Thursday, June 21, 2007

Views From Microsoft TechEd 2007

Day 1: 6/4/07

The first day of any event like this is always the most – well – hectic. People everywhere! Thousands of computer geeks all trying to go in different directions through a convention center, but at the same time all trying to get to the same place – the place where the food is and the opening keynote speech. Once the keynote was done, things sort of calmed down as people went to the various breakout sessions. This convention center is huge! They could fit a few football practice fields in this one building alone. In the main building where the breakout sessions were held, it is a quarter of a mile from one end to the other. And given that some sessions were on one end, and some on the other, we walked this quarter mile span several times a day. The images of the main expo area don’t begin to do this place justice, insofar as giving a good depiction of the size of this facility. The building we were in was around a million square feet, according to sources we asked. And it was carpeted from wall to wall. Had to be one big, honkin’ vacuum cleaner they use in that place!

There were a number of new tools being introduced and discussed in depth. The problem with this conference is that we geeks were like kids in a candy store – so many presentations, but how to decide which ones to attend was a real challenge. I think I changed my schedule a thousand times!



Day 2: 6/5/07

Two recurring themes are emerging from the sessions so far: User awareness and risk analysis are key elements of the security of any system. Many of the technologies that continue to surface still have the interesting aspect of the “man-to-man” factor. That is to say: no matter how secure any new software code developments have become, the weak link is still the human. For example, if a human still clicks on every email link presented to them, then they are still putting their systems and data at risk.

On a final note, Steve made an interesting point by asking the question: “Is email even useful anymore?” He gave a (not too surprising) statistic that stated that 82% of all email is SPAM - unsolicited email to either sell you something, or just discover if your email address is active. I might even classify the endless forwarding of jokes, hoaxes, and other misinformation in this category as well. I mean really – of the 20 or 30 emails I get at home per day, maybe three of them are information I can use, or are “real” correspondence from a friend or relative. I never really hear from people anymore – I just get forwarded jokes on a daily basis. Oh well – at least I know there are still alive and well, which is a bonus.


Day 3: 6/6/07

One of the most interesting presentations so far: “I Can Hack Your Network in a Day” by Marcus Murray. He gave live demonstrations of the various ways to infect a computer with a Trojan horse, take over a computer, and potentially an entire network. The striking thing about this presentation is that he demonstrated how easy it is to create a Trojan horse program, send it to a gullible user and get them to execute it on their computer. One of the big reasons I harp so much on the dangers of clicking on unknown links in emails, and opening email attachments. This is exactly how these attacks get perpetrated and proliferated. This also made a very heavy argument for patching. There are exploits for everything, and growing by the day. Keep your patches up to date, and stay on top of information about new threats. And quit clicking on unknown email attachments!

A presentation on Microsoft threat research by Vinny Gullotto revealed that 3,700 distinct malicious WMF files exploited the part of Windows fixed by MS06-001 patch. This really puts this in perspective, because I remember the scramble we went through in early 2006 to get this patch deployed as soon as possible. Vinny mentioned that 38 million+ pieces of potentially unwanted programs (PUPs) currently existed, which includes adware, viruses, remote control programs, Trojans, bundled software, and other modifiers. This is staggering, as it really illustrates just how big our job as security professionals has become. Some resource that Vinny mentioned are the Virus Information Alliance (VIA), the “Wildlist” for viruses, and the Anti Spyware Coalition (ASC).

Another extremely interesting and energetic presentation was given by Laura Chappell, using Wireshark for troubleshooting a slow network. Like the Marcus Murray presentation, she ditched the PowerPoint slides and showed live demonstrations of packet trace files and showed how to use the Wireshark packet sniffer to analyze packets to get to the bottom of network and computer communications problems. The presentation was extremely interesting and she did a good job explaining the tools and methodologies. It was amazing to find out how much traffic is being generated in the background by an infected computer, just during the boot-up process. Her methodologies illustrated how looking at TCP/IP traffic can tell a lot about what is causing problems with an individual computer, as well as those on an entire network.


Day 4: 6/7/07

Today started with a presentation to get an insight into how Microsoft deals with IT security internally within their company. With over 500,000 computers and 120,000 to manage, security is not an easy task, but Microsoft appears to have some sound strategies in place to handle it, whereby information security is process driven and based on industry standards. The IT security staff at Microsoft makes up approximately 4% of the entire IT staff. Much of what is done related to IT security within Microsoft revolves around the Enterprise Risk Management Framework and the Trustworthy Computing Initiative. Policies are published, and industry standards are put into place to ensure security. Executive sponsorship of the IT security tenets is very strong at Microsoft as well, which is one leading factor in the success of such programs. In many organizations, IT security is viewed as a “tax to the business.” That is to say that users view the security practices as burdensome and preventing them from doing their jobs.

Technology, such as implementing network access protection (NAP), BitLocker (Windows Vista’s encryption implementation) on laptops, and implementation of two-factor authentication are some of the things that are used at Microsoft to ensure security security. These technologies provide sound and secure methods to keep an environment secure, but still enable people to do their jobs.

What most impressed me about Microsoft’s internal information security stance was that they made their employees sign acceptable use policy acknowledgement statements, and that non-compliant (i.e. un-patched) machines were denied access to the network until they became compliant. If a company like Microsoft can implement these types of processes, then why are so many of our other companies having such a hard time doing it? I think part of the answer rests with the fact that many users are unaware, many users view the IT staff as the “network janitors” and many people simply view IT security as a tax (burden) on business processes.
Mark Russinovich presented a talk on the changes in the Windows Vista kernel. Some of the notable new features in Vista include user access control (UAC) and some features that provide better performance. This includes such things as the ability to delay services so that they don’t all try to start up at once. Many who run current and older versions of Windows can attest to the fact that all the services that try to start up at the same time can really make the boot process painful.


Day 5: 6/8/07

The final day of the conference! On one hand, I want to hurry up and get this over with so I can just go home. I have been on travel a lot lately – three trips (including this one) since the middle of April. Living out of a suitcase and eating at Denny’s is getting old. On the other hand, there were so many presentations I wanted to see, but didn’t get to because of conflicts with other presentations, and wanting to visit the vendor expo. The crowd has really thinned out by now, but there are still quite a few people here. I will be interested to find out how many people were in attendance this year – had to be well into the tens of thousands.

They saved the best for last. I attended a few Mark Russinovich talks on the internals of Windows Vista, and using some of his Sysinternals tools to troubleshoot systems. There are a number of free tools that fall under the former Sysinternals umbrella, but are now distributed by Microsoft. Mark Russinovich’s tools are extremely easy to use and leave a very small footprint on the system because they don’t get installed. By developing some troubleshooting skills and using these tools, the average IT technician should be able to better troubleshoot systems. Troubleshooting is all about investigating and trying to see what should or should not be happening. Process Monitor and Process Explorer give a much more in-depth picture of what processes are running, how much of an impact they are placing on resources, and even what malicious processes are trying to spawn processes that can harm your system. Many of Mark Russinovich’s presentations from past TechEd conferences can be found on the web (see resources at the end of this article. – definitely worth a look.


The Conference in Review:

So what do most computer geeks take away form conferences like this? Well, I took away some very important ideas from this year’s TechEd conference: 1) The attackers, as well as their motivations and methods have changed; 2) Everything in security must be approached from a risk analysis and economic standpoint; 3) People are still security unaware and must be educated; 4) Microsoft is (still) not the problem, as I have indicated in my blogs a number of times.

The attackers have changed: Notoriety and getting attention used to be enough for the bad guys. They just wanted to inflict damage, interrupt people’s lives, and get noticed for it. But they figured out that this kind of deviant behavior pays, so they are out to make a buck by finding vulnerabilities, writing exploit code, and stealing data.

Risk analysis is everything: It isn’t enough to simply say that you want to be secure. It is important to find out how high a priority your risks really are and implement appropriate protections. Security professionals have said it a million times: “Don’t protect a $10 dollar horse with a $50 dollar fence.” And in order to pursue projects to put appropriate protections in place, it is important to illustrate to management to economic benefits of these protections. Otherwise, they will just view security as another expense for which they won’t realize any benefit. As Steve Riley and Jesper Johansen mention in their book “Protecting Your Windows Data From Perimeter to Network”: You are implementing security "so that nothing will happen." Meaning that the goal is for nothing to happen to your data, other than it being safe and accessible.

People are security unaware: It’s not that people are blatantly against doing the right thing, it is mostly a case of them not knowing what the right thing is. Further, they need to know how being secure will benefit them, not just that security is a mandated process. If people have some insights into why they need to be secure, the benefits and consequences to them personally, and how to do it, it will be much easier to get their buy-in.

The TechEd experience was unique. Not that I will be anxious to do it again (once is enough), but it was time well spent, and very informative. I got to see live presentations from some well respected names in the computer security biz, and had a chance to see some of the new technologies that Microsoft is producing.

To read the full review, find additional resource links, and see pictures of the convention center, read the full article here.

Friday, May 04, 2007

Security Tips To Keep You Safe While Traveling

As we approach summer, more and more people are once again thinking of traveling, both for business and for pleasure. TechEd is in June, and a variety of other techie conferences are not far behind. School will be out soon, making way for family vacations – although with the ridiculous price of fuel, I’m not sure how many people will be traveling. Even when only traveling for pleasure, many business professionals, as do I, take their laptops and PDA devices with them to be able to do work during a few “down” moments on their trip, or at the very least to have a way to keep tabs on their email and events at work. We geeks are such workaholics, aren’t we?

On a recent business trip to the east coast, I had the opportunity to once again enjoy my hobby of just sitting back and observing people. I was again reminded of just how complacent folks are about their security when it comes to using computers and other information technology enabled devices when on travel. This seemed to be especially true when using computers in public places – either their own laptops, or computers in hotel business centers. I am not sure if people are just in a hurry, or if they just really are not aware of the potentials for exposing themselves (in a “data” sort of sense, that is) while out and about.

There are a number of things I will talk about in this article having to do with ways to keep yourself (and your data) more secure when away on travels. Some of these things are as simple as using fundamental physical measures to shield your computer screen from curious eyes. Others involve the act of just taking the time to clean up after yourself when using a public computer, and yet other measures I will discuss simply involve the use of technology that is already built in to the devices that you are using. There really is very little to no cost involved in protecting yourself with these measures, but the cost of giving away your data can be huge and devastating. So let’s take a look at a few of the vulnerabilities we face everyday when on travel and some solutions for protection.


Shoulder Surfing:

If you are flying, your potential for vulnerability begins the very minute you get to the airport. Many people find that they have to arrive at the airport a few hours early just to make it through check-in and security, in order to make their flight on time. There is often a lot of “down time” here, so many people, as do I, pull out the laptop and the Blackberry, and do some work. In this setting, we are often in very close proximity to other people. Once we board the airplane, it is even worse. Unless you are lucky enough to be in First Class, you are sitting with your elbows right up against someone else’s, and their wandering eyes are just a foot or two north. Even if you aren’t flying, or have arrived at your destination, the local restaurant and the corner coffee shop are no different. When you sit down in that comfortable chair to enjoy your latte and do some work, there are countless wandering eyes trying to figure out what you are doing.

There are two main problems here. First of all, your neighbor (who is usually NOT minding their own business) is looking at your computer as you type in your username and password. If they can see your log-in box, they can see your username, and if your computer is joined to a corporate domain, they can see the domain name. As you type in your password, unless you are lightning fast, they can see you type the characters. I’m one of those “two-finger wonders” (I don’t touch type) so this is a particularly big problem for me. A devious person with intent on harvesting such information (and they are everywhere, trust me) will be very good at following your keystrokes and will be able to obtain all the credentials needed to log in to your corporate network. They now have your username, the name of your corporate domain, and your password. All they have to do is get access into that domain, and they are in. Your username and password exist on the domain, and are only cached on your computer, which means that they can access your account from any computer that can get access to your corporate domain, such as a VPN or other remote connection. Another danger is that if they are able to steal your laptop (more on this later), they will have access to the data on it. Remember – these people are everywhere. And if they are shoulder surfing to get your log-in credentials, they are also following closely to look for an opportunity to grab your laptop as well.

The second (and more common) problem with being in close proximity to others is that they are often able to view what is on your screen. Are you working on a document with sensitive personal or company information? Composing an offline email that you really don’t want others (especially strangers) to know about? How about that PowerPoint presentation chock full of corporate proprietary sales or engineering data? Whatever it is, you have to either make sure you are only working on things that are completely dull and unworthy of your nosey neighbor’s interest, or make the screen un-viewable. In other words, either pick non-sensitive stuff to work on during these times, or find a way to hide the screen. For example, I usually pick some low-level instructional or procedure guide to work on while I’m flying, or just do some professional reading. For example, I keep a lot of pdf white papers and “eBooks” from various online sources on my computer for reading while on the plane. My job is such that professional reading and just keeping are large parts of my work anyway – so it’s not like I’m goofing off.

Solutions: For the password problem, if you are on a computer that is joined to a corporate domain, use a local account on the computer (that does not have administrative privileges), and set a temporary password that will only be good for the duration of your trip. Of course, if you do this, you will have to make sure you know where to browse to on the computer to get to your documents in your “real” account, because the profile you log in with will have a “My Documents” folder in a different location. I get around this by accessing only documents that I have placed on a flash drive. If you are not joined to a domain, then just set a temporary password, and set it back to your actual password when you get home. One of the best solutions for this is to simply get a small finger print scanner to use to log into the machine. Many are small, portable, and just plug into the USB port. The newer laptops and tablet PCs even come with these built in. See my article on biometric devices for more information.

For the “prying eyes on the screen” problem, there are a variety of filters you can buy that will obscure the screen when someone tries to view it from other than looking at it straight on. This particular solution will also help to obscure your username and other login credential information as you log in. If they can’t see your username, the password will do no good. But again, don’t give them any pieces of the puzzle if at all possible. As I always tell people: “If they have even just your username, they then have 50% of the information they need to access your computer.”

Of course, being the wisenheimer that I am, if I notice someone trying to “catch a wave” on “shoulder beach”, I simply open a document, set the font to a larger size (to make sure they can easily read it), and then start typing in some juicy “official looking” verbiage. After a paragraph or two, I start a brand new paragraph, and type in “I think the nosey person sitting next to me is looking at what I am writing. I hope they enjoyed my previous two paragraphs. Now GO AWAY!” I have seen a red face or two resulting from that prank.


Using Flash Drives:

Flash drives are portable and can store a lot of data. Many people have resorted to using them because if they know they will have access to a computer at their destination, all they have to do is put their documents on the flash drive and leave the computer at home. Many cell phones and even iPods can be used for this purpose as well. The problem with these small flash drives is that they are easily lost or forgotten. It isn’t uncommon for someone to use them in a public or borrowed computer and then forget to take them when they are finished. A lost flash drive means lost data. Lost data can mean something as frustrating as losing work and having to do it all over again (if you didn’t have a backup copy somewhere else), or as devastating as putting sensitive information into a stranger’s hands.

Flash drives are cheap these days. If you lose the flash drive, you can just go get another one. But what about the data on the flash drive? Is it replaceable? Will it cost you if someone else has it? Another issue surrounding the ubiquitous nature of these things is that some people seem to have a whole lanyard full of them around their necks. Do you have a good inventory of how many you have? If one came up missing, how long would it take for you to notice? Kind of like the movie “Home Alone” where the family had so many kids that they didn’t notice little Kevin missing until they were in France!

Solution: The manufacturers of many of these drives have solved part of this problem for you. Flash drives have the ability to be encrypted, and the software to do that is often included with the flash drive itself. Typically, this encryption works by having you set up a password in order to access the data. You can encrypt all or only part of the flash drive’s contents. If someone gets a hold of your flash drive, they can access anything that is not encrypted, but will need to know your password to access the encrypted data. In some cases (depends on the drive and the encryption software), you can set your encryption such that if a number of unsuccessful password attempts occur the data on the drive will be erased. Know how many you have and keep track of them. If traveling, take only what you need – leave the other ones at home and in a safe place. I promise – they won’t miss you.


Using Common Area (Business Center) Computers:

Many hotels have business centers with computers to allow their guests to access the Internet and their web based email. In fact on my recent trip, I had full Internet access at the office I was visiting, but had to pay for Internet access if I wanted to use my laptop at the hotel. The only thing I needed after hours Internet access for was to check my personal email, and I wasn’t about to pay $10 just for 5 minutes of use. My remaining option then was to use the business center, since using those computers was free of charge.

A few problems present themselves in this scenario, however. One is that people use these public computers and often leave their surfing tracks for all to see. The other is that some people forget to just close out of their applications, and yet another is leaving those little flash drives plugged in for someone to come along and retrieve later. In fact, while in the hotel elevator on my most recent trip, I heard a woman telling her colleague that when he finished using the computer in the business center, he had left his email open, and she could have gone through all his email. Worse, she could have launched a few questionable emails in his name. This is truly a dangerous situation. What if it had been a stranger, and not a trusted colleague? That person could have read email, sent a few of their own (under the email account owner’s name), looked at the address book to get a list of names of people at the company, and just in general could do some serious damage. All this done under the name of the person who owns the account. How do you prove that it wasn’t you who did those things?

When I used one of the business center computers, I got curious and opened the browser history. I saw a plethora of email sites and surfing history. Wouldn’t be too hard to put together a few patterns and find out where some of these email servers existed. Depending on the cookies still on the machine, going to one of those sites may not even require me to log back in to access the account. The cookie would remember that I (or more accurately the email account owner) was just there and just let me right back in. This is especially true if the previous user had left the web browser open.

On a really malicious (and hopefully rare) side of things, a devious person could sneak into the hotel business center and put a keystroke logging dongle on the back of the computer between the keyboard and the computer, or in a USB port. Such a device is used to capture everything typed into the keyboard. Which means that they can get the URL to your banking site, the username and password for your banking site, and the contents of an email or anything else that you type into the computer. These key loggers have legitimate investigative purposes, but are inexpensive and can be obtained by anyone – including thieves. I say that this is (hopefully) rare, because most hotel business centers require a room key card to access – a person would (theoretically) have to be a paying guest in order to do this. But many public computers often do not offer such access protection as that provided by hotel business centers.

Solutions: For the reasons mentioned above, it is very important to pre-inspect the computer before and clean up after yourself after using a public computer. It takes a few extra minutes to do this, but you can’t put a price on the time it would take to straighten out the mess after you have been exposed because you didn’t have time to prevent these vulnerabilities. Here are some important steps to take when using public computers:

  • Do a quick inspection of the back of the computer and any USB ports to look for key logging devices. If you find something, and are not sure, contact the management immediately and have them investigate.
  • Never select the option to have “Windows remember me on this computer.” Do not allow the computer to store your username and password on the machine. Some web based email applications such as MSN will give you an option to tell it that you are on a public computer and not remember anything about your session.
  • Delete browser history, all temporary Internet files, and all cookies when you are finished using the computer.
  • Make sure you are logged out of any sites that you visited. Just closing the browser is not good enough. You must click the “Log out” link on the web site before closing the browser.
  • Close all instances of the web browser and all applications.
  • Make sure you take your flash drive when you leave.

Being the cheapskate that I am, however, my solution is that I try my best to only patronize hotels and coffee shops that provide complimentary Internet access to their guests. That way, I can avoid public computers altogether. But sometimes that just doesn’t work out, and I end up staying somewhere that makes me pay additional fees for access. In which case, the above solutions are a must.


PDAs/Blackberrys/Cell Phones:

Many of the same problems that exist with flash drives exist with these devices as well. They are small, easily lost, and can really store a lot of information. A Blackberry, for example is a phone, email client, and PDA all rolled into one. Emails, contact lists, to-do lists, documents, and personal journals are just a few of the things that can be kept on these devices. A lost phone device can not only give away sensitive data, but can give someone access to a free phone. And watch what you are discussing. What you say can be as revealing as anything else – especially if you are one of those people who puts everything on speaker phone, even when in public.

Solutions: Just as you can do with your flash drives, you can password protect and encrypt the data on your PDA as well. On my Blackberry, for example, I can password protect access and encrypt the contents. Not only that, but my Blackberry is set so that if someone types in an incorrect password ten times, the Blackberry erases all of the contents. Then, for added security, the data is encrypted, so that even if someone takes apart the Blackberry, and somehow gets the data off of the chip, the data is encrypted and unusable. Don’t discuss anything on your phone that you don’t want others in close proximity to hear. If you are sitting next to me on the plane, just don’t use your phone – period! I have no interest in what you have to say ;)


Laptops:

Saving the best and biggest for last: Laptops (and the data on them) need a lot of protection. They can carry a lot of data, and are very attractive to thieves. Keeping the laptop from being stolen is a job in and of itself, but if it does get stolen, there is more to worry about than just losing an expensive piece of hardware. Keeping the data on it from being compromised is the really important issue at hand, and if someone can access the data, they can potentially do a great deal of damage.

A big part of this problem is that even if they can’t log into the computer itself, and if they have the computer (physically), then they can remove the hard drive and put it into a computer that they can access. In fact, many data recovery techniques rely on taking the hard drive out of the failed (or in this case inaccessible) computer and “slave” it into a working computer. The working computer’s primary hard drive allows it to be booted up, and the slaved in hard drive contains data that can then be accessed. More clever people have freely available tools such as Knoppix (Linux on a CD) that they can use to boot up the computer, bypass the security on that computer, and access the data on the hard drive. In fact Knoppix can even be used to change the administrative password on a computer so that access can be gained through the more conventional method of booting up and logging in.

Solutions: There are some basic measures that will protect against access to a computer, but only if the computer is not stolen. In other words, these measures will work if you can keep the computer from being stolen. But once the computer is in unauthorized hands, these measures can be quickly bypassed. You can set a BIOS password that will prevent the computer from being booted into the operating system. But this is bypassed by simply taking the hard drive out of the computer and putting it into a different computer. Strong passwords for the operating system itself should also be used. As mentioned above, consider using temporary or “disposable” passwords. Small biometric devices, such as fingerprint readers, are fairly inexpensive, and many laptop and tablet computers have a fingerprint reader built in. Unfortunately, this can still be bypassed by putting the hard drive in another computer, or using a tool such as Knoppix to access the hard drive’s contents.

Encrypting the hard drive contents will help a great deal, even if the computer is stolen. Windows XP has the ability to do this using a built in feature. Windows Vista has a built in tool called BitLocker. Technologies such as that which is built into the BitLocker feature, for example, have the ability to protect data even if the hard drive is transferred to another computer. The downside of that is that you need to make sure you remember your password for logging into the computer, or set up what is known as a “recovery agent,” or you will lose your encrypted data.


Wrapping It All Up:

There are many other dangers that I haven’t mentioned here, such as accessing wireless networks while on the road, but that is a topic in and of itself. Wireless encryption, making sure you are not accessing an “evil twin” wireless access point, and a few other issues will be discussed in an upcoming article.

But for the purposes of this article, I wanted to focus mainly on the more ”physical” aspects of being secure on the road, as well as using built-in technologies to protect your data. Shielding your laptop screen from roaming eyes and preventing laptop theft are important ideas. If your laptop is stolen, knowing that you took measures to prevent the data from being usable by unauthorized people is also a very important idea. Other technologies, such as flash drives, cell phones, and PDAs represent things that are small, easily forgotten, or easily stolen. Those items contain sensitive data as well, and must have data security measures proactively applied. Once the data is in unauthorized hands, it must be assumed that it will be used for malicious or illegal purposes. Even if you retrieve your items, it must also be assumed that the information was copied and will be used – unless you took measures to make it useless in the event that a loss occurs.

It is easy to be complacent when traveling. And, unfortunately, there are plenty of people out there willing to take advantage of this fact. By taking a few extra moments to think about what needs to be protected, take inventory of your technology rich possessions, and take the extra time to protect your data, you will ensure a more worry-free travel experience. If I ever go into a hotel business center and see that you left your email open – man – I will hunt you down! (After I email a few jokes to your whole company, that is)


Additional Resources:

  • Theft tracking tools
  • Encrypting files and folders

Wednesday, May 02, 2007

The First 90 Days of an Operating System

People who know me know that I often complain about Microsoft systems because of the constant vulnerabilities they seem to have. "patch Tuesday" is always an interesting time for me, as it typically provides a lot of work. But I read a recent article that outlined the vulnerabilities that occurred within the first 90 days of the life of various operating systems. It was funny to see that of all the operating systems discussed in the article that Red Hat Enterprise Linux 4 Workstation Reduced actually led the way with the most vulnerabilities in the first 90 days. Also mentioned were Ubuntu Linux, Novell SLED 10, and MAC OSX 10.4, all of which had more vulnerabilities than both Windows XP and Windows Vista combined.

It appears that 1) Windows Vista has made great strides in plugging security weaknesses, and that 2) The Linux folks need to reassess their stance on just how much more secure Linux is than Windows. A thought from someone who tests and deploys patches on Windows systems from month to month: I still see a lot of work to be done, but this article really makes us security professionals step back and realize that security vigilance is important, no matter what OS you are working with.

I guess what I am trying to say here is that there is a lot of stereotypical information about where the problems are. As I mentioned in a previous article: Microsoft is really not the problem. The problem is in that people get so wrapped around the axle on making assumptions about that which they are familiar with. For example, the Linux people will swear that Linux is flawless, and the Novell people will feel likewise. Much vigilance gets lost regarding educating users, and just keeping up on the day to day maintenance of the systems you do have. Educate your users, keep your systems patched, and at the end of the day, you Windows users will have an environment that is every bit as safe as that which the Linux folks claim to enjoy.









Federal Information Systems - Information Assurance Reference

I wanted to take this opportunity to post a quick "cheat sheet" on the various resources needed for the certification and accreditation (C&A) of federal information systems, as well as some other related resources. A number of federal C&A things are changing. For example, rather than using the NIST 800-26 self assessment questions, C&A will be done by making assessments against the NIST 800-53 controls. Some organizations use NIST 800-53, and some use 800-53, Rev 1. Here is a quick list of the publications and regulations that apply to federal systems. Enjoy.

National Institute of Standards and Technology (NIST):

SP 800-100
Information Security Handbook: A Guide for Managers

SP 800-12
An Introduction to Computer Security: The NIST Handbook

SP 800-14
Generally Accepted Principles and Practices for Securing Information Technology Systems

SP 800-18
Guide for Developing Security Plans for Federal Information Systems

SP 800-23
Guidline to Federal Organizations on Security Assurance and Acquisition/Use of Tested/Evaluated Products

SP 800-26
Security Self Assessment Guide for Information Technology Systems

SP 800-27
Engineering Principles for Information Technology Security (A Baseline for Achieving Security)

SP 800-30
Risk Management Guide for Information Technology Systems

SP 800-31
Intrusion Detection Systems (IDS)

SP 800-34
Contingency Planning Guide for Information Technology Systems

SP 800-36
Guide to Selecting Information Technology Security Products

SP 800-37
Guide for Security Certification and Accreditation

SP 800-42
Guideline on Network Security Testing

SP 800-47
Security Guide for Interconnecting Information Technology Systems

SP 800-51
Use of the Common Vulnerabilities and Exposures (CVE) Vulnerability Naming Scheme

SP 800-53
Recommended Security Controls for Federal Information Systems

SP 800-53 Rev 1
Recommended Security Controls for Federal Information Systems, Revision 1

SP 800-53A (DRAFT)
Guide for Assessing the Security Controls in Federal Information Systems

SP 800-55
Security Metrics Guide for Information Technology

SP 800-56
Recommendation on Key Establishment Schemes

SP 800-57
Recommendation on Key management

SP 800-60
Guide or Mapping Types of Information Systems to Security Categories

SP 800-61
Computer Security Incident Handling

SP 800-64
Security Considerations in the Information System Development Lifecycle

SP 800-70
Security Configuration Program Checklists Program For IT Products - Guidance For Checklists Users and Developers

-------------------------------------------------------------


Federal Information Processing Standards (FIPS):

FIPS 140-2
Security Requirements for Cryptographic Modules

FIPS 199
Standards for Security Categorization of Federal Information and Information Systems

FIPS 200
Minimum Security Requirements for Federal Information Systems

-------------------------------------------------------------


Office of Management and Budget (OMB):

OMB Circular A-123
Management's Responsibility for Internal Controls

OMB Circular A-130
Management of Federal Information Resources

OMB Circular A-130, Appendix III
Security of Federal Automated Information Resources

-------------------------------------------------------------


Laws and Regulations:

FISMA
Federal Information Security Management Act of 2002

-------------------------------------------------------------


Other Publications and Usefull Information Assurance References:

CNSS
Committee on National Security Systems

Common Criteria
Common Criteria for Information Technology Security Evaluation

Common Criteria - An Introduction
Brochure: An Introduction to the Common Criteria Project

DIACAP
DoD InformationAssurance Certification and Accreditation (will replace DITSCAP)

DITSCAP
DoD Information Technology Security Certification and Accreditation Process

GAO-05-231
Emerging Cybersecurity Issues Threaten Federal Information Systems

Mitre
Common Vulnerabilities and Exposures

NIACAP
National Information Assurance Certification and Accreditation Process

NIAP
National Information Assurance Partnership

NIATS
National Information Assurance Training Standard for System Administrators

NIST and SDLC
Brochure: NIST and the Systems Development Lifecycle (SDLC)

US-CERT
United States Computer Emergency Readiness Team

-------------------------------------------------------------


Topic Reference:

Security Certification and Accreditation
SP 800-37
NIACAP
DITSCAP
DIACAP

Security Categorization (C-I-A, High, Moderate, Low)
FIPS 199
SP 800-60

Saturday, March 24, 2007

Online Predators – A Security Risk to Our Homes and Families

I am going to take a break from enterprise information security and talk about computer security on the home front for a bit. The security aspects of online predators, children, and the Internet are yet again getting a huge amount of publicity, and are worth discussing. In a recent news article in Denver, “Police crack down on Internet predators,” police are using online chat rooms to lure predators into a situation where they think they are going to meet a child for sex, and they then actually get arrested. The article goes on to list the names and personal information about these worthless scum for all to see.

First of all – Good on the cops and law enforcement agencies nationwide who are cracking down on these worthless animals that prey on our kids. Bad on the liberal morons who are criticizing this effort and saying that these people getting caught are victims of entrapment. The predators are making the conscious decision to pursue their uncontrolled urges online. The cops are just acting as the decoys for the predators to go after instead of the predators going after our kids. One predator going after a decoy means that one less kid is becoming the next victim. Kind of like why we use “honey pots” on our corporate networks – to give the bad guys something to attack so as to keep them distracted, and so that they won’t attack our real servers, right?

Now – in my opinion, there are two parts to the solution for deterring would-be predators. One strategy being that which is already being done by our law enforcement agencies, as cited in the article. Shows like Chris Hansen and Dateline’s “To Catch a Predator” are giving high visibility to these pathetic people, and showing these perverts getting busted publicly, exposing them for who they really are. Chris Hansen and John Walsh (“America’s Most Wanted”) are two of my biggest heroes. They are making a difference, and are truly positive forces in our society today. Good job guys – you are two of the true heroes of our time.

The other part of this solution is that parents need to be more proactive in protecting children from these online perverts, and in fact protecting children from their own inability to protect themselves. Children are immature, lack experience, and just don’t have the knowledge and logical thinking tools developed yet to allow them to rationally deal with these types of situations. This is through no fault of children themselves – that’s part of being a child, right? Many will argue that parents should not censor their children’s activities. There is a fine line between censorship and protecting them. True, children can indeed think for themselves on many issues. But their thoughts are often not logically constructed, and tend to be rather impulsive at times. Of course, I could say the same for many adults! Children often do not know any better, believe what they are told, and these animals have become so good at disguising themselves that it is easy for a child to be deceived. Children think that they are hiding behind the anonymity of the Internet, and often feel very uninhibited when chatting online. They then get pulled into the webs spun by these scum bags.

Parents don’t need to hover over their children’s shoulders every minute that they are on the computer to be god parents. Rather, they can take some very easy technical and low-tech steps to protect their children’s Internet usage. All they have to do is be a little pro-active and put a few safeguards in place to show their children that they care about them.


Enforce Internet Hours:

Much of what the experts will tell you about how to prevent your children from venturing into dangerous waters on the Internet has to do with not allowing them to be up all hours of the night chatting. Even if you have the family computer in a common area as suggested, how do you monitor usage if it is late and you are already in bed? If you have broadband service, you can use your router to specify hours of operation. Even if you have only one computer (and think you don’t need a router), people have heard me say over and over that you need to have one of these routers anyway - for the other security measures that they offer, such as firewall protection. I am harping on people yet AGAIN to get one because the broadband router can also help you protect the people that use the computer, not just the data on the computer. Most broadband routers allow you to set hours of operation for all or certain specified computers. The computer will still work as it normally would - allowing your children to print, access files on another computer, and do their homework. Should they be up all hours of the night doing it is your concern, but at least the Internet access will be turned off. If you have multiple computers, you can limit Internet hours to some, but not necessarily all. Many times I am in my office late at night researching something (during a bout of insomnia) and need the Internet to be accessible. But the kids can't use my computer from fear of death, or at least my strong password gets in the way :)


Use Parental Controls:

Just like the V-Chip on your television, your broadband router has the ability to help you sign up for and put parental controls in place. You can specify and allow only content that is appropriate for your family, protecting them from questionable material and web sites that cater to a variety of offensive content from pornography to web sites that contain hidden malicious code. These sites are also often used for phishing and other identity theft scams. Much of what is being discussed as far as the dangers of online predators is the idea that children are often lured to seemingly innocent web sites or chat rooms, but are then exposed to all kinds of things that can lead to, among other things, identity theft - theirs and yours. By signing up for the parental controls services, you can leverage the ability of the service by knowing that they are keeping their definitions up to date and monitoring for the many new dangerous sites that pop up so that you don't have to worry about constant upkeep. You can also specify your own list of prohibited web sites using your router's built-in functions as well.


Use Protection Software:

There are also a wide variety of software packages out there that will allow you to permit and restrict web sites that your children can visit. NetNanny is one such product. There are many others - the Internet Filter Review web site provides a wealth of info, as well as software comparisons. Many of these types of software allow you to prevent access to suspicious web sites, monitor chat room and email activities, and even send you alerts of suspicious activities that are taking place.

Even the more sophisticated personal firewall software has the ability to restrict application access to the Internet. ZoneAlarm, for example, has the ability to allow or disallow any application of your choosing access to the Internet. If you feel your children's usage of their favorite chat program has gotten out of hand or is suspicious, simply turn off access, talk to them about it, and then come up with a strategy for safer usage.

For those of you who use Comcast broadband Internet service, McAfee Personal Firewall comes to you free of charge. I use McAfee, although I have been a ZoneAlarm fan for many years - because it is free with my current service. The McAfee product provides a very robust set of features to allow protect you and your system from harmful activities.


Upgrade to Windows Vista:

The parental controls features of Windows Vista allows parents to more tightly control what and when their children use the Internet. Parents can set hours for computer use, set sites as off-limits or even limit browsing to only a few sites, and even monitor what sites their children are viewing. Easy to confuse this with censorship, but we are talking about children, after all. It is (in my humble opinion) the parent's job to keep children from things that will hurt them or bring liability for illegal activities onto the parents. This allows for a more granular setting of computer restrictions. The other thing I personally like about it is that the parental controls block what you specify, but give a reason why - letting the kids know that you are taking an active interest in their computer activities.


A Low Tech Approach to Web Site Access Prevention:

Within your computer is a low-tech way to prevent the computer from accessing questionable web sites and sites that host chat rooms called the HOSTS file. When you type in a web site address or click on a link in your web browser, you have just told your computer you want to visit an address somewhere on the web. We as humans can only think in terms of plain English names, like www.wflinn.com or www.google.com. Our computers, however, only think of this in terms of addresses known as Internet Protocol (IP) addresses. An IP address looks like the form 192.168.1.1. For instance, what you know as www.wflinn.com is actually located at address 66.226.64.9. When you type in the plain English name, your computer has to do what is known as "name resolution" to find out what IP address you need to go to. The HOSTS file is a file that your computer looks to first to find out the IP address of a web site's location. If it doesn't find a suitable address in the HOSTS file, it goes out to what is known as a Domain Name Services (DNS) server to get the address. Therefore, if you put an entry into your HOSTS file to tell your computer the address of a specific site, it will look no further for the address.

So - you fake your computer out by telling it that the address of a questionable web site is 127.0.0.1. The address 127.0.0.1 is a special address - it is the loop-back address of your own computer. Regardless of what address your Internet Service Provider assigns you, your computer's internal address is always 127.0.0.1. When you tell the HOSTS file that the address of a questionable web site, such as www.myspace.com is actually 127.0.0.1, your web browser will try to go to that address, find out it is not a web server, and simply display the plain white "Page not found" error that you get when you try to go to a web site that doesn't exist. I'm not necessarily trying to pick on MySpace, by the way - but they have been singled out lately as one of the most popular sources that many online predators look to for victims, so I have chosen to outright block all access to that site from all of my computers.

This method, by the way, is an easy method for preventing all those annoying advertising pop-ups in your web browser. There are many web sites where you can obtain entries to copy and paste into your HOSTS file - so you don't have to do the research to figure it out and type them all yourself. The good news is that this method is easy, no cost, and works very well. The bad news is that it must be updated, and if you r kids are computer savvy, they can can find this file and erase the entries to give them back access to web sites that you have blocked.


Summing it all up:

The Internet has exploded into a virtually unlimited resource for finding things and getting information. Unfortunately, it has also brought out the worst in some people. A recent news article made mention of the fact that most of these online predators wouldn't be able to carry out their abhorrent behaviors if not for having a computer and access to the Internet. It was interesting when one young girl on the news article said that parents tell them not to talk to strangers and such - all things related to being safe outside the home. But now, the Internet has brought certain dangers inside the home and can affect your whole family.

There are many ways to protect your kids, from outright prohibition of certain things, to allowing access to everything, but helping them make wise choices. As I said, I am not going to get into this whole debate about what is and isn't censorship and invasion of privacy - that's up to you as parents to decide for yourselves. I will, however, tell you that you can use technology to help enforce your choices, and I encourage you to explore and use the various technologies at your disposal to do so. Not only will you be ensuring more safety for your family, but you will be adding to your overall computer security posture as well.

See my article on my web site from last year for a repeat of this information with images to help you configure the items mentioned in this article :

http://www.gonzosgarage.net/computers/archive0506.html


Thought for the day: Stupid people suck, but worthless predator scum suck even more!


Page copy protected against web site content infringement by Copyscape

Thursday, March 22, 2007

When “Smart” People Make Stupid Security Decisions

Warning: Here’s the deal – I have had a week consisting of four “Mondays” in a row. Bad drivers and stupid people have been working my last nerve, so I gotta vent! This is an angry rant about stupid people. If you are a stupid person and you are easily offended, then you should turn away now. Maybe go play on a porn site for awhile. Either that or get some brains and rational thought, and you can join us for some intelligent conversation.

Here’s why I’m angry - I read an interesting article recently that highlights the folly of allegedly “smart” people who show their information security ignorance and make stupid decisions when they don’t even understand the most fundamental of technologies and reasoning behind information security requirements. Then, when someone with intimate technical knowledge of what the issues are and how to solve them steps in, they are instantly rebuffed when even daring to mention the problems. I have experienced this type of thing my whole working life: I see people go through college, get a degree in underwater basket weaving, then somehow get into the pipeline to become managers. Either that or they drink their way through college, become lawyers or doctors, buy beemers, and act like spoiled children the rest of their lives. I had to laugh when I read the following line in this article:


“The attitude among the legal staff was, ‘This is my computer and my network; you’re just a computer janitor.’”


To give a quick synopsis of the article – there are a bunch of attorneys in a District Attorney’s office (city unknown). These lawyers are the very buffoons behind creating an environment which operates with a wide open network, wide open access to data, and confidential data exposed to anyone on the network (and possibly outside the network) who wanted it. Additionally, there were malware and peer-to-peer applications installed on numerous (most) computers throughout the office. When a network support person in the IT department mentioned the dangers of this existing environment, he/she was presented with numerous roadblocks – arguments from lawyers rationalizing how their activities (mostly music file sharing via Napster) were acceptable. Lawyers, after all, are great at making an argument to support ANY position, no matter how lame or morally wrong it may be. It appears from this article that they expended great energy to make their attitude toward information security seem justifiable instead of facing the fact that they were putting their network and data at grave risk. Essentially, non-technical people were allowed to dictate the standards for technical systems, and all because they didn’t want to be inconvenienced and have their toys taken away. The network support person was later fired for being insubordinate to his/her “betters.” In other words – he/she told these cry babies how it is, what it would take to fix it, and they didn’t like it. Need I remind you – this was allegedly a District Attorney’s Office. I sure wouldn’t want to be that District Attorney when the network gets breached, the data gets stolen, and even ends up getting distributed though the peer to peer sharing network. Notice that I didn’t say “if,” I said “when” because it is going to happen unless they fix it and fix it quick, fast, and in a hurry. What a story that would be in the national news! Of course it wouldn’t be the first time a top lawyer was found to be criminally negligent of something, now would it?

That is why this article seemed to call out to me because I hear of and even see the same thing everyday. The attitude that:


“Your computer security mumbo-jumbo is fine for everyone else, but don’t you dare inconvenience ME!”


It’s all about “ME” and it’s all about the fact that these people are so very important that inconveniencing them would be the most heinous crime committed against humanity.

And this “ME” attitude is coming from people with master’s degrees, doctorates, professional status, and high power positions. Seems the richer they are, the more spoiled and whiny they are. The lawyers in this article are perfect examples. But not only are these types of people complaining about security that keeps them from playing with their toys on the corporate network, some managers these days are complaining about security measures that are revealing large numbers of vulnerabilities and security problems. It’s not even that there are problems that need to be fixed – it is that the numbers are making them look bad. It’s all about the numbers, and it’s all about looking bad. No thought is given to the fact that they look bad because they ARE bad. If they want to look good, then why not just fix the underlying problems? Is that so hard?

(This is the part where I rant about the bad drivers) This is the same population of people, no doubt, who are claiming the roadways as their own as they carelessly drive their beemers with no regard for others. While keeping a cell phone glued to their heads, they are then complaining that the speed limits and laws of common sense are keeping them from totally owning the road for themselves. In fact just today, one of these morons couldn’t find a parking spot at our building, so they parked their car in the motorcycle parking – how stupid is that? Justice was served – the campus police slapped a parking ticket right on that Mitsubishi. Hope the laziness was worth it. (Bad driver rant completed).

In many cases, it all comes down to this:


“Your security reports are making me look bad, so my management is giving me heat and withholding my budget until I fix the problems. So why don’t you come up with a way to make me not look so bad?”


They will try to rationalize how the data needs to be collected a different way so that the numbers (of problems) look better. My answer to that: Rather than waste so much time and energy trying to manipulate numbers to make you look good, why not just fix the problems and it will make you be good – for real! Manipulating numbers and hiding vulnerability problems is one way to make it looked fixed, but taking real action will actually fix it. But, as one of my graduate professors often said: “Figures don’t lie, but a liar sure figures.”

Another clever issue evasion strategy: the smoke screen. When faced with data that clearly shows that their area has problems, the management will ask irrelevant questions and demand explanations in order to throw off or divert effort. They have no idea what they are asking in many cases, and often look like jack asses because their questions show their glaring ignorance of information security concepts. These activities will often tie up security professionals for days while they make every effort to ensure that they are explaining the justification for valid and relevant security measures. Security people shouldn’t have to do this – it is a waste of time and keeps them from the business of keeping networks secure. Security professionals shouldn’t have to agonize how to explain something so simple to allegedly intelligent people. This is more like explaining to your small kids why they can’t run down the hall with scissors.

But time after time, these people want to send us off to find an answer that will appeal to their twisted sense of logic. It may not be the right answer, and it may not be the one that is actually going to solve the problems. This is what an acquaintance of mine refers to as a “find me a rock” exercise. Someone will tell you to go find a rock, and when you bring one back, they say: “No! That isn’t the kind of rock I wanted! Go find me another one.” These types of senseless tactics are meant to waste other people’s time and buy the stupid people some time to think up another excuse. And these people are making decisions! Wow – no wonder so many companies are in trouble.

OK – so let’s bite the bullet and see what it will take to do something about this. In the case of the lawyers in the story above, or even the situations I have described here, it is going to take some work - a lot of work - up front. It is going to take a huge amount of effort and many staff hours in the beginning. But the interesting thing I have found is that if a methodical plan is put into place, and some reasonable time given to remediate the problems, they will eventually get fixed or at least minimized to a tolerable level. If some well-spent time is dedicated up front toward attacking the problems, then the rest of the effort simply becomes a continual maintenance routine. If there are a lot of security problems, it is a matter of prioritizing them in order of severity, tackling the most serious first, cleaning up the rest, then putting a plan in place to keep them under control.

New security issues will always come up as new attacks are discovered, and patches from vendors are released. But if the bulk of the serious issues are already taken care of, then tackling these new issues will be a fairly simple exercise.

But in order for any of this to work, people’s attitudes toward information security have got to change. IT people are not janitors, the computers and network that people in the work place are using do NOT belong to the workers, and these are not toys simply put in place for their enjoyment. Being negligent about information security can get people in trouble – big trouble. So before a plan is put in place to tackle the technical issues, perhaps a plan should be put in place to teach security awareness. Teach people why security is so important, how to be secure, and how they will be held accountable for non-compliance. The touchy feely attitudes have got to give way to terminating buffoons who refuse to comply. If you were a CEO, and your employees continually put your company’s finances, data and reputation at risk, just how long would you put up with it?


My closing Thoughts:

Computer Janitor – indeed! My last tax return I reported income from salaries and earned military pensions in the $$$,$$$ range (six figures for you folks who didn’t get it). Many of my colleagues are pulling down similar salaries, and they are so far from being janitors – to make a statement such as that, or even think such a thing is just so wrong. I don’t know too many janitors who make that much money and have post-graduate educations. But I see all too many instances where otherwise smart, educated people feel and behave just that way – they feel that the equipment and resources that they use on the job don’t belong to anyone but them, and that the IT people are just there to help them when they can’t figure out how to copy a document from one folder to another, or their mouse isn’t doing the little “clicky” thing like it should. Heaven help anyone who should inconvenience these poor babies by telling them that they can’t run Napster un-abated on the corporate wire. Give me a break! Maybe there is a lot of validity to Nick Burns’ (Saturday Night Live) attitude toward users. Automatic drink holder giving you problems today?

Ooops – gotta run. Time to get out the Swiffer and get after those viruses. And by the way… You’re Welcome!!!

Reference: “When Lawyers Use Napster At Work” (Anonymous, InfoWorld, 2/27/07)


  • What do you call 350 lawyers resting at the bottom of the sea? A good start!

  • Stupid people – you can’t live with them, and there are only so many of them that you can cut up and stick in an ice chest.

  • Hey – my rat terrier is smarter than your CEO.

  • Hey you in the beemer – hang up and drive!
  • There is en epidemic in America - Fools! (Mr. T)

Monday, March 19, 2007

Why are Some Software Vendors So Security Unaware?

It seems odd to me that software vendors are releasing products that have vulnerabilities, and that they do not do anything to patch them. In fact in some cases, patching the host operating system breaks certain of these errant applications, and the remedy from the software vendor is to put the original, vulnerable file right back in its place. For example, a security patch is released from the operating system vendor. The minute it is applied, another third party application that relies on these files breaks. Instead of the software vendor releasing a patch for its own product, it relies on a “self repair” method that just restores previous, vulnerable versions of the files that need to be fixed.

Clearly, the software vendors are not talking to each other. Or they just don’t care that they aren’t fixing their applications to keep up with the threats. Either way, these companies are causing more work for IT department security people, and they are putting systems at risk. In Part 2 of my series on investigating false positives and other security anomalies, I discussed just such an instance - where a manual, self researched, and self developed fix had to be applied because the software vendor had no intention of fixing their product. This was clearly a case where the vendor did not care that they were injecting vulnerabilities into my environment. Good thing I'm not mentioning who it is here, eh?


Related Links:


Investigating False Positives and Other Security Anomalies Part 2

In Part 1 of this series, I talked about investigating vulnerability scan results where the scanner alerted on something and further investigation revealed that the vulnerability was a leftover file from an upgrade. For example, the computer was upgraded from Microsoft Office XP to Office 2003. As far as Windows/Microsoft Updates and the enterprise patch management system are concerned, the computer is running Office 2003 completely patched for the installed software. An in-depth investigation was performed which involved going into the scanner session logs and finding out which file caused the scanner to alert on the vulnerability. Indeed it turns out to be a left over file from Office XP that Office 2003 doesn’t even use. Renaming or removing the file fixes the vulnerability, and Office continues to work normally, so all fixed, right? After all, it was a pretty straight forward fix – we knew that a Microsoft product was upgraded, the new Microsoft product didn’t clean up after the old version, and a vulnerability was left on the box. The entire solution of renaming an old Office file seemed logical and one thing was related to the other.


Not so fast! Let’s move on to the next type of scenario in the investigative process that is even a little more difficult to troubleshoot. The vulnerability scanner alerts on something that experience showed was easily remediated by renaming a file or removing it. The vulnerability was related to a left over file, and getting rid of it resolved the vulnerability – for the time being. Later on, the computer is scanned again and the same vulnerability has returned. Nothing had changed. Noting new was installed, and the same versions of the Office software are still on the machine. So let’s take a more in-depth look at this type of scenario and see what happened.


Scenario 3: A scan is run, and the now much discussed vulnerability related to MS Office products has appeared on several computers. The previously developed fix of renaming or removing a vulnerable left-over file proves successful. Later, these same computers are scanned again. Many of them show that the vulnerability has been successfully remediated, but on a few of them, the vulnerability has reappeared. Investigation into the scan session logs shows that the previously renamed vulnerable file is again the culprit causing this vulnerability to appear. Physical inspection of the file system on the target computers verifies that the renamed file is still in its renamed form, but now another copy of the original vulnerable file is on the box. One thing interesting is noted about these computers: They all something in common – they all a have a piece of third-party software (not Microsoft software) installed. The software title and vendor is not important here, and I don’t want to be accused (or worse) of name calling and accusing on the Internet, so I just won’t get into a name-calling session here.


Further in-depth troubleshooting reveals that again renaming the vulnerable file, and performing an immediate scan shows the vulnerability remediated. Now for the next step: verifying that all of the software works. MS Office works fine, the corporate email client works fine, as do the web browser and other normally used applications. The computer is scanned, and the machine is still clean of the vulnerability. Since all of the computers with this problem had in common another piece of software, this particular application is tested last. The application in question is started up, and produces an error. The error is that there is a corrupt or missing DLL file, and is prompting the user to install the original software CD for this application. This is done, and the software repairs itself. The application now runs normally. Another scan reveals that the vulnerability is now present. Looking at the folder on the computer where the vulnerable file resides, we see that sure enough the renamed file is still there, but the original vulnerable file has returned.

In this case, it is clear that another piece of software (not from Microsoft) is related to, and interacting with, the Microsoft native files for an MS Office installation. Not sure what to make of this, a call to the vendor’s tech support reveals that the suspect Microsoft DLL may be used by their software, but they are not sure. This will have to be investigated further with the software developers. There are some known versions of the DLL file that are not vulnerable, so the hypothesis was that replacing the offending DLL with a non-vulnerable version will fix the problem. Replacing with a non-vulnerable version allows the software to operate normally and error free. A re-scan of the computer now shows that it is vulnerability free also.

Note: As of this writing, the software company in question has no intention of fixing this vulnerability in their software. I was in communication with them today and the tech support person I spoke with stated that the company will not be releasing a patch for this product - it is Microsoft's problem, evidently. This brings up the issue that a piece of third party software is latching onto a known application (Microsoft Office) for its functionality, and the vendors are not keeping up on the security ramifications of their software installing known vulnerabilities onto a computer.


Investigations Start with Patch and Scan Testing Process:

It is quite clear from the events discussed in the two parts of this article that a proactive strategy for patching and scanning is in order. Such a strategy will ensure that vulnerability scanning is built in to the patch testing process so that 1) patches will be verified as being applied and that they do not have adverse affects on the system, and 2) the vulnerabilities that the patch is meant to target are actually being remediated. Testing the patches as they are received will ensure that they apply properly and do not break applications. Then a follow up of deploying patches to a pilot group will give the patches more rigorous testing in a real environment, and allow IT staffs to clear up any problems quickly before deploying to the full production environment. Once this is done, a follow-up scan on those same pilot computers will verify whether or not the applied patch mitigated the vulnerability. If it does, then the desired goal was achieved. If it does not, then it is time to have an investigative process to find out if 1) the patch is not doing its job, or 2) the scanner is alerting on a false positive condition. This process will allow for the discovery of scanner alert anomalies as soon as possible, and a fix to be developed before the scanner hits the full production environment.


It is important to note that testing patches and developing vulnerability remediations can be tricky in that hidden causes will sometimes not be found right away. This was evident when scenario 4 as described above brought to light newly discovered problems for a situation that was thought to be previously resolved. For this reason, it is important to carefully choose those users who will be in the pilot group for the second phase of patch testing. They should be fairly computer savvy users who know how to properly respond to error messages, and that they also know how to carefully document any problems that they run into. This is the group of people that will know that these errors are possibly going to occur, and won’t fly off the handle when they do. They will know to calmly notify their IT support staff, and won’t panic and click through all the error messages until the IT staff has had a chance to see them and work the issues. So having said all that, let’s take a look at the chronological steps that would take place in this whole testing and investigative process.


The Steps (in chronological order):

  1. The new patches are released from the vendor and the new cycle of patch and scan testing begins.
  2. Non-production machines in a lab and/or virtualized environment are scanned and verified clean of all vulnerabilities before patch testing begins.
  3. All discovered vulnerabilities are remediated on the designated test machines before patch testing begins. Those that cannot be remediated are documented with the reason why they cannot be resolved (ie false positive, etc.).
  4. The new patches are first tested on the non-production machines in lab or virtualized environment.
  5. All applications on the lab machines are tested for proper operation, and that no errors are experienced on the machines.
  6. The scanner profile is verified to have the proper checks for the latest patches and other newly discovered conditions.
    • Note: This often happens after the new patches are released, and it can sometime take a few days for the new scanning profiles to be configured on the scanner. However, steps 1 – 5 can be performed prior to the new scanner profiles being configured. Step 7 and beyond, however, are dependant on the scanner being configured to look for the new patches that are being tested in this phase.
  7. A test scan is performed on the lab machines to verify that they are free of vulnerabilities. Any vulnerabilities found are investigated and resolved.
  8. Patches are deployed to the designated pilot group of production users.
  9. The designated pilot users are to use their computers for a pre-determined testing period. Three days to one week is recommended for this testing period.
  10. A sample of this pilot group is selected for another verification scan, and the scanner is run against these machines to verify that the machines are clean of the vulnerabilities that the new patches were meant to mitigate.
    • Note: This step can be done concurrently with the operational testing period described in step 9.
    • Any vulnerability conditions that are related to the new patches that exist as a result of this scan are investigated, documented, and solutions determined.
  11. The new patches are deployed to the remainder of the production machines.
  12. Full scan of the production environment is run.
    • Note: The full scan of the production environment to look for the new patches should take place only after allowing sufficient deployment time. This will vary depending on the size and geographical diversity on the organizations.


Wrapping It All Up:

Having a standardized, methodical approach to patching and scanning will help give more structure to the whole process. Using a checklist, like the one above or a locally developed checklist will help ensure that testing is performed properly. It is easy to overlook things, and very easy to be led down an incorrect path when investigating the types of situations mentioned in this series. It is important to use several different tools and analyze the similarities and differences in information that each of the tools provides.


So the lesson learned in this whole exercise is that IT staffs should be less prone to jumping on the “False Positive” bandwagon, and more inclined to using research and investigative techniques to find out what is really happening. Don’t rely on just one analysis tool or set of data to make a conclusion. Security is hard work, and often involves many steps to get it right. Overlooking even a single vulnerability by claiming that it is a false positive gets it off your to-do list, but doesn’t actually clear it up – your machines are still vulnerable. If the bits are on the box, you MUST remediate. Calling it a false positive when it is not does not constitute a valid remediation strategy.

Use some industry respected assessment tools, come up with a good (consistent) methodology, search for clues, and above all else – do some research and investigation! As a line from the movie Apollo 13 goes – “Work the problem! Don’t make it worse by guessing!” Guessing that it is a false positive is a dangerous habit to get into.