Thursday, January 23, 2014

黑客入侵Target窃密 70万加人资料被盗


美国第3大百货连锁店Target于本月初证实﹐遭黑客入侵﹐有7,000万名顾客的个人资料被盗。
昨日该公司向受影响的客户发信﹐其中除了于去年11月27日至12月15日曾过境到美国Target购物的顾客受影响外﹐部分于上述日子未有到美国购物的加人﹐亦接到通知。该公司估计﹐今次事件中约有70万名加拿大人被盗资料。
加拿大Target公司承认﹐部分加拿大顾客的个人资料如姓名﹑地址﹑电邮及电话号码遭黑客窃取﹐但他们的信用卡及银行卡的资料则未受到影响﹐因为在加拿大的Target商店﹐使用付款系统有别于美国。

美 国警方逮捕两名嫌犯﹐两人涉及去年底Target数据失窃案。得萨斯州麦卡伦(McAllen)警局周一展示男子多米尼加国(Daniel Guardiola Dominiguez﹐左)与格雷西亚(Mary Carmen Garcia)的照片﹐两人周日在边境落网﹐执法人员查获96张伪造信用卡﹐不法之徒冒用Target失窃数据﹐制造这批信用卡。(美联社)
Target表示﹐现正陆续通知受影响的顾客﹐并承诺会提供1年免的信用卡监察服务﹐以及其他有关提防被诈骗的贴士。该公司现已聘请第三间机构调查今次事件。 info.51.ca
Target行政总裁Gregg Steinhafel表示﹐给受影响顾客的信件中表示﹐黑客入侵估计偷取了4,000万个信用卡及银行卡帐户资料﹐以及7,000万个顾客的个人资料。但受牵连的加人占总人数不足一成﹐数目料少于70万人。
在美国﹐警方相信早前美国Target顾客个人资料被盗后﹐已被不法之徒分拆﹐并卖往不同的地区。美国南得萨斯州便拘捕了两名墨西哥男女﹐并在他们身上搜出96张假信用卡。 无忧资讯
两人利用假信用卡在全国各地的连锁店购物逾万元﹐当他们于周日早上欲重新进入美国境时被捕。 无忧资讯
旗下拥有Marshall﹑T.J. Maxx及Winners的TJX Cos.﹐早于2005年7月﹐亦有4,750万个信用卡及银行卡帐户资被盗﹐事件直至2006年12月才被发现。直到2009年﹐该公司须支付975万元摆平事件﹐但他们仍坚持自己未有违反资料保安法。

泄62万病人资料 阿省卫生厅4月后才知

泄62万病人资料 阿省卫生厅4月后才知

阿尔伯塔省卫生厅长霍恩(Fred Horne)周三说﹐1部手提电脑被盗﹐里面储存62万名病人的重要资料﹐事件4个月前发生﹐现在才向卫生厅报告﹐他实在“冒火”。
事件4个月前发生
病人资料包括﹕未经加密的姓名﹑出生年月日﹑医疗卡号码﹑帐单代码﹑帐单款额﹑诊症代码﹐所有病人在2011年5月2日到2013年9月19日期间﹐曾在全省各地的Medicare诊所看病。
霍恩指出﹐手提电脑在9月26日失窃﹐数天后﹐诊所经营者向阿省隐私专员克莱顿(Jill Clayton)和爱蒙顿警方报告﹐亦即10月1日。
阿省卫生厅长霍恩在省议会记者会上。
他又说﹐他和卫生厅到周二才获悉此事﹐他收到Medicentres公司副总裁的信。
霍恩在省议会记者会上表示﹕“作为本省居民的代表﹐我实在冒火﹐这样的事情早该报告﹐通知我或我的部门。
“阿省这样的一个省发生这样的事情﹐我认为难以置信。”
霍恩说﹐他要求克莱顿依据《医疗信息法》(Health Information Act)调查此事﹐找出真相﹑研究有没有触犯隐私条例。
Medicentres公司经营一连串家庭医生诊所﹐它的新闻稿说﹐迄今没有发现证据﹐证明有人套取或盗用失窃手提电脑的资料﹐但它敦促病人查看银行和信用卡帐单。
它说﹐案发以来﹐已有升级保安措施﹐还有审计﹐以保证保安措施更完善。
公司声明说﹕“我们向所有病人道歉﹐这次(保安问题)可能引起的忧虑。”
媒体问隐私专员﹐为何隐私专员办公室不在去年秋天通知厅长办公室﹐隐私专员办公室守纪与特别调查总监哈密尔顿(Brian Hamilton)解释说﹐法例规定克莱顿只能通知信息直接牵连的一方。
哈密尔顿说﹕“我们的做法﹐不会通知厅长﹐除非保安事件涉及该厅信息系统。”
他指出﹐克莱顿最早周四决定﹐是否启动调查。 - 多伦多 51 网

Tuesday, January 21, 2014

Security Framework Industry Standards


  • ISO 27001/27002 
  • NIST SP 800-53 
  • SOX 
  • PCI




Compliance != Security





The Security Framework for Information Technology

The Security Framework for Information Technology
Most of the damage to Information Technology (IT) security is not from outside malicious attacks, but rather from simple mistakes, unintended or unauthorized actions of legitimate users and IT engineers who are either untrained in security and/or who misunderstood the instructions from the management.
The two major issues mentioned replay themselves daily in the IT world.  Part of the reason this is happening is a lack of common, proven practices and guidelines developed for IT professionals.  Unlike the legal, financial, and medical fields, the IT field is still somewhat in its infancy. It has yet to develop the kind of respect from the business community that legal, financial, and medical professionals enjoy, despite the fact that IT professionals are increasingly tasked to handle and protect the core values of the organization—data and information that legal, financial, medical professionals, and management depended on.
There is no question how important the IT department is for any organization.  So what are the issues when it comes to poor security in most IT operations? Here are the main issues that I see:
Management vs. System users vs. IT professionals
No one needs to tell a brain surgeon what procedures to follow to perform an operation.  No one tells a Certified Public Accountant (CPA) how to conduct an audit for financial matters, and no one needs to ask an attorney to maintain attorney-client confidentiality during a trial.  And yet, when it comes to IT security, management, system users, and IT professionals are often at odd as to what is the best course of action in response to a given security concern.  The three groups almost always have their own ideas of how the security should function, when sometimes at least one, or two, or all three groups do not understand each other.  Even worse still, sometimes they don’t understand the security issues involved or the remedies available.  Management usually understands the high-level issues; users generally want convenience; and IT of course wants to please the first two while still doing their job.  However, they all do not have a common framework to follow, and most do not have a common policy to follow.  To make matters worse, everyone believes their way is the best, regardless of the real over-riding issues.
Standards
There is a total lack of standards when it comes to IT security.  As mention above, all three stakeholders have their own ideas regarding what the standards are.  And the three groups may even change the standards from time to time in response to a given situation, even though next time around it could be different.  Things are done to solve an “urgent” issue with an intention to revisit the actions taken later, when the urgency is over.  We all know how that goes.
Complexity of the Information Technology
Supporting the current IT infrastructure is exponentially more difficult than it was ten years ago.  While supporting the hardware aspect of IT has gotten dramatically easier, supporting the rest of the IT infrastructure is much more difficult today than it was in the past.  Most management and system users do not appreciate how difficult is to keep the IT operation running smoothly.  Management as well as system users only see the front end of the IT system; it is all Windows, GUI, point and click—but at the back end, IT is facing increasingly complex configurations and environments to make everything work.  Nearly all Operating Systems and most applications today use different security standards.
Consistency
Until just a few years ago, there was not a concerted effort in the IT industry and among IT professionals to focus on security. Even most training focuses on a micro-level that is specific to the given products and at times, a given task.  Very few IT professionals have a comprehensive knowledge of all the levels of IT security necessary for them to be able to perform their job consistently, each and every time.  Without a high-level IT security framework and/or IT security policy, the security tasks will be performed by an individual IT professional based on his or her unique experience. The results are often mixed and may or may not even be desirable. At best, even if the security tasks are performed by the same individual, the results can be inconsistent.
Policy
Most of the organizations today either still do not have a well defined security policy or none is ever developed at all.  Where there is  a comprehensive security policy, it is not well communicated and /or enforced because it lacks high-level framework to guide it.  Very often the policies address security issues at a micro-level that are hard for management, system users, and IT professionals to understand or enforce consistently.  For the organization that has a well defined security policy, very often there is not a well trained team (a workable team has to be composed of all stakeholders) to enforce and fine-tune it, and over time the system breaks down.
Framework
For an IT security system to work, more needs to be done.  A well defined framework needs to be developed involving all stakeholders, and it needs to be self-tuning over time to be useful.  Almost all of the organizations today stop short of having a good framework to enforce and fine-tune the IT security system.  Most understand the need for a well defined security policy, but unfortunately, most stop there after they have developed one.
Below is a high-level view of the Security Framework™ developed by Triware Networld Systems:

Training
One major difference between traditional, well respected professionals such as Medical Doctors, CPAs, Attorneys and the IT practitioner is the IT practitioners’ lack of a structured approach to learning their trade.  There is not a well defined curriculum developed for people who intend to go into IT fields.  Most IT trainings are mainly focused on product-specific and commercial aspects of the subject matter, combining marketing and product promotion as part of the training.  Traditional curricula that produce the skills demanded of most computer programmers and engineers are not suitable for keeping up with today’s IT demands.
In conclusion, in order for any IT security system to work, a well defined, organization-wide security framework needs to be implemented that involves all stakeholders, and the framework needs to be part of the organization’s core operations—its DNA— at all levels of the organizational structure.

Wednesday, June 19, 2013

Nice Visio Draw for Dual Cluster Network Devices (Firewalls, Routers, Switches)


There are two External Firewalls and Two Internal Firewalls. Between them, there are two different zones connected, web DMZ zone and mail DMZ zone.

10 Suggestions for how to be a successful Network Consultant

Having spent over twenty years in I.T. and over seventeen years in networking, Iíve worked with a lot of Network Engineers. Career progression has always been a hot topic. Iíve always been interested in learning how people have found themselves in the job they now do.
Until the Cisco certification bandwagon really got going about twelve years ago, there was very little structure in the profession of ëNetwork Engineerí. People tended to be measured on the manufacturer courses theyíd attended and the bragging they did about the networks theyíd designed, fixed or broken. I was always more impressed with the size of the broken networks. Anyway, now, thanks to Cisco Career Certifications we have a method of ëmeasuringí peoples networking ability which other networking vendors have copied. However, speaking as someone who regularly hires Network Engineers, youíre going to need a bit more than a freshly printed CCNP certificate to convince me that you should be let loose on our customerís networks.
The goal of most Network Engineers I meet or interview is to become a Consultant. Usually their motivation is ëcareer progressioní which will lead to better salaries and enhanced recognition amongst their peers. Often, having the title ëConsultantí is more important than being a consultant. Most people understand that there is no short-cut or boot-camp that will make you a consultant; itís a combination of knowledge, experience and good judgement.
Here are ten things that Iíve learnt and that I will think will help any Network Engineer develop towards being a consultant.
1. Assume you know nothing and take time to understand your customer. Listen to your peers, listen to your customers learn from their experiences. There is always someone who knows more than you and he/she maybe across the table from you listening to your ëdrivelí. Understand your customer, understand their needs, understand their frustrations, understand their motives and understand their skills. Listen to what they have to say and try to empathise with their problems. Generally Networks are built to enable business, make sure you understand that business.
2. Develop your soft skills. Consultancy is about communicating your ideas and opinions. A lot of great ideas have been lost because of a failure to communicate them. Learn to use Visio (or whatever drawing package youíre comfortable with) time spent learning to use the many features of Visio is never wasted. Also learn to use Word, Excel and PowerPoint (please, please donít start arguing the merits of open source software and explaining that Microsoft is Satan come to Earth in a software format; youíre here as the network guru, remember). When you have to present your findings or communicate your ideas, think carefully about how you are going to do it. A picture or graph is generally better than a 100 words. Understand your audience and be aware of their attention span.
3. Learn to write Management Summaries. Why? Because managers make decisions, I’m sorry thatís generally the case in most organizations. They hold the purse strings, are very busy and donít always have time to read your 56 page analysis of why migrating to OSPF from EIGRP would be a really cool thing to do. Itís a sad fact of the ëcomputer ageí that peopleís (especially managerís) attention spans have shortened due to information overload. They tend to read the beginning and the end of a proposal and ëskim readí whatís in between. Think of the Management Summary as a trailer to a movie, a good Management Summary will get the reader interested and read more of the document. If you want to convince someone to take a course of action then the Management Summary is the place to focus onÖ.. Sad but true.
4. First impressions do count. Whilst a freshly printed CCXP certificate may impress your mates and your Mum, it wonít impress your average IT Manager whoís network is in meltdown. His first impression of you will be what you look like or what you sound like. So make it count. Listen to what they have to say and choose your first words carefully. Acting like an expert is a lot easier than sounding like an expert, try and keep the impression going for as long as possible.
5. Donít alienate anyone. Generally IT projects or major troubleshooting events involve people from various aspects of I.T. as well as the ëvictimsí from the Business. They all have an opinion and they are all generally experts in their own areas. Respect their knowledge. They may be bigoted, opinionated and anti-networking, but it is your job to gently show them the error of their ways and guide them to the path of enlightenment regarding TCP/IP. Plus the fact, it may actually be the network at fault and you may end up needing their help.
6. SNMP Management, Syslog Collectors and Packet Sniffers. Learn how to really use these tools. SNMP runs on almost everything in the network and itís just sitting there with the answer to a lot of problems. You just need to know how to pose the right question. Analysing syslog messages takes time and requires patience but it often helps uncover the cause of a problem. Having WireShark on your laptop is all very well, but do you know how to write filters, use regular expressions and follow a TCP conversation?
7. Fix the cause and not just the symptoms. When troubleshooting your goal should always to understand what caused the problem and how it can be avoided in the future. Any fool can clear up an oil leak, but it takes skill to stop the leakÖ. And even more skill to preventing it happening in the first place.
8. Document everything. When troubleshooting, if you donít fix it after your first tracert, then get out the notebook and start drawing diagrams, noting down changes and recording when things happen. When youíre designing a network make sure you get all the information together in one place. Requirements, performance information, data sheets, test results, etc. It may be you that has to come back to fix it or upgrade it.
9. Only use agencies as a last resort and write good covering letters. When you feel the need for a new job then do your research, pick the industry, location and environment carefully. Take time to write customized covering letters for your cv. Remember, to a Recruitment Agent you are worth between 12 – 20% of your Year 1 salary, so most of them would have no qualms about putting you in a Russian Gulag if they happened to be paying well. Approaching a prospective employer direct shows initiative and can save them a lump of cash. Make sure you understand their business.
10. Stick to Networking. If a customer tells you that their marketing department have decided texting is going to be the start of whole new social networking paradigm, then just agree with them and build the network. Remember, we are Networking Gods not Marketing Guruís.

Three Layer Designed vs Layer 2 MultiPath Design

 data centre designs shifting from “North-South” type designs to “East-West-North-South”

Explaining L2 Multipath in Terms of North/South, East West Bandwidth

In a number of Packet Pushers episodes, I’ve been referring to the nature of the data centre designs shifting from “North-South” type designs to “East-West-North-South”. Lets dig into this terminology a bit and show us

Spanning Tree is always North / South

I’m reasonably confident that most people who read this will comprehend how a switching network will use spanning tree to create a TREE.
North south east west 1
It will look something like this where the sore switches are configured to act as the ‘root’ of the spanning tree, and traffic flows to core to the edge. More correctly, traffic always flows from edge to core to edge and always in a fixed direction. Because we tend to draw the core at the top of the diagram, and shows connections to the distribution and access layers as connecting down the hierarchy, we tend to see a ‘top to bottom’ or north-south distribution of data traffic flows.
Where this model fails, is that bandwidth between servers that are on two branches must cross the core of the network as shown in this network diagram.
North south east west 2

The Weakness is the Core Switch Interconnect

The challenge with this is that the connection between the core switches can become heavily overloaded, especially in networks where the server fanout is large and commonly occurs in heavily virtualised network. To some extent, this is a new problem. Previously, the core switches would be interconnected with an EtherChannel that would provide multi-gigabit connectivity, and recently we saw the introduction of 10GbE ports which allowed for further increases in the core capacity.
Now that servers are connected and 10GbE, and the addition of storage data means that sustained traffic flows have increased, and not just by twenty or fifty percent. Storage data (whether iSCSI, NFS or even FCoE) means that these designs won’t last much longer.
Currently, it’s convention to locate the storage arrays close to the core network switches so as to reduce the workload in the branches of the tree which isn’t a bad strategy. But this doesn’t account for the East-West migration of virtual machines.

Layer 2 Multipath Switch Networking

Layer 2 Multipath (L2MP) refers to the recent developments in Data Centre networks where the core switch can no longer handle all the load. That is, if you have a three hundred physical servers and each physical servers hosts twenty virtual machines, then the gross data load including storage traffic will easily exceed the interconnect. We talk about the development of data centre models that support east-west traffic flows.
North south east west 3
In this type of design, we can see that a L2MP core, regardless of the type – Big Brother or Borg style, means that bandwidth does not choke around any specific point in the network. So not only does the network support the traditional North/South bandwidth alignment that we have today, which creates artificial limits on how we can locate and distribute servers inside existing data centre networks, we are now able to provide East/West bandwidth to support loads that are dynamically moved around the data centre with a lesser degree of concern for key choke points that exist in legacy designs.
This especially applies to converged network where the storage data creates new loads that increase the sustained usage of the Ethernet network.

Scale

Also, because hot spots can exist in the network core as traffic loads migrate around the network edge points, the L2MP allows for additional connections to be added as needed. Note that adding does not have the potential service impact and risk profile that making changes to spanning tree presents. Therefore, the network becomes more flexible (or less “crystalline” is the term that I use).
North south east west 4
Note that the terms Borg and Big Brother are fully described inhttp://blog.ioshints.info/2011/03/data-center-fabric-architectures.html blog post from Ivan Pepelnjak.

The EtherealMind View

It’s worth noting that these changes are key to successfully addressing the networking requirements for virtualisation. Hopefull this helps to explain some of the reason that new switch architectures from Juniper and Cisco that relate to Fabric networking are important.

Bisectional Bandwidth

It’s worth noting that this problem is also related to the topic of Bisectional Bandwidth and the measurement of the server to server bandwidth as a function of the architecture. I wrote about this in this blog post : http://etherealmind.com/bisectional-bandwidth-l2mp-trill-bridges-design-value/