Monday, April 28, 2008

Configuring VPN as leased line backup

Q:
Hi every body
Can you help me in configuring a VPN.
The setup is like this my customer has a point to point lease line as a primary link going to head office using Router 1841 , OSPF is running on this segment
, he has a ASA 5510 behind the the router , from ASA he has a ADSL modem directly connected
Now , what he wants to achieve is once the primary link (lease line) goes down , traffic start going out ffrom the ADSL link through a VPN tunnel.
Keep in mind on the Head Office he is running with Juniper Products.
Do you have any idea how it will be achieved.
I will really appreciate your quick response.



A:
Hi ...,
We deploy similar IPSEC VPNs over Internet links for high availability requirements. I call this MPLS Plan B... (In your case Leased Line Plan B :)

Here is my understanding of your setup:
Remote Office: Cisco ASA connected to Internet, Cisco 1841 connected to leased line
Headend: Juniper firewall connected to Internet, Some Cisco hardware connected to leased line
Internal Routing: OSPF


What you need is to extend dynamic routing (in your setup OSPF) to Cisco ASA and the Juniper appliances. Make sure that both ASA and the Juniper appliances participate in the OSPF. First build the IPSEC tunnel between the remote site ASA 5510 and the headend Juniper. Firewalls will route traffic to IPSEC tunnel interfaces as a by product of OSPF routing decision.

An important catch is the validation of the cost of Internet links for OSPF. Internet OSPF cost must be higher than the leased line cost, this will assure that leased line will stay as the primary link. Increase costs manually if that is not the case.

Inter-product IPSEC tunnels (in this case ASA to Juniper) can be tricky I do recommend a lab proof of concept before production cutover.

Another way of building Internet failover is to use GRE tunnels between internal Cisco hardware, so that you can bypass the Juniper headend firewall integration for routing (All you will need is a simple IPSEC VPN between ASA and the Juniper that allows GRE traffic between internal Cisco routers) . I prefer the first option.

cheers,
- yinal

Sunday, April 20, 2008

End Point device security is becoming a major issue?

Q: Hi, End Point device security is becoming a major issue. Devices like IPODS, Mobile's etc. are a threat to Data Security in Organizations. Any of us are facing such challenges in their organizations?

A: Hi .....,
Here are 3 basic approaches:
1- Cut the cord – do not allow transfer of any data to mobile devices, this option assures security but it is not a mature solution on the user side. We all agree that mobile devices are business enablers
2- Control/Manage End Points – You need to manage all these end points as a part of your enterprise operation. Security on the endpoints is no more different than any other enterprise components but it is more difficult since the resources are much more limited (you cannot have 20 applications running on Nokia phones or you cannot manage iPods centrally. You can start with the following list – single client is preferred:
- Port Control (USB, CD, Floppy, Bluetooth, IR, Wi-Fi, Ethernet etc)
- Location awareness
- Encryption (file, disk, mail), key/cert management
- Firewall
- IPS
- Antivirus (http and SMTP)
- Antispam, Phishing, Malware control (http, SMTP, SMS)
- URL filtering
- Application control, and tripwire type change control
- Remote device management (in a secure manner :)
- Biometrics/TPM/SSO/802.1x support
- Easy to scale on multiplatform esp. on mobile
3- Control Data- Instead of focusing on the device level security, you may focus on data security. You can shift from the logical controls to data level security controls. If the data in the organization is classified by security requirements and protected accordingly, the devices will naturally comply with the higher plan. For the critical data I do recommend checking the enterprise rights management systems (a.k.a. DRM). Once your data is protected by enterprise rights management (ERM) or Information Rights Management (IRM) , it will be protected on the endpoint devices as well. Deploying ERM is the challenge. You may start googling with the following keywords; EMC (Authentica), Oracle (SealedMedia), IBM or Microsoft RMS or choose dedicated shops like InstaSecure Modevity or Liquid Machines. I hear a lot of activity around Liquid Machines.

Let me know if you have a specific question on the topics above,
cheers,
- yinal

Tuesday, April 1, 2008

How much can "fear" be used ethically in selling a computer & network security solution?

Hi ...,
I have worked on both buy and the sell sides of the enterprise security space for years.

Fear is not a wrong feeling, but lying is a wrong unethical, immoral act.

The ethics; encompassing right conduct during the information security sales cycle is not unique to information security; it is based on the same ground principles of business ethics.

A sales person should be telling the truth. FUD selling is as unethical as selling unreal hope or misusing trust. FUD is discussed more because buyer side falls into the lies easier.

Fear, is a lifesaver when it is sensed in the right time in the right amount.
Fear can be classified as an instinct instead of an emotion.

If a tire sales person tells me that my car may have a serious accident because I have old tires, and it is the truth, I may owe him my life, there is nothing wrong with the fear there.
But if the same tire sales person tells me that my car may have a serious accident because I have old tires, and whatever he tells me is an is actually an empty ungrounded sales pitch, fear is the tool of sales. It is wrong.


That is the ethics line between the evil and the good. On my personal life I only relay fear where I have fear, where I share the same concerns with the person I am talking with. Risks can only determined from facts, not hearsay or imaginary sources, so my personal fears can be far way from reality for the person I am communicating with. A disclaimer of the facts when discussing the fearful topics can be a good ethical start for the sales side.

I can give more real life examples if you need any,
Let me know if you have any questions,
Regards,
- yinal ozkan

Sunday, March 23, 2008

Managed Security Services Providers and the BPO / ITO Providers

If you follow the managed security services providers (MSSP), you will notice a significant shift in the definition of outsourcing. Usually most of the MSSPs are aiming to manage the customer premises equipment with sophisticated remote management, and central log correlation tools. The manpower required to execute this operation is different from the BPO providers or even Managed Service Providers, just a handful Security Operation Centers (SOCs) and a 24x7 full escalation engineering shift is good enough to kick start an MSSP operation.

The difficulty in managing customer owned security devices derives from multiple sources, but if you exclude the technological challenges (like development, capacity, infrastructure, tools) the main roadblock for the newcomers is “Trust”

Giving up security, the keys to the kingdom is not easy, especially to an operation center that is connected via cross-oceanic fiber cable. All early players in the market played the “local” hand to gain the trust of the potential clients. In a post 9/11 world, relying on the 3rd party for all information security operation required different assurances. Large corporations chose different paths:

1- Choosing their trusted telecom company to provide managed security services instead of their core BPO partner
2- Choosing , monitor-only services from BPOs and limiting the scope to view and alert type of passive access instead of full security operation management
3- Trusting on a local specialized MSSP instead of a low-cost overseas shop

If we look at the MSSP market today, the decision tree above is very visible in the developed markets for managed services. Telecoms are eager to acquire any MSSP that can bring them the services recurring services revenue, and higher services margins. In the last 2-3 years, BT, Verizon, France Telecom NTT, KPN they all acquired some sort of managed security services providers to compete in the global market. The other global/local telecom chose to develop their own services. (e.g. AT&T, DT) Either way telecoms see MSSP market as their own managed CPE market.

On the second category, a lot of large outsourcing contracts came with security monitoring that pushed BPO providers to build impressive monitoring / log correlation operation centers. But large corporations usually kept the internal security team intact to manage the security infrastructure.

The last category of specialized MSSPs grew significantly with the demand. The interesting part is that none of the global players were from the outsourcing world Verisign, Symantec, Integralis, ISS, SecureWorks, Perimeter, RedSiren, Counterpane, NetSec, CyberTrust, Ubizen etc, none of the specialists belonged to a BPO provider. Most the specialized MSSP companies listed were acquired by the telecoms by the way.

So the question lies in “what will happen next?” Will the telecoms finally figure out the magic of delivering services, or will they prove yet another failure in investment. It is very difficult for a telecom company deliver a highly customized service, on the other hand cookie-cutter, managed router, managed MPLS type of boxed solutions do not play well in managed security services..

Of course there are alternatives like IBM acquiring ISS, Microsoft acquiring FrontBridge, Google acquiring Postini, and finally Dell acquiring SilverTech. But with the exception of IBM, in-the-cloud on-demand managed security services form a different category than the outsourcing complete operation, or the managed CPE.

I see a lot of leverage where large scale managed services shops (MSPs) to engage specialized MSSPs to build a hybrid best of both worlds model. At the end of the day it is very difficult to draw a demarcation line for managed security. If the desktops and the servers are a part of grand information security plan, an MSP should play well with the information security management provider; trusted MSSPs will also bring security credibility to MSPs. On the other hand MSSPs will be able to tap 500+ large MSP operation centers, and they will be able to deliver direct end-user security support for the first time. Segregation of duties will automatically be delivered in the meantime.

Time will show, which path will dominate the market.
On personal behalf,
- yinal ozkan

Saturday, March 15, 2008

What are the business drivers that lead to Infrastructure Management Outsourcing?

Q: What are the business drivers that lead to Infrastructure Management Outsourcing? What are some of the most pressing needs/challenges that an organisation wants to overcome through IM outsourcing.
Clarification :Other than cost arbritrage, what are the primary business goals.

A: Hi …….,
I have been working on information security infrastructure management outsourcing area for a considerable time. As listed above, there are several business drivers that lead to these projects. Here is my classification:

1- Efficiency: If somebody else can manage your infrastructure in a more efficient way that your internal team, then you should consider a third party

2- Cost Cutting: Who does not like to spend less for the same deliverable? Even in the cases where the efficiency and risk levels are not better with the third party, decision is obvious when you can cut costs considerably.

3- Competitivenes: Time to market, beating your competitors, innovation capability, intraindustrial integration, financial capability, are good concepts and the good business drivers. If your infrastructure is managed by a third-party, and the third party makes you agile, it is time to outsource.

4- Risk: Risk always matters. Ignoring risk is not bliss. Covering the bases sometimes involves a professional third party. Lowering risk can be measured quickly and can be listed as business driver.

All these 4 drivers involve each other when thoroughly, but classification helps better identification.

If you have specific questions about any category related with examples, please let me know,

Regards,
- yinal ozkan

Monday, February 18, 2008

Enterprise File Transfer Solutions

Q:
Enterprise File Transfer Solutions
I am researching Best Practices surrounding File transfer between business partners. The solution must be able to integrate with various back-end systems and offer Internet facing FTP, SFTP and FTP-SSL.
I have identified the following requirements:
The solution must offer automated encryption/decryption via PGP.
The solution must be able to route the information received to its' final destination.
No data may be unencrypted within the DMZ
(must be encrypted before being sent or decrypted after being moved internally)
Clarification
The PGP requirement is due to legacy considerations. All our current transfers are encrypted using PGP. Would entertain other encryption mechanisms... but PGP suport provides the most effective migration strategy.


A:
Hi …..,
Best practices are the least headaches on the operation side :) (not necessarily on the security side). Best practices are usually determined by the resources and the flexibility of your operations

You need a solution that is both transparent to existing operations while satisfying security and regulation requirements. That is a double edged sword.

If you have in house developers, the most customized way is to use "PGP Command Line" series of products. This is very flexible since it works on all platforms...

SCP, SSL, SSH and SFTP are usually not the full answer set since they encrypt "data in transit" do not answer the "data at rest" questions. I like certificate based encryption solutions but that is far away from PGP keys.

When using a key based solution, the ugly part is the automated key management with remote 3rd parties. You can use a trusted directory like PGP global directory for this purpose.

When you do not have flexibility to touch anything on the servers and the host then there are gateway products:

Sterling Commerce, and Globalscape are referenced above.

You can also check Forum Systems' Presidio OpenPGP security gateway…

Tumbleweed SecureTransport is the other gateway that is used by financial services.

And there is PGP Universal Gateway.

There are several other “store and forward” / “message both parties” secure enterprise data transfer solutions, you can check Ironport (Post x), SecureComputing (Ciphertrust), Zix, Voltage, Entrust and Accelion web sites for different solution sets.

Let me know if you have a specific question,
Regards,
- yinal ozkan

Monday, February 11, 2008

Information Security Statistics

"Statistics are like a bikini. What they reveal is suggestive, but what they conceal is vital."

Recently a colleague of mine recommended me to use statistics on my presentations.. When I see a bunch of numbers, pie charts and the percents signs on the screen, I get back to dot.com hey days… By 2008 we will see a world domination in…..

Statistics are only useful when they are generated according to statistical reality.A complete statistics survey result must contain links for methodological details including population coverage,. sample design, sample size and several other quality indicators .(for those who are wondering the source of the FUD).

In information security world, I see statistics in like “according to xxx institute 60% of the US businesses had been hacked last year so that you have to buy our product”. I have been expecting this cheap FUD to be over for so long, but no, it keeps coming back..
Well, as the smart audience you should ask, what do you mean by hacking, how did you question the respondents, what’s their role, what do they do, who do they work with etc.. You will end up with 300 respondents telling you the fate of the information security industry…By the way. I usually end up believing these numbers since the survey respondent (supposedly CISOs) had nothing else to do but answering these valuable surveys so that they form a lucky set of “60% hacked US operations”..

Tuesday, February 5, 2008

Vulnerability Assessment Vendors

Q: Do you have any recommendations for the Vulnerability Assessment Vendors / Products / Services?

A: Hi ...,
My recommendations will not be neutral (since I did not evaluate all vendors), but I might help you to identify the better Vendors/Products/Services.

There are so many options maybe that is why recommendations matter. Here is my quick dirty list:

Option 1: You can go to a security consultancy shop and ask for vulnerability assessment service.
All accounting firms and IT consultancy shops will offer something. (PWC, Deloitte & Touché, Ernst & Young, KPMG, Grant Thornton LLP, or BDO)...There are risk management companies like Protiviti who can also offer high end assessment services.

As expected the bodyshops with security practices like CSC and IBM offer the vulnerability assessment services along with the Telcos (Verizon, AT&T etc)

And of course all security integrators offer the service

My quick qualification criteria would be:
1- See the actual resumes of the consultants who will perform your scan, buy consultants not the brand. If possible interview consultants.
2- Check methodology documents from the consultancy shop; make sure that the structure is detailed enough for your requirements. You may also check with frameworks like OSSTMM, OWASP etc
3- Check previous deliverable document (sanitized versions)
4- Check references

Option 2: Using regular vulnerability scanner products in a box : You can start with free Nessus and go all the way with Tenable, NCircle, ISS, Foundstone (McAfee), eEye, Saint etc..
These products require your internal resources but you have the option to automate scheduled or event driven scans.

My quick check list would be:
1- Research arm depth of the vendor, are they using public data or actual vulnerability research information
2- Open source integration, ability to support custom signatures, 3rd party signatures
3- Integration with other enterprise tools, esp. with IPS, SIEM, GRC and help desk systems
4- Easy to use, easy to configure , support for dist. Deployment
5- Ability to understand network topology, (hosts behind firewall, hosts that are not routable or hosts that have host firewall etc)
6- Non-intrusive
7- Speed – Must be fast to scan a large quantity of hosts in a limited time frame


Option 3: Find an in the cloud service offering from product companies or specialists like Outpost24, Qualys (Vulnerability scanner-as-a-service or On-demand vulnerability scanning)., or managed security services providers (MSSPs). Payment card industry approved scanner services (ASVs) may give you good start for the list of service providers
https://www.pcisecuritystandards.org/pdfs/asv_report.html
Lately all product vendors joined the long list of on-demand remote scanning providers

When buying a service make sure that you check both option 1 and option 2 checklists , you need the both. It is also important to see how can a remote scanner company will scan your internal systems, they need a device at your premises (CPE) which should not require a lot of attention firewall configuration etc.. I have also seen that self-service providers should have state of the art portal interfaces to manage your scans. Test portals before moving forward.

Option 4: Specialty Scanners.. So far I have talked about regular network scanners. If you are planning to scan a web application, a database or an enterprise application with XML transactions, you should check different vendors/consultants/services. The criteria are a little bit different, Deep levels of application know-how is a must. There are also a couple of pen test tools in the market (e.g. core impact)

I strongly recommend going over the following ppt to find out what is out there:
http://www.owasp.org/images/f/ff/AppSec2005DC-Arian_Evans_Tools-Taxonomy.ppt



Well still no recommendation , but please let me know if you have any specific questions,

Regards,
- yinal ozkan