Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

6/15/2010
11:09 AM
50%
50%

There's A Recipe For That

Back in the dark ages when I was a programmer, I became horribly fascinated with a tool called make. It was a tool for dealing with the complexities of, well, making finished executable code.

Back in the dark ages when I was a programmer, I became horribly fascinated with a tool called make. It was a tool for dealing with the complexities of, well, making finished executable code.The basic unit of executable code in those days (and these days, too, to some extent) was the .exe file, but putting an .exe file together meant compiling source code into object code and then connecting the object code with code libraries containing lots of other bits of object code coming from lots of other source code files. The key point here is that it kept track of dependencies. If something changed in one of the libraries, then it knew enough to know that anything that used those libraries needed to be reconnected with the newer version.

Make didn't know the dependencies by magic, of course. Nor did it know where to copy the various intermediate and final products of the work it initiated. Nor did it do any of the actual work of compiling or linking. You had to tell it all of this stuff by writing it all down in a thing called, none too surprisingly, a "make file."

It was a recipe designed to deal with complexities that were too hard to remember. And there could potentially be a great many complexities. The projects I was working on back in the '90s involved dozens of programmers, hundreds of separate modules, and something on the order of a half million lines of source code written in a few different programming languages.

Pretty much at the exact same time I was getting pretty good at vast and complex make files that relied on other monster make files and so on, the use of make files as a comprehensive solution was being undercut. Rather than linking in objects from libraries and the like, the new paradigm in applications was for the objects to be called up at run time on the system where the application was ultimately deployed. In the case of Windows, what was called up was a Dynamic Link Library, or DLL. In this brave new world, your application had to be smart enough to check whether a given DLL function was the correct version. Microsoft had an amusing propensity for releasing DLLs that had different functionality but the same version number, so the entire exercise had a charming futility about it.

But more to the point, the problem of getting the right versions of things working together at the same time had shifted. It was no longer a programming task that could be handled beforehand by the program developer, but was rather a task that had to be handled by whomever managed the target production system. Keeping the versioning right was now the job of the sysadmin.

By now, the sysadmin job is just that much more complex. Even in a relatively controlled environment where there aren't that many moving parts, getting things configured properly is tough going. Sysadmins are trying to deal with this, in part, by creating something called "devops." Like the make utility of old, devops is in large part about using tools to create programs (real programs, not scripts) that deal with elements of the production network environment as programmable objects.

Devops is at its core not really primarily focused on security. Its aim is to create automation of operations. But it has profound security implications when you consider how often misconfigured applications and components play a role in breaches. Remember that in the first Verizon Business Data Breach Investigations report that 62 percent of breaches were attributed to significant internal errors that either directly or indirectly contributed to a breach. By and large, we're talking about misconfigurations here.

To be honest, it's not entirely clear what the overlap is between commercial security configuration monitors, like BigFix, and open-source devops tools, like Puppet and Chef, but that's something I hope to explore during the next few weeks. Until then, here are a few thoughts from Jesse Robbins, the guy behind Chef, over at gocsi.com.

CSI Director Robert Richardson likes a good recipe fine but a good meal even better. Reach him at [email protected]

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
NetCAT Vulnerability Is Out of the Bag
Dark Reading Staff 9/12/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3738
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
CVE-2019-3739
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
CVE-2019-3740
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
CVE-2019-3756
PUBLISHED: 2019-09-18
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.
CVE-2019-3758
PUBLISHED: 2019-09-18
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.