Thursday, March 6, 2014

The Russians Are Here...

The Russians Are Here

Estonia, Georgia and now Ukraine...

The Russian are coming, the Russians are coming!  As a modern day Paul Revere we're shouting at the tops of our lungs the Russians are coming!  But what does all this portend for those in the security and cyber security space?

In the sixties, seventies and so forth we were warned and taught in schools that the Communist were going to take over the world.  We were told they would do it without firing one single shot.  Given our current technology revolution has this become a more resolute reality?  Are we feeding our own eventual demise by participating in this ever interconnected world via the web?      

Well, if we look at Estonia, Georgia and now the Ukraine cyber invasions are most definitely front and center of every single world power and nation-state.  We invite your comments and observations as Russia leverages Crimean networks, telecom, communications capabilities and the gas pipeline infrastructure which feeds most of Europe and is most undoubtedly connected to SCADA systems.

Those of us in the security space would do well to pay close attention to methods of operation and techniques employed for both offense and defense whether as old as the hills or on the new frontier called the bleeding edge.  The global economy is not going away any day soon and we need to understand the threats-scape, our own infrastructure limits and wherein possible the bolstering of defenses to counter those threats as it may lead directly to our bottom line.  Testing to acceptable baseline defenses and offenses will only get you so far...conducting exercises for real resilience in the face of a MOST determined adversary is as they say, a horse of a different color.

We at Integris Security are here to help you prepare, test and evaluate your enterprise operations with an eye on: Can you survive in this global economy if your adversary has your company in their crosshairs?  Is your staff security aware?  Would you know an attack if it started?  Are your employees asleep at the switch, anchored in a serpentine bureaucracy or are they war-fighters listening, looking and revealing, reporting and proactively taking action?

Lastly, if sixty thousand security related alarms went off at your company would you roll over and go to sleep or more appropriately "RESPOND", "INVESTIGATE" and "REPORT"?

Here are a few links:

http://www.computerweekly.com/news/2240215674/Ukraine-and-Russia-locked-in-a-cyber-stand-off

http://defensetech.org/2008/08/13/cyber-war-2-0-russia-v-georgia/

http://www.computerweekly.com/news/2240215674/Ukraine-and-Russia-locked-in-a-cyber-stand-off

http://www.bbc.com/news/technology-26447200

http://www.huffingtonpost.com/2014/03/04/ukraine-cyberattack-mobile-phones-russia-parliament-security_n_4895287.html

http://www.stratfor.com/weekly/ukraine-and-little-cold-war?utm_source=freelist-f&utm_medium=email&utm_campaign=20140304&utm_term=Gweekly&utm_content=re

Thursday, January 30, 2014


Target Confirms Unauthorized Access...


ANALYSIS:


In recent days we have heard quite a bit about the 2014 Target Breach.  Additionally we have heard about the Neiman-Marcus breach which is said to be independent of the Target event but reports are that the malware used is similar.  Target is now investing billions of dollars to repair both its image and capabilities.  We have been discussing the Target breach and are trying to learn from each aspect of the incident as it becomes public.  The rationale has been to better our own security posture and help improve the overall security posture of the industry as a whole.  This breach investigation will evolve and we at Integris Security will evolve with it and learn as information becomes reliable and forthcoming.

Everything known at this point is speculation and inconclusive until the Target Corporation steps up to the microphone and gives a full autopsy. Not likely to happen any day soon as legal process is just now gathering information.

Law Enforcement (U.S. Secret Service or FBI) is typically very tight lipped about the circumstances and causes (operational details) leading up to such an event like this since they are in various stages of presenting materials to grand juries, attending to hearings, participating in a prosecution, etc..  Normally afterwards which could be a year or better after suspects are declared innocent or a conviction the details slowly pour out and begin to be known.

We are providing here some links which were discussed on weekly conference calls and provided to us by a number of different sources. Target is known as having very strong internal security procedures, posture and no one should take this post to mean target is not helping its own cause.  Previously we have spoken to Target personnel and know full well something seriously went awry. 

We have a deep sense of intrigue which is only natural and want to learn every single detail about this serious beach.  However as security practitioners we must be responsible and utilize some common sense and respect for the internal practitioners with the Security Teams at Target.  The security teams, their tasks, workload, etc these days must be daunting (incident response, business continuity programs and disaster recovery plans will receive plenty of scrutiny this time around).

We are posting from Neiman-Marcus as well even through the two cases have not been connected.

http://www.zdnet.com/neiman-marcus-1-1-million-cards-compromised-7000025513/
http://www.nytimes.com/2014/01/24/business/neiman-marcus-breach-affected-1-1-million-cards.htmlhttp://www.neimanmarcus.com/NM/Security-Info/cat49570732/c.cat?icid=topPromo_hmpg_ticker_SecurityInfo_0114

http://m.computerworld.com/s/article/9245877/Target_says_attackers_stole_vendor_credentials?source=CTWNLE_nlt_security_2014-01-30
http://krebsonsecurity.com/
http://krebsonsecurity.com/2014/01/a-first-look-at-the-target-intrusion-malware/
http://www.cnbc.com/id/101329300
http://www.reuters.com/article/2014/01/12/us-target-databreach-retailers-idUSBREA0B01720140112
http://www.us-cert.gov/ncas/alerts/TA14-002A
http://krebsonsecurity.com/2013/12/sources-target-investigating-data-breach/
http://pressroom.target.com/news/target-confirms-unauthorized-access-to-payment-card-data-in-u-s-stores

This listing is a short list but can lead to many solid sources.  We would also like to acknowledge the SANS organization that provides all of us some well thought out background discussion on this topic in its newsbites publication.  


CONCLUSION: 

Integris Security would be falling short not to mention to our clients and prospects that security awareness starts before a breach, before an employee is let go, before the budget cycle crows no more.  Simple security awareness proves to be an effective first step in a series of steps required to withstand the hailstorm which now befalls Target and others.   Security is not something JUST for those high tech guys and gals to mull over and talk about.  The security discussion from the smallest to the largest corporation starts with the CEO and is a culture he/she causes to infect every single part of the corporation.   This is a difficult thing for some when nothing seems to be happening.  Like fire drills being prepared with worth billions as we now see Target is prepared to spend.  



UPDATE:  3/10/2014

Thanks to our members.  The truth about the Target Breach is getting out.  Here is the latest:

"Troy Leach, the lead security standards architect for the PCI Council, testified March 5 that the vulnerabilities of magnetic-stripe card transactions have to be addressed. But he stressed that a migration to more secure chip card technology that conforms to the Europay, MasterCard, Visa standard would not, by itself, eliminate all security risks. In fact, he contended that the use of chip cards would not have prevented the exposure of card data caused by the malware attacks against Target and Neiman Marcus."

http://www.bankinfosecurity.com/target-hearings-emv-enough-a-6607


UPDATED: 3/13/2014

http://www.businessweek.com/articles/2014-03-13/target-missed-alarms-in-epic-hack-of-credit-card-data

Business week outlines the missed opportunities that TARGET had to stop the bad guys at the front door.  Some generalization about what happened overseas as well as adding to "Who" dropped the ball.  We may live in a global society but what part of the "global" isn't getting the "Security" message - this is not clear.  Assertions have been made that if kept inside the U.S., this security failure would not have happened, but that is easier said then done.  It is to be seen if analyst have the time....with all the blown data breaches if "OUTSOURCING" is in fact a savings or part of the overall cost house.  In this case it would appear as though TARGET may have save some cash by keeping things in the U.S., but all of this is very much UNPROVEN at the time of this post.

Fact was that Target was one of the big box companies at the vanguard of security.  Perhaps in hindsight they have realized that the security staff in place was not as "state of the art" or as "progressive" as one needs to be given the size and complexity of a major corporation.  Then one needs to ponder is this a problem of a CIO, CTO, CISO or other security persons?  Or is this a total miscalculation of the CEO, COO, CFO and do shareholders derserve a say in whether these individuals have earned a long term seat at TARGET?  Truly a let down, a major disappointment of a highly successful retailer here in the U.S.

UPDATED: 3/17/2014
http://www.computerworld.com/s/article/9246942/Major_companies_like_Target_often_fail_to_act_on_malware_alerts

The blog is updated with this article to highlight the fact that technology alone will not solve the IT security issues.  Ongoing professional development, exercises that test the effectiveness of staff with combined with indepth knowledge, skills and abilities about onboarding specific security tools is not cheap, but is the likely candidate for success of any security team.  Combining human resources and effective tools such as Fire Eye is a receipe for success.  Not cheap, but for certain an investment worthy of a healthy report card for any major corporation.

Joseph Concannon

Tuesday, October 1, 2013

Integris Security Tools - Test Yourself Before Your Attackers Do

Integris Security has recently launched their FREE online enabled security tools in conjunction with National Cyber Security Awareness Month.  These tools were typically only available from within a command line interface (CLI) and require low level knowledge of the tools themselves. The Integris Security Tools removes this requirement and extends these tools to within a web browser and even your smart phone. You simply sign up for an account, validate some information and your ready to begin using these tools.  Simply enter a URL/Fully Qualified Domain Name, IP Address and, in some circumstances, a port number.

Depending on the particular scan and the latency between our servers and the target server, scans can take several minutes. Because of this, we've included the capability to have scan results emailed to your registered address. Otherwise, you will receive scan results within your current browsers session.

Available tools currently include the following types of technologies.

  • SSL/TLS Server Strength
  • Port Scanner
  • HTTP Security Scanners
  • Domain Name Checkers
  • Web Framework Scanners
  • DNS Amplification Tester
  • and more...
We're continually investigate adding additional tools to increase the value of our free offering.

We highly encourage you to sign up and begin using these tools to help you increase your security posture.

Our service offerings include capabilities above and beyond these tools. If you require a more thorough, more in depth analysis then do not hesitate to email us at sales (at) integrissecurity (dot) com, call us at +1(516)750-0478 or visit our website at https://www.integrissecurity.com/.

For more information on National Cyber Security Awareness
Month, please visit http://www.staysafeonline.org/ncsam/.

Friday, September 20, 2013

Washington Navy Yard Shootings


Statement from Joe Concannon on Washington Navy Yard Shootings

Former NYPD Captain and New York City Council candidate Joseph Concannon issued a statement today that the horrific murders by a Queens man in Washington DC is an urgent reminder of our need to be prepared as public servants, as private citizens, and as businesses.
Joe Concannon with PBA President Pat Lynch
Joe Concannon with PBA President Pat Lynch at Manhattan Reception
September is National Preparedness Month. We should all be reviewing our personal plans to be prepared for such incidents. Terrorism, foreign or domestic, is alive and well and New York City cannot afford to let its guard down. Whether in our homes, places of business, public spaces, such as malls, parks, or public concerts we need to be vigilant. City agencies and businesses need to review their preparedness plans for Active Shooter Incidents (ASI) and other emergency crises.
This is a tragic reminder that we need to keep our law enforcement organizations strong and give them the tools and the means to protect us. Remember that NYPD will be the very first responders on the scene of any such incidents. We, as residents of the number one target city in the world, need to make sure to empower the NYPD to do their jobs with the urgency and efficiency that our situation in New York City calls for.
The victims of the Washington Navy Yard massacre included civilians, service members and police officers. Our hearts go out in prayer to the families of the loved ones who perished in one of the most deadly attacks on a military installation.
Joseph Concannon, a distinguished public servant for over 30 years in the NYPD and former Deputy Director for Public Safety in the Giuliani administration, is now running for City Council in Eastern Queens, District #23 on the Reform Party line. He has public/private background as CEO of the FBI InfraGard Program here in NYC and presently is president of his own business, Integris Security LLC. His lifelong career in law enforcement and the private security sector makes him the city’s top authority on public safety and security for New York City.
SUPPORT YOUR LOCAL POLICE

Tuesday, July 23, 2013

Open for Business - Integris Security LLC

www.integrissecurity.com is now live
July 23, 2013             

Good evening everyone,

We broke ground about 40 days ago and here's our story:


Integris Security LLC has grown out of years passion for protecting our city, state and nation, its critical infrastructures and providing industry professionals with the best of breed solutions, practices and top notch security awareness. As things change for us from InfraGard to Integris Security LLC one thing will never change - the importance of nurturing your TRUST.
InfraGard a national public/private program of the FBI is the crossroad that brought us together as individual security professionals and that frames the very basis of our focus as a private security
company. Our security journey at InfraGard is well documented at NYM Infragard. We understand all too well the meaning behind Confidentiality, Availability and Integrity; in part its where we derived our name from. Each member of our staff at Integris is a vetted security professional.
For twelve years we've been taking the calls, learning what keeps you up at night and the utter frustration some of you are going through. The gentle balance of security and functionality continues and is a struggle that many professionals in industry have to deal with as a part of their daily routine. We have been busy identifying products, solutions, building bridges between the public and private sectors by seeding discussions, helping others to manage their expectations by providing our analysis, perspectives and at times putting out some fires. We've taken a bumpy ride with you on Wireless, BYOD, Network Security, DLP, The Cloud, Intelligence and much more. We've asked and will continue to ask the questions over and again what are we protecting, why are we protecting it and who owns the data?
At Integris Security we can help you emphasize and prioritize the importance of what's critical to running the business, in identifying the data to be protected, in testing to identify your vulnerabilities, identification of what and who is on your network, in helping you resolve audit recommendations and provide you with a roadmap for future success.
It all starts with building the trust.
We are very excited to continue the security journey with you and invite you to contact us with your security, risk management needs or if all you need is someone to listen as you walk us through your security/risk management concerns.
  1. www.integrissecurity.com is live

Thursday, July 18, 2013

InfraGard Conference Call 7/17/13

Good afternoon all,

Earlier today I had the good fortune to be on the InfraGard NYC weekly conference call.  We were discussing an issue I raised in our Linked-In Group, Integris Security Insights.  If you'd like to be invited to the group just let us know.  The group is a terrific group of security professionals.

On the linked-in group I try to be mildly provocative and sometimes even a little sarcastic given the incident or situation of the day.  In this weeks post I asked the question do you know who's on your network or what's on your network?

The point is this: too many companies have no idea how to even begin to wrap their hands around these questions.  For larger companies this can get complex.  For smaller to mid sized companies we have something which could answer some of your troubles.  

Take a look at Lan Sweeper as a tool which can help you map your network, count your machines, switches, routers, software licenses and more.  Their may also be some "open source" resources and when and if we find them I'll post it here.

Have a great day!

Joe Concannon

Wednesday, July 17, 2013

Integris Security is coming on line and our security services offering is now in development.  Stay tuned as we ramp things up and take our work from construction to ready for prime time.  Hang with us and be patience.