本來是想寫篇產業白皮書的東西,但是不知怎地,卻弄成既不學術也不商業的四不像,為了存真,還是將這篇東西留下來,算是為過去的那些日子留個紀念吧。
Showing posts with label database security. Show all posts
Showing posts with label database security. Show all posts
Friday, March 30, 2012
資料庫活動監視(Database Activity Monitoring)產業概述和未來
資料庫活動監視(Database Activity Monitoring,DAM)這個產品類別,因為個人資料保護法修正條文將在今年實施的關係,在資訊安全產業受到較多的矚目,但是不論是產業界還是必須購買資料庫防護產品的消費者,真的搞清楚這是什麼東西的人(組織)還真不多。所以應友人之請,整理了一些資料,希望對讀者有所幫助。
Thursday, August 25, 2011
資安管理十誡 - The 10 deadly sins of information security management
近日查閱資安管理(information security management)資料,不時看到 Ten Deadly Sin 字眼出現,今晨看過往Business Management 雜誌對現在公司所在領域的幾個原廠總字輩大佬的專訪,又看到文末列出這十宗罪(十宗罪好像是大陸習慣用法?)。
透過谷歌,很快就查到,原來這十誡典出學者 B. von Solms and R. von Solms 於 2004年7月發表在 Computer & Security 的文章。此十誡言簡意賅,強調資安管理不是技術部門獨有的責任,旨哉斯言,爰執鍵(盤)為之記。
B. von Solms and R. von Solms, "The 10 deadly sins of information security management," Computers & Security, vol. 23, no. 5, pp. 371-376, Jul. 2004. [Online]. Available: http://dx.doi.org/10.1016/j.cose.2004.05.002
透過谷歌,很快就查到,原來這十誡典出學者 B. von Solms and R. von Solms 於 2004年7月發表在 Computer & Security 的文章。此十誡言簡意賅,強調資安管理不是技術部門獨有的責任,旨哉斯言,爰執鍵(盤)為之記。
- Not realizing that information security is a corporate governance responsibility (the buck stops right at the top)
- Not realizing that information security is a business issue and not a technical issue
- Not realizing the fact that information security governance is a multi-dimensional discipline (information security governance is a complex issue, and there is no silver bullet or single ‘off the shelf’ solution)
- Not realizing that an information security plan must be based on identified risks
- Not realizing (and leveraging) the important role of international best practices for information security management
- Not realizing that a corporate information security policy is absolutely essential
- Not realizing that information security compliance enforcement and monitoring is absolutely essential
- Not realizing that a proper information security governance structure (organization) is absolutely essential
- Not realizing the core importance of information security awareness amongst users
- Not empowering information security managers with the infrastructure, tools and supporting mechanisms to properly perform their responsibilities
B. von Solms and R. von Solms, "The 10 deadly sins of information security management," Computers & Security, vol. 23, no. 5, pp. 371-376, Jul. 2004. [Online]. Available: http://dx.doi.org/10.1016/j.cose.2004.05.002
Monday, August 22, 2011
Defense in Depth 的解釋
在資通訊安全領域,有個源於軍事領域的術語 defense in depth (DID), 在軍事上,DID 是一種策略理念,防禦不能只靠一道強大的防線(比如說中國的長城和法國的 Maginot Line ),必須用多層次(multi-layer)、多角度、多點、多面的防禦,提高攻擊者的成本與難度,延遲破解防禦的時間,讓防守者有足夠的時間、空間找出破解攻擊的方案。
有人是這樣詮釋的:在建立防禦據點時,整個防禦工事的部署一定要具備足夠的縱深,才能提高攻堅的難度與拉長敵軍的攻擊時程,以避免一下子就被長驅直入。縱深的另一層意義就是要有重重的關卡,就像洋蔥或高麗菜那般地一層一層地把核心包裹得密不透風。
以上的說法,把多層次的防禦和 in depth 的物理意義,說的精闢通透,但是沒有點出多點、多面的策略意義,而且把 DID 和資安領域另外一個詞彙 layered security 畫上等號。這兩個觀念雖然有很多重疊的地方,但畢竟不是同一件事,而且 layered defense 僅是 defense in depth 策略的一部分而已。
TechRepulibc 上有一篇 Chad Perrin 寫的短文,把這兩個很易於混淆的名詞間的差異解釋的很清楚。理解這兩個名詞最大的障礙就是望文生義造成的誤解,就像數學歸納法不是歸納,階層式防禦不只是千層派或高麗菜的層次,DID 裡的 depth 也不只是物理上的距離。
階層式的安全防禦理念說來單純,每個人(工具)都有優、缺點,寸有所長尺有所短,只用一種工具或技術來防禦顯然是不夠的,所以要應用各種技術布置在攻擊的路徑上,以達到最佳防禦效果。這個理念的精髓是工具間優劣互補(be used to cover the gaps in the others’ protective capabilities.),而不是用車輪戰累死攻擊方(當然,這是附帶的效果)。比如說,一個家計用戶,在上網的時候,可能採用的工具包括:
DID 所圖則更遠大,防禦不僅要從技術面來考量,人員素質與觀念、工作標準程序都在策略範圍內,甚至還要考慮到反制手段(means tofight back actively)。美國政府的 Information Assurance Technology Analysis Center (IATAC) 出版的電子雜誌 IAnewletter 在 1999 年討論 Defense in Depth 時就提到:
透過技術,設下層層壁壘(successive barriers),僅是整個防禦策略的一個組成元素,還有制度與流程,有了規章律令,徒法不足以自行,人員的自覺與訓練也不能落下。在美國國家安全局(NSA)出版的白皮書中,很清楚的說明 Defense in Depth 是達成 Information Assurance 的策略,策略中包含人員、技術與作業流程三個構面。
在 NSA 白皮書中,還列出每個構面所需涵蓋處理的最小子集:
[延伸閱讀]
有人是這樣詮釋的:在建立防禦據點時,整個防禦工事的部署一定要具備足夠的縱深,才能提高攻堅的難度與拉長敵軍的攻擊時程,以避免一下子就被長驅直入。縱深的另一層意義就是要有重重的關卡,就像洋蔥或高麗菜那般地一層一層地把核心包裹得密不透風。
以上的說法,把多層次的防禦和 in depth 的物理意義,說的精闢通透,但是沒有點出多點、多面的策略意義,而且把 DID 和資安領域另外一個詞彙 layered security 畫上等號。這兩個觀念雖然有很多重疊的地方,但畢竟不是同一件事,而且 layered defense 僅是 defense in depth 策略的一部分而已。
TechRepulibc 上有一篇 Chad Perrin 寫的短文,把這兩個很易於混淆的名詞間的差異解釋的很清楚。理解這兩個名詞最大的障礙就是望文生義造成的誤解,就像數學歸納法不是歸納,階層式防禦不只是千層派或高麗菜的層次,DID 裡的 depth 也不只是物理上的距離。
階層式的安全防禦理念說來單純,每個人(工具)都有優、缺點,寸有所長尺有所短,只用一種工具或技術來防禦顯然是不夠的,所以要應用各種技術布置在攻擊的路徑上,以達到最佳防禦效果。這個理念的精髓是工具間優劣互補(be used to cover the gaps in the others’ protective capabilities.),而不是用車輪戰累死攻擊方(當然,這是附帶的效果)。比如說,一個家計用戶,在上網的時候,可能採用的工具包括:
- 防毒軟體
- 防火牆
- 親子內容控制(Parental Control)
- 隱私權控制軟體、
DID 所圖則更遠大,防禦不僅要從技術面來考量,人員素質與觀念、工作標準程序都在策略範圍內,甚至還要考慮到反制手段(means tofight back actively)。美國政府的 Information Assurance Technology Analysis Center (IATAC) 出版的電子雜誌 IAnewletter 在 1999 年討論 Defense in Depth 時就提到:
The Defense in Depth approach employs and integrates the abilities of people, operations, and technology to establish multilayer, multidimensional protection — like the defenses of a castle. The approach employs successive layers, using a variety of methods at multiple, key locations,to prevent the potential breakdown of barriers and penetration to the innermost areas of the system.
透過技術,設下層層壁壘(successive barriers),僅是整個防禦策略的一個組成元素,還有制度與流程,有了規章律令,徒法不足以自行,人員的自覺與訓練也不能落下。在美國國家安全局(NSA)出版的白皮書中,很清楚的說明 Defense in Depth 是達成 Information Assurance 的策略,策略中包含人員、技術與作業流程三個構面。
在 NSA 白皮書中,還列出每個構面所需涵蓋處理的最小子集:
- People
- Policies and Procedures
- Training and Awareness
- System Security Administration
- Physical Security
- Personnel Secuirty
- Facilities Countermeasures
- Technology
- IA Architecture
- IA Criteria (Security, Interoperability & PKI, etc)
- Acquisition/Integration of Evaluated Products
- System Risk Assessment
- Operations
- Security Policy
- Security Management
- Ceritification and Accreditation
- Key Management
- Readiness Assessments
- Attack Sensing, Warning and Response
- Recovery and Reconstitution
[延伸閱讀]
- 美國國家安全局(National Security Agency)出版的《Defense in Depth》
- 澳洲政府寬頻、通訊與數位經濟部(Department of Broadband, Communications and Digital Economy)出版的 《Trusted Information Sharing Network for Cirital Infracture Protection - Defence in depth》
- 美國空軍出版的《How to defend cyberspace? Furutre of defence in depth in an offensive world.》
- IATAC 出版的電子雜誌 IAnewletter 第三卷第二期
Sunday, August 21, 2011
人心早就不古!
今年(2011年)才開始,澳洲的 Vodafone Australia 就爆出资料外洩事件,接著一個又一個大型資安事故的新聞接踵而至。
先是 Sony Play Station 網路被駭,然後韓國最大的社群網路 Cyworld 三千五百萬筆客戶資料外洩,還有不要忘了惡名昭彰的駭客團體 Anonymous 宣佈攻破 Exxon Mobil, ConocoPhillips, Canadian Oil Sands Ltd., Imperial Oil, the Royal Bank of Scotland 的消息。上半年才結束,立刻傳來國際貨幣基金(IMF)資料外洩的消息,相形下,衛生署對萬芳醫院病歷外洩裁罰五萬的消息,根本就是不成話的小兒科。
Ponemon Institute 和 Symantec 每年做資料外洩事故成本(cost of data breach)分析,以美國企業為樣本空間的報告顯示:資料外洩事故逐年增加,且處理的成本也逐年升高。今年四月份,Verizon Business 發布年度 Data Breach Investigations Report (DBIR) 的副標題 Breaches Increased Dramatically 更是為這些資安事故的蓬勃「發展」下了「畫龍點睛」的註腳。
不過,資料外洩的事故,真的是如旭日東昇,一天比一天多嗎?資安領域著名的顧問公司 Securosis LLC 技術長 Adrian Lane 不這麼認為,他在 Dark Reading 發表的短文《Data Breach On The Rise?》以他自身輔導企業的經驗和媒體公佈的新聞相參照,斷言並沒有足夠的統計證據支持現在的資安事故比以前多(There is no statistical evidence that breaches are on the rise.)。
Andrian Lane 的論點很簡單,現在的資料庫技術和工具,確實比以前進步,但是人性並沒有改變、企業裡面便宜行事的流程沒有改善、為公司股價著想壓下資安(還包括工安)事故新聞的例子也沒有增減。僅憑登上媒體的公司的有名程度,就斷言現在的事故數比以前多,在論證上是站不住腳的。
換句話說,這年頭,好人沒有比過去少,壞人也沒有比過去多,人性如此,貪婪和犯罪企圖依舊。我們沒有活在比過去壞的世界裡,只是犯罪的技術與工具變了,媒體的報導風格變了,如是而已。以前的人沒有比較高尚,在企業裡撞鐘的和尚不多不少,行事風格依然故我,所以說 on the rise 言過其實,因為以前大過小錯就很多,只是沒有說給你聽而已。
這篇短文讓我想起「人心早就不古」的老段子,坦白說,我還蠻認同 Andrian Lane 的觀點。
讀文章有感,是為記。
先是 Sony Play Station 網路被駭,然後韓國最大的社群網路 Cyworld 三千五百萬筆客戶資料外洩,還有不要忘了惡名昭彰的駭客團體 Anonymous 宣佈攻破 Exxon Mobil, ConocoPhillips, Canadian Oil Sands Ltd., Imperial Oil, the Royal Bank of Scotland 的消息。上半年才結束,立刻傳來國際貨幣基金(IMF)資料外洩的消息,相形下,衛生署對萬芳醫院病歷外洩裁罰五萬的消息,根本就是不成話的小兒科。
Ponemon Institute 和 Symantec 每年做資料外洩事故成本(cost of data breach)分析,以美國企業為樣本空間的報告顯示:資料外洩事故逐年增加,且處理的成本也逐年升高。今年四月份,Verizon Business 發布年度 Data Breach Investigations Report (DBIR) 的副標題 Breaches Increased Dramatically 更是為這些資安事故的蓬勃「發展」下了「畫龍點睛」的註腳。
不過,資料外洩的事故,真的是如旭日東昇,一天比一天多嗎?資安領域著名的顧問公司 Securosis LLC 技術長 Adrian Lane 不這麼認為,他在 Dark Reading 發表的短文《Data Breach On The Rise?》以他自身輔導企業的經驗和媒體公佈的新聞相參照,斷言並沒有足夠的統計證據支持現在的資安事故比以前多(There is no statistical evidence that breaches are on the rise.)。
Andrian Lane 的論點很簡單,現在的資料庫技術和工具,確實比以前進步,但是人性並沒有改變、企業裡面便宜行事的流程沒有改善、為公司股價著想壓下資安(還包括工安)事故新聞的例子也沒有增減。僅憑登上媒體的公司的有名程度,就斷言現在的事故數比以前多,在論證上是站不住腳的。
換句話說,這年頭,好人沒有比過去少,壞人也沒有比過去多,人性如此,貪婪和犯罪企圖依舊。我們沒有活在比過去壞的世界裡,只是犯罪的技術與工具變了,媒體的報導風格變了,如是而已。以前的人沒有比較高尚,在企業裡撞鐘的和尚不多不少,行事風格依然故我,所以說 on the rise 言過其實,因為以前大過小錯就很多,只是沒有說給你聽而已。
這篇短文讓我想起「人心早就不古」的老段子,坦白說,我還蠻認同 Andrian Lane 的觀點。
讀文章有感,是為記。
Tuesday, August 16, 2011
又一碗字母湯( Another Bowl of Alphabet Soup)
雖然走進資安領域,不在原本的規劃裏,但既然被機緣牽進這村徑,總要好好逛遍這山林,庶幾不負這不可言、不可測的緣法。既然要逛逛這原未涉足的土地,那就得認真閱讀此處的風土誌,要認懂這裡的地圖,就得認得這裡的方言俚語,於是得再服一碗字母湯。
- ACL - Access Control List
- APWG - Anti-phishing Working Group
- BASEL - Basel Accords
- BSI - British Standards Institution
- CA - Continuous Auditing
- CA - Certificate Authority
- CC - Common Criteria
- CCM - Continuous Control Monitoring
- CCM-AC - CCM for Application Configuration
- CCM-MD - CCM for Master Data
- CCM-T - CCM for Transaction
- CEH - Certified Ethical Hacker
- CERT - Community Emergency Response Team
- CM - Continuous Monitoring
- CME - Common Malware Enumeration
- COBIT - Control Objectives for Information and related Technology
- DAD - Database Access Descriptors
- DAM - Database Activity Monitoring
- DMZ - Demilitarized Zone
- DLP - Data Loss Prevention
- DOS - Denial of Service
- DDoS - Distributed DOS
- FERPA - Federal Educational Rights and Privacy Act
- FGAC- Fine-Grained Access Control
- GLBA - Gramm–Leach–Bliley Act
- GPG - GNU Privacy Guard
- GRC - Governance, Risk and Control
- GTAG - Global Technology Audit Guide
- HIPAA -Health Insurance Portability and Accountability Act
- IDS - Intrusion Detection System
- IPS - Intrusion Prevention System
- IIA - The Institute of Internal Auditors
- ISACA - Information Systems Audit and Control Association
- ISMS - Information Security Management System
- ITIL - Information Technology Infrastructure Library
- KRI - Key Risk Indicator
- MLS - Multi Level Security
- NIST - National Institute of Standards and Technolog
- PCI-DSS - Payment Card Industry Data Security Standard
- PII - Personally Identifiable Information
- SOAP - Simple Object Access Protocol
- SOX - Sarbanes-Oxley Act
- SSH - Secure Shell
- SSO - Single Sign-On
- VPD - Virtual Private Database
- XSS - Cross Site Scripting
Saturday, January 15, 2011
只有更囧,沒有最囧
本以為這個月初 Vodafone Australia 泄露四百萬客戶資料的事已夠駭人聽聞,沒想到加拿大統計局 (Statistics Canada)諸君的豐功偉業才真是登峰造極令人髮指。
多倫多太陽報這個月10號在一份報導中整理過去五年 Stats Can 的犯行,在 2007年,他們把一個裝了敏感訊息的檔案櫃當作多餘的傢具賣掉,還有一次,統計局的幹員把某家公司的調查資料,留在其他的調查對象的辦公室,太陽報很客氣的說這只是 some examples of breaches.....
多倫多太陽報這個月10號在一份報導中整理過去五年 Stats Can 的犯行,在 2007年,他們把一個裝了敏感訊息的檔案櫃當作多餘的傢具賣掉,還有一次,統計局的幹員把某家公司的調查資料,留在其他的調查對象的辦公室,太陽報很客氣的說這只是 some examples of breaches.....
OCT. 2010: Purolator envelope containing 11 unencrypted, non-password-protected CDs for the Vital Statistics Program in Alberta addressed to Ottawa head office sent July 9, 2010 is discovered missing. It contains more than 21,000 electronic images of confidential information about individual birth, death, stillbirth and marriage registrations. It is found Nov. 30, 2010 locked in a rarely-used filing cabinet.
SEPT. 2009: Stats Can library's password access protocol constitutes "major security breach."
DEC. 2008: A briefcase with documents and personal notes is stolen from the car of an interviewer from Quebec. Confidential addresses of respondents were included.
JULY 2008: An error in transmission meant e-mails of 108 subscribers of Health Reports notifications were "inadvertently revealed" to all recipients of message - constituting a breach of Privacy Act and Stats Can policy.
JUNE 2008: Stats Can is informed that on Feb. 12, 2008 Surrey RCMP and Canada Post recovered completed 2006 census questionnaires from a private residence in a bust of a major identity theft ring. Other items included equipment related to credit card/ID theft, drivers' licences, 3,000 pieces of stolen mail, government-issued cheques, fake currency and more than 100 CDs with thousands of personal data profiles. Census questionnaires were not in the hands of census staff - it is believed they were obtained by tipping mailboxes or break-ins to homes and cars.
AUG. 2007: A laptop containing personal information about individuals who participated in the Labour Force Survey or Canadian Community Health Survey is stolen from the residence of an employee in Abbotsford, BC. Password was written on a sticky note stored in laptop case. Police called, affected people are informed and interviewer receives verbal reprimand.
JUNE 2007: Laptop with three completed household spending surveys stolen in home break-in in Delta, B.C.
MARCH 2007: Edmonton regional office reports two laptop thefts from field interviewers' vehicles. Staff are reminded about protocol for securing material.
MARCH 2007: Privacy Commissioner's office advised of inadvertent disclosure and loss of personal info after surplus filing cabinets with Records of Employment about 66 2006 census workers were sold at a Crown Assets Auction in Edmonton. Affected individuals are contacted and Stats Can implements more stringent procedures to avoid a recurrence.
JULY 2006: Enumerator leaves completed questionnaire instead of blank at Scarborough, Ont. respondent's home.
APRIL 2005: Blank forms faxed to a business include additional pages of confidential information related to two other businesses. Staff receive retraining and posters/notices are displayed as reminders.
FEB. 2005: Marketing information collected for one user is reviewed by another user and possibly four other unknown individuals in a Corporations Returns Act survey.
FEB. 2005: Laptop being shipped from Williams Lake, B.C. to Edmonton containing 23 Survey of Household Spending cases - including 11 completed ones - goes missing. A flurry of e-mails ensues among senior managers at Stats Can and officials "pester" Canada Post to find the lost item. Confidential statistical info is encrypted. Laptop is found two weeks later.
Subscribe to:
Posts (Atom)
如果我的心是一朵蓮花
~ 林徽因 · 馬雁散文集 · 蓮燈 ~ 馬雁 在她的散文《高貴一種,有詩為證》裡,提到「十多年前,還不知道林女士的八卦及成就前,在期刊上讀到別人引用的《蓮燈》」 覺得非常喜歡,比之卞之琳、徐志摩,別說是毫不遜色,簡直是勝出一籌。前面的韻腳和平仄的處理顯然高於戴...
-
~ 林徽因 · 馬雁散文集 · 蓮燈 ~ 馬雁 在她的散文《高貴一種,有詩為證》裡,提到「十多年前,還不知道林女士的八卦及成就前,在期刊上讀到別人引用的《蓮燈》」 覺得非常喜歡,比之卞之琳、徐志摩,別說是毫不遜色,簡直是勝出一籌。前面的韻腳和平仄的處理顯然高於戴...
-
在資通訊安全領域,有個源於軍事領域的術語 defense in depth (DID), 在軍事上,DID 是一種 策略 理念,防禦不能只靠一道強大的防線(比如說中國的長城和法國的 Maginot Line ),必須用多層次(multi-layer)、多角度、多點、多面的防...
