Tuesday, January 24, 2012

What's in a name?.....Strategy

Follow me for a moment on a random thought. If vision begets strategy and strategy begets roadmaps and on down we go; wouldn’t common language and labels be a byproduct of that activity? If that is true, would it be somewhat safe to say if you don’t have common language and labels for groups or efforts it indicates a breakdown further up the chain?
The trick is identifying where the chain is broken....and fixing it.

Friday, January 13, 2012

International Conference on Cyber Security 2012 and "hunters"

Overall impression….meh. It was decent for a first year conference. Oh wait this is its 3rd. That there was a Cyber Security Tutorial before the first actual day of the conference should have been a little telling. Presenters were also only given 30 minutes so not much ability to dive deeply. I think there was more of a focus on law enforcement cyber concepts and general cyber research than anything else which absolutely has a place…..but not for where I am and what I’m doing. If it required a clearance it would probably be a conference I’d like to have happen twice a year given the areas the speakers came from. Ah well. I also hate to knock presenters as on some level it takes some stones to stand up before folks and speak. At one point I did see someone take their iPad, take a picture of one of the presenters as they droned on and on and used some movie special effects app to blow them up. Indeed sir, indeed.

One thing I did find myself thinking about at the airport was the idea of a Cyber Warfighter

Wednesday, December 7, 2011

Oh the pain of marketing material

Ok I can’t resist. I tried but I can’t. Let’s just get it out of the way that I’m a big ArcSight fanboi. Does it have it’s faults, bugs, and places that could use some TLC work/rework?; you bet. What software doesn’t though? Is it a powerful platform that can act as a force multiplier when it comes to your InfoSec program?; absolutely! Does it do stuff natively that other products haven’t even thought of?; only in ways I didn’t fully realize until using other products that leave me scratching my head in wonderment. Would I like to work at ArcSight if the right position came up that didn’t require a ton of travel?; yup. Might this post kill that chance?; doh – maybe.


So I’m reading the July/August Information Security magazine (pdf link) and I come across a full page ArcSight ad with a line that reads “Finely tuned to combat cybertheft and cyberfraud, the ArcSight ETRM (Enterprise Threat and Risk Management Platform) gives you better visibility of real-time events and better context for risk assessment, resulting in reduced response time and costs.”

Tuesday, October 25, 2011

Playing Sudoku in your metrics


This has been percolating in my head for a bit so figured I might as well get it out =). One of the best apps for the iPhone is Sudoku2 by fingerarts. If you aren’t familiar with the Sudoku here is a screenshot.

Each of the smaller boxes needs to have just one of the numbers 1 – 9 while each line vertical and horizontal line can also only have just one of the numbers 1 – 9. It really becomes a process of elimination based on the number you are trying to solve for and where it can go. For example, when I took the screenshot I was solving for 1s. Take a look at the bottom left box. Based on the intersection of other 1s, the 1s in this box have to be in the first vertical column although it isn’t known which of the two it might be (yellow cirlce). Because the ones are in that column though if you look at the top left box there is only one open box where the 1 could go (black 1). By filling that in there is only one open square in the top right square (red 1). And on you go through all the numbers.

There was always a tickle in the back of my mind that there was a security analogy with Sudoku but it didn’t really hit me until a few months ago when I was trying to figure out a way to create a metric-y type view of some virus and incident data.

Wednesday, October 19, 2011

What's the value of chasing alerts and other musings

I don’t know what your thoughts on this are but I’m trying to work out an illustration on how the churn related to the hamster wheel of your run of the mill incident detection and response doesn’t really lead to a whole lot of increased security posture or reduced risk – at least not directly or by itself. Don’t get me wrong, that work needs to be done and isn’t a trivial component of your overall program. At the same time I think this is one of those things where activity doesn’t necessarily indicate/translate/equal accomplishment. Great – you cleaned X machines with Y malware. Next week it will be N machines with Z malware. Soooo….does that mean you are more or less secure than the month before?

I’m of the general opinion that an improved security posture/reduced risk/reduced exposure is a by-product of doing analysis on the information gathered from your incidents and using that to drive change in either various configuration settings or policies (or both). Not rocket science or an original thought really. Hopefully that makes some sense.