Thursday, April 19, 2012

Back: Better, Faster, Stronger

I'm back! After about a 4 year hiatus in this space, I plan on remaking my place in the security blogosphere. Not that I haven't been active since then in security - I have! And I've been involved in the community, too. But this space has been conspicuously vacant as I've tried to maintain a relatively low profile.

But now I'll be back to saying it publicly, rather than sending it through a corporate lens or self-censoring. I'll be posting as often as I find the time to cobble something together. If the past 4 years of output is anything to judge by, that will probably be a lot of stuff coming your way! And I'm going to try to play around with the content, format and delivery too. Keep it loose and entertaining, as well as informative.

One key to that, I think, will be to make better use of social media. I'm going to start off with Twitter, as that tends to be where most of my colleagues and peers gather. So if you haven't already, hit me up @beauwoods.

Wednesday, March 30, 2011

Health Net Loses More Patient Records

This month news came out that Health Net lost another 1.9 million patient records. This comes on the heels of a 1.5 million record loss just two years ago.

A previous data loss event happened in May of 2009, but the company only informed the state Attorneys General where disclosure laws exist, and that took nearly six months. They plan to, but have not yet, informed those affected. Vermont fined Health Net $55,000 on behalf of the 525 state citizens who were affected. And Health Net paid $525,000 to settle two claims with the state of Connecticut.

In the healthcare industry, the new HITECH provisions of the HIPAA rule address these data loss events. They require that an organization notify affected individuals within 60 days of a breach. Though there are provisions which would negate the obligation to notify (such as strong encryption or quick recovery), in the Health Net case these do not apply.

In the May 2009 event, the company claims it took six months to identify what and whose data was lost. The information was stored unencrypted on a portable disk drive. Not to worry, they say, the data was compressed only readable using specialty software. There are at least three things wrong with these positions.

Companies need to know where their sensitive information is stored. Health Net claims that it took six months of forensic investigation to determine what was lost. There may be several explanations for this. Maybe they just don't know what they store where. Or maybe those trying to figure it out weren't good or didn't spend much time doing it. Or it's possible that the right people didn't know about the drive, didn't know it was lost or didn't know it may have contained sensitive information. But in the end, it comes down to a basic lack of data and asset tracking.

Portable media is at high risk of theft and loss, so sensitive data stored there should be protected. Physical protection would mean keeping the media in authorized and secured areas; logical protection would mean encryption. But Health Net failed to do this.

Though the data is supposedly unreadable without special software, I doubt this is the case. I've sometimes found that proprietary formats - for which custom software is often very expensive - are nothing more than standard formats with cryptic file names. If you open the file with a text editor, document editor, image viewer or other widely available software, many times you have no problem extracting the data.

But this problem isn't one that exists for Health Net alone. The DataLossDB catalogs many of the data loss events that happen. Others remain undisclosed and unknown.



Friday, October 29, 2010

Beau on the Local News

Blatant self-promotion. Hey, I can't help it. Check out the video, too.

Tuesday, July 21, 2009

Cyber War Against North Korea

I’ve heard people calling for retaliation against North Korea for the latest cyber attacks on the US and South Korean Internet sites. That idea is worse than bad, it’s nearly insane. The best that could be hoped for in such a move would be to saturate the attacker’s bandwidth and thus cancel out the attacks. The worst that could happen would be a virtual Armageddon of factions fighting each other on the Internet, with most of the damage being done to innocent bystanders.

The first mistake that proponents of retaliation make is that they assume that North Korea’s government was behind the attack. But they don’t ask for any evidence of this other than one of the possible beneficiaries of the attacks would be the Kim Jong Il’s regime. In fact, conflicting evidence has been pointing toward the UK as one major source of the attack, and the botnet controller may reside in Florida – yet no calls have been made to attack the British or US governments.

In fact, it's unlikely that there is a North Korea-UK-US connection in these cyber attacks. It’s very difficult to determine accurately and quickly who may be behind an attack. It is too easy to hide the real source behind several layers of obfuscation and the perpetrator may only be discovered after the attack has ended, if at all. The bottom line is that we just don't know who executed the attacks.

Even if you have the right country as the source of attacks, that doesn’t guarantee that the government had any involvement. Looking at a different cyber-conflict, there’s no doubt that Russians were behind the Estonian cyber attacks. But much of this activity was likely individuals within the country acting on nationalist sympathy, not a government-sponsored network of attackers. As Marcus Ranum has pointed out, cyber war is unlikely (PDF link).

Even if you assume that you have the right target, retaliating against them will simply escalate the level of hostilities, not calm it. The attackers will raise their level of attack and may practice asymmetric warfare, taking out not just government sites but commercial ones, as well. One of the best ways to change a government’s behavior is to hurt them financially or to turn the people against them.

Now consider a different scenario: someone tries to get two other countries to fight each other. One individual can buy access to 10,000 infected computers inside one of the countries. He then uses these to launch an attack against another country’s Internet sites. The second country then retaliates against the first. Voila! Cyber-war has erupted. In the current botnet economy, this would cost $500-$1000 (according to a presentation by Lenny Zeltser I can no longer find online).

Some people have questioned why North Korea has Internet connectivity at all. It would seem to be easy to find the choke points – ISPs providing service – and get them to disconnect Pyongyang. With the McColo situation, the bad guys just jumped on other ISPs and diversified. With North Korea, the people themselves are isolated from the rest of the world. But I would suspect that the benefits from a connected country outweigh the potential bad sides. It is much easier to get information out of the country via the Internet than physically. So there is a vested interest in us having an Internet connection out of North Korea – we can find out what goes on inside.

So the next time one of these cyber attacks happens and is hailed as the next step in cyber warfare, take a step back and really look at the players and the landscape. Consider what would be the best course of action. And remember that it is very difficult to determine who the attackers are, where they are located and what their motives are. Hopefully our policy makers will do the same.

Sunday, June 07, 2009

Blog Comment Spammer Strikes

There's a comment spammer hitting my blog. Some anti-virus company I've never heard of, possibly some rogue anti-malware. Lame. So I've turned on moderation for my old posts.