<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: degrade]]></title>
    <link>http://securityratty.com/tag/degrade</link>
    <description></description>
    <pubDate>Tue, 11 Sep 2007 19:18:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Network Security It Takes a Village]]></title>
      <link>http://securityratty.com/article/79f566385e2aca32d1e3fa16a2ddaf4b</link>
      <guid>http://securityratty.com/article/79f566385e2aca32d1e3fa16a2ddaf4b</guid>
      <description><![CDATA[Something that should not be a surprise it turns out that securing the worlds largest temporary network takes a variety of vendors working together
For three days, InteropNet is one of the largest...]]></description>
      <content:encoded><![CDATA[<p>Something that should not be a surprise – it turns out that securing the world’s <a href="http://www.interop.com/blog/?p=395" target="_blank">largest temporary network</a> takes a <a href="http://www.interop.com/lasvegas/exhibition/interopnet/interopnet_sponsors.php" target="_blank">variety of vendors working together</a>.</p>
<p>For three days, InteropNet is one of the largest hacking targets on the planet. Attacks and threats come from both inside and outside the network. While the external attacks are certainly more malicious in intent, most of the internal ones ended up being due to misconfiguration or just plain misunderstanding.</p>
<p>Let’s play a game. It’s called <strong>Malicious or Not</strong>.</p>
<ol>
<li>Video streaming devices flooded the network with millions of multicast packets per second. EM7 noticed a big bump in latency on that network segment at the same time that the Enterasys Dragon IDS caught the flood of packets. Both tools could tell the origin of the packets and traced them back to misconfigured video multicast devices. In this case Not Malicious, but the result was still degradation to that network segment until the problem was fixed.</li>
<li>One vendor at the show purposely scanned all other devices on the show network to model them in their product demos. They didn’t ask anyone’s permission (or at least they didn’t ask ours). They purposely used multiple community strings to see if any would work. Malicious or Not? I’ll let you guys take this one. Personally I don’t think they meant it to be malicious, but as a monitoring tool in this space, they should have known that doing all that scanning would actually degrade network and other vendors’ device performance. I wonder if this is the vendor that was telling people that it does this at every show, and this is the first time it’s been caught.</li>
</ol>
<p><strong>Connect the Vendors</strong></p>
<p>Enterasys took care of external attacks by identifying them and asking Qwest to block them. But it’s with the internal “devices behaving badly”, that the real fun began. It took a combination of vendors to identify, confirm and track down the offenders on the network.</p>
<p>First <a href="http://www.enterasys.com/products/advanced-security-apps/dragon-intrusion-detection-protection.aspx" target="_blank">Enterasys Dragon IDS</a> alerted on suspicious behaviors. Dragon identified what IP, MAC address or port on a switch was having the issue – which information was cross-checked against vendor registry info in EM7 to track down offenders to a booth, a room or a wireless access point in the facility. <a href="http://blogs.splunk.com/thebaum/2008/05/02/new-splunk-apps-launch-at-interop-and-mms/" target="_blank">Splunk was also used to look at logs and verify the source of bad behavior</a>.</p>
<p>For tracking down wireless misbehavior, <a href="http://www.arubanetworks.com/products/management_analytics_threat_prevention.php" target="_blank">Aruba Networks had a cool tool</a> that took the info from Dragon and EM7 and used it to literally triangulate the location (down to a laptop).</p>
<p>Before the show started, we played wireless security hide and seek – testing our security process by sending people out with laptops and finding them, gps-style, whether they were walking around or hiding under a desk.</p>
<p>Overall, I think the real-life multi-vendor network security solutions I’ve <a href="http://blog.sciencelogic.com/interoperability-how-networking-should-be/05/13/2008/" target="_blank">described here are great examples of why interoperability is so important</a> and why InteropNet was such a great experience.</p>
<p><a href="http://sharethis.com/item?&wp=2.3.3&amp;publisher=f8a81d13-50d0-4a5c-833d-8e5f2341e305&amp;title=Network+Security+%26ndash%3B+It+Takes+a+Village&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fnetwork-security-it-takes-a-village%2F05%2F14%2F2008%2F">ShareThis</a></p>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 09:05:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/degrade network">degrade network</category>
      <category domain="http://securityratty.com/tag/temporary network takes">temporary network takes</category>
      <category domain="http://securityratty.com/tag/internal devices">internal devices</category>
      <category domain="http://securityratty.com/tag/enterasys dragon ids">enterasys dragon ids</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/enterasys">enterasys</category>
      <category domain="http://securityratty.com/tag/network segment">network segment</category>
      <category domain="http://securityratty.com/tag/dragon">dragon</category>
      <source url="http://blog.sciencelogic.com/network-security-it-takes-a-village/05/14/2008/">Network Security It Takes a Village</source>
    </item>
    <item>
      <title><![CDATA[New Banking Code shifts more liability to customers]]></title>
      <link>http://securityratty.com/article/9b44b9c51ea758a7e1d7c3acb08c42ff</link>
      <guid>http://securityratty.com/article/9b44b9c51ea758a7e1d7c3acb08c42ff</guid>
      <description><![CDATA[The latest edition of the Banking Code , the voluntary consumer-protection standard for UK banks, was released last week . The new code claims to give customers the most up to date information on how...]]></description>
      <content:encoded><![CDATA[<p>The latest edition of the <a href="http://www.bankingcode.org.uk/">Banking Code</a>, the voluntary consumer-protection standard for UK banks, was <a href="http://www.bba.org.uk/bba/jsp/polopoly.jsp?d=140&#038;a=13131">released last week</a>.  The new code claims to &#8220;give customers the most up to date information on how to protect their accounts from fraud.&#8221; This sounds like a worthy cause, but closer inspection shows customers could be worse off than they were before.</p>
<p>Clause 12.11 of <a href="http://www.bankingcode.org.uk/pdfdocs/PERSONAL_CODE_2008.PDF">the code</a> deals with liability for losses:<br />
<blockquote>If you act fraudulently, you will be responsible for all losses on your account. If you act without reasonable care, and this causes losses, you may be responsible for them. (This may apply, for example, if you do not follow section 12.5 or 12.9 or you do not keep to your account’s terms and conditions.)</p></blockquote>
<p>&nbsp; </p>
<p>Clauses 12.5 and 12.9 include some debatable advice about anti-virus software and clicking on links in email (more on this in a later post). While malware and phishing emails are a serious fraud threat, it is unrealistic to suggest that home users&#8217; computers can be adequately secured to defeat attacks.</p>
<p>Fraud-detection algorithms are more likely to be effective, since they can examine patterns of transactions over all customers. However, these can only be deployed by the banks themselves.</p>
<p>Existing phishing schemes would be defeated by <a href="http://en.wikipedia.org/wiki/Two-factor_authentication">two-factor authentication</a>, but UK banks have been notoriously slow at rolling out these, despite being widespread in many other European countries. Although not perfect these defences might cause fraudsters to move to easier targets. Two-channel and transaction authentication techniques additionally give protection against <a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack">man in the middle attacks</a>.</p>
<p>Until the banks are made liable for fraud, they have no incentive to make a proper assessment as to the effectiveness of these protection measures. The new banking code allows the banks to further dump the cost of their omission onto customers.</p>
<p>When the person responsible for securing a system is not liable for breaches, the system is likely to fail. This situation of misaligned incentives <a href="http://www.cl.cam.ac.uk/~twm29/science-econ.pdf">is common</a>, and here we see a further example. There might be a short-term benefit to banks of shifting liability, as they can resist introducing further security mechanisms for a while. However, in the longer term, it could be that moves like this will degrade trust in the banking system, causing everyone to suffer.</p>
<p>The House of Lords Science and Technology committee recognized this problem of the banking industry and <a href="http://www.publications.parliament.uk/pa/ld200607/ldselect/ldsctech/165/16511.htm#a49">recommended a statutory change</a> (8.17) whereby banks would be held liable for electronic fraud. The new Banking Code, by allowing banks to dump yet more costs on the customers, is a step in the wrong direction.</p>
]]></content:encoded>
      <pubDate>Wed, 09 Apr 2008 10:08:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/fraud-detection algorithms">fraud-detection algorithms</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/code claims">code claims</category>
      <category domain="http://securityratty.com/tag/electronic fraud">electronic fraud</category>
      <category domain="http://securityratty.com/tag/code deals">code deals</category>
      <category domain="http://securityratty.com/tag/fraud threat">fraud threat</category>
      <source url="http://www.lightbluetouchpaper.org/2008/04/09/new-banking-code-shifts-more-liability-to-customers/">New Banking Code shifts more liability to customers</source>
    </item>
    <item>
      <title><![CDATA[HACKED BY THE RBN!]]></title>
      <link>http://securityratty.com/article/14894413156ade1ed1214fcfffa39a2d</link>
      <guid>http://securityratty.com/article/14894413156ade1ed1214fcfffa39a2d</guid>
      <description><![CDATA[The RBN 0wnZ 7th1$ Bl0g! April 1st, 2008, St.Petersburg, Russia. The Russian Business Network, an internationally renowned cyber crime powerhouse is proud to present its very latest malware cocktail...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R_KeKF281LI/AAAAAAAABho/-NysWxyPiGM/s1600-h/snake_malware_CC.jpg"><img id="BLOGGER_PHOTO_ID_5184380017265398962" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R_KeKF281LI/AAAAAAAABho/-NysWxyPiGM/s200/snake_malware_CC.jpg" border="0" /></a>The RBN 0wnZ 7th1$ Bl0g! April 1st, 2008, St.Petersburg, Russia. The Russian Business Network, an internationally renowned cyber crime powerhouse is proud to present its very latest malware cocktail by embedding live exploit URLs within one of the top ten blogs to be malware embedded due to their overall negative attitude regarding the RBN's operational activities. A negative attitude that's been nailing down the RBN's cyber coffin as early 2007, prompting us to hire extra personel, thereby increasing our operational costs.<br /><br />Hijacked readers of this blog, executing the harmless to a VMware backed up PC setup files below, will not just strengten our relationship by having your computer contact ours, but will also help us pay for the infrastructure we use to host these, and let us continue maintaining our 99% uptime even in times of negative attitude on a large scale against our business services.<br /><br />How can you too, support the RBN, just like hundreds of thousands customers whose computers keep on connecting to ours already did? Do the following :<br /><br />- Execute our very latest, small sized executable files and let them do their job<br /><br /><strong>58.65.239.42/jdk7dx/ inst250.exe</strong><br /><strong>58.65.239.42/jdk7dx/ alexey.exe</strong><br /><strong>58.65.239.42/jdk7dx/ 6.exe</strong><br /><strong>58.65.239.42/jdk7dx/ 1103.exe</strong><br /><strong>58.65.239.42/jdk7dx/ eagle.exe</strong><br /><strong>58.65.239.42/jdk7dx/ krab.exe</strong><br /><strong>58.65.239.42/jdk7dx/ win32.exe</strong><br /><strong>58.65.239.42/jdk7dx/ pinch.exe</strong><br /><strong>58.65.239.42/jdk7dx/ ldig0031242.exe</strong><br /><strong>58.65.239.42/jdk7dx/ 64.exe</strong><br /><strong>58.65.239.42/jdk7dx/ system.exe</strong><br /><strong>58.65.239.42/jdk7dx/ bhos.exe</strong><br /><strong>58.65.239.42/jdk7dx/ bho.exe</strong><br /><br />- Once you've executed them, make sure you initiate an E-banking transaction right way. Do not worry, you don't to give us your banking details for the donation, we already have them, and will equally distribute your income by meeting our financial objectives<br /><br />- Now that you're done transfering money, authenticate yourself at each every web service that you've ever been using. Trust is vital, and so that we've trusted you by providing you with our latest small sized executable files, it's your turn to trust us when asking you to do so<br /><br />- Don't forget to plug-in any kind of writeble removable media once you've executed the files above as well, as we'd really like to deepen our relationship by storing them, and having them automatically execute themselves the next time you plug-in your removable media<br /><br />- Sharing is what drives our business. Just like the way we've shared and trusted with by providing you with direct links to our executables, in exchange we know you wouldn't mind sharing some of that free hard disk space you have for our own distributed hosting purposes<br /><br /><strong>Stop hating and start participating, join our botnet TODAY! Don't forget, diamonds degrade their quality, hosting services courtesy of the RBN are forever!</strong><br /><br />Sincerely yours,<br />"HostFresh" - RBN's Hong Kong subsidiary<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ueGn6wG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ueGn6wG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wqZpMEG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wqZpMEG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2cLodg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2cLodg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WQEdo6g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WQEdo6g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1y4CHjG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1y4CHjG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qctlNeG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qctlNeG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Gl6h5Ig"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Gl6h5Ig" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/262207220" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 11:52:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/42jdk7dx">42jdk7dx</category>
      <category domain="http://securityratty.com/tag/42jdk7dx pinch">42jdk7dx pinch</category>
      <category domain="http://securityratty.com/tag/42jdk7dx system">42jdk7dx system</category>
      <category domain="http://securityratty.com/tag/42jdk7dx ldig0031242">42jdk7dx ldig0031242</category>
      <category domain="http://securityratty.com/tag/42jdk7dx inst250">42jdk7dx inst250</category>
      <category domain="http://securityratty.com/tag/42jdk7dx bhos">42jdk7dx bhos</category>
      <category domain="http://securityratty.com/tag/42jdk7dx win32">42jdk7dx win32</category>
      <category domain="http://securityratty.com/tag/exe">exe</category>
      <category domain="http://securityratty.com/tag/42jdk7dx bho">42jdk7dx bho</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/262207220/hacked-by-rbn.html">HACKED BY THE RBN!</source>
    </item>
    <item>
      <title><![CDATA[Training People on Threat Modeling]]></title>
      <link>http://securityratty.com/article/22e699a62f930079d83cb9548ad0b3f7</link>
      <guid>http://securityratty.com/article/22e699a62f930079d83cb9548ad0b3f7</guid>
      <description><![CDATA[Adam Shostack here. Blogger Ian Grigg has an interesting response to my threat modeling blog series, and I wanted to respond to it. In particular, Ian says I then would prefer to see the threat -...]]></description>
      <content:encoded><![CDATA[<p>&#160;</p>  <p>Adam Shostack here. Blogger Ian Grigg has an interesting <a href="https://financialcryptography.com/mt/archives/001013.html">response</a> to my threat modeling blog series, and I wanted to respond to it. In particular, Ian says &#8220;I then would prefer to see the threat - property matrix this way:&#8221; </p>  <p>I wanted to share an additional table from our training, and talk about repudiation a bit more. </p>  <p>Actually, I&#8217;d like to repudiate the term &#8220;repudiation.&#8221; It&#8217;s an awful name that most people never run into in day-to-day life. It doesn&#8217;t hit the simplification bar the way say, &#8220;denial,&#8221; would. Unfortunately, STDIDE (Spoofing, Tampering, Denial, Information Disclosure, Denial of Service, Elevation of Privilege) doesn&#8217;t make a very memorable acronym. Memorable is important when training people. Our reviewers have raised this as an issue, and &#8217;d love to get feedback from our readers. How can we ensure that the software we build has the right level of logging and audit-ability? What evocative words can we use, and can you help us come up with a word or phrase that starts with R? Let us know! </p>  <p>And then, here&#8217;s the chart:</p>  <table cellspacing="0" cellpadding="2" width="400" border="0"><tbody>     <tr>       <td valign="top" width="100">Threat</td>        <td valign="top" width="100">Property</td>        <td valign="top" width="100">Definition</td>        <td valign="top" width="100">Example</td>     </tr>      <tr>       <td valign="top" width="100"><b>Spoofing</b></td>        <td valign="top" width="100">Authentication</td>        <td valign="top" width="100">Impersonating something or someone else.</td>        <td valign="top" width="100">Pretending to be any of billg, microsoft.com or ntdll.dll</td>     </tr>      <tr>       <td valign="top" width="100"><b>T</b>ampering</td>        <td valign="top" width="100">Integrity</td>        <td valign="top" width="100">Modifying data or code</td>        <td valign="top" width="100">Modifying a DLL on disk or DVD, or a packet as it traverses the LAN.</td>     </tr>      <tr>       <td valign="top" width="100"><b>R</b>epudiation</td>        <td valign="top" width="100">Non-repudiation</td>        <td valign="top" width="100">Claiming to have not performed an action.</td>        <td valign="top" width="100">&#8220;I didn&#8217;t send that email,&#8221; &#8220;I didn&#8217;t modify that file,&#8221; &#8220;I <i>certainly</i> didn&#8217;t visit that web site, dear!&#8221;</td>     </tr>      <tr>       <td valign="top" width="100"><b>I</b>nformation Disclosure</td>        <td valign="top" width="100">Confidentiality</td>        <td valign="top" width="100">Exposing information to someone not authorized to see it</td>        <td valign="top" width="100">Allowing someone to read the Windows source code; publishing a list of customers to a web site.</td>     </tr>      <tr>       <td valign="top" width="100"><b>D</b>enial of Service</td>        <td valign="top" width="100">Availability</td>        <td valign="top" width="100">Deny or degrade service to users</td>        <td valign="top" width="100">Crashing Windows or a web site, sending a packet and absorbing seconds of CPU time, or routing packets into a black hole.</td>     </tr>      <tr>       <td valign="top" width="100"><b>E</b>levation of Privilege</td>        <td valign="top" width="100">Authorization</td>        <td valign="top" width="100">Gain capabilities without proper authorization</td>        <td valign="top" width="100">Allowing a remote internet user to run commands is the classic example, but going from a limited user to admin is also EoP.</td>     </tr>   </tbody></table>  <p>&#160;</p>  <p>(Ian&#8217;s post is here <a href="https://financialcryptography.com/mt/archives/001013.html">https://financialcryptography.com/mt/archives/001013.html</a> . IE users will see a warning about certificate authorities when visiting this site.&#160; As I wrote this, Gunnar Peterson added commentary at &quot;<a href="http://1raindrop.typepad.com/1_raindrop/2008/03/threats-mechani.html">Threats, Mechanisms and Standards</a>.&quot;)</p><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8212656" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 14 Mar 2008 20:11:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows source code">windows source code</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/degrade service">degrade service</category>
      <category domain="http://securityratty.com/tag/non-repudiation">non-repudiation</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/03/14/training-people-on-threat-modeling.aspx">Training People on Threat Modeling</source>
    </item>
    <item>
      <title><![CDATA[TSA's Ideal Laptop Bag]]></title>
      <link>http://securityratty.com/article/9398c6447466b4779713e04a333f1813</link>
      <guid>http://securityratty.com/article/9398c6447466b4779713e04a333f1813</guid>
      <description><![CDATA[This seems not to be a joke. The Transportation Security Administration is interested in evaluating -- and eventually approving - the design of certain laptop bags, so travelers would be permitted to...]]></description>
      <content:encoded><![CDATA[<p><a href="http://gsnmagazine.com/cms/features/news-analysis/542.html">This</a> seems not to be a joke.</p>

<blockquote>The Transportation Security Administration is interested in evaluating -- and eventually approving –- the design of certain laptop bags, so travelers would be permitted to pass through security checkpoints without having to remove their laptops.

<p>[...]</p>

<p>To accomplish this, the TSA RFI pointed out that the laptop bag would need to meet the following requirements: </p>

<ul><li>The carrying bag cannot exceed any one of the proposed dimensions – 16 inches in height, 24 inches wide and 36 inches long. 

<p><li>The materials that make up the bag cannot degrade the quality of the X-ray image of the laptop. </p>

<p><li>No straps, pockets, zippers, handles or closures of the bag can interfere with the image of the laptop. </p>

<p><li>No electronics, chargers, batteries, wires, paper products, pens or other contents of the bag can shield the image of the laptop.</ul></p>

<p>TSA is inviting bag designers and manufacturers to come up with creative ways to meet these design requirements, but it has also suggested three concepts of its own: </p>

<ul><li>A bag that would open completely, and lie horizontally on the X-ray belt, such that one side with hold only the laptop. 

<p><li>A bag that would open completely, leaving the laptop standing vertically, supported by clips. </p>

<p><li>A bag that would pull apart in separate compartments, with one compartment containing only the laptop.</ul></blockquote></p>

<p>Doesn't sound like a particularly useful laptop bag.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=QR8y1yF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=QR8y1yF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Q901qzF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Q901qzF" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 07 Mar 2008 07:42:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/laptop bag">laptop bag</category>
      <category domain="http://securityratty.com/tag/bag">bag</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/bag designers">bag designers</category>
      <category domain="http://securityratty.com/tag/laptop bags">laptop bags</category>
      <category domain="http://securityratty.com/tag/tsa">tsa</category>
      <category domain="http://securityratty.com/tag/inches">inches</category>
      <category domain="http://securityratty.com/tag/inches wide">inches wide</category>
      <category domain="http://securityratty.com/tag/x-ray image">x-ray image</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/tsas_ideal_lapt.html">TSA's Ideal Laptop Bag</source>
    </item>
    <item>
      <title><![CDATA[STRIDE chart]]></title>
      <link>http://securityratty.com/article/96a819221c5280509ecb41c2d92d2eac</link>
      <guid>http://securityratty.com/article/96a819221c5280509ecb41c2d92d2eac</guid>
      <description><![CDATA[Adam Shostack here

I've been meaning to talk more about what I actually do, which is help the teams within Microsoft who are threat modeling (for our boxed software) to do their jobs better. Better...]]></description>
      <content:encoded><![CDATA[<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">Adam Shostack here.</SPAN></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT face=calibri size=3>&nbsp;</FONT></o:p></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">I've been meaning to talk more about what I actually do, which is help the teams within Microsoft who are threat modeling (for our boxed software) to do their jobs better.&nbsp; Better means faster, cheaper or more effectively.&nbsp; <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">There are good reasons to optimize for different points on that spectrum (of better/faster/cheaper) <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">at different times in different products.&nbsp;&nbsp; <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">One of the things that I've learned is that we ask a lot of developers, testers, and PMs here.&nbsp; They all have some exposure to security, but terms that I've been using for years are often new to them.</SPAN></SPAN></SPAN></SPAN></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">Larry Osterman is a <A class="" title="longtime MS veteran" href="http://channel9.msdn.com/ShowPost.aspx?PostID=27667" mce_href="http://channel9.msdn.com/ShowPost.aspx?PostID=27667">longtime MS veteran</A>, currently working in Windows audio.&nbsp; He's been a threat modeling advocate for years, and <SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">has been blogging a lot about our new processes, and describes in great detail the STRIDE per element process.&nbsp;&nbsp; His recent posts are "<A href="http://blogs.msdn.com/larryosterman/archive/2007/08/30/threat-modeling-once-again.aspx" mce_href="http://blogs.msdn.com/larryosterman/archive/2007/08/30/threat-modeling-once-again.aspx">Threat Modeling, Once Again</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/08/31/threat-modeling-again-drawing-the-diagram.aspx">Threat modeling again. Drawing the diagram</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/04/threat-modeling-again-stride.aspx">Threat Modeling Again: STRIDE</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/05/threat-modeling-again-stride-mitigations.aspx">Threat modeling again, STRIDE mitigations</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/07/threat-modeling-again-what-does-stride-have-to-do-with-threat-modeling.aspx">Threat modeling again, what does STRIDE have to do with threat modeling</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/10/threat-modeling-again-stride-per-element.aspx">Threat modeling again, STRIDE per element</A>," "<A href="http://blogs.msdn.com/larryosterman/archive/2007/09/11/threat-modeling-again-threat-modeling-playsound.aspx">Threat modeling again, threat modeling playsound</A>."</SPAN></SPAN></SPAN></SPAN></SPAN></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">I wanted to chime in and offer up this handy chart that we use.&nbsp; It's part of how we teach people to go from a diagram to a set of threats.&nbsp; We used to ask them to brainstorm, and have discovered that that works a lot better with some structure.</SPAN></SPAN></SPAN></SPAN></SPAN></P>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><o:p><FONT face=calibri size=3></FONT></o:p>&nbsp;</P>
<P>
<TABLE class=MsoNormalTable style="BORDER-COLLAPSE: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in" cellSpacing=0 cellPadding=0 border=0 class="MsoNormalTable">
<TBODY>
<TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Property </FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Threat </FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Definition </FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 0.1in; BORDER-TOP: white 1pt solid; PADDING-LEFT: 0.1in; BACKGROUND: #4f81bd; PADDING-BOTTOM: 0.05in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.05in; BORDER-BOTTOM: white 3pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Example </FONT></P></TD></TR>
<TR style="mso-yfti-irow: 1">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Authentication</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>S</B>poofing</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri>Impersonating something or someone else. </FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri>Pretending to be any of billg, microsoft.com or ntdll.dll </FONT></FONT></P></TD></TR>
<TR style="mso-yfti-irow: 2">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Integrity</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>T</B>ampering</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Modifying data or code</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Modifying a DLL on disk or DVD, or a packet as it traverses the LAN.</FONT></P></TD></TR>
<TR style="mso-yfti-irow: 3">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Non-repudiation</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>R</B>epudiation</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Claiming to have not performed an action.</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>“I didn’t send that email,” “I didn’t modify that file,” “I <I>certainly</I> didn’t visit that web site, dear!”</FONT></P></TD></TR>
<TR style="mso-yfti-irow: 4">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Confidentiality</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>I</B>nformation Disclosure</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Exposing information to someone not authorized to see it</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Allowing someone to read the Windows source code; publishing a list of customers to a web site.</FONT></P></TD></TR>
<TR style="HEIGHT: 69.8pt; mso-yfti-irow: 5">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Availability</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>D</B>enial of Service</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Deny or degrade service to users</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #d0d8e8; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Crashing Windows or a web site, sending a packet and absorbing seconds of CPU time, or routing packets into a black hole.</FONT></P></TD></TR>
<TR style="HEIGHT: 55.45pt; mso-yfti-irow: 6; mso-yfti-lastrow: yes">
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: white 1pt solid; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=189>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Authorization</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BORDER-LEFT-COLOR: #f0f0f0; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-BOTTOM: white 1pt solid" vAlign=top width=147>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=calibri><B>E</B>levation of Privilege</FONT></FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=197>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Gain capabilities without proper authorization</FONT></P></TD>
<TD class="" style="BORDER-RIGHT: white 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #f0f0f0; PADDING-LEFT: 5.4pt; BACKGROUND: #e9edf4; PADDING-BOTTOM: 0in; BORDER-LEFT: #f0f0f0; PADDING-TOP: 0.75pt; BORDER-BOTTOM: white 1pt solid" vAlign=top width=395>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><FONT face=calibri size=3>Allowing a remote internet user to run commands is the classic example, but going from a limited user to admin is also EoP.</FONT></P></TD></TR></TBODY></TABLE></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><o:p><FONT face=calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><o:p><FONT size=3></FONT></o:p>&nbsp;</P>
<P class=MsoPlainText style="MARGIN: 0in 0in 0pt"><o:p><FONT face=calibri size=3>[Update: fixed the table so it displays&nbsp;all four columns.]&nbsp;</FONT></o:p></P></SPAN></SPAN></SPAN></SPAN></SPAN>
<P><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"></SPAN></SPAN></SPAN></SPAN></SPAN><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"><SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: 'Calibri','sans-serif'; mso-fareast-font-family: Calibri; mso-bidi-font-family: 'Times New Roman'; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA">&nbsp;</P></SPAN></SPAN></SPAN></SPAN></SPAN><img src="http://blogs.msdn.com/aggbug.aspx?PostID=4872732" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 11 Sep 2007 19:18:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <category domain="http://securityratty.com/tag/stride">stride</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows source code">windows source code</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/stride mitigations">stride mitigations</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/remote internet user">remote internet user</category>
      <source url="http://blogs.msdn.com/sdl/archive/2007/09/11/stride-chart.aspx">STRIDE chart</source>
    </item>
  </channel>
</rss>
