Hmmm… Too much that is relevant here, so my comments going into e-mail. Drop me a line if you want to know what my thoughts were.
Tuesday, 30 September 2008
The Identity and Access Management Scenario
Note: there is a separate Identity and Access Management Summit.
A set of processes and technologies to manage:
- Users' digital identities
- The relationship to civil identity
- Users' access to systems and the information they contain
Identity: user lifecycle management. Access model: role life cycle management. Identity lifecycle consumes roles from access model. Workflow that passes roles to user lifecycle has a lifecycle itself. All this is done to reduce risk (how does the security framework affect the workflows).
Security efficiency; security effectiveness; business enablement.
Interesting that, when talking about the value of IAM, the first thing the speaker mentioned was attracting and retaining customers—that is exactly what we're doing when we use UIM to help with PGA.
Value:
- Attract and retain customers
- Improve critical business processes and workflows
- Maximise performance and profitability
IAM Program Maturity
Non-existent | Initial | Developing | Defined | Managed | Optimizing |
4% | 10% | 40% | 28% | 15% | 4% |
Does indicate the importance of process definition before applying IAM to that process. We need to work out what process definition we need to do for students during the registration process (and during the application process) to give them the access they need.
Controlling Unauthorized Network Access in a Large Organization
Deploying NAC at Nottingham City Council, with Sophos. Chose Sophos because they already had their AV. Interesting that yesterday, we were encouraged to push back on the cost of AV, and threaten to pull out our existing AV if we don't get a cut in price.
Very little detail in this presentation. Does remind me that NAC is not an enforcement technology. The questions from the audience reflect the issues of NAC for: a variety of roles (visitors, parent companies etc); multiple platforms (LINUX and Mac not supported by Sophos).
Protecting Business in a Web 2.0 World
Signature approach to malware is running out of steam, so what should replace that paradigm? Massive increase in the number of unique samples of malware. There are programs now that generate malware (so there are many variants).
Mmmm. This has turned into a brief history of SaaS and a sales pitch for security SaaS…
Managing Legacy Content to Decrease IT Costs and Reduce Business Risks
If our default, as we look at our e-mail is "I'll keep it just in case." Keeping everything is expensive and most of what we keep we don't need to. Data storage needs are going up about 50% per year (without taking into account pictures, audio and video). No one has responsibility for information retention management. How do we manage the costs of undisciplined data retention. Retention schedules cannot be implemented (because no one has the responsibility).
Suggestions:
- Give legal training to IT people so that they can argue with the lawyers over what can be thrown away
- Hire data archivists (directly, not as consultants)—who can make decisions about what to save and what to keep
Information value degrades over time—rarely does it maintain value. After the first month of e-mail archiving, archives are rarely hit. There are certain things that you should keep—but it is the exception, not the rule.
Five Myths about Rising Storage Demand:
- It can be offset by better technology
- It can be offset by paying less
- It can be offset with more storage tiers
- It can be satisfied with more tape
- It can be accommodated with archiving software
Determine TCO for storage and react.
Use automated methods to determine what files can be thrown away. Determine a set of rules that can help build a list of what could be thrown away.
How does this stuff affect us? For students, I assume that people's home directories aren't kept in perpetuity. For their submissions, how long do they need to be kept—do we want to keep them forever? For e-mail, for staff H: drives, we need to work out what can be stored forever and what can't. What's worse: not giving people lots of central storage so that things get lost on C: drives, or giving them lots of central storage and having capacity requirements go up and up…?
Monday, 29 September 2008
Latest Trends in Computer Hacking
This presentation is given by Jess Garcia, of SANS.
Hacking activities have changed over the last three years or so.
- Dec-07—Sophiticated Trojan loots business bank accounts.
- Jan-08—Bank Trojan charges for sex, breaks two factor authentication.
Botnets are being used differently now—they are the basis for more than just Denial of service attacks.
Hackers now attacking the security software itself and then obfuscate what has happened.
Another reason why we should patch immediately—85% of the time now, there are exploits released the same day as patches for vulnerabilities. That's up from 18% in 2004. No longer are the attackers teenager computer experts, now they are professional cyber-criminals (hired by criminal gangs—or, if they are teenagers, they have been kidnapped by the gangs and threatened). Rather than being motivated by prestige and curiosity, they are motivated by money.
Top Threats 2008:
- Client side: Browser Plugin Attacks
- Web Apps (51% of all vulnerabilities): SQL Injection and cross-site scripting
- Virtualization—this seems to be a growing area
- Malware
- Trojan Bankers
- Botnets
- Trojan Bankers
Haydan is a tool that can be used to create payload with the desired MD5 hash… so much harder to trust hashes.
Malice, Misuse or Mistake: Getting to the "root" of the problem
This presentation seemed to suffer the same issue that I saw in vendor presentations in Barcelona—everything seemed to revolve around selling rather than imparting information—the speaker's motivation was different. Little to say really other than we should try to follow the principle of least privilege—but nothing about how much harder that might be as we try to breakdown data silos and provide new views on data across multiple databases—no strategies for managing those new problems… ah well.