Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Tuesday, August 21, 2012

Build a practical Cyber Security Intelligence- quick thought

Stuxnet, Guass, Flamer, other malicious codes and unknown malware attacking organizations of all types, some we knew about and some we do not. But who is the next organization.

Today where threats are more advanced and ahead of protection technologies and methodologies each organization has to build some kind of Cyber Security Intelligence capability to stop or at least detect (in near real time) advanced threats attacking the organization.
 
Building effective Cyber Security Intelligence, first organizations must have a working risk management process and once Cyber Security Intelligence is established then it must be integrated in the risk management process.

Risk management will help identifying the Cyber Security Intelligence framework that can meet your organization business requirements and protect valuable assets.

So what can a Cyber Security Intelligence framework consists of? The following lists the components of the framework; it is not a full list but can be used as starting point

1.      Establish security monitoring, alerting and reporting infrastructure.
2.      Establish a security analysis procedure.
3.      Establish non published cyber security information procedure
4.      Follow up latest security tools
5.      Follow up latest security news, alerts and analysis 
6.      Follow up linkedin groups either security or groups related to your business
    1. Information Security and Risk management experts
    2. Aurora Cyberconflict Research Group
    3. Information Security Community
    4. Information Security Network
    5. ISF - Information Security Forum
    6. Reverse Engineering and Malware Research
    7. Malware Analysis
7.      Build malware analyzing lab
8.      Follow up underground forums

Of course not the entire list is required based on your business type and requirements.
Also you may need to have basic knowledge of other languages such as Arabic, Chinese, Russian, Farsi and Hebrew.
I will keep the list updated and later will detail how to incorporate all the above components, others and risk management.

Tuesday, April 17, 2012

One Hour A Day Keeps Intrusions Away

In IT field, everyone is busy and forget about checking IT infrastructure security, by spending almost one hour daily, IT or security administrators will be able to prevent intrusions or at least detect them before it is too late.

All you need is to have reports generated from security tools in place for example antivirus, proxy, content filter, intrustion prevention systems, etc.. what about firewalls, if no log and reporting tool in place splunk (freeware) or OSSIM (opensource) can be used to generate required reports.

Addition to reports, you have to subscribe to one or more security alerts and news letters.

So how can we spend that hour daily ? simply the following can be done
  1. Based on Antivirus reports
    1. Review the top 5 infected computers
    2. Review the top 5 viruses infections
  2. Based IPS/IDS reports
    1. Review  IPS/IDS report top 5 source of attacks
    2. Review IPS/IDS REPORT top 5 targets of attacks
  3. Based on Proxy or content filtering reports
    1. Review top 5  visited web sites
    2. Review web links visited during non working hours or during week ends
    3. Review suspicious web links.
  4. Based on Firewall ports
    1. Review top 5 blocked ports
    2. Review top 5 blocked internal IP addresses
    3. Review accessed external ports (UDP/TCP)
  5. Search pastebin.com for posted information about your entity
  6. Search zon-h.org for unknown web defacement happened to your web server
  7. Review security news letters and alerts
Soon i will add more details about what to look for and how to identify possible or potentail intrusions or weaknesses.