Showing posts with label issa. Show all posts
Showing posts with label issa. Show all posts

Monday, November 25, 2013

Shhh Files, Security Hunters and Malware Writers, Oh My!

I attended Michael Gough and Ian Robertson’s training on Friday, entitled “From Joe to Pro – Finding Malware in Your Environment,” sponsored by our local ISSA Capital of Texas chapter, BSides Austin, Critical Start and SourceFire.  I know from previous software employers  who have paid ransoms that there are dirty secrets called Shhh! in security.  While it isn't publicized, companies pay handsome ransoms to prevent exploits found from being made public.  Government agencies do, too.  In the case of software companies, it’s self preservation.  In the case of government agencies, might be something tasty they want to let play out, for their own reasons.

First, accolades to Michael and Ian for their service to the security community.  They’re active in ISSA, InfraGard, ISACA and Bsides.  They take time out of their busy days to share security intelligence and their findings as security practitioners with the community.  Great blog about security hunters versus gatherers here http://hackerhurricane.blogspot.com/2013/11/like-natives-infosec-needs-to-become.html 
Caveat, IMHO: grassroots security training, effective patch management, compliance efforts and ongoing security monitoring using conventional means might be called “gathering” -  while not sexy, these measures can monitor or alert on  many security issues without drama.  That being said, compliance is, by its nature, not very effective against dynamically changing security attacks.

For sure, malware writers have the attacker’s advantage.  They have test labs equipped with available security software.  They are not inclined to release malware that won’t work against common countermeasures.  They choose when and where to release their malware.  Defenders are at a distinct disadvantage. 


The training was great, and enjoyed by a full house of security professionals!  One of the many perks of living in Austin is the community of security practitioners.

Thursday, November 7, 2013

Katie Moussouris - Mother of Microsoft Security Bounties - at ISSA Capital of Texas Chapter meeting


Katie Moussouris, Senior Security Strategist at the Microsoft Security Response Center, and Mother of Microsoft bounty programs, presented at our ISSA Capital of Texas Chapter meeting today.   Katie is refreshingly unabashed, putting a fresh new face and positive attitude on Microsoft and security.  She’s absolutely not a stodgy, arrogant guy in an ugly suit being indignant about being a target. It more looks like she is a part of the solution.

Quick version: Microsoft bounty programs are now paying real and significant dollars to ethical hackers who want to do the right thing, which is to use their talents to let the vendor fix security problems before criminals have the pleasure of exploiting them.  Katie described Black Market, Grey Market and White Market approaches.   Enlightened technology providers understand all three, and provide ways for smart hackers to “do the right thing.”  Microsoft is proving itself to be enlightened on this count, with this bounty program.  Good bounty programs scare out targeted attacks out faster, sparing law-abiding users from being hurt.

A few details:
  • Companies like Microsoft have target dominance.   If nobody cares about your company, you’re not a target.  If you are a market leading target, consider a bounty program.  Such a program will benefit your users in flushing out weaknesses and vulnerabilities before they can hurt your users.
  • Bounty programs will not tend to attract bad guys, because they know they will make more money with the Black Market.  Well of course.  However, most smart programmers are intrinsically good, wanting to solve problems and foil the bad guys – hence bounty programs are just good business.
  • Bounty programs can’t take the place of good security programming practices.  Sure, it’s great ad-hoc penetration testing, but it doesn’t take the place of investing in security.


All of that, plus Katie wore boots in Texas style!