Showing posts with label Cloud Computing. Show all posts
Showing posts with label Cloud Computing. Show all posts

Saturday, May 22, 2010

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security & Privacy; Q & A on Cloud, Cyberwar & Internet Freedom w/ Dr. Peter Neumann

Ross Anderson and Steven Murdoch of University of Cambridge accept 2010 IEEE Symposium of Security & Privacy Best Practical Paper Award

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security & Privacy; Q & A on Cloud, Cyberwar & Internet Freedom w/ Dr. Peter Neumann

By Richard Power


The 2010 IEEE Symposium on Security and Privacy, held in Oakland, California, marked the 30th anniversary of this prestigious event.

Carl Landwehr, Program Director for the National Science Foundation, Senior Research Scientist at University of Maryland Institute for Systems Research (and Editor in Chief of IEEE Security & Privacy Magazine) received two awards: IEEE Computer Society Distinguished Service Award and Computer Society Technical Committee on Security and Privacy Outstanding Community Service Award.

Jerry Saltzer, Professor Emeritus of the M.I.T. Computer Science and Artificial Intelligence Lab (CSAIL), received the National Computer Security Award. Previous recipients include Jim Anderson, Dennis Branstad, Steven Bellovin, David Clark, Robert Courtney, Dorothy Denning, Whit Diffie, Virgil Gligor, Martin Hellman, Butler Lampson, Peter Neumann, Donn Parker, Ron Rivest, Roger Schell, Mike Schroeder, Eugene Spafford, Walter Tuchman, Steve Walker, and Willis Ware.

The "Best Paper" award went to Margarita Osadchy, Benny Pinkas, Ayman Jarrous, Boaz Moskovich of Univesity of Haifa for "CiFI - A System for Secure Face Identification."

The "Best Student Paper" award went to "TaintScope: A Checksum-Aware Directed Fuzzing Tool for Automatic Software Vulnerability Detection" by Tielei Wang, Tao Wei and Wei Zou of Peking University, and Guofei Gu of Texas A & M University

The award for "Best Practical Paper," sponsored by IEEE Security and Privacy Magazine, went to Ross Anderson, Steven Murdoch, Saar Drimer and Mike Bond of the University of Cambridge for Chip and PIN is Broken. This work describes and demonstrates "a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card’s PIN, and to remain undetected even when the merchant has an online connection to the banking network. The fraudster performs a man-in-the-middle attack to trick the terminal into believing the PIN verified correctly, while telling the card that no PIN was entered at all." (For more information and the full paper, go Ross Anderson's blog, Light Blue Touchpaper, 2-11-10)

As mentioned in my previous post on this year's Symposium, there were 31 papers presented in the course of the three day event. These papers explored ten research areas, from Malware Analysis (e.g., Automated Extraction of Proprietary Gadgets from Malware Binaries) and Network Security (e.g., Round-Efficient Broadcast Authentication Protocols for Fixed Topology Class) to Systemization II (e.g., Bootstrapping Trust in Commodity Computers) and Analyzing Deployed Systems (e.g., Experimental Security Analysis of a Modern Automobile).

Such research is vital, and it is always inspiring to listen to the fruits of this worthy labor. But I confess that as I sat through session after session, I found myself drawing back to contemplate the big picture, as I have been doing in my writings and talks over the last few years. (See, for example, Starting Over After A Lost Decade, In Search of a Bold New Vision for Cyber Security (Cerias Security Seminar, 9-30-09) and Red Pill? Blue Pill? Ruminations on the Intersection of Inner Space and Cyber Space (CSO Magazine, 10-23-09).

As I scanned the overflowing audience, I saw Peter Neumann hunched over his laptop, and sitting in the last row. So I asked him to give me his insights on the three big pictures questions I have been mulling over.

Q: At this year's RSA conference, I was struck by one keynote speaker after another, declaring the "cloud" as the future, and exhorting everyone to hurry into the "cloud" where we will find security much easier to attain, and everything will be better. Who is "we" is hard to answer in the cloud. Who is securing who, and what else are they doing? These are real concerns. Could you talk about the cyber security and privacy implications of "Cloud computing"?

Peter Neumann: Yes, I noticed Scott Charney, Howard Schmidt, Janet Napolitano extolling the wonders of cloud computing, and so many vendors saying they had it all under control. This is sheer and utter nonsense. Having to trust untrustworthy third- and fourth-party vendors, some of whom you do not even know exist (cf. Les Lamport's definition of a Distributed System) is ridiculous, given that the infrastractures, the computer systems, and the authentication processes are not trustworthy. Confidentiality and privacy may be least of our concerns, compared with system integrity, denials of service attacks, the lack of traceability and attribution, the lack of meaningful audit trails, and so on.

Q: The term "Cyberwar" is taking on a life of its own. You and I discussed "information warfare" well over a decade ago. What would you like to say about this term "cyberwar" and what it purports to describe? Overly hyped? Something different than the issues we have been dealing with all along in the struggle to secure cyberspace? Both?

Neumann: Cyberwar is indeed an overly hyped concept. The "war" on terrorism is a bad enough metaphor, but "cyberwar" is even worse. Who is the enemy? As Pogo once said, "We have met the enemy, and he is us." We will never completely secure "cyberspace", and the "enemy" will always have many advantages. However, we could do much better than we do at present. Also, take a look at my paragraph on the misuse of "cyber" (which is a combining form, not a noun or an adjective) on my website: http://www.csl.sri.com/neumann. (I just put up a new limerick on "metrics" also.)

Q: Spaf said something to me awhile ago, that perhaps there will be no Internet readily and freely accessible ten or twenty years into the future. I used to jokingly tell people that although the proverbial "they" succeeded in burning down the library of Alexandria, the proverbial "they" won't be able to due the equivalent to the Internet ... Ha ha ... Now I wonder. For example, the battle over net neutrality could be won in the legislatures but lost in the cloud, couldn't it? Net neutrality, government censorship, the mysterious hidden workings of the cloud, do these threaten the future freedom and evolution of the internet as a global commons? And is there any hope?

Neumann: On "network neutrality," unless the lobbyists' control over Congress ceases, legislative solutions will continue to be largely misguided in this area. But even if legislation were to become sensible here, you are correct -- it could still be lost in the clouds. Is there any hope? Yes, of course, we have to retain some modicum of optimism, but it must be accompanied by a radical shift in the entire culture by which mediocre systems with short-sighted requirements and short-sighted development practices abound. Think about BP's practices in the Gulf, and the financial industry, and you have an approximation for the computer industry and practice.

In conclusion, Neummann added, "This is off the top of the head, and reflects just a few of my holistic concerns. The picture requires much greater total-system long-term thinking than is used today."

As always, Neumann's thinking is both provocative and profoundly insightful.

And as always, if industry and government choose to ignore him, they do so not only at their own peril, but at the peril of all.

Of course, the Cloud is now inevitable; after all, it has been decreed by the captains of industry. Yes, it will offer both challenges and opportunities. But we should not sell it to ourselves as a security strategy, we should not fool ourselves, it is simply another dimension of risk added to the many dimensions of risk we are already operating within.

In regard to the term "Cyberwar," my views are somewhat complex, and contradictory, I find myself promoting it in some contexts, and debunking it in others, depending upon the misconceptions that dominate the space of the discussion.

And the future of the Internet? Well, the future of the Internet as a free and open cyberspace is nothing less than the future of human civilization; not necessarily the future of the human race, but of human civilization, or perhaps more precisely anything worthy of being called a "human civilization." Therefore, it is too important to be left to industry and government, or both, at least as long as there is a revolving door between the two, and especially while all other voices are without counter-balancing influence.

Preserving a free and open Internet, and making it accessible for the private use of all humans is both a security issue and a human rights issue; and increasingly, in the 21st Century, security issues and human rights issues are becoming interdependent, and as in other arenas of human endeavor, we can no long allow commercial interests to trump security and human rights concerns.

See Also

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?

Friday, March 5, 2010

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?

By Richard Power


Some final observations on RSA Conference 2010:

The presentations I wanted to get to, but couldn't, because of time constraints: "Local is the New Organic - A Bottom-Up Model for Information Sharing," in which Michael Hamilton of the City of Seattle introduced a model for the automated collection of security event data from public and private entities across a metropolitan area, and "Crowd Sourcing Fraud and Abuse Detection," in which Lee Holloway of Project Honey Pot presented early success in breaking down barriers and facilitating the free flow of abuse information between organizations. I hope that even today we live in a world that still allows for the possibility that such ideas can be propagated and exploited for the good of the many as well as the few.

The more and more I hear about the Cloud, from the C-level ("C" for Cloud as well as "Chief") keynoters, the more and more I wonder just where it is we will find ourselves as we migrate lock, stock and barrel into the Cloud (and make no mistake about it, that is where we are all going, or at least that is where most of our IT infrastructure is going).

What are the implications, beyond the obvious security issues? (Indeed, for some enterprises, security in the Cloud will be better than what they have on their own? For example, will all of us find ourselves enveloped in a billowing Cloud so thick it will trump Net Neutrality?

And what about the security and privacy established inside that billowing Cloud, and guaranteed by a cluster of major corporations and massive law enforcement agencies? Will it protect you and I from everyone and everything except (perish the thought) ethically challenged corporations and misdirected law enforcement agencies? Don't get me wrong. We are all going into the Cloud, like it or not.

I just hope you keep one eye on the exits, and remember where everything is (or was) outside that Cloud.

I have covered the RSA Conference annually since the early 1990s. I remember when it consisted of couple of meeting rooms, at the Sofitel Hotel, crammed with cryptographers and a few developers. Then it became an e-commerce conference disguised as a security conference. Then it became the defining event of the year for the IT security sector. And now, it has become even something even bigger; it has become a cross-roads for whole industries, and for government and business, and a window on cultures (corporate, institutional and popular). Swirling in the din that rises up from this Barnum & Bailey production, you can detect intermingled strains of music that are both disturbing and inspiring.

After four CyBlog posts (one for every day of the conference), and over 60 tweets, I will close with a few brief excerpts from a presentation on "Wired for War: The Robotics Revolution and 21st Century Conflict," delivered by Dr. Peter Warren Singer, a Senior fellow and director of the 21st Century Defense Initiative at the Brookings Institution.

Dr. Peter Warren Singer, Brookings Institution: There is something big going on in war today, and maybe even in the overall history of humanity itself. The US military force that went into Iraq in 2003 had a handful of drones ... we now have over 7,000 in the U.S. military inventory. The invasion force on the ground utilizied zero unmanned ground vehicles, we now have over 12,000 ... This year, the U.S. Air Force will train more unmanned systems operators than it will train manned bomber and manned fighter plane pilots combined ... These Predators, [etc.], are the first generation, they are a lot like the Model-T Ford or the Wright Brothers Flyer ... very soon it is not going to be thousands of robots as we use in our war today, it is going to be tens of thousands ...One of the things that you are familiar with, of course is Moore's Law: the idea that we have been able to pack far more computing power into our micro-chips, such so that they just about double in their power capacity just under every two years. Moore's Law, in action, is the reason that if you have ever gotten one of those Hallmark Greeting Cards that opened up and played a little song, you held in your hand more computing power than the entire U.S. Air Force had in 1960 ... Now if Moore's Law holds true, over the next twenty-five years, our systems, our computers and our robots will be over a billion times more powerful than today ... literally ... What if Moore's Law doesn't hold true? Yeah, it's hold true over the last forty years, but there is no guarantee that it is going to hold true over the next twenty-five. What if it only goes one one-hundreth as fast? Well, that would mean that our computers and our robotics mere million times more powerful than today ... The kind of things we only use to talk about at Science Fiction conventions, like Comic-Con, need to be talked about by people like us here, and at the Pentagon. We are living through a robots revolution.

Recent history offers some compelling evidence for the reliability of Moore' Law. Unfortunately, spanning the entire history of human consciousness, there is scant evidence that our collective common sense or our collective conscience will increase in sufficient depth to keep up with the demands that have already long since overwhelmed their existing capacities.

So, lost in the Clouds, shrouded in the Fog of War, how far ahead of your next step are you able to peer?

Here is a summary of CyBlog posts from RSA Conference 2010, in chronological order:

RSA 2010: Lifestyle Hacking -- Notes on "Social Networks & Gen Y Meet Security & Privacy"

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism

RSA 2010: Merging Mind & Machine - Hacking the Neural Net

RSA 2010: Lost in the Cloud, & Shrounded in the Fog of War, How Far Beyond Your Next Step Are You Able to Peer into the Cyber Future?

See also RSA Conference 2009: Summary of Posts

Tuesday, February 23, 2010

Cyber Shock, Virtualization, Cloud Computing & the State of the Web -- Not for the Faint of Heart ...


Partial map of the Internet based on the January 15, 2005 data found on opte.org. Each line is drawn between two nodes, representing two IP addresses. The length of the lines are indicative of the delay between those two nodes. This graph represents less than 30% of the Class C networks reachable by the data collection program in early 2005. Lines are color-coded according to their corresponding RFC 1918 allocation as follows:
* Dark blue: net, ca, us
* Green: com, org
* Red: mil, gov, edu
* Yellow: jp, cn, tw, au, de
* Magenta: uk, it, pl, fr
* Gold: br, kr, nl
* White: unknown

Matt Britt, Internet Map, 12-1-2005

Cyber Shock, Virtualization, Cloud Computing & the State of the Web -- Not for the Faint of Heart ...

Richard Power


Three stories have intrigued me over the past few days, and I will share them with you here. Woven together they deliver a message that needs to be heard (over and over again apparently). And that message? From the corridors of the highest power, through IT networks across the planet, down to each and every end user -- there is a tremendous amount of yet as yet undone, and much of it is attitudinal and cultural.

Cyber Shock

First, there is the Cyber Shock story.

Event: A massive cyber attack has turned the cellphones and computers of tens of millions of Americans into weapons to shut down the Internet. A cascading series of events then knocks out power for most of the East Coast amid hurricanes and a heat wave.
Is the assault on cellphones an armed attack? In a crisis, what power does the government have to order phone and Internet carriers to allow monitoring of their networks? What level of privacy can Americans expect?
A war game, sponsored by a nonprofit group and attended by former top-ranking national security officials, laid bare Tuesday that the U.S. government lacks answers to such key questions.
Half an hour into an emergency meeting of a mock National Security Council, the attorney general declared: "We don't have the authority in this nation as a government to quarantine people's cellphones."
The White House cyber coordinator was "shocked" and asserted: "If we don't have the authority, the attorney general ought to find it."
Ellen Nakashima, War game reveals U.S. lacks cyber-crisis skills, Washington Post, 2-17-10

If you google Cyber Shock, you will find hundreds of news items, and blog posts, about it.

When I heard it, I started hearing the theme music from the hilarious filmGroundhog Day, starring Bill Murray and co-written and directed by Harold Ramis again.

Do you remember The Day After (1996)? Do you remember Eligible Receiver (1997)? There have been many other such cyber war games over the past 15 years. I have been involved in a few, and studied the results of many.

So when I read the WashPo's headline,"War game reveals U.S. lacks cyber-crisis skills," I tweeted, "Shouldn't this read STILL lacks?"

As a reality check, I asked a few friends and colleagues who have been at and beyond the front-line for all the years of this long struggle. I received three responses. None thought it was anything new, of course. One dismissed it as a "bad joke." One said hopefully it would "embarrass" some officials on high to "addressing the issue" at long last. One said that it never hurts to try to get the attention of people who are just tuning in."

From my perspective, I encourage and commend such exercises, but I think everyone would learn more if we framed them in proper historical context, and I certainly would have hoped that we would be much farther along, here at the start of the second decade of the 21st Century, than discovering that we STILL LACK cyber crisis skills.

As it quite often, the press (both mainstream and IT) missed the real story.

Head in the Clouds

Meanwhile, two new studies perked my interest, and not surprisingly they also reinforce the sense that we are spinning our wheels in the the digital Thunderdome.

The first of them was conducted for Symantec by Applied Research. It queried "2,100 top IT and security managers in 27 countries."

Is moving to virtualization and cloud computing making network security easier or harder? The "2010 State of Enterprise Security Survey - Global Data" report shows that about one-third believe virtualization and cloud computing make security "harder," while one-third said it was "more or less the same," and the remainder said it was "easier." The telephone survey was done by Applied Research last month on behalf of Symantec, and it covered 120 questions about technology use -- organizations remain overwhelmingly Microsoft Windows-based -- and cyberattacks on organizations. Ellen Messmer, Security of Virtualization, Cloud Computing Divides IT and Security, Network World, 2-22-10

Harder? About the same? Easier? Well, of course, the most insightful answer would be "All of the Above." (There are numerous security concerns, not the least of which is that we still do not know most of them.) But I doubt the "All of the Above" was available option to the respondents.

Certainly, it should be of concern to us all that most of these "top IT and security managers" are under the impression that virtualization and cloud computing have either made the challenge of cyber security easier to deal with or had no impact on it at all. This data point suggests that a majority of "top IT and security managers" don't really understand security in any depth.

Leading SaaS Vendor Offers Evidence of Enterprise Exposure

The second study is hot of the digital press.

Zscaler Lab's State of the Web - Q4 2009, A View of the Web from an End User's Perspective." Zscaler is a Security-as-a-Service (SaaS) vendor, so its "network of web gateways continually inspects traffic for millions of end users around the globe."

"With the emergence of Advanced Persistent Threats (APT) as evidenced with the Operation Aurora attacks, it is obvious that large enterprise are vulnerable to such targeted attacks that exploit employee behavior," the Zscaler study concludes; and furthermore, it also offers corroboration that "vulnerable desktops and browsers are extremely common in corporate environment making them easier targets than previously believed."

It is an interesting report, with lots of data points to ponder, but two in particular jumped out at me.

First, Internet Explorer continues to dominate among browsers, with over 70% of market share, while Firefox Mozilla its nearest competitor, with only 15% of market share in December 2009. I was not surprised that IE still held sway, but I was surprised that the margin was so significant. But what is even more striking to me was that 48% were still using 6.0, while only 46% had moved on to 7.0, and only 5% have moved on to 8.0. Yes, although 6.0 is still being updated by Microsoft, it lacks several important security features available in later releases. We are talking about IE here? How can this be so?

Another intriguing tidbit, concerning "Top Ten Malware IP Addresses," was that "more and more," Zscaler reports seeing "otherwise legitimate sites hosting malware without being aware of it."

I asked Mike Geide, a senior security researcher for Zscaler, for some insight into the study's findings.

CyBlog: On pg. 17 and pg. 18, you share some numbers on browsers that were eye opening to me, specifically breakdowns of market share and IE versions. I expected to see IE still holding the lion's share, but I confess I was surprised to see by it to be dominating by such a wide margin. Why? Is this a failure on corporate network managers to push upgrades out, or insist on them, or are the 6.x number inflated by home use (of course, either way it represents an unnecessary risk)?

Mike Geide: In short, yes this a failure of corporate network managers. This could be because corporate managers are unfamiliar with the security risks of IE 6 / benefits of IE 8. Because MS is still supporting / releasing patches for IE 6, managers may feel that they are sufficiently secure because their IE 6 is patched. Additionally, while IE 8 is pushed as a High-Priority update from Automatic Updates, it will not automatically install on machines. Users must opt-in to install IE 8 or organizations may deploy via SMS / WSUS. (Ref: http://blogs.msdn.com/ie/archive/2009/04/10/prepare-for-automatic-update-distribution-of-ie8.aspx)

What could corporate IT security people be doing to improve on these numbers?

Mike Geide: Corporate IT should have a centralized method for managing software and patch installation. It is not enough to just patch the underlying OS, web browsers and other client software (e.g., Adobe Acrobat, MS Office, etc.) need to be included in this management.

CyBlog: Is there anything that Microsoft could be doing (or not doing) that could help these numbers?

Mike Geide: If Microsoft announced an end-of-life for IE 6, this may force organizations to conduct an audit of their systems and upgrade to IE 8. However, from MS's point-of-view they may feel that there is still too much of a user base to end-of-life the product, and should continue to maintain/provide patches for any newly discovered vulnerabilities that would impact this user base. The responsibility is really on the corporations and end users to sufficiently patch and upgrade.

CyBlog: On pg. 22, you talk about Top 10 Malware IP Addresses, and note that "more and more legitimate sites are hosting malware without being aware of it." I see you have listed the IP addresses, could you share some more information here? Of the Top 10, how many are "legitimate sites," and could you characterize them in any way? Types of businesses, types of applications, types of traffic?

Mike Geide: For this report we did not specifically break out stats for "legitimate sites" versus "illegitimate sites" for malware- perhaps we will do this for the next report. I would need to pull the logs to properly answer this question, however based on Google results, the majority of the top 10 appeared to be illegitimate sites identified in other resources (e.g., ThreatExpert).

CyBlog: Of the Top 10, how do you define this?

Mike Geide: I would define an illegitimate site as a site that is setup by the attacker explicitly for malicious purposes. Whereas a malicious legitimate site provides or had provided benign content, but has been compromised and is serving some malicious content (e.g., embedded malicious iframe or JS drive-by-download).

CyBlog:Is there any accountability for either "legitimate sites" or "illegitimate sites" that show up in such a ranking?

Mike Geide: Depends. Some hosting providers will terminate legitimate site accounts if they are repeatedly compromised, while other hosting companies care very little about malicious content being hosting. Depending on the severity of the incident and jurisdiction, law enforcement (LE) could enforce accountability- but LE resources do not scale to the Internet. In short, the Internet doesn't have an overall policing body to ensure accountability. If a site continues to be an offending site, block it from being visited. If the site provides a legitimate service they will either fix their security problem or go out of business.

CyBlog: What are key measures that "legitimate sites" should be taking to avoid ending up as a part of the problem instead of being part of the solution?

Mike Geide: Legitimate sites are frequently leveraged to host malicious content through vulnerabilities in 3rd party web applications (e.g., Wordpress, Joomla, etc.). The most common vulnerabilities in these and other web applications are SQL Injection and Cross Site Scripting (XSS). Legitimate sites should only install 3rd party web applications that they absolutely need, and then follow the patch cycle of the application to ensure that known vulnerabilities are fixed.