Wednesday, January 4, 2017

Let's Talk Warfare

Hello and Happy New Year! I hope that you had an amazing holiday. I had a break from school which was nice and a cold, not so nice, lol. The dang thing is still lingering! Seriously, ugh.

I kind of struggled on what topic I wanted to write this week and I guess we aren’t lacking in subject matter in 2017, but I am thinking we should discuss something before this year began since its very critical to our current world affairs. This blog post might not be as light as my previous ones and you will soon see why.


Information Warfare vs. Cyber Warfare


I brought up that Information Warfare and Cyber Warfare are different. This was a couple weeks back and I think we need to talk about this now. There is a reason for this. One is Russia. Our Russian friends have a pretty extreme Information and Cyber Warfare policy. Basically Russia’s policy has declared that a nuclear response is an acceptable reaction for Cyber or Information Warfare. Yeah, I did a double take when I read this in my last class.

While each country governs their policies different that each other on Information and Cyber Warfare, it's still surprising to see that word nuclear floating around in doctrine that most wouldn’t think would be a justifiable reaction. However, I have to give them kudos, they are definitely providing a strong response and a gutsy one too. While each country is taking these types of crimes seriously, let’s look at what the difference is.

Information Warfare is Information based. Think Newspeak or Media Manipulation. Information Warfare isn’t based on hacks or attacks. That is where Cyber Warfare sits. While both are combinable, you can have one without the other.


The Approach & Fake News


One reason I bring this up is the media is going nuts about Trump’s election and possible voting tampering from Russia. Hmmmm? I mean maybe, but considering Russia’s stance on these types of “attacks”, I am not so sure. I don’t know, I wasn’t there, but I can say they take this stuff rather seriously. While Russia takes nuclear approach with some psychological play in there. Seems they like mind games/control as well.
China and the US take different approaches. And while China has a similar approach to the US, their take is more of a dominance approach. Dominate the information and the technology. While the US is more reactive in our approach.

Besides the whole Trump election thing, another consideration is that of “Fake News”. Kinda sounds like Information Warfare to me. What is real, what is fake, what is ____. This is problem for a couple of reasons.

  1. Why can’t we be provided information and discern if it's valid or not?
  2. Who decides what is to be shared?
  3. Why are they controlling it?

So above I posted something about Media Manipulation aka Information Warfare. I kind of have to question the legitimacy of blocking “fake news” since someone has to decide what is fake and whoever that is, what is their goal? Are they playing the world in Information Warfare? Sounds like a play for Information dominance to me.


Food for thought


While I could go on and on there is one really import piece of this that people I don’t think understand. Cyber Warfare and Information Warfare are different and because most people don’t know and they fail to realize that Information Warfare is far more present and happening around us than Cyber Warfare. This is HUGE because we as people are either unaware of manipulation or not taking the time to research issues and what's actually happening.

Cyber Warfare is scary and it does happen. However Information Warfare is already happening and most people don’t even know it.

Until next time, stay safe out there and research! The true is out there, you have to look though. AND incase you wanted to know about Russia, China and US policies there is some great references below.


References

Heickero, R. (2010). RussiaĆ¢€™s Information Warfare Capabilities. Current and Emerging Trends Cyber Operations. Retrieved from http://www.foi.se/ReportFiles/foir_2970.pdf

Lewis, J. (2005, December). Computer Espionage, Titan Rain and China. Retrieved from https://csis-prod.s3.amazonaws.com/s3fs-public/legacy_files/files/media/csis/pubs/051214_china_titan_rain.pdf

Krekel, B. (2009, October 9). Capability of the People’s Republic of China to Conduct Cyber Warfare and Computer Network Exploitation. Retrieved from https://www2.gwu.edu/~nsarchiv/NSAEBB/NSAEBB424/docs/Cyber-030.pdf

Thomas, T. (2004, February). COMPARING US, RUSSIAN, AND CHINESE INFORMATION OPERATIONS CONCEPTS. Retrieved from http://www.dodccrp.org/events/2004_CCRTS/CD/papers/064.pdf


Week 4 CIS 650 Blog Post

Tuesday, December 13, 2016

My MAC, your iPhone, and a vulnerability issue


A long time ago in a valley far away... When I was 8 years old our first computer was a Macintosh. My mother fondly nicknamed it Mac-Baby. She would travel with it to accounting jobs. For lack of a better way to explain it - because my old brain doesn’t remember the model/type, it was an all-in one, with the huge floppy drive and square CRT monitor. I used to play chess on it among other black & white graphic type “video games”.




Now fast forward to 2016 and I ditched the Windows machines, bye Felicia...and I now have 2 Macs. I love the stability of it. The lack of viruses and issues that make it appealing to me, so here we sit. And yes, I know it can still get viruses..I am not delusional.

Recently though there has been a issue with Apple’s calendar feature. What? I know. Looks like someone took note of a system vulnerability and had its way with it. Spammers unit! Ugh. It was black Friday a few weeks ago and myself and hubby both noticed these crazy alarm/alert notifications coming through. On my computer and his phone. We both looked at each other confused and then decided to Google it. And there you have it. Apparently Apple is trying to fix this none sense asap, which is good. But the reason I am touching on this now is because in my current course work we are threat modeling and part of that comes with noting system vulnerabilities.

What broke and what do we do with it


As I am in the thick of building a threat model, which by the way is even harder than it sounds when you feel overwhelmed by two graduate level course and your risk management course was months past and you can’t remember things...just throwing that out there, lol. However, I do know that a key component is identifying threats and vulnerabilities. With that being said...what the heck Apple! You missed one. Anyways..to my points.

  1. Something like this issue should have been caught during whatever process is used for system development testing. Test before release. Say it with me, test before release. Not afterwards. This is how many famous viruses/worms get out and about.
  2. If that was done properly, it would have been repaired or a non-issue.
  3. If it wasn’t caught here, it should have been at least on a radar of some sort in a threat modeling process cycle...maybe? I mean I think so, but I also don’t work for Apple. AND I am in no way bashing them..but this is a really good example in vulnerability assessments.
  4. If it was determined and found, was it considered a part of the risk appetite for the organization or not? My basic question would have been, who dropped this ball?


What to do

So what happens when we miss these? Clearly processes need to be more reformed if things like this are being missed. I mean I know accidents happen, but there is process in place to avoid stuff like this. If it was caught, but it wasn’t determined to be a consider a threat...yikes! I mean it could have been worse for sure! It’s more annoying than anything for the users/customers, but it’s not necessary either.

Threats and vulnerabilities need to always be defined and cataloged in some way shape or form, these processes then help use this to determine next steps and preventive measures. Although even when we try our best, things will still be missed. I realize this and it is OK. I just hope all of these are learning experiences and allow for organizational growth. Plus, I hope no one got fired.

For now, I am going to go work on my threat modeling process some more..maybe I will share that with you all at some point? Either way until next time, stay safe out there!

Week 3 Assignment - CYBR 650

Tuesday, December 6, 2016

Credible news sources 101




Just gonna lay this on the table - Wikipedia does not count. I just want to throw this out there to anyone reading who might be a young adult heading to college..Wikipedia is not a credible news source for any type of research paper or believable content.

What it actually can be used for is looking up something and getting an idea what it might be about. However, that is all it should be used for. Do not go to college and use Wikipedia as a legit reference or source. Your professor will most like have flames shoot from their eyeballs.

BUT but but….


OK why isn’t it credible...because other random people in the world can edit it. AND it is never checked or reviewed for accuracy. So if some random person wanted to write content on brain aneurysms, but he/she is a craps dealer in Las Vegas...with no educational background in that field of study...You see where this is going right? Just avoid it, mkay?

So then, what is a good credible source. The obvious answer is published peer reviewed articles that you will typically find in a library. But Angel, not everyone has access to those fancy online libraries like you do. Correct! However, you can go to your local library and read a book. Kids..seriously you have no idea what a card catalog is do you...ugh that struggle was real.

Without a library, there is also the option of using online search engine. Such as, Google or Yahoo as a starting point. Personally, I use much of the following sites for IT based news. These are legit (aka credible) and generally they don’t contradict each other. These are my "go-to" for IT/Technology based news and information.


Other news sites such as, New York Times, Time, Forbes, or Wall Street Journal.


Credible Sources - How and Why


Evidence. That is really the key factor in determining if a source is credible. Do you remember in math class, I hated math too so for me to use this example is very important, when the teacher would tell you to check your work? You would work a problem backwards and this would let you see if the answer you got actually worked with the problem presented? Same idea. Fact checking, subject matter experts, published articles that are reviewed for accuracy by other subject matter experts - this is the stuff that goes into credible sources. Not craps dealers writing about brain aneurysms. Or me writing about gardening, I have no clue.

What if…



So what happens if these credible sources provide conflicting information. Well the world will still go round and round, but we need to do our due diligence to research further and make an educated conclusion. Ooh, that might be dangerous. But remember that math problem backwards thing? Do that again. Check. Check. Check. This is the only way this will work successfully is if you research and check.

Until then, stay safe out there, use your head, check your "facts", and all will be well.



Imagine above taken from https://pleasureinlearning.files.wordpress.com/2012/12/laffoon2.gif?w=640

Week 2 Assignment - CYBR 650

Wednesday, November 30, 2016

I'm baaaaaack!

So it's been awhile. Yes, it has. Where did I go? Well, school and more school with a start of my own little business that I work from home. So I went and got more busy, hahaha.

As I am closing out my degree, for my new readers, its a Master of Science degree in Cybersecurity. Yeah - whoa momma! Its funny when I tell people that they look at me weird. Not sure why. Is it a girl thing? Hahahaha. Felicity Smoak is my hero! Just saying.

But then there is the, "what did I get myself into", that I ask myself weekly. Truthfully, it has been the most challenging yet rewarding experience. I have learned more than I thought possible. With that being said, I am in my last two course right now. This course CYBR 650 is all about current trends in cybersecurity, so why not blog it! And rightfully so.

Annnnd then there is a question of why should you read my blog. Well, why shouldn't you? I am super fun...probably not entirely relevant, but I am! And funny. At least in my own world. But really its more about bringing attention to certain issues AND hopefully that will inspire critical thinking on your part.

See, while the world goes round, there is many problems we face and things we experience as our technology progresses. Things that need fresh eyes and new minds to conquer. That maybe a 16 year old person that sits down to read my blog on issues with cybersecurity decides that he/she is going to want to understand more and MAYBE be the next Steve Jobs or Bill Gates in a new age with new issues. Who knows really. But then anything is possible right?

So why me and not read someone more fancy on the Internet? Hey - real person here too! I got ideas, questions and issues that need some attention too! Joking aside, I also have experience. I been working in IT for 16 years. OK. Enough with the old person jokes. No, I didn't grow up with a smart phone or the Internet..thank goodness. But I have ran IT Helpdesk, built gaming systems, been a technical trainer and writer, done many IT audits, operations analyst, A/V equipment, built over a million dollar IT budgets, yada yada. Most of this was done in academia, but then there was a few years in the corporate world. So its nice to have a bit of both from where I am standing. That's why me. Why you need to read my blog. I have much in the way of perspective ;)

So standby, read my blog when it posts, think about things critically, and then...discuss. All topics should be related or about cybersecurity in some way. I also like to talk about cyber warfare and information warfare. And yes, those are different. They are not the same...maybe we should talk about that one day..hmmm.

Until then, stay safe out there..


Monday, February 23, 2015

In retrospect....

This is my final week of class for this course, Information Security Management, and while it has been a long ride, it has been most informative and worthy of my time.

Looking at my blog for the past few (cough12cough) weeks they have been a variety of IT/InfoSec yummy-ness.  I wrote a few times about Sony and their malware/hacking drama, we touched on policy/procedures, ISO certification, disasters and a rant about security breaches that actually affected me directly.

I tended to choose these topics because either they were close to my heart, got my blood boiling or I found them interesting. Many times a week I would research Cnet.com for much of my news, I also checked Forbes and of course, Yahoo. But Cnet.com tended to have the goods more so than not.

When I was first asked to write a blog for this course I felt intimidated and a little stuck. What would I write about, what if I couldn't think of anything, how do I do this, what if I sound like an idiot..all of these thoughts went through my mind.

I also found that once I didn't worry about these things I could just be myself and blog. A few tips to the next batch of students that have to do this for course credit:

  • Blogging isn't as serious as a paper/essay. You can be fun and feisty as you write about your topic.
  • Do your research and form your educated opinion. Blogs are opinion based and it's ok to disagree or agree, just give us a reason why.
  • Use reputable sources. Don't use another person's blog unless you have a reason to (I haven't found a reason too)
  • Don't use Wikipedia for research. Technically you shouldn't use this for any college research, so just don't. 
  • Have fun. Enjoy your writing and topic, this way it doesn't feel like an assignment
Lastly, if your still terrified of the blog world or don't understand how to...just look it up online, there are many articles on how to start a blog.

As I progressed through this blog, I discovered the value in the assignment. Much of the reason is keeping up with what's happening out there in the InfoSec world, following trends, seeing whats new, etc. This can only help you in your professional life. IT and InfoSec, well anything technology related, is ever changing and in order to be at the top of our game, we need to stay in the know. This blog helps me do this. And hopefully, you too!

Stay safe out there, thank you for reading!

Tuesday, February 17, 2015

Go Microsoft, kick some butt!

I am proud of Microsoft!

Looks like they are targeting Asia as a global hub of cybercrime and malware. Bout time, yea?

Ok let's be honest, we (the folks in IT in the US) have seen the cyber attacks coming from Asia. I have seen it as well. Working at a university inside a NOC, the attempts to hack into systems containing that "yummy" data of students social security numbers and birth dates. Yup, happens so frequently it looks like the Matrix running in the back ground with nothing unusual in the least.

And while I am not sure this approach will actually work, I am at least glad that Microsoft is attempting to do something about it. Or at least trying...

Microsoft believes that the interpol unit in Singapore will have better access to the surrounding areas with this center. Looking at not only Asia, but the Oceanic countries as well. This way they are watching the money and where it's coming from.

Another huge concern is malware and rightfully so.

"Of a more pressing concern is China, which already has a Cybercrime Satellite Center located in Beijing. Bosco says the infection rate in China is high due to counterfeit software. There's a huge amount of infections within China, and the result of that from our investigative work was that it comes from an unsecured supply chain," said Bosco. "What happens is you're getting a lot of people infected because of simply buying a computer with pre-installed malware. Sometimes, it's not even that, it comes with all of the features, such as automatic updates and firewalls disabled."

"The minute you put it on the Internet, even if you're not infected, within hours you will be infected and it just cascades and you'll see a huge amount of infections in China because of that."

The entire article can be found here:
http://www.cnet.com/news/asia-could-be-the-next-hotbed-of-cybercrime-says-microsoft/

Will this make a difference? Well something has to be done, so why not try it. Until we get to the point of either stopping the way we do business OR never using the Internet (sorry if your laughing so hard your coffee is dribbling out your nose), then let's throw everything against the wall until something sticks. I mean doctors do it when trying to diagnose a disease they can't figure out (I know from personal experience...another blog, another time) But why not this? It will be interesting to see what happens now.

Stay safe out there!

Monday, February 9, 2015

A way of life...the constant fear of a data breach

Is it really a way of life, have we become numb to this?

By this I mean data breaches. They are more and more frequent and seem just like something we have to "live with".

Recently, Anthem Blue Cross and Blue Shield has been the most recent hack to affect nearly 80 million people. And I could be one of them. I have their insurance through my employer, it's good insurance...a bit pricey but good. But now I need to worry about this.

They are supposed to mail their customers letter if they were affected. And while that is a policy. it's a crappy in practice. Do you realize that by the time I get the letter (if I get one; I hope I don't), someone already has opened up credit cards in my name or taken out loans. Seriously this is getting ridiculous.

"Anthem Blue Cross was the target of a very sophisticated external cyber attack. These attackers gained unauthorized access to Anthem’s IT system and have obtained personal information from our current and former members such as their names, birthdays, medical IDs/social security numbers, street addresses, email addresses and employment information, including income data. Based on what we know now, there is no evidence that credit card or medical information (such as claims, test results or diagnostic codes) were targeted or compromised (http://www.forbes.com/sites/gregorymcneal/2015/02/04/massive-data-breach-at-health-insurer-anthem-reveals-social-security-numbers-and-more/)."

Does that make me feel better? Um, no! I am kind of irate. Being a geek (as I so choose to identify with) I find the lack of protect and the "oh, it's just something we need to live with" frustrating to say the least. We shouldn't have to live with this. There has got to be a better way. 


I realize that since we are doing pretty much everything through the Internet...it has an enhanced risk. But maybe doing business this way is OK or maybe it isn't. While I don't have the answers and I can't really think of much else, except to maybe not use social security numbers for things like insurance (maybe a different number to identify with) might help this craze of stealing information and identities. OR even crazier, it's too bad we have a monetary based society (I know way off topic), but it would eliminate the greed factor of crimes....just saying.

If you were compromised or even if you weren't, there are a few things everyone can do to be a little bit safer in the vortex of the Internet. Check out these steps for security: http://www.forbes.com/sites/gregorymcneal/2015/02/05/6-ways-to-protect-yourself-after-the-anthem-data-breach/

I am off to call the 3 credit reporting agencies...just as a precaution. 

Try to stay safe out there....try....