Showing posts with label network defense. Show all posts
Showing posts with label network defense. Show all posts

Monday, January 8, 2024

Avoid Computer Crimes

 A reminder for all:

A person may not intentionally, willfully, and without authorization alter data stored by a computer database.

MD Criminal Law Code § 7-302 covers (among other things) intentionally inserting records, sign-ups, registrations, etc for the purpose of disrupting the proper use of the service. Intentionally signing someone up for a listserv to get that listserv blocked for sending spam clearly falls within this.

For the non-Maryland folks, 18 U.S. Code § 1030 is your guiding light.

Intentional disruption of someone else's use of Internet services is a crime.

Flooding a candidate's volunteer signup system with fraudulent entries to exhaust the system and prevent actual volunteer's from registering: computer crime.

Collecting the credentials of a campaign staffer and using it to download the emails from their account to distribute publicly in an effort to discredit and embarrass the campaign: computer crime.

We do not want or need to resort to computer crime to undermine functions of the electoral process, nonprofit organizations (even those with despicable goals), or generally civil society. (Judgement withheld regarding explicit government corruption. Reading recommendation: The Burglary: The Discovery of J. Edgar Hoover's Secret FBI, Book by Betty Medsger)

To defenders: Protect your systems and accounts as if people are fine with breaking laws. Loosing the confidentiality, integrity, or availability of your data is not mitigated by "Hey, that was illegal!"

Wednesday, February 22, 2017

What are three corporate policies to mitigate risks for cybersecurity attacks at the global level?

What are three corporate policies to mitigate risks for cybersecurity attacks at the global level?
  • Disable macros at the policy level A very common point of entry for malware, be it botnet, remote access trojan, or ransomware, is through the built-in scripting language of Microsoft Office: macros. In fact, the middle of 2016 saw a very large campaign of spammed Office malware leveraging macros within Macro-enabled Document Templates. (Molyett & Lee, 2016) With Windows 10 and new updates to Office the enterprise level configuration, Group Policy, can enable "Block macros from running in Office files from the Internet" (Khanse, 2016) which is a feature that should always be used. Any person on the network that needs to open such files should be provided a virtual machine for reading those files.

  • Submit all email attachments and links to a sandbox scanner Other than Office macros, spam carries with it malware executables, links to exploit kits, and various nested file solutions to execute malcode. An effective network protection policy is to have all incoming emails be submitted to an automated scanner. (Eckstein, 2015) Such a solution does delay emails by a few minutes, but avoiding a ransomware infection is well worth it.

  • Two factor authentication The last common delivery through email are directions to phishing websites for collecting user credentials. When a user falls for one of these sites, which often can look pixel perfect due to the same technologies being available to the scammer as to the original web developer, then the attacker gains the user login and password for the copied service. This was how the Hilary Clinton campaign chairman, John Podesta, had his email's hacked in 2016. (Vaas, 2016) By accidentally logging into a fake Google Mail support page, attackers collected his credentials. Two factor authentication usually means that, in addition to knowing the secret password and the not-so-secret username, a user must also possess a physical device to successfully login. Phishing attacks then fail to provide access even once credentials have been harvested.

Eckstein, P. (2015). AMP Threat Grid Extends and Bolsters Our Ability to Combat Malicious Malware. Cisco. Retrieved from https://blogs.cisco.com/ciscoit/b-sec-10232015-amp-threat-grid-combats-malicious-malware
Khanse, A. (2016). Prevent and block Macros from running in Microsoft Office using Group Policy. The Windows Club. Retrieved from http://www.thewindowsclub.com/block-macro-malware-microsoft-office
Molyett, M. & Lee, M. (2016). Macro Intruders: Sneaking Past Office Defenses. Cisco Talos. Retrieved from http://blog.talosintel.com/2016/08/macro-intruders-sneaking-past-office.html
Vaas, L. (2016). DNC chief Podesta led to phishing link ‘thanks to a typo’. Sophos. Retrieved from https://nakedsecurity.sophos.com/2016/12/16/dnc-chief-podesta-led-to-phishing-link-thanks-to-a-typo/

Sunday, January 4, 2015

Extending your home network... insecurely

I reorganized my house this week and gained a private office space, though one without a coaxial jack. This makes it impossible to immediately replicate my previous setup of a whooping three feet of CAT 6 between my main workstation and the FiOS router. Unfortunately a WiFi connection isn't an option as the box isn't compatible.

Options for connecting a new room to your home network

  1. Add CAT 6 Ethernet cabling: Doing this cleanly requires running cables through the walls and cutting holes for new outlet boxes with a face plate. Highly suggested if you own your house, but I'm in a rental. Pass.
  2. Reuse an extra wireless router as a wireless bridge: I tried this one for a few hours (hours that the wife was not happy I was spending!) but the only router I had sitting around was an Actiontec MI424WR Rev I which is not compatible with DD-WRT firmware.
  3. Power-line networking: Add a device to connect Ethernet networking over the existing power lines within the house. The guy I talked to at Best Buy recommended the Actiontec Powerline Ethernet Adapter Kit [PDF] over the WiFi extender I was looking at. At $39.99 instead of $99.99, I decided to try it.
Fast and easy...setup in less than 5 minutes
The box claims a quick and easy set-up, just plug the single adapter into the wall and wire it to the router. Plug the four port adapter into the wall near your machines and wire them up. So I did, and almost immediately my workstation was connected to the Internet... success! Or so I thought.

Verify that the network is up

Along with my main workstation, my office is home to a server which provides multimedia and intranet web hosting. Once I had Internet access, the next step was to check for the rest of the intranet machines. I navigated to http://192.168.1.1 (default MI424WR address) and the expected page pulled up, but my login failed. Double checking my password typing, the login failed a second and third time. More information needed now!

Check Windows' "Network" page

Under Printers there was a Lexmark, under Computer there was a name I didn't recognize. This is a problem, and one that needed addressed immediately! My workstation was connected to someone else's network.
**generic encryption key**

Ease of setup security hole

The problem was documented right there in the manual, the adapters come pre-provisioned with a default, generic encryption key. This is great for easy set up because you can just plug it in and go. It is bad for security because it means you can just plug it in and join any network that is already there! Turns out my neighbors already had expanded their network with a similar, compatible product. They plugged it in and it just worked. I plugged mine in and it just worked... with their existing network.

I don't understand why the manual in the box doesn't tell how to update the encryption key, it just directs you to their website. Which pretty much guarantees that a random person directed by their Best Buy clerk will never update it.

From the Actiontec website:
    How do I change the encryption key on a PWR500 Powerline Adapter?
    To reset and change the encryption key on the PWR500, follow the steps below:
  1. Plug the Adapters into electrical outlets on the same circuit.

  2. Press and hold the Security button on each unit one at a time for exactly 10 seconds. On the 10th second, let go of the button. When you release the button, the Power LED's will turn off very briefly and turn back on. The LK LED's will not turn back on at this time.

  3. Then on one of the units, press and hold the Security button for exactly 3 seconds. On the 3rd second, release the button. When you release the button, the Power LED will begin to flash.

  4. Now on the other unit, press and hold the Security button for exactly 3 seconds. On the 3rd second, release the button. When you release the button, the Power LED will turn off and back on breifly, and then the LK LED should be lit on both units. Provided the LK lights on both units are lit, the encryption key has been changed and the two Adapters are now connected on the same Powerline network with a new encryption key.

Wednesday, September 18, 2013

Getting Started on Intrusion Detection

If someone asked you for advice on what he or she should do first to get started on Intrusion Detection, what would you recommend?

Honestly, I would meet the question with another. What is meant by “to get started on intrusion detection”? I read this as a set of distinct scenarios, all of which need to be addressed separately. When I first read the sentence, the image brought to mind was a home user first looking to secure their own network.

  • When I first read the sentence, the image brought to mind was a home user first looking to secure their own network. Technical experience is very little, maybe a help desk job; existing host based software consisting of just operating system software firewalls, possibly an assortment of pre-loaded trial personal security products; network size limited to a small handful of consumer out-of-box operating systems.
  • Not too different of a use case is an IT professional looking to add intrusion detection to their existing small business network. More machines, likely with pro OS licenses, but similar a similar basic starting point.
  • My final use case is a significant direction away from the other two. It focuses not on the network just gaining intrusion detection, but rather the asker attempting to break into the field of intrusion detection. They will be, or aspiring to, joining a mature network with entrenched intrusion detection components.

Given that the significant aspects of intrusion detection boil down to host-based monitoring, traffic monitoring, signature-based detection, and behavior anomalies, each of the above use cases need to focus on specific cases. The new home user needs to select and install off-the-shelf monitoring components, as detection cannot be done without the pieces in place. Host based logging should be enabled and a file scanning security product can catch the low-hanging fruit of intrusion detection: recognizing known malicious code on disc. Installing Snort with its default configuration should be sufficient to get the network side started for the small home network, harnessing its preloaded rules for signature detection. (Vacca, 2009, pp 64-65)

The new network admin will want to build up all the components like the home user, while also including behavior anomaly detection in the traffic and host logs. Unlike the home network, the administrator cannot personally vouch for all of the legitimate actions; thus, it is important to have assistance in locating which actions are anomalous.

Even though this write up has gotten far longer than I had intended, there is the third, and far different interpretation of the question: how to get started effectively utilizing the existing, mature intrusion detection setup. As stated by Kemmerer and Vigna, “Auditing your system is useless if you don’t analyze the resulting information.” (2002) Get comfortable with logs and traffic dumps, automating as much of automation as you can. In a large network with a mature set of intrusion detection tools running you will have all the data you can handle to analyze. Learn the protocols of the traffic you are scanning so that your comments about the traffic can be more than just “it’s all greek to me”, to use a Shakespearean idiom.


Kemmerer, R. A., & Vigna, G. (2002). Intrusion detection: a brief history and overview. Computer, 35(4), 27-30.

Vacca, J. R. (2009). Computer and Information Security Handbook. Burlington, MA: Morgan Kaufman