<?xml version="1.0"?>
<!-- name="generator" content="blosxom/2.0" -->
<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN" "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">
  <channel>
    <title>Fred Avolio's Musings   </title>
    <link>http://www.avolio.com/weblog</link>
    <description>Fred Avolio's Musings on Security and Other Topics</description>
    <language>en</language>

  <item>
    <title>Happy Anniversary Firewall ToolKit!</title>
    <link>http://www.avolio.com/weblog/2008/10/01#FWTK-15</link>
    <description>&lt;P&gt;
The TIS FWTK was delivered via FTP to DARPA 15 years ago today. 
The
next day we delivered it to DUNSnet. We did change the firewall
industry with its delivery. 
And then we changed firewall pricing as Steve Walker and I, doing a 
&quot;back of the envelope&quot; SWAG decided on $15K for software only, $18K
with hardware. Other vendors, with pricing at over $50K dropped their
prices within a week.
&lt;P&gt;
Best wishes to its daddy, Marcus Ranum.
&lt;P&gt;
It's still the most fun I had in a job, my own consulting gig 
a close second.

Read something historic at &lt;a 
href=&quot;http://www.avolio.com/papers/fwtk-history.html&quot; target=&quot;_blank&quot;&gt;
Firewall TookKit&lt;/a&gt;.
&lt;P&gt;
As early as v1.0, the firewall toolkit had &quot;application intelligence,&quot; 
also known as &quot;application awareness,&quot; and 
&quot;deep packet inspection.&quot; We just weren't marketing guys.</description>
  </item>
  <item>
    <title>Data Classification</title>
    <link>http://www.avolio.com/weblog/2008/07/08#ClassifyThis</link>
    <description>&lt;P&gt;
I provided some input into an article by writer
Mathew Schwartz, who quotes me in the article
&lt;a href=&quot;http://itpolicycompliance.com/what+s_new/thought_leader_articles/read.asp?ID=47&quot;
target=&quot;_blank&quot;&gt;
Classify This! 10 Best Practices to Jumpstart Your Data Classification Program&lt;/a&gt;.
&lt;P&gt;
I've often pointed out, here and elsewhere, that there is, as the writer
of Ecclesiates says, &quot;nothing new under the sun.&quot; Mr. Schwartz wrote about
this last week (and it &lt;em&gt;is&lt;/em&gt; timely and too few of us are doing it). And
I wrote these words in February 1999 (almost 10 years ago).
&lt;P&gt;
&lt;blockquote&gt;
Security policy planning entails starting with the mission needs. 
Identify the crown jewels through data classification. 
Classifications might include &quot;dont care,&quot; sensitive, financial, 
competitive, legal, privacy-related, etc.
&lt;/blockquote&gt;
&lt;P&gt;
Re-read my &lt;em&gt;old&lt;/em&gt; article at
&lt;a href=&quot;/papers/Foundations.html&quot; target=&quot;_blank&quot;&gt;
Foundations of Enterprise Network Security&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>It's not just who you are, it's who your friends are</title>
    <link>http://www.avolio.com/weblog/2008/07/02#KnowYourNeighbors</link>
    <description>&lt;P&gt;
I've saved this clipping in my &quot;BlogMe&quot; mailbox since February.
&lt;a href=&quot;http://www.foxnews.com/story/0,2933,331088,00.html&quot;
target=&quot;_blank&quot;&gt;How to Hack Into a Boeing 787&lt;/a&gt;. In a nutshell (in
case the article is gone or you don't want to bother)
all variants of the jetliner &quot;have three on-board computer networks. One
network is for flight safety and navigation, a second is for
administrative functions and the third handles passenger
entertainment and Internet access.&quot; You know the punch-line, right? All
three are linked. (Probably, &lt;em&gt;were&lt;/em&gt;, as Boeing says the design has
been fixed.)
&lt;P&gt;
It reminds me of a story.
&lt;P&gt;
It takes place in 1992 or so, DARPA was funding a
small computer security company to securely
connect The White House (really the Executive Office Building) to the
Internet. They came to this security company and asked &quot;Do you know
anything about 'Internet firewalls?'&quot; People at the company did.
&lt;P&gt;After lots of talking and planning someone with a clue said, &quot;We need to
do a network survey.&quot;
&lt;P&gt;&quot;Why?&quot;
&lt;P&gt;
&quot;We need to see what else is connected to your network.&quot;
&lt;P&gt;Now remember, this was 1993, before &lt;b&gt;everyone&lt;/b&gt; including your Aunt Tilly
was on the Internet.
&lt;P&gt;Long story short, the company did the network survey
and found that the White House network was already on
the Internet. They were connected via NASA Goddard, which, at the time,
was
well-known in the local IP community for poor network security. 
They would have had a firewall
in their front door with an unlocked back door.
&lt;P&gt;
Back to the jetliner. People tend to make these mistakes. Why, or why in
the world are&amp;mdash;sorry, 
&lt;b&gt;were&lt;/b&gt;&amp;mdash;the networks interconnected? I don't
know but  experience tells me it was probably to save some copper (or fiber).
No matter how smart you are (and the Boeing engineers are smart), always,
always, always bring someone else in to look at your plans. And make sure
some of those people know something about security and risks.
 &lt;div class=&quot;mycomment&quot;&gt;
&lt;p&gt;
I heard from someone &quot;in the know,&quot; who shall remain nameless.
&lt;blockquote&gt;
&quot;How to hack into a 787&quot; was erroneous from the very beginning. It was  
a scare story launched by someone with no actual knowledge of the  
systems in question.

While there are connections between the sub-networks on the B787, the  
interactions between the passenger-accessible network and the rest is  
strictly firewalled and sandboxed. The only data connection between  
the cabin network and the flight network is a very limited one that  
allows the cabin crew to talk to the flight crew over the IP-based  
interphone system.

Having actually read the Specification Control Documents (SCDs) which  
control the design of the system, I can tell you that they were  
designed with data security issues very much in mind.
&lt;/blockquote&gt;
&lt;P&gt;
Well, certainly good news, but my point remains. These &lt;em&gt;are&lt;/em&gt; the
times when you don't just bring in application experts, or networking experts,
but also security experts.
&lt;/div&gt;
</description>
  </item>
  <item>
    <title>Conventional Wisdom vs. Wisdom</title>
    <link>http://www.avolio.com/weblog/2008/07/01#ConventionalWisdom</link>
    <description>&lt;P&gt;
In February, Dark Reading published, 
&lt;a href=&quot;http://www.darkreading.com/document.asp?doc_id=146093&quot;
target=&quot;_blank&quot;&gt;The Myth of Conventional Wisdom&lt;/a&gt;.
I posted a comment. A rebuttal really. It is no longer on the website. (No
comments or discussions are for the article.)
I think the discussion&amp;mdash;what Tim wrote and my opinions&amp;mdash;might
be useful to present here. So, read his piece (let me know if the link
no longer works; I saved a copy). And then read what I suggest, below.
&lt;blockquote&gt;
&lt;P&gt;
I believe you've misused the term &quot;conventional wisdom.&quot; Conventional
wisdom are things that are generally accepted as true by most people, not by
experts in the field. I suggest that if you ask experts in the field&amp;mdash;and
for grins, let's stick with people who have been in the business for more
than 2 years&amp;mdash;you will find that none of the things you mention came as
surprises. In fact, they could have been, and have been, predicted. But,
using the correct definition of conventional wisdom, I agree with your
assessment of conventional wisdom in the info security realm.
&lt;P&gt;You write,
&quot;The problem with IT security is that it's not a conventional
discipline. It changes with the nature of the business and the nature of the
threat.&quot;
No. Particulars change, but fundamentally there is nothing new in the
attack space, and has not been in years.
&lt;P&gt;Neither of the examples you give of zero-day attacks (are we really surprised
that attackers go for the low-hanging fruit?) and identity fraud 
surprised experts in the field. The public believes that because loss of
100,000 credit card names and numbers will lead to more people exploiting
more cards. The expert knows that you are still more likely to have you card
number taken and used by the young waiter who served you last night.
&lt;P&gt;
And what network or security expert said that &quot;DNS systems were
unassailable&quot;? Steve Bellovin discovered flaws in DNS almost 20 years ago and
security extensions to DNS started in the late 90s. But, yes, &quot;conventional
wisdom&quot;&amp;mdashwhich we see is no wisdom at all&amp;mdash;would say otherwise.
&lt;P&gt;
&quot;IT security 'wisdom'&quot; is far from &quot;fleeting.&quot; We just continue to
forget the past, and believe that everything is new and needing new
solutions. &quot;The security pro&quot; who forgets the basics and neglects what has
worked before &quot;will surely be the first one attacked tomorrow.&quot;
&lt;/blockquote&gt;
</description>
  </item>
  <item>
    <title>The More Things Change...</title>
    <link>http://www.avolio.com/weblog/2008/06/28#AccessControlMag-interview</link>
    <description>&lt;P&gt;
I was interviewd for &lt;a href=&quot;http://www.accesscontrolmag-digital.com/&quot;
target=&quot;_blank&quot;&gt;Access Control and Security Systems Magazine&lt;/a&gt;.
The article makes me sound smart and old. Okay, I guess I'd like to think I am
smart, and I am, after all, getting on in years. (I am only 10 years
old in &quot;dog years!&quot;)
The article is 
&lt;a
href=&quot;/articles/TheMoreThingsChange.pdf&quot; target=&quot;_blank&quot;&gt;
The More Things Change&amp;hellip;&lt;/a&gt;.</description>
  </item>
  </channel>
</rss>