Sponsors

Tuesday, October 13, 2009

Information Security For Small Business

 The following is a SlideShare I first presented via a live online webinar for the Orlando, FL chapter of the BDPA.

"IT INCLUDES VIDEO ON SMALL BUSINESS SECURITY BY NIST SECURITY PROFESSIONALS AT THE END OF PRESENTATION!

If you are a small business with need of Information Security knowledge. Review this presentation and if you need help protecting your critical systems or data contact me.

Enjoy,

Julius Clark

Information Security for Small Business

Tuesday, October 6, 2009

The Unemployed Information Security Professional: How To Keep Your Skills Sharp






Former Chairman of the U.S. Federal Reserve, Alan Greenspan, yesterday when asked for a statement regarding the recovery of the nation's economy said; "expect unemployment to reach 10 percent and hover there for awhile."




He said this is of concern because the longer people are unemployed, they start to loose their job skills. To help Information Security professionals who are unemployed retain their skills I suggest the following:


10 Things for the Unemployed Information Technology Security Professional to Do To Stay Competitive When Between Jobs

  1. Review all of the IT Security Information you can for Microsoft's new Windows 7 .Operating System; you will be ahead of most security professionals in this area if you do.
  2. Refresh your knowledge of the SANS TOP 20 vulnerabilities; the most critical of IT Security vulnerabilities.
  3. Refresh your knowledge of NIST.gov IT Security Control Guidelines; in-depth information about security controls and countermeasures; most company's use some adaptation of NIST security guidelines.
  4. Review CCCure.org's FREE security training videos and test quizzes; can't believe this resource is free! Incrdible!
  5. Studying for a highly sought after Information Security Certification; gaining a cert will help market yourself to prospective employers.
  6. View free online IT Security Webinars; easy way to get cutting edge training.
  7. Become a speaker for other professional organizations on IT Security topics.
  8. Participate in LinkedIn Group discussions and answer questions related to IT Security; become an IT Security Thought Leader!
  9. Volunteer on an IT Security organization's Board and/ or volunteer your time teaching Computer/ Internet Security to schools or non-profit agencies; great networking opportunities.
  10. Take advantage of the time and consider creating a business plan and start an IT Security consultancy; market your services to local businesses or non-profits who normally don't have access to expert security professionals.
Best of luck,


Julius Clark, MBA, CISSP, CISA








, , ,

Tuesday, September 29, 2009

Anatomy of A Failed Nigerian Email Fraud Scam







On Monday, September 28, 2009, I received an email from what first appeared to be a prospective client responding to my Craigslist.com ad for IT Services. It did not take long for me to verify that the individual on the other end was an Internet Cyber Criminal attempting to commit fraud, and decided that I would be their next careless victim. So to educate the public and to have a little fun, I put on my Information Security Professional hat and played along so I could write a really cool Clark Thought Leadership blog on Email Frauds and Scams.


Anatomy of A Failed Nigerian Email Fraud Scam

  Clark Thought Leadership Security Work Blog


9/28/2009 10:00 PM

Information Security Professional receives email solicitation from an individual responding to a Craigslist.com ad for IT Services. Information Security Professional performed screen captures of all email correspondence with solicitor to be used as evidence and saved in this blog. See below.

(To enlarge, click on image)





9/28/2009 10:02 PM

Information Security Professional performed a Google search of the following line contained in the solicitor's email: 
"I got your contact On Craigslist.org and i was just checking if you will be available to repair and install some applications"


Information Security Professional saved the information obtained by the Google search in a screen capture and saved as evidence in the blog. See below.

(To enlarge, click on image)


Information Security Professional inspected the web page of the first link retrieved in the Google search:

  • http://www.blackgate.net/blog/scam-warning-computer-repairer-installer-needed/.

 Information Security Professional observed that the web page link was a blog called Black Vituperative with an article titled:

  • Scam warning: “Computer Repairer & Installer Needed”.
After Inspection of the web link mentioned above, Information Security Professional determined that web link was a blog article warning about a particular type of email scam. Additionally, Information Security Professional concluded that the sentences from the inspected web page and the information in the email received by the solicitor matched and contained similar information.



9/28/2009 10:06 PM

Information Security Professional responds to solicitor's email.



9/29/2009 10:08 PM

Information Security Professional receives reply from solicitor. Information Security Professional inspected the email and determined that the solicitor replied using an email address, which was different from their initial email solicitation. See below.

(To enlarge, click on image)





9/28/2009 10:20 PM

Information Security Professional replied to solicitor in an attempt to have them visit the Clark Leadership Blog, which could be used as a detective control to potentially determine the solicitor's true location.

Note: The Clark Thought Leadership blog uses the StatCounter.com service to track Internet visitor statistics. The data stored on StatCounter.com is secure from unauthorized access. See below.

(To enlarge, click on image)






9/28/2009 10:25 PM

Internet Security Professional receives reply from solicitor acknowledging that they visited the Clark Thought Leadership blog. See below.


(To enlarge, click on image)


9/28/2009 10:21 PM

Information Security Professional replied back to solicitor quoting a price for their service request.



9/28/2009 10:35 PM

Information Security Professional receives reply from solicitor agreeing to the quoted price. See below.


9/28/2009 10:21 PM

Information Security Professional logged in to the StatCounter.com dashboard page to inspect the tracking information for the Clark Thought Leadership blog. Information Security Professional performed screen captures of the StatCounter logs and saved them to the blog as evidence. See below.

(To enlarge, click on image)
StatCounter Image 1


(To enlarge, click on image)
StatCounter Image 2


(To enlarge, click on image)
StatCounter Image 3




Information Security Professional created a table called Visitor Analysis and placed the StatCounter data into it. See below.


Visitor Analysis
Date
September 29, 2009
Time
10:21 PM
IP Address
41.189.0.139
Continent
Africa
Country
Nigeria
Region
Lagos
City
Lagos
ISP
Swift Networks Ltd.
Visitor Path
Julius-clark.blogspot.com


Information Security Professional created a table called Visitor System Specifications and placed the StatCounter data into it. See below.



Visitor System Specifications
Browser
Firefox 3.5
Operating System
Microsoft Windows XP
Monitor Resolution
1024 x768
Javascript
Enabled

  9/28/2009 10:40 PM

Information Security Professional received reply from solicitor agreeing to the price quoted. Additionally, the solicitor requested that my personal information was needed to send a Certified Check to me. See Below.

(To enlarge, click on image)



After Inspection of all the information contained in table above, Information Security Professional determined that the solicitor gave false information in the email about their location being in Panama City, Panama. Inspection by Information Security Professional determined that solicitor was operating from within the city of Lagos, Nigeria, which is located on the continent of Africa.


9/29/2009 2:56 PM

Information Security Professional performed a search of the Arin.net Who Is search database and performed a screen capture and saved it to the blog as evidence. See below.

(To enlarge, click on image)



Information Security Professional created a table of the Who Is data and the information for the scope of this blog into a table. See below.

ARNT.net Who IS Data of Email Solicitor
Domain
Afrinic.net
Registration Date
April 12, 2005
Registration Last Updated
May 5, 2009
Address 1
03B3 3rd Floor Ebene Cyber Tower
Address 2
Cyber City
City
Ebene/ Mauritius
Phone Number
+230 4666616
Email to Report Abuse
abusepoc@afrinic.net


Findings

After inspection of the evidence from above, Information Security Professional has determined that the solicitor is an Internet Cyber Criminal, who was attempting to commit a fraud for monetary gain. Information reported in this blog article will be reported to the proper legal authorities.



9/29/2009

Internet Security Professional reported the attempted criminal activity to the Internet Cyber Crime Center (IC3). IC3 is a partnership between the Federal Bureau of Investigations (FBI) and White Collar Crime Center (NW3C).


Note: IC3 was established as a partnership between the NW3C to serve as a means to receive Internet related criminal complaints and to further research, develop, and refer the criminal complaints to federal, state, local, or international law enforcement and/or regulatory agencies for any investigation they deem to be appropriate.


(To enlarge, click on image)

Enjoy,

Julius, MBA, MSIS, CISSP, CISA

Thanks to my boy Lawrence Belton, CISSP, for providing some Thought Leadership for this blog article!


Below is the email sent by solicitor in ASCII format



Greetings,

I got your contact On Craigslist.org and i was just checking if you
will be available to repair and install some applications on(13) PC ..
Get back to me for details if you'll be available.As soon as possible.


Thanks.


Kind Regards.




++++++++++++++++++++++++++++++++++++++++++++++++++++





Hello ,




How you doing?  


I read your description and i am highly impressed in your services,I have some Hp PCs(Intel Pentium IV) since we currently have a major breakdown on most of our systems and I thought it was best to have a general upgrade and maintenance.(I will be providing the software needed).Below are the things needed to be done one on each laptops:


1 Format Hard Drive
2 Install Win Xp with Service Pack 2
3 Microsoft Office Package
4 AVG Virus Software (Free Lifetime Updates)
5 Adobe Acrobat
6 Laptop Cleaning of the keyboard, screen and other case.
7 Diagnostics of the entire system after to check hard, CD Rom, floppy, etc.


I will like You to know that my mode of payment is by US certified check mailed and address to you from my employer company since I am presently on a business workshop in Panama city,South American and i want you to know that i will handle the shipment myself since i have a shipper from the state here that will bring the laptops to your place,and will come pick them up as soon as you are done with them.


I should have make this a phone order but i have a network problem of where i am and my shipper will be coming with the necessary Software for the installations of the Computers with both the Operating System,Microsoft Office and the Anti-virus for each computers .


However,get back to me with your last asking price for the 11 laptops. I await your urgent response so that i can put the arrangement in order.


Thanks and hope to read from you soon.

Friday, September 25, 2009

Amazing Social Media Icons



Great Social Media Icons All In One Place

If you are like me while on your Social Media Journey you have found yourself spending some time performing web searches to find Social Media Icons for popular sites like Facebook, LinkedIn and Twitter.

So to help others I found several great sites that have a huge assortment of Social Media icons and other fantastic looking icons.

Type of Social Media Icons Available:

  • Different Shaped Icons
  • Hand Drawn Icons
  • Mini Icons
  • Caricature Style Icons
Tutorials On Creating Icons

Great Social Media Icon Sites

The Best Social Media Icons All In One Place

  • http://webdesignledger.com/freebies/the-best-social-media-icons-all-in-one-place
600+ Free Design, Twitter and Social Media Icons: A Collection Motherload!

50 Free High-Quality Icon Sets



Enjoy,

Julius

Wednesday, September 23, 2009

McGruff SafeGaurd Monitors Your Kids Internet Activity



Free Trusted Service to Monitor Your Kids Internet Activity.

McGruff Internet Safety for Parents
Take a bit out of Internet Safety

The Internet is full of perils that kids can fall prey to. Do you as a parent worry about what your child is doing on the Internet? Who they chat with, what they are chatting about, the amount of time they spend on the Internet? Your worry list can become extremely long. You remember McGruff the crime dogs? Parents should remember McGruff's very popular phrase growing while growing up as a child themselves; "take a bite out of crime".

McGruff is now taking a bite out of Internet Safety and offering a FREE service for parents to monitor you're their kids Internet activity.

Free Features

  1. Its basic features are permanently Free!
  2. It installs invisibly on your child's computer and you never have to go back to the computer to review the sites and conversations. You monitor your child's activity from another computer and the service is password protected and secure.
  3. It has an easy to use control panel to monitor & block your child's Internet activities.


  4. Monitors:
    1. • All website visits
      • MySpace/Facebook and social network activity
      • Chat and instant message conversations
      • Search engine phrases
      • Emails sent on popular systems, including AOL, Yahoo, MSN and Hotmail
      • Tracks total hours spent online





  5. Alerts:

    1. • Intelligent monitoring automatically alerts you by email to potential danger
      • Get daily summary of activity
      • Report predators directly to Law Enforcement
      • Auto-monitors for hundreds of dangerous phrases
      • Create your own custom alerts




  6. Search:

    1. • Your child's activity by keyword and date
      • Your child's activity by buddy name


For the Ultimate Level of Protection

The free version of McGruff SafeGuard is great for basic monitoring, but many parents want more. McGruff SafeGuard Plus gives you the highest level of parental monitoring available.

Upgrade-only features include:

  • Get danger Alerts via cell phone
  • Grab passwords from social networks and other websites
  • Email, print, copy & paste activity
  • Receive daily email with all chat conversations
  • Receive weekly summary report of all activity
  • Schedule pre-set times for kids to use the PC
  • View activity up to 30 days old
  • Block inappropriate websites

Screen Shot of Parental Monitoring Console








To review the service go and vist McGruff's website:

http://www.gomcgruff.com

Protect your children and help them to properly enjoy their Internet experience!


Sincerely,


Julius

Thursday, September 3, 2009

Choose The Right Web Browser For The Right Activity: I Will Show You How



Choosing the right Internet Web Browser is similar to choosing the right tool out of a tool box to do a job.

Keeping this simple I recommend that you use the top three Internet Browsers; in my opinion, for the following jobs. The following is my personal order of preference.

Stability & Security - Firefox

  • Worldwide Firefox Browser Market Share as of Sept 2009; Currently 31.2% , up from 26.08% same time last year.
  • Use the Firefox browser mainly for stability and most importantly when you want added security protection for activities such as online banking, credit card payments, email and other activities that require you to safeguard your confidentiality.
Performance - Google Chrome

  • Worldwide Google Chrome Browser Market Share as of Sept 2009; Currently 3.4% , up from 0% same time last year.
  • Use Google Chrome when you demand performance from your web browser. Pages load much faster with Google Chrome, especially when using Social Networking sites like Facebook and MySpace.
Compatibility - Microsoft Internet Explorer

  • Worldwide Browser Internet Explorer Market Share as of Sept 2009; currently 58.83% down from 68.91% same time last year.
  • Use Internet Explorer when you need to be compatible the majority of sites on the internet and especially corporate intranets. IE's market share has been steadily dwindling due to the browsers mentioned above, but it is still the dominate browser because Microsoft Windows operation systems run on over 80% of the worlds PCs, and the IE browser already comes installed on it.
Enjoy,

Julius, MBA, CISSP, CISA

Reference

http://gs.statcounter.com/#browser-ww-monthly-200808-200909

Monday, August 17, 2009

Want To Become A Cyber Warrior?



Cyber security has become critical as our lives are being placed more and more on the Internet and interconnected computing systems. Therefore, it will take an army of skilled new comers to the Information Security field to protect and defend internet & computer usage for society.

One solution to satisfy the need

The US Cyber Challenge

Mission

Encouraging young people to develop the aptitude and skills to become the core of a strong cybersecurity community.



The US Cyber Challenge is looking for 10,000 young Americans with the skills to fill the ranks of cyber security practitioners, researchers, and warriors. Some will become the top guns in cyber security. The program will nurture and develop their skills, give them access to advanced education and exercises, and where appropriate, enable them to be recognized by colleges and employers where their skills can be of the greatest value to the nation.

Competitions Available

Digital Forensics Skills learned by youth

  • Challenges with a solution well known to experienced examiners (e.g. File Signatures, Suspicious Software, Hashing Metadata, etc.)
  • Challenges with a solution, but having a degree of difficulty (e.g. Data Hiding, File Headers, Passwords, Registry, etc.)
  • Difficult challenges that may have a solution, but it is not well known (e.g. Encryption, Parsing, etc.)
  • Challenges with no known solution (e.g. Communication Recovery/Parsing, Concealment of information within computer files, etc.)
Outcome

Finally, the best of the candidates will be brought into federal agencies like the National Security Agency, the FBI, DoD DC3, US‐CERT, and US Department of Energy Laboratories, all of which are helping to make this program effective.


To enable employers to find promising candidates, the program will include a web site where outstanding candidates from this challenge and other related challenges are illuminated with profiles in common, easy‐to‐assess formats. No names will be provided to ensure candidate privacy, but when reputable employers find candidates.

References:

http://www.sans.org/netwars/

http://www.bankinfosecurity.com/articles.php?art_id=1656

http://www.whitehouse.gov/files/documents/cyber/The%20United%20States%20Cyber%20Challenge%201.1%20(updated%205-8-09).pdf

http://csis.org/uscc

Wednesday, August 12, 2009

The Security Triad


For those interested in getting in to the Information Security Field, you must first become aware of the Security Triad. You goal as an Information Security Professional is to ensure CIA.

C.I.A.

  • Confidentiality
  • Integrity
  • Accessibility

Social Media, Your Party


For those building a Brand. Social Media should be fun, its a party among friends of friends. You never have to hear again: "you should of been there". Mix up your conversations so you don't bore your guests and build your network of people who will tell others about the cool parties you host!

Five Practical Tips for Performing Risk Assessments


I cam across CISOHandbook.com and found this site to be very informative and easy to read for Information Security Professionals. The following article stood out and I decided to share it on my blog.


Five Practical Tips for Performing Risk Assessments


by Mike Gentile, Ron Collette, and the CISOHandbook.com Team

Preface:

Risk Assessments are one of the most powerful tools in the arsenal of the security professional. They provide tremendous value when performed correctly, but can have severely detrimental effects when they are not. This article will provide some quick and easy considerations for getting the most out of them within your environment.


1. Measure the Scope of the Risk Assessments That You are Currently Conducting

Most current security programs conduct some form of risk assessment on a regular basis. The issue arises when all risk assessments are treated as identical. For example, an enterprise-wide risk assessment that focuses solely on risks within applications is vastly different than a risk assessment that evaluates risks associated with the operating system on one server for an individual business unit. Though this may seem obvious, in our experience many people within security programs and especially people outside of them still view risk assessments as the same thing regardless of scope. This can lead to gaps between what is expected of the review (from a risk perspective) and what was actually reviewed. Additionally, this can often lead to difficulties with trending of risk over time, another important item we will talk more about in a minute.

2. Use Risk Assessments to Enable Business Decisions

We believe one of the strongest uses for risk assessments is to provide a business with the right type of information regarding security risks in order to enable informed business decision. This is the objective of a risk assessment. In your risk assessments, be sure to focus the message so that they can be consumed by those that do not understand the nuances of security. So in other words, put the reports from risk assessments in business speak, not security jargon.

3. Make a Conscious Decision Regarding the Risk Model Employed in the Assessment

This one becomes especially important if your organization relies upon vendors to perform the assessment. Vendors can be valuable in terms of providing the necessary skill-sets, but there are also some downsides. Vendors often bring proprietary risk evaluation techniques and unique nomenclature to their deliverables. The use of unique terms, language, or techniques can add confusion to the message delivery process, particularly those that are not security focused. A classic example in these situations is the frustration a vendor feels when the client fails to understand the message and value of their work. The other danger to using proprietary risk methodologies and nomenclature is that it commits the organization to its continued use in order to facilitate useful trending information.

4. Focus on the Trending Elements of the Risk Assessment

One of the most important elements of measuring risk is to demonstrate the changes within an organization over time. By the way, we did not make these rules, we bring this one up because we have never, and we mean never, met a Board of Directors or Management Team who have not wanted some type of trending after they review assessment data. It is just the way it is.

Even slight variances in the type of assessment or methodology employed can negatively influence the trending characteristics of the data. When an assessment does not have the capability for tending, it often leads others to question the credibility of the analysis. It can also put you in a bind if you get a request for trending, but can't deliver because of the data you collected or the type of assessment.

When designing an assessment, focus on meaningful forms of measurement that will enable future trending. This is usually best accomplished by taking the time to identify what you want to measure first, and then build an assessment to meet those needs. This should seem simple because it is. When you do not take the time up front, your end result can be much more painful.

5. Ensure the Goal Matches the Approach of the Assessment

Another easy one, but this piece of advice is often missed. Before performing any type of risk assessment, try to establish the primary goals and objectives for the assessment and the future use of the information. A useful technique to aid in this exercise is to identify what you believe the result of the assessment will be by your target audience before performing any work. We have witnessed many occasions where a security officer has gotten themselves into hot water by not considering the end result of their use of an assessment prior to its implementation. They begin by attempting to bring awareness to a security weakness in a particular area, only to find that not only did they get awareness to the issue, but also highly angered the decisions makers in that area through the negative publicity. In these situations, if they simply were more careful in how they approached the assessment, either in its design or approach, they could save themselves a lot of unnecessary trouble and make it easier to reach their true assessment goals. By the way, we are not saying that you should avoid the use of risk assessments, in fact quite the contrary. Just be sure to consider your goals for using one and whether the end result of the review will meet those objectives. In other words, think it through or it can be career limiting.

Conclusion

There is obviously a multitude of ways to approach a risk assessment, but hopefully this will provide you a couple of tips in aiding your efforts when conducting one for you organization.

Get Expert Advice!