2007-07-31

Been a while

Well, it's definitely been a while since I posted or even looked at my blog. since my last post I have changed jobs twice and I'm not even doing security work at this time. Unfortunately, I allowed the game World of Warcraft to completely ruin my learning experience in security. Instead of focusing on learning and working I was more concerned about getting to level 60 at the time and then level 70. Now that I've burned myself out playing the game I have nothing to show for it but a piece of paper that says I'm a CISSP. Right now I'm a business analyst or something like that for a small company based out of Tampa, FL. I work out of the house now with is nice, but I'm going to lose my security clearance next year because I'm not using it anymore.

I miss the security work, but I came to realize that IT people and company leaders could give two shits about security. Security folks are just a necessary evil for them to deal with and they loath our existence. For IT admins, we cause more work for them and get them in trouble after our scans reveal missing patches and rigged security risk configurations. Executives believe we just burn money and provide no real value to the business. What's a brutha gonna do?

Right now I hate my job, but it pays the bills and hopefully will pay off since I was sold on the idea of retiring early if I came on board. We'll see if I should have listened to my instinct and stayed a worker bee.

2005-05-06

Moving on to blue pastures

Today I was offered a position on the "Blue Team" with my current employer. I interviewed for the position last Tuesday and did not expect a decision until next week. The method used for informing was quite comical. My company had a site meeting with all employees assigned to our remote office present. After eating lunch, the site director talks about current and future events. She started talking about moving around within the company and said "For example, we just had a member from AS&W move to the Blue Team, John Collins."

Immediately, I felt dozens of sets of eyes staring at me because only about 10 people knew, and I wasn't one of them. Everyone from my current office, AS&W, started whispering to each other like someone just pulled their pants down. I just keep looking at the director and kept a straight face like I knew already!

After the meeting was over, everyone really got a kick out of me finding out when they did. My division chief apologized but thought it was pretty funny too.

So, what does the Blue Team do? There isn't a lot of documentation on the Internet about it, but they are responsible for vulnerability assessments for an organization. The Red Team, aka penetration testing, is more widely known and they follow up the Blue Team's finding to see if the target organization repaired the vulnerabilities.

My goal is become a Red Team member, but I have to pay my dues and learn some programming and scripting in the meantime. The traveling is pretty grueling but the pay is very good. I guess there is trade off with everything. Once I get started I'll definitely let everyone know how it is.

OUT

2005-04-30

CISSP

I recently attended the Intense School CISSP Boot Camp. The course was very good and the instructor, Dave Bonewell, was excellent. Dave cut through all the granular info found in the ISC2 yellow book and gave us the meat. I think the best part of the course was Dave's knowledge of how the test is written. Dave knows the lead psychometrician for development of CISSP examinations. This inside knowledge allows Dave to convey test writing characteristics, which is very useful.

There are seven different versions of the CISSP examination. One of the versions could be viewed as more difficult than other versions. However, the questions are worth more, therefore allowing a candidate to miss more questions. I have no doubt that I received this version because it was ridiculously hard. I thought maybe it was just me, but a lot of the questions didn't even make sense. The test proctor briefed before the exam started that we could get a comment card for questions we thought were invalid. I could have filled out 200 of those cards for the test I took!

Based on what has been written so far, it probably sounds like excuses for not passing. The fact is I did pass the exam. Was it divine intervention, probably. There is no doubt the information which the test is based on is very useful and pertinent information. The test however is absurd. I think it takes more luck than smarts to pass the test. I believe I’m a good test taker, which probably helped with my passing score. Dave stressed the point of not going back and changing answers or spending to much time on any question. I have a history of going back to change answers, but this time I heeded his advise. It took me 2 hours and 50 minutes to complete the exam. I immediately called over a test proctor and had them take the test off my hands before I did something crazy. I couldn’t imagine sitting in that room for six hours. I believe I was the first CISSP examinee done. It was quite humorous to see all of my Intense School classmates, who were taking the exam, look at me like I was crazy for finishing so fast.

The best advice I can give for the exam is the following:

  1. Attend a Dave Bonewell lead class from Intense School. His pass rate is over 90%.
  2. Study every night for a couple of hours after class. I didn’t attend any of the group study sessions because people just argue about practice questions from www.cccure.org
  3. Hit the highlighted notes the day before the exam.
  4. Take a break from studying the night before you take the exam. Go to a movie, a bar, or to church and pray!
  5. Read each question fully. Understand what they are asking.
  6. Read all the answers and give the BEST answer.
  7. Don’t spend too much time analyzing questions. You will start talking yourself out of the right answer!
  8. DO NOT GO BACK AND CHANGE ANSWERS.
  9. Don’t worry about consecutive questions having the same answer. It is a trick designed to confuse you.
  10. Take some ear plugs to the exam. People around you will drive you nuts with their idiosyncrasies like coughing, sucking air through the snot in their noses, tapping pencils, whispering profanities at the test, etc.
  11. Eat breakfast before the exam.

Good luck to all you future test takers. If you are looking for technical expertise, don’t bother with the CISSP. It is definitely a management certification. Go with Richard Bejtlich’s training or the SANS track.

2005-04-05

immixTechnology Cybersecurity Imperatives

I attended the immixTechnology Cybersecurity Imperatives for Federal Agencies today. It was a marketing show, as usually, but Bill Nugent from Mitre Corporation was quite entertaining. I also received an autographed copy of his book, No Outward Sign. The conference didn't convey any new ideas or groundbreaking news. The speakers talked about current threats, correlating data, IPS implementation, etc. Dr. WeiXiong Ho from SBC was so hard to understand, I totally missed out on his presentation, as did everyone else in the room. Sorry Doc, but it was bad.

Sourcefire had some really cool pink pens with the plastic outline of a pig at the top. Of course I got it for my wife because I wouldn't be caught with a pink pen!

Out

2005-03-31

Network Magazine RNA Review

I received the latest edition of Network Magazine (NM) in the mail yesterday. There is a review article on the Sourcefire RNA. My shop has one RNA device for testing purposes and a couple of coworkers and I recently visited Sourcefire in Tysons Corner to get a more in depth look at RNA and the new Defense Center (DC).

The NM article seems fair and balanced with highlights of both the good aspects and weaknesses of the RNA tool. What I found to be of most interest is RNA will accept input from ISS and Cisco events by end of 2005. This is a very good move by Sourcefire to accept event feeds from vendors other than Sourcefire. ISS is widely used, although it seems to be losing some big customers, and Sourcefire's initiative to incorporate ISS events will be a huge benefit.

Hopefully, Sourcefire can iron out the issues with the RNA's vulnerability alerts by going to an aggresive scanning method. Who cares if it touches the nodes on your network, because after all, it is your network! Another item of interest to me was the mention of ArcSight as an event correlator that accepts RNA output.

2005-03-22

ISS State of Security Seminar

Today, a couple of co-workers and I attended the ISS State of Security Seminar at the Ritz-Carlton in McLean, VA. What a waste of time! The best part was actually being in a Ritz-Carlton and eating the wonderful breakfast.

The seminar was suppose to cover the ever-changing hacker community, which it didn't tell us anything we didn't already know. It was more of a marketing and sales pitch. I guess since ISS is the largest IDS vendor in the world, they can afford to splurge on locations like the Ritz and serve breakfast for approx. 100 people. I look at from the point of view that you will pay for the breakfast in the long run, if you haven't already!

Patrick Gray was the first speaker and he is the director of X-Force operations for the office of the CTO at ISS. This guy was pretty entertaining, but didn't really say anything that blew my skirt up. He talked alot about his career in the FBI and "morons" he had help prosecute. His most interesting statement was linking organized crime to cyber crimes here in the US. I guess ISS believes this will be a huge problem in the future, very similar to the problem in Russia.

The next speaker was Scott Paisley, who is the TD of America for ISS. His whole speech was pretty much an add campaign. He spoke at length about the ISS X-force. Sounds like their main problem is finding morally sound individuals to work on "The Force". They have alot of applicants who are technically proficient, but can't pass the dreaded ISS background investigation. I wouldn't mind working on the X-force, but I can't even write a program that echos "Hello World"!

Something I thought was interesting is the ISS AlertCON tool on their website. This similar to the Homeland Security Threat Advisory system. What I think is interesting is their alert "forecast". This isn't the freakin' weather! I guess they believe their infinite insight into the hacker community allows them to perform a predictive analysis of what is coming down the pipe. Sounds more like blowing smoke up their customers, well you know. I'm sure their disclaimer statement relieves ISS of any responsibility for "forecasting" the future cyber threat level. I'm not a lawyer and would rather read an RFC while doped up on Dramamine than read ISS' disclaimer statements.

I will be attending the Cybersecurity Imperatives for Federal Agencies on April 5th. I believe this may provide much better information because of its vendor transparent atmosphere. I hope. I know it is sponsored by Sourcefire, Intellitactics, and Intelliden, but the guest speakers are from various companies and these type of events usually allow for more broad discussion and information sharing.


New Posting Rule to Avoid Termination

A serious topic has come to my attention and I should have seen this before I started my blog. It concerns employees being terminated for their comments on personal web logs. Case and point is the Delta Airlines stewardess who was terminated for her blog comments. I have removed all occurences of my employer's name from my site and profile. Recent court rulings involving Apple Computers initially brought this subject to my attention.

2005-03-19

Meeting with Sourcefire

Myself and four co-workers met with Tony Leona and a systems engineer named Rich from Sourcefire today at their satellite office in Tyson's Corner. First, I couldn't work on the 14th floor of a building like that because I would be staring out the window all day. What a view!

Second, you guys in the corporate world have it made. Nice and clean buildings with little deli's in the building. A lot of times the federal government is like, well, Uncle Buck. You don't like his accomodations but hey, he pays the bills.

Anyway, the purpose of our visit was to learn more about Sourcefire's Defense Center appliance and what it provides with data feeds from the RNA and IDS appliances. With the infatuation with ArcSight at this time, there didn't seem to be alot to gain from adding this device. However, the impact field could be useful to identify holes in the perimeter if and only if the RNA is able to "see" nodes correctly. We didn't know the RNA is sold on a "by node" basis, meaning you purchase a license for say, 10,000 nodes discovered on your network. $mart, very $mart. An added bonus is the Visualizer 3-D analyzer which is free for as many workstations as you want.

I was more interested in hearing about the IPS capability of the Sourcefire IDS 1000, which we already have (just one though for lab testing). To my suprise, the appliance is IPS capable and needs only a $300 fail open card. We will definitely pursue this and test the 1000's ability to mitigate.

With ISS RealSecure failing from grace rapidly, I think the Sourcefire Defense Center (DC) package provides an excellent alternative. A key feature is the DC's ability to push out policies and rules to Sourcefire sensors. Obviously, Sourcefire only offers the convienience of pushing updates to Sourcefire sensors, but I can't blame them for basic business tactics. The DC also allows SSL connections from any host added to its ACL. This is similar to a Niksun NetDetector, which I've had experience with. I'm sure other devices offer this, but I'm not familiar with them (remember I'm new to this field!).

You can read more about Sourcefire products and case studies by downloading some white papers from their Resource page.

NTR