<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: data-privacy]]></title>
    <link>http://www.securityratty.com/tag/data-privacy</link>
    <description></description>
    <pubDate>Mon, 01 Dec 2008 10:57:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[What is a Wise Risk Decision Worth? or ISO 27001 KPIs Follow Up]]></title>
      <link>http://www.securityratty.com/article/4c9a85007f78452901952cf859ffd96d</link>
      <guid>http://www.securityratty.com/article/4c9a85007f78452901952cf859ffd96d</guid>
      <description><![CDATA[So yesterday I asked readers to comment on thoughts I had that came from a question asked on the ISO 27001 Google Group
How I can communicate the value of an ISO implementation to non-security...]]></description>
      <content:encoded><![CDATA[<p>So yesterday I asked readers to comment on thoughts I had that came from a question asked on the ISO 27001 Google Group:</p>
<blockquote><p>&#8220;How I can communicate the value of an ISO implementation to non-security management?&#8221;</p></blockquote>
<p>This question came to me after one of the posters on the ISO Google Group asked about KPIs for ISO implementation.  Got great responses in <a href="http://riskmanagementinsight.com/riskanalysis/?p=525#comment-33917"><strong>email, blog comments</strong></a>, and on Twitter from current/former CISO folks and consultants and analysts.  Some really great thought and effort, by the way - <strong>thank you</strong>.  It&#8217;s really great to be able to have these sorts of conversations online.</p>
<p>First, I have to point out some resources Brian Honan linked to from Gary Hinson, just because they&#8217;re so cool.  Gary has invested gobs of time and effort to become one of the defacto resources on the ISO (you might also want to read or re-read <strong><a href="http://www.noticebored.com/html/metrics.html">Gary&#8217;s web post on the 7 myths of metrics</a></strong>).   Brian links to an <a href="http://www.iso27001security.com/ISO27k_implementation_guidance_1v1.pdf">implementation guidance document(pdf)</a> and a <a href="http://www.iso27001security.com/ISO27k_security_metrics_examples.pdf">metrics example(pdf)</a> document.</p>
<p>As full of awesomeness as they are, though, these are simply metrics &#8220;mapped&#8221; to the ISO (i.e. the ISO isn&#8217;t a pre-requisite for generating this information).  They are not KPI&#8217;s that express the value of ISO implementation.  Problem is the metrics created here still require some level of &#8220;translation&#8221; in order to create some value statement that data owners can understand.  As <strong><a href="http://www.myrcurial.com/">Myrcurial</a></strong> twittered me &#8220;<span class="entry-content">27001 is orthoganal to process&#8221; meaning (I hope) that metrics have their foundation in events that are generated by processes.  27001 by itself was never meant to create metrics (see above), and so we&#8217;re asking a question the ISO can&#8217;t answer.  But the desire, the need to measure still exists.  To that extent we can google &#8220;ISO compliance&#8221; (whatever that means) and if something can be certifiable or deemed &#8220;compliant&#8221; we can and are &#8220;measuring&#8221;.  But does that have value?</span> Rybolov (<strong><a href="http://www.guerilla-ciso.com/">my favorite Guerilla CISO</a></strong>) wrote:</p>
<blockquote><p><em>&#8220;Whatever you do, don’t start measuring percentage of compliance. Eventually, that’s what all metrics efforts around a framework devolve into.&#8221;</em></p></blockquote>
<p>I have to agree.  Being ISO &#8220;compliant/certified&#8221; has little expressive business value <em>prima facia</em>. I find that one KPI that absolutely asserts value when expressed properly is risk - and similarly  <strong><a href="http://layer8.itsecuritygeek.com//layer8">Shrdlu</a></strong> wrote:</p>
<blockquote><p><em>&#8220;I really have no idea. I personally wouldn’t try to justify an ISO implementation by itself. If I could show traceability on how it affected our overall security risk, then that’s what I’d do.&#8221;</em></p></blockquote>
<p>And that&#8217;s a delightful answer.  That &#8220;traceability&#8221; (geeze-louise Shrdlu - what a word!) is absolutely what I&#8217;m after here.  How do I get that?  <span class="entry-content"> </span></p>
<p><span class="entry-content">If you&#8217;re going to do something with corporate budget (time, money - and goodness knows an ISO implementation is time &amp; money) you better be able to communicate the value.  And while the zealotry for ISO implementation differs from person to person, I have yet to come across someone who says that ISO adoption is totally without value.  It&#8217;s just not apparent what that value of adoption is and how we can measure (metrics) and express it (KPIs).<br />
</span></p>
<p>Jenean Paschalidis wrote what he thought that value was in a very nice email in which he puts a qualitative name on the value of adoption:</p>
<blockquote><p><em>&#8220;Transparency and accountability-this is what all executive/senior management (the company) is on the hook for. ISO provides that. If you want to understand and have confidence in your operations as supported by security (because you will know the who, what, where, when, why and how of a system (human, technical etc.) and you want to be able to trace back why a decision (risk-vetted) had been made - then adoption of this best international practice will assist in providing these answers.&#8221;</em></p></blockquote>
<p>So working with our above thoughts a little here - if we agree with Shrdlu that the only value of an ISO implementation can only be expressed if we can say how said implementation affected our overall security risk - and we agree with Jenean that the primary benefit is an ability to have confidence in operations as supported by security, then&#8230;.</p>
<p><em><strong>The value of the ISO should be expressed as a KPI or set of KPIs that cleary explain how the confidence it generates helps us understand (and then reduce) our risk. </strong></em></p>
<p>If risk is a probability issue,  ISO adoption helps generate confidence in our predictive analytics.  The dollar value the ISO generates (the ultimate KPI) is part of the cost of being able to make wise risk decisions.</p>
<p style="text-align: center;"><strong><span style="color: #ff0000;">So what is that (making wise risk decisions) worth to you?</span></strong></p>
<p style="text-align: center;">
<p><strong><span style="color: #003300;">SOME CONCLUDING THOUGHTS</span></strong><em><span style="color: #003300;"><br />
</span></em></p>
<p>First, it occurs to me that this is a real shame.  In a sense, an inability to generate a quantitative value statement for ISO use is simply more witch-doctory (<em>&#8220;use it because we, the wise men of the tribe say you should&#8221;</em>).  In some future version, the ISO should include some mechanism for measuring and expressing the worth of adoption to the organization (a better reason to use the ISO than &#8220;because we said so&#8221;).</p>
<p><span style="color: #003300;">Second, It should be noted that of Jack Jones&#8217; 3 true value statements from which all metrics/KPIs should point to - we&#8217;re only talking about one of those value statements - the ability to reduce risk.  Using the ISO in an organization most certainly could create operational efficiencies (help us do more with less) - but the ISO isn&#8217;t a standard that creates operational efficiencies as a primary goal, nor does it give implicit direction on how to create operational efficincies.    The ISO folks do, however, play fast and loose with the idea of &#8220;risk&#8221; and &#8220;risk management&#8221; so it&#8217;s within this context that I interpreted our conversation.</span></p>
<p>Finally if you&#8217;re going to hire someone to help you with ISO adoption in your organization, the deliverables you ask for in your RFP/SOW/what-have-you should include quantitative (probability) statments about risk reduction and the creation of operational efficiencies.  If the firms answering can&#8217;t tell you what value their work will be to your company, then drop me a note and I&#8217;ll gladly point you to some friends of RMI&#8217;s that know FAIR &amp; all our Risk Management frameworks and also do great ISO work.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Dec 2008 12:47:11 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/iso">iso</category>
      <category domain="http://www.securityratty.com/tag/iso google">iso google</category>
      <category domain="http://www.securityratty.com/tag/iso adoption">iso adoption</category>
      <category domain="http://www.securityratty.com/tag/iso implementation">iso implementation</category>
      <category domain="http://www.securityratty.com/tag/iso folks">iso folks</category>
      <category domain="http://www.securityratty.com/tag/iso adoption helps">iso adoption helps</category>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/google iso compliance">google iso compliance</category>
      <category domain="http://www.securityratty.com/tag/iso implementation differs">iso implementation differs</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=527">What is a Wise Risk Decision Worth? or ISO 27001 KPIs Follow Up</source>
    </item>
    <item>
      <title><![CDATA[Anti-Debugging Series - Part I]]></title>
      <link>http://www.securityratty.com/article/5dc5d012cfad6c070272eeb8f4c0dc2b</link>
      <guid>http://www.securityratty.com/article/5dc5d012cfad6c070272eeb8f4c0dc2b</guid>
      <description><![CDATA[For those that dont know, anti-debugging is the implementation of one or more techniques within computer code that hinders attempts at reverse engineering or debugging a target process. Typically this...]]></description>
      <content:encoded><![CDATA[<p>For those that don&#8217;t know, anti-debugging is the implementation of one or more techniques within computer code that hinders attempts at reverse engineering or debugging a target process. Typically this is achieved by detecting minute differences in memory, operating system, process information, latency, etc. that occur when a process is started in or attached to by a debugger compared to when it is not. Most research into anti-debugging has been conducted from the vantage point of a reverse engineer attempting to bypass the techniques that have been implemented. Limited data has been presented that demonstrates anti-debugging methods in a high level language that the average developer can understand. It is with this in mind that I hope to begin a series of posts that present some of the methods of anti-debugging in a clear, concise, and well documented fashion. The end goal of this series is to arm developers with the techniques and knowledge that will allow them to add a layer of protection to their software while simultaneous educating reverse engineers in some of the anti-debugging methods used by malware authors today.</p>
<p>Before we delve into the intricacies of individual methods of anti-debugging let&#8217;s use this post to define the classes of anti-debugging that we will be discussing. While other classes may exist, the definition of these classes is an attempt to include the majority of anti-debugging methods in use today. There is some overlap between classifications and we may have left out some methods due to limited exposure or effectiveness.</p>
<p><strong>API Based Anti-Debugging</strong><br />
API based anti-debugging is the most straightforward and possibly the easiest to understand for a typical developer. Using both documented and undocumented API calls, these methods query process and system information to determine the existence or operation of a debugger. From single line calls such as IsDebuggerPresent() and CheckRemoteDebugger() to slightly more complex methods including debugger detaching and CloseHandle() checks. These methods are generally trivial to add to an existing code base and many can even be implemented in as few as two or three lines.</p>
<p><strong>Exception Based Anti-Debugging</strong><br />
Exception based anti-debugging is slightly different than your basic API based techniques. Many times when a debugger is attached to a process, exceptions are trapped and handled by the debugger without regard to passing the exception back to the application for continued execution. Occasionally these exceptions can even crash or terminate a process when run under a debugger and be handled gracefully when running clean. It is these discrepancies that makes exception based anti-debugging techniques possible.</p>
<p><strong>Process and Thread Block Anti-Debugging</strong><br />
Some of the API based anti-debugging methods use published functions to query information from within the process and thread blocks for our running code. Many API based detections can be subverted within a debugger by hooking the API call and returning values that indicate a clean process. One way around this subversion is to directly query the process and thread blocks, bypassing the API calls. Direct analysis of the process and thread blocks, while more complex, can lead to a more accurate and high assurance result.</p>
<p><strong>Modified Code Anti-Debugging</strong><br />
One of the methods that a debugger uses to signal a breakpoint is to insert a break byte into the running code at the location that it wishes to stop execution. The process execution breaks when this value is seen, giving control to the debugger. When the program is resumed, the breakpoint value is removed and replaced with the original byte, the execution backed up one byte, and the program is resumed. Detection of software based breakpoints can be achieved by analyzing the process for modifications from the expected norm.</p>
<p><strong>Hardware and Register Based Anti-Debugging</strong><br />
A second way that a debugger can break the execution of a process is by using a hardware breakpoint. A hardware breakpoint relies upon CPU registers to store the pertinent information and to detect when the target break addresses are seen on the bus. A break interrupt is triggered at the appropriate time based on these register values. Reading or modifying the hardware can allow for the detection of a debugger.</p>
<p><strong>Timing and Latency Anti-Debugging</strong><br />
Finally timing and latency can be used as an effective anti-debugging method. When executing a program within a debugger, specifically when single stepping, a much larger latency occurs between execution of instructions. This latency can be detected and compared against a reasonable threshold to detect the existence of a debugger attached to our process.</p>
<p>Each of the classes of anti-debugging outlined above has merit when used individually to protect a process. While none of them can be assured to ever protect a program from a determined reverse engineer or debugger, implementation of these techniques (or many of them if appropriate) can sufficiently slow down the debugging process and hopefully make the attacker spend his time on other, easier, ventures. In the remainder of this series on anti-debugging we will review in depth some of the more interesting methods of each of the above classes. So bring along your debugger and your development environment and let the games begin.</p>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 17:56:25 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/process execution breaks">process execution breaks</category>
      <category domain="http://www.securityratty.com/tag/execution">execution</category>
      <category domain="http://www.securityratty.com/tag/process">process</category>
      <category domain="http://www.securityratty.com/tag/methods query process">methods query process</category>
      <category domain="http://www.securityratty.com/tag/hardware breakpoint">hardware breakpoint</category>
      <category domain="http://www.securityratty.com/tag/hardware">hardware</category>
      <category domain="http://www.securityratty.com/tag/process information">process information</category>
      <category domain="http://www.securityratty.com/tag/target process">target process</category>
      <category domain="http://www.securityratty.com/tag/methods">methods</category>
      <source url="http://www.veracode.com/blog/2008/12/anti-debugging-series-part-i/">Anti-Debugging Series - Part I</source>
    </item>
    <item>
      <title><![CDATA[Gartner Data Center Conference 2008]]></title>
      <link>http://www.securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</link>
      <guid>http://www.securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</guid>
      <description><![CDATA[The Gartner Data Center Conference kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Pucks...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="96" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/12/clip-image002.jpg" width="439" border="0" /></p>
<p>The <a href="http://www.gartner.com/it/page.jsp?id=627607" target="_blank">Gartner Data Center Conference</a> kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Puck&#8217;s Bistro told me they were looking <a href="http://www.datacenterknowledge.com/archives/2008/12/02/at-the-gartner-data-center-conference/" target="_blank">forward to the 1800 people coming</a> to this show to fill the hotel up. As we&#8217;ve noted, the economic crisis is impacting business travel all around.</p>
<p>22% of the attendees at Data Center come from the public sector and government, with 44% coming from very large enterprises of 20K+ employees.</p>
<p>During the <a href="http://www.gartner.com/it/page.jsp?id=603107" target="_blank">Gartner IOM conference</a> in June, some of the most interesting info coming out of it was the quick polls of the audience on a variety of infrastructure and operations management topics. What are enterprises doing? Where are they headed? What&#8217;s important to them? Here are some quick takes from the opening session:</p>
<p>1) What is the largest data center challenge that you currently face?</p>
<ul>
<li><b>Smaller Budgets: 21%</b></li>
<li><b>Power &amp; Cooling: 20%</b></li>
<li>Dealing with the Rate of Technology Change: 15%</li>
<li>Aligning Activities with the Business: 15%</li>
<li>Modernizing Legacy Applications: 10%</li>
<li>Lack of Data Center Space because of Equipment Spread: 9%</li>
<li>How to Source IT Services: 5%</li>
<li>How to Find and Retain Talent: 5%</li>
</ul>
<p>Well, it&#8217;s taken almost a year to be &#8220;official&#8221;, but the National Bureau of Economic Research just announced that <a href="http://www.msnbc.msn.com/id/27999557/" target="_blank">the US has been in a recession since December of 2007</a>. It should come as a surprise to no one that dealing with smaller budgets is top of mind, even for the predominantly larger enterprises attending here. </p>
<p>2) What projects will receive the most funding in 2009?</p>
<ul>
<li><b>Virtualization/Consolidation: 31%</b></li>
<li>Data Center Facilities &#8211; new builds: 17%</li>
<li>IT Operations Process Improvement: 12%</li>
<li>IT Modernization: 7%</li>
<li><b>Green IT: 5%</b></li>
</ul>
<p>Virtualization and (server) consolidation projects are clearly a priority for larger enterprises in 2009. What&#8217;s interesting here is the relatively very low priority of <a href="http://www.devx.com/IT_Innovation/Article/40073?trk=DXRSS_LATEST" target="_blank">Green IT projects</a> &#8211; in spite of the importance to attendees of getting power and cooling costs under control. Perhaps there&#8217;s a gap here between what&#8217;s often the hype of Green IT and practical considerations for data center managers when it comes to power and cooling management.</p>
<p>3) Where are you with server consolidation projects?</p>
<ul>
<li>No Plans: 3%</li>
<li>Looking at it now and will start in next 2 years: 13%</li>
<li><b>In process now: 58%</b></li>
<li><b>Have already completed server consolidation project: 26%</b></li>
</ul>
<p>Larger enterprises are consolidating servers with a quarter of attendees already having gone through the process at least once. And according to poll #2, this trend will definitely continue.</p>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 15:55:49 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/data center">data center</category>
      <category domain="http://www.securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://www.securityratty.com/tag/predominantly larger enterprises">predominantly larger enterprises</category>
      <category domain="http://www.securityratty.com/tag/server">server</category>
      <category domain="http://www.securityratty.com/tag/server consolidation projects">server consolidation projects</category>
      <category domain="http://www.securityratty.com/tag/data center managers">data center managers</category>
      <category domain="http://www.securityratty.com/tag/consolidation projects">consolidation projects</category>
      <category domain="http://www.securityratty.com/tag/data center facilities">data center facilities</category>
      <category domain="http://www.securityratty.com/tag/larger enterprises">larger enterprises</category>
      <source url="http://blog.sciencelogic.com/gartner-data-center-conference-2008/12/2008">Gartner Data Center Conference 2008</source>
    </item>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://www.securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://www.securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://www.securityratty.com/tag/fast">fast</category>
      <category domain="http://www.securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://www.securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://www.securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://www.securityratty.com/tag/mybank">mybank</category>
      <category domain="http://www.securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://www.securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://www.securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Opinion: Is there a hidden cost to data protection?]]></title>
      <link>http://www.securityratty.com/article/dfc1703064585bcca4528d89ce343275</link>
      <guid>http://www.securityratty.com/article/dfc1703064585bcca4528d89ce343275</guid>
      <description><![CDATA[Companies rushed into data protection by the fear of losing precious information may have been too quick to throw together a patchwork quilt of security software, which is now proving...]]></description>
      <content:encoded><![CDATA[Companies rushed into data protection by the fear of losing precious information may have been too quick to throw together a patchwork quilt of security software, which is now proving costly.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3ecb326618f303934af84094020a0199:OZ6%2BQzp8NNp6H9pYICbBqngEEwS606b%2F4Cx9qY1hHbnTkbDpYmePdlJV8f%2FPkcm2iUQSlrz33tg3'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f3798621b2e09530d4964cee659be6b6:2EK%2B7xdz4RJC0hwzAvoDlX9IZsupLJQ7VlkdpoGkNSz2C%2FYscCiAA6fM5y0mdJkopNEU%2FlC1W%2FSOeQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2394ecdce673f9934b0515d68bc3db82:F7NeyLHemw2pvRZbtGIyZr1vovwiG7ii9BvSexFesHL2GXaRcHAb0xwqseHpD013ADE0s3KGYv6Tlg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:85bcd0a812095b02462bfb949a4ba46e:jNQHN9UMCvrzmHmHW4k6mmpzITqD80c21KfqL4CzcEi70o9dA71lJp3mS8mRjGU6Wcnea16hEIwLHA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/click.phdo?s=7adbefb21761e9bc1b21bc6013e906dc&p=1"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=7adbefb21761e9bc1b21bc6013e906dc&p=1"/></a>
<img src="http://www.pheedo.com/feeds/tracker.php?i=7adbefb21761e9bc1b21bc6013e906dc" style="display: none;" border="0" height="1" width="1" alt=""/>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/data protection">data protection</category>
      <category domain="http://www.securityratty.com/tag/security software">security software</category>
      <category domain="http://www.securityratty.com/tag/patchwork quilt">patchwork quilt</category>
      <category domain="http://www.securityratty.com/tag/precious information">precious information</category>
      <category domain="http://www.securityratty.com/tag/fear">fear</category>
      <category domain="http://www.securityratty.com/tag/companies">companies</category>
      <category domain="http://www.securityratty.com/tag/costly">costly</category>
      <category domain="http://www.securityratty.com/tag/quick">quick</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=7adbefb21761e9bc1b21bc6013e906dc">Opinion: Is there a hidden cost to data protection?</source>
    </item>
    <item>
      <title><![CDATA[Job-fearing workers admit plans to steal corporate data]]></title>
      <link>http://www.securityratty.com/article/bf75c9cb3469a6028f3a9dfd5369a79b</link>
      <guid>http://www.securityratty.com/article/bf75c9cb3469a6028f3a9dfd5369a79b</guid>
      <description><![CDATA[Workers that are anxious about being laid off are prepared to steal corporate data on removable devices or bribe IT staff for information, a survey has...]]></description>
      <content:encoded><![CDATA[Workers that are anxious about being laid off are prepared to steal corporate data on removable devices or bribe IT staff for information, a survey has revealed.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e2319b1b456117aaa7989f87039e2ddf:3M8lMfgSbaTLJHH%2FvNBLxA8eK2BU9sLqvWS7AM%2BZBRj1baUO2g9Hb0oBa6KLZnUK1BYzxXTFCEzI'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f8e9de4616c57adc6939c762e3378bb1:9gjaFvipVYn%2BC0EMo6UO0C2%2BCzEpOrroVHYs8BzKPqO3OfC27amunpDVHP%2BqSkiH%2B6Obwh0GxqID7g%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9815720009f93d7ed0b1c83320addda6:z0%2FArCzmizz%2BukERhijYenHgmvZRsh%2F5rFRQYr0DpEGNABLrhXxa%2FhGSNzp1Wqy03F6fJnrUxSgn9Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:12a1738ca9490d3403a979af35812650:WZXHA%2BS37ewZqy61rovI%2F2Id%2B1L9LDmWr96ITFcit8v0jPEe5TyhkwBr0CQovfm%2B1pLq%2Ftcs3saQjg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=5433eec9ffd34381f58148d3aa4cd6d2&amp;p=1"><img style="border:0;" src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=5433eec9ffd34381f58148d3aa4cd6d2&amp;p=1" border="0" /></a>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 02:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/workers">workers</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/removable devices">removable devices</category>
      <category domain="http://www.securityratty.com/tag/laid">laid</category>
      <category domain="http://www.securityratty.com/tag/bribe">bribe</category>
      <category domain="http://www.securityratty.com/tag/information">information</category>
      <category domain="http://www.securityratty.com/tag/staff">staff</category>
      <category domain="http://www.securityratty.com/tag/survey">survey</category>
      <category domain="http://www.securityratty.com/tag/anxious">anxious</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=5433eec9ffd34381f58148d3aa4cd6d2">Job-fearing workers admit plans to steal corporate data</source>
    </item>
    <item>
      <title><![CDATA[Updated Microsoft Security Assessment Tool]]></title>
      <link>http://www.securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</link>
      <guid>http://www.securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</guid>
      <description><![CDATA[Greetings. In case you havent already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. Its been four years since the initial...]]></description>
      <content:encoded><![CDATA[<p>Greetings. In case you haven’t already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. It’s been four years since the initial release, and two years since the prior version. Between then and now your security world has evolved a lot, and the tool now reflects that.</p>  <p>Read more: <a title="http://technet.microsoft.com/en-us/security/cc185712.aspx" href="http://technet.microsoft.com/en-us/security/cc185712.aspx">http://technet.microsoft.com/en-us/security/cc185712.aspx</a></p>  <p>Download now: <a title="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en</a></p>  <p>Take a few moments and give yourself a security checkup. If you have any comments or feedback on the tool, feel free to leave them here on my blog—I’ll make sure the right people see it.</p>  <p>&#160;</p>  <p>From the download page:</p>  <p>The MSAT employs a holistic approach to measuring your security posture by covering topics across people, process, and technology. Findings are coupled with prescriptive guidance and recommended mitigation efforts, including links to more information for additional industry guidance. These resources may assist you in keeping you aware of specific tools and methods that can help change the security posture of your IT environment. </p>  <p>There are two assessments that define the Microsoft Security Assessment Tool: </p>  <ul>   <li>Business Risk Profile Assessment</li>    <li>Defense in Depth Assessment (UPDATED)</li> </ul>  <p>The questions identified in the survey portion of the tool and the associated answers are derived from commonly accepted best practices around security, both general and specific. The questions and the recommendations that the tool offers are based on standards such as ISO 17799 and NIST-800.x, as well as recommendations and prescriptive guidance from Microsoft’s Trustworthy Computing Group and additional security resources valued in the industry.</p>  <p>After completing an Assessment, you will gain access to a detailed report of your results. You may also compare your results with those of your peers (by industry and company size), provided that you upload your results anonymously to the secure MSAT Web server. When you upload your data the application will simultaneously retrieve the most recent data available. To be able to provide this comparative data, we need customers such as you to upload their information. All information is kept strictly confidential and no personally identifiable information whatsoever will be sent.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3162703" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 01:13:03 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/security world">security world</category>
      <category domain="http://www.securityratty.com/tag/additional security resources">additional security resources</category>
      <category domain="http://www.securityratty.com/tag/tool">tool</category>
      <category domain="http://www.securityratty.com/tag/security posture">security posture</category>
      <category domain="http://www.securityratty.com/tag/identifiable information whatsoever">identifiable information whatsoever</category>
      <category domain="http://www.securityratty.com/tag/assessment">assessment</category>
      <category domain="http://www.securityratty.com/tag/information">information</category>
      <category domain="http://www.securityratty.com/tag/tool offers">tool offers</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/12/01/updated-microsoft-security-assessment-tool.aspx">Updated Microsoft Security Assessment Tool</source>
    </item>
    <item>
      <title><![CDATA[Feds nab more members of alleged identity theft gang]]></title>
      <link>http://www.securityratty.com/article/7b6c103dda5a8d3db36fbc7e2686d443</link>
      <guid>http://www.securityratty.com/article/7b6c103dda5a8d3db36fbc7e2686d443</guid>
      <description><![CDATA[Federal authorities say they have taken another step toward busting a multinational identity theft ring that is alleged to have used stolen personal data to withdraw millions of dollars from home...]]></description>
      <content:encoded><![CDATA[Federal authorities say they have taken another step toward busting a multinational identity theft ring that is alleged to have used stolen personal data to withdraw millions of dollars from home equity line-of-credit accounts at dozens of financial institutions in the U.S., including some of the country's largest banks.]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 21:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/multinational identity theft">multinational identity theft</category>
      <category domain="http://www.securityratty.com/tag/federal authorities">federal authorities</category>
      <category domain="http://www.securityratty.com/tag/personal data">personal data</category>
      <category domain="http://www.securityratty.com/tag/withdraw millions">withdraw millions</category>
      <category domain="http://www.securityratty.com/tag/financial institutions">financial institutions</category>
      <category domain="http://www.securityratty.com/tag/country">country</category>
      <category domain="http://www.securityratty.com/tag/banks">banks</category>
      <category domain="http://www.securityratty.com/tag/step">step</category>
      <category domain="http://www.securityratty.com/tag/dollars">dollars</category>
      <source url="http://www.networkworld.com/news/2008/120208-feds-nab-more-members-of.html?fsrc=rss-security">Feds nab more members of alleged identity theft gang</source>
    </item>
    <item>
      <title><![CDATA[Windows software encrypts group-policy security]]></title>
      <link>http://www.securityratty.com/article/8ad904188f1544041ce596aebc452ae7</link>
      <guid>http://www.securityratty.com/article/8ad904188f1544041ce596aebc452ae7</guid>
      <description><![CDATA[Unisys Stealth Solution for Network makes use of session-based encryption keys for policy-based access to...]]></description>
      <content:encoded><![CDATA[Unisys Stealth Solution for Network makes use of session-based encryption keys for policy-based access to data.]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 21:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/unisys stealth solution">unisys stealth solution</category>
      <category domain="http://www.securityratty.com/tag/encryption keys">encryption keys</category>
      <category domain="http://www.securityratty.com/tag/network">network</category>
      <category domain="http://www.securityratty.com/tag/access">access</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <source url="http://www.networkworld.com/news/2008/120208-unisys-stealth-encryption.html?fsrc=rss-security">Windows software encrypts group-policy security</source>
    </item>
    <item>
      <title><![CDATA[The "A"]]></title>
      <link>http://www.securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</link>
      <guid>http://www.securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</guid>
      <description><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here

Generally, most people in Information...]]></description>
      <content:encoded><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here.<br /><br />Generally, most people in Information Security today did not start out as pure Information Security people, they evolved. And where they evolved from gives one a clue as to their mindset and how they see themselves.<br /><br />Some come from an Audit background and you'll recognise these guys from their love of lists and frameworks - they dream of Cobit controls and little boxes that are waiting for ticks. Somehow they have tons of documentation and they know it all and can find it all. They generally drive Volvo's and like order.<br /><br />But most InfoSec guys come from an IT background and it shows. I guess that, having said that, most hackers come from an IT background too. And it shows.<br /><br />Now, lets consider the C-I-A triangle thingum. Quick lesson for those who don't know it - there are three aspects of information that Information Security wishes to preserve - the <span style="font-weight: bold;">C</span>onfidentiality, the <span style="font-weight: bold;">I</span>ntegrity and the <span style="font-weight: bold;">A</span>vailability. From my experience, most IT people are governed by Availability - the "A". In fact, when an IT contract is drawn up - there is no SLI or SLC but there will always be an SLA. With very specific terms, measurements and penalties.<br /><br />If the Firewall crashes and has to be rebuilt. What will the IT manager be most interested in? The A - how fast can you get the traffic moving again?<br /><br />So we have tools to measure uptime in 99.999999999999999s and such and anything that can cause network downtime (or if the network is up and the services such as mail are down - same difference) is taken care of. Spam, worms, viruses etc.<br /><br />I guess that hackers (those that define what we do) are also IT background people. They seem to be more concerned with big-bang, widely deployed DoS attacks and stealing IT resources. At least, they used to be, until they discovered that they could make money from stealing information. Actually, I may be naive but I don't believe that the hackers we have today are the same as those we had in the past... I believe that we have a new generation of hackers - criminals who merely use the Internet to steal money because that it where the money is easiest to steal.<br /><br />The problem is that we were lucky in a way that our old tools worked against the threats that we had - firewalls, antiviruses, etc etc. They don't work against people breaking into our networks and stealing information. For that we need a new generation of Information Security people (or the old generation to update their game)...<br /><br />Here is a quick poll to see which generation you are in:<br /><br />1. What is the one piece of information on your network that your competitors would love to see?<br />2. What is the percentage of mails coming into your network that are spam?<br />3. What mail is going to competitors?<br />4. What is the process for someone to order a pencil?<br />5. What is a blog?<br />6. Who in your organisation uses facebook for business?<br />7. How many of your PCs have up-to-date antivirus?<br />8. What is the worst virus out at the moment?<br />9. Do you believe that your Firewall is configured correctly?<br /><br />The answers are as follows:<br />1. This is ESSENTIAL to know if you want to be in the next generation. And you can't guess this. You may think that it is something financial but most financial information can be guessed by your competitors anyhow. You may think it is a recipe or special way of doing something but any established company has had their recipe ripped off anyhow and can beat any new competitor by competitive pricing. It may be new product information. It may be staff information. It may be the CEO's contact list. Don't guess - find out.<br /><br />2. Who cares? Certainly not the CEO. Maybe the CIO. "We are saving you x amount of bandwidth and your users x amount of time" is nice but won't save the business from closing down due to data loss. Operationalise this and get on with your job.<br /><br />3. Good to know. I'm sure that if you told your CEO/CIO "Last week we detected 5 large emails going to our competitors from inside our R&amp;D department" you'd have his full attention.<br /><br />4. Good to know. Who does the ordering? Who does the okaying? Who does the paying? If you know all of this then you know how business works. And when things go wrong - you'll be able to help.<br /><br />5. And do you want your staff to use them? And if they do, what can they put on them? What are they puting on them?<br /><br />6. This is an interesting question because Facebook is usually an issue of "The A" (productivity). But it can be an issue of C and I.<br /><br />7. Who cares? Again, this is an operational issue. Viruses that jump onto your radar are usually ones that attack "the A" but its the ones that are pushing information out of your organisation that are sneaky enough not to have sgnatures and not to be discovered. You will have PCs without up-to-date antivirus and you will have viruses. The trick is not to let your information be stolen by viruses. Also, keep backups so if a PC does get wiped out - you can get the information back again (but this is an operational issue again).<br /><br />8. Trick question - the answer is - the one you don't know about. Old generation InfoSec guys can rattle off names of viruses that are all in the top 10 at the moment.. New generation viruses are targetted and usually do their worst before a pattern is out.<br /><br />9. Old generation answer - yes. New generation answer - who cares? Information flows all over including in and out of the Firewall. Firewalls also usually rely on port security but most everything runs on port 80 anyhow so the Firewall should be configured but it doesn't kep us safe - more work needs to be done for that.<br /><br />I find that it is not very easy to move from old generation to new generation InfoSec. The main difference is that old generation was very technical and appealed to the technical nature of computer geeks. The new generation is business oriented and requires more interaction with people, more meetings, more time with people. Ouch.<br /><br />There will always be a place for technical people in Information Security but as the tools mature and "just work" there is less demand. And a background in technology is very useful when the technical guys try to "BS" you.<br /><br />And "the A" is very important too. Protecting your network from being brought down. Protecting information from disappearing. Stopping viruses. Etc. But the new generation will need to consider "the I" and "the C" as well because the attacks against these and the importance of protecting information against disclosure or manipulation will increase.<br /><br />This post was done to add my voice to what Rich says so quickly and concisely in the <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">securosis blog</a>.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/471338550" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:57:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/financial information">financial information</category>
      <category domain="http://www.securityratty.com/tag/information">information</category>
      <category domain="http://www.securityratty.com/tag/information security">information security</category>
      <category domain="http://www.securityratty.com/tag/generation infosec guys">generation infosec guys</category>
      <category domain="http://www.securityratty.com/tag/infosec guys">infosec guys</category>
      <category domain="http://www.securityratty.com/tag/information security people">information security people</category>
      <category domain="http://www.securityratty.com/tag/guys">guys</category>
      <category domain="http://www.securityratty.com/tag/staff information">staff information</category>
      <category domain="http://www.securityratty.com/tag/technical guys">technical guys</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/471338550/a.html">The "A"</source>
    </item>
  </channel>
</rss>
