Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

CRITICAL LOG REVIEW CHECKLIST FOR SECURITY INCIDENTS

This cheat sheet presents a checklist for reviewing critical logs when responding to a security incident. It can also be used for routine log review. To download it, click here:
http://www.securitywarriorconsulting.com/security-incident-log-review-checklist.pdf


General Approach
  • Identify which log sources and automated tools you can use during the analysis.
  • Copy log records to a single location where you will be able to review them.
  • Minimize “noise” by removing routine, repetitive log entries from view after confirming that they are benign.
  • Determine whether you can rely on logs’ time stamps; consider time zone differences.
  • Focus on recent changes, failures, errors, status changes, access and administration events, and other events unusual for your environment.
  • Go backwards in time from now to reconstruct actions after and before the incident.
  • Correlate activities across different logs to get a comprehensive picture.
  • Develop theories about what occurred; explore logs to confirm or disprove them.

Typical Log Locations
  • Linux OS and core applications: /var/log
  • Windows OS and core applications: Windows Event Log (Security, System, Application)
  • Network devices: usually logged via Syslog; some use proprietary locations and formats.
What to Look for on Linux
  • Successful user login- “Accepted password”, “Accepted publickey”, "session opened”
  • Failed user login- “authentication failure”, “failed password”
  • User log-off- “session closed”
  • User account change or deletion- “password changed”, “new user”, “delete user”
  • Sudo actions- “sudo: … COMMAND=…”, “FAILED su”
  • Service failure- “failed” or “failure”
What to Look for on Windows
Event IDs are listed below for Windows 2000/XP. For Vista/7 security event ID, add 4096 to the event ID.Most of the events below are in the Security log; many are only logged on the domain controller.
  • User logon/logoff events -Successful logon 528, 540; failed logon 529-537, 539; logoff 538, 551, etc
  • User account changes- Created 624; enabled 626; changed 642; disabled 629; deleted 630
  • Password changes- To self: 628; to others: 627
  • Service started or stopped- 7035, 7036, etc.
  • Object access denied (if auditing enabled)- 560, 567, etc
What to Look for on Network Devices
Look at both inbound and outbound activities. Examples below show log excerpts from Cisco ASA logs; other devices have similar functionality.
  • Traffic allowed on firewall- “Built … connection”, “access-list … permitted”
  • Traffic blocked on firewall- “access-list … denied”, “deny inbound”; “Deny … by”
  • Bytes transferred (large files?)- “Teardown TCP connection … duration … bytes …”
  • Bandwidth and protocol usage- “limit … exceeded”, “CPU utilization”
  • Detected attack activity- “attack from”
  • User account changes- “user added”, “user deleted”, “User priv level changed”
  • Administrator access- “AAA user …”, “User … locked out”, “login failed”
What to Look for on Web Servers
  • Excessive access attempts to non-existent files
  • Code (SQL, HTML) seen as part of the URL
  • Access to extensions you have not implemented
  • Web service stopped/started/failed messages
  • Access to “risky” pages that accept user input
  • Look at logs on all servers in the load balancer pool
  • Error code 200 on files that are not yours
  • Failed user authentication- Error code 401, 403
  • Invalid request- Error code 400
  • Internal server error- Error code 500 
Other Resources

How to choose your Information Security Training

In the past couple of years, the economy has struck hard on organizations seeking to educate their employees. Training budgets have been cut down, and choosing the right course that will give you real Return on Investment is not an easy job. This is especially true in the offensive InfoSec arena, where training standards and qualifications are weakly defined. So how can you make sure your getting your money’s worth ?
Welcome to our “10 questions you should be asking your InfoSec Training Provider“.

1. What are the objectives of the training ?

What will the training do for you ? Anyone promising you that you will be a “hardcore penetration tester” or a “security expert” after their 5 day class has never run a pentest, or otherwise has no clue what they are talking about. Learning *any* profession in 5 days is unrealistic, let alone one as complex as IT Security, or penetration testing. This is one of the first questions I ask before attending a training… its allows me to set my goals for the course and gives me a baseline for my expectations.

2. What topics does the course cover ?

Always read the syllabus of the course you want to attend, before you attend it.  Try finding other people who have taken the class, (if possible) and get their opinion. Try to see if the syllabus follows a reasonable methodology, or if it’s just a collection of topics. If you see a list of 1500 tools on the syllabus – expect to spend around 0.6 minutes per tool. 

3. Who is your trainer ?

Are they well known in their field ? Do they have training experience ? Are they involved in the security community ? Do they practice what they preach? Although these are 4 separate questions, they all relate to one thing – the ability of the trainer to provide the goods you paid so dearly for. Finding a GOOD InfoSec trainer is NOT easy. Most computer genii are usually lacking in their social skills – something a good trainer must have.

4. What previous reviews does the class have ?

Running a few internet searches for the name of your class, or the name of the trainer is a must. Find out what people have to say about their experiences – during and after the class. Although you can’t believe *everything* on the internet, taking an average of all the reviews will usually give you a solid idea of what you are getting into.

5. What is the ratio of students to trainers ?

How many students will there be in the class ? Some training providers cram more than 30 students in one class – often with a single instructor. During a 5 day period, a trainer can’t give personal attention to 30 people, no matter what. In general, smaller classes mean a more intimate environment, more attention from the trainer, and a more productive and engaging experience.

6. What is the ratio between theory and hands-on exercises ?

Remember the famous saying “In theory, there is no difference between theory and practice – But in practice, there is”. If you don’t exercise what you learn, you are less likely to retain or understand it as nothing replaces practical experience. Ask for a rough ratio estimate for “theory VS exercise” for your class – anything above 40% class-time spent on exercises is a good sign. Of course, this greatly depends on the quality of the exercises too.

7. How often is the course updated ? Is the material relevant to modern day situations ?

Learning methods and techniques on antiquated systems will bring you little benefit in the real world. Hacking a Windows 2000 SP4 machine with RCP DCOM doesn’t cut it any more. On the other hand, don’t expect to learn “Bypassing Windows 7 Stack Protection” in an introductory buffer overflows course. You need to gauge the balance between these two elements carefully.

8. What are the pre-requisites for the class ?

How should you prepare yourself for the class? Do you need to refresh your knowledge on certain topics? Nothing is more frustrating than coming to a class, and then lagging behind because you are not up to par with the class requirements. Not good for your learning experience, and not good for your self esteem – on the other hand “no pre-requisites required” might indicate lack of depth. If the pre-requisites were defined well by the training provider, it’s definitely a good resource to use to evaluate the relevancy of the course to you.

9. Is there a certification involved ? What is it’s value ?

The “value” of a certification can be measured in the real world using two main indicators:
  • The “market value” of the certification – how popular is this certification in the workforce ? Is the certificate recognized and appreciated by the industry ? And of course, will it help you get a (better) job ?
  • The “practical value” of the certification – or as Eddie Murphy would say “WHAT HAVE YOU DONE FOR ME LATELY?”.  What real world skills does the certificate prove? If it proves you can memorize 100 questions, you might not be up to the job when confronted with a real world scenario.

10. What post training benefits are provided?

What ongoing benefits will you get from the training provider, if any ? Is there a continuation path for the training ? Will the trainers be available for future questions or issues that may arise ? Is there a student community you can join, to discuss the course with other student ? Or in other words, what kind of “post customer service” can you expect ?
These 10 questions should cover all the important elements you should verify before committing your valuable time and limited training budget to any service provider. The average person only gets a limited number of training opportunities per year, therefore you should always maximize the return you receive.

Top 5 Security No Brainers for Businesses

Occasionally folks forget about covering the fundamentals of security and start off down a rabbit hole following some shiny new technology that turns out to be just a rat hole. With today's limited security budgets you need to be sure that you've adequately covered your highest risk areas before moving on to other things. The high-risk areas are, of course, not the same for everyone and will change on you fairly frequently. The bad guys are always mixing it up; the attacks we see prevalent today are not those that we saw just a few years ago. Thus the reason for this article, to take a look at the top 5 security solutions you can put in place today to cover the widest scope of current and emerging threats. In many respects these solutions are considered obvious "no brainers". But, you'd be surprised by how many companies (big and small) that don't have them in place. Many times it is the obvious that temporarily escapes us (or at least escapes those holding the purse strings ☺)
These 5 items working together will stop more cyber attacks on your data, network and users than any other 5 items in the marketplace today. There are lots of other very useful security solutions on the market but when it comes to picking the top five most effective and readily available ones here are my choices:
Firewall – The keystone of network defense for a decade or more is still required for solid foundational security. Its job is still fairly simplistic; control what data flows can go where. Without firewalls in place to drop unwanted flows, your job of protecting your assets increases exponentially. Firewalls need to be present at your external perimeters but also inside of your network for secure segmentation of data. Deploying firewalls internally is a relatively new best practice. It is largely driven by the dissolution of any sense of a tangible, reliable network border that can differentiate trusted network traffic from untrusted external network traffic anymore. Our nice clean Internet border of old just doesn't exist anymore in modern networks. What has also recently changed is that firewalls are getting smarter and more granular in there definition of data flows. It is now common for a firewall to be able to control a data flow based on the type of application or even application function it represents. For example, a firewall can block a SIP voice call based on what number was dialed.
Secure Router (FW, IPS, QoS, VPN) – Routers are everywhere in most networks. By tradition they have been used just as traffic cops for flows. But modern routers can do so much more than that! Routers are chock full of security features, sometimes even more so than a modern firewall. Most routers in the industry today are capable of robust firewalling features, some semblance of useful IDS/IPS functionality, robust quality of service and traffic management tools and of course strong Virtual Private Network data encryption features. The list doesn't stop there either. The power of modern routers to add to the security of your network is commonly overlooked today. With modern vpn technology it is fairly straight-forward to start encrypting all of the data crossing your WAN links, but very few people do so. It is also too atypical that folks use the firewall functions and IPS features in their routers. Turn 'em on and see your security posture improve!
Wireless WPA2 – This is the no-brainer of them all. If you aren't using WPA2 wireless security then stop what you are doing and form a plan to start doing so. Many other methods of wireless security are not secure and can be compromised in minutes. Don't make it easy for the bad guys, turn on WPA2 with AES encryption today.
Email Security – We all know email is currently the top attack vector used by black hats. Viruses, malware and worms all love to use email as their propagation method. Email is also the top way we loose most of our sensitive data. On top of the threats and data loss we experience through email we also have simple junk mail, spam. About 90% of all email sent today is spam! A good email security solution will get rid of the junk and filter out the malicious stuff as well. It is likely that if you are getting a lot of spam through your current system then you are getting even more malware through it. The thought process being that the spam features in email security gateways is usually the focus, core competency of the product. So if it is not doing its job dropping spam then it certainly isn't doing its job catching malware and data leakage.
Web Security – Threats coming from port 80 and 443 are rising faster than any other threat vector today. The expanding complexity of web based attacks necessitates that a company deploy a robust web security solution. Simple URL filtering has been with us for years and it is a core component to web security for sure. However, web security needs more than just URL filtering it needs AV scanning, malware scanning, IP reputation awareness, dynamic URL categorization techniques and Data leakage prevention functions. Attackers are compromising high profile sites at such an alarming rate that if we just relied on URL white list, black list filtering we'd have nothing left in the white list anymore! Any web security solution has to be able to dynamically scan web traffic to make a decision on its validity. Of all the solutions listed here, it is in web security where taking the risk of deploying a cutting edge, best of breed solution will pay of the most. The other solutions on the list are, for the most part established and mature. Web security solutions bells and whistles are coming out as fast as the hackers are building new attacks. Well ok, not quite that fast.
What are your thoughts on my choices for top 5 security no brainers? Think I got it wrong or right? If you had to add a sixth one what would it be?
If your company doesn't have all of these 5 in place today, go bang on some doors and raise the roof on awareness! Don't let it all burn!

The opinions and information presented here are my PERSONAL views and not those of my employer. I am in no way an official spokesperson for my employer.

Here’s what’s coming in Outpost 7.5


As promised in an earlier blog posting, we’re kicking off a series of posts about the upcoming Outpost 7.5. As with all previous and existing product lines, this release will include the all-in-one Outpost Security Suite Pro as well as the standalone Outpost Firewall Pro and Outpost Antivirus Pro, both offering subsets of the suite's functionality.

What follows covers new and improved functionality in the suite; if you have either Firewall Pro or Antivirus, it should be clear which updates will apply to your product. So without further ado, let’s dive into the most important changes planned for Outpost 7.5:

Updated anti-malware engine – version 5.2

Thanks to new management and storage methods for the signature databases, we’ve been able to reduce the anti-malware module’s memory usage by 50%. The updated anti-malware engine will deliver significantly-improved virus detection accuracy by grouping similar virus versions under a single signature.

Skyrocketed web content filtration

Our engineers have reworked the Web Control module to decrease resource load without impacting PC security. According to our internal research, HTML filtering is 50 times faster than in previous versions, ad-site filtering is 25 times faster, and spyware-site filtration is 50 to 100 times faster.

New! Outpost SmartDecision

A replacement for SmartAdvisor, Outpost SmartDecision rates every executable file against a number of criteria to determine its authenticity or potential for damage, using multi-level risk measurements. Using the results of this analysis, Outpost will give users visual guidance for further actions (allow or block).

SmartScan 4 / XAS technology

The 4th generation of SmartScan, code-named eXtended AttributeS (XAS), permits even faster caching of file and folder check information without affecting system performance.

Anti-Malware / eXtended Heuristic Analyzer

HAX now uses additional indicators and parameters for suspicious programs (the number of HAX signatures has grown by tens of times).

New! Clipboard and screen contents protection

There is a type of malware that aims to intercept personal data from the clipboard (so-called *clipboard-loggers*) or send randomly-taken screenshots to cyber-crooks (*screenloggers*). Outpost 7.5’s Clipboard content protection will prevent data leaks and inadvertent information disclosure by this type of malware during "copy" and "paste" operations.

Decreased memory usage

By consolidating the signature databases in user- and kernel-modes, Outpost 7.5 will reduce memory usage by 45 to 50 percent compared with Outpost 7.

PDF filtering

Outpost's PDF scanning module is now able to tackle non-standard and damaged files more effectively, and has cut down on false positives on PDF email attachments.

Full firewall compatibility with mobile broadband devices

Outpost’s firewall module now secures all traffic delivered through all known 3G modems.

Improved security for 64-bit platforms

Outpost 7.5 has been specifically redesigned to reflect improved performance and stability on 64-bit PCs.

The bottom line

Outpost 7.5 delivers high-speed performance in day-to-day web surfing and helps users make better security decisions. Outpost 7.5 provides fully-fledged network protection when using the latest broadband technologies and consistently strengthens proactive protection capabilities.

Stay tuned to learn more about the improvements and new functionality in our Outpost 7.5 series!
 
 
Blogger Templates