SANS NewsBites is a semiweekly high-level executive summary of the most important news articles that have been published on computer security during the last week. Each news item is very briefly summarized and includes a reference on the web for detailed information, if possible.
Spend five minutes per week to keep up with the high-level perspective of all the latest security news. New issues are delivered free every Tuesday and Friday.
Volume XII - Issue #24
March 26, 2010
When the history of cyber security in the US is written, the US House of Representatives' hearing on March 24, 2010, will play a prominent role. It was at that hearing that the White House official charged with overseeing $80 billion of IT expenditures told the members, under oath, that the US government mandated culture of compliance resulted in waste of over a hundred of million dollars at one agency alone (more than $3 billion across government). He vowed to change government requirements, to stop asking agencies to develop three-ring binders of compliance reports. Those reports (certification and accreditation) are filled with out-of-date data and rarely discuss the important threats. Corporations and state agencies cheered along with all the feds who wanted to invest in security instead of 3-ring binders. Most importantly, Federal Inspectors General were put on notice that if they demand their agencies produce those wasteful reports, then the IGs are taking responsibility for the failures of security that the misallocated spending creates. See the first story for testimony from the hearing. If you are still making money selling those reports or buying them as a government official, check out the second story about the statement from the FBI's top cyber official about why you might want to share Mr. Kundra's sense of urgency.
A second good news story this week, covered by FOX News this morning. The US Navy has established full four-year scholarships for young people who have good cyber security talent as demonstrated in the US Cyber Challenge. The first competition for scholarship eligibility will run during the second week in April. Information on how to get your kids those scholarships at uscyberchallenge.org.
Alan
TOP OF THE NEWS
Harsh Words for FISMA; FISMA 2.0 Bill Supported By Industry and Government WitnessesCyber Attacks Could "Challenge Our Country's Very Existence"
FOX, Yahoo and Google Ads Delivering Malware, Claims Security Company
TJX Mastermind Gets 20 Years in Prison
THE REST OF THE WEEK'S NEWS
House Bill Would Restrict P2P Use on Government SystemsGoogle to Alert Gmail Users to Suspicious Account Activity
Anti-Counterfeiting Trade Agreement Draft Leaked
Mozilla Releases Firefox 3.6.2 a Week Ahead of Schedule
TJX Accomplice Gets Probation
Professional Certification Requirements in Rockefeller-Snowe Bill Raise Concerns
Proposed Legislation Would Tie Foreign Aid to Effective Cyber Security Efforts
*********** Sponsored By Trusted Computer Solutions ***********
Is your IT organization struggling to keep your enterprise servers in compliance with security policy? Could your organization pass a surprise security audit today? Security Blanket performs fast, consistent, and repeatable operating system lock down to industry or custom security settings in minutes, not days. Audit ready, all the time! Try Security Blanket for FREE.
http://www.sans.org/info/57269
*************************************************************************
TRAINING UPDATE
-- SANS Northern Virginia Bootcamp 2010, April 6-13 Bonus evening presentations include Safe Surfing: How to Surf the Net Without Getting PWND
http://www.sans.org/reston-2010/
-- SANS Security West 2010, San Diego, May 7-15, 2010 23 courses. Bonus evening presentations include Killer Bee: Exploiting ZigBee and the Kinetic World
http://www.sans.org/security-west-2010/
-- SANSFIRE 2010, Baltimore, June 6-14, 2010 38 courses. Bonus evening presentations include Software Security Street Fighting Style and The Verizon Data Breach Investigations Report
http://www.sans.org/sansfire-2010/
-- SANSFIRE Rocky Mountain 2010, Denver, July 12-17, 2010 8 courses. Bonus evening presentations include Hiding in Plain Sight: Forensic techniques to Counter the Advanced Persistent Threat
http://www.sans.org/rocky-mountain-2010/
-- SANS Boston 2010, June 6-14, 2010 11 courses
http://www.sans.org/boston-2010/
Looking for training in your own community? http://sans.org/community/
Save on On-Demand training (30 full courses) - See samples at http://www.sans.org/ondemand/spring09.php
Plus Dubai, Geneva, Toronto, Singapore and Amsterdam all in the next 90 days. For a list of all upcoming events, on-line and live: http://www.sans.org/index.php
*************************************************************************
TOP OF THE NEWS
Harsh Words for FISMA; FISMA 2.0 Bill Supported By Industry and Government Witnesses (March 25, 2010)
Chairwoman Watson of the House Committee on Oversight and Government Reform's Subcommittee on Government Management, Organization and Procurement (responsible for drafting the Federal Information Security Management Act) introduced a complete rewrite of FISMA that solves many of the problems that made federal cyber security spending so wasteful. Industry (TechAmerica), ex federal CIO John Gilligan, and government witnesses (OMB, State Dept. and DoD) all gave it thumbs up. Mrs. Watson expressed a sense of urgency, so the bill may have a chance to become law soon. Even if it doesn't, Vivek Kundra, the US CIO, appears to be willing to implement many of the most important changes using the White House's existing authorities. SANS Director of Research Alan Paller told the Subcommittee that FISMA, as it has been implemented and enforced until now has been more detrimental than helpful to government IT security. In his testimony, Paller focused in particular on FISMA provisions that have siphoned necessary resources away from spending that would have helped the government respond more quickly and effectively to cyber attacks. He said the misdirected expenditures have led to an imbalance in pay for security professionals that is equivalent to "pa[ying ]
the compliance staff at a hospital more than the surgeons," Paller listed the four "terribly damaging" processes created to implement FISMA: the federal information security controls and audit manual (FISCAM); the annual report implemented by federal CIOs and inspectors general; the certification and accreditation report writing process; and the security controls assessment specified in the National Institute of Standards and technology's (NIST) Special Publications 800-53. Paller said that the most important and effective security process the government could implement would be to monitor IT systems and networks in real time.
-http://www.computerweekly.com/Articles/2010/03/25/240719/Sans-founder-slams-39te
rribly-damaging39-US-cyber-security.htm
-http://gcn.com/articles/2010/03/25/fisma-hearing-032510.aspx
-http://www.federaltimes.com/article/20100324/IT01/3240305/1001
Kundra Testimony:
-http://oversight.house.gov/images/stories/Hearings/Government_Management/032410_
Federal_Info_Security/2010.FISMA.Kundra.testimony.final.pdf
Paller Testimony:
-http://oversight.house.gov/images/stories/Hearings/Government_Management/032410_
Federal_Info_Security/Testimony_of_Alan_Paller_March_24_2010.pdf
Gilligan Testimony:
-http://oversight.house.gov/images/stories/Hearings/Government_Management/032410_
Federal_Info_Security/Testimony_of_J_Gilligan_3-24-10.pdf
More testimony at:
-http://oversight.house.gov/index.php?option=com_content&task=view&id=485
5&Itemid=28
Cyber Attacks Could "Challenge Our Country's Very Existence" (March 24, 2010)
Speaking at the Federal Office Systems Exposition (FOSE) government IT trade show on Tuesday, March 23, deputy assistant director of the FBI's cyber division Steven Chabinsky warned that cyber attackers are growing increasingly more sophisticated and that the attacks could pose a threat to the existence of the US as we know it. He also said the FBI's top priorities are terrorism and countries "that seek every day to steal our state secrets and private sector intellectual property, sometimes for" nefarious purposes.-http://www.computerworld.com/s/article/9173967/Cyberattacks_an_existential_threa
t_to_U.S._FBI_says?source=CTWNLE_nlt_dailyam_2010-03-24
-http://www.theregister.co.uk/2010/03/24/us_under_cyber_threat/
FOX, Yahoo and Google Ads Delivering Malware, Claims Security Company (March 22, 2010)
Viruses and other malware were found to be lurking in ads last year on high-profile sites like The New York Times <-http://news.cnet.com/8301-27080_3-10353402-245.html>
and conservative news aggregator Drudge Report.com <
-http://news.cnet.com/8301-27080_3-10466044-245.html>
Users don't need to click on anything to get infected; a computer becomes infected after the ad is loaded by the browser, the company said.
-http://news.cnet.com/8301-27080_3-20000898-245.html
TJX Mastermind Gets 20 Years in Prison (March 25, 2010)
A US District Court Judge has sentenced Albert Gonzalez to 20 years in prison for masterminding cyber attacks that resulted in the theft of tens of millions of payment card numbers and associated PINs. Kim Zetter (Wired) provides a clear and comprehensive description of the lengthy cyber crime operation that involved accomplices in Latvia and Ukraine.-http://www.wired.com/threatlevel/2010/03/tjx-sentencing/
-http://www.eweek.com/c/a/Security/Gonzalez-Gets-20-Years-in-Hacker-Case-827849/
-http://news.bostonherald.com/business/general/view/20100325tjx_hacker_gets_20_ye
ars_in_prison/srvc=home&position=also
-http://www.scmagazineus.com/hacker-albert-gonzalez-receives-20-years-in-prison/a
rticle/166571/
THE REST OF THE WEEK'S NEWS
House Bill Would Restrict P2P Use on Government Systems (March 25, 2010)
The US house has passed legislation (HR 4098) that would restrict the use of peer-to-peer software on government computers. Recreational use of P2P software would be banned outright, and legitimate uses of the software would need to be approved by the Office of Management and Budget (OMB) on a case-by-case basis. OMB would also provide Congress with a list of agencies that are using P2P software along with the justification for its use. The bill now goes to the Senate.-http://fcw.com/articles/2010/03/25/peer-to-peer-bill.aspx
Google to Alert Gmail Users to Suspicious Account Activity (March 24 & 25, 2010)
In an effort to fight spam and social engineering attacks, Google has begun notifying Gmail users of suspicious activity on their accounts. The company now provides information about the dates and times the accounts were last accessed as well as logs of the IP addresses used to access the account. The detailed information will be accessible by clicking through a warning banner that will appear on the in-box page. The banner will contain basic information about why Google deemed the activity suspicious.-http://news.cnet.com/8301-27080_3-20001078-245.html?tag=mncol;title
-http://www.securecomputing.net.au/News/170491,google-to-scan-for-suspicious-emai
l-activity.aspx
-http://gmailblog.blogspot.com/2010/03/detecting-suspicious-account-activity.html
[Editor's Note (Pescatore): The warning of suspected suspicious activity is a good thing, but much, much better to crank up the protections to prevent takeover of mail accounts. That same detailed information is what mainframe email used to show users and they quickly learned that peering at login times and IP or MAC addresses wasn't very meaningful to them. ]
Anti-Counterfeiting Trade Agreement Draft Leaked (March 24, 2010)
According to a leaked draft of the Anti-Counterfeiting Trade Agreement (ACTA), the US is urging other countries to suspend the Internet access of users who download digital content in violation of copyright laws. If the ACTA accord were adopted as written in the draft, Internet service providers (ISPs) would be held responsible for the downloading habits of their subscribers unless the ISPs "adopt and reasonably implement a policy to address the unauthorized storage or transmission of materials protected by copyright or related rights," namely a "graduated response" or three-strikes policy.-http://www.wired.com/threatlevel/2010/03/terminate-copyright-scofflaws/
-http://voices.washingtonpost.com/fasterforward/2010/03/draft_of_acta_trade_deal_
leaks.html
-http://www.theregister.co.uk/2010/03/25/full_acta_text_leaked/
Mozilla Releases Firefox 3.6.2 a Week Ahead of Schedule (March 23 & 24, 2010)
Mozilla has pushed out an updated version of Firefox to address a critical zero-day flaw a week ahead of schedule. Firefox 3.6.2 was slated for release on March 30, 2010, but users were notified that the update was available on the evening of March 22. The new version of the browser fixes an integer overflow flaw in the WOFF font decoder that could be exploited to spread malware through drive-by attacks and allow attackers to take control of vulnerable computers. The vulnerability affects older versions of Firefox 3.6, but previous versions of Firefox are not affected. Firefox 3.6.2 also addresses seven other vulnerabilities.-http://www.theregister.co.uk/2010/03/23/firefox_zero_day_fix/
-http://www.h-online.com/security/news/item/Firefox-3-6-2-closes-critical-securit
y-hole-961057.html
-http://www.computerworld.com/s/article/9174056/Mozilla_discloses_more_Firefox_fl
aws?taxonomyId=17s
-http://www.mozilla.com/en-US/firefox/3.6.2/releasenotes/
TJX Accomplice Gets Probation (March 23 & 24, 2010)
Jeremy Jethro has been sentenced to three years of probation for selling exploit code to Albert Gonzalez, who masterminded data breaches at TJX, Hannaford Brothers, Heartland payment Systems and other businesses. Jethro reportedly received US $60,000 for the exploit code. Jethro pleaded guilty to a misdemeanor conspiracy charge. He will also pay a US $10,000 fine.-http://www.wired.com/threatlevel/2010/03/jethro-sentencing/
-http://www.scmagazineus.com/another-gonzalez-co-conspirator-sentenced/article/16
6428/
Professional Certification Requirements in Rockefeller-Snowe Bill Raise Concerns (March 24, 2010)
Provisions in the Rockefeller-Snowe cyber security bill in the Senate that would require cyber security professionals to obtain yet-to-be-specified training, accreditation and certification are raising concerns among technology trade associations. While applauding the 2009 Cybersecurity Act's efforts to bolster public-private cyber security cooperation, the associations are concerned that "the bill creates a compliance-focused framework that we think could hamper effective risk management." The Senate Commerce Committee approved the bill on Wednesday, March 24.-http://fcw.com/blogs/cybersecurity/2010/03/technology-companies-worry-about-cert
s.aspx
-http://www.computerworld.com/s/article/9174065/Cybersecurity_bill_passes_first_h
urdle?taxonomyId=17
-http://www.nextgov.com/nextgov/ng_20100324_7395.php?oref=topstory
-http://thehill.com/blogs/hillicon-valley/technology/88649-three-tech-groups-cybe
rsecurity-bill-could-prove-too-bureaucratic
[Editor's Note (Pescatore): Since software engineering is still an oxymoron, there really are no meaningful software developer or IT system architect certifications. So, trying to say IT security professionals need certification will be good for the companies that will sell such certifications but really does not make sense from the point of any improvement of security.
(Paller): Cisco and NSA and SANS are compiling the available body of knowledge on what works and what doesn't work in security engineering. They will be doing a workshop in June for people who will be hiring security engineers and architects.
-http://www.sans.org/security-architecture-summit-2010]
Proposed Legislation Would Tie Foreign Aid to Effective (March 23, 24 & 25, 2010)
The Senate earlier this week would cut off financial assistance to countries that refuse to take an active stand against cyber crime. The International Cybercrime Reporting and Cooperation Act aims to address the problem inherent in prosecuting cyber criminals who operate across international borders. Without harmonized rules, cyber criminals often evade punishment. The US would identify those countries that appear to be cybercrime havens, offer help establishing plans to crack down on cyber crime offenses, and evaluate the countries' progress after a year. Those countries that fail to take needed steps could have their aid, financing and trade programs suspended. The Senate bill is sponsored by Senators Kristen Gillibrand (D-NY) and Orrin Cyber Security Efforts Legislation introduced in the US Hatch (R-Utah). House members plan to introduce their own version of the bill.-http://www.krebsonsecurity.com/2010/03/cybersecurity-policy-roundup/#more-1975
-http://www.theregister.co.uk/2010/03/23/senate_cybercrime_bill/
-http://www.computerworld.com/s/article/9173970/Proposed_U.S._law_would_single_ou
t_cybercrime_havens?taxonomyId=82
-http://www.scmagazineus.com/bill-could-restrict-funds-for-nations-ignoring-cyber
crime/article/166449/
-http://www.nextgov.com/nextgov/ng_20100323_6358.php?oref=topnews
-http://www.technewsworld.com/story/69621.html?wlc=1269536395
-http://thehill.com/blogs/hillicon-valley/technology/88555-new-cybercrime-bill-wo
uld-penalize-safe-havens-for-hackers
**********************************************************************
The Editorial Board of SANS NewsBites
Eugene Schultz, Ph.D., CISM, CISSP is CTO of Emagined Security and the author/co-author of books on Unix security, Internet security, Windows NT/2000 security, incident response, and intrusion detection and prevention. He was also the co-founder and original project manager of the Department of Energy's Computer Incident Advisory Capability (CIAC)
John Pescatore is Vice President at Gartner Inc.; he has worked in computer and network security since 1978.
Stephen Northcutt founded the GIAC certification and currently serves as President of the SANS Technology Institute, a post graduate level IT Security College, www.sans.edu.
Prof. Howard A. Schmidt is the Cyber Coordinator for the President of the United States
Dr. Johannes Ullrich is Chief Technology Officer of the Internet Storm Center and Dean of the Faculty of the graduate school at the SANS Technology Institute.
Ed Skoudis is co-founder of Inguardians, a security research and consulting firm, and author and lead instructor of the SANS Hacker Exploits and Incident Handling course.
Rohit Dhamankar is the Director of Security Research at TippingPoint, where he leads the Digital Vaccine and ThreatLinQ groups. His group develops protection filters to address vulnerabilities, viruses, worms, Trojans, P2P, spyware, and other applications for use in TippingPoint's Intrusion Prevention Systems.
Tom Liston is a Senior Security Consultant and Malware Analyst for Inguardians, a handler for the SANS Institute's Internet Storm Center, and co-author of the book Counter Hack Reloaded.
Dr. Eric Cole is an instructor, author and fellow with The SANS Institute. He has written five books, including Insider Threat and he is a senior Lockheed Martin Fellow.
Ron Dick directed the National Infrastructure Protection Center (NIPC) at the FBI and is the incoming President of the InfraGard National Members Alliance - with 22,000 members.
Mason Brown is one of a very small number of people in the information security field who have held a top management position in a Fortune 50 company (Alcoa). He is leading SANS' global initiative to improve application security.
David Hoelzer is the director of research & principal examiner for Enclave Forensics and a senior fellow with the SANS Technology Institute.
Mark Weatherford, CISSP, CISM, is Chief Information Security Officer of the State of California.
Alan Paller is director of research at the SANS Institute
Marcus J. Ranum built the first firewall for the White House and is widely recognized as a security products designer and industry innovator.
Clint Kreitner is the founding President and CEO of The Center for Internet Security.
Brian Honan is an independent security consultant based in Dublin, Ireland.
David Turley is SANS infrastructure manager and serves as production manager and final editor on SANS NewsBites.
Please feel free to share this with interested parties via email, but no posting is allowed on web sites. For a free subscription, (and for free posters) or to update a current subscription, visit http://portal.sans.org/