Half of this book is filled with detailed command lines and procedures to follow to run Security Onion. These details have since become quite dated. the prose around this remains useful. Before diving into the details of running tools, the book explores what network security monitoring is and why it is important. The various techniques (and legal concerns) are also covered. This part has much better stood the test of time. A key principle is that no matter what the defenses, a bad actor will find their way into your network. You need to expect that and be able to find them and prevent too much damage from happening. (Sometimes that means letting them stay for a while so they can be tracked.)
Friday, October 06, 2023
The Practice of Network Security Monitoring: Understanding Incident Detection and Response
Wednesday, April 12, 2023
Pegasus: How a Spy in Your Pocket Threatens the End of Privacy, Dignity, and Democracy
Phones have become a personal part of our lives today. They have a great deal of technology and connectivity that is not well understand by users. Things are fairly opaque and "secure". This makes the phones vulnerable to attacks. Software can theoretically use the microphone to listen, camera to see and scan any activity from the phone. Via the network, this can all be sent back to others to view. NSO group took advantage of this "theory" and implemented spyware that it sold to states. Once installed, a person could be tracked in detail.
This book has two parts. The title parts is a look at modern computer security, the NSO Group and the Pegasus Spyware. However, a big part of the book is spent on the second part: the process of journalism. There is discussion of how different journalists work together, and the concerns they have when breaking a story. They want to balance giving people a chance to defend themselves with the alerting bad players of the investigation. They also don't want to hurt people's feelings by breaking news.
The Pegasus spyware was supported by a large computer system. They focussed on selling it to state actors. It had been used to infiltrate Mexican Drug Lords and other criminal operations. However, it had also been illicitly used to spy on opposition parties and journalists. There are many people that could be viewed as "bad" by those with the power of spyware. With great power comes great responsibility. Openness and privacy each have benefits and drawbacks.
Tuesday, March 07, 2023
Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World
Saturday, May 08, 2021
This Is How They Tell Me the World Ends: The Cyberweapons Arms Race
Today most everything is connected to the internet. The amount of code written is growing everyday. The amount of bugs in the code is also increasing. This creates vulnerabilities in multiple layers. It is impossible for any one person to understand everything their computer is doing. The application software, the operating system, BIOS, network routers and more each have their own code and have their source for vulnerabilities. Unpatched zero-day vulnerabilities remain out there in the wild. Hackers may be lurking in any system.
The world powers have been a source for hoarding vulnerabilities for use in offensive hacking. The US and Israel showed the power when they were able to hack Iran to disable nuclear facilities. Russia took it a step further and caused havoc in Ukraine on multiple times, temporarily shutting off power and shutting down many critical resources. With most everything connected these days, there are many chances for bad guys to infiltrate. In many cases, they already have. They may be after secrets. They me be ransomware gangs in it for money. Or most dangerous, they may be nation-states waiting for war.
The world of hacking is clouded in a lot of secrecy. Highly educated countries on the fringes of global prosperity are likely to produce more vulnerability finding hackers. With limited other prospects, the monetary rewards can be much greater than other legitimate opportunities. Some have scruples on who they sell to. Others, however, will sell to the highest bidder. These bidders will often be nation states. However, the secrecy required by these players may result in a hacker being enticed by a lesser "bug bounty" and the name recognition allowed.
Our society has an interesting dichotomy. We demand extreme openness of anything "public", yet absolute privacy for any "private" activity. However, the boundary can be murky. The public salivated at the juicy revelations in private email conversations unearthed in a Sony data breach, rather than be offended that this data was made public.
We cannot expect anything to be totally safe. There are likely unpatched vulnerabilities that could allow anything to be shut down or any data to be stolen. Security requires "defense in depth". We must hope that all are critical infrastructure is well protected. Often the most difficult part of an attack is gaining entry. Having systems patched helps reduce the easy attack vectors. We must also worry about social engineering attacks. A carelessly clicked on email or a weak password is often the easy entry.
Social engineering can also take the form of "opinion manipulation". Foreign nations can show discord by fanning flames of differing views. Even subtle coaxing can gradually steer people to extremist views or even views not in their best interest.
We have let computers enter nearly every aspect of our lives. How do we prevent them from being our own destruction?
Thursday, August 28, 2014
Worm: The First Digital World War
The will sometimes get a little flaky on the technical details. However, it does a great job of bringing out the personalities and producing a riveting narrative on what is mostly a bunch of people sitting around computer screens. It also helps to make clear how our internet and computer systems are at the same time both extremely fragile and robust.