<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: real]]></title>
    <link>http://securityratty.com/tag/real</link>
    <description></description>
    <pubDate>Tue, 30 Sep 2008 13:23:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Why Risk Management Doesnt Work (?!)]]></title>
      <link>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</link>
      <guid>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</guid>
      <description><![CDATA[Several folks (Hi Daniel , Brent , David !) sent email &amp; twitters asking us our opinion on a Dark Reading article called Why Risk Management Doesnt Work which if you click on the link should come up...]]></description>
      <content:encoded><![CDATA[<p>Several folks (Hi <a href="http://dmiessler.com/">Daniel</a>, <a href="http://stateofsecurity.com/">Brent</a>, <a href="http://www.twitter.com/debix">David</a>!) sent email &amp; twitters asking us our opinion on a Dark Reading article called &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=165107">Why Risk Management Doesn&#8217;t Work</a>&#8221; which if you click on the link should come up for you after seeing someone&#8217;s advertisement for a few seconds.</p>
<p>I&#8217;m assuming the author wants us to read the title as <strong>&#8220;Things to Look Out For in Performing Risk Analysis&#8221;</strong> and not <strong>&#8220;Risk Management is Folly - Stop, Stop, Stop!&#8221;</strong> The former is fine, the latter isn&#8217;t supported by the evidence presented by the subjects of the article.<br />
The subjects of the article are a <strong><a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">good study from Wade Baker &amp; Co. at Verizon</a></strong>, and a report from RSA&#8217;s Security for Business Innovation Council. Let&#8217;s take a look at each of these and examine why what they&#8217;re saying might contribute to poor risk management, shall we?</p>
<p><strong>1.)  THE VERIZON REPORT</strong></p>
<p>The Verizon report is an analysis of some 530 forensic investigations their company performed.  It is well worth your time as it&#8217;s chock full of interesting information.  As it relates to the Dark Reading piece, a coarse summary would be that &#8220;likelihood&#8221; is &#8220;different&#8221; for different people and so you can&#8217;t use the same &#8220;likelihood&#8221; across different industries.</p>
<p>Distilled through the lens of FAIR:</p>
<blockquote><p>&#8220;different threat communities may be applicable based on Probability of Action factors which include: Value, Level of Effort and Risk (of Getting Caught).&#8221;</p></blockquote>
<p>Or, even further distilled and in the words of my six year old son,</p>
<blockquote><p>&#8220;Duh-uh&#8221;.</p></blockquote>
<p>With regards to what I assume is the purpose of the article (What Doesn&#8217;t Work in Risk Analysis) this concept  seems just to rehash the old GIGO argument regarding risk analysis.  Great.  Can&#8217;t argue with that, nor it&#8217;s corollary QIQO (quality in, quality out).</p>
<p>But let me ask you -  <strong><em>is this really a problem common in your analysis</em></strong>?  Did reading this article make you go &#8220;Crap, we&#8217;ve been using data normalized across multiple industries in our analysis! They&#8217;re all wrong!&#8221;  Or have you already been accounting for the unique value proposition your company has to the specific threat community you&#8217;re worried about?  See, maybe I&#8217;m just not your average analyst, but even in my NIST/OCTAVE days, this has *never* been an issue for me.</p>
<p>Let me be specific, this is not a problem with Verizon&#8217;s very cool report.  It&#8217;s just that I don&#8217;t see what the big deal is.  This article is starting to feel like someone is running through the motions, trying to play the &#8221; a crazy title gets people to read a boring article&#8221; game.</p>
<p>Speaking of cool reports - You know what would be cool?  I think it would be interesting to see is the quality of these companies&#8217; &#8220;risk management process&#8221; established using good criteria,  and then correlated to the frequency and magnitude of real-world losses across the aggregate sample.  In other words, can we establish evidence that strong risk management practices not just reduce &#8220;risk&#8221; but also reduce actual incidents.</p>
<p><strong>2.)  THE RSA COUNCIL &#8220;EXPLORES WHY LEGACY METHODS OF EVALUATING INFORMATION SECURITY RISK DON&#8217;T WORK IN TODAY&#8217;S CONNECTED WORLD, IN WHICH ANY NEW BUSINESS INNOVATION INHERENTLY CARRIES SOME LEVEL OF RISK TO INFORMATION.&#8221;</strong></p>
<p>This report from the RSA council puts forth a seemingly obvious proposition, that risk must be balanced by reward.  Why is this news?  Now as I read the article it&#8217;s not clear if:</p>
<ul>
<li>The RSA Council is claiming that the CISO&#8217;s office should be the ones determining reward.  Absurd.</li>
</ul>
<p>or</p>
<ul>
<li>Businesses aren&#8217;t doing a good job at determining risk and reward.</li>
</ul>
<p>Let&#8217;s go with the latter.  So I&#8217;m pretty sure (good) businesses do a good job at estimating reward.  Businesses I&#8217;ve been a part of?  We LOVE(D) estimating reward.  We don&#8217;t tend to start projects all willy-nilly. No we tend to be careful to identify the size of the market and what it will cost to address the market.  So what could the problem be that this RSA council is trying to address?  Maybe it has to do with something like the following:</p>
<p>Yesterday, I got a demo of an IT-GRC application that shall remain nameless.  It seemed to be very good at the &#8220;C&#8221; bits - lots of information on regulations and expectations and even what sorts of controls would answer the regulations (which is goofy, but we&#8217;ll have to talk about that later).  It also gave you the ability to build workflow quite nicely.  But it measured NOTHING.  There really was no observable &#8220;G&#8221; and &#8220;R&#8221; was really Medium X Low X Low = High sorts of stuff.  So let&#8217;s use this relatively expensive tool as evidence of what your average CISO is armed with going into a Risk/Reward sort of meeting.  I imagine a nice board room with wood-grain paneling and glass bowls filled with little chocolate covered mints designed to give everyone involved in the meeting (CEO, CFO, CIO, CSO, VP S&amp;M, etc&#8230;) a little sugar rush when needed and fresh breath.  The conversation goes a little something like this (apologies to <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich</a></strong>):</p>
<blockquote><p><em><strong>Business Guy Who Wants to Make Money Because That&#8217;s What Businesses Do:</strong></em> Based on market studies, we believe that initial gross revenues from the new product and technology rollout will be eleventy gazillion dollars based on a 37% market penetration in Scandinavia, alone.</p>
<p><em><strong>CSO: </strong></em> Well now, we have a likelihood of &#8220;High&#8221; and a &#8220;C&#8221; impact of Medium, and an &#8220;I&#8221; impact of Low, and an &#8220;A&#8221; impact of &#8220;High&#8221; and because we are a (bank/hospital/retailer/basically any business that breathes anymore) we weight &#8220;C&#8221; by a factor of 2 - we multiplied those all together and got a &#8220;High&#8221;.</p>
<p>So can you guys delay the product rollout by 9 months and give me a bunch more money that&#8217;s not in the budget so that I can get this thing down to a &#8220;Medium&#8221;, please?</p></blockquote>
<p>Again, I just don&#8217;t see the problem with Information Risk Management being that our businesses have no idea what the rewards of business might be.  Now maybe we need get a seat in that boardroom just to be able to talk about our &#8220;Mediums&#8221;, sure.  And maybe we&#8217;re infantile in our ability to describe our problem space.  But I cannot fathom that &#8220;<em>Risk Management Doesn&#8217;t Work</em>&#8221; because businesses haven&#8217;t been considering &#8220;reward&#8221;.</p>
<p><strong>WHY RISK MANAGEMENT MAY  NOT BE WORKIN&#8217; FOR YOU</strong></p>
<p>Two meta-categories of causation:</p>
<ul>
<li>No skills</li>
</ul>
<p>and/or</p>
<ul>
<li>No resources</li>
</ul>
<p>Any ancillary &#8220;cause&#8221; can be mapped to one of these categories.  You could have significant resources but crappy models, and have conversations like our imaginary CSO, above.  You could have really good models and people trained and motivated to use them, but scarce time &amp; money, so no conversation happens.</p>
<p>Now my question for you is - which does it make sense to acquire *first* to solve the &#8220;<em>Why Risk Management Doesn&#8217;t Work</em>&#8221; problems, skills or resources?</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 13:15:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/information security risk">information security risk</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/cool report">cool report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=459">Why Risk Management Doesnt Work (?!)</source>
    </item>
    <item>
      <title><![CDATA[MSP Snapshot Monitoring with EM7]]></title>
      <link>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</link>
      <guid>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</guid>
      <description><![CDATA[Between the fifth anniversary for ScienceLogic and the Inc 500 milestone, weve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally...]]></description>
      <content:encoded><![CDATA[<p>Between the <a href="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008" target="_blank">fifth anniversary for ScienceLogic</a> and the Inc 500 milestone, we’ve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally designed with managed service providers in mind? Not so surprising when 5 of the first 6 employees (including all 3 founders) came from hosting and MSP backgrounds and had first-hand experience with the daily trials and tribulations of MSP operations – and the tools that didn’t quite work for them.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="John at Interop Vegas" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas-thumb.jpg" width="244" align="left" border="0"></a>Here we talk to John Proctor, who started out as one of our first customers (and the first MSP customer). And he believed in it so much, he eventually became part of the ScienceLogic team. (Remember &#8220;I&#8217;m not only the President, I&#8217;m also a client&#8221; from <a href="http://www.hairclub.com/inthenews_article1.php" target="_blank">the Hair Club for Men</a>?)
<p>John shares his perspectives about the service provider world and why he took a chance on a little-known product called EM7.
<p><strong>ScienceLogic:</strong> What is your background? How many years have you worked as a service provider and for what types of companies?
<p><strong>John Proctor:</strong> I have been working with Service providers for over twelve years. I worked at a major regional service provider for six years and before that I designed and built national and international networks for ISP’s and Fortune 500 companies as a consultant for PriceWaterhouseCoopers and WorldComm.
<p><strong>ScienceLogic:</strong> You were one of the first customers of EM7 – why did you choose it and how did you get over the hurdles associated with using a start-up company’s product?
<p><strong>John Proctor:</strong> We were actually customer number five. Back in 2004 when we evaluated and purchased EM7 we could see that EM7 provided about 80% of what we were looking for in one integrated solution right out of the box. One of the things that sold us on EM7 was that the ScienceLogic founders had all previously worked for a service provider, so we knew they understood our business and our challenges. But in the end, it comes down to features. Once we compared EM7 functionality to the alternatives, it was clearly a “no brainer.”
<p><strong>ScienceLogic:</strong> What other alternatives were being considered?
<p><strong>John Proctor:</strong> Well, we had started with a few point solutions, but as our business and product offerings matured, this resulted in a growing number of point solutions. What started with 3 or 4 ended up as 14 separate tools. They all had strengths but what they didn’t have was integration and because of this they could not scale. And, if the tools could not scale, our business could not grow.
<p>So, naturally we started looking at framework solutions, but they are expensive to buy, expensive to implement, and expensive to maintain. At one point, we even considered some open source projects. There were several that showed promise, but we would still be stuck with tools that were not integrated. So then we considered hiring developers to cobble something together that would work for our business. The only problem with this alternative was that we felt it would take 6 to 8 months before we could have something viable to work with.
<p><strong>ScienceLogic:</strong> What products were you using before EM7? What were your goals?
<p><strong>John Proctor:</strong> Before we purchased EM7 we used 14 different point solutions to deliver our products and services to the marketplace. Tools like NetCool, Openview, Argent, Heat, What’s Up Gold as well as several other point solutions, vendor specific applications and manually updated spreadsheets. And, as I mentioned before, this does not scale. This also adds a great deal of complexity when you begin to consider business continuity and disaster recovery. All these tools were vital to the delivery of our products and services. Any service provider will tell you it is all about uptime. So if the product is uptime, the tools used to deliver it have to be available 24&#215;7x365.
<p>Our goals were simple: scale and redundancy. As it turns out, the solution was simple as well. EM7 provided a tool that could replace the functionality of almost half of the existing point solutions and the applications that could not be replaced were integrated with EM7 to provide our staff with a “single pane of glass” to see the status and performance of each area of the business from one application. We had visibility into everything from facility systems to applications using EM7.
<p>ScienceLogic also delivers an extensible configuration that addressed uptime and redundancy. We deployed collectors throughout our network that reported back to a central pair of redundant database servers and with this configuration we were able to perform backups and add capacity without taking the system down.
<p><strong>ScienceLogic:</strong> Why are service providers different from enterprises? How are their needs different?
<p><strong>John Proctor:</strong> First and foremost, service providers face the same challenges that only the largest enterprises ever face and they also have many unique challenges that only service providers experience.
<p>One challenge we faced was that we had multiple datacenters in different states. They were all interconnected with plenty of bandwidth between each site, but the tools were not designed to be used across the WAN. Our staff in our remote data center did not have the same access as our staff in the corporate office. Since EM7 is web-based, it immediately eliminated this problem.
<p>Another challenge is that service providers must manage systems across multiple domains. Back in the early version of a specific tool we were using before EM7, the only way you could implement it across multiple domains was to put the same username and password on every computer that you monitored. Beyond the security concerns, maintenance was a nightmare. Anytime we had to change the password, we would get locked out of dozens upon dozens of systems. When the password was changed on the monitoring server, it would attempt to login to the remote machines and fail. Repeated attempts would result in the account getting locked. I think that vendor eventually addressed this issue, but service providers seldom find tools that were designed for their unique situations.
<p><strong>ScienceLogic:</strong> How is EM7 geared to service providers?
<p><strong>John Proctor:</strong> Enterprise IT is a trusted part of the business; they are one of the team. Service providers are outsiders that must earn trust by showing the customer exactly what they are doing.
<p>EM7 provides a multi-tenant environment that allows service providers to manage systems across many different customers while at the same time providing the customer access to see the same information but only what’s relevant to them.
<p>EM7 was built by service providers and even includes a few features just for them. Two of my favorites are bandwidth billing and the emergency notification system. Take bandwidth billing, for instance. EM7 provides a way to collect bandwidth utilization, store subscription information, and calculate a bill from any one of about 10 different methodologies. And at the end of the billing period, EM7 sends the completed report out to whomever you chose via email.
<p>Another unique service provider feature is the emergency notification system. EM7 allows the provider to track what customers used their unique infrastructure components. If they have to perform maintenance on the infrastructure component or have a problem they can send an email to all of the impacted customers in a matter of minutes.
<p><strong>ScienceLogic:</strong> What trends do you see for service providers? What about big trends such as virtualization and cloud computing – how will they impact service providers?
<p><strong>John Proctor:</strong> Virtualization is really hot for service providers right now and for the same reasons as in the enterprise. Service providers run data centers and data centers must be powered and cooled. So, anytime they can use a virtual server instead of adding physical equipment it is a good thing. But then you add the complexity that multiple customers reside on the same host and you must track things like bandwidth utilizations by guest OS, and it all gets a little harder. Lucky for us this is not a problem for EM7.
<p>I still think it’s early days for cloud computing. Depending on who you talk to, much of what service providers (especially the big ones) have already been doing with SAAS offerings and hosted applications could be described as cloud computing already. In which case, service providers are ahead of the game. But whatever the “final” definition, cloud computing actually shares many similarities with virtualization – in that service providers (or enterprises) will need to be able to manage far more “devices” in real-time with “zero downtime” expectations by customers. What this really means is that you’re going to see much more automation in provisioning and IT monitoring tools to handle the scale and speed with which things can change in the data center given vm migration and the talked-about switching between “clouds” that can be used for high availability. </p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:51:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service providers experience">service providers experience</category>
      <category domain="http://securityratty.com/tag/service providers seldom">service providers seldom</category>
      <category domain="http://securityratty.com/tag/impact service providers">impact service providers</category>
      <category domain="http://securityratty.com/tag/em7 functionality">em7 functionality</category>
      <category domain="http://securityratty.com/tag/em7 sends">em7 sends</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider world">service provider world</category>
      <source url="http://blog.sciencelogic.com/msp-snapshot-monitoring-with-em7/10/2008">MSP Snapshot Monitoring with EM7</source>
    </item>
    <item>
      <title><![CDATA[A Life or Death InfoSec Subversion]]></title>
      <link>http://securityratty.com/article/ce84889e3d8b870803c3f3d97330cfdd</link>
      <guid>http://securityratty.com/article/ce84889e3d8b870803c3f3d97330cfdd</guid>
      <description><![CDATA[Details about failures of complex and well-implemented information-based attacks on systems are extremely difficult to obtain. However, here the authors examine a real-life analoguean information...]]></description>
      <content:encoded><![CDATA[Details about failures of complex and well-implemented information-based attacks on systems are extremely difficult to obtain. However, here the authors examine a real-life analogue—an information attack on a highly complex security system, that of the Colombian guerrilla group FARC. This operation included a man-in-the-middle attack, targeted denial of service (DoS), and authentication subversion. The attack on FARC's communications structure is interesting not only because of its electronic and analog components, but also because it was a life or death matter. The authors examine the hostages' liberation from an information security perspective, compiling data from several Colombian newspapers and magazines and using the most accepted version of the events.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=344380c94465538d8840535190445e21"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=344380c94465538d8840535190445e21"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=344380c94465538d8840535190445e21" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/authors examine">authors examine</category>
      <category domain="http://securityratty.com/tag/information security perspective">information security perspective</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/communications structure">communications structure</category>
      <category domain="http://securityratty.com/tag/death matter">death matter</category>
      <category domain="http://securityratty.com/tag/colombian guerrilla">colombian guerrilla</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/colombian newspapers">colombian newspapers</category>
      <category domain="http://securityratty.com/tag/extremely difficult">extremely difficult</category>
      <source url="http://www.pheedo.com/click.phdo?i=344380c94465538d8840535190445e21">A Life or Death InfoSec Subversion</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[The Results Are In: Real Savings with Deploying Global Telepresence & Multimedia Services]]></title>
      <link>http://securityratty.com/article/a70543fdfebfecce1ea619cd5382c0ae</link>
      <guid>http://securityratty.com/article/a70543fdfebfecce1ea619cd5382c0ae</guid>
      <description><![CDATA[WHEN: Thursday, October 30th10 AM PT / 1 PM ET Join us today!SPONSORED BY: Nortel-PolycomJoin this FREE webinar to see how leading enterprises are effectively deploying global Telepresence to...]]></description>
      <content:encoded><![CDATA[WHEN: Thursday, October 30th10 AM PT / 1 PM ET Join us today!SPONSORED BY: Nortel-PolycomJoin this FREE webinar to see how leading enterprises are effectively deploying global Telepresence to communi...]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 08:42:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/global telepresence">global telepresence</category>
      <category domain="http://securityratty.com/tag/october 30th10">october 30th10</category>
      <category domain="http://securityratty.com/tag/free webinar">free webinar</category>
      <category domain="http://securityratty.com/tag/communi">communi</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://securityratty.com/tag/effectively">effectively</category>
      <category domain="http://securityratty.com/tag/join">join</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/413124564/">The Results Are In: Real Savings with Deploying Global Telepresence &amp; Multimedia Services</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.3.08]]></title>
      <link>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</link>
      <guid>http://securityratty.com/article/bfa12b1f280cc26f4ffcd92a791acc11</guid>
      <description><![CDATA[Well finally, an upside to the financial crisis more students in computer science. After the dot-com crash, enrollment went down in computer science, almost 50% since 2003. Many students shifted their...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/africa-map.jpg" border="0" alt="africa-map" width="204" height="240" align="left" /> Well finally, an upside to the financial crisis – more students in computer science. After the dot-com crash, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9066659" target="_blank">enrollment went down</a> in computer science, almost 50% since 2003. Many students <a href="http://www.washingtontechnology.com/online/1_1/33584-1.html" target="_blank">shifted their interest from the technology field</a> to banking and finance because they thought they’d make more money. And now the financial crisis could scare them into <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115616&amp;source=rss_news" target="_blank">choosing majors and careers that are “safer alternatives”</a>, like IT. And perhaps the trend is reversing for those already on Wall Street as well. Ben Worthen writes about the influx of resumes Kodiak Venture Partners has been getting: <a href="http://blogs.wsj.com/biztech/?s=wall+street+jobs" target="_blank">from financial-services vets who want to work at tech startups</a>, – not to “strike it rich” this time around, but just to make a living. And it’s not just the tech workers. Seems like the ones that don’t even have any real IT experience are looking too – for jobs as VPs of marketing (harrumph). (<a href="http://www.fas.org/irp/imint/docs/rst/Sect6/africa-map.jpg" target="_blank"><em>img from www.fas.org</em></a>)</p>
<p>I’m sure you already know about the other “network management” – where ISPs and carriers get their hands publicly slapped for limiting bandwidth to high-traffic offenders. But when is this kind of “network management” a good thing? At a panel sponsored by the FCC in DC, reps from carriers and ISPs discussed what steps they’ve been taking <a href="http://www.networkworld.com/news/2008/091808-telcos-pandemic.html?hpg1=bn" target="_blank">to prepare for a pandemic</a> or other major global crisis – that would force workers to stay at home or work from more remote locations to limit exposure.</p>
<p>Are people paying attention to ICANN? They’re saying that IPv4 will be fully <a href="http://blog.icann.org/?p=365" target="_blank">allocated in the next two or three years</a>. Does anyone care? In their bid to make people care, ICANN talks about the state of IPv6 adoption and <a href="http://www.thestandard.com/news/2008/09/30/africa-faster-adopting-ipv6-according-icann">touts Africa as the most rapid adopter</a>.</p>
<p><a href="http://blogs.zdnet.com/service-oriented/?p=1187" target="_blank">SOA soon part of the ‘cloud’</a>? No, please no.</p>
<p>Microsoft – The Silver Lining in Every Cloud. Joe Wilcox over at eWeek’s Microsoft Watch, has been <a href="http://www.microsoft-watch.com/content/corporate/steve_ballmer_sure_has_lots_to_say.html?kc=EWWHNEMNL10022008STR4" target="_blank">following Steve Ballmer</a> around and collecting some nice quotes on how the company is transitioning. “For many years, we had kind of what I would call the all-encompassing mission, vision and scorecard statement: a computer on every desk and in every home. …Well, our footprint and portfolio is broader than that. “ [In every hand and of course, in every cloud…] “So, as a vision statement we talk about creating seamless experiences that combine the magic of software, the power of the Internet across a world of devices.” The magic of software – something I haven’t thought about for a while. And:</p>
<blockquote><p>&#8220;You need a real platform in the cloud. When we wanted to go after the PC, we built an operating system. When we wanted to go after the phone, we built an operating system. When we wanted to go after the enterprise, we built an operating system. We&#8217;ll announce a new operating system, one that runs in the cloud and has a wide variety of capabilities.”</p></blockquote>
]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 16:55:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/computer science">computer science</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/people care">people care</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/financial crisis">financial crisis</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/eweeks microsoft">eweeks microsoft</category>
      <source url="http://blog.sciencelogic.com/links-list-10308/10/2008">Links List 10.3.08</source>
    </item>
    <item>
      <title><![CDATA[XRumer Spambot Cracks Captchas]]></title>
      <link>http://securityratty.com/article/8e16e4882509e89db49f04e7c4d2deb7</link>
      <guid>http://securityratty.com/article/8e16e4882509e89db49f04e7c4d2deb7</guid>
      <description><![CDATA[Weve known CAPTCHAs are insecure for some time, but now even the CAPTCHA-alternatives (often based on identifying cats from dogs or other animals) have proven insecure. Gmail, Windows Live hotmail and...]]></description>
      <content:encoded><![CDATA[<p>We&#8217;ve known CAPTCHAs are insecure for some time, but now even the CAPTCHA-alternatives (often based on identifying cats from dogs or other animals) have proven insecure. Gmail, Windows Live hotmail and other popular sites were hacked as early as <a rel="nofollow" target="_blank" href="http://http://arstechnica.com/news.ars/post/20080415-gone-in-60-seconds-spambot-cracks-livehotmail-captcha.html">February</a>. Recently another defeat has come in the form of <a rel="nofollow" target="_blank" href="http://en.wikipedia.org/wiki/Xrumer">XRumer,</a> a <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081002-right-back-at-ya-captcha-bad-guys-crack-gmail-hotmail.html">spam bot</a> that posts messages on blogs and through email in order to boost search engine rankings.</p>
<p>What&#8217;s the solution? Ars Technica suggests there might not be a good one, in part because malware distributors can go so far as to hire real people to do their dirty work:</p>
<blockquote><p>Instead of trying to build better CAPTCHA-cracking programs, the malware industry went out and got itself some humans of its own. This effectively bypasses the primary security strength of the CAPTCHA system and leaves it entirely dependent on what we&#8217;ll call secondary security characteristics. CAPTCHAs are often complex (particularly these days), which does increase the chance that they&#8217;ll be misread (and returned incorrectly), while the font and display of the characters themselves are at least somewhat unfamiliar to the CAPTCHA crackers sitting on the other side of the world.</p></blockquote>
<p>Sometimes those captcha phrases are pretty incoherent to me too. When I post over at Craigslist sometimes it says I&#8217;ve gotten its Captcha wrong, and I end up wondering if secretly I&#8217;m a bot?? Apparently not a very smart one either.</p>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 07:40:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/captchas">captchas</category>
      <category domain="http://securityratty.com/tag/bot">bot</category>
      <category domain="http://securityratty.com/tag/primary security strength">primary security strength</category>
      <category domain="http://securityratty.com/tag/windows live hotmail">windows live hotmail</category>
      <category domain="http://securityratty.com/tag/spam bot">spam bot</category>
      <category domain="http://securityratty.com/tag/ars technica suggests">ars technica suggests</category>
      <category domain="http://securityratty.com/tag/hire real people">hire real people</category>
      <category domain="http://securityratty.com/tag/popular sites">popular sites</category>
      <category domain="http://securityratty.com/tag/xrumer">xrumer</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/410515365/">XRumer Spambot Cracks Captchas</source>
    </item>
    <item>
      <title><![CDATA[ePolicing - Tomorrow the world?]]></title>
      <link>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</link>
      <guid>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</guid>
      <description><![CDATA[This week has finally seen an announcement that the Police Central e-crime Unit (PCeU) is to be funded by the Home Office. However, the largesse amounts to just 3.5 million of new money spread over...]]></description>
      <content:encoded><![CDATA[<p>This week has finally seen an <a href="http://press.homeoffice.gov.uk/press-releases/new-specialist-ecrime-unit">announcement</a> that the <a href="http://www.met.police.uk/pceu/index.htm">Police Central e-crime Unit</a> (PCeU) is to be funded by the Home Office. However, the largesse amounts to just £3.5 million of new money spread over three years, with the Met putting up a further £3.9 million &#8212; but whether the Met&#8217;s contribution is &#8220;new&#8221; or reflects a move of resources from their existing <a href="http://www.met.police.uk/computercrime/">Computer Crime Unit</a> I could not say.</p>
<p>The announcement is of course Good News &#8212; because once the PCeU is up and running next Spring, it should plug (to the limited extent that £2 million a year can plug) the &#8220;level 2&#8243; eCrime gap that I&#8217;ve <a href="http://www.lightbluetouchpaper.org/2006/02/06/mysterious-and-menacing/">written</a> <a href="http://www.lightbluetouchpaper.org/2006/10/13/mainstreaming-ecrime/">about</a> <a href="http://www.lightbluetouchpaper.org/2007/02/11/soca-we-just-want-your-money/">before</a>. viz: that SOCA tackles &#8220;serious and organised crime&#8221; (level 3), your local police force tackles local villains (level 1), but if criminals operate outside their force&#8217;s area &#8212; and on the Internet this is more likely than not &#8212; yet they don&#8217;t meet SOCA&#8217;s threshold, then who is there to deal with them?</p>
<p>In particular, the PCeU is envisaged to be the unit that deals with the intelligence packages coming from the <a href="http://www.cityoflondon.police.uk/CityPolice/ECD/Fraud/">City of London Fraud Squad&#8217;s</a> new online Fraud Reporting <a href="http://www.kablenet.com/kd.nsf/Frontpage/356DD0A1942F3A998025745F0049092C?OpenDocument">website</a> (once intended to launch in November 2008, now scheduled for Summer 2009).</p>
<p>Of course everyone expects the website to generate more reports of eCrime than could ever be dealt with (even with much more money), so the effectiveness of the PCeU in dealing with eCriminality will depend upon their prioritisation criteria, and how carefully they select the cases they tackle.</p>
<p>Nevertheless, although the news this week shows that the Home Office have finally understood the need to fund more ePolicing, I don&#8217;t think that they are thinking about the problem in a sufficiently global context.</p>
<p>A little history lesson might be in order to explain why.<br />
<span id="more-401"></span></p>
<p>Back in 1930&#8217;s, <a href="http://www.fbi.gov/libref/historic/famcases/clyde/clyde.htm">Bonnie and Clyde</a> and other US bank robbers were using the new-fangled automobile to flee across state lines &#8212; creating jurisdictional problems as a result. The US solution was to make bank robbery (along with auto-theft and other related offences) into federal offences rather keeping them as state-specific infractions. In particular this meant that the FBI could provide federal level policing (tracking down and killing <a href="http://en.wikipedia.org/wiki/John_Dillinger">John Dillinger</a> for example).</p>
<p>We have the same jurisdictional issues dealing with cyberspace, with criminals in one country fleecing consumers in another while using systems hosted in a third. The <a href="http://conventions.coe.int/Treaty/EN/Treaties/Html/185.htm">Convention on Cybercrime</a> addresses part of the problem by trying to ensure international consistency where eLaws are specifically needed (which of course is only the case for small parts of eCriminality, <a href="http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060035_en_1">fraud</a> is fraud whether eEnabled or not). However, there is limited inter-jurisdictional <em>co-ordination</em> for eCrime investigations &#8212; for example <a href="http://www.interpol.int/">Interpol</a> (often <a href="http://en.wikipedia.org/wiki/Interpol#Interpol_in_popular_culture">incorrectly perceived</a> to be international police force)  merely keeps a large database and passes faxes from one place to another.</p>
<p>In practice, most cross-border investigations are done as &#8220;joint operations&#8221; and the jointness is usually very limited &#8212; one force does all the legwork and a liaison officer in the other country deals with local paperwork. There&#8217;s usually a <a href="http://www.phrases.org.uk/meanings/quid-pro-quo.html">quid pro quo</a> element to these joint operations, for budgeting reasons if no other.</p>
<p>What isn&#8217;t happening, or at least only in a handful of very specialised areas, is any international co-operation in setting priorities or selecting cases to pursue. Every country is doing its own thing about eCrime, and there&#8217;s a widespread impression that any criminal who can operate from &#8220;across the state line&#8221; is essentially immune from serious investigation.</p>
<p>We identified this problem last year when we (<a href="http://www.cl.cam.ac.uk/~rja14/">Ross Anderson</a>, <a href="http://www.inf.tu-dresden.de/index.php?node_id=489">Rainer Böhme</a>, <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a>) wrote a report on <a href="http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&#038;_int_mark_20080131.pdf">Security Economics and the Internal Market</a> for <a href="http://www.enisa.europa.eu/">ENISA</a>. It&#8217;s not an easy one to fix whilst politicians (and populaces) are unwilling to see &#8220;foreign&#8221; police officers operating in their country, and the establishment of a truly international &#8220;cyber police force&#8221; seems equally unlikely.</p>
<p>Our policy proposal to tackle the issue harks back to WWII&#8217;s <a href="http://www.archives.gov/research/holocaust/finding-aid/military/rg-331.html">SHAEF</a>, which has morphed into similar arrangements within <a href="http://www.nato.int/shape/about/background2.htm">NATO</a>. In essence liaison officers from multiple forces would sit around a single table, working with a central coordinator, to set policy and decide which investigations to pursue. They would then communicate back to their own countries, who have specifically budgeted to provide appropriate assistance. So it&#8217;s very like &#8220;joint operations&#8221;, but the scheme is multi-laterial, and has a true command and control function in the centre &#8212; who will quickly learn to shy away from politically sensitive topics and make a real impact on eCriminality.</p>
<p>To summarise then, a <a href="http://www.cartoonbank.com/item/34449">welcome</a> to the Home Office for finally finding a small amount of funding for some country-wide ePolicing; but it&#8217;s well past time to be working on world-wide initiatives.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 13:57:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecrime gap">ecrime gap</category>
      <category domain="http://securityratty.com/tag/ecrime">ecrime</category>
      <category domain="http://securityratty.com/tag/provide federal level">provide federal level</category>
      <category domain="http://securityratty.com/tag/ecrime investigations">ecrime investigations</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/level">level</category>
      <category domain="http://securityratty.com/tag/country deals">country deals</category>
      <category domain="http://securityratty.com/tag/deals">deals</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/02/epolicing-tomorrow-the-world/">ePolicing - Tomorrow the world?</source>
    </item>
    <item>
      <title><![CDATA[CEP, Event Noise and Asymmetric Event Processing]]></title>
      <link>http://securityratty.com/article/2749df765875344a0e16c9acc0faf260</link>
      <guid>http://securityratty.com/article/2749df765875344a0e16c9acc0faf260</guid>
      <description><![CDATA[In The Genesis of Complex Event Processing: Asymmetric Capabilities I introduced the abstract concept of asymmetric processing capabilities to describe the foundations of complex event processing. If...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Genesis of Complex Event Processing: Asymmetric Capabilities" rel="bookmark" href="../2008/09/29/the-genesis-of-complex-event-processing-asymmetric-capabilites/">The Genesis of Complex Event Processing: Asymmetric Capabilities</a> I introduced the abstract concept of &#8220;asymmetric processing capabilities&#8221; to describe the foundations of complex event processing.   If you take a few moments to review the <a href="http://www.thecepblog.com/2008/07/07/a-blast-from-the-past-cep-at-stanford1998-2003/" target="_blank">first CEP projects</a> from <a href="http://www.stanford.edu" target="_blank">Stanford University</a>, you will see that the application of CEP was toward  solving myriad asymmetric event processing problems in distributed networks.    These applications included challenging problems such as:</p>
<ul>
<li><a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt">Network Level Monitoring and Management,<br />
</a></li>
<li><a href="http://pavg.stanford.edu/ID/">Cyber Security: Network Intrusion Detection,<br />
</a></li>
<li>Enterprise Monitoring and Management,</li>
<li><a href="http://pavg.stanford.edu/cep/final-version-131102.pdf">Modeling and Simulation of Collaborative Business Processes, </a></li>
<li>Business Policy Monitoring, and</li>
<li>Analysis and Debugging of Distributed Systems.</li>
</ul>
<p>In each of the CEP application examples above, the amount of event information available to software developers can be staggering; however, despite all the available information, the capability to sense-and-respond to threats and opportunities is crude, at best.</p>
<p>Folks who work in network and security management, for example, are bombarded with event information.  However, this deluge of event information is, for the most part, &#8220;noise&#8221; that is difficult to understand.   In network management one of the most difficult things to accomplish is to find the root cause of an outage or performance problem.   This is why researchers at Stanford were funded to focused on research topics such as (above), <em>the Analysis and Debugging of Distributed Systems</em>.</p>
<p>These are the classes of asymmetric event processing problems that define complex event processing, or CEP.   Processing events by mediating events, routing events, or running a rule-set against events and making a processing decision are all perfectly valid event processing applications.   However, the core reason to have &#8220;complex event processing&#8221; is to solve event processing problems where there exists a significant asymmetry between the deluge of &#8220;event noise&#8221;  (Professor Luckham called this phenomena the &#8220;event cloud&#8221;) and detecting business-relevant, actionable complex events in an climate of uncertainty and noise.</p>
<p>In my next post on this topic I will briefly the review motivation behind my 1999 ACM paper, <a title="Intrusion Detection Systems and Multisensor Data Fusion" rel="bookmark" href="../intrusion-detection-systems-and-multisensor-data-fusion/">Intrusion Detection Systems and Multisensor Data Fusion, </a> where we were working on solving complex distributed security challenges based on real-world experiences with the problems of asymmetric processing capabiilities.   I will discuss why we evolved from an early rule-based expert system model to a more advanced inference model that was not dependent solely on rule-based thinking.   I will also explain why other researchers and developers experienced in complex event detection applications have come to the same conclusion.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 01:22:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asymmetric event">asymmetric event</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/define complex event">define complex event</category>
      <category domain="http://securityratty.com/tag/asymmetric">asymmetric</category>
      <category domain="http://securityratty.com/tag/actionable complex events">actionable complex events</category>
      <category domain="http://securityratty.com/tag/myriad asymmetric event">myriad asymmetric event</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/security management">security management</category>
      <source url="http://www.thecepblog.com/2008/10/02/cep-event-noise-and-asymmetric-event-processing/">CEP, Event Noise and Asymmetric Event Processing</source>
    </item>
    <item>
      <title><![CDATA[Identifying the Gpcode Ransomware Author]]></title>
      <link>http://securityratty.com/article/7fcd166cea35b581caf45eb753d96890</link>
      <guid>http://securityratty.com/article/7fcd166cea35b581caf45eb753d96890</guid>
      <description><![CDATA[Interesting article, but it implies that there has been a shortage of quality OSINT regarding the campaigners behind the recent Gpcode targeted cryptoviral extortion attacks

The individual is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKf-AHSSyI/AAAAAAAACNA/2DxahyQID7E/s1600-h/gpcode_decryptor.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKf-AHSSyI/AAAAAAAACNA/xl-jNWBubqU/s200-R/gpcode_decryptor.jpg" /></a>Interesting article, but it implies that <a href="http://www.techworld.com/security/news/index.cfm?newsid=105043">there has been a shortage of quality OSINT</a> regarding the campaigners behind the recent <a href="http://it.slashdot.org/article.pl?sid=08/09/30/1446211">Gpcode targeted cryptoviral extortion attacks</a> :<br />
<br />
"<i>The individual is believed to be a Russian national, and has been in contact with at least one anti-malware company, Kaspersky Lab, in an attempt to sell a tool that could be used to decrypt victims' files. Kaspersky Lab set about locating the man by resolving the proxied IP addresses used to communicate with the world to their real addresses. The proxied addresses turned out to be zombie PCs in countries such as the US, which pointed to the fact that GPcode's author had almost certainly used compromised PCs from a single botnet to get Gpcode on to victim's machines.</i>"<br />
<br />
In reality, there hasn't been a shortage of timely OSINT aiming to to identify the authors - "<a href="http://blogs.zdnet.com/security/?p=1259">Who’s behind the GPcode ransomware?</a>" :<br />
<br />
"<i>So, the ultimate question - who’s behind the GPcode ransomware? It’s Russian  teens with pimples, using E-gold and Liberty Reserve accounts, running three  different GPcode campaigns, two of which request either $100 or $200 for the  decryptor, and communicating from Chinese IPs. Here are all the details  regarding the emails they use, the email responses they sent back, the currency  accounts, as well their most recent IPs used in the communication (<b>58.38.8.211; </b><b>221.201.2.227</b>) :</i><br />
<br />
<i><b>Emails used by the GPcode authors where the infected victims are  supposed to contact them :</b><br />
content715@yahoo .com<br />
saveinfo89@yahoo  .com<br />
cipher4000@yahoo .com<br />
decrypt482@yahoo .com</i><br />
<br />
<i><b>Virtual currency accounts used by the malware authors  :</b><br />
Liberty Reserve - account U6890784<br />
E-Gold - account -  5431725<br />
E-Gold - account - 5437838</i>"<br />
<br />
The bottom line - out of the four unique emails used by the GPcode campaigners, only two were actively corresponding with the victims, each of them requesting a different amount of money, but both, taking advantage of U.S based web services to accomplish their attack.<i></i><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bQZsL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bQZsL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q8qRL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q8qRL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UNhel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UNhel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SUDkl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SUDkl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d50OL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d50OL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RaaqL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RaaqL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YsUgl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YsUgl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407661528" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 13:23:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gpcode">gpcode</category>
      <category domain="http://securityratty.com/tag/gpcode campaigns">gpcode campaigns</category>
      <category domain="http://securityratty.com/tag/recent gpcode">recent gpcode</category>
      <category domain="http://securityratty.com/tag/gpcode ransomware">gpcode ransomware</category>
      <category domain="http://securityratty.com/tag/gpcode campaigners">gpcode campaigners</category>
      <category domain="http://securityratty.com/tag/gpcode authors">gpcode authors</category>
      <category domain="http://securityratty.com/tag/kaspersky lab">kaspersky lab</category>
      <category domain="http://securityratty.com/tag/virtual currency accounts">virtual currency accounts</category>
      <category domain="http://securityratty.com/tag/liberty reserve accounts">liberty reserve accounts</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407661528/identifying-gpcode-ransomware-author.html">Identifying the Gpcode Ransomware Author</source>
    </item>
  </channel>
</rss>
