Tuesday, October 21, 2008

BlueHat v8 After-Thoughts

Hello everyone, Jeff Forristal here. Last week I ventured over to Redmond to attend BlueHat v8. For those of you unfamiliar with BlueHat, it's Microsoft’s security conference that they put on for their internal developers (and select partners/third-parties). This year was slightly different than years past, as all of the talks were not under NDA. I heard the recorded talks may wind up on Microsoft Technet as public on-demand webcasts, but they haven’t been released to date.

Anyways, I thought I would give you a few interesting highlights and some food for thought. The first comes from the "Crimeware: Behind the scenes" talk given by Iftach Amit of Alladin. Basically the moral to his story is simple: malware is now a business. There is real money to be had; we are no longer dealing with bored teenagers who make viruses simply because they can (well, they are still around too, but they are hardly the majority threat anymore). There is now financial incentive to make better malware, and thus I suspect we are going to start seeing more creative malware tactics in the future. But there were two interesting things I want to point out (derived from information Amit presented). First, the crimeware/malware business model contains strong parallels to online advertising business models—syndication by smaller sites from a large distribution agency, high-value placements on popular/busy web sites, and impression/click tracking. Other than substituting a piece of malware for an ad, it seems everything else is virtually identical between the two models...right down to the tools used, payment relationships, pricing structures, etc. Second, Amit mentioned that his company recovered a log file from a crimeware server that had 200,000+ web site FTP credentials in it. Think about that: 200,000 legitimate web sites that the attackers could arbitrarily change and introduce malware to. This really calls into question the value of web site reputation systems, if reputable websites can be switched over to host malware at a moment's notice. It really doesn't matter if the site was angelic yesterday (or an hour ago) because it can be evil today. Real-time classification and scanning seems to be the burgeoning practical solution.

I was having a discussion with Dave Weinstein, a Microsoft senior security developer, and he made a really good point: making an arbitrary guess, there are how many competent security experts in the world? 5000? He noted that Microsoft alone had ten times that many developers on staff (which I can’t confirm, but I can confirm Microsoft reporting
85,000 certified application developers as of September 2008). It's probably a safe guess to say the number of developers in the world measure in the millions. Overall, this is a really important correlation: the amount of developers in the world outnumbers the amount of security experts by a seriously significant factor. There simply isn't enough security expertise to go around, and so there needs to be investment in making security as distilled and accessible to developers as possible. Mind you, the goal is not to turn developers into security experts...they already have their skill specialty (development), and we should not force them to be dual-specialists (it's just not going to happen for the vast majority). Developers need simple steps and processes for dealing with security that does not require them to thrive in the particulars of security. Which brings me to the second day of BlueHat v8, focused on Microsoft's Security Development Lifecycle.

The day was kicked off with some perspectives on threat modeling. Now, I've done my fair share of threat modeling, and I often find it technically repetitive and numbingly demanding of small nuances to the point of de-motivating me from wanting to do it again. And yet, I was a bit inspired by the way Danny Dhillon described how EMC distilled the threat modeling process to the bare essentials, thus making it more manageable for the average developer. They actually managed to move threat modeling towards a "list of checkboxes" model...which we all know scales much better than an open-ended "just think of all the bad things someone could do to your app" thought exercise. Adam Shostack from Microsoft also demo'ed Microsoft's new version of their internal threat modeling tool—which they plan on releasing to the public eventually (November 2008, if all goes according to plan). It's cool and nifty, but personally I'd really like to get my hands on the EMC tools.

Later in the day a gaggle of Microsoft engineers gave a presentation on the use of fuzzers within Microsoft. I didn't know Microsoft had embraced fuzzers to the level that they have--apparently they have internal SDL mandates to file-format fuzz anything that can read a file...and that encompasses over 300 different file parser components in Vista alone. There is a lot of public opinion by security experts dismissing fuzzing, but I believe that's purely because of fuzzing's no-expertise-required approach and lack of sexiness. The basic fact is that fuzzing, when done correctly, is a simple and inexpensive way to flush out bugs--and it's something that non-security developers can wield and understand. Plus you have to keep in mind that some enterprising hacker type will probably use a fuzzer against your product eventually, so you might as well find the problems before they do. Anyways, Microsoft has committed a lot of internal resources into really streamlining the fuzzing process. They've developed a significant internal suite of fuzzing tools, and they've even done long-term research to determine where the point of diminishing returns lies for their fuzzing efforts. It doesn't seem likely that Microsoft will ever release their fuzzing tools to the world, but it shouldn't be difficult for other organizations to adapt Microsoft's methodology to the plethora of publicly-available fuzzers. A good place to start would be the book
Fuzzing: Brute Force Vulnerability Discovery by Zscaler’s own Michael Sutton (I felt obligated to make a shameless plug on his behalf :).

Overall, BlueHat v8 was a great time (as always). The chance to hobnob with other industry security experts and leaders always yields some insightful takeaways. Personal thanks to everyone at the BlueHat conference...organizers, speakers, and attendees...for making it a pleasant and engaging opportunity to mingle with security-minded peers.

- Jeff

No comments: