Tuesday, June 23, 2015

Fitbit Data Helps Disprove Rape Claim

I know, I know...not the typical headline you expect to see on a security topics blog.  Bear with me for a bit, though...

Last March a woman name Jeannine Risley called 9-1-1 alledging that a man in his 30s  had broken into the place she was staying, woke her,  and raped her.  Police found overtuned furniture, a vodka bottle, and a knife on the scene when they responded.  Still, something didn't seem right about the story (example:  there was fresh snow on the ground and there were now footprints in the snow leading to the house) so they kept investigating.  As part of the investigation, police requested that Mrs. Risley provide them the Fitbit device that she was wearing so that they could analyze the data.  Sure enough, the Fitbit data proved that Mrs. Risley was awake and walking around during the period where she claimed to be asleep.  This, combined with other evidence, provided sufficient cause to charge Mrs. Risley with several misdemeanor offenses.

As one might imagine, it is use of Fitbit data that has propelled this matter to the national stage.  As those in our profession have stated far too often, once individuals place data "out there" it is nigh impossible to restrict its use.  Mrs. Risley willingly wore a device designed to track and record her activity;  it should not be surprising to anyone that that same data could be used to prove or disprove the commission of an unlawful act. While it's doubtful that this one case will spark a substantive ripple in the push for wearable technologies or an expansion of the Internet of Things, we might finally begin to see some chatter outsite of our own professional circles about the privacy and legal implications of an uber-networked society -- to include protecting the data collected from from unauthorized alteration.

My two cents.  Click here for a quick link to the original story.

Monday, June 8, 2015

Security IPB

For the past 6 weeks I have been listening to the rumbles and fallout of the RSA conference…
 
…no, that’s not quite correct. It’s not been the fallout from the conference itself, but of the gauntlet thrown by RSA’s new president, Amit Yoran.
 
In his keynote address, Amit called out the security industry for its “dark ages” approach to the problem of security, laying out 5 tenets for navigating the terrain of today's new security battlefield. While I was not in attendance at RSA this year (San Francisco for a conference or the Caribbean for my wife's birthday? Hmm…) , I read both the RSA press release and a transcript of the address in the days after the event.
 
I am wholeheartedly supportive of Amit’s overall message regarding the need for both the security industry and the security profession to adjust their thinking regarding the problem and the fight. Should we fail to make such an adjustment, we will continue to be viewed as an obstacle to success, an impediment to revenue…and, should we continue to fail in our perceived mission, we risk being viewed as an ineffective drag on profitability. That being said, as the profession reaches to pick up the gauntlet that Mr. Yoran has thrown, it is important to understand the full context of the battlefield on which we fight. Amit pulls upon his experience as a West Point graduate and former military officer. As another graduate and former military officer, allow me to continue the analogy by doing some old-fashioned “intelligence preparation of the battlefield (IPB)” and take a deeper look at some of the battlefield conditions we face daily.
 
1. We need to preach to masses, not to the choir.  “Let’s stop believing that even advanced protections work. No matter how high or smart the walls, focused adversaries will find a way over, under, around, and through.” My first thought when I read this statement was, “Preach it, brotha!” Every board member and every executive I meet when I take a new job wants to know that they are “safe.” I spend much of my time during the first 30 days of any new gig reminding executives that as long as they are open for business they will never be completely invulnerable. My next thought around this point, though, was to hope that members of the security industry (those professionals who create and market the wonderful tools, technologies, and services we all use) and not just the security profession (in house personnel currently working to protect an organization’s resources) heard what Amit was saying. While it remains true that any professional who thinks they can make an enterprise invulnerable needs a wake-up call, it is equally true that members of the security industry also need to stop making promises of nirvana and panacea -- and not just to us, but to those around us who can influence purchasing. How many of us continue to have to address the CFO, CIO, or CEO who “just talked to XYZ Vendor and they said we can’t be compliant/secure/grow hair/stop global warming without their product?” Indeed, as C-level security professionals are increasingly weaving a story of managed risk and potential vulnerability, the security industry has begun to find points of entry into the enterprise that do not involve us. Amit alludes to such promises being made during his address, but this point should not be glossed over as it is a contributor to some of the challenges we face daily whilst attempting to secure the enterprise.
 
2. There is a cost associated with visibility – and that cost exists outside of the security budget.  Amit advocates “a deep and pervasive level of true visibility everywhere -- from the endpoint to the network to the cloud.”  He goes on to describe true visibility as including things such as full packet capture; endpoint compromise assessment visibility; and a detailed understanding of which systems are communicating with which, and what’s being communicated. Many security professionals are faced with the every-present quandary of obtaining complete, detailed, and accurate data flow diagrams within older, multi-faceted enterprises. In many cases (except in heavily regulated spaces), these diagrams do not exist until security personnel ask for them -- and when provided, their accuracy levels tend to be suspect. Further, assuming the data flows exist, the level of potential increase in bandwidth and horsepower on the network and the systems themselves in order to provide “true visibility” may be punitive and/or force systems upgrades and unexpected costs within the IT organization. (Think I’m kidding? How many of you reading this article have been told that “turning auditing on for <insert system here> will kill the server/bog down the application/consume too much bandwidth?”)
 
3. You can’t ignore the rest of the I-AAA equation.  Amit rightfully discusses the importance of Identity and Access “[i]n a world with no perimeter and fewer security anchor points.”  Let us remember, though,  that there are two other A’s to the I-AAA equation and at least one of them is of equally (if not more) critical importance in the current terrain: Authorization. Pop quiz, everyone: raise your hand if you can, with 100% certainty, guarantee that you know exactly the privileges and roles for absolutely every system and person in your organization AND that they are 100% complete, accurate, and appropriate. I'm not talking about the quarterly signoffs that organizations do in lieu of the in-depth visibility that Amit is referring to, but rather a detailed role mining and mapping of every system and every application in the enterprise to a meticulous level of detail that ensures entitlements are tight and accurate. 
 
Most mature enterprises struggle with I-AAA over time. Unless the organization has either (a) taken the opportunity to maintain entitlement and role accuracy throughout its life cycle, or (b) invested the time (and not insignificant dollars) to do the detailed analysis and mapping, the result is a level of blindness to entitlements which is a (if not the) major contributor to security professionals maintaining a border-centric outlook. If I don’t know who you are and/or whether where you are allowed to go is appropriate, then the easiest solution is to build a wall and limit the entries/egresses to the castle. Cleaning up the authorization problem requires a level of (expensive) buy-in from IT and the organization as a whole. Many organizations do not see the criticality of such an expense yet still wish for the flexibility of a borderless environment…placing the security professional in the awkward position of appearing to be a Luddite and an inhibitor to the business or weakening (if not eliminating) the ROI associated with borderless cloud-based operations.
 
4. Asset categorization, to be useful, requires a depth of understanding of the enterprise and data flows. In most organizations, at least part of the assets considered to be critical and/or high value would be data. Strongpointing your defenses around critical assets which house the data is a good start…but it also means controlling who has access to that data and the systems which communicate to/from that critical asset. In other words, in order to effectively accomplish Point 5 of Amit’s 5-point plan, Points 2 (deep visibility) & 3 (strong identity & access) need to be accomplished first.  Again, these objectives will require buy in and expense outside of security’s bailiwick in order to succeed.
 
Amit Yoran’s call to arms is one that is timely, accurate, and well needed…as far as it goes. Yes, security professionals need to look at the problem differently and more holistically, but I would also contend that many (most?) C-level security professionals. already do this and are actively educating our teams and constituents appropriately. The challenge, however, in operating in a manner reflective of a proper mindset is to change the conditions of the battlefield upon which we engage. The security profession continues to refine our language and our metrics to discuss the causal relationships between incomplete data flow analysis, I-AAA concerns, and the increased risks of tearing down borders -- with mixed success. The border is effectively dead, yes…but security professionals cannot maintain comparable levels of risk to the enterprise if we tear down the borders without addressing the areas in Amit’s five-point treatise. This requires those we serve to (a) prioritize the efforts necessary to allow the depth of insight into the enterprise necessary to manage risk in a borderless world, and (b) accept the fact that regardless of this level of detail we will be compromised to some extent. 
 
(Let’s not forget, either, that the security industry will need to continue evolving its toolset and its message, to include delivering this same message to the Boards of Directors and chief technologists whom we serve and eschewing discussions about security which do not include members of the security team.)
 
Understand that I offer this analysis not as an excuse for inaction but rather as a completion of the treatise offered by Mr. Yoran. Throwing away the old maps, as Amit suggests, is important…but equally important is acknowledging the limitations of the terrain upon which we Warriors of the Light do battle every single day (even as we struggle to modify the terrain to suit our needs).
 
Amit has thrown down a gauntlet to the security industry and the security profession alike; however, I believe what he will find is that many of us picked up this gauntlet many moons ago and are already fighting the good fight.

Welcome to the line, Brother Amit. Your shield, your sword arm, and your voice are more than appreciated.

My two cents…

Monday, April 27, 2015

Thoughts on The Irari Rules

I’ve had the pleasure of knowing Ira Winkler and Araceli Treu Gomes for over a decade now.  Both are quality and insightful security professionals who raise the bar within our industry.  As such, I’ve enjoyed reading their joint commentaries on various security issues and challenges over the past few months.

Winkler and Gomes’ latest contribution to the fight are “The Irari Rules” (named after a combining of their first names).  The relevance of the Irari rules re: determining the true technical attack sophistication cannot be overstated;  it is easy for business leaders and other technology professionals to talk about a new level of sophistication in attacks when in reality we are seeing increased efficiencies and volume around highly predictable (and preventable) attack vectors.  That being said, Winkler and Gomes take a slight – and, in my opinion, erroneous – detour in their conclusions which may obscure some of the important messaging we all need to hear.

Think about what the Irari rules are advocating for a second:

  • Use anti-virus or anti-malware software
  • Patch your systems
  • Use multi-factor authentication
  • Change passwords frequently
  • Create detailed, realistic, holistic education programs
  • Turn on and monitor your alert mechanisms
  • Segment your networks
  • Aggressively manage user accounts and their privileges

None of this is rocket science -- nor is it anything that we as security professionals haven’t been saying for the better part of two decades, with arguably the same level of mixed (poor?) results.  Yet clearly something has changed within the ecosystem given that (a) the number of compromised records per breach has increased exponentially; and (b) concern regarding breaches has entered the mainstream consciousness.  So if it’s not the sophistication of the technical attack…what’s going on?

Winkler and Gomes posit that the “new normal” for organizations should be to “expect to be targeted by people with more than a trivial level of skills and the time and resources to search for blatant vulnerabilities.”  This would seem to support an argument for the efficacy of a more sophisticated attacker as opposed to a more sophisticated attack – which results in higher levels of risk overall to an organization.   Remembering the basic risk multiplicative of (T)hreat x (V)ulnerability x (A)sset-Value, a more sophisticated threat can make better use of existing vulnerabilities than casual aggressor.  Continuing the lock analogy used in their article, the issue isn’t whether the door is locked or not as most security is rarely so binary a calculus; rather, it’s the newness and maintenance of the locks in place.  While these locks may be sufficient to stop an opportunistic intruder, a focused intruder with moderate skills could defeat these locks (single factor authentication; static passwords; etc.) with relative ease.

There’s another factor in the risk equation that Winkler and Gomes have failed to consider:  asset value.   While consumers have not yet fully rationalized their willingness to achieve convenience and personalized service via providing personal data with their concerns over its use, the value of data to both individuals and corporations has increased dramatically.  As the value and proliferation of data within organizations increases, the security professional must reevaluate whether the locks remain sufficient and are sufficiently maintained to mitigate risks within the environment to an appropriate level. 

Winkler and Gomes conclude that “(c)laims of sophisticated attacks deflect blame, obscure the need to make improvements and attempt to shirk responsibility for implementing poor security efforts.” In this I agree…but only to a point.  Yes, claims of sophistication can contribute to obscuring the need for improvements, but the argument for improving programs isn’t in the elimination of obscuration but the removal of our profession's own obfuscation of risk issues.  Fundamental blocking and tackling within a security program is essential, yes...but even the best managed programs can’t bring risk to zero.  As we do the blocking and tackling to eliminate vulnerabilities, it is equally critical to acknowledge attacker (versus attack) sophistication as well as the marked increased in asset value regarding data.  In this environment, yesterday’s locks and windows (read:  yesterday’s security program implementation) won’t keep the bad guys away.

My two cents…

Sunday, March 22, 2015

Security Awareness: Changing User Behavior Reduces Overall Risk

Last week I was asked to participate in a webinar regarding security awareness and its efficacy within the workplace. I and my fellow panelists -- Sam Masiello of Teletech; Michael Angelo of NetIQ, and Joe Ferrara of Wombat Security -- had a lively and wide ranging discussion of the benefits, pitfalls, and challenges of security awareness.  If you're inerested, the webinar is available for playback at this link.  Note, you'll be required to register at the site before viewing/listening.  

Enjoy!

Saturday, October 4, 2014

"What Keeps You Up at Night?"

Recently I was asked by SecureWorld to write an article responsind to the question, "What keeps you up at night?" Like most security professionals, I get asked that question quite a bit in various contexts.  

My answer to this question tends to be somewhat unorthodox, but it brings a perspective to the problem that I believe we Warriors of the Light should contemplate and consider.  My full response can be found here on the SecureWorld site.  Give it a read and let me know what you think!

Thursday, September 11, 2014

It Is Still All About The Business

Two weeks ago,m Baseline Magazine published the results of a survey regarding executives' views toward the CISO position.  The results were less than encouraging:
  • 74% of the C-Level executives surveyed believe that CISOs should not be a part of organizational leadership teams
  • 44% view the primary role of the CISO as "being accountable for any organizational data breaches."
These results are not surprising to most practitioners.  In many companies, the title ‘CSO’ stands for “chief scapegoat officer” even to this day.  CSOs and CISOs live in fear of the inevitable breach, because such an event will lead to accusations and recriminations versus investigation and remediation.    Ironically, this attitude by the organization's executives actually reduces the efficacy of the security team.  In addition to creating an undertone of survival and us-against-the-world within the CISO organization, the senior security executive now feels compelled to spend a goodly portion of their time covering themselves (i.e., "creating the paper trail") and focusing on tactical issues versus strategically driving the security program.

While many of my brethren will focus on the aforementioned results, this survey reveals a more telling statistic: 68% of the executives surveyed feel CISOs lack broad awareness of organizational objectives and business needs. Despite our best efforts, and despite certifications that preach otherwise, we are clearly failing to adequately link ourselves to the businesses we support.  While there are no silver bullet answers out there, here are a couple of tips and pointers that I've found effective in bridging the "business gap" over the years:
  • Ask The Key Question.  When I assume the role of CSO/CISO in any organization, I make it a point to meet every business line leader and their direct reports within the first two weeks of my arrival.  The first question that I pose to each of them is always the same:  "How do you make money?"  Not "what do you do for a living," but how does that business unit generate revenue for the organization?  When they answer me, I keep probing and asking questions until I truly have at least a high-level understanding of the services and products offered and how they contribute to the company's bottom line.  Once you understand how the business makes money, it becomes exponentially easier to understand where security controls are appropriate -- and, more importantly, the potentially negative impact a specific control can have on the revenue picture.  
Note that I used the terms "money" and "revenue" instead of "profit."  Even non-profit and not-for-profit organizations generate revenue to pay the bills.  While the mission/purpose of any organization is critical, that mission must generate some level of revenue in order to succeed at its efforts.

  • Have A Strategy.  Sounds simple, right?  Yet to this day a significant portion of CSOs do not have a documented strategy.  Those who have documented their strategies tend to link their objectives solely toward risk reduction and mitigation versus achieving the business' objectives -- which leaves an impression with executives that security is something that they "have to do" that is diverting expenditures away from revenue-generating efforts.
I'm an old Common Criteria (CC) tester and evaluator.  The one thing that I loved about the CC was its structured approach regarding requirements.  Functional requirements led to technical functional requirements which in turn logically led to security functional requirements.  I take a similar approach when structuring my strategic imperatives.  The business wants to do something; that "something" will require a specific operational and technical capabilities.  Creating those capabilities at a risk level consistent with current risk levels requires us to enable/enhance/create these specific security capabilities.  This linkage helps intrinsically tie your security endeavors to the business.  

Understand that there are times that you will need to drive compliance and/or risk reduction activities purely for the sake of compliance/risk reduction;  but never forget that being compliant is a business requirement and that you are reducing risk to a level acceptable to the business.  Say those things in your strategy.
  • Educate Your Teams.  You can't be the only one that understands the business;  every member of your team needs this level of understanding as well.  Not only will it change the optics re: your team as they interface with the business, but it will also enable them to bring more business-appropriate solutions to the table as they problem solve in the security space.  
It would be easy for us to make a bit of a chicken-and-egg argument here and claim that we security warriors can't start thinking strategically and better integrate security with the business because we fear recriminations when something goes wrong. If this survey is any indication, though, we are collectively limiting -- if not damaging -- the profession by not aggressively focusing on relating our activities to the our organizations' strategic imperatives.  If we are living in an era where massive breaches are becoming commonplace and we cannot guarantee that  a breach will not occur, then a lack of a strategically-driven security program that is intrinsically linked to business objectives only justifies the opinions listed above.

My two cents...   

Saturday, August 23, 2014

The Impact of Situational Privacy

Pop quiz today!  Which of the following situations is a violation of privacy:

 

  • A national retailer utilizes purchases you make with them to send you advertisements about products you might enjoy or need
  • A reputable search engine utilizes data about you from previous searches and other products to better tailor its content to your needs
  • A government entity utilizes data in the public domain to hone in on potential criminals.

 

If you answered anything but "it depends" on this quiz, you haven't been following the nuances of the privacy debate lately :)

 

Let's get a little deeper into each of these examples for just a moment:

 

  • In 2012, Target came under media scrutiny for using data analytics to predict which of its shoppers might be pregnant.  The retailer then began sending coupons to those shoppers for things like baby clothes, strollers, etc.  The story made news when one Minnesota father noticed that his teenage daughter was receiving these materials.  The irate father marched into a local Target, demanding to see a manager, and accused the retailer of attempting to encourage his daughter to get pregnant…only to find out from his daughter that she was, indeed, already pregnant.  Target's analytics had identified her pregnancy before her own father had known. 
  • Just last month, Amazon.com celebrated its 20th birthday.  One of the features this massive online retailer is known for is utilizing knowledge of your shopping habits to send you advertisements about products and services which you might enjoy.  As of this year, Amazon is exploring pushing the envelope around this concept and has taken a patent out on what it is describing as "anticipatory shipping."  Utilizing the data it already has about you, the mega-retailer intends to just start sending you items which it believes you want before you purchase them, arguing that the success rate of its algorithms is such that the number of returns would not exceed the benefits reaped by this level of customer service. 
  • Several years ago, people started noticing that their search engines -- in particular, Google -- were displaying different sets of results for the same question.  Upon further exploration, people discovered (realized) that most search engines utilize data from your location and your browser history to better customize answers for you.  Providing such customization makes it easier to retrieve more meaningful results for the consumer which shortens search time…and also makes it easier to tailor advertisements to the consumer that s/he might be interested in.  The downside, of course, is that it may also be masking important yet contradictory information that is relevant to the individual's search -- thus reinforcing research bias.  (Note:  you can turn off "search customization" (as Google refers to it), but it's difficult to find out how if you go onto their support site. The link above also provides information on how to disable search customization relatively easily.)
  • In June 2013 Edward Snowden exposed the NSA's domestic cellular collection program.  The general public was outraged that the government would utilize cellular metadata (such as location information) to spy on its citizens; however, these same citizens exhibited no qualms about carrying a device which regularly broadcasts location nor the use of that location data by other governmental entities and agencies.

 

The examples above are illustrative of the complexity around privacy.  Gone are the days when we could simply state that "<x> data is private"; indeed, we are moving more to an environment of "situational privacy" where the data itself isn't as much an issue as how the data is used.  Consumers freely and openly volunteer exabytes of data on a daily basis for seemingly innocuous transactions…yet they are regularly shocked and angered as this data is combined with other seemingly innocuous (and freely given)  pieces of data to provide predictive intelligence to marketers, corporations…and yes, to  government entities.

 

As security professionals, we are becoming more embroiled in the debate around privacy.  Remembering that privacy itself is impossible without appropriate  security controls, the situational nature of data mining and appropriate data usage makes the protection  equation  daunting.  Do we wrap a cocoon of Pentagon-level protection around the data lake, even though 99% of the data within it is considered publicly available?  Do we inject ourselves into the data analytics process and become part of the arbitration question re: should we use the data in a certain fashion?  Can we monitor and limit/restrict data combination similar to the way in which systems can monitor separation of duties access control issues? 

 

Let's take it a step further.  Remembering that corporate data analytics seeks to (among other things) improve the sales cycle and make marketing campaigns more efficient, imagine the implications if the bad guys choose to take such an approach.  Consider:  your systems are penetrated and data is stolen…but none of the data is regulated by current privacy law or regulation.  Six months later, the bad guys run data analytics against the acquired data and determine the best targets for fraud or scam.  You protected the data and your borders reasonably and can show a tiered approach to your controls…and those controls were appropriate for your environment…you even prevented the breach from reaching the most sensitive data stores…yet data stolen from you was used to target your customers in the same manner that your marketing and sales team target prospects.  Imagine the liability issues that will circulate through the courts.


As your organizations recognize the value of the data it holds, it is important that we as security professionals remind people of the larger risk & privacy landscapes out there.  We cannot rely solely on the legal/regulatory framework to guide us as the potential brand risks go beyond what the hodgepodge of privacy regulations currently address.  In most cases, you as the will be the first person to bring these concerns to light and as such will risk the possibility of being initially portrayed as  naysayers…but more often  the security warrior ends up prognosticating  future risks and challenges looming on the horizon.  As we continue to enable our businesses we must ensure that the aforementioned questions -- and dozens more -- are acknowledged and addressed by our business leaders.

 

My two cents…