: cooking it in a rice cooker.

You can find my recipe for banana bread here.

Read article »

Banana Frosting for your Banana Bread


If you are looking for a way to spice up your banana bread, you should try making some banana frosting!

Read article »