<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: classic]]></title>
    <link>http://securityratty.com/tag/classic</link>
    <description></description>
    <pubDate>Mon, 25 Aug 2008 08:11:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Classic Closeouts retailer booted from TRUSTe program]]></title>
      <link>http://securityratty.com/article/1b9fe7f0b46846438343631668ec98ec</link>
      <guid>http://securityratty.com/article/1b9fe7f0b46846438343631668ec98ec</guid>
      <description><![CDATA[Online retailer Classic Closeouts has been expelled from the TRUSTe consumer-protection program due to inappropriate handling of unauthorized credit-card...]]></description>
      <content:encoded><![CDATA[Online retailer Classic Closeouts has been expelled from the TRUSTe consumer-protection program due to inappropriate handling of unauthorized credit-card charges.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=14580?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=14580?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/program due">program due</category>
      <category domain="http://securityratty.com/tag/credit-card charges">credit-card charges</category>
      <category domain="http://securityratty.com/tag/truste">truste</category>
      <source url="http://www.networkworld.com/news/2008/100608-classic-closeouts.html?fsrc=rss-security">Classic Closeouts retailer booted from TRUSTe program</source>
    </item>
    <item>
      <title><![CDATA[23 things I wish would just go away]]></title>
      <link>http://securityratty.com/article/603a4cf64e87ceb5ccd1be61f064b68f</link>
      <guid>http://securityratty.com/article/603a4cf64e87ceb5ccd1be61f064b68f</guid>
      <description><![CDATA[It's list season here at PC World, so I may as well join in--with something that resembles the &quot;little list&quot; made famous by Ko-Ko, Lord High Executioner in Gilbert and Sullivan's classic The Mikado....]]></description>
      <content:encoded><![CDATA[It's list season here at PC World, so I may as well join in--with something that resembles the "little list" made famous by Ko-Ko, Lord High Executioner in Gilbert and Sullivan's classic The Mikado. He sings of "offenders who might well be underground, and who never would be missed." Me, too.]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list season">list season</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/gilbert">gilbert</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/famous">famous</category>
      <category domain="http://securityratty.com/tag/underground">underground</category>
      <category domain="http://securityratty.com/tag/classic">classic</category>
      <category domain="http://securityratty.com/tag/executioner">executioner</category>
      <category domain="http://securityratty.com/tag/mikado">mikado</category>
      <source url="http://www.networkworld.com/news/2008/093008-23-things-i-wish-would.html?fsrc=rss-security">23 things I wish would just go away</source>
    </item>
    <item>
      <title><![CDATA[Of Planes and Ships]]></title>
      <link>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</link>
      <guid>http://securityratty.com/article/47dfbf92b3eaba317f07cfa2064d0a9b</guid>
      <description><![CDATA[Tom Barnett is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.thomaspmbarnett.com/weblog/2008/09/column_121.html">Tom Barnett</a> is consistently the most interesting writer on globalization and econo-security seam. This weeks piece confronts a problem every security architect can relate to (emphasis added on the &quot;nail it to the wall&quot; quote at the end):</p><p><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">One of the main problems in counterterrorism today is that there are so many people and vehicles, and so much data and material, moving through globalization&#39;s myriad networks that it seems virtually impossible to track it all effectively. Nowhere has this problem been more acute than on the high seas.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In 2006, Adm. Harry Ulrich, then U.S. commander of NATO Naval Forces Europe, decided to do something about it. Despite having virtually no resources, his dream was to transpose the global air-traffic control system onto sea traffic.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Worldwide, aircraft are transparent, because they&#39;re all required to carry an identification beacon that allows them to be tracked leaving and entering airports, and monitored between airports, by a global network of sensors. Act suspiciously and somebody&#39;s fighter aircraft will soon be on your tail.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">No such pervasive system currently exists globally for maritime traffic. While bigger ships carry an ID beacon similar to aircraft, without a shared monitoring network, that&#39;s like tracking only selected commercial jets and giving everyone else a pass.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">So Ulrich, upon taking command, asked a simple question: &quot;If we can do that in the air, why can&#39;t we do it on the sea?&quot; He made a point of pioneering his sea-traffic-control effort first inside the Mediterranean, where NATO&#39;s southern naval forces have historically been concentrated, but his real target was waters off Africa -- the most ungoverned maritime space in the world.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich knew the U. S. Navy couldn&#39;t do it alone, much less bring Africa&#39;s meager coast-guard-like navies up to snuff so they could do it on their own. So he quickly created a network of assets -- both public and private -- to manage that space, modeling his monitoring system on international air-traffic control.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Ulrich began stitching together a network of shore-based sensors ringing the Mediterranean. His naval command then began initial monitoring by tapping into the International Maritime Organization&#39;s existing Automated Identification System, transforming NATO&#39;s ability to track ship traffic in the Med.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Almost overnight, NATO went from tracking dozens of ships on the Mediterranean to thousands, and instead of getting the data sometimes up to 72 hours late, now the contacts were being tracked in one to five minutes -- to an accuracy within 50 feet on the earth&#39;s surface.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When the classic big-firm systems integrators told Ulrich it would be too costly to pull it off, the admiral turned to the Volpe Center in Cambridge, Massachusetts, a U.S. Department of Transportation research center. Instead of hundreds of millions of dollars, Ulrich&#39;s initial network cost $900,000. The shore-based receivers are small, roughly the size of a radar dish you might find on a pleasure craft.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The strength of the system is a function of its reach: the more countries join, the larger the shared operational picture. By the time Ulrich retired at the end of 2007, he had enlisted 32 countries throughout the Mediterranean, the North Atlantic, along the west coast of Africa, around the Black Sea, and in the Pacific. Today, the network continues to spread around the planet.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; font-size: 14px; line-height: 20px; "><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">With Ulrich&#39;s system in place, local police, coast guards, and border patrols catch most bad guys, obviating American military responses. As Harry told me for an article I wrote about his work in a fall 2007 issue of Esquire, </span><span style="font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;I don&#39;t do defense; I do security. When you talk defense, you talk containment and mutually assured destruction. When you talk security, you talk collaboration and networking. This is the future.&quot;</span></span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The admiral&#39;s legacy program, the Maritime Safety and Security Information System, earned the Volpe Center a prestigious &quot;Innovations in American Government&quot; award this month from Harvard University&#39;s Ash Institute for Democratic Governance and Innovation.</span></p></blockquote><p><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Security Collaboration + Networking &#160;= Federation. This is indeed the future - SAML came along just at the nick of time.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When you assume that to do access control you must have &quot;Complete Mediation&quot; in Saltzer and Schroeder&#39;s terms of the subject (users), the objects (data), the session, and the roles, then you are going to have an interesting life trying to deliver anything. And if you do it will mucho expensive.</span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="border-collapse: collapse; line-height: 20px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">if you take the federated autonomous nodes approach, agree upon an attribute schema plus a protection model for same, and basic protocol, you are then free to move about the country. Security doesn&#39;t have to equal centralization or high cost. Get the attributes from point a to point b securely.</span></div>]]></content:encoded>
      <pubDate>Sun, 28 Sep 2008 19:04:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architect">security architect</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/identification system">identification system</category>
      <category domain="http://securityratty.com/tag/initial network cost">initial network cost</category>
      <category domain="http://securityratty.com/tag/initial">initial</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/ulrich">ulrich</category>
      <category domain="http://securityratty.com/tag/time ulrich">time ulrich</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/of-planes-and-ships.html">Of Planes and Ships</source>
    </item>
    <item>
      <title><![CDATA[DHS rejects criticism of agency as Beltway politics]]></title>
      <link>http://securityratty.com/article/c68b479a29faaea1950c785b7c004000</link>
      <guid>http://securityratty.com/article/c68b479a29faaea1950c785b7c004000</guid>
      <description><![CDATA[The U.S. Department of Homeland Security dismissed as classic Beltway politics the suggestion by a group of experts that it was unfit to lead the country's cybersecurity...]]></description>
      <content:encoded><![CDATA[The U.S. Department of Homeland Security dismissed as classic Beltway politics the suggestion by a group of experts that it was unfit to lead the country's cybersecurity initiatives.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:d425f7f2ef6f606b57e0cbe38b2f41b7:yh1nxkfjG422uPxKMEBS3zZx1Ni3tbHOwuPs0JlBXtoIObsBra0%2BFOy%2Bqa4s8a0NI6gtEIG96ftGVOf65rOVfsilfRReDVEjNmtBOTUeohc%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:9835717c897c78dfc6d7ded81a068800:QtJxw78KxlqxSGfejvB3kMYQfrfqQpzCqF5CGN1Fqphr4qPpdiOZ3WVYfylnnUbXKM1WNe2j2jIaqFd2hdKDhqlyyXcPMqk%2BowIm1PiwZpk%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:d1f9c51876618305b250144a55cd6cbe:jJacslvZJQTXY78LJDCJsOAWc6QkVxuoBBct5HRhfuT54Wh1JfUnD0%2FODsfeT%2BKeCj7nCsgzKZzMEBoUHIHQvFRCMn7QIbMhCRcQTsELE4A%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:6a34d2ba76213794a9a7bde859cc8a34:MMGswF00fg7fe0se8YCpIwn4%2BQaW0DgqNlc%2BIV47jqJ7OjQDUUH2wTo3b1fCZs9o5iG3dIYdwBe3ymnkmZBzb3furfeNCKCymvy31hCpdBI%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=70ccdafad7c14d498fc3aef7bd64f419" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=70ccdafad7c14d498fc3aef7bd64f419" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/classic beltway politics">classic beltway politics</category>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/cybersecurity initiatives">cybersecurity initiatives</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/lead">lead</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/suggestion">suggestion</category>
      <category domain="http://securityratty.com/tag/unfit">unfit</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=70ccdafad7c14d498fc3aef7bd64f419">DHS rejects criticism of agency as Beltway politics</source>
    </item>
    <item>
      <title><![CDATA[DHS rejects criticism of agency as Beltway politics]]></title>
      <link>http://securityratty.com/article/83b23f8898932935debccb80345fa61b</link>
      <guid>http://securityratty.com/article/83b23f8898932935debccb80345fa61b</guid>
      <description><![CDATA[The U.S. Department of Homeland Security Wednesday dismissed as classic Beltway politics the suggestion by a group of experts that it was unfit to lead the country's cyber security...]]></description>
      <content:encoded><![CDATA[The U.S. Department of Homeland Security Wednesday dismissed as classic Beltway politics the suggestion by a group of experts that it was unfit to lead the country's cyber security initiatives.]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cyber security initiatives">cyber security initiatives</category>
      <category domain="http://securityratty.com/tag/classic beltway politics">classic beltway politics</category>
      <category domain="http://securityratty.com/tag/homeland security wednesday">homeland security wednesday</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/lead">lead</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/suggestion">suggestion</category>
      <category domain="http://securityratty.com/tag/unfit">unfit</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <source url="http://www.networkworld.com/news/2008/091708-dhs-rejects-criticism-of-agency.html?fsrc=rss-security">DHS rejects criticism of agency as Beltway politics</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Logs and Log Management - 2]]></title>
      <link>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</link>
      <guid>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</guid>
      <description><![CDATA[I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not &quot;the original logging evangelist&quot; anymore :-) Here is a bunch of good log-related reading, useful for those...]]></description>
      <content:encoded><![CDATA[<p>I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not <a href="http://www.chuvakin.org">&quot;the original logging evangelist&quot;</a> anymore :-) Here is a bunch of good log-related reading, useful for those struggling with logs (aka &quot;everybody&quot; :-))</p>  <ol>   <li>Our brilliant field engineer Dimitri McKay <a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">talks about</a> the eternal topic of converting Windows event logs to syslog. <a href="http://blogs.msdn.com/ericfitz/">Yes, Eric, we ALL know</a> it is ugly, but that is the only way that actually works well across all systems ...</li>    <li>More on Windows and syslog: &quot;<a href="http://redmondmag.com/columns/article.asp?editorialsid=1868">Syslog ... 20 Years Later</a>.&quot;&#160; BTW, this is really not about syslog, but about Vista/2k8 finally getting an ability to natively centralize the event logs via event subscriptions (&quot;It's only about twenty years behind schedule, if you're counting.&quot;)</li>    <li>Two fun pieces on correlation: <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">1</a> and <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">2</a>. What often kills &quot;a log correlation project&quot;? &quot;Whoever had worked on it <em>had not had much time available to learn the way to properly configure the software</em>&quot; (from <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">this</a>)&#160; and &quot;correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs.&quot; (from <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">this</a>) None of this is new, but a useful reminder nonetheless</li>    <li>Fun <a href="http://www.loglogic.com">LogLogic</a> podcast is <a href="http://blogs.zdnet.com/Gardner/?p=2723">here</a>. The topic of this high-level discussion (CEO) is related to operational use for logs. I did one with them too; on logs and virtualization (will be up soon)</li>    <li>A couple of good posts on logging from Nemertes Research: &quot;<a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals</a>&quot;,&#160; &quot;<a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy</a>&quot;</li>    <li><a href="http://eventlogs.blogspot.com/2008/08/why-your-hr-department-will-love.html">Reminder</a> about a few useful Windows Vista and 2k8 events: 4802 (screensaver engaged) and 4803 (screensaver dismissed)</li>    <li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">One person is wondering</a> about the usefulness of logging after &quot;experiencing&quot; Linux auditd logging (kernel audit): &quot;Logs are like a warm blanket; verbose logging means you can know what's happening on your systems if you keep up with the logs.&#160; At the same time, logs become a burden very very easily, and they are easy to ignore.&quot; <a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">This post</a> is a must read for <a href="http://www.chuvakin.org">us logging afficionados</a>; producing too much log data is a sure way to make people hate you...</li>    <li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">This</a> also follows the same theme: people doubting the god-like power of logs :-) &quot;So for an administrator to not care about logs was a shock.&quot; But would I argue that &quot;<a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">log management is NOT a pain?</a>&quot; Now, would I? :-)</li>    <li>A classic about logging for application developers: &quot;<a href="http://www.securityfocus.com/infocus/1888">Building Secure Applications: Consistent Logging</a>.&quot;&#160; I am noticing a lot more discussions about logging in a developer community, e.g. see <a href="http://ayende.com/Blog/archive/2008/08/02/Logging-Auditing-and-Alerts.aspx">this</a> and <a href="http://www.softwaremag.com/l.cfm?doc=1048-5/2007">this</a> (the latter, BTW, contains a lot of info on &quot;why log&quot; for developers). Overall, &quot;getting logging right&quot; is important (and will get more important in the future) and people need something NOW and cannot wait for the <a href="http://cee.mitre.org">standards.</a>&#160; BTW, I am planning a mini-crusade on how to train application developers to include useful logging in their applications...</li>    <li>Finally, the &quot;Is SIEM dead?&quot; theme is continued in this fun post &quot;<a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">Life after SIEM. Situational Awareness is next.</a>&quot; Indeed, <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">context is key for logs</a>. BTW, if somebody mentions that I have &quot;vendor bias&quot;, I will kick your ass! :-)</li> </ol>  <p>Enjoy!</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gABUL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gABUL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=5mpyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=5mpyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AMhOL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AMhOL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393291744" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 04:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/windows event logs">windows event logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <category domain="http://securityratty.com/tag/train application developers">train application developers</category>
      <category domain="http://securityratty.com/tag/log correlation project">log correlation project</category>
      <category domain="http://securityratty.com/tag/application developers">application developers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393291744/fun-reading-on-logs-and-log-management.html">Fun Reading on Logs and Log Management - 2</source>
    </item>
    <item>
      <title><![CDATA[Anti-theft Protocols]]></title>
      <link>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</link>
      <guid>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</guid>
      <description><![CDATA[At last Fridays Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong
Examples include
GSM mobile phones have...]]></description>
      <content:encoded><![CDATA[<p>At last Friday&#8217;s Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong.</p>
<p>Examples include:</p>
<ul>
<li>GSM mobile phones have an identifier for the phone (separate from the identifier for the user) that can be blacklisted when the phone is stolen.</li>
<li>Some car radios will stop working when the battery is disconnected, and only start working again when a numeric code is entered. This is intended to deter theft of the radio.</li>
<li>In Windows Vista, Bitlocker can be used to encrypt files. One of  the intended applications for this is that if someone steals your laptop, it will be difficult for them to gain access to your encrypted files.</li>
</ul>
<p>Ross told a story of what happened when he needed to disconnect the battery on his car: the radio stopped working, and the code he had been given to reactivate it didn&#8217;t work - it was the wrong code.<br />
Ross argues that these reactivation codes are unecessary, because other measures taken by the car manufacturers - such as making radios non-standard sizes, and hence not refittable in other car models - have made them redundant.</p>
<p>I described how the motherboard on a laptop had needed to be replaced recently. The motherboard contains the TPM chip, which contains the encryption keys needed to decrypt files protected with Bitlocker. If you replace the motherboard, the files on your hard disk will become unreadable, even if the disk is physically OK. Domain-joined Vista machines can be configured so that a sysadmin somewhere within your organization is able to recover the keys when this happens.</p>
<p>Both of these situations suffer from classic usability problems: the recovery procedures are invoked rarely (so users may not know what they&#8217;re supposed to do), and, if your system is configured incorrectly, you only find out when it is <i>too late</i>: you key in the code to your radio and it remains a doorstop; the admin you hoped was escrowing your keys turns out not to have the private key corresponding to the public key you were encrypting under (or, more subtly: the person with the authority to ask for your laptop&#8217;s key to be recovered is not you, because the appropriate admin has the <i>wrong name</i> for the laptop&#8217;s owner in their database).</p>
<p>I also described what happens when an XBox 360 is stolen. When you buy XBox downloadable content, you buy <i>two</i> licenses: one that&#8217;s valid on any XBox, as long as you&#8217;re logged in to XBox live; and one that&#8217;s valid on just your XBox, regardless of who&#8217;s logged in. If a burglar steals your Xbox, and you buy a new one, you need to get another license of the <i>second</i> type (for all the other people in your household who make use of it). The software makes this awkward, because it knows that you already have a license of the <i>first</i> type, and assumes that you couldn&#8217;t possibly want to buy it again. The work-around is to get a new email address, a new Microsoft Live Account, and a new Gamer Tag, and use these to repurchase the license. You can&#8217;t just change the gamertag, because XBox live doesn&#8217;t let the same Microsoft Live account have two gamertags. And yes, I know, your buddies in the MMORPG you were playing know you by your gamertag, so you don&#8217;t want to change it.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:18:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xbox">xbox</category>
      <category domain="http://securityratty.com/tag/xbox downloadable content">xbox downloadable content</category>
      <category domain="http://securityratty.com/tag/wrong code">wrong code</category>
      <category domain="http://securityratty.com/tag/xbox live">xbox live</category>
      <category domain="http://securityratty.com/tag/wrong">wrong</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/car radios">car radios</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/microsoft live account">microsoft live account</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/03/anti-theft-protocols/">Anti-theft Protocols</source>
    </item>
    <item>
      <title><![CDATA[Security ROI]]></title>
      <link>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</link>
      <guid>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</guid>
      <description><![CDATA[Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable
It's become a big deal...]]></description>
      <content:encoded><![CDATA[<p>Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable.</p>

<p>It's become a <a href="http://www.csoonline.com/article/print/217727">big</a> <a href="http://www.computerworld.com/securitytopics/security/story/0,10801,83207,00.html?nas=ROI-83207">deal</a> in IT security, too. Many corporate customers are demanding ROI models to demonstrate that a particular security investment pays off. And in response, vendors are providing ROI models that demonstrate how their particular security solution provides the best return on investment.</p>

<p>It's a <a href="http://communities.intel.com/openport/blogs/it/2008/08/25/are-security-roi-figures-meaningless">good</a> <a href="http://communities.intel.com/openport/blogs/it/2007/08/14/the-problem-of-measuring-information-security">idea</a> in <a href="https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/677-BSI.html">theory</a>, <a href="http://taosecurity.blogspot.com/2007/07/are-questions-sound.html">but</a> <a href="http://www.bloginfosec.com/2007/07/13/bejtlich-and-business-will-it-blend/">it's</a> <a href="http://blog.vorant.com/2007/07/my-input-to-roi-spat.html">mostly</a> <a href="http://taosecurity.blogspot.com/2007/07/no-roi-no-problem.html">bunk</a> <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">in</a> <a href="http://taosecurity.blogspot.com/2007/07/security-roi-revisited.html">practice</a>.</p>

<p>Before I get into the details, there's one point I have to make. "ROI" as used in a security context is inaccurate. Security is not an investment that provides a return, like a new factory or a financial instrument. It's an expense that, hopefully, pays for itself in cost savings. Security is about loss prevention, not about earnings. The term just doesn't make sense in this context.</p>

<p>But as anyone who has lived through a company's vicious end-of-year budget-slashing exercises knows, when you're trying to make your numbers, cutting costs is the same as increasing revenues. So while security can't produce ROI, loss prevention most certainly affects a company's bottom line.</p>

<p>And a company should implement only security countermeasures that affect its bottom line positively. It shouldn't spend more on a security problem than the problem is worth. Conversely, it shouldn't ignore problems that are costing it money when there are cheaper mitigation alternatives. A smart company needs to approach security as it would any other business decision: costs versus benefits.</p>

<p>The classic methodology is called annualized loss expectancy (ALE), and it's straightforward. Calculate the cost of a security incident in both tangibles like time and money, and intangibles like reputation and competitive advantage. Multiply that by the chance the incident will occur in a year. That tells you how much you should spend to mitigate the risk. So, for example, if your store has a 10 percent chance of getting robbed and the cost of being robbed is $10,000, then you should spend $1,000 a year on security. Spend more than that, and you're wasting money. Spend less than that, and you're also wasting money.</p>

<p>Of course, that $1,000 has to reduce the chance of being robbed to zero in order to be cost-effective. If a security measure cuts the chance of robbery by 40 percent -- to 6 percent a year -- then you should spend no more than $400 on it. If another security measure reduces it by 80 percent, it's worth $800. And if two security measures both reduce the chance of being robbed by 50 percent and one costs $300 and the other $700, the first one is worth it and the second isn't.</p>

<p>The Data Imperative</p>

<p>The key to making this work is good data; the term of art is "actuarial tail." If you're doing an ALE analysis of a security camera at a convenience store, you need to know the crime rate in the store's neighborhood and maybe have some idea of how much cameras improve the odds of convincing criminals to rob another store instead. You need to know how much a robbery costs: in merchandise, in time and annoyance, in lost sales due to spooked patrons, in employee morale. You need to know how much not having the cameras costs in terms of employee morale; maybe you're having trouble hiring salespeople to work the night shift. With all that data, you can figure out if the cost of the camera is cheaper than the loss of revenue if you close the store at night -- assuming that the closed store won't get robbed as well. And then you can decide whether to install one.</p>

<p>Cybersecurity is considerably harder, because there just isn't enough good data. There aren't good crime rates for cyberspace, and we have a lot less data about how individual security countermeasures -- or specific configurations of countermeasures -- mitigate those risks. We don't even have data on incident costs.</p>

<p>One problem is that the threat moves too quickly. The characteristics of the things we're trying to prevent change so quickly that we can't accumulate data fast enough. By the time we get some data, there's a new threat model for which we don't have enough data. So we can't create ALE models.</p>

<p>But there's another problem, and it's that the math quickly falls apart when it comes to rare and expensive events. Imagine you calculate the cost -- reputational costs, loss of customers, etc. -- of having your company's name in the newspaper after an embarrassing cybersecurity event to be $20 million. Also assume that the odds are 1 in 10,000 of that happening in any one year. ALE says you should spend no more than $2,000 mitigating that risk.</p>

<p>So far, so good. But maybe your CFO thinks an incident would cost only $10 million. You can't argue, since we're just estimating. But he just cut your security budget in half. A vendor trying to sell you a product finds a Web analysis claiming that the odds of this happening are actually 1 in 1,000. Accept this new number, and suddenly a product costing 10 times as much is still a good investment.</p>

<p>It gets worse when you deal with even more rare and expensive events. Imagine you're in charge of terrorism mitigation at a chlorine plant. What's the cost to your company, in money and reputation, of a large and very deadly explosion? $100 million? $1 billion? $10 billion? And the odds: 1 in a hundred thousand, 1 in a million, 1 in 10 million? Depending on how you answer those two questions -- and any answer is really just a guess -- you can justify spending anywhere from $10 to $100,000 annually to mitigate that risk.</p>

<p>Or take another example: airport security. Assume that all the new airport security measures increase the waiting time at airports by -- and I'm making this up -- 30 minutes per passenger. There were 760 million passenger boardings in the United States in 2007. This means that the extra waiting time at airports has cost us a collective 43,000 years of extra waiting time. Assume a 70-year life expectancy, and the increased waiting time has "killed" 620 people per year -- 930 if you calculate the numbers based on 16 hours of awake time per day. So the question is: If we did away with increased airport security, would the result be more people dead from terrorism or fewer?</p>

<p>Caveat Emptor</p>

<p>This kind of thing is why most ROI models you get from security vendors are <a href="http://www.postini.com/services/roi_calculator.html">nonsense</a>. Of course their model demonstrates that their product or service makes financial sense: They've jiggered the numbers so that they do.</p>

<p>This doesn't mean that ALE is useless, but it does mean you should 1) mistrust any analyses that come from people with an agenda and 2) use any results as a general guideline only. So when you get an ROI model from your vendor, take its framework and plug in your own numbers. Don't even show the vendor your improvements; it won't consider any changes that make its product or service less cost-effective to be an "improvement." And use those results as a general guide, along with risk management and compliance analyses, when you're deciding what security products and services to buy.</p>

<p>This essay <a href="http://www.csoonline.com/article/446866/Security_ROI_Fact_or_Fiction_">previously appeared</a> in <i>CSO Magazine</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Ql60WL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Ql60WL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=npHViL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=npHViL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 02:05:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security countermeasures">security countermeasures</category>
      <category domain="http://securityratty.com/tag/countermeasures">countermeasures</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/security incident">security incident</category>
      <category domain="http://securityratty.com/tag/individual security countermeasures">individual security countermeasures</category>
      <category domain="http://securityratty.com/tag/security measure cuts">security measure cuts</category>
      <category domain="http://securityratty.com/tag/security measure reduces">security measure reduces</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/security_roi_1.html">Security ROI</source>
    </item>
    <item>
      <title><![CDATA[ColdFusion: Hack Me or Help Me]]></title>
      <link>http://securityratty.com/article/9fb9073abbbbfc649c8feeed2afceb21</link>
      <guid>http://securityratty.com/article/9fb9073abbbbfc649c8feeed2afceb21</guid>
      <description><![CDATA[For your consideration, the endless battle between security and convenience
Front and center: ColdFusion
I've been picking on ColdFusion-built apps again a bit lately, and one of my observations has...]]></description>
      <content:encoded><![CDATA[For your consideration, the endless battle between security and convenience.<br />Front and center: ColdFusion.<br />I've been picking on ColdFusion-built apps again a bit lately, and one of my observations has been that consistently, if mismanaged, the verbose error reporting features in ColdFusion can be really problematic.<br /><br /><a href="http://holisticinfosec.org/content/view/78/45/" target="_blank">HIO-2008-0713 JOBBEX JobSite SQLi & XSS</a><br /><a href="http://holisticinfosec.org/content/view/79/45/" target="_blank">HIO-2008-0729 BookMine SQLi & XSS</a><br /><br />Recently, I stumbled on an example of way too much information disclosure in a few sites running a ColdFusion-built CMS. The error reporting was so verbose it included the base path, data source name, database username, and yes, the <strong>database password</strong>.<br />I've cleaned it up for the protection of all involved, but here's a screen shot of only 1/4 of the details this site coughed up when I tweaked the input to a calendar date variable.<br /><br /><a href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SLblWNYqSmI/AAAAAAAAACc/BIPkxSBOxpg/s1600-h/ColdFusionTMI.png"><img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SLblWNYqSmI/AAAAAAAAACc/BIPkxSBOxpg/s320/ColdFusionTMI.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5239627386205129314" /></a><br /><br />When I reached out to the developers of this app (always and immediately responsive), they assured me that this was not due to a flaw in the app, but that the "information should be protected, and is by default for our installations" and that the client disabled the security check and turned debugging on. I accept this explanation entirely, but it leads to the classic debate around the dangers of mismanaged debugging features, be they developer added or ColdFusion feature driven. Stupid user tricks are always an issue, but how much rope should they be given to hang themselves? Does error reporting really need to include the database username and password?<br /><br />Allow me to present a few different perspectives.<br />First, rvdh's take on <a href="http://www.0x000000.com/?i=610" target="_blank">Attacking ColdFusion</a>. Developers can learn a lot from this post, if only in that it precisely points out attack vectors. Ronald sums up my concerns aptly:<br />"As we know, error messages are important. Especially error messages generated by database software we want to inject. This, is useful for obtaining information about table structures that can be a real time-saver for attackers. If the right information is available, attackers do not have to guess database tables and fields anymore, nor having to brute force them. I have never seen so much information regarding the site's structure, used database, table names, drivers, server setup and other information useful for attackers that those of ColdFusion. It almost says: Please Hack Me!"<br />As I can't presume to improve on this stance, I won't. Well said.<br /><br />Next, a developer's take on the issue from <a href="http://www.usefulconcept.com/" target="_blank">Joshua Cyr</a>, who has declared it <a href="http://www.usefulconcept.com/index.cfm/2008/8/27/ColdFusion-Errors-and-Security" target="_blank">Check Your Error Output Day</a>. Joshua highlights two key points:<br />1) Do NOT enable the robust errors setting in CF Administrator.<br />2) Don't forget to remove debugging dump code.<br />Heed this advice, ColdFusion fans!<br /><br />One destination that all "secure" ColdFusion paths should lead to is the use of <em>cfqueryparam</em>. Ronald spells it out well mid way through his <a href="http://www.0x000000.com/?i=610" target="_blank">discussion</a>, and so do the following resources:<br /><a href="http://www.coldfusionjedi.com/index.cfm/2008/7/29/What-Folks-arent-using-cfqueryparam" target="_blank">coldfusionjedi</a><br /><a href="http://www.coldfusionmuse.com/index.cfm/2008/7/28/cfqueryparam-protects-against-daleks" target="_blank">Coldfusion Muse</a><br /><br />Further excellent resources for ColdFusion security issues:<br /><a href="http://www.coldfusionmuse.com/index.cfm/2008/7/18/Injection-Using-CAST-And-ASCII" target="_blank">SQL Injection Part II (Make Sure You Are Sitting Down)</a><br /><a href="http://www.12robots.com/index.cfm/Security" target="_blank">12Robots.com</a><br /><br />In closing, security and convenience needn't always be at odds, but often allowing for both requires a higher state of awareness for developers and end-users. Let common sense prevail; perhaps it'll give me less to do in the way of <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">research</a>. ;-)<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/08/coldfusion-hack-me-or-help-me.html&title=ColdFusion:%20Hack%20Me%20or%20Help%20Me " title="ColdFusion: Hack Me or Help Me ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/08/coldfusion-hack-me-or-help-me.html" title="ColdFusion: Hack Me or Help Me ">digg</a>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 06:13:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/coldfusion">coldfusion</category>
      <category domain="http://securityratty.com/tag/coldfusion paths">coldfusion paths</category>
      <category domain="http://securityratty.com/tag/coldfusion fans">coldfusion fans</category>
      <category domain="http://securityratty.com/tag/coldfusion security issues">coldfusion security issues</category>
      <category domain="http://securityratty.com/tag/error">error</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database username">database username</category>
      <category domain="http://securityratty.com/tag/error messages">error messages</category>
      <category domain="http://securityratty.com/tag/coldfusion feature">coldfusion feature</category>
      <source url="http://holisticinfosec.blogspot.com/2008/08/coldfusion-hack-me-or-help-me.html">ColdFusion: Hack Me or Help Me</source>
    </item>
    <item>
      <title><![CDATA[Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis]]></title>
      <link>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</link>
      <guid>http://securityratty.com/article/f1bc531055cb81363944693871c78d6a</guid>
      <description><![CDATA[Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned here , here ; SANS jumped in as well ), I decided to follow along and join the initiative. One of the bloggers called it...]]></description>
      <content:encoded><![CDATA[<p>Following the new &quot;tradition&quot; of posting a security tip of the week (mentioned <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/08/pay_it_forward__1.html">here</a>, <a href="http://mcwresearch.com/archives/265">here </a>; <a href="http://isc.sans.org/diary.php?storyid=1530&amp;rss">SANS jumped in as well</a>), I decided to follow along and join the initiative. One of the bloggers called it <a href="http://mcwresearch.com/archives/255">&quot;pay it forward</a>&quot; to the community.</p>  <p>So, Anton Security Tip of the Day #16: <strong>Virtually Screwed - Journey Into VMWare ESX Log Analysis</strong></p>  <p>CISecurty guide for VMWare (<u><a href="http://www.cisecurity.org/bench_vm.html">here</a></u>) and DISA STIG for virtual machines (<u><a href="http://iase.disa.mil/stigs/stig/index.html">here</a></u>) both mandate collection and analysis of VM platform logs; none goes into enough details on what to look for in logs. Let's try to shed some light on security-focused log analysis of VMWare ESX v. 3.x logs. </p>  <p>First, at least until ESXi becomes the default choice, one needs to keep in mind that ESX as &quot;Linux-inside&quot; and thus diving into <em>/var/log</em> will not reveal any &quot;alien technology&quot; (well, not much :-)). However, one of the most useful logs is <em>/var/log/hostd.N </em>which is not a descendant of Linux standard logs. Extensive VM event records are written into this file. </p>  <p>Let's focus on various types of logins to the ESX platform and identify logs that indicate a successful and failed attempts to log in. Here are a few useful examples to analyze:</p>  <p><strong>Successful logins:</strong></p>  <ul>   <li><em>May 30 09:20:42 esx2 su(pam_unix)[9405]: session opened for user root by jhonny(uid=1626)</em> </li> </ul>  <p>This is a classic Linux root login message; you can watch for these by searching VMWare ESX logs for &quot;session AND opened AND user AND root.&quot;&#160; Notice the user name of the user who switched to root.</p>  <ul>   <li><em>May 30 09:20:34 esx2 sshd(pam_unix)[9364]: session opened for user jhonny by (uid=0)</em> </li> </ul>  <p>This is also a classic Linux message for a normal (non-root) user login.</p>  <ul>   <li><em>[2008-05-25 06:57:48.774 'ha-eventmgr' 111639472 info] Event 40645 : User jhonny@1.1.1.1 logged in</em> </li> </ul>  <p>This is a VMWare -specific application login to ESX. You can track such events by username, by event ID or by keywords &quot;event AND logged AND user&quot; (if you are using search)</p>  <p><strong>Failed logins:</strong></p>  <ul>   <li><em>May 30 09:20:31 esx2 sshd[9356]: Failed password for jhonny from 1.1.1.1 port 54773 ssh2</em> </li> </ul>  <p>Another classic Linux message from the ESX system; a failure to login due to incorrect password. </p>  <ul>   <li><em>May 27 12:06:59 esx2 sshd[4756]: Failed password for illegal user jonny from 1.1.1.1 port 30594 ssh2</em> </li> </ul>  <p>A message indicating a failure to login due to incorrect username (note a typo). </p>  <ul>   <li><em>May 25 07:03:48 esx1 sudo:&#160;&#160;&#160;&#160; jhonny : 3 incorrect password attempts ; TTY=pts/0 ; PWD=/var/log ; USER=root ; COMMAND=/bin/bash</em> </li> </ul>  <p>This ESX Linux platform message should also be familiar to Linux/Unix admins: it indicates multiple sudo password failures; look for such messages in the logs.</p>  <p>BTW, do you <a href="http://chuvakin.blogspot.com/2006/09/anton-security-tip-of-day-3-watch-for.html">need to be reminded</a> to track NOT only failed, but also successful login events?!</p>  <p>Overall, you must prepare for the future by learning to analyze&#160; VMWare logs, just like you handled &quot;legacy OS&quot;, such as Linux/Unix and Windows.</p>  <p>As I said before, I am tagging all the tips on <a href="http://del.icio.us/anton18">my del.icio.us feed</a>; here is the link: <a href="http://del.icio.us/anton18/security+tips">All Security Tips of the Day</a>.</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:54499c21-dd11-4ff7-9221-4cf2ec0c95fe" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/tips" rel="tag">tips</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a>, <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a></div> <script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");<br />document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script><script type="text/javascript"><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />var pageTracker = _gat._getTracker("UA-101395-5");<br />pageTracker._initData();<br />pageTracker._trackPageview();</script>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fhl1bK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fhl1bK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xW7PtK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xW7PtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=qHcDbK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=qHcDbK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/374532539" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware esx">vmware esx</category>
      <category domain="http://securityratty.com/tag/analyze vmware logs">analyze vmware logs</category>
      <category domain="http://securityratty.com/tag/analyze">analyze</category>
      <category domain="http://securityratty.com/tag/vmware esx logs">vmware esx logs</category>
      <category domain="http://securityratty.com/tag/esx">esx</category>
      <category domain="http://securityratty.com/tag/security tip">security tip</category>
      <category domain="http://securityratty.com/tag/anton security tip">anton security tip</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/374532539/anton-security-tip-of-day-16-virtually.html">Anton Security Tip of the Day #16: Virtually There - Journey Into VMWare ESX Log Analysis</source>
    </item>
  </channel>
</rss>
