<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: attackers]]></title>
    <link>http://securityratty.com/tag/attackers</link>
    <description></description>
    <pubDate>Sun, 21 Sep 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Motivation Behind Adaptive Analytics and CEP]]></title>
      <link>http://securityratty.com/article/2a2a666360a23f6491ff25e41de8c981</link>
      <guid>http://securityratty.com/article/2a2a666360a23f6491ff25e41de8c981</guid>
      <description><![CDATA[This is a continuation of The Genesis of Complex Event Processing: Asymmetric Capabilities and CEP, Event Noise and Asymmetric Event Processing where I have been discussing the motivation behind CEP...]]></description>
      <content:encoded><![CDATA[<p>This is a continuation of <a title="The Genesis of Complex Event Processing: Asymmetric Capabilities" rel="bookmark" href="../2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</a> and <a title="CEP, Event Noise and Asymmetric Event Processing" rel="bookmark" href="../2008/10/02/cep-event-noise-and-asymmetric-event-processing/">CEP, Event Noise and Asymmetric Event Processing</a> where I have been discussing the motivation behind CEP and adaptive analytics in cyberspace.</p>
<p>Around the same time that Professor Luckham and his team was working on CEP applications in network management and security management, I was leading efforts to build network and security management control centers for the <a href="http://www.af.mil">United States Air Force</a>.  In the beginning, dating back to 1994, my Internet-related work was for <a href="http://www.acc.af.mil/" target="_blank">Air Combat Command (ACC)</a>, working out of ACC headquarters at <a href="http://www.langley.af.mil/" target="_blank">Langley Air Force Base</a>.</p>
<p>In 1997, I lead a technical team that developed countermeasures against an actual distributed Internet-based attack on the Langley AFB SMTP email infrastructure.  This attack was documented in a technical paper, <a href="http://www.thecepblog.com/e-mail-bombs-and-countermeasures-cyber-attacks-on-availability-and-brand-integrity/" target="_blank"><em>E-Mail Bombs and Countermeasures: Cyber Attacks on Availability and Brand Integrity,</em> IEEE Network Magazine, Vol. 12, No. 2, pp. 10-17, March/April 1998</a>.  In addition, this attackand countermeasures I designed was featured in Popular Science Magazine in an 1998 article, <a href="http://www.thecepblog.com/warcom-by-frank-vizard/" target="_blank">War.Com</a> and other news channels.  I also published a number of related papers on this topic.</p>
<p>Our team used a rule-based approach for countermeasures against massive email bombs attacks on the Langley Air Force Base email infrastructure.   We called this rule-based system, <em>BombShelter.</em> and it was written in <a href="http://www.perl.org/" target="_blank">PERL</a>.  I developed both the original software architecture and the original working prototype for BombShelter (in two days) and then we turned the software over to our team who used the rule-based approach for daily attack countermeasures.</p>
<p>I watched for days, and then weeks, as my team designed rules, and the attackers wrote new attacks that circumvented the rules.  Some folks in the Pentagon used to say that I &#8220;lead the effort to fight the first war in cyberspace&#8221;.   It might have have been the first cyberwar, I am not sure, but it was certainly the first publicly documented cyberwar.  There is no doubt about this.</p>
<p>Without getting into all the historical footnotes and significance of this cyberwar that was fought with experts and rule-based systems, I would like to jump to an important conclusion.</p>
<blockquote><p><em>Rule-based systems are useful, but have limited functionality and scaleability in most complex event processing applications.</em></p></blockquote>
<p>Rule-based systems are human resource intensive because rule-based systems cannot learn and adapt on their own, humans learn and then write new rules.  This is how rule-based systems work.</p>
<p>This is the motivation behind why I spend a lot of time to search for new, more efficient and adaptive methods as alternatives to rule-based systems.   After extensive research, I published a series of papers on the future of intrusion detection in the Internet.  <a href="http://www.thecepblog.com/intrusion-detection-systems-and-multisensor-data-fusion/" target="_blank"><em>Intrusion Detection Systems &amp; Multisensor Data Fusion - Creating Cyberspace Situational Awareness</em></a> <a class="external autonumber" title="http://www.silkroad-asia.com/papers/pdf/acm-p99-bass.pdf" rel="nofollow" href="http://www.silkroad-asia.com/papers/pdf/acm-p99-bass.pdf">[1]</a>, helped lead an evolution in Internet security, particularly in the area of network-based intrusion detection systems (IDS).</p>
<p>In my published research work, motivated by limitations with rule-based approaches, I used the same mature functional model that is used to process missile attacks, control global air traffic, and other complex event processing applications in physical space; but I applied these concepts to cyberspace.</p>
<p>Around the same time, Professor Luckham and others were working on similar problems, all related to real-time detection and response to threats in cyberspace.  They were also funded by the US government.</p>
<blockquote><p>Sidebar: Stream processing of transaction- based systems (databases), another area of interest, was focused on a totally different problem, which was the low latency processing of straight-thru processing in databased-oriented systems.   These stream processing systems were, and remain however,  rule-based systems.  The problems we were trying to solve in cyberspace, however, cannot be efficiently and pragmatically solved by rule-based systems alone.  Only relatively simple scenarios can be efficiently detected by rule-based stream processing systems.</p></blockquote>
<p>The vast majority of complex event processing classes of problems require rules plus advanced algorithms that can learn and adapt in real-time.    I know this, not from reading papers or taking university classes on rule-bases systems, but from working on some very challenging operational problems in real-time.    This is why I remain interested in complex event processing and why I continue to elaborate on why rule-based systems have limitations.</p>
]]></content:encoded>
      <pubDate>Sat, 11 Oct 2008 09:15:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/intrusion detection systems">intrusion detection systems</category>
      <category domain="http://securityratty.com/tag/rule-bases systems">rule-bases systems</category>
      <category domain="http://securityratty.com/tag/transaction- based systems">transaction- based systems</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/real-time detection">real-time detection</category>
      <category domain="http://securityratty.com/tag/real-time">real-time</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/countermeasures">countermeasures</category>
      <source url="http://www.thecepblog.com/2008/10/11/the-motivation-behind-adaptive-analytics-and-cep/">The Motivation Behind Adaptive Analytics and CEP</source>
    </item>
    <item>
      <title><![CDATA[Another Google Bug Put Users At Phishing Risk Due To Domain Flaw And Frame Injection Possibility]]></title>
      <link>http://securityratty.com/article/a3a826883c2875f86d3d818f4095efc1</link>
      <guid>http://securityratty.com/article/a3a826883c2875f86d3d818f4095efc1</guid>
      <description><![CDATA[A security expert has demonstrated that Googles Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users login credentials....]]></description>
      <content:encoded><![CDATA[A security expert has demonstrated that Google&#8217;s Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users&#8217; login credentials. Google Calendar and other sensitive Google services are susceptible to similar tampering.
A proof-of-concept (PoC) attack, published by Adrian Pastor of the GNUCitizen ethical hacking collective, exploits [...]]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 19:05:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive google services">sensitive google services</category>
      <category domain="http://securityratty.com/tag/users login credentials">users login credentials</category>
      <category domain="http://securityratty.com/tag/spoof pages">spoof pages</category>
      <category domain="http://securityratty.com/tag/adrian pastor">adrian pastor</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/google calendar">google calendar</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/collective">collective</category>
      <source url="http://cyberinsecure.com/another-google-bug-put-users-at-phishing-risk-due-to-domain-flaw-and-frame-injection-possibility/">Another Google Bug Put Users At Phishing Risk Due To Domain Flaw And Frame Injection Possibility</source>
    </item>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for September]]></title>
      <link>http://securityratty.com/article/0862d75223b7c454c16ff0e7eaa11124</link>
      <guid>http://securityratty.com/article/0862d75223b7c454c16ff0e7eaa11124</guid>
      <description><![CDATA[As usual, here's September's summary of all of my posts at Zero Day . You may also want to catch up and go through August's and July's summaries , next to adding my personal RSS feed or Zero Day's...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrZOYxNDcI/AAAAAAAACQ4/Ktm1do-Wybs/s1600-h/zero_day_october.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrZOYxNDcI/AAAAAAAACQ4/77K4rA4iDJo/s200-R/zero_day_october.png" /></a>As usual, here's September's summary of all of my posts at <a href="http://blogs.zdnet.com/security">Zero Day</a>. You may also want to catch up and go through <a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html">August's</a> and <a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html">July's summaries</a>, next to adding <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal RSS feed</a> or <a href="http://feeds.feedburner.com/zdnet/security">Zero Day's main feed</a> to your RSS reader.<br />
<br />
Notable article for September - <a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a>.<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1847">DoS vulnerability hits Google's Chrome, crashes with all tabs</a><br />
<b>02.</b> <a href="http://blogs.zdnet.com/security/?p=1852">Malware and spam attacks exploiting Picasa and ImageShack</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1899">Spamming vendor launches managed spamming service</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1908">Facebook introducing new security warning feature</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1911">Google downplays Chrome's carpet-bombing flaw</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1922">Targeted malware attack against U.S schools intercepted</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1926">The most "dangerous" celebrities to search for in 2008</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1935">Norwegian BitTorrent tracker under DDoS attack</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1939">Attacker: Hacking Sarah Palin's email was easy</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1958">Bill O'Reilly's web site hacked, attackers release personal details of users</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1964">India's government: At last, we've cracked Blackberry's encryption</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1975">Memory exhaustion DoS vulnerability hits Google's Chrome</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1983">44% of second hand mobile devices still contain sensitive data</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1986">Spammers attacking Microsoft's CAPTCHA -- again</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8t7TM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8t7TM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9ttSM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9ttSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7rNcm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7rNcm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BtQ4m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BtQ4m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7SqTM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7SqTM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZCYzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZCYzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Gu2Bm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Gu2Bm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413926169" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 06:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google downplays chrome">google downplays chrome</category>
      <category domain="http://securityratty.com/tag/chrome">chrome</category>
      <category domain="http://securityratty.com/tag/vendor launches">vendor launches</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/september">september</category>
      <category domain="http://securityratty.com/tag/norwegian bittorrent tracker">norwegian bittorrent tracker</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/hand mobile devices">hand mobile devices</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413926169/summarizing-zero-days-posts-for.html">Summarizing Zero Day's Posts for September</source>
    </item>
    <item>
      <title><![CDATA[Hacking Your VoIP Box From The Net]]></title>
      <link>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</link>
      <guid>http://securityratty.com/article/ddef0bbead6572419deccb8cf4914ce6</guid>
      <description><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read this recent blog from McAfee's Avert Labs and you may wonder. An Avert analyst, reading about vulnerabilities in the...]]></description>
      <content:encoded><![CDATA[Do you do penetration testing of your own network? Is it comprehensive enough? Read <a href="http://www.avertlabs.com/research/blog/index.php/2008/09/29/the-lack-of-attention-in-voip-devices/">this recent blog from McAfee's Avert Labs</a> and you may wonder.

An Avert analyst, reading about vulnerabilities in the Cisco IP phone model 7960 then used Google to try to find publicly-accessible 7960 phones. He found "almost 10" (does that mean 9? awkward turn of phrase). 1 of them had the vulnerable firmware version  And the vulnerability was that the phone's web interface reveals a lot of sensitive network information, so the company that holds that phone has a vulnerable network.

What was revealed by the phone? "...the IP addresses of the TFTP server/router/DNS server/DHCP server/Cisco Call Manager, as well as some application links, internal device configuration, and debugging information. If there are any exploitable vulnerabilities in one of these linked servers, attackers could use this information to stage further attacks."

There's always more to test for, and mistakes you in device configuration can have dire consequences.
<p><a href="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/a"><img src="http://feedads.googleadservices.com/~a/KqezZ8B5wlQOthXrTY4hSBEoKXo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/sIcbcZ5FSGQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 04 Oct 2008 13:06:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive network information">sensitive network information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/device configuration">device configuration</category>
      <category domain="http://securityratty.com/tag/internal device configuration">internal device configuration</category>
      <category domain="http://securityratty.com/tag/phone model">phone model</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/exploitable vulnerabilities">exploitable vulnerabilities</category>
      <category domain="http://securityratty.com/tag/vulnerable network">vulnerable network</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/sIcbcZ5FSGQ/hacking_your_voip_box_from_the_net.html">Hacking Your VoIP Box From The Net</source>
    </item>
    <item>
      <title><![CDATA[Mitigating Exploitation Techniques]]></title>
      <link>http://securityratty.com/article/27bfc341fbca807ff6ecae555aaf5bad</link>
      <guid>http://securityratty.com/article/27bfc341fbca807ff6ecae555aaf5bad</guid>
      <description><![CDATA[Hi, Matt Miller from Microsofts Security Science team here to talk about exploitation &amp; mitigation

Over the past decade exploitation techniques have been developed and refined to the point that very...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>Hi, Matt Miller from Microsoft’s Security Science team here to talk about exploitation &amp; mitigation.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>Over the past decade exploitation techniques have been developed and refined to the point that very little expertise has been needed to successfully exploit software vulnerabilities.&nbsp; These refinements have lowered the bar for attackers and drastically increased the probability that an attack will be successful.&nbsp; This has led to the need for mitigation techniques that can prevent or otherwise reduce the reliability of a given exploitation technique.&nbsp; In relation to one another, we can think about exploitation techniques as attempting to drive the probability of successful exploitation to 100%, whereas mitigation techniques attempt to drive the same probability to zero.&nbsp; While probability gives us a nice measure for the effectiveness of a mitigation technique, it doesn't give us immediate insight into the specific problems being solved by mitigations or the techniques that are being used to solve those problems.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>Understanding the problems that are solved by mitigations is what provided the motivation for the presentation I will be giving at BlueHat.&nbsp; Many of the materials in this presentation were taken from my work with Leviathan Security Group and have been repurposed to focus on taking attendees on a journey through the technical evolution of the mitigation techniques developed by Microsoft.&nbsp; This evolution is illustrated in terms of the problems each mitigation technique is attempting to solve, the methods used to solve them, and how well each mitigation has stood the test of time thus far.&nbsp; The journey itself starts first with /GS and ends with a glimpse of the mitigation techniques we might expect to see in the future.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: PMingLiU; mso-fareast-theme-font: minor-fareast; mso-ansi-language: EN-US; mso-fareast-language: ZH-TW; mso-bidi-language: AR-SA">It is my hope that this presentation will illustrate that mitigation<SPAN style="COLOR: #1f497d">s</SPAN>, when working in concert with one another, can be an effective method <SPAN style="COLOR: black; mso-themecolor: text1">of</SPAN><SPAN style="COLOR: #1f497d"> </SPAN>helping to keep users secure by reducing the probability of a successful exploitation attempt for the majority of known exploitation techniques.</SPAN><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8974688" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 20:07:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/techniques">techniques</category>
      <category domain="http://securityratty.com/tag/mitigation technique">mitigation technique</category>
      <category domain="http://securityratty.com/tag/mitigation">mitigation</category>
      <category domain="http://securityratty.com/tag/mitigation techniques attempt">mitigation techniques attempt</category>
      <category domain="http://securityratty.com/tag/exploitation">exploitation</category>
      <category domain="http://securityratty.com/tag/mitigation techniques">mitigation techniques</category>
      <category domain="http://securityratty.com/tag/exploitation techniques">exploitation techniques</category>
      <category domain="http://securityratty.com/tag/successful exploitation attempt">successful exploitation attempt</category>
      <category domain="http://securityratty.com/tag/successful">successful</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/10/02/mitigating-exploitation-techniques.aspx">Mitigating Exploitation Techniques</source>
    </item>
    <item>
      <title><![CDATA[Flaw in internet protocol core could disrupt almost any broadband connection device]]></title>
      <link>http://securityratty.com/article/1492ec3fdfb1fea641e9b9b53474b92a</link>
      <guid>http://securityratty.com/article/1492ec3fdfb1fea641e9b9b53474b92a</guid>
      <description><![CDATA[Security experts have discovered a flaw in a core internet protocol that can be exploited to disrupt just about any device with a broadband connection. The finding could have profound consequences for...]]></description>
      <content:encoded><![CDATA[Security experts have discovered a flaw in a core internet protocol that can be exploited to disrupt just about any device with a broadband connection. The finding could have profound consequences for millions of people who depend on websites, mail servers, and network infrastructure.
The bug in the transmission control protocol (TCP) affords attackers a wealth [...]]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 18:22:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/broadband connection">broadband connection</category>
      <category domain="http://securityratty.com/tag/transmission control protocol">transmission control protocol</category>
      <category domain="http://securityratty.com/tag/core internet protocol">core internet protocol</category>
      <category domain="http://securityratty.com/tag/network infrastructure">network infrastructure</category>
      <category domain="http://securityratty.com/tag/profound consequences">profound consequences</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/affords attackers">affords attackers</category>
      <category domain="http://securityratty.com/tag/mail servers">mail servers</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <source url="http://cyberinsecure.com/flaw-in-internet-protocol-core-could-disrupt-almost-any-broadband-connection-device/">Flaw in internet protocol core could disrupt almost any broadband connection device</source>
    </item>
    <item>
      <title><![CDATA[Gartner: Security risks rise as smart phones get smarter]]></title>
      <link>http://securityratty.com/article/ff8b6dc70506debbf40d9c136d6ff95f</link>
      <guid>http://securityratty.com/article/ff8b6dc70506debbf40d9c136d6ff95f</guid>
      <description><![CDATA[As mobile devices are increasingly used in business applications, they're becoming bigger targets for attackers, a Gartner analyst warned at an IT security...]]></description>
      <content:encoded><![CDATA[As mobile devices are increasingly used in business applications, they're becoming bigger targets for attackers, a Gartner analyst warned at an IT security conference.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:086a1f75376cb8dcd29352e6ff6bdeeb:atyT7W2s4v4O59VxhyEzplCcJEDq8xDnHvm3SHNsxE9GPFny9oTXIRl33WRYi%2BLU6SmKJhlyl%2FX6'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fb9389412603aa623966a296bb232bcd:ZCZnmRKHQr6lTVfTngkU2jIP7MLxHggRZp7sa9wATM7wfi9gm%2BsCDc0UU%2BY6Z6aVsJrQkrybEJsNRA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5df9f3a9e64d40765d58e71ce150bbea:68ZBU8pYsM1CFlIdElsCIBY0kmrfO%2FKzB3s3Le22%2BGxhMEhCyp2Rtc8bDlTmo%2BTWG5iHpfnZcOcseQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:85bf31792693558910544e7b519f8883:ASsxOtjlDc3RKWpLPP22Y%2B5QPhUrHjW9oxgsWm8gB2GO%2BbtBCoXCpL3X9vyEv2ZLVD6Nc8stbFNidw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e8347f7b3cf6dea62109dd9cebe56220" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e8347f7b3cf6dea62109dd9cebe56220" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security conference">security conference</category>
      <category domain="http://securityratty.com/tag/mobile devices">mobile devices</category>
      <category domain="http://securityratty.com/tag/business applications">business applications</category>
      <category domain="http://securityratty.com/tag/gartner analyst">gartner analyst</category>
      <category domain="http://securityratty.com/tag/bigger targets">bigger targets</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/increasingly">increasingly</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e8347f7b3cf6dea62109dd9cebe56220">Gartner: Security risks rise as smart phones get smarter</source>
    </item>
    <item>
      <title><![CDATA[Have CrackBerry, Will Travel]]></title>
      <link>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</link>
      <guid>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</guid>
      <description><![CDATA[Blogger: Dan Blum
It is no surprise for us to hear loose lips flapping in India about a capability to decrypt Blackberry and other carrier traffic
After all, weve done basic threat analysis for years...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>It is no surprise for us to hear loose lips flapping in India about <a href="http://economictimes.indiatimes.com/At_last_govt_cracks_BlackBerry_code/articleshow/3510719.cms">a capability to decrypt Blackberry and other carrier traffic</a>.</p>

<p>After all, we’ve done basic threat analysis for years and it was only months ago that I was brought into a company-wide CISO meeting at a U.S. defense contractor to help them hash out their travel policy for mobile devices. Going into the meeting, I knew their policy restricted taking devices to a list of countries considered dangerous – but there was an exemption for BlackBerries.</p>

<p>Our research uncovered that BlackBerry is pretty secure in most respects. It has transport encryption along with optional password protection, remote kill, disk encryption, and S/MIME encryption. Viruses have not flourished on this functionally limited and closed platform. Few if any third party add on programs are required for additional protection. Nonetheless, I went into the meeting prepared to talk with the CISOs about the risks and security limitations of life on BlackBerry.</p>

<p>Was the BlackBerry exemption reasonable? At the time, BlackBerry transport encryption was not known to have been broken (to be fair, the article listed above still qualifies as rumor, not certainty of breakage). However, I pointed out that it is dangerous to assume well-equipped attackers like military or intelligence organizations can’t crack transport encryption. And even if they haven’t cracked the BlackBerry network and whole disk encryption features, sophisticated adversaries have other attack paths. Check out Neal Stephenson’s excellent book <a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1222262354&amp;sr=1-1">Cryptonomicon</a> for a description of how a talented adversary might “see” your keystrokes and screen images through a motel room wall, for example.</p>

<p>If one of your employees – such as a key scientist, project manager, or executive – is targeted for surveillance and is carrying sensitive data through certain countries, one could argue that he or she had better undergo serious counter-intelligence training.&nbsp; Learn to spot and shake tails, sneak into dark alleys for that BlackBerry fix. Learn to paper the closet with layers of aluminum foil and send messages in the dark. Defend that BlackBerry with encryption, long passphrases, and kung fu. But unless James Bond is running your company, I doubt this is what your executives have in mind for the next business trip!</p>

<p>Assuming your organization’s lower level employees are like needles in a haystack and won’t be bothered could be an exercise in wishful thinking. It is always possible that nation states are monitoring some or all of the airwaves. Not so long ago the NSA had a massive a covert surveillance program in place. Years before the government was reportedly snarfing up terabytes of emails and crunching them through a program called Carnivore. And of course, selective monitoring of people on watch lists continues on a large scale. This is just the surveillance we know about in the U.S. We suspect there’s more behind the scenes and especially in countries such as China. Even if you train your non-specifically-targeted low level employees to write and speak in search-keyword-free code, the carnivore programs of the world are pretty good at sniffing out those interesting needles – such as descriptions of your business plans, manufacturing processes, and trade secrets.</p>

<p>Sound paranoid? I admit that I don’t know what the probabilities of being targeted or monitored are – just that it can happen. It’s the height of arrogance to believe that a nation state can’t get your information if they’ve targeted it and you’re within their borders. And it’s dangerous to rely on security by obscurity when medium or high consequence information must be protected.</p>

<p>What can be done? If key personnel can't dispense with the BlackBerry (or any other email device) during international travel to those countries where information may be most at risk, they (the users) should limit communications to what they’d feel comfortable uttering over a potentially-monitored telephone call. Controlling incoming communications – messages sent by others – is a harder problem. Until data loss prevention (DLP) products become more contextually sensitive about the travel issues, it may be best not to synchronize the BlackBerry with the overseas user’s home mailbox. Instead, have the user give out a temporary address for the BlackBerry and warn senders to be discreet. </p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/402766223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry transport encryption">blackberry transport encryption</category>
      <category domain="http://securityratty.com/tag/transport encryption">transport encryption</category>
      <category domain="http://securityratty.com/tag/exemption">exemption</category>
      <category domain="http://securityratty.com/tag/blackberry exemption reasonable">blackberry exemption reasonable</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption features">disk encryption features</category>
      <category domain="http://securityratty.com/tag/blackberry fix">blackberry fix</category>
      <category domain="http://securityratty.com/tag/decrypt blackberry">decrypt blackberry</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/402766223/have-crackberry.html">Have CrackBerry, Will Travel</source>
    </item>
    <item>
      <title><![CDATA[Adobe slates patch for Flash clipboard poisoning attacks]]></title>
      <link>http://securityratty.com/article/4e0d9590da5d132673d05e65fb2b68de</link>
      <guid>http://securityratty.com/article/4e0d9590da5d132673d05e65fb2b68de</guid>
      <description><![CDATA[Adobe Systems said it will soon fix a bug in Flash that attackers have used for more than a month to poison Mac and Windows users' clipboards with URLs to malicious...]]></description>
      <content:encoded><![CDATA[Adobe Systems said it will soon fix a bug in Flash that attackers have used for more than a month to poison Mac and Windows users' clipboards with URLs to malicious sites.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:735d509972e78c06d7711058462a7d60:yrNr5e8rdrfPEkvMRZGO%2B77oafUvBPhtZpcmoj5ai9201cuIWPdJdBDhw%2FxUGGKVpOd5GIedX%2FpH7DZyO6e6Dt5Ucmhey7DBPehO42QgDrk%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:e467a613dd0723bd207fa020556fd7dc:Q8CMqq7UVr2F73sIvyzzYAJde8iDbcm41kwi%2F1bquZWGbm9au%2BGc9wmeStpdscQBZNEH%2FeB3snRNWB718WbJRTRmlHSBo7ll1%2B2kOxWlna4%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:80caf23f63c3bde3ef12ececfab87842:bt0cksl8mYJ2Duf3NIrd57Ei5xRYoxc2%2B9ecE1799w%2FkbaqjXZg3PftIqVq0WLGGRQf%2FOLjbgJEVodab%2FEfgUPDfbrZYMKksKDpszoCmfzI%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:de6e721ac71c04b712370cb81760f83e:HSeqjPVUFKB%2BWmXdYiAb400f8jGrnFoWC77gOUPBOZkw1NxjUY3SKU%2Bz1NxUsVWlm5Wb8mq%2BvUrMdFaI52XqN%2FhgoY4nHuUtx39ioL93KrA%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=11d75a97820759bd4e1e66aebd5ec1c9" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=11d75a97820759bd4e1e66aebd5ec1c9" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious sites">malicious sites</category>
      <category domain="http://securityratty.com/tag/poison mac">poison mac</category>
      <category domain="http://securityratty.com/tag/windows users">windows users</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/fix">fix</category>
      <category domain="http://securityratty.com/tag/urls">urls</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=11d75a97820759bd4e1e66aebd5ec1c9">Adobe slates patch for Flash clipboard poisoning attacks</source>
    </item>
    <item>
      <title><![CDATA[Adobe slates patch for Flash clipboard poisoning attacks]]></title>
      <link>http://securityratty.com/article/1597eb15dcce09615dfb2a12e73a9e7d</link>
      <guid>http://securityratty.com/article/1597eb15dcce09615dfb2a12e73a9e7d</guid>
      <description><![CDATA[Adobe Systems last week said it will soon quash a bug in Flash that has been used for more than a month by attackers to poison Mac and Windows users' clipboards with URLs to malicious...]]></description>
      <content:encoded><![CDATA[Adobe Systems last week said it will soon quash a bug in Flash that has been used for more than a month by attackers to poison Mac and Windows users' clipboards with URLs to malicious sites.]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious sites">malicious sites</category>
      <category domain="http://securityratty.com/tag/poison mac">poison mac</category>
      <category domain="http://securityratty.com/tag/windows users">windows users</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/quash">quash</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.networkworld.com/news/2008/092208-adobe-slates-patch-for-flash.html?fsrc=rss-security">Adobe slates patch for Flash clipboard poisoning attacks</source>
    </item>
  </channel>
</rss>
