Wednesday, February 27, 2013

News of the Day - February 27, 2013

Rather than posting a bunch of individual news articles, I thought I'd collect them throughout the day and post them in my blog. If this works well, I'll continue. If it doesn't, I'll keep experimenting. In any event, the following are some of the news articles that caught my attention today. I've provided a few editorial comments just to keep things interesting.

Malware archeology. Symantec discovered an early version of stuxnet dating back to 2005. http://securityaffairs.co/wordpress/12616/malware/stuxnet-was-dated-2005-symantec-discovered-earlier-version-05.html

Skyrocketing attacks on U.S. infrastructure are real cyber threat. http://www.forbes.com/sites/eliseackerman/2013/02/27/forget-twitter-hacks-verizon-says-skyrocketing-attacks-on-u-s-infrastructure-are-real-cyber-threat/

Are we forgetting basic security protection on our most critical systems? http://securitywatch.pcmag.com/none/308586-rsa-stopthehacker-expands-antivirus-scanning-for-websites
Editorial - Antivirus can be bypassed fairly easily. That isn't really up for debate. Unfortunately, for many, the fact that AV can be bypassed is reason not to use it. I believe that mindset is wrong. Let's us an analogy to see just how dumb that approach is. Consider vaccinations. We vaccinate our children against diseases like smallpox and polio. Many of us get vaccinated against the flu every year. Do these vaccinations stop us from getting sick entirely? Absolutely not, but they do stop us from catching certain strains of certain diseases. The same can be said for AV. Even if it is 60% or 50% effective, it still stops 50% or 60% of the malware and that is better than nothing. I believe this overall mindset problem stems from the fact that most security people come from the IT world. In the IT world, if you network was up and running 90% or even 95% of the time, that would be a complete failure. Looking at the converse, having your network down 5% or 10% of the time is a guaranteed resume generating event. In the IT world we shoot for as close to 100% as possible, thus our mindset tends to be to throw away solutions that are less effective. That is valuable in the broader IT industry but with security, incremental gains are always positive (assuming they are also cost effective). Think about the math. If our security rates a "1" on January 1st (on whatever arbitrary scale you want to use) and you make a 1% improvement each of the 5 business days throughout the full 52 week year, your final security, on the same arbitrary scale, will be 168.8. As people focused, at least to some degree, on security, we need to keep the concept of incremental gains top-of-mind and do our best to eliminate the "100% or nothing" mentality. On, an deploy AV on your web servers.
NIST begins process of creating a national cyber security framework. http://www.nist.gov/itl/csd/framework-022613.cfm 

Fixing XSS: A practical guide for developers. http://www.coverity.com/srl/a-guide-to-fixing-xss-for-devs.html 

Bit9 blames SQL injection for security breach. https://www.infoworld.com/d/security/hacking-victim-bit9-blames-sql-injection-flaw-213488?source=rss_security
Editorial - I know this isn't the point of the previous article about SQL injection but the language used drives me a bit nuts. Blaming SQL injection for a breach is, in my opinion, like blaming a gun for a shooting or a car for an accident. The fault is not with SQL injection. the fault lies with developers who wrote an insecure application that did not validate user input correctly. The fault lies with the company who decided not to deploy a web application firewall. As long as we, as an industry, continue to blame the vulnerability instead of those who created or allowed the vulnerability to occur, we will continue to lose.
Critical security updates for Adobe reader and Java. http://krebsonsecurity.com/2013/02/critical-security-updates-for-adobe-reader-java/ 




State sponsored hackers snatch more than 1TB data per day. http://news.hitb.org/content/state-sponsored-hackers-have-been-snatching-more-1tb-data-day 

China wants hacking allegations to stop. REALLY? http://news.hitb.org/content/china-wants-hacking-allegations-stop 




Use strong passwords. Not rocket science or groundbreaking advise but this article provides a good overview of how to do passwords right. http://news.yahoo.com/review-strong-passwords-other-security-211025295.html

No comments:

Post a Comment