According to this post, our innate sense of numbers is logarithmic and not linear. This means that a choice between a risk of 100 or 200 is comparable to a choice between a risk of 200 or 400. Maybe we should consider this when communication risk? What do you think?
Wednesday, August 6, 2008
Monday, June 30, 2008
Back to the FAIR discussion
Overcoming Bias: Average Your Guesses
In short, the article states that making two (many?) guesses is better than making one guess...
So if you have an approach (FAIR) that lets an expert make several informed guesses and combine them rigorously, then it is quite likely you will get a better estimation than only by making one single guess.
Monday, October 8, 2007
Citrix vulnerability
CITRIX: Owning the Legitimate Backdoor | GNUCITIZEN
I have found the explanation for why it is easy to hack a citrix server at Citrix Systems Inc
Citrix’s passion is to simplify information access for everyone. As the only enterprise software company 100% focused on access, this is also our unique passion.So Citrix wants to simplify information access for everyone and make the access invisible, and Citrix does it with passion...
... Higher Productivity—Users need access to be invisible. They want easy, on-demand access from wherever they are, using any device and network.
Wednesday, September 19, 2007
Psychological warfare
Powered by ScribeFire.
Friday, August 31, 2007
Richard on risk analysis and FAIR again
Richard at TaoSecurity is addressing FAIR again. This time I have come up with what I think is a pretty good argument in defense of FAIR. I wrote a comment at Richard's post but I cite it below as well:
Richard,What do you think?
I think you are right in some aspects, that is: since with FAIR you do not usually have real data to make probability estimates and then you will not get as good risk estimate as you might wish.
However, in FAIR and similar frameworks you get help to elicit expert knowledge and transform it into a risk estimation. And the validity of this risk estimation is of course related to the validity of the expert knowledge: If you put garbage in, you get garbage out.
But, I think you are wrong when you are saying that the input to FAIR is arbitrary. Of course, if used incorrectly, the input can be arbitrary.
My question is: why would anybody that seriously wants to use FAIR make "arbitrary" input? Why not make "guesses" that are the best according to your knowledge? Then, based on the input and its modeling assumptions, FAIR will output the best possible risk estimation (at least if you believe in Bayesian statistics and decision theory..).
This means that you cannot make any better risk estimation based on the knowledge you have given as input without changing the FAIR model or adding more input.
So if you have to make decision that is the best according to you knowledge, then FAIR might work well.
Tuesday, August 28, 2007
FAIR is defended
In defence of FAIR, I think it should be possible to show that by making more fine grained decisions and then combine them, you get less errors than making a single monolithic decision. However I cannot come up with a good model that shows this. Maybe it is already done? Does anybody know?
Powered by ScribeFire.
Monday, August 27, 2007
Riska analysis
I think Richard's arguments against risk analysis are quite convincing but I also think that a detailed analysis as prescribed by FAIR is better than a shallow one. I will come back to the reason later.
Monday, June 25, 2007
Visualization
Anton Chuvakin points to this funny link about visualization. Especially the statement:
"Chart-based encryption -- data goes in, no information comes out" is funny. This is worth keeping in mind when thinking about what to visualize in a security setting. In my work we want to visualize potential intrusion activities and attacks at a network level. We want to give the user a situational picture ("Lägesbild " in Swedish) of the activities at different nodes in the network. In order to do that, we have to use visualization to communicate in an understandable way.
Sunday, May 20, 2007
IDS is dead, long live the IDS!
TaoSecurity: It's Only a Flesh Wound
His remarks are quit interesting to me since my research is most on the intrusion detection and alert analysis part. Not that much about active response or prevention.
Wednesday, April 18, 2007
TaoSecurity: Fight to Your Strengths
Would it be possible to let a firewall or inline IDS automatically block incoming ssh traffic to the default port and then make ssh communication going out using the default port appear to be using a different port?The idea would be to automatically make a temporarily obfuscation until it is possible to switch port on the server. In this way it might be possible to not interfere with the running service but still stop automated attacks. Is there anybody out there who can tell me if this would work in reality?
Powered by ScribeFire.
Monday, April 16, 2007
About: Open-Source Security Tools Abound
Linux/Open Source - Open-Source Security Tools Abound
Powered by ScribeFire.
Tuesday, April 3, 2007
"Signatures are usually based on vulnerabilities rather than exploits"
Errata Security: ANI 0day vs. intrusion detection providers
signatures are usually based on vulnerabilities rather than exploitsThis means that learning systems, like Polygraph, that generates signatures from exploits are not automating the signature generation properly. Though, they are able to block worms exploiting unknown vulnerabilities.
