Showing posts with label Trends. Show all posts
Showing posts with label Trends. Show all posts

Friday, July 18, 2008

Среднестатистический участник инцидента по ИБ

Анализируя статистику инцидентов по ИБ, за последний год я пришел к интересному наблюдению об уровне «просвещенности» по вопросам ИБ наиболее частого нарушителя. Странно, но следующая мысль была о целесообразности просвещения по вопросам ИБ вообще. Тем, не менее, я все же позволю себе не согласиться с Ранумом относительно полной ненужности просвещения по вопросам ИБ, поскольку, как мне кажется, – это единственное, что мы можем сделать, и не стоит от этого отказываться.

Но, ближе к делу. Я пришел к выводу, что «компьютерно низко образованные» сотрудники, как это не странно, как правило, не являются причиной инцидентов ИБ.

В свою очередь, высококвалифицированные сотрудники подразделений ИТ и ИБ, также не замечались часто в инцидентах.

Если с профессионалами все понятно, то «феномен низкообразованных» я пытаюсь объяснить тем, что недостаточные знания являются ингибитором любопытства и излишней самоуверенности.

Именно «средние компьютерно пресвященные» сотрудники являются наиболее частыми участниками инцидентов в области ИБ. Как мне кажется, здесь мы имеем дело с «синдромом опытного водителя» – когда есть некие навыки, дающие избыточную уверенность в своих возможностях, а также желание «познать неизведанное», «испробовать неиспробованное», «побывать там, где никто не бывал», пр.

Wednesday, June 18, 2008

Ruining Privacy To Build (Feeling Of) Security

Brilliant! This is just what is going on in the world today. Picture found here:

Monday, January 28, 2008

Trend With Web Site Attacks

Web site attacks are going the same route as malware. In early days computer viruses mostly did something fun or just destructed some or all of your data (mostly without any obvious reason). Now they are used to earn money - spam, cyber extortions etc. Most of modern malware is staying stealth to not interfere with normal computer operation and avoid detection.

Same is true for latest web site breaches - attackers just slightly modify legitimate web sites to spread malware to their audience.

SecurityFocus: Attackers favor compromise over creation
SecurityFocus: Legitimate sites serving up stealthy attacks
PCWorld: 10,000 Web Sites Rigged with Advanced Hack Attack

Tuesday, January 15, 2008

SANS: Top Ten Cyber Security Menaces for 2008

SANS has posted Top Ten Cyber Security Menaces for 2008.
To my mind this can be a good argument against low attention to securing employee Internet access and mobile devices.

Tuesday, December 4, 2007

SANS Top20

SANS issued an updated version of their annual Top20 security risks list. Interesting part is the summary, outlining changes and trends. You may have guessed - shift from server-targeted attacks to client-targeted attacks. Botnets. No new "global" network worms. Increase in web vulnerabilities.

Full report is definitely worth reading:
SANS Top20
2007 Press Release

Wednesday, October 24, 2007

Терроризм? Какой терроризм?

Понятие "терроризм" прочно вошло в нашу жизнь. И характеризуется это не столько частыми терактами, сколько тенденцией называть терроризмом все подряд. Апофигеем этого была (случайно) подслушанная за обедом фраза "...врезалась в столб и загорелась машина, иномарка. Но не крутая, так что я не думаю что это теракт...". Такими темпами мы скоро терроризмом будем называть все подряд. Подорожало масло? - это просто террористы заразили крупный рогатый скот птичьим гриппом.

А если серьезно, то такая тенденция объясняется достаточно просто. Кому это выгодно? Хорошенько припугнув с помощью масс медиа население терроризмом, можно под это дело выделять огромные бюджеты, делать борьбу с терроризмом лозунгом политической кампании, принимать авторитарные законы. Именно это и происходит сейчас в США, России и, без сомнения, в целом ряде других стран. А тем временем от сердечных приступов и автокатастроф гибнет ежегодно на несколько порядков больше людей, чем от терроризма. Есть над чем задуматься...

Friday, October 19, 2007

The Other Side Of Compliance

Yesterday I was thinking about Big Brother and privacy… It is proved historically that systems like ECHELON won’t have success mainly because even if was possible to collect and store such amount of data, it’s tremendously difficult to analyze this data or somehow use it.

I asked myself: ‘What can I do if I still need to collect, store and use this data?’ The answer was obvious – let’s a collect and store data not in one central place, but in place of origination. To my mind, it’s really easier to process a number of small databases than one huge database.

How government agencies can force companies store desired amount of data for desired period of time and process that data in predefined way? The answer is obvious again – let’s make a number of regulations and make everybody comply with them.

Finally, special agency with power to take collected records – that’s all I would have needed.

So, what are the pros and cons?

Pros:

  • No need to employ staff who will support huge DB, the will be ‘outsourced’.
  • No need to store somewhere that DB, and I don’t need to invent systems to collect the data.
  • ….
  • Well, nothing is required – just write standard to comply with.

Cons:

  • No ability to correlate data between Companies to see general picture… But it isn’t 100% so.

Thursday, September 27, 2007

Can You Prove An Axiom?

Several days ago I spent a lot of time and effort trying to convince my system administrators that it’s not possible to change computer account’s password in MS Active Directory 2003 using nmap. Their main argument was that Microsoft Premium Support’s consultant said that it is possible!

Well, I posted this as joke but I would never think, that it can concern me directly. Of course, there were smart guys that realized words: “nmap is port scanning tool that doesn’t try to guess password”, so thanks a lot to them, but it’s really pity that I was ought to spend time and nerves to prove this axiom not only to highly-skilled administrators, but also to Microsoft Premium Support’s consultant. It’s very sad truth, and unfortunately I see no future with such IT.

Tuesday, August 28, 2007

Грустные мысли / Sad thoughts

В настоящее время в России так плохо с профессиональными кадрами, что скоро общая вменяемость будет считаться за одаренность.

===================
Now in Russia the situation with the professional staff is so bad, that soon common sense will be treated as endowment.