Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Thursday, February 22, 2018

This is one of the reasons i love my work

For the last year, I'm developing Cyber Training classes. One of them was "Cyber Programmer", for which I have joined forces with Tsofen (an Israeli NGO perusing to manpower arbs in the High-tech industry) and IITC (Israeli Institute of Technology and Communication).
In this class we have taken graduates in the IT and systems arena, giving them some Cyber awareness as well as basic pan testing and forensics skills and know-how, as well as Java and Python coding.
As a project I have asked them to build a SIEM system that will monitor Windows and Linux clients, will collect logs and push them securely to the server.
The server, in turn, will parse the logs, identify events and list them into a DB that will be shown on a web interface. This is what I had in mind….

The team have excelled and have done amazing things within a time frame of only two months. They have written the product description and the design documents for each component of the system. Then they have started to code. The core of the product; the push agent and the server are Java based. Pulling the logs every 3 min (both OS and Snort IDS) and sending them over SFTP to the server. At the server some Python scripts are parsing the logs, identifying the cyber-attacks and listing the outputs in MySQL server that in turn makes it available for the web server to display. This is how it looks like.
They did capture my vision.

It was amazing journey nursing those kids (since they are half of my age I can call them…Kids) seeing a group of individuals working together, handling all roles in the development cycle; Product management, System Architects, Researchers, Developers, QA, and integration. They also did a fabulous job as Presales when they have demonstrated the system's capabilities.      

Tuesday, September 5, 2017

Malicious Authorized User

An interesting article that I have just read is talking about vulnerabilities in MongoDB. I'm not that savvy in the DB arena, but I know one or two things in patching systems. The bottom line of that article saying that "Organizations should have a documented patch management process, should scan for vulnerabilities and configuration mishaps, and discover and classify sensitive data and systems so they can properly lock them down."

I agree with that statement. As I have just learned that companies pay a great effort to have their production segments of network well protected, hardened and patched to the latest revision (once Microsoft provided security patch for XP, they are all safe…), however within their enterprise network, it is a different issue. IT pays attention to the servers but ignore the workstations. A few days back, a SOC that I work with found that some 30% of an organization's workstations are using outdated software that their vulnerabilities were well documented into CVEs two to three years back.  Did this report meant something to the IT, not a bit, as they are relying on their peripheral cyber barriers to protect them? 



They probably never heard from the "malicious authorized user" the inner threat that can cause much more damage, allowing the payload to be safely found the right exploit to breed itself to the entire network.  

Credits:
Image source ipa.go.jp (here)
The article that triggered this post (here)

Friday, April 21, 2017

Corporate Cyber Protection Methodology

Earlier this week the Israeli CERT (CERT-IL) have issued a final draft for a "Civilian Corporate Cyber Protection Methodology." in this publish they are asking for comments before making this paper official, and releasing it.  This 160-page long paper was written for providing a professional solution for the entire marketplace. The organization's protection plan derived from this document adapted to the extent of the body's dependence on cyber.

The central principle of which this defense doctrine paper was written is the organization as a whole recognizing that it is necessary to protect the continuity of the organization's functioning and to support its business objectives.
This concept is expressed in the document as follows:

A. Management Responsibility - The responsibility for protecting the information lies first and foremost with the management of the organization.

B. Protection Depending on the potential damage - the investment in the protection of each asset will be per its critical level to the functioning of the organization.

C. Defense based on Israeli knowledge and experience - the theory of defense enables the focus on the relevant risks to all
Organization and organization. As part of the activities of the National Authority for Cyber ​​Defense, periodic intelligence audits and assessments are conducted to the economy. These actions enable organizations to target specific areas of the various defense circles.

D. Proactive protection - The security controls were defined with the understanding that the organization must invest additional efforts The passive defense. This is expressed through the definition of protective controls for the stages of prevention, identification, and reaction and return to routine.

E. Multilayered Protection - Protection is a process that combines three main components: people, technology and processes (3 P's - People & Products & Processes) Defense theory defines a defensive response that is required on all these levels.

The original published document can work in for any organization. Regardless the locale of your office, I think that the third concept, mentioned above (translated from the original paper) should be read "Defense based on LOCAL knowledge and experience." The intel and assessments which are applicable for Israel might not be right for India, Mozambique or Brazil. In an organization that it is multinational and the organization's CSO need to handle with cyber aspects in each country, it is important to pay attention to the local recommendations for each branch as it was it was the only location in the network. 

There is nothing new there in this document that we don't know by now as it is based on NIST CSF (Cyber Security Framework). The ingenuity here is that this paper adjusting the standard and making it accessible to the Israeli market.  

Monday, February 27, 2017

The Web site is up

Even if it temporary until i will crate the right website for me, for now it is up. visit www.comit-net.com. It was build over WIX platform which i have found vary intuitive to build. It wasn't my original plan, never mind it will serve its purpose as well.

Thursday, February 16, 2017

Advanced networking introduction lessons

Not long ago I was asked to build a short training to be delivered as part of a longer training program for “Cyber specialists”. A program that is being conducted by the “Technion”, The Israeli technological institute. In the program, all students are programmers that are being taught in correlation to cyber issues, mainly how to avoid leaving vulnerable exploits in their future codes. Of course, they are being taught also how to “attack” and “protect”. I have decided to split the training into two sessions.
The first session named “50 shades of Cyber in 7 layers of networking”. It is a recap of OSI model and applying the tools they have created onto the network, to the relevant layer (I.e ARP poisoning script).






The second sessions names “Cybersecurity vs. Cyber Security: Exploiting that gap”. In this lesson, we have examined existing and legitimate tunnels and encapsulation that in the wrong context will be 
at the service of an attacker. 

Saturday, December 31, 2016

I’m building my web site

I’m building my web site. I could have asked (or pay) someone that knows what to, but I think it is for the best that I will try it myself, as it is going to showcase my services.
The idea behind COMITNET is to bring my skillset in Communication, IT (& IS) and networking, that in one word is known as Cyber. This with unambiguous working approach of total commitment to my customer success.
So, the services that I’m offering are all related to Cyber. Training, Project & Program Management, Integration of NOC and SOC solution as well as IT and IS systems.
For the time being I will use my blog as the main source for info sharing and to my services portal. In the meantime, here is a glance of the website design… 


Wednesday, December 7, 2016

For some 24 years I have worked in various functions related to ‘Customer Success and Growth’, doing that at across the Cyber work-space. Be it in an military telecommunication unit, Greenfield ISP or IT. Looking into my backpack, checking what I have gained, and what I can do with the tools that I have made during the years. I have decided that it is about time that I will get Independence and start freelancing my knowledge and skills.

I had that thought some time ago. 10 years to be exact. Decided that it will be nice to revive my old DNS name that I was using back then, found it still available ComIT-Net.com ….found some old (and ugly looking) logo.


So building up.. starting to spread the news...      

Monday, July 27, 2015

CSO 2.0

Recently I was invited to participant in brainstorming dealing with the definition of “CSO 2.0”, where the main point that were selected to be discussed and examined are as follows:
·         What is Public cloud for Information Security Managers?
·         Traditional Security in the Cloud
·         Innovation & security, Better together?
However I couldn’t attend this meeting, never the less I’m sharing my thoughts

When using public clued services, web Security should be set in layered formation, in 3 layers to be exact. First layer, at the campus and branch office protecting the internal connected users. Second layer on the network for mobile users and those that are at home. Third layer at the public cloud itself protecting the access to cloud data centers.

Any solution that is used should be comprehensive and include deep visibility into the content and control (like done in QoS platforms), anti-malware / infection detection and URL filtering as well as protecting the public cloud and the network infrastructure from DDOS attacks.

Although the threat landscape rapidly changes, threat protection need to retain the current solutions and practices and to add new and innovative solutions that proof their effectiveness rather than jumping into protections against future threat that might or might not come true. 


Should it be single vendor solutions or each segment beast of bread… more to follow…

Saturday, June 27, 2015

Business Continuity Plan versus Disaster Recovery Plan, or should they co-exist?

Disaster recovery and business continuity planning are processes aim for organizations to be prepare for that one disruptive event that can take them out of business, even temporarily. In the context of this assay, it is related to event that can affect the IT systems, be it passive infrastructure (i.e caballing) or systems.

Often, when an organization deals with this subject they often discuss "DRP vs BCP", Disaster recovery or business continuity planning, what’s important, and what can be more cost effective. Most organizations that I'm familiar with takes the approach of " business continuity first, we will deal with the disaster when it will happen". That is why IT organization replicate their servers to a location name "DRP". You have live copy of the content, but will you be able to access it?
Should it was decided to replicate the content of the IT servers to secondary and tertiary sits (someone said cloud?) to allow smooth contingency. It is nice to have them available, but think of the ability to use them.

True story. Some day at 1999, arrived to the office early in the morning, just to find out that the northern wing of the management building was on fire. The first floor was burnt out to the ground (literally the floor fell down on to the ground floor). Unfortunately the Backbone switch was in that floor. Using the infrastructure on the south wing to connect the building back to the working campus network, people were able to return to their desks the following morning.


Having "hot and active" multiple datacenters, that is contingency plan. Having redundant "cold and passive" infrastructure, that is disaster recovery plan.

(Written as part of the Coursera based seminar "Cybersecurity and Its Ten Domains")

Monday, June 1, 2015

So I was invited to lecture at InfoSec2015

So I was invited to lecture at InfoSec2015 in Israel, the 16th annual event of the security industry in Israel. I was talking about the expectations from the service provider to adopt security tools and technics to protect it assets (international links for example) and at the same time to gain some profits, using the security aspects as the new growing engine.
The presentation was already shared (here) then I referred to an article on "People and Commuters" the magazine that organized the event. Apparently someone actually listen to what I have said before, during & after the event and took notes (here, in Hebrew). Therefore for my non Hebrew readers here is a translation of some highlights:

Is security a luxury or a basic consumer product? What about the security of the communications infrastructure provider? These questions were raised by Mr. Roee Besser, Technical Manager for EMEA and APAC at Allot Communications, at InfoSec 2015, held recently.According to Besser, "network monitoring, information security, content filtering and preventing attacks - all these are necessary and have become part of the DNA for Service providers, to allow customers faster and smoother access to the internet" (with DDOS Mitigation platforms).Another area that is gaining momentum, he said, is data security as a service. "Many of those who provide cloud services also provide data security in the cloud. In this way they give a security added value to subscribers."
 

Monday, May 25, 2015

InfoSec vs CyberSec: same-same but different

Information security and Cybersecurity are often mistaken used as synonymous where actually they don’t.  
To be more focused, Cybersecurity is a subset of information security.
While Information security deals with protection of information from unauthorized access, use, disruption, modification or destruction, regardless of whether the information is stored, the Cybersecurity defines the technologies and processes to protect networks, computers, programs and data from attack, damage or unauthorized access.

In a nut shell, Information security defines what is needed to protected and Cybersecurity defines ways the pathways to this content will be secured.