<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Web Admin Blog &#187; tools</title>
	<atom:link href="http://www.webadminblog.com/index.php/tag/tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webadminblog.com</link>
	<description>Real Web Admins.  Real World Experience.</description>
	<lastBuildDate>Thu, 22 Jul 2010 16:18:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Enterprise Application Security &#8211; GE&#8217;s Approach to Solving Root Cause</title>
		<link>http://www.webadminblog.com/index.php/2009/11/12/enterprise-application-securit/</link>
		<comments>http://www.webadminblog.com/index.php/2009/11/12/enterprise-application-securit/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 16:30:28 +0000</pubDate>
		<dc:creator>Josh</dc:creator>
				<category><![CDATA[OWASP AppSec DC 2009]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[ge]]></category>
		<category><![CDATA[metrics]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.webadminblog.com/?p=299</guid>
		<description><![CDATA[The first presentation of the day that I went to  was by GE's Darren Challey and was about GE's application security program and how he took a holistic approach to securing the enterprise.  My notes on this presentation are below: Why is AppSec so hard? AppSec changes rapidly (look at difference between 2004, 2007, and [...]]]></description>
			<content:encoded><![CDATA[<p>The first presentation of the day that I went to  was by GE's Darren Challey and was about GE's application security program and how he took a holistic approach to securing the enterprise.  My notes on this presentation are below:</p>
<p>Why is AppSec so hard?</p>
<ul>
<li>AppSec changes rapidly (look at difference between 2004, 2007, and 2010 Top 10)</li>
<li>Changing landscape
<ul>
<li>Increase skill and talen t pool of technically proficient individuals willing to break the law</li>
<li>Growing volume of financially valuable data online</li>
<li>Development of criminal markets (black markets) to facilitate conversion to money</li>
</ul>
</li>
<li>"Attackers now have effective skills, something to steal, and a place to sell it"</li>
</ul>
<ul>
<li>Application Security is a complete one-sided game</li>
<li>Need to become an enabler (not a barrier)</li>
<li>Must inject application security earlier through Guidance, Education, and Tools</li>
<li>Must understand the development and deployment process and integrate rather than mandate</li>
<li>NIST study on cost to repair defects when found at different stages of software development (http://www.nist.gov/director/prog-ofc/report02-3.pdf)</li>
<li>Solving the problem of the enterprise (Culture Change)</li>
<li>Success factors</li>
<li>Form a mission and strategy</li>
<li>Develop policy (but not corporate "mandate")</li>
<li>Gain executive buy-in (cost / benefit / risk)</li>
<li>Understand the magnitude of problem (metrics)</li>
<li>Asset inventory and vulnerability management</li>
<li>Develop standards (what should I do and when?)</li>
<li>Establish a formal program (strong leadership)</li>
<li>Focus on education and training materials</li>
<li>Develop in-house expertise, services and "COE"</li>
<li>Continuous improvement, measurement, KPI</li>
<li>Communicate!</li>
<li>Drive a culture change (shared need, WIIFM)</li>
<li>Communicate expectations with vendors</li>
<li>Implement incentives (and penalties)</li>
<li>Digitize after the process is solid (tools)</li>
<li>AppSec program mission &amp; structure</li>
<li>AppSec program strategy</li>
<li>Policy (guidance) -&gt; Standards (Guidance) -&gt; Training (Education) -&gt; Metrics (tools) -&gt; Security tools (tools) -&gt; Inventory &amp; tracking (tools) -&gt; Monitor &amp; Improve</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Guidance</strong></span></p>
<ul>
<li>"GE Application Security Working Group" (Talking to the businesses is critical!  Meet every 2 weeks.)</li>
<li>Secure Coding Guidelines</li>
<li>Vulnerability Remediation Guide</li>
<li>Secure Deployment</li>
<li>Quick Reference Card</li>
<li>Contractual Language</li>
<li>Desk Calendars</li>
<li>Metrics: AppSec calendars helped increase visitors to key Guidance materials  (track hits to website docs when certain activities take place)</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Education</strong></span></p>
<ul>
<li>CBT1: Intro to AppSec at GE (60 min for any IT person) - why AppSec is important and what happens when you don't do it</li>
<li>CBT2: GE Best Practices for Secure Coding (90 min)</li>
<li>CBT3: Attack Profiles &amp; Countermeasures (120 min for security people)</li>
<li>Developer Awareness Assessment:
<ul>
<li>100's of internally-developed questions</li>
<li>Randomized questions, timed completion</li>
<li>Vendors track their own resutls</li>
<li>Allows tailoring of training/awareness programs</li>
</ul>
</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Tools</strong></span></p>
<ul>
<li>- COE AppSec assessment services</li>
<li>Vendor framework &amp; Metrics</li>
<li>Compliance handbook</li>
<li>Common objects repository</li>
<li>GE Enterprise Application Security</li>
<li>Scanning and Monitoring tools</li>
<li>Automation is the way to go (but the tools are not quite there yet)</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Metrics</strong></span></p>
<ul>
<li>Measure Vendor AppSec Performance (Avg % Critical/High Vulnerabilities per Assessment vs % Assessments with Zero Critical/High Vulnerabilities)</li>
<li>Is it making a difference (map avg of critical/high vulnerabilities per assessment)</li>
</ul>
<p><span style="text-decoration: underline;"><strong>Forming a Center of Excellence</strong></span></p>
<ul>
<li>Combines the best available people, processes and tools</li>
<li>Formal training &amp; defined roles (Comprehensive training program for all auditors to ensure skills are kept current and that auditors can provide more than one type of service)</li>
<li>COE Team structure (tools, research, operations, stakeholder management, queue management, application security auditors</li>
<li>Application Assessment Types (black/grey box vs white box)</li>
<li>Application assessment process (map of the workflow with "swim lanes" of who does each step)</li>
<li>Measure number of vulnerabilities and severities</li>
<li>Measure customer satisfaction (overall, ease of engagement, responsiveness)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.webadminblog.com/index.php/2009/11/12/enterprise-application-securit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anatomy of an Attack: From Incident to Expedient Resolution</title>
		<link>http://www.webadminblog.com/index.php/2009/03/25/anatomy-of-an-attack-from-incident-to-expedient-resolution/</link>
		<comments>http://www.webadminblog.com/index.php/2009/03/25/anatomy-of-an-attack-from-incident-to-expedient-resolution/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 14:15:49 +0000</pubDate>
		<dc:creator>Josh</dc:creator>
				<category><![CDATA[TRISC 2009]]></category>
		<category><![CDATA[anatomy]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[flow]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[resolution]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.webadminblog.com/?p=196</guid>
		<description><![CDATA[For the first session of the morning on the last day of the TRISC 2009 Conference, I decided to attend the "Anatomy of an Attack: From Incident to Expedient Resolution" talk by Chris Smithee, a Systems Engineer at Lancope.  He talked about the different types of attacks that you see on your network and how [...]]]></description>
			<content:encoded><![CDATA[<p>For the first session of the morning on the last day of the TRISC 2009 Conference, I decided to attend the "Anatomy of an Attack: From Incident to Expedient Resolution" talk by Chris Smithee, a Systems Engineer at Lancope.  He talked about the different types of attacks that you see on your network and how using FLOW data can be used to monitor and eliminate some of these types of threats.  My notes from the session are below:<span id="more-196"></span><br />
<span style="text-decoration: underline;">Types of Attacks</span></p>
<ul>
<li> Barbarian Horde
<ul>
<li>Our castle walls must keep us safe
<ul>
<li>Script kiddies and DDoS</li>
</ul>
</li>
</ul>
</li>
</ul>
<ul>
<li> Ninjas
<ul>
<li>Knowledgeable “Haxx0rs” with deliberate intent
<ul>
<li>Social engineering to exploits</li>
</ul>
</li>
</ul>
</li>
<li>Vampires
<ul>
<li>Generally have to be “invited” in
<ul>
<li>Convert others to their side</li>
<li>Malware, worms, and botnets</li>
</ul>
</li>
<li>Vampires are social creatures</li>
</ul>
</li>
</ul>
<p><span style="text-decoration: underline;">Problems with Traditional Mechanisms</span></p>
<ul>
<li> The Barbarian Horde
<ul>
<li>How do we know its working?</li>
</ul>
</li>
<li>Ninjas
<ul>
<li>Ninjas are stealthy and think outside the box</li>
<li>Social Engineering can grant all manner of access</li>
</ul>
</li>
<li>Vampires
<ul>
<li>What happens if you’re the first one bit?</li>
<li>Where do you have your safeguards?</li>
</ul>
</li>
</ul>
<p><span style="text-decoration: underline;"> How can Flow Data help? (Packet level logging for network devices – Ex: NetFlow)</span></p>
<ul>
<li> Global Accounting
<ul>
<li>Who, what, where, when, how</li>
</ul>
</li>
<li>Barbarians
<ul>
<li>Who made it through the castle wall?</li>
</ul>
</li>
<li>Ninjas
<ul>
<li>Forensic data</li>
<li>“Soft-Firewall” like rules</li>
</ul>
</li>
<li>Vampires
<ul>
<li>Containment is key – one hop away</li>
<li>Policy verification</li>
</ul>
</li>
</ul>
<p><span style="text-decoration: underline;"> Why Flow?</span></p>
<ul>
<li> Leverage your existing network infrastructure to quickly, accurately detect, contain and remediate incidents.</li>
<li>Anywhere from a 3-10% impact on processor.  Memory impact is even smaller.</li>
</ul>
<p><span style="text-decoration: underline;"> Freeware flow data</span></p>
<ul>
<li> FLOW-TOOLS</li>
<li>NMon</li>
</ul>
<p><span style="text-decoration: underline;"> Behavioral Analysis?</span></p>
<ul>
<li> Flow data is awesome.  Why the expert system?
<ul>
<li>Flow data is plentiful – drinking from the firehose can hurt</li>
</ul>
</li>
<li>The problem of context
<ul>
<li>Signatures and rules may not always be appropriate</li>
</ul>
</li>
<li>Bobby Sue doesn’t normally upload this many files to the Net</li>
<li>Who has staff available to constantly scrub files and graphs?</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.webadminblog.com/index.php/2009/03/25/anatomy-of-an-attack-from-incident-to-expedient-resolution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
