Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Sunday, July 13, 2014

A Decade Into Its Vital Work, Another Savory SOUPS, A Report from the 10th Annual Symposium On Usable Privacy and Security



CMU CyLab's Dr. Lorrie Cranor, Founder of CUPS and SOUPS preps
for welcoming remarks at SOUPS 2014


The CyLab Usable Privacy and Security Laboratory (CUPS) 10th Annual Symposium on Usable Privacy and Security (SOUPS) was hosted by Facebook at its headquarters in Menlo Park, California (7/9/14 - 7/11/14). CUPS Director Lorrie Cranor welcomed the attendees, with the record-breaking numbers in both attendance and papers submitted. For three full days of proceedings, hundreds of researchers from business, academia and government communed together amidst the proliferation of signage which has come to characterize the social media giant's corporate culture: e.g., "Ship Love," "Ruthless Prioritization," "Demand Success," Nelson Mandela, arms outstretched, with the caption, "Open the Doors," etc. (Not so subliminal messaging.)
 
Perhaps more poignantly than any previous SOUPS keynote, Christopher Soghoian of American Civil Liberties Union (ACLU) articulated the vital nature of research into usable privacy and security. Putting flesh and blood on these issues, Soghoian used examples from the shadow world of investigative reporters and whistle-blowers to highlight the need for privacy and security software that is not only robust but eminently usable. One great benefit of the revelations brought forth by Glenn Greenwald in the Edward Snowden affair, Soghoian opined, is that there has been increased crypto adoption by journalists.
But the heightened engagement has also brought long-standing problems into a harsh new light. For example, Soghoian told SOUPS attendees, many investigative journalists using PGP still do not realize subject lines are not encrypted. "The best our community has to offer sucks, the usability and the default values suck," Soghoian declared, "the software is not protecting journalists and human rights activists, and that's our fault as researchers"

As contributing markets factors for why we still don't have usable encryption, Soghoian cited: potential data loss ("telling your customer that they've just lost every photo of their children is a non starter"), current business models, and of course, government pressure.

Facebook HQ Signage, 1 Hacker Way, Menlo Park
In other parts of his very substantive keynote, Soghoian touched on consumer issues related to the efficacy of privacy and security. He elucidated the differences in privacy and security between the iPhone and the Android: "The privacy and security differences ... are not advertised." He also shed light on a new aspect of the growing gap between rich and poor, "security by default for the rich," and "insecurity by default for the poor." "Those who are more affluent get the privacy benefits without shopping around," he explained, because the discounted, and mass-marketed versions of software often do not have the same full-featured privacy and security as the more expensive business or professional versions.

[NOTE: Full-length video of Soghoian's keynote is available via the CyLab YouTube Channel.]

Several awards were also announced during the opening sessions, including:

The 2014 IAPP SOUPS Privacy Award for the paper with the most practical application in the field of privacy went to Would a Privacy Fundamentalist Sell Their DNA for $1000...If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences authored by Allison Woodruff, Vasyl Pihur, Sunny Consolvo, and Lauren Schmidt of Google; and Laura Brandimarte and Alessandro Acquisti of Carnegie Mellon University.

The 2014 SOUPS Impact Award for a SOUPS paper "published between 2005 and 2009 that has had a significant impact on usable privacy and security research and practice" went to Usability of CAPTCHAs or Usability Issues in CAPTCHA Design authored in 2008 by Jeff Yan and Ahmad Salah El Ahmad of Newcastle University (UK).

Two Distinguished Papers awards were presented:

Understanding and Specifying Social Access Control Lists, authored by Mainack Monda of Max Planck Institute for Software Systems (MPI-SWS), Yabing Liu of Northeastern University, Bimal Viswanath and Krishna P. Gummadi of Max Planck Institute for Software Systems (MPI-SWS), and Alan Mislove of Northeastern University.

Crowdsourcing Attacks on Biometric Systems, authored by Saurabh Panjwani, an independent consultant and Achintya Prakash of University of Michigan.
Carnegie Mellon University (CMU), home to the CyLab Usable Privacy and Security (CUPS) Lab and the MSIT-Privacy Engineering Masters Program was well-represented in the proceeding.

In addition to the IAPP SOUPS Privacy Award winning "Would a Privacy Fundamentalist Sell Their DNA for $1000...If Nothing Bad Happened as a Result? The Westin Categories, Behavioral Intentions, and Consequences," co-authored with Google researchers, several other CMU papers were presented:

Parents’ and Teens’ Perspectives on Privacy In a Technology-Filled World, authored by Lorrie Faith Cranor, Adam L. Durity, Abigail Marsh, and Blase Ur, Carnegie Mellon University

Privacy Attitudes of Mechanical Turk Workers and the U.S. Public, authored by Ruogu Kang, Carnegie Mellon University, Stephanie Brown, Carnegie Mellon University and American University, Laura Dabbish and Sara Kiesler, Carnegie Mellon University

CMU researcher Ruogu Kang presenting
Privacy Attitudes of Mechanical Turk Workers and the U.S. Public
Harder to Ignore? authored by Cristian Bravo-Lillo, Lorrie Cranor, and Saranga Komanduri, Carnegie Mellon University, Stuart Schechter, Microsoft Research, Manya Sleeper, Carnegie Mellon University

The Effect of Social Influence on Security Sensitivity, authored by Sauvik Das, Tiffany Hyun-Jin Kim, Laura A. Dabbish, and Jason I. Hong, Carnegie Mellon University

Modeling Users’ Mobile App Privacy Preferences: Restoring Usability in a Sea of Permission Settings, authored by Jialiu Lin, Bin Liu, Norman Sadeh, and Jason I. Hong, Carnegie Mellon University

The full proceedings of SOUPS 2014 are available via USENIX.

-- Richard Power

Check out CyLab CyBlog's Archive of SOUPS Coverage

A Distinguish Paper Award for CUPS, and Other News from Ninth Annual SOUPS 2013

CyLab's SOUPS 2012 Continues Its Ongoing, Deepening Dialogue on What Works and What Doesn't

SOUPS 2011 Advances Vital Exploration of Usability and Its Role in Strengthening Privacy and Security  

 SOUPS 2010: Insight into Usable Privacy & Security Deepens at 6th Annual Symposium

Reflections on SOUPS 2009: Between Worlds, Cultivating Superior Cleverness, Awaiting a Shift in Consciousness

Glimpses into the Fourth Annual Symposium on Usable Security and Privacy (SOUPS 2008)

Mike Farb of CyLab's SafeSlinger project presents during the 2014 EFF Crypto Usability Prize (EFF CUP)
Workshop on Day One of SOUPS 2014

Facebook HQ Signage, 1 Hacker Way, Menlo Park

Thursday, May 22, 2014

IEEE Security and Privacy Symposium 2014: Another Challenging Year, Another Compelling IEEE SSP, and Another Significant Contribution from CMU CyLab


Giovanni Domenico Tiepolo - Procession of the Trojan Horse in Troy (1773)
Another challenging year in cyber security and privacy means another compelling IEEE Security and Privacy Symposium, and another compelling IEEE Security and Privacy Symposium means another significant contribution from Carnegie Mellon University CyLab.

This year, three hundred and thirty three papers were submitted. After a rigorous review process (which included ninety nine "intensive discussions," one thousand two hundred eighteen reviews and a rebuttal phase), forty four papers were selected to be published as part of the Symposium.

Of these forty four worthy contributions, four were singled out for IEEE Security and Privacy Symposium 2014 Best Papers Awards:

Best Paper
 
Secure Multiparty Computations on BitCoin by Marcin Andrychowicz, Stefan Dziembowski, Daniel Malinowski, and Łukasz Mazurek (University of Warsaw)

Best Practical Paper
 
Using Frankencerts for Automated Adversarial Testing of Certificate Validation in SSL/TLS Implementations by Chad Brubaker and Suman Jana (University of Texas at Austin), Baishakhi Ray (University Of California Davis), and Sarfraz Khurshid and Vitaly Shmatikov (University of Texas at Austin)

Best Student Papers

Framing Signals — A Return to Portable Shellcode by Erik Bosman and Herbert Bos (Vrije Universiteit Amsterdam)

Bootstrapping Privacy Compliance in Big Data Systems by Shayak Sen (Carnegie Mellon University), Saikat Guha (Microsoft Research, India), Anupam Datta (Carnegie Mellon University), Sriram Rajamani (Microsoft Research, India), Janice Tsai (Microsoft Research, Redmond), and Jeannette Wing (Microsoft Research)

CMU CyLab researcher Shayak Sen presented the award winning paper co-authored by members of the CyLab and Microsoft Research teams:

In this paper, we demonstrate a collection of techniques to transition to automated privacy compliance compliance checking in big data systems. To this end we designed the LEGALEASE language, instantiated for stating privacy policies as a form of restrictions on information flows, and the GROK data inventory that maps low level data types in code to highlevel policy concepts. We show that LEGALEASE is usable by non-technical privacy champions through a user study. We show that LEGALEASE is expressive enough to capture real-world privacy policies with purpose, role, and storage restrictions with some limited temporal properties, in particular that of Bing and Google. To build the GROK data flow grap we leveraged past work in program analysis and data flow analysis. We demonstrate how to bootstrap labeling the graph with LEGALEASE policy datatypes at massive scale. We note that the structure of the graph allows a small number of annotations to cover a large fraction of the graph. We report on our experiences and learnings from operating the system for over a year in Bing. -- Shayak Sen (Carnegie Mellon University), Saikat Guha (Microsoft Research, India), Anupam Datta (Carnegie Mellon University), Sriram Rajamani (Microsoft Research, India), Janice Tsai (Microsoft Research, Redmond), and Jeannette Wing (Microsoft Research), Bootstrapping Privacy Compliance in Big Data Systems, IEEE Security and Privacy Symposium 2014, Best Student Paper (1 of 2)

But, of course, the Bootstrapping Privacy Compliance paper was not the only CyLab contribution to the Symposium program, e.g., CMU CyLab researcher Zongwei Zhou spoke on Dancing with Giants; Wimpy Kernels for On-Demand Isolation I/O, a paper co-authored with Miao Yu and Virgil Gligor:

Trustworthy applications are unlikely to survive in the marketplace without the ability to use a variety of basic services securely, such as on-demand isolated I/O channels to peripheral devices. This paper presents a security architecture based on a wimpy kernel that provides these services without bloating the underlying trusted computing base. It also presents a concrete implementation of the wimpy kernel for a major I/O subsystem, namely USB subsystem, and a variety of device drivers. Experimental measurements show that the desired minimality and efficiency goals for the trusted base are achieved. -- Zongwei Zhou, Miao Yu, Virgil Gligor, Dancing with Giants; Wimpy Kernels for On-Demand Isolation I/O, IEEE Security and Privacy Symposium 2014

Other CMU papers selected and presented at IEEE SSP 2014 included:

All Your Screens Are Belong to Us; Attacks Exploiting the HTML5 Screen Sharing API, Analyzing Forged SSL Certificates in the Wild by Lin-Shung Huang, Yuan Tian, Patrick Tague and others, CMU SV and Facebook

Analyzing Forged SSL Certificates in the Wild by Lin-Shung Huang, Alrex Rice, Erling Ellingsen, Collin Jackson

Stopping A Rapid Tornado with A Puff by Jose Lopes and Nuno Neves of CMU Portugal
CyLab's contribution to IEEE SPP 2014 also included several papers from two CMU CyLab alumni and alumna.

There were three papers co-authored by CMU CyLab alumnus XiaoFeng Wang of Indiana University (Bloomington): Hunting the Red Fox Online: Understanding and dectection of Mass Redirect-Script Injections, Upgrading Your Android, Elevating My Malware - Privilege Escalation Through Mobile OS updating, and Perils of Fragmentation: Security Hazards in Android Device Driven Customizations.

Also CMU CyLab alumnus Bryan Parno of Microsoft Research and a CMU CyLab alumna Elaine Shi of University of Maryland (College Park) were among the co-authors of PermaCoin: Repurposing Bitcoin Work for Data Preservation, and Shi co-authored a second paper, Automating Efficient RAM-Model Secure Computation.

CyLab's efforts were also apparent on the organizational level at IEEE SSP 2014:

Adrian Perrig of ETH Zürich, formerly CyLab's Research Director, now a CyLab Distinguished Fellow, served as one of the Symposium's three program chairs.

Three CyLab researchers served as Session Chairs, Lujo Bauer for Systems Security, Virgil Gligor (CyLab Director) for Attacks 3 and Anupam Datta for Secure Computation and Storage.

Also, CMU CyLab alum Bryan Parno served as a Session Chair for Privacy and Anonymity.

And, looking ahead to next year, Lujo Bauer will be one of the Symposium program chairs. 2015 will likely be another challenging year in cyber security and privacy, which will mean another compelling IEEE Security and Privacy Symposium, with another significant contribution from Carnegie Mellon University CyLab.

Related Posts

CyLab's Strong Presence Continues at Annual IEEE Symposium on Security and Privacy (2013)

CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop

A Report on 2012 IEEE Symposium on Privacy and Security

Microcosm & Macrocosm: Reflections on 2010 IEEE Symposium on Security & Privacy; Q & A on Cloud, Cyberwar & Internet Freedom w/ Dr. Peter Neumann

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium



Tuesday, April 15, 2014

CyLab Research Sheds Light on Heartbleed and Its Implications


Heartbleed is a significant event along the cyber security timeline. Its consequences will be with us all for quite awhile. If you haven't already come to grips with this issue, you should do so urgently.

For some guidance go to http://heartbleed.com/

To verify if a particular server is vulnerable, go to: http://filippo.io/Heartbleed/

For a command-line tool, go to: https://github.com/FiloSottile/Heartbleed

Here at CyLab, the story has provided us with an opportunity to reflect on some of our recent research and its relevancy to the problem at hand, e.g., --

Perspectives: If you scan a server, and find that it isn't vulnerable, you would still need to know if it had been vulnerable in the past, and/or if it has been updated. One way to answer that question is to determine if the private key has been updated. If you connect to the server with a Firefox browser that has the Perspectives extension installed, and then inspect the key history. To do so, click the Perspectives icon on the left-hand of the URL bar, and select "View Notary Results." (Of course, if the key has not been changed, you're still none the wiser.) For more on Perspectives, visit the Perspectives Project page.

TrustVisor: In TrustVisor, we proposed keeping the OpenSSL private key inside a PAL, which would have defended against this vulnerability. See our paper on TrustVisor: Efficient TCB Reduction and Attestation, authored by Jonathan M. McCune (now with Google), Yanlin Li, Ning Qu, Zongwei Zhou, Anupam Datta, Virgil Gligor and Adrian Perrig.

Flicker: In Flicker, we proposed to store the SSH password database inside a PAL, which would also prevent password theft. See Flicker: An Execution Infrastructure for TCB Minimization,
authored by three CyLab researchers Jonathan M. McCune, Bryan Parno (now with Microsoft), and Adrian Perrig (now with ETH Zurich), along with Michael K. Reiter of University of North Carolina (Chapel Hill), and Hiroshi Isozaki of Toshiba Corporation.

Perspectives, TrustVisor and Flicker all evolved out of CyLab's work on Trustworthy Computing Platforms and Devices. And this continues to be one of CyLab's major research thrusts.

Amit Vasudevan, a CyLab  Research Systems Scientist, and Miao Yu, a CyLab grad student, took a few moments to sit down with CyBlog, and share some insights on where we are and what's next.

According to Vasudevan, "the IEE technologies and prototypes we have been developing (XMHF - TrustVisor, KISS, Minibox, etc.) lay a solid foundation to protect against Heartbleed-like attacks."

"But going from our prototypes to the real-world is a different kind of challenge. The software ecosystem out there today does not really consider security as a first-class citizen. Consequently, tweaking these components to adapt to our IEE design is non-trivial ...  In the long term, developers of security-oriented/sensitive software would benefit from a simple and solid security framework that would allow them to leverage strong security properties, while letting them also implement the desired functionality. And our work with XMHF plus Trustvisor plus other hypapps (http://xmhf.org) is the right step in this direction."

"This bug is still underestimated," warns Yu.

He cites three reasons for his concern:
"Currently, we putting a lot of care into HTTPS websites. But other protocols, e.g., FTPS (used in file transfer) server, can also be impacted by this bug. 

"Not only servers, but also clients, e.g. smart phones and other devices, may suffer from this bug. And for certain devices, the problem can be even worse. For example, mobiles phones have long patch cycles. For the heartbleeding bug, the first patch of this bug came out in 20 minutes and web servers began the repair in the first day. But Android phones only get scanners, e.g., Bluebox Heartbleed Scanner or Heartbleed Detector to help users find out if their phone is vulnerable ... From our experience with past vulnerabilities, it would take tens of weeks until half of the mobile devices get patched. During this period, the devices are at risk. Other devices, which may use OpenSSL for establishing administration channels, also may suffer from long patch cycles. At CyLab, Zongwei Zhou, Miao Yu, Yoshiharu Imamoto, Amit Vasudevan, Virgil Gilgor and I have developed an isolated execution environment for the ARM mobile platform. It is quite similar to TrustVisor, but focuses on mobile system security, so that, e.g., you could run a banking client (or some other sensitive application) in an isolated execution environment, so that your code and data would still be secure in spite of this or other vulnerabilities present in Android.

"All three recent SSL bugs, i.e., IOS's goto fail bug, the GnuTLS bug and the Heartbleed bug are implementation-related rather than design related. The lesson is that design security doesn't mean implementation security. We do need runtime protection as a last line of defense."

-- Richard Power

Wednesday, March 12, 2014

New on @CyLab @YouTube Channel: Osman Yagan - Designing Secure and Reliable Wireless Sensor Networks (Full-length CyLab Seminar)


The CyLab Seminar Series is held on Mondays during the school year, at CyLab HQ on the main campus of Carnegie Mellon University (Pittsburgh, PA.) These weekly talks feature the latest research from CyLab faculty and visiting colleagues from other centers of academic research into cyber security and privacy. Occasional Business Risk Forum events introduce the insights of cybersecurity and privacy excerpts from the operational side of business and government.

Access to the webcasts of this dynamic Seminar Series is an exclusive benefit of corporate partnership with CyLab. But from time to time, to encourage further research into cybersecurity and privacy, and to contribute to the ongoing dialogue on these vital issues, we release select videos for free public viewing via the CyLab You Channel.

Here is the abstract and embedded video for one such talk released via @CyLab @YouTube.

Abstract
Wireless sensor networks (WSNs) are distributed collection of small sensor nodes that gather security-sensitive data and control security-critical operations in a wide range of industrial, home and business applications. The current developments in the sensor technology and ever increasing applications of WSNs point to a future where the reliability of these networks will be at the core of the society’s well-being, and any disruption in their services will be more costly than ever. There is thus a fundamental question as to how one can design wireless sensor networks that are both secure and reliable. 
In this talk, we will present our approach that addresses this problem by considering WSNs that employ a randomized key predistribution scheme and deriving conditions to ensure the k-connectivity of the resulting network. Random key predistribution schemes are widely accepted solutions for securing WSN communications and the k-connectivity property ensures that the network is reliable in the sense that its connectivity will be preserved despite the failure of any k − 1 sensors or links.
 
CyLab Seminar: Osman Yagan - Designing Secure and Reliable Wireless Sensor Networks
)

For more information on the work of CyLab researcher Osman Yagan. For more information on the CyLab corporate partnership program.

Friday, March 7, 2014

Descending Into the Maelstrom - Notes on RSA Conference 2014

Dan Geer: "We are all intelligence officers now." (RSA Conference 2014)

Descending Into the Maelstrom -- Notes on RSA Conference 2014

By Richard Power 
  
I confess that I was tempted to simply go to Trustycon instead. But from a historical perspective, I could not resist the bitter ironies that RSA Conference 2014 offered up. After all, I had been there, two decades earlier, when Jim Bidzos, then President and CEO of RSA, led industry and public advocacy resistance to the adoption of the National Security Agency's Clipper Chip. In the mid-1990s, the RSA Conference was one of the principle venues for the marshaling of that resistance. So how could I not attend this year's RSA Conference, with Snowden-sourced revelations of RSA's "secret $10 million" deal to an NSA "backdoor" rolled into its Bsafe product (Reuters, 12/20/13). How could I not bear witness to how all of this would play out?

So I attended RSA Conference 2014, as I have since the beginning, as a member of the press. I simply had to follow up on this latest twist in the plot of our collective lives and careers in security and intelligence. Walking toward the escalators to descend into the maelstrom, I glanced up. An overarching banner read: "Share. Learn. Secure. Capitalizing on Collective Intelligence." Seriously. Such a strange thematic choice for this particular RSA Conference. Were they going for irony, or doubling down on the brouhaha, or was someone simply asleep at the wheel. "Capitalizing on Collective Intelligence." Wow. Don't misunderstand me. I am a strong champion for the role of intelligence in government and business. Despite the tendency of governments to "sex up" intelligence to serve ideological agendas, and the tendency of business executives to avoid any real intelligence that might force them to confront some inconvenient truth. Nevertheless, at this particular moment in time, with the allegations concerning NSA's paid-for "backdoor" into RSA product still causing a profound disturbance in the force, "Capitalizing on Collective Intelligence" seemed, well, a strange spin. Was it ill-chosen, or plucky, or both?

Lucy in the Sky with Diamonds

As I sat in the front row of the auditorium for the first day's keynote session, I was still mulling over the organizers' choice of conference themes, when over the loudspeakers a secondary (and completely unrelated) theme was introduced: "Security the final frontier ... These are the voyages of the RSA Conference ..." Suddenly, William Shatner (yes, the original Captain James T. Kirk) burst into the hall and took the stage, to sing the Beatles "Lucy in the Sky with Diamonds," with lyrics re-written for the occasion: "Follow her down to a patch in the system ... where the people eat malicious code pies ... and the botnets grow so incredibly high ..." Seriously.


William Shattner: "Security gets us high ..." (RSA Conference 2014)
And then came the C-suite kabuki.

In his address, RSA Executive Chairman Art Coviello declared "our personal information" the "true currency of the digital age." (Given the backdrop of the Snowden revelations regarding RSA and the NSA, this comment struck me in the same way as the Conference theme of "Capitalizing on Collective Intelligence.") And he went on to proclaim, "We are at a crossroads ... I call on all the nations of the world to adopt these four principles:  renounce the use of cyber weapons and the use of Internet to wage war... cooperate internationally on the apprehension of cyber criminals ... respect intellectual property rights ... ensure privacy of all individuals ..." 

Nawaf Bitar, Senior VP and GM of Security Business Unit, Juniper Network opened his presentation with the image of a Tibetan protester's self-immolation, and went on to invoke the spirit of Nelson Mandela. In the course of his mocking remarks about what he termed "#FirstWorldOutrage," Bitar took a swipe at Trustycon: "not showing up at a conference is not outrage," and belittled the role of social media: "Bitar argued that 'liking a cause on Facebook' or 'retweeting a link' are not appropriate displays of outrage" (See Rachel King, Juniper Networks exec: 'First-world outrage' will not help cyber security, ZDNet, 2/25/14 )

Although I am tempted to take some time to dissect these speeches, and explore some possible contradictions inherent in their premises, I will not.

I will simply say this -- there was no Andrei Sakharov in the house.

Crypto Panel Reality Check

As I am a well-seasoned veteran of many RSA Conferences, I know that if you are looking for a reality check in the throes of that C-level kabuki, you just have to hold out for the Cryptographers Panel. And as in previous years, Ron Rivest, Whit Diffie and Adi Shamir  delivered.

In agreeing with Rivest that the most disturbing aspect of the Snowden revelations was that the NSA would tamper with NIST security guidance to the U.S. government, Diffie added:

"I grew-up in an era, where despite my conflicts with them, I believed that they were just  100% interested in the security of American communications, I thought that began to crumble when we saw key escrow, and I now sort of feel that they gave up doing that above board and turned aside to do it in other places, and that puts on us a tremendous additional burden of trying to vet things and make sure they haven't been tampered with."

The panel participants didn't just dwell on the Snowden revelations.

For example, Shamir highlighted some of his latest research: "I published a few weeks ago a paper with my colleagues ... that showed [a new] attack on RSA, where we can just listen to the sound made by a laptop ... from eight meters away we can eavesdrop on the acoustic sound made by the laptop and after less than an hour we can recover the full RSA key ..."  

Here are a few more bread and circus vignettes from RSA Conference 2004. 

BSIMMering

On the second day of RSA 2014, I decided on two worthy sessions to tweet out via @CyLab, the first of these was "Lessons from BSIMM" with Citigal CTO Gary McGraw.

As the BSIMM project evolves, it is yielding more and more insight into how organizations are approaching software security in the real world. 

In this talk, McGraw focused on how to scale some of the best practices in the area of Software Security, and particular on three touch-points:
  • Remedial Code Review
  • Remedial Architecture Analysis
  • Remedial Penetration Testing
According to McGraw, 50 of 67 of the BSIMM participants have automated tool for remedial code review, 56 of 67 review security features, and 62 of 67 use external pen testers.

As he shared his real-world data on these three activities, McGraw also elucidated pitfalls, shared some perspective on trends and offered practical suggestions.

For example, concerning remedial code review, he remarked, "security people are good at finding problems, but they suck at fixing them,"  and "developers learn to game the results."

Ruminating on the second touch-point, remedial architecture analysis, McGraw optimistically opined, "We are in the Age of Bugs, next will be the Age of Flaws."

In regard to his third touch-point, remedial pen testing, McGraw exhorted attendees to "periodically pen test everything you can," and added "fix what you find."


Gary McGraw, Citigal - Scaling A Software Security Initiative: Lessons from the BSIMM (RSA Conference 2014)
Gumshoes: Investigative Journalists Speak Out
– Security Investigative Journalists Speak Out

The other session that I tweeted out on Day 2 was "Gumshoes: Security Journalists Speak Out" with  Brian Krebs (Krebs on Security), Nicole Perlroth (New York Times) and Kevin Poulson (Wired).

The role of the investigative journalist is one of the most vital in all of the realm of cyber risk; it is also one of the most challenging. The work can be frustrating and dangerous too. 

Although there are many more reporters on this beat than there were two decades ago, there are still only a handful that stand out as consummate professionals.

Three of them participated in this panel discussion.

Here are a few of the many insights they shared.

Krebs: "A lot of stuff has happened to me that what I talk about publicly. People have offered me money to do something, or not do something ..."

Poulsen: "We are all accustomed to being approached by people who aren't who they say they are."

Krebs: "In national security reporting, you only get certain stuff by being spun a few times ..."

Perloth: "I get a lot of information that is over-hyped, every single day. And I think that is perhaps the biggest challenge in my job ..."

Krebs: "My biggest challenge is what not to write about ..."

Perlroth: "It is really interesting that Snowden released tens of thousands of these documents, as I was sifting through them this summer, I thought about that a lot ... There was a lot of stuff I didn't need to see, a lot more than what we needed ..."

Perlroth: "After spending summer looking through the Snowden documents, I looked at my  co-worker ... and said, Well, I think there is a consensus here, being a spy is one of the most [expletive] jobs ..."

Poulsen: "I would like to see a better explanation of what [RSA] thought they were doing [re: NSA]."
Nicole Perlroth, N.Y. Times (RSA Conference 2014)
Brian Krebs, Krebs on Security (RSA Conference 2014)
Key Trends in Security: The Venture Capitalists' View 

On Day 3, I attended "Key Trends in Security: The Venture Capitalists' View."

Moderated by Joseph Menn (@josephmenn) of Reuters, this panel featured David Cowan of Bessemer Venture, Ray Rothrock of Venrock and Asheem Chandra of Greylock.

One takeaway from this session was Cowan's savvy perspective on mobile device security:

"There is a lot of money going into mobile computing that is not going to be well-spent, by either the investors or the customers ... It is mostly around wrapping apps, encrypting data on the mobile devices, compartmentalizing the phone, trying to figure out what's work and what's personal. There are various problems with these approaches. Not every product suffers all of these problems, but every product suffers from one or more of these problems. One problem is that they all assume that there are work apps and personal apps, and we all know we use our phones, SMS, e-mail and cameras for both work and for personal, so it's delusional to think you can compartmentalize them ... The app wrappers are kludgy ... You have problems because there are some that say they are going to encrypt the data created inside the app; well, that means, great, I can upload some things to my phone, but if I try to get to it from my browser I am going to get a lot of garbage because my browser doesn't know how to decrypt what my wrap app encrypted. And then there is a fundamental security flaw, which is that you can wrap data inside a phone, but at some point if it's going to be useful, you are going to have to unwrap it ... then when you unwrap the data for the user, I am going to collect it right then and there ... enterprises are grasping for solutions ... but these are not really solutions, this is grasping for straws ..."

Yes, but isn't that what much of the cyber security industry is about: "grasping for straws"? 

We Are All Intelligence Officers Now 

It wasn't until Day 4 that I heard someone speak truth to the power of that we, as a civilization, have unwittingly unleashed upon ourselves.

Dan Geer is a force of nature in the field of cyber security and intelligence. He has been engaged at the highest levels of our discourse for as long as I have been involved, and I go back to the early 1990s. As the darkness deepens, his vision sharpens and expands.

Here are some excerpts from Dan's speech, "We Are All Intelligence Officers Now," followed by a link to the full text:

We are all data collectors, data keepers, data analysts. Some citizens do it explicitly; some citizens have it done for them by robots. To be clear, we are not just a society of informants, we are becoming an intelligence community of a second sort  ...

This is not a Chicken Little talk; it is an attempt to preserve if not make a choice while choice is still relevant ... 

Richard Clarke's novel _Breakpoint_ centered around the observation that with fast enough advances in genetic engineering not only will the elite think that they are better than the rest, they will be. [RC] I suggest that with fast enough advances in surveillance and the inferences to be drawn from surveillance, that a different elite will not just think that it knows better, it will know better. Those advances come both from Moore's and from Zuboff's laws, but more importantly they rest upon the extraordinarily popular delusion that you can have freedom, security, and convenience when, at best, you can have two out of three ... 

If knowledge is power, then increasing the store of knowledge must increase the store of power; increasing the rate of knowledge acquisition must increase the rate of power growth. All power tends to corrupt, and absolute power corrupts absolutely,[LA] so sending vast amounts of knowledge upstream will corrupt absolutely, regardless of whether the data sources are reimbursed with some pittance of convenience ... Very nearly everyone at this conference is explicitly and voluntarily part of the surveillance fabric because it comes with the tools you use, with what Steve Jobs would call your digital life. With enough instrumentation carried by those who opt in, the person who opts out hasn't really opted out. If what those of you who opt in get for your role in the surveillance fabric is "security," then you had better be damnably sure that when you say "security" that you all have close agreement on precisely what you mean by that term ...

It is said that the price of anything is the foregone alternative. The price of dependence is risk. The price of total dependence is total risk. Standing in his shuttered factory, made redundant by coolie labor in China, Tom McGregor said that "American consumers want to buy things at a price that is cheaper than they would be willing to be paid to make them." A century and a half before Tom, English polymath John Ruskin said that "There is nothing in the world that some man cannot make a little worse and sell a little cheaper, and he who considers price only is that man's lawful prey." Invoking Zittrain yet again, the user of free services is not the customer, he's the product. Let me then say that if you are going to be a data collector, if you are bound and determined to instrument your life and those about you, if you are going to "sell" data to get data, then I ask that you not work so cheaply that you collectively drive to zero the habitat, the lebensraum, of those of us who opt out. If you remain cheap, then I daresay that opting out will soon require bravery and not just the quiet tolerance to do without digital bread and circuses. 

To close with Thomas Jefferson: 'I predict future happiness for Americans, if they can prevent the government from wasting the labors of the people under the pretense of taking care of them.'   

Dan Geer, We Are All Intelligence Officers Now, RSA Conference 2014 (Full Text) 

End Game? 

Back in the mid-1990s, reporting from those early RSA Conferences, at the eye of the raging Clipper Chip storm, I was sympathetic to the concerns of national intelligence and law enforcement communities. I was awake to the very real threat from Al Qaeda (yes, very much pre-9/11). I was also deeply concerned about the abomination of child pornography (and the hell realms that provide its content). I understood the frustrations and genuine needs of government agents, friends and colleagues dedicated to fighting such evils. I did not want to deny them tools.

But, of course, I was also laboring under some false assumptions about where we were as a "civil society." It was inconceivable to me that the Bill of Rights would prove to be somehow less than inviolate or that any White House official would ever characterize the Geneva Accords as "obsolete" and "quaint." Likewise, I assumed that the Powell Doctrine would never be ignored, and that the findings of the Church Committee would never be forgotten.  

All these assumptions proved to be wrong. 

It would be easy, too easy, to argue that these false assumptions were swept away in the aftermath of the slaughter of the innocents on 9/11. And that our desperate efforts to respond to that atrocity put us in conflict with some of our own most cherished societal values. But I realize, now, that it would only be misleading to attribute our current circumstances solely to the atrocity of 9/11. Because much of what has happened to us would have happened anyway, one way or another, much of what has been lost in terms of the Bill of Rights, would have been lost anyway, just not as rapidly. Perhaps with better governance in the months prior to 9/11 and in the years, there would have been more time for reasoned debate. Perhaps better choices could have been made.

Perhaps. But only perhaps.

As Geer's speech elucidates, our current circumstances are to a great extent the consequence of Moore's Law (number of transistors on integrated circuits doubles approximately every two years) and Zuboff's Three Laws (everything that can be automated will be automated, everything that can be informated will be informated, every digital application that can be used for surveillance and control will be used for surveillance and control).

The process is seemingly inexorable. Is there time for the relevant choice that Geer eluded to in his remarks, and are there viable options from which to choose?

Either way, "we are all intelligence officers now."

-- Richard Power 


Jim Bizdos posthumously honoring F. Lynn McNulty with the RSA Lifetime Achievement Award. Lynn's wife Peggy accepted on behalf of the family. I had the great pleasure of knowing F. Lynn McNulty, I interviewed him on several occasions in the halycon days, and sought his views on important issues. He was a man of integrity, and a true patriot. (RSA Conference 2014)

Related Posts

RSA 2012: Diffie, Rivest & Shamir Shine on Crypto Panel, Ranum, Too, re: Cyber War 

RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step? 

RSA 2010: Lifestyle Hacking - Notes on "Social Networks & Gen Y Meet Security & Privacy"

RSA 2010: Hacking the Smart Grid - Myths, Nightmares & Professionalism

RSA 2010: Merging Mind & Machine - Hacking the Neural Net

RSA Conference 2009: Summary of Posts 


RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.4AGXnxqr.dpuf
RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.dO6FYYKP.dpuf
RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.4AGXnxqr.dpuf
RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.4AGXnxqr.dpuf
RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.4AGXnxqr.dpuf
RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.4AGXnxqr.dpuf
RSA 2011: One Flew Over the Kaku's Nest & Other Ruminations - See more at: http://www.cyblog.cylab.cmu.edu/2011/02/rsa-2011-one-flew-over-kakus-nest-other.html#sthash.4AGXnxqr.dpuf


Thursday, May 23, 2013

CyLab's Strong Presence Continues at Annual IEEE Symposium on Security and Privacy

Min Suk Kang with fellow CyLab grad student, after presenting The Crossfire Attack at
34th Annual IEEE Security & Privacy Symposium (May 2013, San Francisco).
The 34th annual IEEE Security and Privacy Symposium was held May 19-22 2013, in downtown San Francisco. Once again, as in recent years, Carnegie Mellon University CyLab researchers made a significant contribution to both its content and its tone.

CyLab Distinguished Fellow Adrian Perrig served as one of the three Program Chairs, along with Wenke Lee of Georgia Tech and Michael Backes of Saarland University.

Also, four of the thirteen Session Chairs were current or former CyLab researchers: current faculty members Lujo Bauer and Anupam Datta, and former faculty members Jon McCune, now with Google, and Bryan Parno, now with Microsoft Research.

Two CyLab papers were among the thirty-eight presented: The Crossfire Attack authored by Min Suk Kang, Soo Bum Lee and Virgil D. Gligor of CyLab, and Design, Implementation and Verification of an eXtensible and Modular Hypervisor Framework authored by CyLab researchers Amit Vasudevan, Limin Jia, James Newsome and Anupam Datta, along with Sagar Chaki of the Software Engineering Institute (SEI) at Carnegie Mellon University) and Jonathan M. McCune of Google (a former CyLab researcher, as mentioned above).

Furthermore, the Best Paper Award went to Bryan Parno for Pinocchio: Nearly Practical Verifiable Computation, co-authored with Craig Gentry and Mariana Raykova of IBM Research and Jon Howell, also of Microsoft Research. Before he went to Microsoft, Parno did his PhD at Carnegie Mellon University CyLab under the supervision of Adrian Perrig, and his dissertation won the 2010 ACM Doctoral Dissertation Award.

Here are excerpts from the two CyLab papers presented, with links to the full texts:

In this paper, we present the Crossfire attack. This attack can effectively cut off the Internet connections of a targeted enterprise (e.g., a university campus, a military base, a set of energy distribution stations); it can also disable up to 53% of the total number of Internet connections of some US states, and up to about 33% of all the connections of the West Coast of the US. The attack has the hallmarks of Internet terrorism3: it is low cost using legitimate-looking means (e.g., low-intensity, protocol conforming traffic); its locus cannot be anticipated and it cannot be detected until substantial, persistent damage is done; and most importantly, it is indirect: the immediate target of the attack (i.e., selected Internet links) is not necessarily the intended victim (i.e., an end-point enterprise, state, region, or small country). The low cost of the attack (viz., Section IV), would also enable a perpetrator to blackmail the victim. The Crossfire Attack , Min Suk Kang, Soo Bum Lee and Virgil D. Gligor (Carnegie Mellon University CyLab)

We propose an eXtensible and Modular HypervisorFramework (XMHF) which strives to be a comprehensible and flexible platform for building hypervisor applications (“hypapps”). XMHF is based on a design methodology that enables automated verification of hypervisor memory integrity. In particular, the automated verification was performed on the actual source code of XMHF – consisting of 5208 lines of C code – using the CBMC model checker. We believe that XMHF provides a good starting point for research and development on hypervisors with rigorous and “designed-in” security guarantees. Given XMHF’s features and performance characteristics, we believe that it can significantly enhance (security-oriented) hypervisor research and development. Design, Implementation and Verification of an eXtensible and Modular Hypervisor Framework, Amit Vasudevan, Limin Jia, James Newsome and Anupam Datta (Carnegie Mellon University CyLab), Sagar Chaki (SEI, Carnegie Mellon University) and Jonathan M. McCune (Google)

Some Related Posts
 
CyLab Chronicles: CyLab's Strong Presence at IEEE Security and Privacy 2012 Packs A Wallop

CyLab Research has Powerful Impact on 2010 IEEE Security & Privacy Symposium

CyLab Researchers Virgil Gligor and David Brumley Receive Honors

CyLab researcher Bryan Parno wins ACM 2010 Doctoral Dissertation Award

Parno, McCune and Perrig Author Book on Bootstrapping Trust in Modern Computing

-- Richard Power




Sunday, May 19, 2013

CyLab Researchers Alessadro Acquisti and Marios Savviddes featured on CBS Sixty Minutes



[NOTE: This CyBlog story is cross-posted as a CyLab Chronicles on the CyLab home page.]

In the wake of the Boston Marathon bombing investigation, there has been some mainstream news media attention paid to facial recognition software. After years of NCIS and other popular law enforcement TV dramas, there is an expectation that such technology could have led to a speedier conclusion to the manhunt, or perhaps even have prevented the savage attack.

In recent weeks, looking for meaningful answers, major news organizations turned to researchers at Carnegie Mellon University CyLab. Why? Because they are at the forefront of research into related technologies; and that's the forefront of not only research on how to deliver these technologies, but also the forefront on their broader implications on society as a whole.

On the May 19th edition of CBS Sixty Minutes, the work of two Carnegie Mellon University CyLab researchers were featured: Alessandro Acquisti, Associate Professor of Information Technology and Public Policy (Heinz College), author of some blockbuster privacy studies, related to the convergence of facial recognition software and social media and other vital issues, and Marios Savvides, Carnegie Mellon University Associate Professor (Electrical and Computer Engineering Department) and Director of the CyLab Biometrics Center.

Here is the CBS Sixty Minutes video, followed by some transcript excerpts:


This may look like a high school science project, but this is Carnegie Mellon's CyLab, a world-class research center.

[Lesley Stahl: Look at that!]

Marios Savvides and his students outfitted this ordinary toy drone with their new advanced facial recognition software... that locks in on a face from a distance, and then identifies it. [Drone: Hello Lesley, nice to see you.

Lesley Stahl: It got it.]

The students are taking surveillance technology to the next level. They can now turn a blurry face into a clear one; a flat image into a 3D model.

[Lesley Stahl: Oh my goodness.]

Their technology can take a masked face and by focusing only on the eyebrows search a catalog of faces, come up with several people with very similar eyebrows and eventually find the identity of the person.

Marios Savvides: So Utzav is going to take a normal photo of you. The software maps a face using dots like electronic measles and creates something as unique as a fingerprint: a faceprint.

Lesley Stahl: This is your facial recognition technology working right now to find me? Utzav: Yes.

For this demonstration, they had added my picture ahead of time to the university's database. Marios Savvides: That's the top match.

[Samsung Lady: To use face recognition, use the color-coded button on your remote.]

Facial recognition is already in some of our home appliances like TVs. In our mobile devices, PINs and passwords are giving way to faceprints. And the technology can single us out in real-time as we go about our daily business, often without us ever knowing ...

Alessandro Acquisti: The ability of remaining anonymous is shrinking. And the places where we can be anonymous are getting fewer and fewer.

Alessandro Acquisti is a professor at Carnegie Mellon who does research on how technology impacts privacy. He says that smart phones may make "facial searches" as common as Google searches and he did an experiment to show how easy it could be. He took photos of random students on his campus. He then ran the pictures through a facial recognition program he downloaded for free that sifted through Facebook profiles and other websites. And he was able not only to identify many of them instantly, he also got their personal data, including in some cases, their social security numbers.

Lesley Stahl: In order for this to work, does the person you're trying to identify have to be on one of these social networks?

Alessandro Acquisti: You must have, somewhere on the Internet, a face with your name on it. Lesley Stahl: Well, let's say someone doesn't have a Facebook account, but his or her daughter or son does, and they've got your picture. So are they now automatically in the mix?

Lesley Stahl: Well, let's say someone doesn't have a Facebook account, but his or her daughter or son does, and they've got your picture. So are they now automatically in the mix?

Alessandro Acquisti: It's funny because one of the participants, before doing the experiment, told us, "You're not going to find me because I'm very careful about my photos online." And we found him. Because someone else had uploaded a photo of him.

But if an academic can easily mine our data with facial recognition, what about the government? Well, the government has a problem because to be effective, facial recognition requires a good database. Facebook for instance has one with billions and billions of photos. The government not nearly that many, and so the FBI is now assembling on these rows of servers the largest biometric database on Earth, costing over a billion dollars ...

Alessandro Acquisti: Often we are not even aware of how much data we are actually revealing or it is being gathered about us or, in fact, how it would be used. The idea that you can start from a face and predict social security numbers from that face seemed quite alien and surprising. But now we know that it can be done.

Lesley Stahl: So there's no place to hide, absolutely no place to hide.

Alessandro Acquisti: It's those places are shrinking.


CBS 60 Minutes, 5-19-13

(Savvides also appeared in a recent CNN news story on the same subject.)

-- Richard Power

Wednesday, May 8, 2013

CyLab's Marios Savvides Appears on CNN in Wake of Boston Marathon Bombing Investigation



In the wake of the Boston Marathon bombing investigation, there has been some mainstream news media attention paid to facial recognition software. After years of NCIS and other law enforcement TV dramas, there is some popular expectation that such technology could have led to a speedier conclusion to the manhunt, or perhaps even have prevented the savage attack.

Looking for meaningful answers, CNN turned to Marios Savvides, Carnegie Mellon University Associate Professor and Director of the CyLab Biometrics Center, a leading expert in the field.

Here is a video excerpt, followed by a transcript of the news story:



TOM FOREMAN, CNN CORRESPONDENT: "When the FBI released these photos during the search for the Boston suspects, there was hope that computers might help as they do on shows like CSI, comparing facial features with existing data and coming up with a name. But even though pictures of both brothers were in public databases, the computers that searched that data missed them, and came up empty. The government has been working on facial identification software since the 1960s, and companies like Facebook and Apple use similar technology to tag people in photos. But security analysts widely admit this technology is not good enough to spot a suspect in the crowd. At Carnegie Melon, Mario Savvides runs the CyLab Biometric Center.

MARIOS SAVVIDES, DIRECTOR, CMU CYLAB BIOMETRICS CENTER: While the toughest problems is low resolution, when you look at images collected from (inaudible) TV footage, the faces are way too small.

FOREMAN: His team is developing next generation software to change poor and partial images into much clearer pictures. They are creating programs that can reliably match images of people to their true identities, despite low light, movement, odd positions.

SAVVIDES: Off-angle is a big challenge. How do you match an off- angle image that`s say 50 degrees, 60 degrees, 45 degrees off angle to a face that`s just a frontal sort of, you know, passport-type photo.

FOREMAN: They`re even transforming flat pictures into 3D, look at what their lab did with a single photo of me. In less than an hour it was turned into a series of images showing how I might look from above, from the left, from the right. Savvides believes such programs can and will substantially improve the reliability of facial recognition and lead police to suspects much faster.

SAVVIDES: And ultimately, hopefully save life, because that`s our aim, that`s our goal, that`s everything we do here.

FOREMAN: For now, the FBI is installing its latest version of facial identification software to work with security cameras coast to coast as part of the billion-dollar program called "next generation identification." Still, in Boston, it wasn`t technology, but human investigators who triumphed. Tom Foreman, CNN, Washington.

 
CNN, 5-7-13

-- Richard Power