Monday, November 6, 2017

DNS, DNS what is your name?

- A little poem of DNS visiting DNS-OARC 27 in San Jose, CA

As I sitting quietly on the metal chairs, a tap on my shoulder 
asking “DNS, DNS what is your name?”
I quickly responded “I am not playing your game?”
Don’t you really know I am cybersecurity, 

Thursday, March 9, 2017

Data analysis - Clustering using euclidean distance

Recently our ability to gather large amounts of complex data has far outstripped our ability to analyze them.  Although our human brains can process data in complex ways but it does not scale when it comes to large volumes of data. Clustering is one way to distill data to some groups and understand relationships within the dataset.  Clustering is used in many scientific research fields such as natural science, genetics, politics and of course in sales and marketing.  I recently published a blog on analysis performed using euclid distance and clustering at my work SEI for cybersecurity- link here.  Here I am going to simply explore the mechanics of using Euclid distance for clustering using some simple Python code and examples.  Don't worry, it is simple Math hopefully once you walk through this sample.

Thursday, December 17, 2015

The phishing game new tactics

I recently came across a very well formatted phishing email with a valid SSL certificate and close enough domain name to PayPal - paysnal.com that caught my attention.  The techniques are age old as in the real world of fishing - the lure, the distraction and the impersonation.  Like in the real world of fishing - what a fish considers a day-to-day normal business (like fish eating worms), can be a successful trap (death for the fish).  Let me explore this to show how the story unfolded

Tuesday, November 10, 2015

Information Security Strategy


In the few encounter I have with C-level executives, I find that most of information security investments (both engineering and its operations) are done with very little strategy.  My attempt here is to target C-level executives with a model and a set of standards with nomenclature to enable strategic decision making.  It is important to note that this strategy will require some fine tuning by project managers, solutions architects and others for each organization.  The focus here is to ensure The CEO, CIO, CISO and CTO can have the right toolkits and an abstract model to drive the information security needed for a mid to large enterprise.

"Strategy a deliberate, conscious set of guidelines that determines decisions into the future".

- adopted from "Patterns in Strategy Formation" Henry Mintzberg 

Saturday, November 7, 2015

Uncovering a code injection attempt via user-agent

After a long time, I took some time to analyze results of monitoring I put in place for my website. The data is collected from an apache module to track user agent string that were scanning for "Wordpress" looking URL's in my webserver..   I just pulled some recent ones to see if code injection is still being attempted! Let's see

Friday, October 30, 2015

IPv6 geolocation in database

IPv6 popularity is grown to the extent that I have about 15% of my visitors to my website and tools download to be using dual stack.  It is time for me to get a handle on these IPv6 using some geolocation to identify the users.

Thursday, October 15, 2015

Why choose an Enterprise Architect?

As one who has come from electrical and computer engineering with experience building infrastructure from instrumentation to Information Technology, I find it hard to explina to people what I actually do as an Enterprise Architect.  As you can guess there are major misunderstandings when people hear the word "Architect" or "Architecture."

Saturday, September 19, 2015

SilkWeb - Netflow via Webservices

 "Your  security operations or network operations tools cannot run in isolation anymore. True SOC operations is about cohesion of data." 

The common need I get from many Network & Security Operations Centers (NOC & SOC) analysts is their wish to integrate data from their various feeds into UI frameworks and dashboards.  How about NetFlow data itself, NetFlow basically is (at a minimum) a 5-tuple summary of network traffic that crosses your perimeter (firewall or router).  If your NetFlow data goes into a database there are a few tools to translate your database queries to JSON/XML and make these available over webservices.   In this blog I am introducing a project that will help expose SiLK NetFlow data over webservices JSON/XML/CSV to able to integrate SiLK data into your NOC/SOC dashboard with some basic examples. The project is in GitHub called silkweb.

Wednesday, May 13, 2015

IP address tools in Javascript

In my earlier blog I put a set of tools together for IPv4 address manipulation for sqlite,oracle and even Excel. How can I forget the simple tools needed in Javascript.  Changing IP address to long integer, subnet mask to IP address range, have all become a necessity to daily security operations people.  So here is what I have cooked up.


Saturday, October 25, 2014

So you want to disable SSLv3?

Recent vulnerability released by Google called Poodle - puts security administrators to scramble keeping up with "heartbleed", "retiring of SHA-1" and "removal of SSLv3"  As I come from the solutions and enterprise architecture background, I get pinged by these questions about the real risk and impact of implementing these security enforcement's.

Tuesday, June 3, 2014

Integrating Google's BigQuery into your Security Operations Center (SOC).

In your security operations it is not uncommon for you to require access to some large datasets and analyze them.  The obvious answer is to store them in a bigdata solution.  If you are in the business of building your own bigdata solution, you find many technical details as distractions to running your core service - security analysis in this case.

Wednesday, March 26, 2014

Rolling PCAP (Packet Capture) for a production network

It is common to see many SOCs (Security Operations Centers) wanting a packet capture of a recent event to trace down some network activity either part of an attack or an investigation.  A file format called PCAP is a good way to store network data on the disk.  However no one can afford to store PCAP forever, so a rolling packet capture depending on your network bandwidth is a very viable way to collect and store PCAP.

Saturday, February 8, 2014

Overcoming your CDN provider in web logs

As I consult with clients on security incidents in large organizations, they always puzzled by an incident that shows all their web attacks as originating from either Akamai or Amazon.  This is typically due to some reconfiguration of application services to be distributed using a CDN (Content Delivery Network).  It is not surprising for organizations like Target after a large breach incident to sift through millions of logs only to find attacks appear to have come either through a trusted service provider (like Akamai) or through a partner.

Monday, October 28, 2013

Human friendly printing numbers in command line

When I am on Unix system running things of from command line (either SQL or shell of any sort) with long number, I find these numbers hard to read.  For example a printout of netstat packets shows
236477161 packets
Which is really 236.4  million packets, a human friendly representation will be more like 
236,477,161 packets

Monday, September 30, 2013

DNSSEC maintenance tools

DNSSEC has a reasonable effort for one time setup but even more pain comes in managing the keys, expiry and updating your keys and then adding DS (Delegation Signer) keys with your provider or DLV (DNSSEC Look-aside Validation) to the less ideal DLV. system.

Friday, August 30, 2013

Inconvenience != Security

Many people have suggested idea for how they can better secure their users from doing stupid mistakes and ask for my opinion.  Most of these ideas (IMO) seems to add just inconvenience to the user without improving security.  So, my quote for this has been

"While security is not convenient, just inconvenience is not security either!"

Wednesday, August 28, 2013

My favorite egrep patterns

When it comes to using finding matching patterns inside text files, log files and text emails; egrep is very useful tool in your UNIX toolbox.  Here are some of these to find IP addresses, emails, URLs ...

Friday, July 19, 2013

DNS PCAP and BPF

DNS most interesting protocol can be analyzed using some packet filters that can help you look at and analyze various types of DNS packets on the network.  In this blog, I am compiling a list of these to summarize the ones I have discovered as useful for analyzing DNS packets.  The examples are relevant to UDP DNS which is about 90-95% of DNS packets seen.

Tuesday, April 30, 2013

GeoIP and SQL (Oracle)

I wrote a blog in CERT/CC on GeoIP in your SOC (Security Operations Center).  Here I am exploring a little bit more nuts and bolts (technical) details on optimal ways to use GeoIP data in SQL.  The idea is really optimize bulk lookup of IP addresses for geolocation with very quick response times for say thousands or millions of IP addresses.

Thursday, April 25, 2013

ip2long and long2ip in Excel, SQLite and Oracle

Ever stuck with having to do data manipulation in Excel at a customer's restricted Microsoft environment, say with IP Addresses?  Here are some time savers for your IPV4 address manipulation in Microsoft Excel.  I have also added some SQLite function which can be helpful as SQLite has no native INET_NTOA or INET_ATON functions in MySQL.