DDoS Vocabulary and Mathematics

<p>Some language and math that come in handy when you talk about or fight Distributed Denial of Service&#8230; Distributed Denial of Service: an attack that uses a number of attacking nodes that overwhelm the target with network, web, or application traffic.  DDoS implies 100 or more nodes attacking the same target, although just about everybody [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2170">DDoS Vocabulary and Mathematics</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2012/10/26
阅读更多

DDoS and Elections

<p>I&#8217;ve noticed a trend over the past 6 months: DDoS traffic associated with elections.  A quick sampling of news will show the following: http://www.opendemocracy.net/od-russia/irina-borogan-andrei-soldatov/kremlin-and-hackers-partners-in-crime &#60;-Russia http://www.theregister.co.uk/2012/03/26/hong_kong_vote_hack/ &#60;-Hong Kong http://www.theregister.co.uk/2011/12/07/korean_election_ddos_row/ &#60;-Korea http://www.cbc.ca/news/politics/story/2012/03/27/pol-ndp-voting-disruption-deliberate.html &#60;-Canada (rybolov: yikes!) http://www.csoonline.com/article/700523/ddos-attackers-target-russian-election-webcams &#60;-Russia again Last week it picked up again with the re-inauguration of Vladimir Putin. http://en.ria.ru/russia/20120506/173265737.html http://www.washingtonpost.com/world/europe/peaceful-protest-turns-violent-in-moscow/2012/05/06/gIQAFti35T_story.html http://english.ruvr.ru/2012_05_06/73954450/ http://www.rferl.org/content/independent_russian_daily_hit_by_dos_attack_kommersant/24571463.html And then yesterday, Ustream and their awesome response: which, [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2144">DDoS and Elections</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2012/5/10
阅读更多

FedRAMP: It’s Here but Not Yet Here

<p>Contrary to what you might hear this week in the trade press, FedRAMP is not fully unveiled although there was some much-awaited progress. There was a memo that came out from the administration (PDF caveat).  Basically what it does is lay down the authority and responsibility for the Program Management Office and set some timelines.  [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2121">FedRAMP: It’s Here but Not Yet Here</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/12/12
阅读更多

The “Off The Record” Track

<p>So while I was at some conferences over the past couple of months, I had an awesome idea while sitting in a panel about data breaches, especially notification. While streaming conferences is pretty awesome for most content, I keep thinking that we need that as an industry we need the exact opposite: a track of [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2099">The “Off The Record” Track</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/11/21
阅读更多

DHS is Looking for a CISO

<p>Job announcement is here.  Share with anybody you think can do it.Similar Posts: Radio Nigel Why You Should Care About Security and the Government Help the Government, Become Literate SP 800-53A Now Finally Final Wanted: Some SCAP Wranglers</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2105">DHS is Looking for a CISO</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/11/4
阅读更多

#RefRef the Vaporware DoS Tool

<p>Ah yes, you now know how I spend my Saturday mornings lately. Similar Posts: DDoS Planning: Business Continuity with a Twist The Rise of the Slow Denial of Service Training the Apache Killers Oh to be a Program Manager A Little Story About a Tool Named #RefRef</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2089">#RefRef the Vaporware DoS Tool</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/9/23
阅读更多

A Little Story About a Tool Named #RefRef

<p>Let me tell you a little story. So September 17th was Constitution Day and was celebrated by protestors in most major cities across the US with a sizable percentage of folks on Wall Street in NYC.  In conjunction with this protest, a new Denial-of-Service tool, #RefRef, was supposed to be released.  It supposedly used some [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2085">A Little Story About a Tool Named #RefRef</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/9/23
阅读更多

Training the Apache Killers

<p>Here at IKANHAZFIZMA, we&#8217;re training the next generation of Apache webserver Denial-of-Service gurus.  It involves punching bags, some nomz for the troops, and lots of requests for kibble. Similar Posts: The Rise of the Slow Denial of Service A Little Story About a Tool Named #RefRef DDoS and Elections DDoS Planning: Business Continuity with a [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2076">Training the Apache Killers</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/9/2
阅读更多

Apache Killer Effects on Target

<p>Oh noes, the web is broken.  Again.  This time it&#8217;s the Apache Killer.  This inspired a little ditty from @CSOAndy based on a Talking Heads tune: I can&#8217;t seem 2 handle the ranges I&#8217;m forked &#38; memlocked &#38; I Can&#8217;t spawn I can&#8217;t sleep &#8217;cause my net&#8217;s afire Don&#8217;t spawn me I&#8217;m a dead server [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2063">Apache Killer Effects on Target</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/8/30
阅读更多

Noms and IKANHAZFIZMA

<p>Kickin&#8217; it old-school with some kitteh overflows Similar Posts: LOLCATS Take on Catalog of Controls LOLCATS and Firewalls Conflicker ala IKANHAZFIZMA IKANHAZFIZMA Tackles the Consensus Audit Guidelines Training the Apache Killers</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2060">Noms and IKANHAZFIZMA</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/8/26
阅读更多

The Rise of the Slow Denial of Service

<p>Usually when you think about Denial of Service attacks nowadays, most people think up images of the Anonymous kids running their copy of LOIC in a hivemind or Russian Gangsters building a botnet to run an online protection racket.  Now there is a new-ish type of attack technique floating around which I believe will become [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2049">The Rise of the Slow Denial of Service</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/8/23
阅读更多

DDoS Planning: Business Continuity with a Twist

<p>So since I&#8217;ve semi-officially been granted the title of &#8220;The DDoS Kid&#8221; after some of the incident response, analysis, and talks that I&#8217;ve done, I&#8217;m starting to get asked a lot about how much the average DDoS costs the targeted organization.  I have some ideas on this, but the simplest way is to recycle Business [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1961">DDoS Planning: Business Continuity with a Twist</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/8/17
阅读更多

Realistic NSTIC

<p>OK, it&#8217;s been out a couple of months now with the usual &#8220;ZOMG it&#8217;s RealID all over again&#8221; worry-mongers raising their heads. So we&#8217;re going to go through what NSTIC is and isn&#8217;t and some &#8220;colorful&#8221; (or &#8220;off-color&#8221; depending on your opinion) use cases for how I would (hypothetically, of course) use an Identity Provider [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2023">Realistic NSTIC</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/8/10
阅读更多

Clouds, FISMA, and the Lawyers

<p>Interesting blog post on Microsoft&#8217;s TechNet, but the real gem is the case filing and summary from the DoJ (usual .pdf caveat applies).  Basically the Reader&#8217;s Digest Condensed Version is that the Department of Interior awarded a cloud services contract to Microsoft for email.  The award was protested by Google for a wide variety of [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2013">Clouds, FISMA, and the Lawyers</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/4/26
阅读更多

LOLCATS and NSTIC

<p>Ref: NSTIC Ref: On the Internet&#8230; Similar Posts: Realistic NSTIC Et Tu, TIC? Hackers, Protesters, Iran, Twitter, and Lolcats Cyberlolcats Watch the Hackers at DefCon LOLCATS and Hackable Coffee Pots</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/2010">LOLCATS and NSTIC</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/4/14
阅读更多

Some Comments on SP 800-39

<p>You should have seen Special Publication 800-39 (PDF file, also check out more info on Fismapedia.org) out by now.  Dan Philpott and I just taught a class on understanding the document and how it affects security managers out them doing their job on a daily basis.  While the information is still fresh in my head, [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1999">Some Comments on SP 800-39</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/4/6
阅读更多

Micro Digital Signatures Howto

<p>With RSA wrapping up, I figured I would do something fun with Alice, Bob, and crypto.  There is a need for small digital signatures (Micro Digital Signatures/&#8221;MicroDigiSigs&#8221; if I can be as bold as to think I can start a nerdy meme) and tools to support them over small message spaces such as The Twitters, [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1988">Micro Digital Signatures Howto</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/2/22
阅读更多

IKANHAZFIZMA Ponders “The Move to Cloud”

<p>Similar Posts: IKANHAZFIZMA Does Awareness Training Conflicker ala IKANHAZFIZMA Noms and IKANHAZFIZMA FedRAMP Released &#8220;Real Soon Now&#8221;, Lolcats Happy Lolcats Coming to you from the Cloud</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1985">IKANHAZFIZMA Ponders “The Move to Cloud”</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/2/17
阅读更多

Reinventing FedRAMP

<p>“Cloud computing is about gracefully losing control while maintaining accountability even if the operational responsibility falls upon one or more third parties.” &#8211;CSA Security Guidance for Critical Areas of Focus in Cloud Computing V2.1 Now enter FedRAMP.  FedRAMP is a way to share Assessment and Authorization information for a cloud provider with its Government tenants.  [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1973">Reinventing FedRAMP</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/2/15
阅读更多

Happy New Year

<p>Believe it or not, this is a friend&#8217;s cat named Little Phat Man, and we cat-sat him over Christmas.  Mrs Rybolov took the photo.  I&#8217;ve been trying to get Phat into a lolcat for a long time. Similar Posts: Snowmageddon Meets the IKANHAZFIZMA Lolcats Exhaustive Security Testing is Bad For You IKANHAZFIZMA and Transparency Look [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1968">Happy New Year</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2011/1/1
阅读更多

DojoCon DDoS Video

<p>My DDoS presentation at DojoCon on Sunday.  A big thanks to Marcus J Carey for organizing the con and Adrian Crenshaw for doing the recording. Michael Smith, @rybolov DDoS from Adrian Crenshaw on Vimeo. Similar Posts: DojoCon 2009 Presentation Barcode Hacking DDoS and Elections Massively Scaled Security Solutions for Massively Scaled IT DDoS Planning: Business [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1964">DojoCon DDoS Video</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2010/12/16
阅读更多

no rly, iz protest

<p>Inspired by Anonymous, Operation Payback, and the &#8220;DDoS attacks as a legitimate form of protest?&#8221; article at ZDNet Similar Posts: Conflicker ala IKANHAZFIZMA Noms and IKANHAZFIZMA IKANHAZFIZMA Finds Caution Tape Training the Apache Killers #RefRef the Vaporware DoS Tool</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1954">no rly, iz protest</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2010/12/16
阅读更多

WikiLeaks: Coming to an Agency Near You

<p>Nope, we&#8217;re not going to talk about ego trips, hidden agendas, or complete irresponsible transparency.  This blog post is about some of the fallout inside the Government security teams. The powers that be would like to remind you that downloading classified documents off the Intertubez does not make them unclassified.  An anonymous source that I [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1947">WikiLeaks: Coming to an Agency Near You</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2010/12/9
阅读更多

Interviewed for the “What It’s Like” Series for CSOOnline

<p>Joan Goodchild interviewed me about some of my experiences in the big sandbox and how I was good enough at avoiding IEDs to make it there and home again&#8211;an abstract form of risk management. Go check it out.  And while you&#8217;re on the subject or for visuals to go along with the story, check out [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1936">Interviewed for the “What It’s Like” Series for CSOOnline</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2010/11/23
阅读更多

Evolving the Physical Hacking at Security Conferences

<p>There has been a fun evolution at hacker conference for the past couple of years: the inclusion of hackerspaces.  Hackerspaces fit nicely into the hacker ethos.  But I&#8217;ve also heard grumblings via the tubes about the relevance of projects that they bring to hacker conferences, something along the lines of &#8220;Why has every security conference [&#8230;]</p> <p>The post <a href="http://www.guerilla-ciso.com/archives/1904">Evolving the Physical Hacking at Security Conferences</a> first appeared on <a href="http://www.guerilla-ciso.com">The Guerilla CISO</a>.</p>

2010/11/22
阅读更多