Wednesday, June 1, 2011

And The Hits Keep Coming

skunkIn case you missed this over the long weekend, a few more notable names were compromised in recent weeks.  A few weeks ago I wrote about how the Big Attacks are Back and it sure seems like the hits keep coming.  First, last Friday, Lockheed Martin said that earlier in the week, they detected that someone was trying to break into their network through the VPN.  Lockheed is a huge military contractor providing fighter jets, spy satellites and other military and intelligence equipment for the US and other government entities.  They are also known for Skunk Works or their Advanced Development Program projects.  These are highly classified assignments with the SR-71 Blackbird and F-117 Nighthawk (Stealth) as examples over the years.  I live very close the Skunk Works facility and I can say that I’ve seen some interesting craft flying over at various times. 

Anyway, there is some indication that this attempted breach is tied to the security tokens issued to the workers.  Reports have indicated that it was RSA tokens and this incident might be directly tied to the RSA breach earlier this year.  Lockheed quickly shut the remote access doors and issued new tokens and passwords to the entire workforce.  They do say that their systems are secure and nothing notable, like customer/employee/program data, was taken.  While defense contractors like Lockheed get probed daily, this is significant since the ‘sources’ are saying that there is a connection between the RSA breach and Lockheed’s.  The intruder seemed to have knowledge of some critical information (possibly algorithm, seed, serial, cloned soft key, key gen time) for the current tokens and dropped a key logger on an internal computer.  After RSA’s initial announcement, Lockheed did take additional protective measures, like an additional password for remote users but a key logger probably would have sniffed that.  Lockheed was fortunate to have caught it quickly but this might be the beginning of the token breach fallout.

Lockheed is not the only defense contractor that has been specifically targeted using compromised tokens .  L-3 Communications has also been fending off penetration attempts according to reports.  In both cases, it appears that the intruders are using both phishing and cloned soft keys to try to attack SecurID systems.  Installed malware or phishing campaigns are being used in an attempt to link end-users with tokens.  Many companies are increasing PIN lengths and lowering the number of failed attempts before accounts are locked out.  Even McAfee is talking about how employees are being approached by strangers in public places looking to gain information. 

Another breach this past weekend involved PBS.  This time, C is for Compromise…and not good enough for anyone.  While, according to PBS, no internal networks were exposed, the malicious hackers were able to break into the website and posted a bogus story about Tupac being alive and well in New Zealand.  They also posted credentials for PBS’s internal media and affiliate station portals.  This was a response to a Frontline story about WikiLeaks called WikiSecrets.  Apparently the group that claimed the attack was less than impressed by the program.

2011 started out *relatively* quiet but is now tuning into a banner year for breaches.

ps

Resources:

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, securID, cyber-threat, social engineering, attacks, virus, vulnerability, web, internet, cybercrime, identity theft, scam, data breach, rsa, lockheed, pbs

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, May 25, 2011

Audio White Paper - Application and Data Security with F5 BIG-IP ASM and Oracle Database Firewall

Organizations need an end-to-end web application and database security solution to protect data, customers, and their businesses. The integrated solution from F5 and Oracle provides improved protection against SQL injection attacks and correlated reporting for richer contextual information.  F5 and Oracle have partnered to offer enhanced security for web-based database applications. The integration between F5 BIG-IP® Application Security Manager (ASM) and Oracle Database Firewall provides richer forensic information about SQL injection attacks through correlated reporting.  Running Time: 17:54  Read full white paper here.  And click here for more F5 Audio.


ps

Technorati Tags: F5, integration, data center, Pete Silva, security, business, education, technology, application delivery, data replication, cloud, oracle, database firewall, web, internet, security, hardware, audio, whitepaper, big-ip

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1] o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Interop 2011 - TMCNet Interview

Thursday, May 19, 2011

It’s Show Time

Ladies and gentleman.  In tonight’s show the role of Application Delivery, normally played by Load Balancer will be replaced by ADC.  We hope you enjoy the performance. 

I studied Theatre in college and have spent a good amount of time in and around the performing arts.  The telling of a engaging story and the creativity, imagination and spontaneity of a great live performance is something I truly enjoy.  Most of my life, when I think of the term performance, I think of the performing arts – acting, dancing, singing and the rest.  When you pay good money for a show, you expect a great performance.  Actors embodying the characters, musicians merged with their instruments, singers feeling every note, dancers moving to the tune.  When we perform ourselves, we want to give it our all, have good energy, be prepared, engage our audience and tell a good story no matter if it’s vocal, musical or movement.  And if we nail it, there’s no better feeling when you hit every note, lived the character or let the music take your body.  With Method acting (Stanislavski/Strasberg/Actors Studio) you try to create, in yourself, the thoughts and feelings of the character and often rely on emotional memory to generate, for instance, tears.  Remember how you felt when your first dog died.  Hoffman, De Niro, Pacino and Baldwin are some that practice this technique.  William Gillette, an actor/director/playwright in the late 1800’s talked about ‘The Illusion of the First Time.’  That, no matter how many times you’ve done this, you need to make it seem/feel as if it is the first time that the character has ever heard or encountered whatever is occurring.  This gives true responses, reactions and behavior, within the character itself, to the many conflicts within the story.  The other important facet to this is, it is the audience’s first time seeing it so an actor should not ‘telepath’ a response.  

Just what the heck does this all have to do with application delivery?  As part of the 50 Ways to Use Your BIG-IP series, this week we cover performance.  How the BIG-IP system helps improve performance and what are some of the variables that can impact the performance of an application.  Again you may ask, what does acting have to do with application delivery?  ‘Method’ application delivery might be things like caching and data deduplication – I know I’ve seen his before so let me pull from memory and deliver the content.  What is this character user trying to accomplish and I can get them there.  Session persistence might be another area.  I remember you from an earlier meeting, remember that you were doing this particular thing and it made you happy or more productive.  I remember that if users are requesting access from a particular geo-location, then send them to that data center. 

The illusion of the first time also connects well with application delivery via context.  The ADC might have seen this user hundreds, maybe thousands of times, but this time, they are coming from a unrecognized network or from an unknown device and the ADC needs to make an instantaneous decision as to how best handle the request…since it is the first time…within this context.  Just like a character, the ADC absorbs the information, processes it and answers with the best possible response at that moment.  I can tell you, there have been a few times where I did forget my line but so immersed in the moment, that when I opened my mouth, the actual written words just came out.  ADC’s need to perform at their best every moment of every day, not just 8 times a week on an Equity stage.  They need to remember certain pieces of information but also, receive information for the very first time and make instantaneous, intelligent decisions.  They need to adjust depending on the conditions and star in that strategic point of control within the data center stage.  They don’t sign autographs, appear on the front page of the National Enquirer or show up at red carpet events, but can help deliver all the Tony, Grammy, Oscar, Emmy and Obie award(s) data. 

As a director/actor once said in one of my acting classes, a true artist is someone who cannot do anything else, but their craft…if there is anything else that you can do with your life, do it.  Hello Internet circa 1995, I’m Peter.

ps

Resources:

Technorati Tags: F5, F5 News, BIG-IP, application delivery, network, Pete Silva, event, #50waystousebigip, 50 Ways, availability, BIG-IP, acceleration,WAN optimization, caching, compression, offload, theatre, acting, performing arts, ADC

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Friday, May 13, 2011