Showing posts with label Information. Show all posts
Showing posts with label Information. Show all posts

Sunday, 12 May 2013

Welcome to the red team!

You may not know that ‘red teaming’ refers to the practice of “viewing a problem from an adversary or competitor’s perspective. The goal of most red teams is to enhance decision making, either by specifying the adversary’s preferences and strategies or by simply acting as a devil’s advocate. Red teaming may be more or less structured, and a wide range of approaches exists. In the past several years, red teaming has been applied increasingly to issues of security, although the practice is potentially much broader. Business strategists, for example, can benefit from weighing possible courses of action from a competitor’s point of view.” That definition comes from the Red Team Journal at http://redteamjournal.com/about/red-teaming-and-alternative-analysis/.

One thing that red teams are often asked to do these days is test IT security. The red team will try to infiltrate a company’s IT system in order to identify any previously unknown vulnerabilities. It seems that one of the best ways to get into a system is to be the first to find a new vulnerability in the software that no-one else has spotted. This ‘zero day’ vulnerability can be used to get malware of some kind into an organization, and, from then on, the red team own the IT system. And that’s why it’s a good idea to pay a team of experts rather than wake up one day and find the bad guys have found their way into your IT infrastructure.

Basically, that small piece of malware can be used by the red team to gain access to the network. And from there they can gain access to any documents or databases and download whatever information they want. If you’re company is a bank, they could find a way to steal money. And a lot of the time, no-one would know it was happening until it’s too late.

Internet Explorer has been in the press over the years for the number of vulnerabilities that it once had, but nowadays, Java is a prime target for red teams because Java is meant to run on 3 million devices – providing what’s called a large ‘attack surface’. Stack walking refers to the way that the different components of an IT platform exchange information about security privileges. This makes it an ideal target.

Attacking the software is getting harder these days, but there’s one component of an organization’s computer system that is always potentially vulnerable – and that’s the people who use the computers. In the past there were stories of dumpster diving – where people would look through dumpsters and rubbish bins for information on paper that was thrown away. Nowadays, most companies collect and destroy paper, so that can’t happen. Even so, walking around a building a visitor can still find passwords on Post-It notes stuck to screens. There’s also a technique called spearphishing that can be used. In this, a seemingly legitimate e-mail contains a malicious link or attachment. Once a person clicks on the link or opens the attachment, the malware is on the system. Another technique is to send infected memory sticks to staff, who often plug them in to see what’s on them, and, again, the malware strikes!

Red team members can now use social media to find the names of staff as well as details of their experience, so that e-mails and phone calls from the red team can sound quite legitimate. Part of the answer is SIEM (Security Information and Event Management) solutions. These provide real-time analysis of security alerts generated by network hardware and applications. SIEM solutions come as software, appliances, or managed services, and are also used to log security data and generate reports for compliance purposes.

The other part of the solution is education of staff so that they don’t insert memory sticks or click on attachments from unknown sources. But often, the best way to get access to corporate data is to find a disgruntled employee. So maybe another part of the solution is to ensure that staff are happy – that terms and conditions are going to avoid people feeling disgruntled. And if they are, then policies and procedures must be in place to manage that situation. And that’s not so easy with a large organization.

Mainframes are mostly used by large organizations – which obviously puts them at risk from unhappy employees. The risk is increased because most mainframe sites also use other platforms – PCs etc. And there is a new and huge security risk with BYOD. The red team could, perhaps, get a piece of malware onto someone’s tablet, which then gets connected to network, which then starts opening security doors all the way to the mainframe.

You may feel your data isn’t important enough to warrant the employment of a red team to test out any exposure to vulnerabilities you might have. But most organizations can learn from the types of vulnerability red teams exploit, and take steps to ensure that they are not at risk from them.

Sunday, 22 May 2011

For the journey

There’s an accurate, but much-overused, metaphor for life as a journey. Well, coming soon, this metaphor has been taken a stage further by giving us a destination – Destination z. According to the Web site at www.destinationz.org, Destination z is a community where all things mainframe converge to keep you informed. The new destinationz.org site becomes live in summer 2011, and when it launches, members will be connected to a new global community of  peers – mainframe users, business partners, academia, consultants, and others.

An inaugural enewsletter (tentatively called zNEWS) will be sent out in June, formally announcing the destinationz.org community.

In fact, Destination z has been around since 2007 and had 26 founding members. Since then,  more business partners, supporting members, and academic members have joined, bring the number of members to 100 by the end of 2010. This next phase broadens the membership to include IBM System z clients and it’s planned to provide numerous resources and benefits.

Here’s their logo:
According to an article on the MainframeZone Web site: “The latest phase will bring value to mainframe clients and their employees by providing rich Web content, connecting the community through social media, and creating a ‘one-stop shop”’for everything z through an index of key resources, including IBM and partner product content, customer stories, and links to blogs, forums, an online mentorship program to introduce students to the mainframe community, and more. These members can access all the resources available through the Website and can opt to be included in special communications from both the IBM Destination z Team and IBM Business Partner members.”

To my mind, anything that helps the community of mainframe users has got to be good, and I’ve pre-registered to become a member. You might like to do the same.

And while we’re on the subject of moving things around, you might be interested to know that the IBM Information Champion programme has changed its home location.

For the past few years, it has been sitting at www-01.ibm.com/software/data/champion/, but it is now on IBM’s developerWorks site at www.ibm.com/developerworks/champion, and they’re promising that the shorter URL of www.ibm.com/champion will work. There’s also a new logo:



I’ve been a ‘Champion’ each year since 2009. You can see me my profile at https://www.ibm.com/developerworks/mydeveloperworks/profiles/html/profileView.do?key=d5b16dc4-2a16-4a1b-86d5-dc4d1cd7d318&lang=en.

The change of location is, I believe, part of IBM’s strategy to raise the profile of this programme and help increase awareness of mainframes to the general public.

Hopefully, after the summer, with these two initiatives, information and other resources for mainframers will be more readily available and easier to locate.

Sunday, 8 August 2010

Virtual IMS Connection user group - under threat

Virtual IMS Connection is a vendor-neutral, independently-operated, virtual user group for IMS (IBM's Information Management System) professionals. It can currently be found at www.virtualims.com. It was launched at the beginning of November 2007.

Virtual user group meetings take place every other month and a guest speaker gives a presentation relevant to the IMS user community. The user group meetings last a little over an hour in total. Participation in meetings is free to members. The Virtual IMS Connection user group is also free to join.

User group members also get a bi-monthly newsletter. You can see the flip-book version here and the PDF version here.

The Web site contains details of future meetings, information about IMS-related articles (published elsewhere on the Web) and events, a list of IMS tools (software - the listing is free to vendors) and services, a list of IMS consultants, and a job bank (with resumes - CVs - and job opportunities).

New IMS products and new versions of existing products are always included in the News page. There's a link to the IMS-L listserv, where IMS professionals can ask questions and share information.

Members can access PDF versions of presentations and PDF versions of newsletters.

The idea was to create a one-stop shop for IMS professionals, where individuals using IBM’s IMS hierarchical database and transaction processing systems could exchange information, learn new techniques, and advance their skills with the product.

Obviously, there are sponsorship opportunities available to vendors of IMS-related products to help fund this work. Vendors can place banner adverts, etc. However, since its inception, NEON Enterprise Software has provided Web hosting for the site, and funded the WebEx technology that we have used to make the regular webinars possible, as well as meeting other costs. This is now coming to an end, and the Virtual IMS Connection user group is looking for a new home.

If your organization might be able to help keep this important user group running, please contact me on trevor@itech-ed.com.

You can also find the user group on Twitter at twitter.com/VirtualIMS.
You can become a fan on Facebook at www.facebook.com/#/pages/Virtual-IMS-Connection-user-group/282385116069.

Let's hope that the Virtual IMS Connection user group can continue to share ideas, information, and skills into the future.