Monday, December 6, 2010

Neuroprivilogy is the Holy Grail

Is your Neuroprivilogy vulnerable?
The answer is most probably yes, you simply have no clue what Neuroprivilogy is (yet)…

The first step with any discussion is defining a fancy term to describe the phenomenon. That’s where Neuroprivilogy came about.
As the name suggests Neuroprivilogy is constructed from the words neural (network) and privileged (access), and can be defined as the science of privileged access points’ networks. Using the neural network metaphor, organization’s infrastructure is not flat but a network of systems (neuron=system). The connections between systems are access points similar to synapses (for neurons). Some of these access points are extremely powerful (i.e. privileged) while others are not. Regardless, access points should be accessed only by authorized sources.

This privileged access points’ network is vulnerable as you’ll find out by observing the Neuroprivilogy vulnerability 7 fallacies:

1. These access points have limited permissions
Systems almost always use proxy accounts to interact with other systems (e.g. application to database). Now let’s be honest – when was the last time we used any type of mechanism to restrict systems’ access based on anything (e.g. propagate end user permissions to the app-database interaction)? In most cases we simply grant privileged access rights to systems. Hey, it is much easier to use most permissive access rights required as the common (permission) denominator…

2. Given the associated high risk I probably already have controls in place
Does anything from the following list sounds familiar? Hardcoded passwords, clear text passwords in scripts, default password never changed, if we’ll touch it everything will break… The irony is personal accounts for real users has very limited access rights, while having stricter controls (even simple ones such as mandating frequently password change).

3. But I have all those security systems so I must be covered, right?
This topic calls for a separate blog post altogether, however I’ll point out the fundamental principle of most systems handling users and accounts (such as IAM, SIEM, GRC, etc.) - the prerequisite to all operations is identification of users. They are great tools for personal accounts correlated to known users, and not really for privileged access points used by non carbon based entities. The solution is very simple – use the adequate tools!

4. Privileged access points vulnerability is strictly for insiders
Picture yourself as the bad guy, which of the following would you target? Personal accounts with limited capabilities protected by some controls, OR privileged access points with limitless access protected by no control? The notion of an internal access point is long gone; especially with the borderless infrastructure trend (did I say cloud?).

5. Adding new systems (including security) should not impact my security posture
That’s where it gets interesting. Most systems interact with others, whether of infrastructure nature (such as database, user store) or services. Whenever adding a system to your environment you immediately add administrative accounts to the service, and interaction points (access points) to other systems. As already mentioned most of these powerful access points are poorly maintained, causing a local vulnerability (of the new system) as well global vulnerability (new system serves as a hopping point to other network nodes). Regardless, your overall security posture goes down.

6. I have much more accounts for real users than access points for systems
Though this fallacy might sound right, the reality is actually very different. It is not about how many systems you have but the inter-communication between them. Per enterprise customers I’ve talked with, the complexity of the network and magnitude of this challenge will surprise many.

7. This vulnerability is isolated to my traditional systems
Some of the more interesting attacks/breaches from the past year present an interesting yet non-expected trend. The target is no longer confined to the traditional server, application, or database. Bad guys attacked source code configuration management systems (Aurora attacks), point of sale devices, PLC (stuxnet), ATMs, Videoconferencing systems (Cisco), etc. The extent of this phenomenon is actually very surprising. I even heard the other day, pacemakers has privileged accounts (for remote management). Now this is what I call a life and death type of vulnerability!

When observing these fallacies and APT attacks characteristics, you realize Neuroprivilogy vulnerability is the Holy Grail for APT attackers. It perfectly fits the APT characteristics - not about quick/easy wins, but rather very patient, methodological and persistent attacks targeting a well defined (big) “prize”. You work the privileged access points’ network until finding the way in and winning the “big prize” (limitless access to the required/targeted parts of the infrastructure).

The dummy version of comparing traditional to APT attacks is: traditional = a quick and easy win, APT = keep your eyes on the prize.

Now going back to my opening question – is your Neuroprivilogy vulnerable? (No need to answer, just a rhetorical question)

BTW – an interesting TED talk about neural networks and how it actually defines us: http://www.ted.com/talks/sebastian_seung.html

Monday, November 22, 2010

v1.0 is always more successful when bundled with two sunny days at Orlando

Nothing like sunny Orlando in the middle of a Boston’s November, therefore you can imagine my excitement about participating at the first Cloud Security Alliance Conference this week.
So what did we have there (other than ~90 degrees)?
  • Interesting mix of participants (customers, vendors, thought leaders, consultants, federal)
  • Lots of cloud and security related sessions
  • Securing privileged users (insiders threat) and privileged access points (API management) are top concerns
  • Sitting in a panel discussion about securing applications and data in the cloud
  • Booth at the expo center (chance to both pitch and have interesting discussions with participants)
  • AND one big debate about security and the cloud
(Basically all the ingredients for two days well spent)

While I can go into lengthy descriptions of sessions and other discussions, I prefer focusing on what I perceived as the biggest debate at the conference. Which of the following is right?

The cloud is new therefore requires all applications and security solutions to be re-written
OR
Just of the same, been around for a while, let’s move our apps and secure it using current controls

Surprisingly (or not) most influencers seem to believe things needs to be re-written.
Not surprising (or …) I have a different take on that. But first a couple of clarifications:

  1. I’m tired with this binary approach to the cloud some people present – “either everything going to the cloud (1) or nothing (0)”. Think hybrid, we are going to have mixed environments for as long as you can currently plan.
  2. Tired++ from this ongoing FUD competition (though I have to admit occasionally I participate). RELAX, don’t panic, we are going to be OK. The cloud is a great thing and a decision whether to adopt it is a business decision (based on its many virtues). And yes it has vulnerabilities and issues which need to be highlighted and addressed (start with focusing on operations accountability and transparency).
It is off my chest and I can finally address the cloud-security debate. As with most cases, the answer is somewhere in the middle. The cloud represents new concepts, technologies and delivery mechanism. Given the extent of the change (and opportunities) some areas are definitely going through a revolution and require re-thinking/re-architecting or as some of my colleagues put it – re-writing. However, when looking at public IaaS there are quite a few challenges that only experience evolution and can be addressed with existing tools and expertise (only some adjustments required). I thought my friend Gilad (founder+CEO @ Porticor) presented it nicely during his session.
Now it is true every several years products gets re-written anywhere, therefore the shift to the cloud might be a good opportunity.

My recommendation (my personal crystal ball):

  • If you are in the services business – identify evolution areas and follow them.
  • A vendor? the revolution domains is where you should be looking for opportunities.
When all is said and done, looking at Friday’s financial news: Salesforce’s Q3 results exceeded expectations and their stock is on fire! Makes you wonder whether customers really care or are we simply over hyping it all…

Thursday, September 30, 2010

Anything you can do I can do better

During the past several years it has become a hobby of many to bash the Identity Management vendors, solutions, deployments, you name it. It is too expensive, it takes forever to deploy, eventually it provides limited coverage, it is not business aware, it is too complex, did I mention the price? As an Identity Management veteran I can admit that, despite the major consolidation the market experienced and the multibillion $$$ market, some of it (probably most of it) is kind of right…

Why is it any different from the natural evolution of other domains?

Sometimes you encounter a special phenomenon where:

1. The problem is well understood by everyone

2. It is a major problem

3. Every organization experiences it

4. And are willing to pay to resolve it (thus the market is defined as a multibillion $$$ market)

5. There are plenty of solutions out there

BUT NO EXPONENTIAL GROWTH for any of the vendors, wouldn’t you expect at least one to break away?

So why does it happen? Sometimes because the existing products’ coverage is limited, other cases it is too complex, too expensive, (basically most of the reasons previously described).

Those familiar with the domain knows that despite the white noise (of existing vendors) the market is anxiously awaiting someone to actually “do it better”, “be greater”, “sing louder”, “go higher”…

This month I’ve participated in a couple of events – VMWorld 2010 and Arcsight Protect 2010. While representing Cyber-Ark and discussing our PIM (Privileged Identity Management) technologies I had a chance to listen to what the hosting vendors had to say.

I’m happy to report that there are two new players stepping into the Identity Management space claiming to do it better. Meet VMWare (provisioning, self service and SSO) and Arcsight (IdentityView).

It is true both vendors are very cautious with their announcements (Arcsight – we only do monitoring, VMWare – it is only for synchronous provisioning and we only manage our systems), come-on…

What do you think, if VMWare customers ask to “simply integrate with a ticketing system for approvals” would they provide it? Or “can you open the platform for plug-ins to control other systems”?

How about Arcsight customers requesting to be able to do some remediation actions (such as disable a suspicious account) directly from their control panel?

I don’t know about you, but I think these guys are here to stay.

Another market that experiences a similar phenomenon is information protection (DLP and/or ERM and/or EIP …). The extent of this challenge is huge (i.e. a major major problem for all organizations) and the current products are straggling to solve this hairy problem. However products are simply too complex, limited and fail to pick up. If I had to predict I would say waves of innovation are expected, and only a different take will manage to lift this domain to the next level.

So if you are out there considering starting an information security start-up definitely look at this space, there’s alllllllllooooooooottttt to be done and it requires a fresh approach.

Thursday, August 5, 2010

A Flat to Let – the Challenge of Selecting Neighbors

This week I would like to begin with a fable, based on an Eastern European folk tale translated to several other languages. Bear with me as I’m positive you’ll get (and like?) the metaphor!

"At the edge of a valley so quiet and pretty, stands a five-story building far away from the city,"

It begins, and describes the animal tenants on each floor: a fat hen, a cuckoo, a pampered black cat, a voracious squirrel. The fifth floor used to be inhabited by Mr. Mouse, but he disappears, and the neighbors put up a sign: "A Flat to Let." The flat is shown to many animals. Each follows the same cycle of sing-song questions and exclamations. But each visitor objects to one of the other animals, and rejects the flat.


“Do you like the rooms?
          They are nice.

Do you like the kitchen?
          It is nice.

Do you like the hallway?
          It is nice.

Then dwell with us, Rabbit.
          No, I won’t!

Why?
I don’t like the neighbors. How can I, a mother of twenty bunnies, dwell together with a cuckoo, which deserts her children? Her children grow up in weird nests. All of them deserted, all of them neglected. What would my children learn from them?

The cuckoo bird was hurt. And the rabbit went on her way.”

Finding the right neighbors is tough, you don’t want end up with someone that will mow the lawn too early in the morning, drag his trash bins too late in the evening, nor have loud parties every other day. But how can you control it?

Representing Cyber-Ark, I participated in Burton Catalyst 2010 conference last week. During the virtualization and cloud tracks, the inhibitors to public clouds topic was discussed. As expected security is still #1 concern, where multi-tenancy is a big part of it.

Translating it to “fable language” - organizations are very concerned about their neighbors (with whom they share infrastructure), and want to take part in the neighbors selection process. Everyone is using the example of Coke, claiming they will never agree to share infrastructure with Pepsi. Frankly, I believe they should be more concerned if Johnnie Hacker was their neighbor, but that’s just me…

Some history - once upon a time infrastructure was private, no neighbors at all. Parents only had to deal with room allocations to family members (I want a bigger one, a better view, close to the kitchen, isolated, etc.).

Fast forward, then there was the Cloud where infrastructure has become a shared resource for all citizens of the world, with no ability for tenants to impact the neighbors selection process.

As potential tenants grew concerned with automatic allocation of neighbors, cloud vendors quickly responded offering a dedicated infrastructure option. This is obviously more expensive, to the point that the risk vs. benefit ratio is not as appealing anymore. Organizations preferred building private clouds, gaining partial capabilities of the “cloud movement”, while compromising on others.

I believe we will witness evolution of new cloud computing models/offering in addition to public and dedicated, addressing the neighbors challenge.

A few potential directions which come to mind:

1. Co-location based on reputation - think about your car insurance policy, coverage as well as cost depends on your reputation (previous claims, driving record, etc.). Credit score is another reputation mechanism with direct impact on services you receive. An organization’s reputation (such as controls in place, attack record, load) will be used to determine their co-location. Companies with good reputation will be granted better service, lower cost and above all – reputable neighbors!

2. Cloud communities – in the physical world we see communities forming around joint interests or trust. Similarly “cloud communities” with shared interests (such as regulations) or trust (community members trust each other) will be created. They will run their systems on shared infrastructures dedicated for the community. I foresee an eco-system of brokerage services helping forming these communities, and negotiating terms with cloud service providers on behalf of the community.

3. The Cloud Randomizer – this started as a joke, but think about it. The cloud’s underlying technology is mainly virtualization; virtualization enables moving environments around with no down time. How about frequently moving organization’s systems around in a randomize way, reducing the likelihood of attacks (at least planned ones)?

What do you think? Am I dreaming? Should I stick to folk tales?

Friday, July 23, 2010

Hard-coded default passwords? The Ostrich for the rescue!

Some days I feel the world will be a much easier place to live in if we simply adopt the ostrich approach. If something looks slightly challenging, let’s just stick our head in the ground for a while and the problem will simply go away.


Those of you who enjoy tracking threats, attacks, malware and the likes probably heard about the Stuxnet worm by now. For the rest of you it is malware targeting windows environments running Siemens software used by industrial companies. Once on systems, it uses Siemens default passwords to connect to the database and collect information.

Does not sound like a big deal. Nobody is using default passwords these days and even in case they foolishly did, just change the password and have a good night sleep, right?

ahmmm… unfortunately in that case I had to look for a different topic for my post…

Those of you who follow my blog know by now that I’m not really a security radical, but rather moderate and open minded when it comes to the way security specialist grasp the world. But I can tell you that this incident is mind boggling even for me.

Sin #1: using hard-coded passwords – happens from time to time, irresponsible behavior, slap on the wrist.

Sin #2: sin #1’s hard-coded passwords are the default ones and are similar for all customers – doh!

Sin #3: these passwords cannot be change (per Siemens) or the systems will stop working – what were these guys thinking? It is even worse than creating a system with no authentication mechanism at all, zip, open to the public, web 2.0 like... You communicate a FALSE sense of security that there are controls in place to secure usage of the system (i.e. authentication), yet the passwords are known to the public and cannot be changed?!

Top it with Siemens’ response (reportedly advised customers not to change their default passwords, arguing it “may impact plant operations.”), leaving customers out there in the cold having to choose between bad and worst…

There are many articles describing this incident, an example: http://tiny.cc/osg8q

I’m positive Siemens will snap out of their current state of mind and resolve it, but the unfortunate part is the fact that this phenomenon and state of mind is not limited to Siemens. Some still use hard-coded passwords, some still use default passwords and some don’t change passwords.

It is time to GET BACK TO THE BASICS!

1. Authentication between systems should be externalized and governed by processes/tools that can rotate and secure credentials.

2. Default passwords might be good for the initial bootstrap/setup procedure, however should be changed and should definitely be unique per customer

3. There are tools designed to address the whole privileged accounts challenge regardless whether it is performed by humans or non carbon based entities (such as application, services, or devices).

Unlike the common belief that vulnerability of internal, powerful credentials are a target for internal threat only, the reality is privileged accounts are a gem for external attackers. More frequently than you imagine external attacks target these powerful accounts, as hijacking these accounts makes external hackers’ life/job much easier.

Next week is Burton Group’s Catalyst week, stay tuned for my take-aways/insights from the conference and sunny San Diego!

Tuesday, July 20, 2010

The Jerry Maguire take on Security

I have a strong feeling this post is going to be my Jerry Maguire’s “Mission Statement”…

A couple of comments for those who have not seen the movie:
1. Keep reading as watching the movie is not a prerequisite
2. You should probably consider watching it, it has some funny quotes

A recap - Jerry Maguire is a 1996 film starring Tom Cruise about a sports agent who has a moral epiphany and is fired for expressing it, who then decides to put his new philosophy to the test as an independent with the only athlete who stays with him (Wikiquote.org - http://tiny.cc/sqj8p).

My case is obviously different: it is not so much an epiphany but rather some thoughts/insights, and the whole firing part???

Despite the many changes the security community experienced, one thing seemed to stick with us throughout the years (especially as compliance has been bolted on to security) – FEAR.

If we’ll scare them they will come!

Fear as a way of thinking about the challenges, fear as a design criteria, fear as a way to prioritize features, fear as a driver for pricing, and certainly fear as a selling tactic.

It is kind of a negative way of thinking, don’t you think?

Recently I have participated in the Enterprise 2.0 conference. Surprisingly these guys approach issues differently, on the verge of a Woodstock atmosphere. It is all about collaboration, opening up the organization, loosing controls, doing good for everyone (rainbows and violin background music…). Almost too much positive thinking for me…

In the audience I could notice quite a few CIOs, most of which participate in our (security) conferences as well. It simply mind boggling what is going through their minds when they hear both enterprise 2.0 and security pitches. The contradiction is simply amazing.

So who has it right?
Are we right and they are naïve, or they have it right and we are simply afraid?

As with most things, I believe the truth is somewhere in between.

You would rightfully say organizations spend their security budgets addressing threats. And Rod Tidwell’s immortal motto is probably correct (from the movie of course): “Show me the money!” security vendors should continue addressing these threats and fears. Hey, this is our thing and we should keep on doing it.

However I still believe there is a place for positive thinking in our domain (security). The infrastructure play and information our security systems are exposed to can be leveraged for positive spins. Topics such as increase awareness, productivity and reduce cost can all be addressed.

Just a few simple examples (I’m keeping the real interesting ones for internal usage…):
1. While monitoring usage of applications the system can recommend (potentially even automate) adding the more popular apps under the SSO umbrella.
2. As we monitor behavioral patterns for fraud detection we can contribute to optimize web applications increasing productivity and reducing cost.
3. During the access control to unstructured data we can identify usage frequency and suggest lower cost storage for hardly used documents or “cache” more frequently used data.
4. And even small frustrating thing as laptop’s startup time can be improved as application usage is monitored, we can identify hardly used apps/services and remove them from the startup sequence.

Can you imagine positive thinking can become a differentiator in the security domain?
Do you believe customers will actually be willing to spend their security $$$ on positive things?

Friday, June 25, 2010

Gold Rush – The return of the King

5:45pm – just as I was planning to head out to the Apple store I get the following alert:
SEVERE THUNDERSTORMS PRODUCE DAMAGING WINDS AND LARGE HAIL... AS WELL AS DEADLY LIGHTNING AND TORRENTIAL RAIN. GET TO SAFE SHELTER NOW... INSIDE A STURDY BUILDING OR IN A VEHICLE. DO NOT SEEK SHELTER UNDER TREES. IF YOU CAN HEAR THUNDER... YOU ARE CLOSE ENOUGH TO BE STRUCK BY LIGHTNING. DRIVERS SHOULD BE ALERT FOR PONDING OF WATER AND AVOID FLOODED ROADS.
A SEVERE THUNDERSTORM WATCH REMAINS IN EFFECT UNTIL 800 PM EDT THURSDAY EVENING FOR NORTHERN CONNECTICUT AND MASSACHUSETTS AND SOUTHERN NEW HAMPSHIRE AND CENTRAL RHODE ISLAND.

You got to be kidding me!
If you really think a deadly thunderstorm storm will hold me back from getting the prize, then think again.

6:10pm got to the store (still alive) only 5 people in line (all with pre-orders or tickets). This obviously proves that you get a better treatment if you are invited to the party…

7:00pm returning home as a winner, I’m probably looking at a romantic evening where together each one is busy updating his new iPhone…

Not sure what the big excitement is all about – after all it is just a phone (and an ipod and an email device and an app platform probably the coolest gadget around…)

I have finally figured out the name “iPhone 4”, looks like you have to wait 4 hours to get an iPhone…