Friday, June 27, 2008

Mitnick - Communications Technology

Mail Drop - The Social engineer's term a rental mailbox, typically rented under an assumed name which is used to deliver documents or packages the victim has been duped into sending.

Data Classification Policy - the differentiation of securing public and private information

Innocuous - not harmful or injurious, harmless

Information Security Department - ISD
Conducts:
-awareness training
-detail methods

Explanation: Social Engineer Employees

-Lingo| "Use None Sensitive things" [Poker Chip]

Types of Security Violations

Here are some basic component violation in security, in the perspective of the malicious code,

Virus :Typical piece of code copies itself into a program, and executes when the program runs

-modifys other programs
-loss or contamination of data, or program

Worm: Reproduces itself until slowd down or shuts down a comptuer system or network, does not notify other programs

Clogging or Flodding : Form of a worm
- sending large amounts of bogus traffic too a node until clogged and unable to serve a legitamate user. AKA DoS Attack (Denial of Service)

Trojan Horse : piece of code, hides itself in another piece of a program

"Think" a simple login screen
Login Code
Hidden Code <--------interlopes exits with no trace (steals info)
Login Code

BOMB: Same as a Trojan
signature" time or logic trigger

Trigger software routine, upon detecting the absence of the rogue program records, initiats actions to damage the system

Trap Door: Allows penetration into the system can be programmed in code by programmer. Usually used in case you must get back into the program to fix something. Usually guarded by authentication process.

Salami: Small alteration of numbers in files having of numbers and distorting the system.

Replay violation: Active attack on a resource.
entails: capturing data, perhaps modifying and resending it.

Monday, June 23, 2008

John Searle, The Chinese Room

Philosophy professor at Berkeley, On Intelligence

The Chinese Room:

Suppose you have a room with a slot in one wall, and inside is an English-speaking person sitting at a desk, He has a big book of instructions and all the pencils and scratch paper he could ever need. Flipping through the book, he sees that the instructions, written in English, dictate ways to manipulate, sort and compare Chinese characters. Mind you, the directions say nothing about the meanings of the Chinese characters; they only deal with how the characters are to be copied, erased reordered, transcribed and so forth.

Someone outside the room slips a piece of paper through the slot. On it is written a story and questions about the story, all in Chinese. The man inside doesn't speak or read a word of Chinese, but he picks up the paper and goes to work with the rulebook. He toils and toils, rotely following instructions in the book. At the times the instructions tell him tow rite characters on scrap paper, and at the other times to move and erase characters. Applying rule after rule, writing and erasing characters, the man works until the book's instructions tell him he is done. When he is finished at last he has written a new page of characters, which unbeknownst to him are the answers to the questions. The book tells him to pass his paper back through the slot. He does it, and wonders what this whole tedious exercise has been about.

Outside, a Chinese speaker reads the page. The answers are all correct, she notes--even insightful. If she is asked whether those answers came from an intelligent mind that had understood the story, she will definitely say yes. But can she be right? Who understood the story? It wasn't the fellow inside, certainly; he is ignorant of Chinese and has no idea what the story was about. It wasn't the book, which is just, well, a book, sitting inertly on the writing desk amid piles of paper. So where did the understanding occur? Searle's answer is that no understanding did occur; it was just an bunch of mindless page flipping and pencil scratching. And now the bait-and-switch: the Chinese Room is exactly analogous to a digital computer. The person is the CPU, mindlessly executing instructions, the book is the software program feeding instructions to the CPU, and the scratch paper is the memory. Thus, no matter how cleverly a computer is designed to simulate intelligence by producing the same behavior as a human, it has no understanding and it is not intelligent. (Searle made it clear he didn't know what intelligence is; he was only saying that whatever it is, computers don't have it)

--Jeff Hawkins, On Intelligence

Saturday, June 14, 2008

SEC520: 10 More

Here are 10 more Security Log Management at both the Infrastructure and System Levels

Log parsing: using log data to be used as another part of the logging process

Event filtering: suppress data that is not needed like the duplication of a record.

Event Aggregation: Logging same events as one and counting each occurrence.
Log rotation: rotate logs to make them manageable, ex: examine archived logs to perform filtering.

Log archival: keeping logs for a extended period of time on a SAN’s network, two types Log retention archive on a regular basis, or Log preservation, keeping logs that would be discarded because they contain records of activity of particular interest.
--------------------------
Log compression: reduce the amount of storage space needed (filter)

Log reduction: remove entries of no important to make the log smaller

Log conversion: convert logs to different formats XML or database

Log Normalization: Ordered in a particular data representation and categorized consistently. DATES and TIME in a single format

Log file integrity checking - having a message digest for each file MD5 or SHA1
-------------------------------------
Event correlation: finding relationships between one or more entries

Log viewing :Display log entries in human readable format

Log reporting: displays the results of log analysis
-------------------------------------
Log clearing: removing all entries from the log that precede certain date and time. Remove old logged data b/c importance has been archived.
-------------------------------------
Syslog is a central framework for log entry generation, storage and transfer, the syslog format assigns messages based on importance. Two attributes to consider are message type, known as a facility(kernel messages, mail system messages, authorization messages, printer messages, and audit messages). Severity a value assigned, from 0(emergency) to 7 debug.
Mar 1 06:25:43 server1 sshd[23170]: Accepted publickey for server2 from 172.30.128.115 port 21011 ssh2
Mar 1 07:16:42 server1 sshd[9326]: Accepted password for murugiah from 10.20.30.108 port 1070 ssh2
Mar 1 07:16:53 server1 sshd[22938]: reverse mapping checking getaddrinfo for ip10.165.nist.gov failed - POSSIBLE BREAKIN ATTEMPT!
----------------------------
Syslog security does not conform to the use of basic security controls that would give it the confidentiality, integrity and availability of logs. Weaknesses the syslog protocol encounters is the UDP transfer of data, anyone can send information to the syslog server(DOS ATTACKS). MITM on the syslog, and analyze the syslog for a vector.
----------------------------
Reliable Log Delivery, TCP
Transmission Confidentiality Protection, SSH TLS
Transmission Integrity Protection and Authentication,MD5 SHA-1
----------------------------
Robust Filtering –handles messages based on programs or hosts that generate a message or RE matching content in the body.

Log Analysis –Use separate add on programs to analysis data

Event Response – Alert admins through pages or e-mails

Database storage logs, log file encryption,

----------------------------
Security Information and Event Management Software that is a centralized loggin software , SEIM does its job
Agentless which would mean it pulls logs from the hosts by authenticating to each host and retrieving logs, or the host pushing log files on the server this server will then perform even filtering and aggregation and log normalization and analysis on the collected logs

Advantage no installation on hosts, Disadvantage – large amounts of data transferred, some need credentials so you have to install an agent on the host.

Agent-Based all the filtering and aggregation and log normalization is done at the host then transmitted

Advantage all filtering and aggregation don’t on the host, small load going over the network , Disadvantage – installing agents on every host

Thursday, June 12, 2008

SEC520: Whizzing About - Senecan

Since I've been to busy \n I haven't been posting ANYTHING OH NO! \t Well I decided I'm just going to go on a snippet| \ spree->(enjoy) since this semester has taught me well...these condensed courses have put me in the mind_frame of shaving the bits off everything and putting it to light,_\ I'm going to share my mini definitions.

10 - Question Answers SEC520:

Services such as firewalls, routers, authentication servers, and intrusion detection and intrusion prevention systems provide logs useful information for security purposes.

\System Events – ex: LDAP/Kerberos authentication response for services, error codes, user accounts and systems account with an event are logged and checked for any suspicious activity.

Audit Records – pertain to more administratively tasks that are generated and logged, ex: security policy changes, policy folders/file access, account changes

Client request and server responses are logged in order to check on persons transactions between systems when accessing/ using certain resources or networked resources ex: E-mail, web browsers,, business applications.

Account Information: checks the failed authentication attempts, account changes, and use of privileges. This also identifies any malicious attacks toward the account and the use of what applications used by the client.

Usage information: checks the number of transactions occurred in the case that any malware threat or anything abnormal in size might indicate suspicious activity such as the transfer of company internal information.

Significant operational actions: checks application startup and shutdowns, application failures and major application configurations changes

Log management is necessary to provide sufficient detail of processes for an appropriate period of time. This will enable revision of logs in order to identify any security incidents, policy violations, fraudulent activity, and operational problems shortly after the initial occurrence.

Log Generation: Hosts generate log data; they are retrieved by logging client applications, services that are automated retrieving processes either by authentication or networked log servers.

Log Analysis and Storage: Receive the log data from the hosts that are gathered in real-time, near-real-time, or batches the servers are often called collectors or aggregator's. (Multiple: 1 analysis, 1 storage)

Log Monitoring: Analysis of the data and generation of automated reports.

Monday, May 26, 2008

SEC520W2L2

PAM Today

AAA Friday,

Next week hardening Linux, he will rejig Lab5 and Lab5b


Tuesday next week is a lab day

He moved the test from this week to the 27 till the end of week3 the test is up to


ChaPTER 5 and the intrusion discovery, n Hardening Linux

Put off the take home tank lab,

Finish up to lab 4 by Friday,


When he says its due, he is going to take the open boodle, PDF file report and upload it to open

And He will mark it online, and you must upload it by the due date


NO distatory recovery,

Test is on exploits and the text the stuff we do on labs,



PAM a lot of the labs are about

This week Access Control,

Linux comes with a lot of services working independently,

Till Pam came alone in the terms of Authorization and Authentication you would have to do everything independly

PAM is basically a system you can set all the authentication parameters through one program and have it affect all the services,


Theirs a directory PAM.d their use to be PAM.conf one file with the services, PAM is the same as xinet.d what ever you want to control with pam you put the config in the directory theirs another file called other and is the default that will handle the services, it comes in modules. Modules use permission and passwords,

Is the password strong enough, you can determine is the auth is going to fail or a warning you might say they have a weak password and go in or password weak you cannot go through you can do this all through PAM,


If you look at pam it carriers a lot of files and you can also see all the services that have configuration files, the default is other,

Looking at the files we can see …the login one… we can see four interface types, theirs AUTH this is called stacking modules, the login process uses 11 modules, and each modules everyone uses login the modules are executed one at a time, the first thing is authentication auth , after that required means this must succeed or the login field, more then 4 required mean both requisite means this this failed then the login failsso if 4 fail it will fail in the end, if it says requisite it will stop.

Option will give a warning,


Sufficient that means if there are all sufficient then some will pass,

So you have interface the parameter how it will work then the module, to find out how they work you gotta do research on the module, some commonly and some aren’t

System.auth is used often, after the module theirs parameters that are sent to the module

You can find out on the net how these works, if you look at the links on the course notes you can look at everything and see what it says,

Going through the lab do backup reading and see what it does, no ignorance!

We will look at password checking and setting criteria for authentication for the needs at the time, we are looking at the basic of using one thing you always do , is so ssh does not allow root login, people will try to brute force password for root login, never login as root through ssh or login as all if exposed to the net ,

Pam solves the previous problem.