<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: scada]]></title>
    <link>http://securityratty.com/tag/scada</link>
    <description></description>
    <pubDate>Tue, 22 Jan 2008 11:24:55 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control]]></title>
      <link>http://securityratty.com/article/85dd8ffe0f10a11626880b7de9e30386</link>
      <guid>http://securityratty.com/article/85dd8ffe0f10a11626880b7de9e30386</guid>
      <description><![CDATA[The following quote is from Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control by Evo Eftimov, iSec Consulting Ltd
Complex Event Processing...]]></description>
      <content:encoded><![CDATA[<p>The following quote is from <a href="http://www.top-consultant.com/articles/CEP.pdf" target="_blank">Complex Event Processing – An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control</a> by Evo Eftimov, <a href="http://www.isecc.com" target="_blank">iSec Consulting Ltd</a></p>
<blockquote><p>&#8220;Complex Event Processing (CEP) is a technology which has been used for many years in the Aerospace and Defence Industry for Situational Awareness and Data Fusion modules in Command, Control, Communications, Computing and Intelligence Systems (aka C4I).</p>
<p>Currently CEP is being rediscovered as a foundation for new class of extremely effective Business Intelligence, Security and System/Network/SCADA Monitoring solutions in industries like Financial Services, Telecommunications, Oil and Gas, Manufacturing, Logistics etc. The increasing connectivity and processing power of the modern IT and Telecom technologies lead to increasing speed and volume of the dataflow available to the organisations. By using CEP solutions companies can gain competitive advantage by achieving real-time situational awareness and tapping the information value that is hidden within the streams of real-time event data that are coming from a variety of sources such as enterprise applications, financial transactions, sensor networks and supply chains.&#8221;</p></blockquote>
<p style="text-align: left;">Unfortunately, the author does not cite references in the paper.</p>
]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 01:59:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/cep solutions companies">cep solutions companies</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/situational awareness">situational awareness</category>
      <category domain="http://securityratty.com/tag/real-time situational awareness">real-time situational awareness</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/business intelligence">business intelligence</category>
      <source url="http://www.thecepblog.com/2008/09/21/complex-event-processing-%e2%80%93-an-emerging-paradigm-in-business-intelligence-security-and-monitoring-and-control/">Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control</source>
    </item>
    <item>
      <title><![CDATA[CitectSCADA ODBC Service Exploit Published, Computerized Control Systems In Critical Facilities Are Vulnerable]]></title>
      <link>http://securityratty.com/article/f06e531a38d36157a8177d736b5e1c87</link>
      <guid>http://securityratty.com/article/f06e531a38d36157a8177d736b5e1c87</guid>
      <description><![CDATA[Supervisory Control And Data Acquisition (SCADA) systems buffer overflow vulnerability was discovered in June by CORE. It affects the CitectSCADA product and could allow a remote unauthenticated...]]></description>
      <content:encoded><![CDATA[Supervisory Control And Data Acquisition (SCADA) systems buffer overflow vulnerability was discovered in June by CORE. It affects the CitectSCADA product and could allow a remote unauthenticated attacker to force DoS or to execute arbitrary code on vulnerable systems. This weekend, Kevin Finisterre, the director of penetration testing at security firm Netragard, has published a [...]]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 23:35:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/execute arbitrary code">execute arbitrary code</category>
      <category domain="http://securityratty.com/tag/security firm netragard">security firm netragard</category>
      <category domain="http://securityratty.com/tag/supervisory control">supervisory control</category>
      <category domain="http://securityratty.com/tag/data acquisition">data acquisition</category>
      <category domain="http://securityratty.com/tag/vulnerable systems">vulnerable systems</category>
      <category domain="http://securityratty.com/tag/kevin finisterre">kevin finisterre</category>
      <category domain="http://securityratty.com/tag/citectscada product">citectscada product</category>
      <category domain="http://securityratty.com/tag/force dos">force dos</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <source url="http://cyberinsecure.com/citectscada-odbc-service-exploit-published-computerized-control-systems-in-critical-facilities-are-vulnerable/">CitectSCADA ODBC Service Exploit Published, Computerized Control Systems In Critical Facilities Are Vulnerable</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: June 20th]]></title>
      <link>http://securityratty.com/article/1bfc63ff81e391bc3c3f814b2bf51762</link>
      <guid>http://securityratty.com/article/1bfc63ff81e391bc3c3f814b2bf51762</guid>
      <description><![CDATA[Friday is upon us and I can see light at the end of the tunnel
Click here to subscribe to Liquidmatrix Security Digest
And now, the news
Computer with software stolen from RIDC Park Company ( SCADA...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Friday is upon us and I can see light at the end of the tunnel.</p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a>. </p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.pittsburghlive.com/x/pittsburghtrib/news/s_573740.html">Computer with software stolen from RIDC Park Company</a> (<i>SCADA management software</i>) | Pittsburgh Tribune-Review</li>
<li><a href="http://www.itpro.co.uk/603843/staff-ignore-data-security-surveys-say">Staff ignore data security, surveys say</a> | IT PRO</li>
<li><a href="http://weblog.infoworld.com/securityadviser/archives/2008/06/lessons_from_th.html">Lessons from the Verizon 2008 Data Breach Investigations Report</a> | InfoWorld</li>
<li><a href="http://www.networkworld.com/news/2008/061908-microsofts-critical-bluetooth-patch-didnt.html">Microsoft&#8217;s critical Bluetooth patch didn&#8217;t work on XP</a> | Network World</li>
<li><a href="http://www.iht.com/articles/2008/06/19/technology/sweden.php">Sweden passes eavesdropping law</a> | International Herald Tribune</li>
<li><a href="http://www.it-director.com/technology/applications/content.php?cid=10558">From zero day exploit to zero day fix</a> | IT Director</li>
<li><a href="http://www.guardian.co.uk/uk/2008/jun/20/ukcrime.internet">Briton searched web for ways to kill, court told</a> | The Guardian</li>
<li><a href="http://www.pcworld.com/businesscenter/article/147288/facetime_security_program_locks_out_myspace_applets.html">FaceTime Security Program Locks out MySpace Applets</a> | PC World</li>
<li><a href="http://blogs.zdnet.com/security/?p=1295">Security breach hits DivShare, unauthorized access to its database</a> | ZDNet</li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=Hlr7PC"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=Hlr7PC" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=fydn8I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=fydn8I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=MQb82i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=MQb82i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=RNEg6i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=RNEg6i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=uXombi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=uXombi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=2exTsi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=2exTsi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/316194104" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 08:52:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/scada management software">scada management software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/international herald tribune">international herald tribune</category>
      <category domain="http://securityratty.com/tag/ridc park company">ridc park company</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/network world">network world</category>
      <category domain="http://securityratty.com/tag/day exploit">day exploit</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/316194104/">Security Briefing: June 20th</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 4]]></title>
      <link>http://securityratty.com/article/1b46ad3d94d15ea2bc8502ef7ed2e55d</link>
      <guid>http://securityratty.com/article/1b46ad3d94d15ea2bc8502ef7ed2e55d</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #4, dated June 17, 2008
So my...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual "blogging frenzy" machine gun blast of short posts, I will just combine them into my new blog series "<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>." Here is an issue #4, dated June 17, 2008.</p> <p>So my next iteration of fun reading on security, logging and other topics.</p> <ol> <li>"Security-as-control" vs "security-as-assurance" - a very useful idea (more <a href="http://lists.immunitysec.com/pipermail/dailydave/2008-June/005073.html">here</a>), which is often confused with bad results (e.g. "secure" software = has password authentication OR has has no overflow bugs)  <li>Rich Mogul grabs GRC by the balls and <a href="http://securosis.com/2008/06/05/a-most-concise-accurate-description-of-the-problem-with-grc/">kicks it, hard, again.</a> A Burton Group guy comes and helps him by doing <a href="http://srmsblog.burtongroup.com/2008/06/its-all-grc-to.html">a nice roundhouse kick in its butt</a>. Still, it doesn't die, as <a href="http://srmsblog.burtongroup.com/2008/06/its-all-grc-to.html">more people kick it</a> ... Maybe 'cause Andy <a href="http://andyitguy.blogspot.com/2008/06/grc-love-it-or-hate-it.html">"loves or hates it?"</a> <li>Good advice from <a href="http://andyitguy.blogspot.com/">Andy IT Guy</a>: "We need to step back from time to time and evaluate what we are doing to determine if it still makes sense." (<a href="http://andyitguy.blogspot.com/2008/05/i-don-care-how-you-always-done-it.html">more</a>)  <li><a href="http://news.bbc.co.uk/1/hi/technology/7421099.stm">BBC on cloud security</a>, actually interesting. <a href="http://gigaom.com/2008/06/10/the-amazon-outage-fortresses-in-the-clouds/">More on the same subject</a>, albeit with a dumb name <li>Breach disclosure laws and security <a href="http://www.theregister.co.uk/2008/06/05/breach_disclosure_effects/">study</a> by CMU, that <a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=10&amp;issue=45">SANS called idiotic</a> ("What a silly study. It measures the wrong outcome. What matters about data breach notification is what it does to the quality of defenses.") AND "badly flawed" as well. More fun comments on it are <a href="http://www.emergentchaos.com/archives/2008/05/please_read_more_carefull.html">here</a>.&nbsp; <a href="http://www.csoonline.com/article/383313/Researchers_Notification_Laws_Not_Lowering_ID_Theft">More discussion</a> of this complicated subject. Rick kicks it too <a href="http://securosis.com/2008/06/09/new-identity-theft-stats/">here</a>. <li>Along the same line, "<em>Data breaches at retailers are the top cause of credit and debit card theft</em>, accounting for about 20% of all incidents." <a href="http://www.pcworld.com/businesscenter/article/146278/most_retailer_breaches_are_not_disclosed_gartner_says.html">Wow!</a> <li>"The biggest issue in both Audit and IT is a lack of strategic thought." (<a href="http://gse-compliance.blogspot.com/2008/06/biggest-issues-with-audit-security-it.html">maybe</a>) When I read it, it reminded me of the <a href="http://blog.penelopetrunk.com/2008/01/10/do-you-think-youre-a-strategist-youre-probably-wrong/">old wisdom from Ms Trunk</a>: "if you think you are a 'strategist' - check maybe you think that 'cause your execution sux"  <li>A very fun read: "<a href="http://www.informationweek.com/news/management/compliance/showArticle.jhtml?articleID=208400730&amp;subSection=All+Stories">Facing The Monster: The Labors Of Log Management</a>." I am happy that <a href="http://www.loglogic.com">log management</a> has been granted a monster status :-)  <li><a href="http://www.investors.com/Tech/TechExecQA.asp?artid=296765228592148">Role of compliance for SCADA security</a> puzzles me: think about it - you need a law to make people protect systems that control utilities EVEN THOUGH you already demonstrated (<a href="http://www.cnn.com/2007/US/09/26/power.at.risk/index.html">kind of</a>) that hackers can explode generators remotely. So, people fear fines from regulators more than exploded power generators? Yep. <li><a href="http://blog.loglogic.com/2008/06/a_pcidata_security_standard_for_cloud_computing/">Is it time</a> to regulate the security of cloud computing? <li><a href="http://www.schneier.com/blog/archives/2008/05/how_to_sell_sec.html">"How to Sell Security" by Bruce Schneier</a> - a MUST read. BTW, FUD is NOT dead, and won't be dead. Ever! <li>OMG, this is huge and will grow: <a href="http://pcianswers.com/2008/05/21/pci-compliance-and-virtualization/">PCI Compliance and Virtualization</a> (think "only one primary function per server" mandated in PCI). Same source on <a href="http://pcianswers.com/2008/05/19/cost-of-pci-compliance/">costs of PCI</a> (also fun!) - still, IMHO, PCI is cheaper than properly securing your environment ... And while we are on the subject of PCI, check out Rich's "<a href="http://securosis.com/2008/06/03/the-good-yes-good-and-bad-of-pci/">The Good (Yes, Good) And Bad Of PCI</a>" and the discussion that followed. <li>New wave of compliance is <a href="http://www.bloginfosec.com/2008/05/05/proposed-sec-rules-broaden-scope-of-infosec-compliance-responsibilities/">incoooooooooooooming</a>. Take cover!!! <li>Please shut up about ALL security being rolled into the network. Hoff says it best <a href="http://rationalsecurity.typepad.com/blog/2008/06/security-will-n.html">here</a>.&nbsp; If you want to join this bandwagon, say "all NETWORK security will be in the network."&nbsp; (you'd probably still be wrong, but less embarassed :-)) <li>Finally, some "<a href="http://blog.vorant.com/2008/06/unintentional-hilarity.html">Unintentional hilarity</a>" from David: <a href="http://blog.vorant.com/2008/06/unintentional-hilarity.html">this</a> is sooooo the world we live in :-)<br></li></ol>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=BFzhPI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=BFzhPI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=c4M1BI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=c4M1BI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=oOfUEI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=oOfUEI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/313999697" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 07:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/scada security puzzles">scada security puzzles</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/security study">security study</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/cloud security">cloud security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/313999697/fun-reading-on-security-4.html">Fun Reading on Security - 4</source>
    </item>
    <item>
      <title><![CDATA[Gas manufacturer defends SCADA systems]]></title>
      <link>http://securityratty.com/article/2ef05e7e4faf32633532a145d05d3160</link>
      <guid>http://securityratty.com/article/2ef05e7e4faf32633532a145d05d3160</guid>
      <description><![CDATA[A large medical-grade gas firm is installing intrusion-prevention systems to circumvent security problems that the government fears are a menace to power utilities and other essential...]]></description>
      <content:encoded><![CDATA[A large medical-grade gas firm is installing intrusion-prevention systems to circumvent security problems that the government fears are a menace to power utilities and other essential industries.]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/medical-grade gas firm">medical-grade gas firm</category>
      <category domain="http://securityratty.com/tag/essential industries">essential industries</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/government fears">government fears</category>
      <category domain="http://securityratty.com/tag/circumvent security">circumvent security</category>
      <category domain="http://securityratty.com/tag/power utilities">power utilities</category>
      <category domain="http://securityratty.com/tag/menace">menace</category>
      <source url="http://www.networkworld.com/news/2008/061208-scada.html?fsrc=rss-security">Gas manufacturer defends SCADA systems</source>
    </item>
    <item>
      <title><![CDATA[New Hurdles for Vulnerability Disclosure]]></title>
      <link>http://securityratty.com/article/f20273056546468d8fdebdd96683bd33</link>
      <guid>http://securityratty.com/article/f20273056546468d8fdebdd96683bd33</guid>
      <description><![CDATA[Vulnerability disclosure is an important part of information security. In recent years, vulnerabilities in specific Web sites and SCADA implementations have created new hurdles for vulnerability...]]></description>
      <content:encoded><![CDATA[Vulnerability disclosure is an important part of information security. In recent years, vulnerabilities in specific Web sites and SCADA implementations have created new hurdles for vulnerability disclosure. These aspects of information security have different risks and benefits to the involved stakeholders, which has prevented the establishment of an ideal environment for vulnerability disclosure.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=4719f44c653c8141e5f9261a0023a8d6" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=4719f44c653c8141e5f9261a0023a8d6" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 22 May 2008 02:22:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerability disclosure">vulnerability disclosure</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/specific web sites">specific web sites</category>
      <category domain="http://securityratty.com/tag/ideal environment">ideal environment</category>
      <category domain="http://securityratty.com/tag/hurdles">hurdles</category>
      <category domain="http://securityratty.com/tag/scada implementations">scada implementations</category>
      <category domain="http://securityratty.com/tag/establishment">establishment</category>
      <category domain="http://securityratty.com/tag/stakeholders">stakeholders</category>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <source url="http://www.pheedo.com/click.phdo?i=4719f44c653c8141e5f9261a0023a8d6">New Hurdles for Vulnerability Disclosure</source>
    </item>
    <item>
      <title><![CDATA[Experts hack power grid in no time]]></title>
      <link>http://securityratty.com/article/feaff1d9be7cf980f3bf573d9f59bde2</link>
      <guid>http://securityratty.com/article/feaff1d9be7cf980f3bf573d9f59bde2</guid>
      <description><![CDATA[Cracking a power company network and gaining access to supervisory, control and data acquisition (SCADA) systems that could shut down the grid is simple, security expert and penetration-testing...]]></description>
      <content:encoded><![CDATA[Cracking a power company network and gaining access to supervisory, control and data acquisition (SCADA) systems that could shut down the grid is simple, security expert and penetration-testing consultant Ira Winkler told an RSA audience, and he has done so in less than a day.]]></content:encoded>
      <pubDate>Tue, 08 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/consultant ira winkler">consultant ira winkler</category>
      <category domain="http://securityratty.com/tag/power company network">power company network</category>
      <category domain="http://securityratty.com/tag/grid">grid</category>
      <category domain="http://securityratty.com/tag/data acquisition">data acquisition</category>
      <category domain="http://securityratty.com/tag/rsa audience">rsa audience</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/supervisory">supervisory</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <source url="http://www.networkworld.com/news/2008/040908-rsa-hack-power-grid.html?fsrc=rss-security">Experts hack power grid in no time</source>
    </item>
    <item>
      <title><![CDATA[What can we learn from Hannaford & TJX?]]></title>
      <link>http://securityratty.com/article/88ff070aae362259fdd674697fc1c483</link>
      <guid>http://securityratty.com/article/88ff070aae362259fdd674697fc1c483</guid>
      <description><![CDATA[The Hannaford data breach was of course all over the news last week. It is reported that Hannaford's internal practices were considered PCI compliant, yet they suffered a massive data breach. It begs...]]></description>
      <content:encoded><![CDATA[<p>The Hannaford data breach was of course all over the news last week. It is reported that Hannaford's internal practices were considered PCI compliant, yet they suffered a massive data breach. It begs the question whether PCI requirements were sufficient. </p>

<p>While many companies still lag behind in terms of achieving PCI compliance, quite a few organizations have gone above and beyond to protect their critical operations. I call those &quot;next practice&quot; adopters (as opposed to best practice). For instance, PCI requires that you scan your computing assets quarterly. Many of the next practice companies would scan their most critical assets weekly or even daily. </p>

<p>So, what should you consider as your critical assets. Here is a list to get you started: </p>

<p>- Web applications (those that handle online transactions) </p>

<p>- Web servers (those that interface with external Web users) </p>

<p>- Database servers </p>

<p>- Application servers that serve up your core applications </p>

<p>- Firewall (between DMZ and the Internet) </p>

<p>- VPN servers </p>

<p>Your list may defer, depending on your business operations. For instance, some businesses operate SCADA system, and that would be their critical asset. But the above list is a good place to start thinking about your critical network assets and how you should management vulnerabilities both at the network layer and in the applications. </p>

<p>For more information, see the Forrester report: &quot;Operationalizing Application Vulnerability Management&quot;. </p>]]></content:encoded>
      <pubDate>Sun, 30 Mar 2008 08:58:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hannaford">hannaford</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <category domain="http://securityratty.com/tag/critical assets weekly">critical assets weekly</category>
      <category domain="http://securityratty.com/tag/critical assets">critical assets</category>
      <category domain="http://securityratty.com/tag/practice companies">practice companies</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/practice">practice</category>
      <category domain="http://securityratty.com/tag/hannaford data breach">hannaford data breach</category>
      <source url="http://blogs.forrester.com/srm/2008/03/what-can-we-lea.html">What can we learn from Hannaford &amp; TJX?</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-01-25 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/d2b4012cbc2d91a2ccbd36bc5f65e8e9</link>
      <guid>http://securityratty.com/article/d2b4012cbc2d91a2ccbd36bc5f65e8e9</guid>
      <description><![CDATA[Beware the knowledgable insider. Societe Generale shows us why. | Threat Chaos | ZDNet.com
Intel ROSI Paper: Sets Practical Guidelines and Proper Expectations : bloginfosec.com
Security Thoughts:...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blogs.zdnet.com/threatchaos/?p=513">&raquo; Beware the knowledgable insider. Societe Generale shows us why. | Threat Chaos | ZDNet.com</a></li>
<li><a href="http://www.bloginfosec.com/2008/01/24/intel-rosi-paper-sets-practical-guidelines-and-proper-expectations/">Intel ROSI Paper: Sets Practical Guidelines and Proper Expectations : bloginfosec.com</a></li>
<li><a href="http://securethink.blogspot.com/2008/01/prediction-2-for-2008-stealth-hackers.html">Security Thoughts: Prediction 2 for 2008 - Stealth &quot;Hackers&quot;</a></li>
<li><a href="http://rationalsecurity.typepad.com/blog/2008/01/dont-be-a-scada.html">Rational Survivability: Pushing Reset On the IT vs. SCADA Security Debate....</a></li>
<li><a href="http://www.schneier.com/blog/archives/2008/01/hacking_power_n.html">Schneier on Security: Hacking Power Networks</a></li>
<li><a href="http://vmyths.com/column/1/2008/1/20/">Vmyths on SCADA - SANS director confirms the CIA confirmed ... absolutely nothing</a></li>
<li><a href="http://pcidss.wordpress.com/2008/01/22/majority-of-visa-merchants-are-compliant-as-of-jan-22-2008/">Majority of VISA Merchants are Compliant as of Jan. 22, 2008 &laquo; Payment Card Security &amp; IT Controls Explained</a></li>
<li><a href="http://www.daemon.be/maarten/targetedattacks.html">Targeted Trojan Attacks</a></li>
<li><a href="http://www.eetimes.com/showArticle.jhtml;jsessionid=BL3FUQ4L5JOXEQSNDLPCKH0CJUNN2JVN?articleID=205918880">EETimes.com - New cybersecurity specs target power grid</a><br/>
Huge benefits could follow adoption of the new standards, according to one industry voice. &quot;The NERC regulations might well trigger a golden age of security in the energy industry,&quot; said Anton Chuvakin, &quot;chief logging evangelist&quot; with LogLogic (San Jose,</li>
<li><a href="http://www.theregister.co.uk/2008/01/24/disgruntled_employee_silent_rampage/">Employee's silent rampage wipes out $2.5m worth of data | The Register</a><br/>
Cooley was charged with damage in excess of $1,000 to computers and was released on bail.</li>
<li><a href="http://www.pcadvisor.co.uk/news/index.cfm?newsid=11909">2008: The year of the Apple hack News - PC Advisor</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/223341476" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/payment card security">payment card security</category>
      <category domain="http://securityratty.com/tag/scada">scada</category>
      <category domain="http://securityratty.com/tag/scada security">scada security</category>
      <category domain="http://securityratty.com/tag/sets practical guidelines">sets practical guidelines</category>
      <category domain="http://securityratty.com/tag/sans director confirms">sans director confirms</category>
      <category domain="http://securityratty.com/tag/intel rosi paper">intel rosi paper</category>
      <category domain="http://securityratty.com/tag/silent rampage wipes">silent rampage wipes</category>
      <category domain="http://securityratty.com/tag/apple hack news">apple hack news</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/223341476/anton18">Links for 2008-01-25 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Hacking Power Networks]]></title>
      <link>http://securityratty.com/article/827c4e5d935db9b3586563a48e95974d</link>
      <guid>http://securityratty.com/article/827c4e5d935db9b3586563a48e95974d</guid>
      <description><![CDATA[The CIA unleashed a big one at a SANS conference : On Wednesday, in New Orleans, US Central Intelligence Agency senior analyst Tom Donahue told a gathering of 300 US, UK, Swedish, and Dutch government...]]></description>
      <content:encoded><![CDATA[<p>The CIA unleashed a big one at <a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=10&issue=5">a SANS conference</a>:</p>

<blockquote>On Wednesday, in New Orleans, US Central Intelligence Agency senior analyst Tom Donahue told a gathering of 300 US, UK, Swedish, and Dutch government officials and engineers and security managers from electric, water, oil & gas and other critical industry asset owners from all across North America, that "We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. We have information that cyber attacks have been used to disrupt power equipment in several regions outside the United States. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet."

<p>According to Mr. Donahue, the CIA actively and thoroughly considered the benefits and risks of making this information public, and came down on the side of disclosure.</blockquote></p>

<p>I'll bet.  There's nothing like an vague unsubstantiated rumor to forestall reasoned discussion.  But, of course, <a href="http://www.engadget.com/2008/01/19/hackers-reportedly-targeting-cities-power-systems/">everyone</a> <a href="http://www.forbes.com/2008/01/18/cyber-attack-utilities-tech-intel-cx_ag_0118attack.html">is</a> <a href="http://www.ibls.com/internet_law_news_portal_view.aspx?s=latestnews&id=1963">writing</a> <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=205901631">about</a> <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/18/AR2008011803277.html">it</a> <a href="http://www.pcworld.com/article/id,141564-c,hackers/article.html">anyway</a>.</p>

<p>SANS's Alan Paller is happy to <a href="http://www.forbes.com/2008/01/18/cyber-attack-utilities-tech-intel-cx_ag_0118attack.html">add details</a>:</p>

<blockquote>In the past two years, hackers have in fact successfully penetrated and extorted multiple utility companies that use SCADA systems, says Alan Paller, director of the SANS Institute, an organization that hosts a crisis center for hacked companies. "Hundreds of millions of dollars have been extorted, and possibly more. It's difficult to know, because they pay to keep it a secret," Paller says. "This kind of extortion is the biggest untold story of the cybercrime industry."</blockquote>

<p>And to up the <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=205901631">fear factor</a>:</p>

<blockquote>The prospect of cyberattacks crippling multicity regions appears to have prompted the government to make this information public. The issue "went from 'we should be concerned about to this' to 'this is something we should fix now,' " said Paller. "That's why, I think, the government decided to disclose this."</blockquote>

<p>More <a href="http://www.ibls.com/internet_law_news_portal_view.aspx?s=latestnews&id=1963">rumor</a>:</p>

<blockquote>An attendee of the meeting said that the attack was not well-known through the industry and came as a surprise to many there. Said the person who asked to remain anonymous, "There were apparently a couple of incidents where extortionists cut off power to several cities using some sort of attack on the power grid, and it does not appear to be a physical attack."</blockquote>

<p>And more <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/18/AR2008011803277.html">hyperbole</a> from someone in the industry:</p>

<blockquote>Over the past year to 18 months, there has been "a huge increase in focused attacks on our national infrastructure networks, . . . and they have been coming from outside the United States," said Ralph Logan, principal of the Logan Group, a cybersecurity firm.

<p>It is difficult to track the sources of such attacks, because they are usually made by people who have disguised themselves by worming into three or four other computer networks, Logan said. He said he thinks the attacks were launched from computers belonging to foreign governments or militaries, not terrorist groups."</blockquote></p>

<p>I'm more than a bit skeptical here.  To be sure -- <a href="http://www.schneier.com/blog/archives/2007/10/staged_attack_c.html">fake staged attacks</a> aside -- there are serious risks to SCADA systems (Ganesh Devarajan <a href="http://www.defcon.org/html/defcon-15/dc-15-speakers.html#Devarajan">gave a talk at DefCon</a> this year about some potential attack vectors), although at this point I think they're more a future threat than present danger.  But this CIA tidbit tells us nothing about how the attacks happened.  Were they against SCADA systems?  Were they against TCP/IP systems?  Were they against Windows?  Insiders may have been involved, so was this a computer security vulnerability at all?  We have no idea.</p>

<p>Cyber-extortion is certainly on the rise; we see it at Counterpane. Primarily it's against fringe industries -- online gambling, online gaming, online porn -- operating offshore in countries like Bermuda and the Cayman Islands.  It is going mainstream, but this is the first I've heard of it targeting power companies.  Certainly possible, but is that part of the CIA rumor or was it tacked on afterwards?</p>

<p>And <a href="http://en.wikipedia.org/wiki/List_of_power_outages">here's</a> list of power outages.  Which ones were hacker caused?  Some details would be nice.</p>

<p>I'd like a little bit more information before I start panicking.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=CcqAWvD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=CcqAWvD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SStleeD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SStleeD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SRKOXVD"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SRKOXVD" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 22 Jan 2008 11:24:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/power">power</category>
      <category domain="http://securityratty.com/tag/power companies">power companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/cia actively">cia actively</category>
      <category domain="http://securityratty.com/tag/power outages">power outages</category>
      <category domain="http://securityratty.com/tag/cia">cia</category>
      <category domain="http://securityratty.com/tag/cia rumor">cia rumor</category>
      <category domain="http://securityratty.com/tag/disrupt power equipment">disrupt power equipment</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <source url="http://www.schneier.com/blog/archives/2008/01/hacking_power_n.html">Hacking Power Networks</source>
    </item>
  </channel>
</rss>
