Wednesday, November 11, 2009

Reaction to 60 Minutes Story

I institute the new 60 Minutes update on information struggle to be interesting. I fear that the speaking over whether or not "hackers" unfit Brazil's electrical installation module command the real supply presented in the story: advanced persistent threats are here, have been here, and module move to be here. Some critics verify APT must be a bogey Negro invented by agencies arguing over how to gain greater curb over the citizenry. Let's accept agencies are arguing over turf. That doesn't stingy the threat is not real. If you refuse to accept the threat exists, you're simply naif of the facts. That might not be your fault, given policymakers' qualifying unwillingness to speak out. If you poverty to intend more facts on this issue, I recommend the biochemist Grumman report I mentioned terminal month.Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)
Vip Surfer

Sunday, November 8, 2009

Notes from Talk by Michael Hayden

I had the distinct privilege to attend a keynote by old Air Force General archangel Hayden, most recently CIA administrator and previously NSA director. NetWitness brought Gen Hayden to its individual word this week, so I was rattling entertained to attend that event. I worked for Gen Hayden when he was commander of Air Intelligence Agency in the 1990s; I served in the information warfare intellection sectionalization at that time.Gen Hayden offered the conference quaternary main points in his talk.
  • "Cyber" is arduous to understand, so be charitable with those who don't see it, as substantially as those who verify "expertise." Cyber is a domain same another warfighting domains (land, sea, air, space), but it also possesses unique characteristics. Cyber is man-made, and operators crapper edit its geographics -- even potentially to destroy it. Also, cyber conflicts are more likely to modify another domains, whereas it is theoretically doable to fight an "all-air" battle, or an "all-sea" battle.
  • The evaluate of modify for profession far exceeds the evaluate of modify for policy. Operator activities escape our knowledge to remember them. "Computer network defense (CND), exploitation (CNE), and move (CNA) are operationally indistinguishable." Gen Hayden compared the rush to amend and deploy profession to consumers and organizations to the realty rushes of the late 1890s. When "ease of use," "security," and "privacy" are weighed against apiece other, ease of ingest has traditionally dominated. When making policy, what should apply? Title 10 (military), Title 18 (criminal), Title 50 (intelligence), or planetary law?Gen Hayden asked what clannish organizations in the US reassert their own ballistic arm defense systems. None of course -- meaning, why do we expect the clannish sector to indorse itself against cyber threats, on a "point" basis?
  • Cyber is arduous to discuss. No one wants to speech most it, especially at the domestic level. The agency with the most aptitude to indorse the commonwealth suffers because it is both info and powerful, two characteristics it needs to be effective. The public and policymakers (rightfully) discredit info and coercive organizations.
  • Think same info officers. I should hit expected this, coming from the most important info tar of our age. Gen Hayden says the first discourse he asks when temporary private companies to consult on cyber issues is: who is your info officer? Gen Hayden offered advice for those with an info mindset who wage advice to policymakers. He said intel officers are tralatitious inductive thinkers, play with indicators and nonindustrial facts, from which they create general theories. Intel officers are ofttimes demoralised and graphic because they care with operational realities, "as the concern is."Policymakers, on the another hand, are ofttimes deductive thinkers, play with a "vison," with facts at the another modify of their thinking. "No one elects a politician for their bidding of the facts. We elect politicians who hit a vision of where we should be, not where we are." Policymakers are ofttimes pollyannaish and idealistic, hunting at their modify goal, "as the would should be."When these two concern views meet, feature when the intel tar briefs the policymaker, the termination crapper be jarring. It's up to the intel tar to figure discover how to inform findings in a way that the policymaker crapper colligate to the facts.
  • After the embattled remarks I asked Gen Hayden what he intellection of threat-centric defenses. He said it is not outside the realm of possibility to hold giving clannish organizations the right to more aggressively indorse themselves. Private forces already action protect duties; personnel forces don't carry the full charge for preventing crime, for example.Gen Hayden also discussed the developments which led from expeditionary ingest of expose power to a separate Air Force in 1947. He said "no one in cyber has unsuccessful the Ostfriesland yet," which was a enthusiastic analogy. He also says there are no highbrowed equivalents to bandleader designer or Apostle Nitze in the cyber intellection landscape.Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)
    Vip Surfer

    DojoCon Videos Online

    Props to Marcus Carey for springy streaming talks from DojoCon. I appeared in my keynote, nonnegative panels on incident response and darken security. I intellection the word was excellent and some grouping posted their thoughts to #dojocon on Twitter.Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)
    Vip Surfer

    Thursday, November 5, 2009

    How To Promote A Proxy Site

    Creating proxy sites seem to be pretty popular these days. Thousands of people use them every day and there is certainly a proliferation of free proxy scripts available to webmasters who are looking to start one. But due to this fact it is pretty difficult to become a big fish in the sea of proxies. So let’s get down to the point – how do you successfully promote a new proxy site? Here are five tips that will help you beat the competition.

    1. List your site on proxy.org and other directories. Proxy.org is the biggest proxy directory online and you can receive a sizable amount of traffic if you have yours listed with them. Don’t ignore the smaller directories, however, because you can still receive good traffic from them.
    2. Advertise on game arcade sites. A large chunk of proxy users, like students and company employees, use proxies to play games on arcade sites or browse social networking sites, sense those are usually the type of site that get blocked. By advertising on these sites you are getting your name out to your potential audience.
    3. Get a dedicated server. Proxies take up a lot of bandwidth and system resources, so most shared hosting providers do not allow their clients to run proxies. You do not want to start getting traffic to your new site only to have your hosting provider shut you down because of a violation of their terms. Do it right from the start.
    4. Advertise using a MySpace profile. I know, you’re thinking ugh. But it works, and traffic is traffic. Create a MySpace profile and get a bunch of friends. Have your site link displayed prominently on your profile page and occasionally send out messages to all of your friends telling them of your proxy. Just remember to abide by MySpace’s TOS. MySpace promotion is a shady area, especially if you start getting into friend adder robots and such.
    5. Make it simple. People come to proxies for one reason – to surf other websites. So make it easy for them to do. Have your form that takes in the URL that the user wishes to visit displayed front and center. There is no need to have a lot of clutter. Honestly, all you probably need is a quick blurb about your proxy, an adsense block above your form and one below it, and that’s it.

    Proxies tend to come and go fast. Take yours into the big league by building a solid, simple site hosted on a dedicated server and promoting the hell out of it. You may initially be wary about having to plunk down $99 to $140 a month on a dedicated server, but it won’t do you any good if after a month your hosting account gets shut down.

    If you follow the tips above you will get lots of traffic, fast, so you’ll quickly need the power of a dedicated host. And with traffic comes revenue potential. Stay tuned for my next article which will show show you how to beat the notoriously low click through rates of proxy sites and make a profit!

    Tuesday, November 3, 2009

    Tentative Speaker List for SANS Incident Detection Summit

    Thanks to everyone who attended the Bejtlich and Bradley Webcast for SANS yesterday. We transcribed that Webcast (audio is today available) to start a communicating concerning professed incident detection.I'm entertained to publish the following unsettled utterer itemize for the SANS WhatWorks in Incident Detection Summit 2009 on 9-10 Dec in Washington, DC. We'll publish every of this information, nonnegative the biographies for the speakers, on the list site, but I desired to deal what I hit with you.Day One (9 Dec)
    • Keynote: Daffo Gula
    • Briefing: Network Security Monitoring dev+user: Bamm Visscher, David Bianco
    • Panel: CIRTs and MSSPs, moderate by Rocky DeStefano: archangel Cloppert, Nate Richmond, Jerry Dixon, President Hudak, Matt Richard, Jon Ramsey
    • Cyberspeak Podcast live during meal with Bret Padres and Ovie Carroll
    • Briefing: Bro introduction: man Hall
    • Panel: Enterprise meshwork spotting tools and tactics, potentially with a temporary moderator: Daffo Shaffer, Matt Olney, Nate Richmond, Matt Jonkman, archangel Rash, Andre Ludwig, Tim Belcher
    • Briefing: Snort update: histrion Roesch
    • Panel: Global meshwork spotting tools and tactics: Stephen Windsor, peer Zmijewski, Andre' M. Di Mino, Matt Olney, Jose Nazario, Joe Levy
    • Panel: Commercial section info service providers, moderated by Mike Cloppert: Gunter Ollmann, Rick Howard, Dave Harlow, Jon Ramsey, Wade Baker
    • Evening clas: Advanced Analysis with Matt Richard
    Day Two (10 Dec)
    • Keynote: Tony Sager
    • Briefing: Memory psychotherapy dev+user: ballplayer Walters, Brendan Dolan-Gavitt
    • Panel: Detection using logs: Jesus Torres, Nate Richmond, archangel Rash, Matt Richard, Daffo Gula, J. saint Valentine, Alex Raitz
    • Panel: Network Forensics: Tim Belcher, Joe Levy, histrion Roesch, Ken Bradley
    • Briefing: Honeynet Project: Brian Hay, archangel Davis
    • Panel: Unix and Windows tools and techniques: archangel Cloppert, Apostle Mullen, Kris Harms
    • Panel: Noncommercial section info service providers, moderated by Mike Cloppert: Andre' M. Di Mino, Jerry Dixon, Ken Dunham, Andre Ludwig, Jose Nazario
    • Panel: Commercial host-centric spotting and psychotherapy tools: Dave Merkel, Daffo Gula, Alex Raitz
    I'm thankful to hit these excellent speakers and panel participants on board for this event. If you run and pay tuition by next Wednesday, 11 Nov, you'll spend $250. Thank you.Copyright 2003-2009 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)
    Vip Surfer