Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, February 29, 2012

Defeating Hackers and Malware With Disorder

Entropy — the measure of disorder or randomness — isn’t always desirable in the world of IT security. Kinda, sorta patching your IT systems sometimes, for example, would be a bad thing. At times, though, entropy can be a powerful tool, as in the case of well-chosen passwords that are difficult to crack. A fast-growing SIEM (security incident event managment) company called Vigilant is using entropy in an innovative way that warrants a closer look: Its anomaly-detection service identifies malicious threats based on entropy.
First, a quick primer: Entropy, often measured in bits, is the technical measurement of the randomness of the next piece of data in a string. If you see a sequence of letters with a clear pattern, such as “ABABABABA,” you would logically predict the next letter in the series will be B. Because the answer is fairly certain, the entropy would be 0. If you’re flipping a coin, the predicted outcome, heads or tails, is considered to be 1 bit of entropy. If a native English speaker is shown a sequence of standard English text and is asked to predict the next letter, he or she could guess it with great accuracy. English text is considered to have an entropy of 0.6 to 1.5 bits.
One more example: A truly random 8-character password, using every possible character on a standard keyboard, could have 52 bits of entropy. Unfortunately, most people use common words as part of their passwords, so most have only 18 bits of entropy. Thus, a password cracker doesn’t need to work through every permutation, just the most likely ones in the range of 218, which is far easier than 252. (Read Appendix A and Table A.1 of NIST Special Publication 800-63 for all the nerdy calculations and details.)
In the realm of IT security, antispam services have long used entropy and its link to anomaly detection to sniff out unwanted messages. If the service detects a single email account sending out messages to thousands of seemingly random and unconnected addresses, the provider will usually examine the message for other indicators that it’s spam. Entropy and its link in anomaly detection isn’t new, but Vigilant has extended it further to fighting malware.
Malware often generates random file names when writing Trojans to the system directory. When I perform light forensic analysis on a Windows machine, my first clue that it’s been compromised is one or more very strange-looking file names, such as vx3kjngq.exe or bb9[qamz.exe, in the Windows/System32 folder. Many malware programs use nonrandom names, but enough use randomly generated names that high-entropy filenames are a fairly good — if only rudimentary — indicator of something bad. (If you want to perform an experiment on your system, look for high-entropy file names in unexpected places, such as Windows/System32 or a root folder. Not every extremely weird name is a sign of maliciousness — but it’s a consistent characteristic.)
Vigilant has figured out that the average domain name has from 2.5 to 3.9 bits of entropy per byte. The company’s analysis algorithms flag DNS domains with more than 4.0 bits of entropy per byte; it also looks for less frequently occurring top-level domains, such as .biz and .info, with less entropy.
Vigilant’s services also looks for high-entropy file names and network connections to unexpected locations. But perhaps my favorite Vigilant check is for high entropy within HTTP content. Most HTTP content is close to the English language (or whatever native language is used) and should have low entropy. Encryption, on the other hand, has — or should have — high entropy. In fact, good crypto should have such high entropy that its encrypted ciphertext is indistinguishable from “noise.” Vigilant knows that advanced persistent threats often send out victims’ data in encrypted form using HTTP versus the normally expected encrypted HTTPS. If Vigilant’s service sees an outbound data stream using HTTP with high entropy, it raises a red flag.
Again, Vigilant isn’t the first company to use randomness in its anomaly detection, but it’s the first company of which I am aware that looks for, measures, and alerts of entropy characteristics. Sure, the company does all the traditional anomaly detection, but I like the fact that Vigilant uses mathematics and expected probabilities to add in another type of measurement.
Continue Reading»

HTTPS Everywhere Update: Now Reports Website Weaknesses

HTTPS Everywhere, a collaborative security project produced by The Tor Project and the Electronic Frontier Foundation (EFF), has been updated to identify security weaknesses in websites visited with Mozilla Firefox.
The new optional feature, called the “Decentralized SSL Observatory,” detects encryption weaknesses in websites and notifies users about said weaknesses. Such weaknesses can be used by hackers to snoop on users’ web activity or pose “man in the middle” attacks against the browser.
“In recent weeks, an unexpected weakness in the encryption used by many routers, firewalls and VPN devices made big news,” EFF Technology Projects Director Peter Eckersley said in a statement.
“The new version of HTTPS Everywhere for Firefox will let users know when they connect to a website or device that has a security problem–including weak key problems like the ones that were disclosed two weeks ago–giving people the information they need to protect themselves.”
The security flaw in network devices was discovered earlier this month by security researchers. They found that four out of every 1000 security keys generated for protecting webmail, online banking, and other sensitive net services provide no cryptographic security. It’s estimated that more than a million Internet sites use such technology to prevent eavesdropping.
The EFF also released a beta version of HTTPS Everywhere for Chrome.
Continue Reading»

Tuesday, February 28, 2012

Cisco Innovates to Provide More Nimble Network Security

At a special media event hosted by Cisco at the RSA Security conference in San Francisco this week, the company unveiled a new vision for network security. Cisco is deploying new security technologies adapted to meet the needs of an increasingly diverse and mobile network.
Between the BYOD trend, and the need to allow various partners, suppliers, contractors, and others to access the network in some limited capacity, businesses need finer control over access permissions. The problem is that most of the security tools available today do not provide enough control, so many organizations are being forced into a choice between security and productivity.
padlock on circuit boardCisco is providing tools that allow for productivity without compromising security.Speaking to the media, Chris Young, senior vice president for Cisco’s Security and Government group, explained that Cisco is equipped to meet the security needs of tomorrow by integrating security into the network fabric. Young also stressed that Cisco has a responsibility to incorporate security at the network level due to how much of the critical infrastructure of the nation is riding on Cisco equipment.
The devices used to connect and access information are more diverse, and the ways data is accessed and used may change, but one thing stays the same at the core: the network. Somehow or another, all of the information is still being passed over, on, and through network hardware.
Cisco’s own CSO, John Stewart, is also a Cisco customer in many respects, and needs tools to meet evolving security needs just like any other security admin. He said that what he needs from security tools is the ability to be highly nimble. He described scenarios where, whether the need is to allow an activity or device for a business need, or to block an activity or device for a security need, the overriding driver is to respond quickly. He needs security tools to be adaptable and agile.
To meet those needs, Cisco announced TrustSec 2.1 with some new features and functionality. New active scanning provides more accurate device identification to automatically determine what a device is so appropriate policies can be applied. Cisco also introduced new security group access technology features in its Identity Services Engine (ISE) platform that make it simpler to define and assign policies without having to exert so much manual effort to configure the network to enforce it.
In addition, Cisco unveiled a new line of ASA CX firewall appliances, which include the Cisco SecureX Framework for context-aware security. Cisco explained that many network security appliances can identify mobile or Web apps, but that often the controls are too blunt. For example, an organization may want to allow Facebook, but not FarmVille, or sharing video clips with friends.
Cisco is promising to provide very granular, context-sensitive control over what is acceptable. The ASA CX software provides visibility not just that iTunes is being used, but which devices are being used to connect to iTunes, and what types of content on iTunes is being accessed. Armed with that information policies can be built to block or allow activity at that level as well.
Instead of assigning access rights simply by group or even for an individual user, Cisco envisions granting access based on context and state. A user might have one set of access rights from the desktop PC at work, a different level of access when connecting over VPN from a home PC, and more limited rights when connecting from a smartphone or tablet over a public Wi-Fi network.
The demonstrations given by Cisco were impressive—but I always take such events with a grain of salt. How a product works in a managed scenario on stage, and how it works on your network in the real world are often too very different things. The new Cisco products are available starting today. Check them out and judge for yourself.
Continue Reading»