Perimeter
2/23/2011
02:34 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Another Side Of B-Sides

The "unconference" across the street from the RSA show in San Francisco last week was shaped, in part, by recent security events

Last week's B-Sides San Francisco had a much different vibe than the previous B-Sides I attended. Granted, that one was held at a private resort in Las Vegas, and San Fran ain't Vegas -- although that may be debatable after Sourcefire's glittery Vegas-themed casino party and Barracuda Networks' Gold Club bash held in conjunction with the RSA Conference there last week.

The backdrop of the recent targeted attack on HBGary by Anonymous, Stuxnet, and a year of advanced persistent threat (APT) revelations and discussions in some ways made for a slightly more serious B-Sides. It also created a lot more buzz at the typically marketing-oriented RSA Conference across the street. The location for the "unconference" at a kids' museum (complete with kids running in and out of the venue amid hackers and attendees) kept B-Sides still a far cry from the more formal RSA Conference, though, and the informal nature of the presentation sessions were still apparent, even with the little theater lecture hall rooms in the Zeum.

Noticeably missing from the B-Sides agenda, of course, was the now-infamous talk that never happened: Aaron Barr's presentation on using social networks to gather intelligence. Among the three case studies Barr had planned to discuss during the talk, "Who Needs the NSA When We Have Social Media," were the Anonymous group, a critical infrastructure facility, and a military installation. The fallout came when Barr told The Financial Times in an article prior to the show that he was able to identify real names of most of the higher-ups in Anonymous. Anonymous hit back hard, dumping the contents of the HBGary Federal and HBGary's email messages and other sensitive information online, as well as commandeering Barr's Twitter account and posting his Social Security number and address.

Barr subsequently canceled his B-Sides talk, and HBGary later pulled out of the RSA Conference as well, leaving behind a sign on its booth on the show floor noting threats against its employees: "In addition to the data theft, HBGary individuals have received numerous threats of violence including threats at our tradeshow booth."

So the big week for the security industry began on a slightly more somber note; the HBGary/Anonymous incident infiltrated many presentations and talks, and was carefully discussed among gun-shy attendees and speakers. But that wasn't the only reality check for the security industry that had hit the fan. Stuxnet's presence also was felt, serving as a chilling reminder of the vulnerability of the power grid, and generating more debates over cyberwar and espionage.

One of the talks at B-Sides looked at security "marketecture," with Richard Bejtlich, director of incident response for General Electric and leader of the GE computer incident response team, and Travis Reese, president and COO at Mandiant. Andrew Hay, senior security analyst with The 451 Group's enterprise security practice, chaired the panel, which debated how security vendors use and abuse terms like "advanced persistent threat" and "cyberwar" to sell their wares.

Cyberwar has become one of the most popular topics of debate in the industry given the events of the past year: What the heck is cyberwar? Are we in one now? How will we know when we are at cyberwar? The panels sorted out just what constitutes cyberwar and an APT or targeted attack.

Bejtlich pointed out that according to Chinese information war doctrines, China believes the U.S. already started an information war against it. "They believe our culture is an affront to their sovereignty," he said. And Chinese attackers tend to use the "persistence" strategy of gaining a foothold in a targeted network for espionage purposes and finding ways to remain there as long as possible and employing a strategy of "plausible deniability."

Attackers from other regions take more pains to remain anonymous. "They don't use persistence. If you shut a box down [where they had infiltrated], they are gone," Bejtlich said.

And Mandiant's Reese noted that cyberespionage isn't the same as cyberwar, even though nearly 20 percent of the targeted attacks Mandiant has seen of late were against energy companies. He said cyberwar would have a military element as well.

No one drew definitive conclusions, but that's half the fun of the B-Sides banter. There's no stock "takeaway" slide at the end of a preso -- just open and continued dialogue and debate on security's hottest topics. Even with the large turnout last week in San Francisco, with some 500 attendees, B-Sides still was able to maintain the intimate atmosphere it was built on while at the same time growing into a more prominent venue for security professionals.

-- Kelly Jackson Higgins, Senior Editor, Dark Reading Follow Kelly (@kjhiggins) here on Twitter.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6501
Published: 2015-03-30
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...

CVE-2014-9652
Published: 2015-03-30
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...

CVE-2014-9653
Published: 2015-03-30
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...

CVE-2014-9705
Published: 2015-03-30
Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVE-2014-9709
Published: 2015-03-30
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.