You may not know that ‘red teaming’ refers to the practice of “viewing a problem from an adversary or competitor’s perspective. The goal of most red teams is to enhance decision making, either by specifying the adversary’s preferences and strategies or by simply acting as a devil’s advocate. Red teaming may be more or less structured, and a wide range of approaches exists. In the past several years, red teaming has been applied increasingly to issues of security, although the practice is potentially much broader. Business strategists, for example, can benefit from weighing possible courses of action from a competitor’s point of view.” That definition comes from the Red Team Journal at http://redteamjournal.com/about/red-teaming-and-alternative-analysis/.
One thing that red teams are often asked to do these days is test IT security. The red team will try to infiltrate a company’s IT system in order to identify any previously unknown vulnerabilities. It seems that one of the best ways to get into a system is to be the first to find a new vulnerability in the software that no-one else has spotted. This ‘zero day’ vulnerability can be used to get malware of some kind into an organization, and, from then on, the red team own the IT system. And that’s why it’s a good idea to pay a team of experts rather than wake up one day and find the bad guys have found their way into your IT infrastructure.
Basically, that small piece of malware can be used by the red team to gain access to the network. And from there they can gain access to any documents or databases and download whatever information they want. If you’re company is a bank, they could find a way to steal money. And a lot of the time, no-one would know it was happening until it’s too late.
Internet Explorer has been in the press over the years for the number of vulnerabilities that it once had, but nowadays, Java is a prime target for red teams because Java is meant to run on 3 million devices – providing what’s called a large ‘attack surface’. Stack walking refers to the way that the different components of an IT platform exchange information about security privileges. This makes it an ideal target.
Attacking the software is getting harder these days, but there’s one component of an organization’s computer system that is always potentially vulnerable – and that’s the people who use the computers. In the past there were stories of dumpster diving – where people would look through dumpsters and rubbish bins for information on paper that was thrown away. Nowadays, most companies collect and destroy paper, so that can’t happen. Even so, walking around a building a visitor can still find passwords on Post-It notes stuck to screens. There’s also a technique called spearphishing that can be used. In this, a seemingly legitimate e-mail contains a malicious link or attachment. Once a person clicks on the link or opens the attachment, the malware is on the system. Another technique is to send infected memory sticks to staff, who often plug them in to see what’s on them, and, again, the malware strikes!
Red team members can now use social media to find the names of staff as well as details of their experience, so that e-mails and phone calls from the red team can sound quite legitimate. Part of the answer is SIEM (Security Information and Event Management) solutions. These provide real-time analysis of security alerts generated by network hardware and applications. SIEM solutions come as software, appliances, or managed services, and are also used to log security data and generate reports for compliance purposes.
The other part of the solution is education of staff so that they don’t insert memory sticks or click on attachments from unknown sources. But often, the best way to get access to corporate data is to find a disgruntled employee. So maybe another part of the solution is to ensure that staff are happy – that terms and conditions are going to avoid people feeling disgruntled. And if they are, then policies and procedures must be in place to manage that situation. And that’s not so easy with a large organization.
Mainframes are mostly used by large organizations – which obviously puts them at risk from unhappy employees. The risk is increased because most mainframe sites also use other platforms – PCs etc. And there is a new and huge security risk with BYOD. The red team could, perhaps, get a piece of malware onto someone’s tablet, which then gets connected to network, which then starts opening security doors all the way to the mainframe.
You may feel your data isn’t important enough to warrant the employment of a red team to test out any exposure to vulnerabilities you might have. But most organizations can learn from the types of vulnerability red teams exploit, and take steps to ensure that they are not at risk from them.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Sunday, 12 May 2013
Welcome to the red team!
Labels:
attack surface,
blog,
Eddolls,
Event,
Information,
malware,
management,
red,
security,
SIEM,
spearphishing,
team,
teaming,
vulnerabilities,
vunerability,
zero day
Sunday, 13 November 2011
Guest blog – Mainframe security: who needs it?
This week, for a change, I’m publishing a blog entry from Peter Goldberg, a senior solution architect at Liaison Technologies, a global provider of cloud-based integration and data management services and solutions based in Atlanta. He works directly with customers to identify their unique data security and integration challenges and helps to design solutions to suit their organizations’ requirements. A frequent speaker at industry conferences on eBusiness security issues and solutions, he can be reached at pgoldberg@liaison.com.
I’ve been helping companies on both sides of the pond solve their data security problems for many years now. If I’ve learned one thing, it’s this: when I go into an organization that runs Windows, there’s little question of the need for data security. The organization knows it and so do I. When I visit a company whose IT infrastructure revolves around a mainframe, however, the mindset is often quite the opposite. In fact, the biggest data security misconception I encounter is the belief that the mainframe environment is inherently secure. Most IT staff view the mainframe as just another network node. Why? Because it’s universally perceived as a closed environment and, therefore, invulnerable to hackers.
In some cases, it’s the mainframe IT pros who hold this conviction. In other instances, it’s the executive management team. Lack of management attention allows “bad practices” to continue. I can tell you this without reserve: data stored in mainframes needs protection just as much as sensitive information stored on a Windows server or anywhere else. And, as systems continue to support more data, users, applications, and services, effective security management in the mainframe environment becomes significantly more difficult.
News flash: mainframes can be hacked!
For that simple reason, mainframe security should not be taken for granted.
Even though the mainframe is a mature platform, there is a real shortage of mainframe-specific security skills in the market. And, the few mainframe security practitioners who are out there spend a lot of time implementing configuration and controls within their environments as well as putting into place security systems like RACF, which provide access control and auditing functionality. As for other security measures, in my experience, the mainframe people know about encryption, but they’re not terribly aware of newer data security techniques like tokenization as it relates to protecting data within the mainframe environment and beyond.
Tokenization is a data security model that substitutes surrogate values for sensitive information in business systems. A rapidly rising method for reducing corporate risk and supporting compliance with data security standards and data privacy laws, it can be used to protect cardholder information as well as Personally Identifiable Information (PII) and Protected Health Information (PHI).
In fact, for companies that need to comply with the Payment Card Industry’s Data Security Standard (PCI DSS), tokenization has been lauded for its ability to reduce the cost of compliance by taking entire systems out of scope for PCI assessments. And, even in companies that do not deal with PCI DSS or other mandates, tokenization has proven effective for managing the duplication of data across LPARs and for facilitating the usage of potentially sensitive data for development purposes.
Too often, compliance audits skim over mainframe control weaknesses and there are also fewer mainframe-specific security guidelines. But this does not mean that significant risk is not there. You can apply a risk-based, defence-in-depth approach within the mainframe environment by using stronger mainframe host security controls and by using tokenization to protect the data itself.
To beef up data security on a mainframe, here’s my advice:
I’ve been helping companies on both sides of the pond solve their data security problems for many years now. If I’ve learned one thing, it’s this: when I go into an organization that runs Windows, there’s little question of the need for data security. The organization knows it and so do I. When I visit a company whose IT infrastructure revolves around a mainframe, however, the mindset is often quite the opposite. In fact, the biggest data security misconception I encounter is the belief that the mainframe environment is inherently secure. Most IT staff view the mainframe as just another network node. Why? Because it’s universally perceived as a closed environment and, therefore, invulnerable to hackers.
In some cases, it’s the mainframe IT pros who hold this conviction. In other instances, it’s the executive management team. Lack of management attention allows “bad practices” to continue. I can tell you this without reserve: data stored in mainframes needs protection just as much as sensitive information stored on a Windows server or anywhere else. And, as systems continue to support more data, users, applications, and services, effective security management in the mainframe environment becomes significantly more difficult.
News flash: mainframes can be hacked!
For that simple reason, mainframe security should not be taken for granted.
Even though the mainframe is a mature platform, there is a real shortage of mainframe-specific security skills in the market. And, the few mainframe security practitioners who are out there spend a lot of time implementing configuration and controls within their environments as well as putting into place security systems like RACF, which provide access control and auditing functionality. As for other security measures, in my experience, the mainframe people know about encryption, but they’re not terribly aware of newer data security techniques like tokenization as it relates to protecting data within the mainframe environment and beyond.
Tokenization is a data security model that substitutes surrogate values for sensitive information in business systems. A rapidly rising method for reducing corporate risk and supporting compliance with data security standards and data privacy laws, it can be used to protect cardholder information as well as Personally Identifiable Information (PII) and Protected Health Information (PHI).
In fact, for companies that need to comply with the Payment Card Industry’s Data Security Standard (PCI DSS), tokenization has been lauded for its ability to reduce the cost of compliance by taking entire systems out of scope for PCI assessments. And, even in companies that do not deal with PCI DSS or other mandates, tokenization has proven effective for managing the duplication of data across LPARs and for facilitating the usage of potentially sensitive data for development purposes.
Too often, compliance audits skim over mainframe control weaknesses and there are also fewer mainframe-specific security guidelines. But this does not mean that significant risk is not there. You can apply a risk-based, defence-in-depth approach within the mainframe environment by using stronger mainframe host security controls and by using tokenization to protect the data itself.
To beef up data security on a mainframe, here’s my advice:
- Bring in mainframe security experts to identify and remediate risks, and to develop and enforce security policies and procedures.
- Develop in-house capabilities and skilled professionals across the mainframe platform to support security initiatives.
- Evaluate available security configuration and administration tools – there are some really good ones out there.
- Apply an in-depth security strategy that includes secure access and authentication controls, and use them appropriately.
- Adopt encryption and tokenization to protect sensitive information. Through their proper implementation, it’s really not that hard to achieve a true high level of protection within the mainframe environment.
Protecting sensitive and/or business-critical data is essential to a company’s reputation, profitability, and business objectives. In today’s global market, where business and personal information know no boundaries, traditional point solutions that protect certain devices or applications against specific risks are insufficient to provide cross-enterprise data security. Combining encryption and tokenization, along with centralized key management, as part of a corporate data protection programme works well – including in mainframe-centric environments – for protecting information while reducing corporate risk and the cost of compliance with data security mandates and data privacy laws.
Don’t be fooled: your mainframe isn’t inherently secure. Doing nothing is no longer an option!
Thanks Peter for your guest blog.
And remember, there's still time to complete the mainframe user survey or place a vendor entry in the Arcati Mainframe Yearbook 2012.
Friday, 2 September 2011
Create custom permissions – for SharePoint
It’s been a while since we’ve published one of iTech-Ed Associate Darren Pritchard’s SharePoint 2007 beginners’ guides. This time he’s explaining custom permissions and how to create them.
Let’s start off by defining what we’re talking about. Specifying custom permission levels give you more control over the degree of access users can have to SharePoint sites, site collections, or site content. In effect, you create a new security group.
So, let’s run through the steps:
Let’s start off by defining what we’re talking about. Specifying custom permission levels give you more control over the degree of access users can have to SharePoint sites, site collections, or site content. In effect, you create a new security group.
So, let’s run through the steps:
- From the site collection click ‘Site Actions’
- Click ‘Site Settings’
- Under ‘Users and Permissions’ click ‘Advanced Permissions’
- You will then see a list for permission level group
- Select the ‘Settings’ drop down
- Click ‘Permission Levels’
- Click ‘Add a Permission Level’
- You will then be able to create your own security group.
It’s worth remembering that only this site and all its sub-sites will have access to your new group.
Below is a list of permissions that can be set. Please note that selecting one may also result in others being selected because they are required as part of your selection.
List Permissions:
- Manage Lists – create and delete lists, add or remove columns in a list, and add or remove public views of a list.
- Override Check Out – discard or check in a document that is checked out to another user.
- Add Items – add items to lists, add documents to document libraries, and add Web discussion comments.
- Edit Items – edit items in lists, edit documents in document libraries, edit Web discussion comments in documents, and customize Web Part Pages in document libraries.
- Delete Items – delete items from a list, documents from a document library, and Web discussion comments in documents.
- View Items – view items in lists, documents in document libraries, and view Web discussion comments.
- Approve Items – approve a minor version of a list item or document.
- Open Items – view the source of documents with server-side file handlers.
- View Versions – view past versions of a list item or document.
- Delete Versions – delete past versions of a list item or document.
- Create Alerts – create e-mail alerts.
- View Application Pages – view forms, views, and application pages. Enumerate lists.
Site Permissions:
- Manage Permissions – create and change permission levels on the Web site and assign permissions to users and groups.
- View Usage Data – view reports on Web site usage.
- Create Subsites – create subsites such as team sites, Meeting Workspace sites, and Document Workspace sites.
- Manage Web Site – grants the ability to perform all administration tasks for the Web site as well as manage content.
- Add and Customize Pages – add, change, or delete HTML pages or Web Part Pages, and edit the Web site using a Windows SharePoint Services-compatible editor.
- Apply Themes and Borders – apply a theme or borders to the entire Web site.
- Apply Style Sheets – apply a style sheet (.css file) to the Web site.
- Create Groups – create a group of users that can be used anywhere within the site collection.
- Browse Directories – enumerate files and folders in a Web site using SharePoint Designer and Web DAV (Distributed Authoring and Versioning) interfaces.
- View Pages – view pages in a Web site.
- Enumerate Permissions – enumerate permissions on the Web site, list, folder, document, or list item.
- Browse User Information – view information about users of the Web site.
- Manage Alerts – manage alerts for all users of the Web site.
- Use Remote Interfaces – use SOAP, (Simple Object Access Protocol) Web DAV, or SharePoint Designer interfaces to access the Web site.
- Use Client Integration Features – use features that launch client applications. Without this permission, users will have to work on documents locally and upload their changes.
- Open – allows users to open a Web site, list, or folder in order to access items inside that container.
- Edit Personal User Information – allows a user to change his or her own user information, such as adding a picture.
Personal Permissions:
- Manage Personal Views – create, change, and delete personal views of lists.
- Add/Remove Personal Web Parts – add or remove personal Web Parts on a Web Part Page.
- Update Personal Web Parts – update Web Parts to display personalized information.
Armed with that information, you’re now in a position to try to create a new security group and give a person or a group of people a different level of access from what they had previously.
Sunday, 24 October 2010
Mainframe security
RACF (Resource Access Control Facility) from IBM has been around for so long that I guess we take it for granted. It is one of the “big three” External Security Manager (ESM) products for mainframes. The other two are ACF2 (Access Control Facility 2) and Top Secret, both of which are owned by CA. But, as they like to say on impartial radio and TV programmes, other security products are available!
For example, Alexandria, Virginia-based Type80 (www.type80.com) provides SMA_RT, which functions as a security monitor program product that looks for patterns of abuse and sends real-time alerts. It supports systems environments across multiple CPUs and over geographically diverse locations.
Las Vegas, Nevada-based Vanguard Integrity Professionals (www.go2vanguard.com) provides solutions for identity and access management, audit and compliance, security administration, and intrusion detection. For security management there’s Vanguard Administrator, Vanguard Advisor, and Vanguard SecurityCenter. For audit and compliance they provide Vanguard Analyzer, Vanguard incompliance, Vanguard Enforcer, and Vanguard Policy Manager. For access management there’s Vanguard Authenticator, Vanguard ez/SignOn, Vanguard ez/Token, Vanguard Tokenless Authentication, Vanguard ez/Integrator, and Vanguard PasswordReset. And for intrusion detection there’s Vanguard Enforcer (again).
Naples, Florida-based Advanced Software Products Group (ASPG) (www.aspg.com) provides a number of data security products including: MegaCryption, its file level encryption tool; ReACT, which automates the password reset and synchronization process; ERQ (Easy RACF Query), its automated ISPF RACF administrative and reporting utility; CryptoMon its ICSF analyser; and Secure/FTP, which provides a full audit trail of all FTP commands that were executed or attempted and offers online monitoring of all active FTP sessions.
While mentioning encryption, IBM has its Integrated Cryptographic Service Facility (ICSF) and a Cryptographic Coprocessor. And, of course, in terms of security, there’s also IBM’s Tivoli zSecure Suite.
Hackensack, NJ-based Bsafe Solutions (www.bsafesolutions.com) offers: Bsafe/Enterprise Security for MVS TCP/IP for network security; Bsafe/Security for CICS-MVS, providing extended security for DB2, IMS, and VSAM; and Bsafe/Enterprise Security for CICS, providing control of mainframe security from a PC.
Torrance, CA-based Data21 (www.data21.com) has ZIP/390, which enables zSeries batch jobs to send and receive PGP (Pretty Good Privacy) files.
Aliso Viejo, CA-based Quest Software (www.quest.com) has a number of security products that came with its acquisition of PassGo Technologies. Its mainframe security tools include: GoPlex, a full screen interface allowing users to control and view users logged on to any of the PassGo’s MultSess, NC-Access, or NCI/XF products; NC-Pass Network Security Managers, which protect information by directing the user to permitted applications only using their user ID and password; Defender ME uses tokens that provide security – there’s Defender ME VSSE for VTAM Session Security, Defender ME Secure for active network security, and Defender ME Authenticator for almost everything; NC-Syncom provides password synchronization spanning multiple systems, servers, networks, and applications; and NC-Access, a session manager. In addition, for VTAM networks, Quest provides: MultSess, a session manager; and NCI/XF, a programming tool for tailoring, customizing, and extending functionality for 3270 terminals and developing single point of entry VTAM network systems.
There’s definitely other mainframe software products out there, and it’s interesting to see just what is available.
For example, Alexandria, Virginia-based Type80 (www.type80.com) provides SMA_RT, which functions as a security monitor program product that looks for patterns of abuse and sends real-time alerts. It supports systems environments across multiple CPUs and over geographically diverse locations.
Las Vegas, Nevada-based Vanguard Integrity Professionals (www.go2vanguard.com) provides solutions for identity and access management, audit and compliance, security administration, and intrusion detection. For security management there’s Vanguard Administrator, Vanguard Advisor, and Vanguard SecurityCenter. For audit and compliance they provide Vanguard Analyzer, Vanguard incompliance, Vanguard Enforcer, and Vanguard Policy Manager. For access management there’s Vanguard Authenticator, Vanguard ez/SignOn, Vanguard ez/Token, Vanguard Tokenless Authentication, Vanguard ez/Integrator, and Vanguard PasswordReset. And for intrusion detection there’s Vanguard Enforcer (again).
Naples, Florida-based Advanced Software Products Group (ASPG) (www.aspg.com) provides a number of data security products including: MegaCryption, its file level encryption tool; ReACT, which automates the password reset and synchronization process; ERQ (Easy RACF Query), its automated ISPF RACF administrative and reporting utility; CryptoMon its ICSF analyser; and Secure/FTP, which provides a full audit trail of all FTP commands that were executed or attempted and offers online monitoring of all active FTP sessions.
While mentioning encryption, IBM has its Integrated Cryptographic Service Facility (ICSF) and a Cryptographic Coprocessor. And, of course, in terms of security, there’s also IBM’s Tivoli zSecure Suite.
Hackensack, NJ-based Bsafe Solutions (www.bsafesolutions.com) offers: Bsafe/Enterprise Security for MVS TCP/IP for network security; Bsafe/Security for CICS-MVS, providing extended security for DB2, IMS, and VSAM; and Bsafe/Enterprise Security for CICS, providing control of mainframe security from a PC.
Torrance, CA-based Data21 (www.data21.com) has ZIP/390, which enables zSeries batch jobs to send and receive PGP (Pretty Good Privacy) files.
Aliso Viejo, CA-based Quest Software (www.quest.com) has a number of security products that came with its acquisition of PassGo Technologies. Its mainframe security tools include: GoPlex, a full screen interface allowing users to control and view users logged on to any of the PassGo’s MultSess, NC-Access, or NCI/XF products; NC-Pass Network Security Managers, which protect information by directing the user to permitted applications only using their user ID and password; Defender ME uses tokens that provide security – there’s Defender ME VSSE for VTAM Session Security, Defender ME Secure for active network security, and Defender ME Authenticator for almost everything; NC-Syncom provides password synchronization spanning multiple systems, servers, networks, and applications; and NC-Access, a session manager. In addition, for VTAM networks, Quest provides: MultSess, a session manager; and NCI/XF, a programming tool for tailoring, customizing, and extending functionality for 3270 terminals and developing single point of entry VTAM network systems.
There’s definitely other mainframe software products out there, and it’s interesting to see just what is available.
Subscribe to:
Posts (Atom)