Cloud Forensics
Cloud Computing, Computer Forensics, Cybercrime Investigation, Security, Entrepreneurship & Innovation
Tuesday, September 22, 2009
Monday, July 20, 2009
Log management as a cloud-based service
“There are three primary uses for the Log Management application: operational troubleshooting, security and compliance monitoring, and Web app and application log monitoring,” says Chris Waters, Paglo co-founder and CTO.
The service works in two ways. For existing Paglo customers, the Paglo core technology already installed in their environment will automatically capture and transmit the network device and system logs to Paglo. New customers would be required to perform “a simple configuration change” to send logs directly to Paglo using tools such as the open source application Syslog-ng.
“Paglo is providing log management capabilities without requiring an upfront investment in software or appliances, but as a cloud-based service that customers pay for as they use it,” says Brian de Haaff, Paglo CEO. “We are securely transporting all log data from companies into a cloud-based service, combining that with asset information and analysis, which we believe is a killer combination that really gives IT managers a system of record for IT.”
Paglo is also making available a free version of its Log Management service. The free version includes 10 megabytes of peak log volume per day and 7 days of log storage.
Friday, June 26, 2009
Internet crimes to be proud of
Thanks to Pretty Good Privacy encryption creator Phil Zimmermann for software that undermines suppression -- and for keeping me out of jail
When does a passionate advocate for securing the Internet find himself pulling for Internet criminals? When the "crime" is running afoul of a perverse definition of the law. Of course I'm talking about people purposefully ignoring their country's illegitimate attempts to censor or monitor otherwise legitimate Internet use.
Recent events have reinforced the justifiable need for software and sites that can ensure that citizens can continue to communicate freely and confidentially, even when that right is taken away. I especially support people who circumvent the heavy-handed enforcement of questionable censorship laws that exist solely to protect the figureheads in power from the influence of the people they supposedly govern.
Bypassing censorship filters can be accomplished by using regular services not blocked by the censorship software (such as Twitter) or by using any of the plethora of anonymous proxy services. To get a list of the latter, just search on "anonymous proxies" using any Internet search engine. The best ones encrypt the connection between the originator and proxy so that the information cannot be inspected by intervening filters.
Pretty great privacy
The availability of free, reliable encryption software should be a basic human right. From the beginning of computer science, the makers of computer ciphers have considered protecting communications from an oppressive government's prying eyes to be one of the primary uses of their software.
Certainly Phil Zimmermann, the creator of Pretty Good Privacy (PGP) encryption software, had this on his mind as a central theme when he first coded PGP in 1991. He spoke about this need frequently and even covered it in his documentation, FAQ, and book.
At the time, as a citizen who took the freedoms of the United States for granted, I didn't realize the importance of his declaration. Mr. Zimmermann did. He was investigated by the U.S. government for many years -- facing the prospect of a lengthy prison sentence and possibly even the serious charge of treason (punishable by death) -- for making PGP widely available for the world to use. He spent hundreds of thousands of dollars fighting the investigation, and in the face of overwhelming adversity and the opposition's unlimited monetary resources, he didn't back down.
By 1994, even I recognized the importance of PGP to all freedom-loving peoples. In my youthful exuberance, I was enraged that Zimmermann, who I had personally e-mailed a few times, was being accused of being an American traitor. I came up with a scheme, that upon reflection, was either incredibly ballsy or can only be attributed to adolescent arrogance. My plan was to intentionally violate the U.S. federal statues against distributing encryption programs to foreign governments. This was a charge that Mr. Zimmermann had craftily and legally avoided for good reason.
I was going to create a Web site that would allow any visitor to easily send a copy of PGP to a random foreign e-mail address recipient with a carbon copy of the transfer automatically sent to the White House, along with a protest letter. My idea was to get millions of visitors to violate our "stupid" software encryption laws on purpose and see how the U.S. Justice Department could handle a million violations. My fantasy included the government realizing how ignorant it was, forcing it to change the laws, and to drop the charges against Zimmermann.
Pretty bad protest
This wasn't just a silent fantasy. I had created the bare bones of the Web site and contacted Newsweek magazine. I had been profiled in a March 1992 issue regarding the popular Michelangelo virus and the newly emerging Dark Avenger's polymorphic virus mutation engine, and I'd established friendly inside contacts. The magazine's computer and science associate editor loved my idea and promised to give it coverage.
I even understood the potential legal consequences of my actions. I knew I could end up in jail or, at the very least, wasting a lot of money in my defense. I had told my new wife and mother of my first daughter of my idea and the possible consequences. As you can imagine, she was not very supportive of my risking my good job, our house, and our comfortable life. But I was that emotionally driven. At the time I was fond of quoting, "You can take my right to privacy out of my cold, dead hands!" This from a guy who's never held a gun.
Although the exact details are a bit hazy now, I remember nervously dialing Zimmermann for the first time, with the Newsweek editor listening in. I knew getting Zimmermann's support would lock in the magazine's commitment and get me the publicity I would need to get large numbers of visitors willing to join me in my privacy fight.
When I explained my intentions to my crypto hero, instead of embracing my idea as I had expected, he scolded me. He told me that I was stupid for what I was trying -- and that I didn't understand the real consequences of what I was doing. He explained how much time, money, and effort he had put into his own legal defense, and he finished by saying that he did not support my project and would no longer communicate with me.
I was stunned and embarrassed. But fortunately, his admonishment was enough to get me to drop my plans, much to the relief of my family and friends. Years later, the charges against Zimmermann that so offended me were dropped (or more accurately, never filed). His legal defense against the federal investigation helped define the legal treatment of subsequent encryption software as it proliferated around the globe.
Since then, Phil Zimmermann has developed other encryption products, most recently an innovative, free plug-in product, Zfone [4], which works with a variety of IP telephony software clients. Listening to Zimmermann speak about his latest project at a security conference last year, I was amazed to hear him again reassert the need for encryption products to ensure people's freedom.
As I watched the recent political struggles of a suppressed people and learned how they used the Internet to circumvent a repressive regime, it made me realize the importance of contributions from people like Zimmermann.
So although this is too long overdue, thank you, Phil Zimmermann. Thank you for your free encryption products. Thank you for standing up to our federal government when it was wrong and for battling on behalf of those without a voice. And personally, thanks for steering me clear of a run-in with the feds.
Tuesday, June 23, 2009
Cloud Computing and Cyber Defense
Friday, June 12, 2009
Remarks by the President on Securing Our Nation's Cyber Infrastructure
Office of the Press Secretary
______________________________________________________
For Immediate Release May 29, 2009
REMARKS BY THE PRESIDENT
ON SECURING OUR NATION'S
CYBER INFRASTRUCTURE
East Room
11:08 A.M. EDT
THE PRESIDENT: Everybody, please be seated. We meet today at a transformational moment -- a moment in history when our interconnected world presents us, at once, with great promise but also great peril.
Now, over the past four months my administration has taken decisive steps to seize the promise and confront these perils. We're working to recover from a global recession while laying a new foundation for lasting prosperity. We're strengthening our armed forces as they fight two wars, at the same time we're renewing American leadership to confront unconventional challenges, from nuclear proliferation to terrorism, from climate change to pandemic disease. And we're bringing to government -- and to this White House -- unprecedented transparency and accountability and new ways for Americans to participate in their democracy.
But none of this progress would be possible, and none of these 21st century challenges can be fully met, without America's digital infrastructure -- the backbone that underpins a prosperous economy and a strong military and an open and efficient government. Without that foundation we can't get the job done.
It's long been said that the revolutions in communications and information technology have given birth to a virtual world. But make no mistake: This world -- cyberspace -- is a world that we depend on every single day. It's our hardware and our software, our desktops and laptops and cell phones and Blackberries that have become woven into every aspect of our lives.
It's the broadband networks beneath us and the wireless signals around us, the local networks in our schools and hospitals and businesses, and the massive grids that power our nation. It's the classified military and intelligence networks that keep us safe, and the World Wide Web that has made us more interconnected than at any time in human history.
So cyberspace is real. And so are the risks that come with it.
It's the great irony of our Information Age -- the very technologies that empower us to create and to build also empower those who would disrupt and destroy. And this paradox -- seen and unseen -- is something that we experience every day.
It's about the privacy and the economic security of American families. We rely on the Internet to pay our bills, to bank, to shop, to file our taxes. But we've had to learn a whole new vocabulary just to stay ahead of the cyber criminals who would do us harm -- spyware and malware and spoofing and phishing and botnets. Millions of Americans have been victimized, their privacy violated, their identities stolen, their lives upended, and their wallets emptied. According to one survey, in the past two years alone cyber crime has cost Americans more than $8 billion.
I know how it feels to have privacy violated because it has happened to me and the people around me. It's no secret that my presidential campaign harnessed the Internet and technology to transform our politics. What isn't widely known is that during the general election hackers managed to penetrate our computer systems. To all of you who donated to our campaign, I want you to all rest assured, our fundraising website was untouched. (Laughter.) So your confidential personal and financial information was protected.
But between August and October, hackers gained access to emails and a range of campaign files, from policy position papers to travel plans. And we worked closely with the CIA -- with the FBI and the Secret Service and hired security consultants to restore the security of our systems. It was a powerful reminder: In this Information Age, one of your greatest strengths -- in our case, our ability to communicate to a wide range of supporters through the Internet -- could also be one of your greatest vulnerabilities.
This is a matter, as well, of America's economic competitiveness. The small businesswoman in St. Louis, the bond trader in the New York Stock Exchange, the workers at a global shipping company in Memphis, the young entrepreneur in Silicon Valley -- they all need the networks to make the next payroll, the next trade, the next delivery, the next great breakthrough. E-commerce alone last year accounted for some $132 billion in retail sales.
But every day we see waves of cyber thieves trolling for sensitive information -- the disgruntled employee on the inside, the lone hacker a thousand miles away, organized crime, the industrial spy and, increasingly, foreign intelligence services. In one brazen act last year, thieves used stolen credit card information to steal millions of dollars from 130 ATM machines in 49 cities around the world -- and they did it in just 30 minutes. A single employee of an American company was convicted of stealing intellectual property reportedly worth $400 million. It's been estimated that last year alone cyber criminals stole intellectual property from businesses worldwide worth up to $1 trillion.
In short, America's economic prosperity in the 21st century will depend on cybersecurity.
And this is also a matter of public safety and national security. We count on computer networks to deliver our oil and gas, our power and our water. We rely on them for public transportation and air traffic control. Yet we know that cyber intruders have probed our electrical grid and that in other countries cyber attacks have plunged entire cities into darkness.
Our technological advantage is a key to America's military dominance. But our defense and military networks are under constant attack. Al Qaeda and other terrorist groups have spoken of their desire to unleash a cyber attack on our country -- attacks that are harder to detect and harder to defend against. Indeed, in today's world, acts of terror could come not only from a few extremists in suicide vests but from a few key strokes on the computer -- a weapon of mass disruption.
In one of the most serious cyber incidents to date against our military networks, several thousand computers were infected last year by malicious software -- malware. And while no sensitive information was compromised, our troops and defense personnel had to give up those external memory devices -- thumb drives -- changing the way they used their computers every day.
And last year we had a glimpse of the future face of war. As Russian tanks rolled into Georgia, cyber attacks crippled Georgian government websites. The terrorists that sowed so much death and destruction in Mumbai relied not only on guns and grenades but also on GPS and phones using voice-over-the-Internet.
For all these reasons, it's now clear this cyber threat is one of the most serious economic and national security challenges we face as a nation.
It's also clear that we're not as prepared as we should be, as a government or as a country. In recent years, some progress has been made at the federal level. But just as we failed in the past to invest in our physical infrastructure -- our roads, our bridges and rails -- we've failed to invest in the security of our digital infrastructure.
No single official oversees cybersecurity policy across the federal government, and no single agency has the responsibility or authority to match the scope and scale of the challenge. Indeed, when it comes to cybersecurity, federal agencies have overlapping missions and don't coordinate and communicate nearly as well as they should -- with each other or with the private sector. We saw this in the disorganized response to Conficker, the Internet "worm" that in recent months has infected millions of computers around the world.
This status quo is no longer acceptable -- not when there's so much at stake. We can and we must do better.
And that's why shortly after taking office I directed my National Security Council and Homeland Security Council to conduct a top-to-bottom review of the federal government's efforts to defend our information and communications infrastructure and to recommend the best way to ensure that these networks are able to secure our networks as well as our prosperity.
Our review was open and transparent. I want to acknowledge, Melissa Hathaway, who is here, who is the Acting Senior Director for Cyberspace on our National Security Council, who led the review team, as well as the Center for Strategic and International Studies bipartisan Commission on Cybersecurity, and all who were part of our 60-day review team. They listened to a wide variety of groups, many of which are represented here today and I want to thank for their input: industry and academia, civil liberties and private -- privacy advocates. We listened to every level and branch of government -- from local to state to federal, civilian, military, homeland as well as intelligence, Congress and international partners, as well. I consulted with my national security teams, my homeland security teams, and my economic advisors.
Today I'm releasing a report on our review, and can announce that my administration will pursue a new comprehensive approach to securing America's digital infrastructure.
This new approach starts at the top, with this commitment from me: From now on, our digital infrastructure -- the networks and computers we depend on every day -- will be treated as they should be: as a strategic national asset. Protecting this infrastructure will be a national security priority. We will ensure that these networks are secure, trustworthy and resilient. We will deter, prevent, detect, and defend against attacks and recover quickly from any disruptions or damage.
To give these efforts the high-level focus and attention they deserve -- and as part of the new, single National Security Staff announced this week -- I'm creating a new office here at the White House that will be led by the Cybersecurity Coordinator. Because of the critical importance of this work, I will personally select this official. I'll depend on this official in all matters relating to cybersecurity, and this official will have my full support and regular access to me as we confront these challenges.
Today, I want to focus on the important responsibilities this office will fulfill: orchestrating and integrating all cybersecurity policies for the government; working closely with the Office of Management and Budget to ensure agency budgets reflect those priorities; and, in the event of major cyber incident or attack, coordinating our response.
To ensure that federal cyber policies enhance our security and our prosperity, my Cybersecurity Coordinator will be a member of the National Security Staff as well as the staff of my National Economic Council. To ensure that policies keep faith with our fundamental values, this office will also include an official with a portfolio specifically dedicated to safeguarding the privacy and civil liberties of the American people.
There's much work to be done, and the report we're releasing today outlines a range of actions that we will pursue in five key areas.
First, working in partnership with the communities represented here today, we will develop a new comprehensive strategy to secure America's information and communications networks. To ensure a coordinated approach across government, my Cybersecurity Coordinator will work closely with my Chief Technology Officer, Aneesh Chopra, and my Chief Information Officer, Vivek Kundra. To ensure accountability in federal agencies, cybersecurity will be designated as one of my key management priorities. Clear milestones and performances metrics will measure progress. And as we develop our strategy, we will be open and transparent, which is why you'll find today's report and a wealth of related information on our Web site, www.whitehouse.gov<http://www.whitehouse.gov/>.
Second, we will work with all the key players -- including state and local governments and the private sector -- to ensure an organized and unified response to future cyber incidents. Given the enormous damage that can be caused by even a single cyber attack, ad hoc responses will not do. Nor is it sufficient to simply strengthen our defenses after incidents or attacks occur. Just as we do for natural disasters, we have to have plans and resources in place beforehand -- sharing information, issuing warnings and ensuring a coordinated response.
Third, we will strengthen the public/private partnerships that are critical to this endeavor. The vast majority of our critical information infrastructure in the United States is owned and operated by the private sector. So let me be very clear: My administration will not dictate security standards for private companies. On the contrary, we will collaborate with industry to find technology solutions that ensure our security and promote prosperity.
Fourth, we will continue to invest in the cutting-edge research and development necessary for the innovation and discovery we need to meet the digital challenges of our time. And that's why my administration is making major investments in our information infrastructure: laying broadband lines to every corner of America; building a smart electric grid to deliver energy more efficiently; pursuing a next generation of air traffic control systems; and moving to electronic health records, with privacy protections, to reduce costs and save lives.
And finally, we will begin a national campaign to promote cybersecurity awareness and digital literacy from our boardrooms to our classrooms, and to build a digital workforce for the 21st century. And that's why we're making a new commitment to education in math and science, and historic investments in science and research and development. Because it's not enough for our children and students to master today's technologies -- social networking and e-mailing and texting and blogging -- we need them to pioneer the technologies that will allow us to work effectively through these new media and allow us to prosper in the future. So these are the things we will do.
Let me also be clear about what we will not do. Our pursuit of cybersecurity will not -- I repeat, will not include -- monitoring private sector networks or Internet traffic. We will preserve and protect the personal privacy and civil liberties that we cherish as Americans. Indeed, I remain firmly committed to net neutrality so we can keep the Internet as it should be -- open and free.
The task I have described will not be easy. Some 1.5 billion people around the world are already online, and more are logging on every day. Groups and governments are sharpening their cyber capabilities. Protecting our prosperity and security in this globalized world is going to be a long, difficult struggle demanding patience and persistence over many years.
But we need to remember: We're only at the beginning. The epochs of history are long -- the Agricultural Revolution; the Industrial Revolution. By comparison, our Information Age is still in its infancy. We're only at Web 2.0. Now our virtual world is going viral. And we've only just begun to explore the next generation of technologies that will transform our lives in ways we can't even begin to imagine.
So a new world awaits -- a world of greater security and greater potential prosperity -- if we reach for it, if we lead. So long as I'm President of the United States, we will do just that. And the United States -- the nation that invented the Internet, that launched an information revolution, that transformed the world -- will do what we did in the 20th century and lead once more in the 21st.
Thank you very much, everybody. Thank you. (Applause.)
END
11:25 A.M. EDT
Thursday, May 7, 2009
Forensic Tools
Saturday, March 14, 2009
Google Apps Admins Jittery About Gmail, Hopeful About Future
Juan Carlos Perez, IDG News Service
Friday, August 15, 2008 3:40 PM PDT
When Gmail crashed on Monday, affecting many organizations that depend on it for work e-mail via the Google Apps suite, widespread gnashing of teeth ensued.
At Alaska's APTI public TV and radio station, reporters working on deadline scrambled to gather information without e-mail as a tool.
In the middle of an important press announcement, staffers at San Francisco Internet startup Kwiry sought alternate ways to stay in touch with contacts.
At Davidoff Communications, the outage hit less than 24 hours after the Chicago company's migration of its five users to Google Apps.
"Since we're only on day four of our implementation, let's just say if Apps were on my baseball team, it would be hitting at the bottom of the lineup," said Davidoff Systems Administrator Mitch Wilkos in an e-mail interview this week.
With its Apps hosted suite of communications and collaboration applications, Google is a leading proponent of software-as-a-service (SaaS), an emerging model of software delivery that backers say represents the future.
Because vendors host applications in their own data centers, companies don't have to concern themselves with hardware provisioning and software maintenance. By living in the Internet "cloud," these hosted applications simplify sharing and collaboration among employees.
However, the experience of users living through the recent Google Apps outages could serve as a deterrent to some IT and business managers who might not be ready to ditch conventional software packages that are installed on their servers.
If a company relies on Google Apps for its e-mail, its IT and business managers have little to do when a Gmail outage hits them, and, with end-users demanding explanations, this waiting game can be a very stressful situation, as John Proffitt, IT services director at APTI, can attest.
"For me as the Google Apps administrator, the disruption was pretty damn irritating. Aside from getting kicked out of e-mail I need to do my own job, it also forced me to completely refocus on figuring out what's happening with Gmail and Google Apps," he said in an e-mail interview.
For the two hours that the outage lasted, Proffitt estimates that about 75 percent of the organization's approximately 40 employees were affected, some severely, including the journalists who make up about a quarter of the staff.
"It was constant troubleshooting, testing, research, posting to the Google Apps forums and so on. Plus there's the emotional strain of wondering whether you completely screwed up by moving everyone to Google Apps as our sole e-mail system. That's what freaked me out: Did Google just make me look like an idiot?" Proffitt added.
That's not a nice feeling to have, especially since Proffitt did his homework and took his time before deciding to move his end-users to Google Apps. He used the suite for about nine months himself "as a guinea pig" and then rolled it out to the entire organization six weeks ago.
Prior to Monday's crash, his satisfaction level with Google Apps was about 90 percent. Now he puts it at 70 percent.
"Mostly that 20 percent drop is based on fear of another, perhaps more damaging, outage. It hasn't happened, but now I know it could happen any time and without warning, and if it does I have virtually no recourse to get the service running again," he said.
Monday's outage was sandwiched between two other Gmail crashes -- one last week and another one on Thursday and Friday of this week, both of which were smaller in scale. Proffitt wasn't affected by those other outages, but he's ready to rethink his status as hosted software adopter if things don't go well in the future.
"If we began to experience a similar outage more than about two or three business hours per quarter, we'd probably make Google Apps and Gmail a backup solution to a locally hosted mail system, if we used it at all. And it would likely be years before we'd try a cloud-based collaborative system again from any vendor," Proffitt said.
Still, Proffitt and other Apps administrators interviewed are hoping that Google will quickly strengthen the reliability of Gmail and the other suite components to a point where crashes become extremely rare. The benefits Apps offers to their small and medium-size organizations are significant in terms of cost savings and the flexibility of Web-based software.
"Even though we've only had Apps for a few days, I'm already impressed with the customization options. The ability to completely ditch Outlook makes Apps a worthwhile service to our company," said Davidoff's Wilkos. "The Gmail interface feels more intuitive and is significantly quicker than Outlook. And the mobile accessibility is a huge improvement over our old e-mail service."
Although Monday's outage stung Kwiry on an important day, and the startup was hit briefly again on Thursday, CEO Ron Feldman is betting on Google Apps. "Google understands its tremendous responsibility to keep things up and running," Feldman said via e-mail.
Carlos Leyva, managing shareholder at Digital Business Law Group, is also confident in Google and is sold on the SaaS model, which he expects will allow his new law firm to grow quickly without having to spend a fortune on its computing infrastructure.
"No one's happy when there's downtime, but there's always downtime. I've seen Exchange go down often. Many times you're left to your own IT people to fix it. That can be good or bad. I'd rather it be Google's problem. They've got a world-class team. Their reputation is on the line. Over time, they're going to get better and better," he said in a phone interview.
Thomas Harbinson, president of IDA International in Derby, Connecticut, found Monday's outage a minor disruption for the engineering and construction service company's 11 users. They have been very satisfied with Apps, which the company has been using for about a year after migrating away from Exchange.
"As a small organization looking at pre-Google Apps practice, if it had been my hardware in-house that went down, I would not have had anywhere near the reaction time and response to be restored as Google did with the Apps service," Harbinson said via e-mail.
About Me
Cloud Computing Manifesto
Journals
Conferences
White Papers
Stories
- A Brief History of Cloud Computing: Is the Cloud There Yet?
- Cloud Computing: From Metaphor To Mainstream
- Cloud Computing: The Evolution of Software-as-a-Service
- Clouds and Storms: Nicholas Carr on cloud computing
- Computers without borders
- Defining “Cloud Services” and “Cloud Computing”
- Enterprise Cloud Services: Driving Business Value from Cloud Computing
- Forrester's Advice to CFOs: Embrace Cloud Computing to Cut Costs
- Forrester: Is Cloud Computing Ready For The Enterprise?
- Gartner Says Worldwide IT Spending On Pace to Surpass $3.4 Trillion in 2008
- Gartner Special Report on Cloud Computing
- Gartner: Seven cloud-computing security risks
- Google Apps makes its way into big business
- Google, Inc. Q2 2008 Earnings Call Transcript
- Microsoft Plans ‘Cloud’ Operating System
- Open source fuels growth of cloud computing, software-as-a-service
- The Internet Cloud
- Wikipedia: Cloud Computing
Links
Providers
- 3Tera
- Agathon Group
- Amazon Web Services
- Appistry - Cloud computing middleware
- Bungee Connect
- Cassatt
- CloudScale Networks
- CloudStatus
- Coherence
- CohesiveFT
- ElasticHosts
- Enomaly Inc
- Flexiscale
- Force.com
- GigaSpaces
- GoGrid
- Good OS - gOS and Cloud operating systems
- Google AppEngine
- GridLayer
- Heroku
- Kaavo
- LayeredTechnologies
- Microsoft Mesh
- Mosso
- Nasstar
- Newservers
- Nirvanix
- Opsource
- Qrimp
- RightScale
