<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2018-06-27T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/atom.xml</id>
    <entry xml:lang="en">
        <title>Emerging Cyber Ranges: Competition to Compliance</title>
        <published>2018-06-27T00:00:00+00:00</published>
        <updated>2018-06-27T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/"/>
        <id>https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cyber-ranges-sans-with-script/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons SANS @ Night presentation Emerging Cyber Ranges: Competition
to Compliance, delivered on June 27, 2018, explores how purpose-built
environments can accelerate offensive and defensive security practice, foster
competitive e-sports, and underpin formal compliance and product validation
efforts .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cyber-range&quot;&gt;Cyber Range&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon defines a cyber range as any isolated, refreshable networkvirtual
or physicalused to detonate malware, test exploits, or simulate advanced
threats. He surveys existing platforms from SANS NetWars (both virtual
challenges and the physical CyberCity model) to JYVSECTECs SCADA-focused ranges
and the Michigan Cyber Range, and even the DARPA-led National Cyber Range. Each
example illustrates how controlled environments enable realistic training,
product proof-of-concepts, and large-scale team competitions without risking
production assets .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;principles-to-proof-of-concept&quot;&gt;Principles to Proof of Concept&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the talk shifts to design principles and hands-on constructs. Harmon
outlines key requirementscontainment, auto-scaling, encrypted peer tunnels,
explicit authorization, rapid restoration, and portabilityand presents a
Raspberry Pi-based proof-of-concept leveraging OPNsense, HardenedBSD routing,
iPXE booting, and YubiKey-backed hardware security modules. He also covers
adversary simulation using MITRE CALDERA, Uber Metta, and Netflixs Simian Army,
and shows how cyber ranges can be woven into compliance lifecyclesfrom
requirements gathering through vendor evaluation, baseline verification, and
resilience testingtransforming these playgrounds into governance-grade testbeds
.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;58296_2018-06-27_Cyber_Ranges-SANS_with_Script.pdf&quot;&gt;Cyber Ranges,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Internet of Everything: Hands-On Cyber Security</title>
        <published>2017-06-21T00:00:00+00:00</published>
        <updated>2017-06-21T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/"/>
        <id>https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/internet-of-everything-hands-on/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night Internet of Everything workshop on June 21, 2017, by Matthew J.
Harmon frames the cybersecurity challenges posed by a rapidly expanding
landscape of interconnected devices and emphasizes why smart often means
exploitable.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;legal-hurdles&quot;&gt;Legal Hurdles&lt;&#x2F;h2&gt;
&lt;p&gt;Harmon begins by unpacking the legal hurdles around IoT security research
including reverse-engineering restrictions and patent ambiguities and uses an
analogy to routine maintenance to stress the need for continuous device hygiene.
He then quantifies the IoT explosion (8 billion connections in 2016 per Cisco,
460 million responsive IPs in the Carna botnet census) and surveys Shodans index
of exposed smart endpoints. Drawing on the OWASP IoT Attack Surface model, he
breaks down exploitable vectorsdefault credentials, unencrypted data flows,
firmware backdoors, sensor privacy leaksi and poses probing questions (e.g., Is
your dishwasher a web-server?) to underline the urgency of visibility and risk
awareness.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;hands-on&quot;&gt;Hands-On&lt;&#x2F;h2&gt;
&lt;p&gt;In the hands-on segment, participants build a known state monitoring stack:
deploying Security Onion for network visibility; integrating Darkstat and ntopng
for passive traffic analysis; and using Bro for protocol inspection, alongside
OSSEC and Sysmon for host telemetry. Harmon extends the lab with DCIM&#x2F;IPAM via
NetBox and leverages MITREs Cyber Analytics Repository (CAR) and ATT&amp;amp;CK
frameworks to detect lateral movement and prune low-hanging IoT risks. Through
systematic enumeration of devices, data stores, and normal traffic baselines,
the workshop demonstrates how comprehensive visibility transforms an
overwhelming IoT attack surface into manageable, proactive security controls.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57925_2017-06-21_MJH_Internet_of_Everything-SANS.pdf&quot;&gt;SANS @ Night: Internet of Everything
Workshop&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence and Baselining</title>
        <published>2016-07-20T00:00:00+00:00</published>
        <updated>2016-07-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night session Threat Intelligence: Neighborhood Watch for Your
Networks &amp;amp; Why Baselining Matters, delivered by Matthew J. Harmon on July 20,
2016, explores how integrating crowdsourced Indicators of Compromise (IoCs) with
rigorous network baselining practices equips defenders to spot, prioritize, and
respond to threats before they escalate .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;state-of-cyber-security&quot;&gt;State of Cyber Security&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon frames the state of cybersecurity emphasizing that breaches are
inevitable against motivated adversaries and introduces the fundamentals of
threat intelligence. He walks through the CIAs 15 Axioms for Intelligence
Analysts, defines IoC types (DNS hosts, IPs, URLs, file hashes), and outlines
the CybOX, STIX, and TAXII standards for packaging and exchanging structured
threat data. A real-world case study shows how to trace a Dyreza banking-trojan
infection from anomalous traffic to phishing emails, package findings into a
STIX header, and share via TAXII. Harmon then compares commercial and
open-source intelligence feedsi ThreatConnect for expert-curated data and
CriticalStack Intel for aggregated TSV-formatted IoCs demonstrating how
organizations can leverage these resources for timely, actionable insight.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;baselining&quot;&gt;Baselining&lt;&#x2F;h2&gt;
&lt;p&gt;Next, the presentation pivots to the critical role of baselining: defenders must
know their normal network behavior to detect deviations. Harmon introduces key
open-source tools Bro (for traffic analysis), PRADS (for asset discovery), SGUIL
(for alert management), and LOKI (for IOC scanning)and shows how they integrate
within the Security Onion distribution. He provides a do-it-yourself lab
outline: install Security Onion, subscribe to CriticalStack feeds, configure Bro
and YARA rules, and deploy a network tap for continuous monitoring. By combining
structured threat intelligence with continuous baselining, organizations can
proactively identify both emerging campaigns and internal anomalies,
dramatically improving detection and response capabilities.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;2016-07-20_Threat_Intelligence_and_Baselining-SANS.pdf&quot;&gt;Threat Intelligence and
Baselining&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence 101: Introduction and Foundations</title>
        <published>2015-10-20T00:00:00+00:00</published>
        <updated>2015-10-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-101/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-101/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-101/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Cyber Security Summit 2015 presentation Threat Intelligence 101:
Introduction and Foundations by Matthew J. Harmon provides an entry level
overview of the role and practice of cyber threat intelligence (CTI). Harmon
begins by framing the inevitability of breaches citing high-profile incidents,
and the principle that attackers need only one success, then introduces CTI as
the structured collection and sharing of Indicators of Compromise (IoCs)
enriched with context to support detection and response.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;foundations&quot;&gt;Foundations&lt;&#x2F;h2&gt;
&lt;p&gt;He then explains the foundational CTI standards, CybOX (the vocabulary of
observables), STIX (the XML based language for packaging observables into
indicators, incidents, TTPs, and courses of action), and TAXII (the protocol for
exchanging STIX packages) and walks through a real-world example: from spotting
anomalous server traffic to extracting email, hash, IP, and URL indicators;
packaging them into a STIX header; and sharing via TAXII to uncover a broader
campaign.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;diy&quot;&gt;DIY&lt;&#x2F;h2&gt;
&lt;p&gt;Finally, Harmon showcases two CTI platforms ThreatConnect (expertcurated
CybOX&#x2F;STIX feeds) and CriticalStack Intel (aggregated open-source IoCs in TSV
for Bro integration) and outlines a hands-on lab using Bro or Security Onion and
CriticalStack feeds. This culmination demonstrates how organizations can do it
themselves by deploying free tools, subscribing to feeds, automating IoC
ingestion, and participating in community-driven neighborhood watch initiatives
to elevate their collective security posture.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57315_2015-10-20_Threat_Intelligence_Intro_And_Foundations-CSSummit.pdf&quot;&gt;Threat Intelligence
101&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence: Neighborhood Watch for Your Networks</title>
        <published>2015-07-23T00:00:00+00:00</published>
        <updated>2015-07-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night session Threat Intelligence: Neighborhood Watch for Your
Networks by Matthew J. Harmon introduces the concept of crowdsourced cyber
threat intelligence as a critical component of modern defense. Harmon defines
threat intelligence as the collection of Indicators of Compromise, DNS hosts, IP
addresses, email addresses, URLs, and file hashesi, enriched with contextual
information about campaigns, tactics, techniques, and procedures (TTPs) to
produce actionable insights. He stresses that confidence in data varies from
unvetted open-source feeds to expert-curated platforms and that standardized
formats like CybOX for observables, STIX for structured information, and TAXII
for automated exchange enable seamless sharing across organizational boundaries.&lt;&#x2F;p&gt;
&lt;p&gt;Through a step-by-step case study, Harmon demonstrates how to apply these
standards in practice: identifying excessive traffic on a server, back-tracing
it to a phishing email with a malicious ZIP attachment, extracting MD5 hashes
and C2 IPs, and packaging them into a STIX header with appropriate Course of
Action blocks. He then compares two data-sharing solutions: ThreatConnect, which
offers high-confidence, expert-vetted intelligence via CybOX&#x2F;STIX&#x2F;TAXII; and
CriticalStack Intel, which aggregates over a hundred open-source IoC feeds in
simple tab-separated values for rapid integration with Bro (the network analysis
framework). To reinforce the concepts, Harmon outlines a hands-on lab deploying
Bro or Security Onion, subscribing to Intel feeds, and using bro-cut to validate
detectionsunderscoring the power of a community-driven neighborhood watch to
elevate collective security posture.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57226_2015-07-23_Threat_Intelligence_Neighborhood_Watch-SANS.pdf&quot;&gt;Threat Intelligence: Neighborhood Watch for your
Networks&lt;&#x2F;a&gt;
&lt;a href=&quot;&#x2F;attachments&#x2F;57925_2017-06-21_MJH_Internet_of_Everything-SANS_Script.pdf&quot;&gt;Threat Intelligence: Neighborhood Watch for your Networks,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Taking Control of IT Operations through the Critical Security Controls</title>
        <published>2015-06-01T00:00:00+00:00</published>
        <updated>2015-06-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/"/>
        <id>https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/taking-control-with-critical-security-controls-csooutlook/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The CSO Outlook article Taking Control of IT Operations through the Critical
Security Controls by Matthew J. Harmon explains how embedding the first five of
the SANS&#x2F;CIS 20 Critical Security Controls into everyday IT processes can
transform security from a reactive cost center into a proactive, measurable
discipline.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;starting-easy&quot;&gt;Starting Easy&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon shows that many breaches start with unknown or low-priority
systems, devices and software not inventoried or patched. Controls 1 (Inventory
of Authorized and Unauthorized Devices) and 2 (Inventory of Authorized and
Unauthorized Software) create visibility by correlating DHCP, ARP, and DHCP
assignments for hardware and using WMIC, RPM&#x2F;APT, or SCCM to catalog installed
applications. This foundational inventory maps assets to owners, enables
application whitelisting, and allows organizations to detect unauthorized
additions before attackers can pivot.&lt;&#x2F;p&gt;
&lt;p&gt;Next, the article tackles Controls 3 through 5: secure configurations,
continuous vulnerability assessment and remediation, and malware defenses.
Harmon advocates applying vendor and CIS hardening guidelines via Group Policy
Objects or configuration-management tools (Puppet, Chef), enforcing a 48-hour
patch window for critical flaws through tiered testing and deployment, and
layering defenses beyond antivirus, such as host firewalls, DNS filtering (e.g.,
OpenDNS), and threat-intelligence driven proxies. He concludes by recommending a
gap assessment against the remaining controls and a phased implementation
roadmap to embed these practices into routine IT operations and gauge their
impact over time .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57174_2015-06-01_Taking_Control_with_Critical_Security_Controls-CSOOutlook.pdf&quot;&gt;CSO Outlook: Taking Control of IT Operations Through the Critical Secuity
Controls&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>State of Cyber Security</title>
        <published>2015-05-07T00:00:00+00:00</published>
        <updated>2015-05-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/fuel-pan/"/>
        <id>https://blog.itys.net/vol1/posts/fuel-pan/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/fuel-pan/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Minneapolis Chapter Palo Alto Networks Fuel Users Group Meeting on May 7,
2015, opened with a sobering overview entitled State of Cyber Security,
underscoring that breaches are not a question of if but when. Drawing on
cultural touchstones from Sesame Streets Oscar the Grouch to BBCs Moriartyi the
presenter highlights that even simple lapses (like exposed post-it note
credentials) can enable attackers and that motivated adversaries will exploit
both technical and human weaknesses.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;hard-data&quot;&gt;Hard Data&lt;&#x2F;h2&gt;
&lt;p&gt;The bulk of the talk reviewed hard data from the 2015 Verizon Data Breach
Investigations Report, detailing 2014s most significant incidentsranging from
Neiman Marcuss 350,000 records to JP Morgan Chases 76 million households and
cataloged threat sources, attack vectors, and time-to-compromise metrics. This
context stressed that organizations must evolve beyond perimeter defenses and
adopt proactive monitoring, rapid patching, and layered controls to limit dwell
time and impact.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;information-sharing&quot;&gt;Information sharing&lt;&#x2F;h2&gt;
&lt;p&gt;In response to these challenges, the presentation pivoted to the power of shared
intelligence. It outlined the founding of the NorSec ISAO under recent executive
orders, described opensource feeds (APTnotes, ShadowServer, REN-ISAC CIF), and
defined Indicators of Compromisefrom DNS hosts to file hashesemphasizing that
crowd-sourced, expert-vetted threat data is essential for timely detection.
Finally, it showcased Palo Alto Networks solutions WildFire for sandbox analysis
and Traps for endpoint exploit preventionas integral tools for automating IoC
blocking and closing the gap between discovery and defense.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57149_2015-05-07-FUEL_PAN_UG.pdf&quot;&gt;State of Cyber Security 2015&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>ACM Club Cyber Security Workshop</title>
        <published>2014-04-09T00:00:00+00:00</published>
        <updated>2014-04-09T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/keynote-acm-club/"/>
        <id>https://blog.itys.net/vol1/posts/keynote-acm-club/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/keynote-acm-club/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons ACM Club Cyber Security Workshop, presented at Saint Paul
College on April 9, 2014, frames the modern cybersecurity landscape as a
high-stakes arena where adversaries backed by virtually limitless R&amp;amp;D budgets
that need only exploit a single vulnerability to wreak havoc. Through vivid
attack-map visuals and a rundown of headline-grabbing breaches, Harmon drives
home that traditional defenses alone are no longer sufficient.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;threat-environment&quot;&gt;Threat Environment&lt;&#x2F;h2&gt;
&lt;p&gt;He first surveys the threat environment: adversaries overcapitalization, the
evolution from amateur pranks to organized extortion campaigns, and real-world
DDoS, data-exfiltration, and malware incidents (Adobe, Heartland, Target, and
more). Harmon then flips the narrative to the defenders advantage akin to
knowing ones own network, deploying active defenses (honeypots, fake devices),
and leveraging tools like the Active Defense Harbinger Distribution to
illustrate how preparedness and ingenuity can tip the balance in favor of the
good guys.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cyber-security-as-a-career&quot;&gt;Cyber Security as a Career&lt;&#x2F;h2&gt;
&lt;p&gt;Building on these insights, the workshop explores cybersecurity as both a career
path and a community mission. Harmon traces the evolution of security roles from
SysAdmin beginnings to specialized certifications and scripting-driven
administration with Ansible, Puppet, and Chef, highlighting the explosive demand
and near-zero unemployment in the field. He closes with a rallying call for
collaboration across ACM, ISSA, (ISC)2, and other groups, urging attendees to
unite under a trust but verify ethos, prepare for emerging IoT threats, and
drive resilient computing initiatives in their organizations and beyond.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57121_2014-04-09_ACM_Club_Keynote.pdf&quot;&gt;ACM Club Keynote&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>DDoS Survival</title>
        <published>2013-10-18T00:00:00+00:00</published>
        <updated>2013-10-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/ddos-survival-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmon and Phil Reno present at the (ISC)2 Twin Cities Area Chapter
on DDoS Survival, delivered on October 18, 2013, provides a comprehensive primer
on Distributed Denial of Service (DDoS) attacks and how organizations can
withstand and mitigate them. It begins by defining DDoS as resource exhaustion
aimed at disrupting servicesand tracing its roots from IRC-driven pranks to
sophisticated protest and extortion campaigns.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;threats-and-attack-techniques&quot;&gt;Threats and Attack Techniques&lt;&#x2F;h2&gt;
&lt;p&gt;The first section surveys real-world threats and attack techniques. The
presenters highlight notable incidents such as Anonymous&#x2F;AntiSec campaigns and
itsoknoproblembro browser-based botnets and reference data on rising attack
volumes from sources like Arbor Networks. They categorize attack vectors across
the OSI stack (TCP&#x2F;SSL floods, HTTP-level assaults like Slowloris and
chunked-header exploits, and ICMP&#x2F;UDP floods) and assess attacker skill levels,
from low-effort LOIC&#x2F;XOIC scripts to more advanced injection-driven browser
botnets.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense-and-resilience&quot;&gt;Defense and Resilience&lt;&#x2F;h2&gt;
&lt;p&gt;The second section focuses on defense and resilience strategies. Harmon and Reno
outline four architectural approaches: ISP-level scrubbing, Cloud SOC via
proxy&#x2F;DNS redirection, full-service cloud scrubbing with BGP rerouting, and
in-house solutions. Detailing the pros and cons of each. They emphasize risk
transference through CDNs and anti-DDoS services, null-routing tactics, and
bigger pipes, supplemented by application-level tweaks. The presentation
concludes with guidance on selecting providers (key questions on SLAs,
mitigation capabilities, and cost structures), proactive load testing, and
leveraging automation tools (Chef, Puppet, Ansible, SaltStack, Fabric) to scale
and verify infrastructure readiness under attack.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56583_2013-10-18_DDoS_Survival-ISC2TC.pdf&quot;&gt;DDoS Survival&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Cloud Security</title>
        <published>2013-06-18T00:00:00+00:00</published>
        <updated>2013-06-18T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/"/>
        <id>https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/cloudsecurity-isc2tc/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The (ISC)2 Twin Cities Area Chapter presentation Cloud Security by Matthew J.
Harmon at the 2013 Annual Meeting introduces the fundamentals of virtualization
and cloud computing, emphasizing both their transformative potential and the
security considerations they entail.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;cloud-technology&quot;&gt;Cloud Technology&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon unpacks virtualization basics like defining hypervisors (Type 1
and Type 2), guests, and core virtualization architecturesand maps these
concepts onto cloud service models such as Software-as-a-Service (SaaS),
Infrastructure-as-a-Service (IaaS), and Anything-as-a-Service. He highlights key
benefits including server consolidation, rapid provisioning and decommissioning
of resources, auto-patching and silent upgrades, reduced operational overhead,
and the ability to harvest processing power on demand. This framing positions
cloud computing as a natural extension of traditional virtualization that
delivers scale, flexibility, and cost efficiency.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-and-privacy-risks&quot;&gt;Security and Privacy Risks&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation shifts to the security and privacy risks inherent in
cloud environments. Harmon details confidentiality challenges in multi-tenant
platformswhere co-located data often lacks provider-managed encryption and
availability threats stemming from service outages, contractual lock-in, or
disputes with providers. He also addresses integrity risks due to limited
transparency into vendor operations and the potential for insider threats. To
mitigate these issues, he advocates a trust but verify approach: enforce
end-to-end encryption (in transit, processing, and at rest), conduct rigorous
vendor audits, codify security requirements in contracts, and maintain
continuous risk assessments to ensure that cloud-hosted assets remain under
organizational control and resilient against data breaches.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56461_2013-06-18_CloudSecurity-ISC2TC.pdf&quot;&gt;Cloud Security&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Java Exploits: Offense and Defense</title>
        <published>2012-10-24T00:00:00+00:00</published>
        <updated>2012-10-24T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/java-exploits/"/>
        <id>https://blog.itys.net/vol1/posts/java-exploits/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/java-exploits/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;Matthew J. Harmons (ISC)2 Twin Cities Chapter presentation Java Exploits:
Offense and Defense, delivered on October 24, 2012, examines the pervasive risk
of client-side Java vulnerabilities and outlines why these flaws represent a
critical attack vector for organizations. Harmon, drawing on his two decades of
security experience, highlights how the Java sandbox can be bypassed via
reflection and code injectiondemonstrated by high-impact exploits documented by
researchers like Joshua Drake and Adam Gowdiakand underscores the urgency of
addressing these pervasive weaknesses.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;The talk begins by quantifying the threat: in 2012 alone, 23 out of 50 Oracle
JRE vulnerabilities carried a CVSS score of 10, signaling complete system
compromise without authentication. Harmon dissects sample exploit code that
disables the Java SecurityManager by injecting an AllPermission-granted
ProtectionDomain, illustrating how easily an attacker can escalate privileges.
He reviews major sandbox escapes and stresses that patch cycles alone cannot
keep pace with adversaries who weaponize newly discovered flaws .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h2&gt;
&lt;p&gt;To counter these risks, Harmon presents a two-pronged defense strategy. On the
technical side, he advocates strict whitelisting of Java applets via Group
Policy, Click-to-Run settings in browsers to prevent drive-by code execution,
and deployment of inline or local sandboxessuch as Invinceas VM-based isolation
or FireEye appliancesto contain untrusted code. Complementing this, he urges
policy-driven measures: eliminate Java where it isnt business-critical, enforce
inventory and configuration controls per the SANS Critical Security Controls
(especially Controls 15), and integrate Java risk assessments into broader
security governance. By combining these controls, organizations can
substantially reduce their Java attack surface and stay ahead of emerging
exploit techniques .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56224_2012-10-24_JavaExploitsOffenseAndDefense-ISC2TC.pdf&quot;&gt;Java Exploits Offense and
Defense&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Security on a Shoestring Budget</title>
        <published>2012-03-16T00:00:00+00:00</published>
        <updated>2012-03-16T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/"/>
        <id>https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/security-on-a-shoestring-budget/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Minnesota Council for Non Profits presentation Security on a Shoestring
Budget by Matthew J. Harmon and Natascha E. Shawver delivers practical guidance
for nonprofit organizations to improve their security posture without large
investments. It frames security as a mission enabler rather than a cost center
and stresses that common-sense controls can dramatically reduce risk.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;security-concepts&quot;&gt;Security Concepts&lt;&#x2F;h2&gt;
&lt;p&gt;The presenters begin by defining core information-security concepts: impact,
risk, threats, vulnerabilities, and controlsto build a shared vocabulary. They
emphasize why nonprofits must care about security, listing potential losses
(reputation, funding, productivity, legal liability) that imperil organizational
missions. By demystifying terms and highlighting that security is more than just
computer stuff, they prepare attendees to tackle specific, budget-friendly
measures.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;actions&quot;&gt;Actions&lt;&#x2F;h2&gt;
&lt;p&gt;The heart of the talk is a prioritized bare necessities checklist of seventeen
actions tailored for resource-constrained environments. Starting with secure
password management and asset inventories, it moves through network hardening
(firewalls, patching, wireless security), malware defenses, automated backups,
and principle-of-least-privilege user controls. It rounds out with training,
policies, disaster-recovery planning, and vendor oversight. Each step is
designed to be actionable with free or low-cost tools, enabling nonprofits to
take incremental, sustainable strides toward resilience.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;56002_2012-03-16_Security_on_a_Shoestring_Budget-MNCNP.pdf&quot;&gt;Security on a Shoestring
Budget&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Why Take the Risk? Doing Risk Assessments Right</title>
        <published>2011-12-07T00:00:00+00:00</published>
        <updated>2011-12-07T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/why-take-the-risk-mngts/"/>
        <id>https://blog.itys.net/vol1/posts/why-take-the-risk-mngts/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/why-take-the-risk-mngts/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS presentation Why Take the Risk? Doing Risk Assessments Right by Matthew
J. Harmon, delivered at the 30th Annual Minnesota Government IT Symposium on
December 7, 2011, lays out a structured approach for organizations to identify,
analyze, and manage IT risks. Harmon draws on industry standards and real-world
examples to show how a disciplined risk assessment process can both prevent loss
and add strategic value.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;risks-and-probability&quot;&gt;Risks and Probability&lt;&#x2F;h2&gt;
&lt;p&gt;First, the talk defines an IT risk assessment as an analysis of system assets
and vulnerabilities to establish an expected loss from certain events based on
estimated probabilities, per the Department of the Navy (OPNAVINST 5239.1A) and
ISO Guide 73:2009. Key terminology such as threat agents, vulnerabilities,
impact, and riskis clarified, with threats described as anything capable of
harming an asset and risk framed as a function of likelihood and impact. Harmon
emphasizes that thorough identification of assets, threat scenarios, and
existing controls is essential to determine whether current safeguards reduce
risk to acceptable levels.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;frameworks&quot;&gt;Frameworks&lt;&#x2F;h2&gt;
&lt;p&gt;Second, Harmon surveys leading frameworks like NIST SP 800-30, ISO 27005, ISO
31010, FAIR, and OCTAVE and maps them onto a Plan-Do-Check-Act lifecycle. The
process begins with planning and establishing context, then moves through asset
and threat identification, vulnerability analysis, and impact assessment. He
details methods for both quantitative (e.g., Annualized Loss Expectancy
calculations) and qualitative (e.g., Low&#x2F;Medium&#x2F;High scales) analyses, and
outlines risk treatment optionsaccept, mitigate, transfer, or avoidguided by
senior-management engagement. The presentation concludes by stressing the
importance of actionable treatment plans, ongoing monitoring, and regular
reviews to maintain and improve organizational resilience.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55902_2011-12-07_Why_take_the_risk-MNGTS.pdf&quot;&gt;Why take the risk?&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Incident Handling, Forensics and Hacking Techniques</title>
        <published>2011-10-19T00:00:00+00:00</published>
        <updated>2011-10-19T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/incident-handling-mncia/"/>
        <id>https://blog.itys.net/vol1/posts/incident-handling-mncia/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/incident-handling-mncia/">&lt;p&gt;The SANS Incident Handling &amp;amp; Forensics presentation by Matthew J. Harmon
provides a comprehensive overview of how organizations should prepare for,
respond to, and learn from security incidents. Drawing on industry best
practices and real-world examples, it emphasizes the importance of structured
processes, clear communication, and rigorous evidence handling to minimize
damage and restore operations promptly.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;incident-response&quot;&gt;Incident Response&lt;&#x2F;h2&gt;
&lt;p&gt;First, the talk lays out the six core phases of incident response: Preparation,
Identification, Containment, Eradication, Recovery, and Lessons Learneddetailing
the goals and key actions at each stage. Core principles such as work in pairs,
maintain a strict chain of custody, never operate on original data, and enforce
a need-to-know policy are reinforced throughout. These guidelines ensure that
responders act methodically, take comprehensive notes, and prevent further
compromise while preserving forensic integrity.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;techniques-and-toolkits&quot;&gt;Techniques and Toolkits&lt;&#x2F;h2&gt;
&lt;p&gt;Second, the presentation transitions to practical techniques and toolkits. It
introduces the SANS Investigative Forensic Toolkit (SIFT) and offensive-focused
distributions like BackTrack for evidence acquisition and analysis. Step-by-step
procedures cover documenting the scene, identifying and preserving data sources
(from servers and workstations to mobile devices), performing bit-by-bit
imaging, and analyzing logs and memory. Finally, it underscores the need to
produce clear, audience-appropriate reportswhether for corporate management,
legal teams, or law enforcementto drive improvements and policy changes
post-incident.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55853_2011-10-19_Incident_Handling_Forensics_and_Hacking_Techniques-MNCIA.pdf&quot;&gt;Minnesota High Tech Crime Investigators
Association&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>ISO Focus+ Article: Plugging Security Gaps</title>
        <published>2010-04-01T00:00:00+00:00</published>
        <updated>2010-04-01T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/iso-focus-plus/"/>
        <id>https://blog.itys.net/vol1/posts/iso-focus-plus/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/iso-focus-plus/">&lt;p&gt;The attached article examines the explosive adoption of radio-frequency
identification (RFID) technology across industries and the emerging security
concerns that threaten its continued growth. As organizationsfrom the U.S.
Department of Defense to livestock ranchers and healthcare providersincreasingly
rely on RFID for tracking assets, the industry must confront vulnerabilities
that could undermine both privacy and trust in this pervasive technology.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;attacks&quot;&gt;Attacks&lt;&#x2F;h2&gt;
&lt;p&gt;In the face of demonstrated attackssuch as drive-by cloning of passport tagsRFID
systems are exposed to a spectrum of threats at multiple points: the tag itself,
the reader (interrogator), and the air interface. Common attack vectors include
mimicking (spoofing, cloning, malicious code), information gathering (skimming,
eavesdropping, data tampering), and denial-of-service tactics (reader jamming,
tag blocking or killing). Each of these can compromise confidentiality,
integrity, or availability, potentially disrupting business operations and
eroding user confidence.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;defense&quot;&gt;Defense&lt;&#x2F;h3&gt;
&lt;p&gt;To address these challenges, international standards bodies have moved to embed
security into RFID deployments. ISO&#x2F;IEC TR 24729-4 lays out guidelines for tag
data securitycovering encryption, authentication, and secure data
transmissionwhile balancing cost, storage constraints, and read-performance
requirements. The report recommends leveraging a suite of countermeasures (e.g.,
unique tag identifiers per ISO 15963, password protection, and cryptographic
controls) and employs the OWASP DREAD model to assess and prioritize risks.
Ongoing work by ISO&#x2F;IEC SC 31s WG 7 seeks to harmonize these efforts into a
coherent framework that ensures interoperability, efficiency, and privacy as
RFID becomes ever more ubiquitous.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;55287_2010-04-01_Plugging_Security_Gaps-ISOFP.pdf&quot;&gt;ISO Focus+ April
2010&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
