Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Tuesday, April 15, 2014

CyLab Research Sheds Light on Heartbleed and Its Implications


Heartbleed is a significant event along the cyber security timeline. Its consequences will be with us all for quite awhile. If you haven't already come to grips with this issue, you should do so urgently.

For some guidance go to http://heartbleed.com/

To verify if a particular server is vulnerable, go to: http://filippo.io/Heartbleed/

For a command-line tool, go to: https://github.com/FiloSottile/Heartbleed

Here at CyLab, the story has provided us with an opportunity to reflect on some of our recent research and its relevancy to the problem at hand, e.g., --

Perspectives: If you scan a server, and find that it isn't vulnerable, you would still need to know if it had been vulnerable in the past, and/or if it has been updated. One way to answer that question is to determine if the private key has been updated. If you connect to the server with a Firefox browser that has the Perspectives extension installed, and then inspect the key history. To do so, click the Perspectives icon on the left-hand of the URL bar, and select "View Notary Results." (Of course, if the key has not been changed, you're still none the wiser.) For more on Perspectives, visit the Perspectives Project page.

TrustVisor: In TrustVisor, we proposed keeping the OpenSSL private key inside a PAL, which would have defended against this vulnerability. See our paper on TrustVisor: Efficient TCB Reduction and Attestation, authored by Jonathan M. McCune (now with Google), Yanlin Li, Ning Qu, Zongwei Zhou, Anupam Datta, Virgil Gligor and Adrian Perrig.

Flicker: In Flicker, we proposed to store the SSH password database inside a PAL, which would also prevent password theft. See Flicker: An Execution Infrastructure for TCB Minimization,
authored by three CyLab researchers Jonathan M. McCune, Bryan Parno (now with Microsoft), and Adrian Perrig (now with ETH Zurich), along with Michael K. Reiter of University of North Carolina (Chapel Hill), and Hiroshi Isozaki of Toshiba Corporation.

Perspectives, TrustVisor and Flicker all evolved out of CyLab's work on Trustworthy Computing Platforms and Devices. And this continues to be one of CyLab's major research thrusts.

Amit Vasudevan, a CyLab  Research Systems Scientist, and Miao Yu, a CyLab grad student, took a few moments to sit down with CyBlog, and share some insights on where we are and what's next.

According to Vasudevan, "the IEE technologies and prototypes we have been developing (XMHF - TrustVisor, KISS, Minibox, etc.) lay a solid foundation to protect against Heartbleed-like attacks."

"But going from our prototypes to the real-world is a different kind of challenge. The software ecosystem out there today does not really consider security as a first-class citizen. Consequently, tweaking these components to adapt to our IEE design is non-trivial ...  In the long term, developers of security-oriented/sensitive software would benefit from a simple and solid security framework that would allow them to leverage strong security properties, while letting them also implement the desired functionality. And our work with XMHF plus Trustvisor plus other hypapps (http://xmhf.org) is the right step in this direction."

"This bug is still underestimated," warns Yu.

He cites three reasons for his concern:
"Currently, we putting a lot of care into HTTPS websites. But other protocols, e.g., FTPS (used in file transfer) server, can also be impacted by this bug. 

"Not only servers, but also clients, e.g. smart phones and other devices, may suffer from this bug. And for certain devices, the problem can be even worse. For example, mobiles phones have long patch cycles. For the heartbleeding bug, the first patch of this bug came out in 20 minutes and web servers began the repair in the first day. But Android phones only get scanners, e.g., Bluebox Heartbleed Scanner or Heartbleed Detector to help users find out if their phone is vulnerable ... From our experience with past vulnerabilities, it would take tens of weeks until half of the mobile devices get patched. During this period, the devices are at risk. Other devices, which may use OpenSSL for establishing administration channels, also may suffer from long patch cycles. At CyLab, Zongwei Zhou, Miao Yu, Yoshiharu Imamoto, Amit Vasudevan, Virgil Gilgor and I have developed an isolated execution environment for the ARM mobile platform. It is quite similar to TrustVisor, but focuses on mobile system security, so that, e.g., you could run a banking client (or some other sensitive application) in an isolated execution environment, so that your code and data would still be secure in spite of this or other vulnerabilities present in Android.

"All three recent SSL bugs, i.e., IOS's goto fail bug, the GnuTLS bug and the Heartbleed bug are implementation-related rather than design related. The lesson is that design security doesn't mean implementation security. We do need runtime protection as a last line of defense."

-- Richard Power

Tuesday, November 27, 2012

CyLab Researchers Make Major Advances In Audit Technology For Privacy Protection



A team of researchers at Carnegie Mellon University led by Dr. Anupam Datta, Assistant Research Professor at CyLab and Electrical & Computer Engineering, has developed algorithms that can help protect individual privacy by checking that organizations such as hospitals and banks are disclosing personal information about their customers to third parties in compliance with privacy regulations. They have produced the first complete formal specification of disclosure clauses in two important US privacy laws -- the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and the Gramm-Leach-Bliley Act (GLBA).

They also built an algorithm that can help investigators detect violations of these laws and similar privacy policies. The research team included Henry DeYoung (a graduate student in the Computer Science Department) and three postdoctoral researchers in Dr. Datta's research group: Dr. Deepak Garg (now faculty at MPI-SWS), Dr. Limin Jia (now faculty at CMU CyLab), and Dr. Dilsun Kaynar (now faculty at CMU Computer Science Department).

Privacy has become a significant concern in modern society as personal information about individuals is increasingly collected, used, and shared, often using digital technologies, by a wide range of organizations. To mitigate privacy concerns, organizations are required to respect privacy laws in regulated sectors (e.g., HIPAA in healthcare, GLBA in financial sector) and to adhere to self-declared privacy policies in self-regulated sectors (e.g., privacy policies of companies such as Google and Facebook in Web services). Enforcing these kinds of privacy policies in organizations is difficult because privacy laws and enterprise policies typically identify a complex set of conditions governing the disclosure of personal information. For example, the HIPAA Privacy Rule includes over 80 clauses that permit, deny, and even require the disclosure of personal health information, making it difficult to manually ensure that all disclosures are compliant with the law. 

The research team at Carnegie Mellon University created a formal language for specifying a rich class of privacy policies. They then used this language to produce the first complete formal specification of disclosure clauses in two important US privacy laws -- the Health InsurancePortability and Accountability Act (HIPAA) Privacy Rule and theGramm-Leach-Bliley Act (GLBA). Recognizing that certain portions of complex privacy policies such as HIPAA are subjective and might require input from human auditors for compliance determination, the specification clearly separates out the subjective and the objective portions of a given policy.

The team then developed an algorithm that checks audit logs for compliance with privacy policies expressed in their language.  The algorithm has two distinct characteristics. First, it automatically checks the objective portion of the privacy policy for compliance and outputs the subjective portion for inspection by human auditors. Second, recognizing that audit logs are often incomplete in practice (i.e., they may not contain sufficient information to determine whether a policy is violated or not), the algorithm proceeds iteratively: in each iteration it checks as much of the policy it possibly can over the current log and outputs a residual policy that can only be checked when the log is extended with additional information. Initial experiments with a prototype implementation checking compliance of simulated audit logs with the HIPAA Privacy Rule indicates that the algorithm is fast enough to be used in practice. 

Additional information about this work can be found on the project web page:http://www.andrew.cmu.edu/user/danupam/privacy.html

Carnegie Mellon CyLab Awarded DHS Contract For Research Into Understanding And Disrupting The Economics Of Cybercrime



Carnegie Mellon University CyLab has been awarded a multi-million dollar contract for research into Understanding and Disrupting the Economics of Cybercrime. Nicolas Christin, CyLab Senior Systems Scientist and Associate Director of the Information Networking Institute (INI), is Principle Investigator (PI). His co-PIs are fellow CyLab researcher Alessandro Acquisti, along with Tyler Moore of Southern Methodist University, Ross Anderson of Cambridge University, and Ryan Williams of NFCTA. Richard Clayton of Cambridge University will also participate as instrumental senior personnel.

Based on the realization that focusing on a particular attack, or a specific set of attacks, is unlikely to provide the detailed level of understanding necessary to design meaningful intervention policies against cybercrime, the methodology developed by Christin and his colleagues holistically combines network measurements with behavioral and economic analysis. The project will consist of four research tasks: designing cybercrime indicators, designing data interchange formats and standards, modeling online-crime supply chains and modeling attackers' behavioral psychology The contract is one of thirty four, totaling $40 million that the U.S. Department of Homeland Security (DHS) Science and Technology Directorate (DHS S&T) has awarded to twenty-nine academic and research organizations. This funding is for research and development of cyber security solutions.

In January 2011, the DHS S&T Cyber Security Division (CSD) issued a Cyber Security R&D Broad Agency Announcement (BAA 11-02) that solicited proposals for 14 Technical Topic Areas (TTAs) aimed at improving security in federal networks and across the Internet while developing new and enhanced technologies for detecting, preventing and responding to cyber attacks on the nation's critical information infrastructure. BAA 11-02 elicited white paper responses from more than 1,000 offerors.

Following extensive review and down-select process, more than 200 offerors were invited to submit full proposals for final review. And of those, new awards were made to the twenty-nine organizations that were announced on October 26, 2012.

"The work to be accomplished through these contracts will significantly advance cyber security and support the mission of the DHS Science and Technology Directorate's Cyber Security Division to create a safe, secure and resilient cyber environment," Dr. Douglas Maughan, director of DHS' S&T Cyber Security Division told Homeland Security Today. "Our goal," said Maughan, "is to transform the cyber-infrastructure to be resistant to attack so that critical national interests are protected from catastrophic damage and our society can confidently adopt new technological advances." (See Homeland Security Today, 10-26-12)


Monday, November 5, 2012

Glimpses into the 9th Annual CyLab Partners Conference

CyLab Researchers Nicolas Christin, Rahul Telang, Alessandro Acquisti
9th Annual Cylab Partners Conference (October 2012)
Glimpses into the 9th Annual CyLab Partners Conference

[NOTE: This CyBlog post is also cross-posted as a CyLab Chronicles on the main CyLab web site.]

The 9th Annual CyLab Partners Conference was held at the main campus of Carnegie Mellon University (Pittsburgh, Pa.), on October 2nd and 3rd, 2012.

The Partners Confernce is an exclusive benefit of membership in the CyLab Partners program, and like the recruitment opportunities, reputational boost and Seminar webcasts, it is one of several benefits that is available to all Partners, whether at $25,000 level, the $100,000 level or the $350,000 level.

For two days, representatives from CyLab's corporate Partners recieve research updates from our work across a broad range of areas, e.g., Next Generation Internet, Trustworthy Computing, Mobility, Software Security, Usable Privacy and Security, Businss Risks and Economic Implications, and more. Perhaps even more important is the time to interact one on one with faculty researchers during breaks and meals, and to interact with CyLab's graduate students at the poster session.

Annual Partners Conference content is archived on the CyLab Partners Portal (another exclusive benefit of membership), including videos of the research presentations, along with .pdfs of the slides for each presentation, as well as electronic files of the student posters, documenting current projects.

To entice you to consider taking advantage of the benefits of CyLab partnership, and to contribute to the general dialogue on the vital issues of cyber security and privacy, we have posted a CyLab Partners Conference video sampler and some other content to both the CyLab YouTube Channel and the CyLab iTunesU Store.

The sampler, 9th Annual Partners Conferenece Excerpts, includes two or three minute snippets from each of the following six presentations:
  • Virgil Gligor - "On Foundations of Trust in Networksof Humans and Computers"
  • David Brumley - "Automatically Finding Exploitable Bugs in Off-The-Shelf Executables"
  • Mike Farb - "SafeSlinger: Applied Ad-Hoc Smartpone Trust Establishment"
  • Lorrie Cranor - "Measuring the Success of Web-based Spoofing Attacks on OS Password-Entry Dialogs" 
  • Collin Jackson - "Web Security" 
  • Rahul Telang - "Competition and Data Breaches"
  • Norman Sadeh - "Mobile Privacy"


Four full faculty researcher presentations have also been made available publicly:
Related Posts

Tuesday, October 30, 2012

An Update on My "Secrets Stolen/Fortunes Lost" Co-Author Christopher Burgess



In case you missed it, my Secrets Stolen, Fortunes Lost co-author, Christopher Burgess was featured in a recent Forbes Magazine article on What Do Former CIA Spies Do When They Quit the Spy Game?

Upon retirement after thirty years with the Central Intelligence Agency, in various position including Station Chief, Burgess, was awarded the Career Distinguished Intelligence Medal, the highest level of career recognition. After retirement, he took on important roles in the private sector, first as Senior Advisor to Cisco Chief Security Office (CSO) John Stewart, and then as CSO himself at Atigeo. In the Forbes piece, Christopher shares some insights on his transition:

One [skill] that served me well was my ability to collaborate. That’s a huge skill for a field officer. Everybody on a team has something to contribute and you have to truly recognize and believe that. Another skill is a technique common to planning intelligence operations: building in ‘fall back positions’ and alternate routes while mapping out how to attain a goal. In Agency operations, things go wrong and you have to have backup plans. Also in the corporate world, whether you are selling a widget or consulting, competitors will surprise you. Dealing with that surprise, keeping your cool when all about you are losing theirs, definitely came from Agency training. Another key skill I developed in the Agency was creating loyal workforces, which yield outstanding results. A big part of that is knowing exactly what you are asking someone to do. If you don’t know from personal experience, you cannot be shy about asking them to give you feedback on their probability of success in a risky operation. Art Keller, What Do Former CIA Spies Do When They Quit the Spy Game? Forbes, 10-12-12

As I have mentioned in previous posts, this year, in CSO Magazine, I have been focusing on interviews with C-level executives, who also happened to be thought-leaders. (Surely, you have noticed that "C-level executives" and "thought leaders" are not straightforward synonyms?)

In the first of these interviews (fourth one coming soon), Christopher and I discussed a range of vital issues, but of course we started with a look back at our collaboration on Secrets Stolen/Fortunes Lost:

My 30,000-foot perspective has not changed since we co-authored Secrets Stolen, Fortune Lost — every company (emphasis intended) regardless of locale has the potential to fall into the sights of an entity or individual who has designs on their assets. The company can choose to educate or not educate their workforce to this reality. Sadly, I continue to see far too many companies operating as if they are immune from falling into the cross-hairs of someone's targeting scheme because they aren't engaged in national security work — they equate economic espionage and IP theft to only those in the national security vertical. While I don t disagree the nation state vector is one about which we, collectively, must pay attention; the individual, the competitor and the criminal vectors also warrant every company's attention. How to meet the challenges of 21st century security and privacy, CSO Magazine, 4-18-12

NOTE: You can find links to all my CSO Magazine articles in the CyBlog sidebar.

Christopher Burgess is also one of those experts from business and government (in this instance, it's a twofer!) who have delivered CyLab Seminars in the context of my Business Risks Forum. He has given two Seminars, one in 2010 and one this year.

Access to the webcast and online archive of the CyLab Seminar series is an exclusive benefit available only to CyLab Partners. But from time to time, we release select seminars, and excerpts from seminars, via You Tube and iTunes to both promote our program and contribute to the public dialogue on the vital issues of cyber security and privacy.

Here are embedded videos of both of Burgess' CyLab Seminars. Enjoy.

CyLab Business Risks Forum: Christopher Burgess - Collaborative Distributed Inferencing (2012)



CyLab Business Risks Forum: Christoper Burgess - Common Sense Approach to Social Media (2010)

Sunday, July 18, 2010

TIW 2010: Jonathan McCune for Adrian Perrig on "Software-Based Attestation: History, Constructions, Applications, Current State of Research" (6-9-10)

Jonathan McCune for Adrian Perrig on "Software-Based Attestation: History, Constructions, Applications, Current State of Research," TIW 2010, 6-9-10, CyLab/Carnegie Mellon University (Part I)



Jonathan McCune for Adrian Perrig on "Software-Based Attestation: History, Constructions, Applications, Current State of Research," TIW 2010, 6-9-10, CyLab/Carnegie Mellon University (Part II)



Jonathan McCune for Adrian Perrig on "Software-Based Attestation: History, Constructions, Applications, Current State of Research," TIW 2010, 6-9-10, CyLab/Carnegie Mellon University (Part III)



Jonathan McCune for Adrian Perrig on "Software-Based Attestation: History, Constructions, Applications, Current State of Research," TIW 2010, 6-9-10, CyLab/Carnegie Mellon University (Part IV)



For more information on TIW 2010:

Notes on TIW 2010: The Builders & Building Blocks of Trustworthy Infrastructure

CyLab Chronicles: A Report on TIW 2010

Trustworthy Infrastructure Workshop (TIW) 2010

TIW 2010: Research Workshop Panel Discussion - Adrian Perrig, Jonathan McCune. (6-9-10)

TIW 2010 Research Workshop Panel Discussion: Adrian Perrig, Jonathan McCune. 6-9-10, CyLab/Carnegie Mellon University



TIW 2010 Research Workshop Panel Discussion: Adrian Perrig, Jonathan McCune. 6-9-10, CyLab/Carnegie Mellon University (Part II)



TIW 2010 Research Workshop Panel Discussion: Adrian Perrig, Jonathan McCune. 6-9-10, CyLab/Carnegie Mellon University (Part III)



TIW 2010 Research Workshop Panel Discussion: Adrian Perrig, Jonathan McCune. 6-9-10, CyLab/Carnegie Mellon University (Part IV)



For more information on TIW 2010:

Notes on TIW 2010: The Builders & Building Blocks of Trustworthy Infrastructure

CyLab Chronicles: A Report on TIW 2010

Trustworthy Infrastructure Workshop (TIW) 2010

TIW 2010: Virgil Gligor Delivers "A Challenge for Trustworthy Computing" (6-7-10)

Virgil Gligor, CyLab Director, issues "A Challenge for Trustworthy Computing" at TIW 2010 on the Carnegie Mellon Campus, in Pittsburgh, Pa., on 6-7-10. (Part I)



Virgil Gligor - Part II - Axioms (continued), (Ir)relevance of Virtualization to Humans



Virgil Gligor - Part III - (Ir)relevance of Security Kernels to Assurance, Conclusions



For more information on TIW 2010:

Notes on TIW 2010: The Builders & Building Blocks of Trustworthy Infrastructure

CyLab Chronicles: A Report on TIW 2010

Trustworthy Infrastructure Workshop (TIW) 2010

Saturday, July 17, 2010

CyLab Business Risks Forum: Cormac Herley - "Everything You Know About Cybercrime is Wrong"



CyLab Business Risks Forum: Cormac Herley - "Everything You Know About Cybercrime is Wrong" (4-26-10)

This CyLab You Tube Channel video is a brief excerpt from a CyLab Business Risks Forum event featuring
Cormac Herley
, Principal Researcher at Microsoft Research, speaking on "Everything You Know About Cybercrime is Wrong."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Ed Stroz - "Manipulation of Digital Evidence in Investigations"



CyLab Business Risks Forum: Ed Stroz - "Manipulation of Digital Evidence in Investigations" (3-22-10)

This CyLab You Tube Channel video is a brief excerpt from a CyLab Business Risks Forum event featuring Ed Stroz of Stroz Friedburg, speaking on "Manipulation of Digital Evidence in Investigations."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Christoper Burgess - "Common Sense Approach to Social Media"



CyLab Business Risks Forum: Christoper Burgess - "Common Sense Approach to Social Media"(1-25-10)

This CyLab You Tube Channel video is a brief excerpt from a CyLab Business Risks Forum event featuring Christoper Burgess, co-author of Secrets Stolen, Fortunes Lost, and a Senior Security at Cisco Systems, speaking on "Common Sense Approach to Social Media."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Erin Kenneally - "Information Sharing vs. Privacy, Is it a Celebrity Death Match?"



CyLab Business Risks Forum: Erin Kenneally - "Information Sharing vs. Privacy, Is it a Celebrity Death Match?"(11-16-09)

This CyLab You Tube Channel video is a brief excerpt from CyLab Business Risks Forum: Erin Kenneally on "Information Sharing vs. Privacy - Is it a Celebrity Death Match?"

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Richard Power - "Starting Over After A Lost Decade; In Search of a Bold New Vision for Cyber Security"



CyLab Business Risks Forum: Richard Power - "Starting Over After A Lost Decade; In Search of a Bold New Vision for Cyber Security" 10-26-09

This CyLab You Tube Channel video is a brief excerpt from CyLab Business Risks Forum: Richard Power on "Starting Over After A Lost Decade; In Search of a Bold New Vision for Cyber Security."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Jennifer Bayuk - "Enterprise Security for the Executive: Setting the Tone From the Top"



CyLab Business Risks Forum: Jennifer Bayuk - "Enterprise Security for the Executive: Setting the Tone From the Top"(09-28-09)

This CyLab You Tube Channel video is a brief excerpt from CyLab Business Risks Forum: cyber security expert and author Jennifer Bayuk on "Enterprise Security for the Executive: Setting the Tone From the Top."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Rebecca Herold - Convergence of Information Security, Privacy and Compliance



CyLab Business Risks Forum: Rebecca Herold, "Convergence of Information Security, Privacy and Compliance" (2-23-09)

This CyLab You Tube Channel video is a brief excerpt from CyLab Business Risks Forum: Rebecca Herold of www.rebeccaherold.com on "Convergence of Information Security, Privacy and Compliance."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

CyLab Business Risks Forum: Mike Susong - Electronic Crime Ecosystem: Evolution from Cold War to Cold Cash



CyLab Business Risks Forum: Mike Susong - "Electronic Crime Ecosystem: Evolution from Cold War to Cold Cash" (1-26-09)

This CyLab You Tube Channel video is a brief excerpt from CyLab Business Risks Forum: Mike Susong of iSIGHT Partners on "Electronic Crime Ecosystem: Evolution from Cold War to Cold Cash."

The CyLab Business Risks Forum is a part of the CyLab Seminar Series.

Forum events feature guest speakers from business and government, invited by CyLab Distinguished Fellow, Richard Power.

CyLab Business Risks Forum and CyLab Seminar Series events are open to CyLab Partners and to Carnegie Mellon CyLab faculty and students.

Full-length recordings of these talks are available via the CyLab Partners Portal, and access to the Portal is only granted to participants in the CyLab Partners Program.

For more information on how and why to become a CyLab Partner, visit CyLab Online at http://www.cylab.cmu.edu.

Wednesday, April 21, 2010

CyLab News Update: Recent Awards & Activities Highlight Strength & Scope of Program

Samuel Langhorne Clemens (a.k.a. Mark Twain) in the lab of Nikola Tesla, spring of 1894.

CyLab News Update: Recent Awards & Activities Highlight Strength & Scope of Program

By Richard Power


Here are brief excerpts on CyLab news stories about three awards and four activities from the first third of 2010 (with links to the full text of posts). These items highlight the strength and scope of CyLab's world-class research program.

Stay tuned, it is going to be an exciting year!

CyLab's Anupam Datta Named to SHARPS Multi-University Research Effort into Health IT Security & Privacy
Carnegie Mellon University’s Anupam Datta is part of a multi-institutional research team that received a $15 million grant from the U.S. Department of Health and Human Services to reduce security and privacy barriers to the meaningful use of health information technology. Datta, an Assistant Research Professor with Carnegie Mellon CyLab, is one of twenty senior investigators from twelve institutions involved in this collaborative project named Strategic Healthcare IT Advanced Research Projects on Security (SHARPS). Carnegie Mellon’s portion of the award is around $700,000 spread over 4 years. Full text.

Carnegie Mellon CyLab’s David Brumley Receives Prestigious Early Career Award from National Science Foundation
Carnegie Mellon University CyLab's David Brumley has received the National Science Foundation's Faculty Early Career Development (CAREER) Award, its most prestigious award for junior faculty.
Brumley, 35, who is a CyLab researcher as well as an assistant professor in the Department of Electrical and Computer Engineering and the School of Computer Science, received a five-year, $521,494 award to develop a system that will track and eliminate annoying software bugs.
Full text.

CyLab Researchers Win ACM WiSec Best Paper Award for Mobile User Location-specific Encryption (MULE)
CyLab's Technical Director Adrian Perrig and graduate student Ahren Studer have won Best Paper for the Association of Computing Machiner (ACM) Conference on Wireless Network Security (WiSec).
The award-winning paper is entitled: "Mobile User Location-specific Encryption (MULE): Using Your Office as Your Password."

Full text.

CUPS wins Google Focused Research Award
Dr. Lorrie Cranor, CUPS Director, has been named one of the recipients of a Google Focused Research Award ... According to Google, "These unrestricted grants are for two to three years, and the recipients will have the advantage of access to Google tools, technologies, and expertise."
Dr. Cranor is one of thirty-one professors at ten universities, working on twelve different projects.
Full text.

A Report from "Hacking Comes of Age: Climategate, Cyber-Espionage and iWar," a University Lecture Series Event
On March 18, 2010, six distinguished speakers participated in a Carnegie Mellon University Lecture Series (ULS) panel on "Hacking Comes of Age: Climategate, Cyber-Espionage and iWar." The panel explored these issues with uncommon depth and uncommon clarity. This event was a testimonial on just how uniquely situated Carnegie Mellon University really is, to serve as a vital national resource; the event also underscored the importance of CyLab's role within the University, cultivating, as it does, both the human factor and the technological edge. (Indeed, five of the six panel participants have some CyLab affiliation.) Full text.

A Report on the CyLab Silicon Valley Briefing
On 3-8-10, an impressive gathering was held at the Carnegie Mellon Silicon Valley Campus in NASA Research Park. The presenters were CyLab researchers. The other participants consisted of CEOs, VPs, CTOs, CSOs and leading technologists from a range of companies including Cisco and Microsoft to WhiteHat Security and iSEC, along with regional representatives from the Federal Bureau of Investigations and the U.S. Secret Service, as well as Board of Directors members from the local chapters of Information Systems Security Association (ISSA) and the American Society for Industrial Security (ASIS). Full text.

CyLab's Cranor Testifies on Privacy Issues to Joint Hearing of Two Congressional Subcommittee
On 2-24-10, the U.S. House of Representatives Committee on Energy and Commerce's Subcommittees on Commerce, Trade, and Consumer Protection and Communications, Technology, and the Internet held a joint hearing titled, "The Collection and Use of Location Information for Commercial Purposes."
Lorrie Cranor, Director of CyLab Usable Privacy and Security (CUPS) testified on the privacy issues related to the use of location information for commercial purposes.

Full text.

For more about CyLab, visit http://www.cylab.cmu.edu/

Friday, March 5, 2010

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?

By Richard Power


Some final observations on RSA Conference 2010:

The presentations I wanted to get to, but couldn't, because of time constraints: "Local is the New Organic - A Bottom-Up Model for Information Sharing," in which Michael Hamilton of the City of Seattle introduced a model for the automated collection of security event data from public and private entities across a metropolitan area, and "Crowd Sourcing Fraud and Abuse Detection," in which Lee Holloway of Project Honey Pot presented early success in breaking down barriers and facilitating the free flow of abuse information between organizations. I hope that even today we live in a world that still allows for the possibility that such ideas can be propagated and exploited for the good of the many as well as the few.

The more and more I hear about the Cloud, from the C-level ("C" for Cloud as well as "Chief") keynoters, the more and more I wonder just where it is we will find ourselves as we migrate lock, stock and barrel into the Cloud (and make no mistake about it, that is where we are all going, or at least that is where most of our IT infrastructure is going).

What are the implications, beyond the obvious security issues? (Indeed, for some enterprises, security in the Cloud will be better than what they have on their own? For example, will all of us find ourselves enveloped in a billowing Cloud so thick it will trump Net Neutrality?

And what about the security and privacy established inside that billowing Cloud, and guaranteed by a cluster of major corporations and massive law enforcement agencies? Will it protect you and I from everyone and everything except (perish the thought) ethically challenged corporations and misdirected law enforcement agencies? Don't get me wrong. We are all going into the Cloud, like it or not.

I just hope you keep one eye on the exits, and remember where everything is (or was) outside that Cloud.

I have covered the RSA Conference annually since the early 1990s. I remember when it consisted of couple of meeting rooms, at the Sofitel Hotel, crammed with cryptographers and a few developers. Then it became an e-commerce conference disguised as a security conference. Then it became the defining event of the year for the IT security sector. And now, it has become even something even bigger; it has become a cross-roads for whole industries, and for government and business, and a window on cultures (corporate, institutional and popular). Swirling in the din that rises up from this Barnum & Bailey production, you can detect intermingled strains of music that are both disturbing and inspiring.

After four CyBlog posts (one for every day of the conference), and over 60 tweets, I will close with a few brief excerpts from a presentation on "Wired for War: The Robotics Revolution and 21st Century Conflict," delivered by Dr. Peter Warren Singer, a Senior fellow and director of the 21st Century Defense Initiative at the Brookings Institution.

Dr. Peter Warren Singer, Brookings Institution: There is something big going on in war today, and maybe even in the overall history of humanity itself. The US military force that went into Iraq in 2003 had a handful of drones ... we now have over 7,000 in the U.S. military inventory. The invasion force on the ground utilizied zero unmanned ground vehicles, we now have over 12,000 ... This year, the U.S. Air Force will train more unmanned systems operators than it will train manned bomber and manned fighter plane pilots combined ... These Predators, [etc.], are the first generation, they are a lot like the Model-T Ford or the Wright Brothers Flyer ... very soon it is not going to be thousands of robots as we use in our war today, it is going to be tens of thousands ...One of the things that you are familiar with, of course is Moore's Law: the idea that we have been able to pack far more computing power into our micro-chips, such so that they just about double in their power capacity just under every two years. Moore's Law, in action, is the reason that if you have ever gotten one of those Hallmark Greeting Cards that opened up and played a little song, you held in your hand more computing power than the entire U.S. Air Force had in 1960 ... Now if Moore's Law holds true, over the next twenty-five years, our systems, our computers and our robots will be over a billion times more powerful than today ... literally ... What if Moore's Law doesn't hold true? Yeah, it's hold true over the last forty years, but there is no guarantee that it is going to hold true over the next twenty-five. What if it only goes one one-hundreth as fast? Well, that would mean that our computers and our robotics mere million times more powerful than today ... The kind of things we only use to talk about at Science Fiction conventions, like Comic-Con, need to be talked about by people like us here, and at the Pentagon. We are living through a robots revolution.

Recent history offers some compelling evidence for the reliability of Moore' Law. Unfortunately, spanning the entire history of human consciousness, there is scant evidence that our collective common sense or our collective conscience will increase in sufficient depth to keep up with the demands that have already long since overwhelmed their existing capacities.

So, lost in the Clouds, shrouded in the Fog of War, how far ahead of your next step are you able to peer?

Here is a summary of CyBlog posts from RSA Conference 2010, in chronological order:

RSA 2010: Lifestyle Hacking -- Notes on "Social Networks & Gen Y Meet Security & Privacy"

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism

RSA 2010: Merging Mind & Machine - Hacking the Neural Net

RSA 2010: Lost in the Cloud, & Shrounded in the Fog of War, How Far Beyond Your Next Step Are You Able to Peer into the Cyber Future?

See also RSA Conference 2009: Summary of Posts

Wednesday, March 3, 2010

RSA 2010: Merging Mind & Machine - Hacking the Neural Net


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

We are developing encyclopedia of the brain, neuron by neuron ... Dr. John P. Donoghue, Brown University

RSA 2010: Merging Mind & Machine - Hacking the Neural Net

By Richard Power


On Monday, at the I.S.S.A. CISO Executive Forum, I delivered the current iteration of my Executive Intelligence Briefing. I update it quarterly, and have delivered it in forty countries, over the last 15 years. The 2009-2010 theme is "Starting Over After A Lost Decade: In Search of A Bold New Vision of Security." The CISO Executive Forum presentation was the fifth time I have delivered this version.

In the current iteration, I continue to track the evolution of the five areas of concern that I started with: i.e., E-Commerce Crime, Information Age Espionage, Infrastructure Attacks, Personal Cyber Insecurity. But, in addition, I articulate five new areas of concern: IT supply chain insecurity, virtualization and the Cloud, Corporate Governance, Climate Change, Sustainability and Cyber Security, and Being and Consciousness in Cyberspace.

The last of these, "Being and Consciousness in Cyberspace" is an exploration of some philosophical issues from what "the Wisdom of Insecurity" and the theory of the "Biocentric Universe" can offer us in terms of perspective, to the existential implications and security consequences of the merging of human and cyber, a radical transformation which is happening at a far more accelerated pace than most of us realize.

At the ISSA CISO Executive Forum, as elsewhere, the responses registered in attendees range from bewilderment to a deep grokking.

So I smiled when I saw that at the last keynote session, at the end of the day on the second day of the RSA, featured Dr. John P. Donoghue, Director of Brown Institute for Brain Science, Brown University and his work on "connecting the internet to the brain," i.e., "hacking the neural net."

Why would we want a sensing neural interface system? Well, the principle answer (at this point in time) is to transform the lives of people paralyzed by disease or injury.

Five paralyzed people were implanted with BrainGate in a pilot project.

In his powerful presentation, Dr. Donoghue answered these questions:

Can motor intention activate neurons after long-standing paralysis? Yes.

What area of the brain? "Primary Motor Cortex/Arm."

What signals are there to read? "FP and Spikes."

How are these signals decoded? "Neural patterns in the Spikes become control signals."

Donoghue showed how researchers could listen to one brain cell of a patient, as the patient imagined opening a hand (active) and then closing a hand (silent).

What technologies are involved (and evolved) in this research?

Donoghue showed a video of a paralysis patient using the brain to move a computer cursor to open e-mail, & then draw a circle. He also showed a video of a paralysis patient controlling robotic "assistants."

The Brown Institute team is working on a version of BrainGate with wireless, fully implanted sensors.

Such neural output, it is projected, will be used not only to assist paralysis patients, but to replace the limbs, and even to restore movement in limbs.

Referencing TV Sci-Fi, Donoghue illustrated how BrainGate was now somewhere between technology imaged in Star Trek and technology imagined in Star Wars.

"Neurotechnology," Donoghue remarked, "is already here." He cited some examples: electronic stimulation used to "turn off" Parkinson's Disease, as well as bionic ears to restore hearing, and bionic eye to transmit some imagery to the brain.

BTW, I was inspired when Donoghue showed a slide juxtaposing an image of the human brain and with a mapping image of the internet, because my briefing starts with a slide juxtaposing images of the earth from space with a mapping image of the internet. Yes, I will soon be juxtaposing all three images in the next iteration of my briefing.

Now, we are getting somewhere ...

After Donoghue's dazzling presentation, he sat with Ari Juels of RSA Laboratories to answer some compelling questions.

Here is just a brief excerpt:

Ari Juels: BrainGate restores lost capabilities to patients who are suffering from a dysfunction, but as you have shown it is possible to control more than just artificial limbs, you showed, for instance, the ability to control a cursor. Can you envision a day when healthy patients have implants of this sort, to supplement their functionality in the world, implants that help people stick to their diets, or control devices for a third arm, or something along those lines?

Dr. John Donoghue: There are many people who think about these things, and who want to be able to extend their capabilities. This is a medical device. We are trying to develop something for individuals who have disabilities, to make their lives better. The biggest barrier is that this does require brain surgery. We don't take that lightly. It is something that always raises a concern. Where we go with this, and how we use it will require serious debate and discussion. But, as I said, I think the barrier will always be the surgical one. We will not in any cavalier way, implant able-bodied people to have frivolous functions. On the other hand, we have many things already available to us that are aids, we have smart phones that we carry around with us that are substitutes for our memories, we have many, many devices; so it would have to be clear that at some point we would outstrip all of the available external technology before we begin to think about enhancing ourselves by implanting something in the brain.

Juels: Have you in fact been approached by industries, or companies, or government agencies that are hoping to exploit BrainGate for purposes other than the strictly medical ones?

Donoghue: I would say "exploit." I mentioned this EEG-like signal that is available from outside your head. There are a lot of people interested in how much control can you get from that. It is, in fact, a very noisy and hard to manage signal. And it is not very reliable. There are a lot of people who are interested in seeing that signal be as good as the one that you can from inside your head ... One place where there is a lot of interest is in the toy industry ...

Well, I am going to leave it there.

There are profound implications for security and privacy.

First, the network perimeter vanished, as the internet popped up inside the enterprise, and vice-versa; and now, both the network and the internet are vanishing into the Cloud. What's next? Will Being and Consciousness vanish into the Cloud, or will the Cloud vanish into Being and Consciousness? The answer to that either/or question is, of course, a very Zen "Yes."

Stay tuned ...

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

NOTE: What do we mean by smart grid? Speaking on "Investing in Our Energy Future" at a Gridweek event on 9-21-09, Secretary of Energy (and Nobel prize winning physicist) Steven Chu offered a worthy definition: “Dynamic optimization of grid operations and resources. Incorporation of demand response and consumer participation.” (For your convenience, I have embedded Secretary Chu's full presentation at the end of this post.) Ah, but what about it's security?

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism

By Richard Power


The implementation of Smart Grid is in the vital national interest of the U.S., and all other industrial (and post-industrial) nations; it is vital both in terms of energy security and climate security, which, of course, means Smart Grid is also vital to economic security.

Any nation that wants to compete in the 21st Century needs Smart Grid. Indeed, any nation that wants to survive in the 21st Century needs Smart Grid.

In framing the issue for this RSA 2010 session on "Hacking the Smart Grid," Gib Sorebo of SAIC (one of CyLab corporate partner, BTW), cited several Smart Grid drivers, most notably, resiliency and reliability and reduction in carbon emissions, as well as several Smart Grid challenges, including the integration and distribution of renewables, the complexity of transmission networks, how to eventually provide infrastructure for electric vehicles (hopefully much sooner than later), and yes, what to do in regard to cyber security.

A smart grid, after all, is not necessarily a secure grid.

Smart grid is full of innovation, and it is being designed and implemented swiftly (or certainly should be), and innovation and urgency only tend to exacerbate security issues.

Furthermore, the issues swirling around the cyber security of power grids, whether legacy, smart or in transition, have shifted from the theoretical to the down and dirty. A decade or so ago, talking about attacks on the power grid were mostly speculative, but a decade ago, well, that was a century ago.

Some incidents have even ended up in the headlines:

In a rare public warning to the power and utility industry, a CIA analyst this week said cyber attackers have hacked into the computer systems of utility companies outside the United States and made demands, in at least one case causing a power outage that affected multiple cities. Washington Post, 1-19-08

A power failure has blacked out Brazil's two largest cities and other parts of Latin America's biggest country for more than two hours, leaving millions of people in the dark after a huge hydroelectric dam suddenly went offline. All of neighbouring Paraguay also lost power, but for only about 20 minutes ... The blackouts came three days after the CBS's 60 Minutes news programme in the US reported that several past Brazilian power outages were caused by hackers. Guardian, 11-11-09

So what is really happening in the space of Smart Grid cyber security?

The RSA 2010 panel Sorebo moderated consisted of Matthew Franz, Principle Security Consultant, SAIC, Matthew Carpenter, Senior Security Analyst, InGardians and Seth Bromberger, Information Systems Security Manager, PG&E.

For those of us who have firsthand knowledge of the decade-long struggle to promote critical infrastructure protection for existing systems, this few brief excerpt from their discussion offer a tantalizing, but humbling glimpse into this profoundly promising, yet clearly perilous undertaking glibly dubbed Smart Grid:

Seth Bromberger, PG&E: The research is being done on security in these components is not necessarily new. We are talking about encryption, key management, strong authentication. These are not new concepts. The devil is in the implementation. Where you have vendors, manufacturers and product developers taking short-cuts, or implementing poorly, that's where we are finding these vulnerabilities ...

Matthew Carpenter: We need pen-testing out of everybody. That doesn't mean everyone in the audience should go disassemble our firmware and look for buffer overflows. But there are so many different layers in this very complex system, and sometimes we just need critical thinking done about how we implement x, or whether this is a great feature to have. For instance, some utilities are thinking about having [an automated process by which] a person's credit report could impact whether or not that person can actually have power. This may not be the smartest choice to have automated throughout the system, without checks and balances in place. But it is actually something that has been pushed forward as a To-Do. So I can break into meters using this technology, but what about the guys who can influence credit reports? Or how about getting in between the communication of these credit reports? How can I manipulate the system? So we need everyone in the entire implementation of Smart Grid to be thinking critically about this could be abused. If I turn on this security protection, how could it be abused to cause more damage? How do I turn on anti-tampering technology in this device? OK, now what? So if I have anything higher than a 1.0 on some scale, I just shut down my entire neck of the woods? OK, maybe not the best bet. We need critical thinking done by everyone who has purview into the system, and good communication of "Well, maybe this isn't such a good idea." We need to open up that flow of communication.

Gib Sorebo, SAIC: For a long time, the [utility] industry has had a reputation of being tight-lipped about incidents, even about vulnerabilities that have been discovered (and, of course, it is not the only one). There have been a lot of bad feelings, recently, about some disclosures related to meters, people were branded not as terrorists, but it was almost that kind of thinking; in other words, "You guys are destroying the industry by revealing information about these vulnerabilities." And then we have the issue of everyone complaining that incidents are never reported to the regulators, or to the industry, or to whatever. Is there a middle ground? Obviously, we do not want to disclose vulnerabilities right away for an infrastructure that takes a long time to change, but where can we go with that?

Matthew Franz, SAIC: I am still kind of traumatized by my involvement with the disclosure of some SCADA vulnerabilities. Speaking of [being called] terrorists, I remember a utility software vendor that ... I gave a case study back in 2006 about some ... protocol vulnerabilities that I worked through the CERT process ... To paraphrase, what I was told was that by telling US CERT, i.e., giving them the details, and how to reproduce it, etc., and having US CERT release an advisory, we were arming the terrorists ... Just as a bell-weather of where we are I went to four or five of the leading meter AMI vendors this morning, and I looked for their /security site. The kind of site that Microsoft and Cisco and others have, in terms of how you go about reporting vulnerabilities, and only one of these meter vendors had the contact information, the GPG keys, etc., and that is the first step if that researcher wants to do the right thing, to get a hold of these vendors, and there is no way to do that ... The level of transparency you have is far less than Cisco or Microsoft ...

Matthew Carpenter, InGaurdians: We have to be more cautious than a Microsoft vulnerability disclosure. If you know me, you have probably heard me talk about responsible disclosure being a communication mechanism for vulnerabilities, but also a way to keep vendors in line. For IT, I think that makes a lot more sense. We have to be more cautious because of the impact in this arena. But we need to have fluid motion for our vulnerability research, we need to have a way to disclose to a vendor that there is an issue. We need to be able to have discourse throughout the utility space, so that effected customers have an early warning, "Hey, something's up, we've got a fix that's in the works, but just to give you some warning, when this comes out, you need to put it into test immediately, and in a certain amount of time, roll it out ... I remember hearing a vendor say, "Think about thirty days." I said, "That seems a little long, but if get a vulnerability notification, and within thirty days you have a fix out, well, you're better than Microsoft." But no, thirty days was actually the number to push out the patch from the time they clicked the button. "Whoa," I said, "we have some problems in our viewpoint into vulnerability handling." Disclosure needs mechanisms ...

Seth Bromberger, PG&E: You talked about making sure that the affected customers are made aware of the vulnerability. I am all for knowing ... The challenge that we have is that the lines dividing customers and non-customers are very blurry when it comes to things like critical infrastructure. I could see an argument that anyone who consumes power is a customer of the vendor whose control systems help deliver that power. From a utility perspective, I would say that the utilities are probably the customer base that the vendor would be beholden to. So when we talk about disclosing vulnerabilities ... to what end is the researcher disclosing, is it to feed ego? If so, that is probably not the most responsible way of doing it. Sending out on one of the public lists, information on a zero-day in a control system handling power or manufacturing is probably not the best way to people who are going to be impacted by it. And someone could argue that everyone is impacted by it, but I would challenge [by saying] that the average power consumer doesn't have any ability to effect the change and necessary remediation in those systems. So there are mechanisms the word to the right people, and again, I would say from my perspective, knowing about it is better than not knowing, so if the only way to get it out there is full disclosure, well, if it is actionable, I can take action, if I don't know about it, I can't do anything, and we can't pressure the vendors to fix it. But ultimately the utilities are in the position here of being the consumers of the product, and not necessarily the manufacturers of the product, and so the leverage we have is as a paying customer ... But it also puts us at a little bit of a disadvantage in that we need to be able to have the influence with our vendors to actually affect this change. We can't do it by ourselves.