Sponsors

Monday, August 17, 2009

Want To Become A Cyber Warrior?



Cyber security has become critical as our lives are being placed more and more on the Internet and interconnected computing systems. Therefore, it will take an army of skilled new comers to the Information Security field to protect and defend internet & computer usage for society.

One solution to satisfy the need

The US Cyber Challenge

Mission

Encouraging young people to develop the aptitude and skills to become the core of a strong cybersecurity community.



The US Cyber Challenge is looking for 10,000 young Americans with the skills to fill the ranks of cyber security practitioners, researchers, and warriors. Some will become the top guns in cyber security. The program will nurture and develop their skills, give them access to advanced education and exercises, and where appropriate, enable them to be recognized by colleges and employers where their skills can be of the greatest value to the nation.

Competitions Available

Digital Forensics Skills learned by youth

  • Challenges with a solution well known to experienced examiners (e.g. File Signatures, Suspicious Software, Hashing Metadata, etc.)
  • Challenges with a solution, but having a degree of difficulty (e.g. Data Hiding, File Headers, Passwords, Registry, etc.)
  • Difficult challenges that may have a solution, but it is not well known (e.g. Encryption, Parsing, etc.)
  • Challenges with no known solution (e.g. Communication Recovery/Parsing, Concealment of information within computer files, etc.)
Outcome

Finally, the best of the candidates will be brought into federal agencies like the National Security Agency, the FBI, DoD DC3, US‐CERT, and US Department of Energy Laboratories, all of which are helping to make this program effective.


To enable employers to find promising candidates, the program will include a web site where outstanding candidates from this challenge and other related challenges are illuminated with profiles in common, easy‐to‐assess formats. No names will be provided to ensure candidate privacy, but when reputable employers find candidates.

References:

http://www.sans.org/netwars/

http://www.bankinfosecurity.com/articles.php?art_id=1656

http://www.whitehouse.gov/files/documents/cyber/The%20United%20States%20Cyber%20Challenge%201.1%20(updated%205-8-09).pdf

http://csis.org/uscc

Wednesday, August 12, 2009

The Security Triad


For those interested in getting in to the Information Security Field, you must first become aware of the Security Triad. You goal as an Information Security Professional is to ensure CIA.

C.I.A.

  • Confidentiality
  • Integrity
  • Accessibility

Social Media, Your Party


For those building a Brand. Social Media should be fun, its a party among friends of friends. You never have to hear again: "you should of been there". Mix up your conversations so you don't bore your guests and build your network of people who will tell others about the cool parties you host!

Five Practical Tips for Performing Risk Assessments


I cam across CISOHandbook.com and found this site to be very informative and easy to read for Information Security Professionals. The following article stood out and I decided to share it on my blog.


Five Practical Tips for Performing Risk Assessments


by Mike Gentile, Ron Collette, and the CISOHandbook.com Team

Preface:

Risk Assessments are one of the most powerful tools in the arsenal of the security professional. They provide tremendous value when performed correctly, but can have severely detrimental effects when they are not. This article will provide some quick and easy considerations for getting the most out of them within your environment.


1. Measure the Scope of the Risk Assessments That You are Currently Conducting

Most current security programs conduct some form of risk assessment on a regular basis. The issue arises when all risk assessments are treated as identical. For example, an enterprise-wide risk assessment that focuses solely on risks within applications is vastly different than a risk assessment that evaluates risks associated with the operating system on one server for an individual business unit. Though this may seem obvious, in our experience many people within security programs and especially people outside of them still view risk assessments as the same thing regardless of scope. This can lead to gaps between what is expected of the review (from a risk perspective) and what was actually reviewed. Additionally, this can often lead to difficulties with trending of risk over time, another important item we will talk more about in a minute.

2. Use Risk Assessments to Enable Business Decisions

We believe one of the strongest uses for risk assessments is to provide a business with the right type of information regarding security risks in order to enable informed business decision. This is the objective of a risk assessment. In your risk assessments, be sure to focus the message so that they can be consumed by those that do not understand the nuances of security. So in other words, put the reports from risk assessments in business speak, not security jargon.

3. Make a Conscious Decision Regarding the Risk Model Employed in the Assessment

This one becomes especially important if your organization relies upon vendors to perform the assessment. Vendors can be valuable in terms of providing the necessary skill-sets, but there are also some downsides. Vendors often bring proprietary risk evaluation techniques and unique nomenclature to their deliverables. The use of unique terms, language, or techniques can add confusion to the message delivery process, particularly those that are not security focused. A classic example in these situations is the frustration a vendor feels when the client fails to understand the message and value of their work. The other danger to using proprietary risk methodologies and nomenclature is that it commits the organization to its continued use in order to facilitate useful trending information.

4. Focus on the Trending Elements of the Risk Assessment

One of the most important elements of measuring risk is to demonstrate the changes within an organization over time. By the way, we did not make these rules, we bring this one up because we have never, and we mean never, met a Board of Directors or Management Team who have not wanted some type of trending after they review assessment data. It is just the way it is.

Even slight variances in the type of assessment or methodology employed can negatively influence the trending characteristics of the data. When an assessment does not have the capability for tending, it often leads others to question the credibility of the analysis. It can also put you in a bind if you get a request for trending, but can't deliver because of the data you collected or the type of assessment.

When designing an assessment, focus on meaningful forms of measurement that will enable future trending. This is usually best accomplished by taking the time to identify what you want to measure first, and then build an assessment to meet those needs. This should seem simple because it is. When you do not take the time up front, your end result can be much more painful.

5. Ensure the Goal Matches the Approach of the Assessment

Another easy one, but this piece of advice is often missed. Before performing any type of risk assessment, try to establish the primary goals and objectives for the assessment and the future use of the information. A useful technique to aid in this exercise is to identify what you believe the result of the assessment will be by your target audience before performing any work. We have witnessed many occasions where a security officer has gotten themselves into hot water by not considering the end result of their use of an assessment prior to its implementation. They begin by attempting to bring awareness to a security weakness in a particular area, only to find that not only did they get awareness to the issue, but also highly angered the decisions makers in that area through the negative publicity. In these situations, if they simply were more careful in how they approached the assessment, either in its design or approach, they could save themselves a lot of unnecessary trouble and make it easier to reach their true assessment goals. By the way, we are not saying that you should avoid the use of risk assessments, in fact quite the contrary. Just be sure to consider your goals for using one and whether the end result of the review will meet those objectives. In other words, think it through or it can be career limiting.

Conclusion

There is obviously a multitude of ways to approach a risk assessment, but hopefully this will provide you a couple of tips in aiding your efforts when conducting one for you organization.

Friday, July 24, 2009

Top 20 List of Most Critical Cyber Security Controls


The twenty controls were agreed upon by by cyber security experts from various Federal Government agencies.



Note: The list of controls includes fifteen that are able to be validated in an automated manner and five that must be validated manually.

Consensus Audit Guideline Controls



Critical Controls Subject to Automated Measurement and Validation:

1: Inventory of Authorized and Unauthorized Hardware.

2: Inventory of Authorized and Unauthorized Software.

3: Secure Configurations for Hardware and Software on Laptops, Workstations, and Servers.

4: Secure Configurations of Network Devices Such as Firewalls and Routers.

5: Boundary Defense 5

6: Maintenance and Analysis of Complete Security Audit Logs

7: Application Software Security

8: Controlled Use of Administrative Privileges

9: Controlled Access Based On Need to Know

10: Continuous Vulnerability Testing and Remediation

11: Dormant Account Monitoring and Control

12: Anti‐Malware Defenses

13: Limitation and Control of Ports, Protocols and Services

14: Wireless Device Control

15: Data Leakage Protection

Additional Critical Controls (not directly supported by automated measurement and validation):

16. Secure Network Engineering

17. Red Team Exercises

18. Incident Response Capability

19. Data Recovery Capability

20. Security Skills Assessment and Training to Fill Gaps



The controls above were agreed upon by knowledgeable individuals from the Federal Government entities listed below.



Contributing Federal Groups:



  • Red team members in NSA tasked with finding ways of circumventing military cyber defenses
  • Blue team members at NSA who are often called in when military commanders find their systems have been compromised
  • US‐CERT and other non‐military incident response employees and consultants who are called upon by civilian agencies and companies to identify the most likely method by which the penetrations were accomplished
  • Military investigators who fight cyber crime
  • Cybersecurity experts at US Department of Energy laboratories and Federally Funded Research and Development Centers (FFRDCs).
  • DoD and private forensics experts who analyze computers that have been infected
  • Civilian penetration testers who test civilian government and commercial systems to find how they can be penetrated
  • Federal CIOs and CISOs who have intimate knowledge of cyber attacks
  • The Government Accountability Office (GAO)


Reference:

http://csis.org/files/media/csis/pubs/090223_cag_1_0_draft4.1.pdf

Monday, July 20, 2009

Share Files Effortlessly over the Internet with RapidShare



You ever want to share a file with friends or collaborators effortlessly without having to the person to logon or share login information?

RapidShare.com allows you to upload files then share the link with others so they can download the file to their computer.

RapidShare is a free service, but based on the file size, users of the free service must wait 30- 140 seconds before the download starts. Customers who pay for instant access to uploaded files can download immediately.

According to WikiPedia, RapidShare.com is a German owned company with its servers hosted in Switzerland. RapidShare has grown to be one of the largest File hosting service sites and the 17th most visited site on the internet.

Enjoy!

Julius





Wednesday, July 15, 2009

Merchants and Wireless Security


Merchants Have New Guidelines to protect Cardholder Data from the risks of Using Wireless Technology.

The PCI Counsel issued new PCI Wireless Guidelines This week. Some of the new changes are as follows:

1. Perform a security risk assessment of merchant's environment prior to implementation and using findings to design controls to mitigate discovered risks.

2. Mount Wireless Devices on ceiling if possible to reduce the risk of unauthorized access to the device physically disable console interface and use a tamper proof chassis.

3. The Wireless device must sit on the outer edge of the merchant's network, meaning that all wireless traffic must flow through a firewall before entering network with Card Holder Data flowing or is stored.

4. Only non-sensitive information should be allowed to go through the wireless device.

5. AES encryption is the recommended encryption method. WEP encryption makes the Vendor non-compliant to PCI Standards.

6. Businesses must conduct a wireless assessment to detect active rouge wireless devices quarterly and implement security measures to reduce risks from them. Large organizations must set up automatic scanning and have an updated incident response plan to handle rouge wireless devices when detected.

7. Change the default settings like: Administrative passwords, encryption settings, reset function, disable SNMP access if possible. Do not advertise or organization names in the SSID transmission.

8. A Wireless usage policy should be established for "explicit management approval to used wireless networks on the same network where cardholder data flows or is stored.

These guidelines will help merchants better protect cardholder data while allowing them to benefit from wireless technology.



PCI Standards Guideline can be found at:

https://www.pcisecuritystandards.org/security_standards/download.html?id=pci_dss_v1-1.pdf

Network World Article:

http://www.networkworld.com/news/2009/071509-pci-wireless-guidelines.html?page=2

Friday, June 19, 2009

Microsoft Windows Malicious Software Removal Tool


The Microsoft Windows Malicious Software Removal Tool checks computers running:

  • Windows Vista;
  • Windows XP;
  • Windows 2000;
  • Windows Server 2003;

for infections by specific, prevalent malicious software—including Blaster, Sasser, and Mydoom—and helps remove any infection found. When the detection and removal process is complete, the tool displays a report describing the outcome, including which, if any, malicious software was detected and removed.

Having an anti-virus program installed and by running this tool occasionally, will help you achieve some effective results on some prominent malicious software that attacks your computer.

This software tool deals with malware differently than anti-virus software, because it removes the most prominent malicious software from a PC that is infected and actively running on a PC. Anti-Virus software is good at the quarantine of a malicious program, but sometimes cannot remove it completely form an infected computer.


Microsoft releases an updated version of this tool on the second Tuesday of each month, and as needed to respond to security incidents. The tool is available from Microsoft Update, Windows Update and the Microsoft Download Center.

Because computers can appear to function normally when infected, Microsoft advises you to run this tool even if your computer seems to be fine. You should also use up-to-date antivirus

Download the Tool Free!

http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

Enjoy,

Julius

Friday, June 12, 2009

2008 African American Information Technology Experience

2008 African American Information Technology Experience

by: Julius Clark


This is a re-post originally featured by the BDPA Education Foundation.


I pulled these statistics from different sources to make a compelling point regarding the state of the African American Information Technology Professional in 2008. Barack Obama used the Internet to help him win the presidency like no other and has re-written the book on political campaigning.

In the U.S., 20% of all undergraduate degrees received by African Americans are Business Degrees. But in the age of information, only 3% of undergraduate degrees awarded to African Americans are in Computer Science; when technology professionals are in such a desperate demand in this country; despite the color of an individual, and despite the slowing economy.

We have a lot of work to do in influencing our children to pursue careers in technology. It can be difficult when on one end of the spectrum, Science and Technology competes with little punch against the images of athletics and entertainment, which are so dominant in the African American culture for just a small few of individuals to successfully get into.


    1. Community - African American children have made strives and the digital divide is narrowing in our community, but we need to stop boring our brightest children to death with continued basic computer literacy. They need to be taught how to solve problems with computers and the Internet.


    2. Academia/ College
      • African Americans represent 13-14% of the American Population, but only represent 3% of BS degrees awarded in Computer Science. This could change if we emphasize early to kids to use computers to solve problems.


      • Only 1% of PhD degrees are earned by African Americans this year and each year in the near future. People with the PhDs get money to research problems. The problem here is that our community has lots of problems, yet only 1% of African Americans with PhDs are qualified as researchers at universities to seek the funding to research solutions for our communities problems. This is not an efficient problem solving method.


    3. IT Professional
      • Only 3% of Information Technology jobs are held by African Americans. Hmmm... this number is the same as BS degrees awarded to African Americans.


      • African American IT professionals are making 85.9 cents to every dollar of our white computer Professionals. Last year we made 86.4 percent; we lost some ground.


      • One identified gap for the salary lag: "intangibles" -- subjective factors that determine where in the compensation range an individual falls. The building of trusted relationships that enables people to reach the higher end of the subjective range apparently hasn't strengthened in the past year and is disappointing.


      • Whites saw a 3.4% compensation increase from last year, compared with 2.7% for African Americans, the lowest increase for any ethnicity


    4. 2008 Computerworld Salary Survey - Click here to the survey


    5. Heartening Discoveries -
      • African American children are addicted to computers and the Internet and want to be challenged more. Let's not bore or ignore them.


      • When asked how satisfied they were with their decision to pursue an IT career, 89.3% of African Americans said they were satisfied or very satisfied. That's the highest percentage of support for the career path voiced by any ethnicity, including whites, at 84.5%. Hey, we love what we do!!


    6. eCommerce - In 2008 African Americans made up 11.8% of all Internet purchases. Very high numbers here and they are rising. We need to get more African American students interested in Computer Science and get some of this eCommerce money.
    7. My Final Thoughts - An Information Technology career is the best return on investment for your money and time. The satisfaction rate of African Americans in IT demonstrate our perseverance as a people in the wake of continuing disparities. I welcome the future with hopeful feelings. Let's keep it with the "Change We Need" and "From the Classroom to the Boardroom" mantras. Go BDPA Information Technology Thought Leaders!!!

      Championing the cause,
      Julius Clark, President-Elect
      BDPA Charlotte Chapter

Get Expert Advice!