<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The New School of Information Security &#187; presentation</title>
	<atom:link href="http://newschoolsecurity.com/category/presentation/feed/" rel="self" type="application/rss+xml" />
	<link>http://newschoolsecurity.com</link>
	<description>The Blog Inspired By The Book</description>
	<lastBuildDate>Mon, 06 Feb 2012 16:09:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New School of Information Security Book Reading at Ada&#8217;s</title>
		<link>http://newschoolsecurity.com/2011/10/new-school-of-information-security-book-reading-at-adas/</link>
		<comments>http://newschoolsecurity.com/2011/10/new-school-of-information-security-book-reading-at-adas/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 15:12:10 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[Book]]></category>
		<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=2289</guid>
		<description><![CDATA[Last Sunday, I did a book reading at Ada&#8217;s Technical Books. As I say in the video, I was excited because while I&#8217;ve talked about the New School, and I&#8217;ve given talks about the New School, I hadn&#8217;t done a book reading, in part because of the nature of the book, and my personal comfort [...]]]></description>
			<content:encoded><![CDATA[<p>Last Sunday, I did <a href="http://blog.seattletechnicalbooks.com/?p=405">a book reading</a> at <a href="http://blog.seattletechnicalbooks.com/">Ada&#8217;s Technical Books</a>.  As I say in the video, I was excited because while I&#8217;ve talked about the New School, and I&#8217;ve given talks about the New School, I hadn&#8217;t done a book reading, in part because of the nature of the book, and my personal comfort zone in promotional activity.   Since Ada&#8217;s is just getting started on taking video, the quality of the recording isn&#8217;t super-high, but the conversation afterwards is great stuff.</p>
<p>
<iframe src="http://player.vimeo.com/video/29692169?color=ffffff" width="400" height="268" frameborder="0" webkitAllowFullScreen allowFullScreen></iframe>
<p><a href="http://vimeo.com/29692169">Adam Shostack at Ada&#8217;s Technical Books</a> from <a href="http://vimeo.com/adasbooks">Ada&#039;s Technical Books</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p>Thanks to Danielle for inviting me, and I&#8217;d be happy to do more readings in the future.</p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2011/10/new-school-of-information-security-book-reading-at-adas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Self Promotion: A Little Interview about Alex @ RSA</title>
		<link>http://newschoolsecurity.com/2011/02/self-promotion-a-little-interview-about-alex-rsa/</link>
		<comments>http://newschoolsecurity.com/2011/02/self-promotion-a-little-interview-about-alex-rsa/#comments</comments>
		<pubDate>Tue, 01 Feb 2011 18:48:16 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=2055</guid>
		<description><![CDATA[Self Promotion time, sorry for the spam, but I think the stuff I&#8217;ll be participating in at RSA is pretty NewSchool.  Here&#8217;s an interview that talks about both of the things I&#8217;ll be doing and you can see if they&#8217;ll be interesting: http://itacidentityblog.com/rsa-podcast-alex-hutton-principal-in-research-and-risk-intelligence-verizon-business]]></description>
			<content:encoded><![CDATA[<p>Self Promotion time, sorry for the spam, but I think the stuff I&#8217;ll be participating in at RSA is pretty NewSchool.  Here&#8217;s an interview that talks about both of the things I&#8217;ll be doing and you can see if they&#8217;ll be interesting:</p>
<p><strong><a href="http://bit.ly/f0RL00">http://itacidentityblog.com/rsa-podcast-alex-hutton-principal-in-research-and-risk-intelligence-verizon-business</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2011/02/self-promotion-a-little-interview-about-alex-rsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What They Know (From the WSJ)</title>
		<link>http://newschoolsecurity.com/2010/08/what-they-know-from-the-wsj/</link>
		<comments>http://newschoolsecurity.com/2010/08/what-they-know-from-the-wsj/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 18:08:56 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[metrics]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1720</guid>
		<description><![CDATA[Interesting interactive data app from the Wall Street Journal about your privacy online and what various websites track/know about you. http://blogs.wsj.com/wtk/ Full disclosure, our site uses Mint for traffic analytics.]]></description>
			<content:encoded><![CDATA[<p><a href="http://newschoolsecurity.com/wp-content/uploads/2010/08/what_they_know.png"><img class="aligncenter size-full wp-image-1721" title="what_they_know" src="http://newschoolsecurity.com/wp-content/uploads/2010/08/what_they_know.png" alt="" width="419" height="246" /></a></p>
<p>Interesting interactive data app from the Wall Street Journal about your privacy online and what various websites track/know about you.</p>
<p><a href="http://blogs.wsj.com/wtk/"><strong>http://blogs.wsj.com/wtk/</strong></a></p>
<p>Full disclosure, our site uses Mint for traffic analytics.</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2010/08/what-they-know-from-the-wsj/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pie charts are not always wrong</title>
		<link>http://newschoolsecurity.com/2010/02/pie-charts-are-not-always-wrong/</link>
		<comments>http://newschoolsecurity.com/2010/02/pie-charts-are-not-always-wrong/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 16:44:03 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1369</guid>
		<description><![CDATA[In a comment, Wade says &#8220;I’ll be the contrarian here and take the position that using pie charts is not always bad.&#8221; And he&#8217;s right. Pie charts are not always bad. There are times when they&#8217;re ok. As Wade says &#8220;If you have 3-4 datapoints, a pie can effectively convey what one is intending to [...]]]></description>
			<content:encoded><![CDATA[<p>In a comment, Wade says &#8220;I’ll be the contrarian here and take the position that using pie charts is not always bad.&#8221;  And he&#8217;s right.  Pie charts are not always bad.  There are times when they&#8217;re ok.  As Wade says &#8220;If you have 3-4 datapoints, a pie can effectively convey what one is intending to present.&#8221;  Which is true.  But in every case I&#8217;ve seen, those situations are as well served with a small bar graph.</p>
<p>
What&#8217;s the least contrived situation in which a pie chart is better than a bar graph or table?  (<a href="http://www.hemmy.net/2007/12/01/pacman-pie-chart/">Pac man</a> and <a href="http://emergentchaos.com/archives/2008/10/the-only-time-it-makes-sense-to-use-a-pie-chart.html">pies</a> are two obvious examples.)</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2010/02/pie-charts-are-not-always-wrong/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The Visual Display of Quantitative Information</title>
		<link>http://newschoolsecurity.com/2010/02/the-visual-display-of-quantitative-information/</link>
		<comments>http://newschoolsecurity.com/2010/02/the-visual-display-of-quantitative-information/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 16:11:47 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[Data Analysis]]></category>
		<category><![CDATA[measurement]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[Reports and Data]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1361</guid>
		<description><![CDATA[In Verizon&#8217;s post, &#8220;A Comparison of [Verizon's] DBIR with UK breach report,&#8221; we see: Quick: which is larger, the grey slice on top, or the grey slice on the bottom? And ought grey be used for &#8220;sophisticated&#8221; or &#8220;moderate&#8221;? I&#8217;m confident that both organizations are focused on accurate reporting. I am optimistic that this small [...]]]></description>
			<content:encoded><![CDATA[<p>In Verizon&#8217;s post, &#8220;<a href="http://securityblog.verizonbusiness.com/2010/02/16/sbir-2-dbir-comparison/?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+verizonbusiness%2FtWvQ+%28Verizon+Business+Security+Blog%29">A Comparison of [Verizon's] DBIR with UK breach report</a>,&#8221; we see:
<div style="text-align:center;"><img src="http://newschoolsecurity.com/wp-content/uploads/2010/02/pie-charts-suck.jpg" alt="pie-charts-suck.jpg" border="0" width="528" height="540" /></div>
<p>
Quick: which is larger, the grey slice on top, or the grey slice on the bottom?  And ought grey be used for &#8220;sophisticated&#8221; or &#8220;moderate&#8221;?<br />
<P><br />
I&#8217;m confident that both organizations are focused on accurate reporting.  I am optimistic that this small example in the utlity of pie charts will inform report writers.  The report writers and their graphics departments, loving their customers, will move to bar charts to help them compare numbers between sources.</p>
<p>
I&#8217;m confident that not using pie charts is a best practice.</p>
<p>
Elsewhere: &#8220;<a href="http://emergentchaos.com/archives/2008/10/the-only-time-it-makes-sense-to-use-a-pie-chart.html">The only time it makes sense to use a pie chart</a>.&#8221;</p>
<p>
And elsewhere: &#8220;<a href="http://www.amazon.com/gp/product/0961392142?ie=UTF8&#038;tag=httpwwwemer04-20&#038;linkCode=as2&#038;camp=1789&#038;creative=390957&#038;creativeASIN=0961392142">The Visual Display of Quantitative Information, 2nd edition</a>&#8220;</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2010/02/the-visual-display-of-quantitative-information/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Miscommunicating risks to teenagers</title>
		<link>http://newschoolsecurity.com/2009/12/miscommunicating-risks-to-teenagers/</link>
		<comments>http://newschoolsecurity.com/2009/12/miscommunicating-risks-to-teenagers/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 23:30:03 +0000</pubDate>
		<dc:creator>Russell</dc:creator>
				<category><![CDATA[Amusements]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[Science of Risk Management]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1093</guid>
		<description><![CDATA[A lesson in miscommunication of risk from "abstinence only" sex education aimed at teenagers.  The educators emphasize the failure rate of condoms, but never mention the failure rate of abstinence-only policies when implemented by teenagers.]]></description>
			<content:encoded><![CDATA[<p>Security programs that depend on 100% compliance are a bad idea, especially if they depend on 100% compliance from people who are proven to be poor in compliance capabilities.</p>
<p>Case in point:  I saw a <a href="http://www.der.org/films/abstinence-comes-to-albuquerque.html">documentary</a> about &#8220;Abstinence only&#8221; sex education programs for teens in the public schools of New Mexico &#8212; one negative example in Albuquerque and one positive example in Socorro.   (This is federally funded.)  Skipping over the most aggregious errors and misstatements in these programs, I noticed one big blooper regarding risk estimation and risk communication.</p>
<p>The educators who developed and deliver this program emphasize the failure rate of condoms as argument against relying on them.  In contrast, abstinence-only is touted because it is 100% effective in preventing unplanned pregnancy and all the negative stuff that goes along with it.  Funny thing&#8211;they never mentioned the <em><strong>failure rate of abstinence-only when implemented by teenagers!</strong></em>     Sure, you can tell teenagers to be abstinent and they can even commit to it, but would you bet on it?   What odds would you demand for a large bet(say, $100,000 from your bank account) that a large group of teens would remain abstinent for five years?  There are plenty of studies (e.g. <a href="http://www.cbsnews.com/stories/2007/12/02/health/main3564047.shtml">here </a>and <a href="http://aspe.hhs.gov/health/Reports/TeenRisk/TeenRiskTaking.html">here</a>) that demonstrate the limited capabilities of teens to avoid risky behavior, control impulses, rationally balance short-term gain against long-term pain, think beyond a short planning horizon, resist peer pressure, etc.    For most teens in the US, their &#8220;failure rate&#8221; (i.e. failing to avoid risky behaviors) is greater than 0%, and in cases of &#8220;multiple-risk adolescents &#8221; the failure rate is far above 0%.</p>
<p><span><a href="http://newschoolsecurity.com/wp-content/uploads/2009/12/full-body-condom.jpg"><img class="alignright size-full wp-image-1094" style="border: white 5px solid" src="http://newschoolsecurity.com/wp-content/uploads/2009/12/full-body-condom.jpg" alt="full-body condom" width="242" height="201" /></a></span></p>
<p>I would bet that condoms are much more reliable than the average teenage<span>r&#8217;s commitments to eschew immediate pleasures.   Of course, using both would be much more reliable than either alone.   This is &#8220;defense in depth&#8221;, of course.  Better still, take it to the max and advise that they add a &#8220;full-body condom&#8221;.  Then they would be &#8220;<em>fer sher,  fer sher</em>!&#8221;, as the Valley Girl might say. <img src='http://newschoolsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </span></p>
<p><span><a href="http://newschoolsecurity.com/wp-content/uploads/2009/12/full-body-condom.jpg"></a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/12/miscommunicating-risks-to-teenagers/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Ooops! and Ooops again!</title>
		<link>http://newschoolsecurity.com/2009/10/ooops/</link>
		<comments>http://newschoolsecurity.com/2009/10/ooops/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 15:47:46 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=832</guid>
		<description><![CDATA[Those of you who&#8217;ve heard me speak about the New School with slides have probably heard me refer to this as an astrolabe: Brett Miller just emailed me and asked (as part of a very nice email) &#8220;isn&#8217;t that an orrery, not an astrolabe?&#8221; It appears that I&#8217;m going to have to update my commentary. [...]]]></description>
			<content:encoded><![CDATA[<p>Those of you who&#8217;ve heard me speak about the New School with slides have probably heard me refer to this as an astrolabe:</p>
<p><div align="left">
<a href="http://www.flickr.com/photos/eldave/40717897/"><img src="http://newschoolsecurity.com/wp-content/uploads/2009/10/images09octorrey.jpg" alt="orrey.jpg" border="0" width="486" height="376" /></a></div>
<p>
Brett Miller just emailed me and asked (as part of a very nice email) &#8220;isn&#8217;t that an <a href="http://en.wikipedia.org/wiki/Orrery">orrery</a>, not an <a href="http://en.wikipedia.org/wiki/Astrolabe">astrolabe</a>?&#8221;</p>
<p>
It appears that I&#8217;m going to have to update my commentary.  Thanks, Brett!</p>
<p>
[And thanks Scott--I misspelt orrery, now corrected.]</p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/10/ooops/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Speaking in Michigan on Tuesday</title>
		<link>http://newschoolsecurity.com/2009/10/speaking-in-michigan-on-tuesday/</link>
		<comments>http://newschoolsecurity.com/2009/10/speaking-in-michigan-on-tuesday/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 15:14:40 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[presentation]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=756</guid>
		<description><![CDATA[Andrew Stewart and I will be speaking at the University of Michigan SUMIT_09 on Tuesday. We&#8217;re on 10:30-11:25. If you&#8217;re in the area, please come by.]]></description>
			<content:encoded><![CDATA[<p>Andrew Stewart and I will be speaking at the <a href="http://safecomputing.umich.edu/events/sumit09/">University of Michigan SUMIT_09</a> on Tuesday.  We&#8217;re on 10:30-11:25.  If you&#8217;re in the area, please come by.</p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/10/speaking-in-michigan-on-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Visualization Friday &#8211; Beautiful, Functional, and Effective</title>
		<link>http://newschoolsecurity.com/2009/09/visualization-friday-beautiful-functional-and-effective/</link>
		<comments>http://newschoolsecurity.com/2009/09/visualization-friday-beautiful-functional-and-effective/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 07:07:18 +0000</pubDate>
		<dc:creator>Russell</dc:creator>
				<category><![CDATA[presentation]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[visualization]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=682</guid>
		<description><![CDATA[We can all learn from this great role model, aimed at personal nutrition awareness and education: Nutritiondata.com.  If only security awareness web sites were this good.]]></description>
			<content:encoded><![CDATA[<p>We can all learn from this great role model, aimed at personal nutrition awareness and education: <a href="http://www.nutritiondata.com/">Nutritiondata.com</a> .</p>
<p>I encourage you to click on the images below to visit the site and explore interactive features. </p>
<p><a href="http://www.nutritiondata.com/facts/vegetables-and-vegetable-products/3043/2"><img class="alignleft size-medium wp-image-685" src="http://newschoolsecurity.com/wp-content/uploads/2009/09/nutritiondata-dot-com1-300x287.PNG" alt="nutritiondata-dot-com1" width="300" height="287" /></a><br />
<a href="http://www.nutritiondata.com/facts/vegetables-and-vegetable-products/3043/2"><img class="alignleft size-medium wp-image-686" src="http://newschoolsecurity.com/wp-content/uploads/2009/09/nutritiondata-dot-com21-300x133.PNG" alt="nutritiondata-dot-com2" width="300" height="133" /></a></p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p>If only security awareness web sites aimed at end-users and consumers were this good.</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/09/visualization-friday-beautiful-functional-and-effective/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Making Sense of the SANS &#8220;Top Cyber Security Risks&#8221; Report</title>
		<link>http://newschoolsecurity.com/2009/09/making-sense-of-the-sans-top-cyber-security-risks-report/</link>
		<comments>http://newschoolsecurity.com/2009/09/making-sense-of-the-sans-top-cyber-security-risks-report/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 22:52:54 +0000</pubDate>
		<dc:creator>Russell</dc:creator>
				<category><![CDATA[Data Analysis]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[top risks]]></category>

		<guid isPermaLink="false">http://newschoolsecurity.com/?p=613</guid>
		<description><![CDATA[The SANS Top Cyber Security Risks report has received a lot of positive publicity. I applaud the effort and goals of the study and it may have some useful conclusions. We should have more of this.  Unfortunately, the report has some major problems.  The main conclusions may be valid but the supporting analysis is either confusing or weak.  It would also be good if this study could be extended by adding data from other vendors and service providers.
]]></description>
			<content:encoded><![CDATA[<p>The SANS <a href="http://www.sans.org/top-cyber-security-risks/">Top Cyber Security Risks</a> report has received a lot of positive publicity (19 online stories, at last count).  (TippingPoint and Qualys were partners in the report.) But none of the reporters or bloggers analyzed the report, the methods, or the data.  They just repeat the main points from the report. </p>
<p>I applaud the effort and goals of the study and it may have some useful conclusions. We should have more of this type of study, especially at a large scale.</p>
<p>Unfortunately, the report has some major problems, listed roughly in order of severity:  (for details, read on&#8230;)</p>
<p><span id="more-613"></span></p>
<ol>
<li><strong>The most basic charts are missing.</strong>  What was the total number of attacks in the study period?  The total number of vulnerabilities?  What percentage of identified vulnerabilities were actually attacked?  Were the most prevalent vulnerabilities attacked most frequently?  What how prevalent are zero-day vulnerabilities as a percentage of total vulnerabilities?</li>
<li><strong>Some of the most important statements in the report have no backing data or detailed analysis</strong>.  Here are examples from the Executive Summary:
<p><em>&#8220;Waves of targeted email attacks, often called spear phishing, are exploiting client-side vulnerabilities in commonly used programs such as Adobe PDF Reader, QuickTime, Adobe Flash and Microsoft Office.”</em></p>
<p>There is no analysis or data in the report regarding targeted email attacks (a.k.a. spear phishing).  The rise of spear phishing has been documented <a href="http://www.signtific.org/en/node/52935">elsewhere</a>, but if there was data coming from this study to support that assertion, it didn’t appear in the detailed section of the SANS report. </p>
<p><em>&#8220;Attacks against web applications constitute more than 60% of the total attack attempts observed on the Internet.”</em> </p>
<p>Looking at the detailed sections of the report, I could not find any table or chart that listed the total number of attacks in the study and the percentage of attacks on each on category (i.e. web applications vs. app platform vs. OS).  (Figure 1 doesn’t do it.  <a href="http://newschoolsecurity.com/2009/09/visualization-friday-%e2%80%93-improving-a-bad-graphic/">Here</a> is my critique of this bad graphic.)</p>
<p><em>&#8220;Rising numbers of zero-day vulnerabilities”</em></p>
<p>I couldn’t find any support in the report for the assertion that the number of zero-day vulnerabilities were rising.  There was no data analysis and no charts in the “Zero-day Vulnerability Trends” section.</p>
<p><em>&#8220;On average, major organizations take at least twice as long to patch client-side vulnerabilities as they take to patch operating system vulnerabilities. In other words the highest priority risk is getting less attention than the lower priority risk.”</em></p>
<p>There isn’t any chart that shows the average time to patch client-side vulnerabilities vs. OS vulnerabilities.  They don’t mention or analyze server-side application patching, which seems weird.  How about a chart with two bars, one for web applications and other for OS, showing the average number of days to reduce vulnerabilities by half?  That would be simple and clear.  Regarding the charts they do show…</li>
<li><strong>The charts in the “Vulnerabilities” section are poorly executed and poorly explained.</strong>  The wiggly “percentage vs. days” graphs leave me scratching my head.  The data is probably in there, but it’s very hard to see in this format. Here’s my interpretation of these charts (but I might be wrong).  These are supposed to “aging charts” that graph the % of vulnerabilities that remain unresolved or unpatched after X days.  If none are resolved, then the line should be flat at 100%.  If all are resolved on day one, then it would be vertically down from 100% to 0%.  If they are gradually resolved, then the line will slope downward.  If some of the vulnerabilities are never resolved, then the line should plateau at some residual level. But why don’t the charts all start with a value of 100% on Day zero?  I don’t know and it’s not explained.  I’m guessing that it takes some number of days before all the vulnerabilities appear in the scans. More disturbing is the periodic oscillations in data series.  These jump out visually.  But what does this pattern mean?   You might be inclined to think that vulnerabilities were resolved every 5 to 7 days, only to reappear the next week, and so on.  That would be a huge process problem.  But it turns out that these oscillations are a spurious result of the scanning process and the data analysis method.  Consider this phrase from the report:
<p><em>“Periodic drops in detection rates occur during the weekends when scanning focuses on servers rather than desktop machines and the detection rates of vulnerabilities related to desktop software fall accordingly.”<br />
</em><br />
If this is really true (and it could probably be verified), then it would make sense to drop weekend data points and just include weekday data points for client-side vulnerabilities.  The data analysis could be further improved by using a smoothing or curve fitting method, because what counts in this analysis is not the day-by-day squiggles but the overall slope of the curve and whether it plateaus.  Finally there should be some marker for “half-life” or something, to allow easy visual identification of how long it takes to resolve half of the vulnerabilities in each class.</li>
<li>One finding was not highlighted but deserves more attention: <strong>the intentional use of security-violating methods by legitimate web applications.</strong>  This blurs the distinction between “good guys” and “bad guys” and makes security management much more difficult.  Examples from the report:
<p><em>&#8220;…an advertiser&#8217;s banner might be embedded in a web page which is set up to <strong>reflect</strong> some JavaScript off of the advertiser&#8217;s HTTP server for tracking purposes. However, in this case, there is little risk because the site in question (usually) has full control over his/her page, so this request to the advertiser is not generally malicious. It is the <strong>&#8220;reflection&#8221; attacks</strong>, along with attacks that leverage flaws in form data handling, that make up the vast majority of XSS attacks that we have seen in the last six months.”</em> [emphasis added]</p>
<p><em>”A very large spike in SQL Injection attacks in July was caused mostly by an online advertiser who distributed code to many affiliates using SQL injection as functionality. The application was quickly pulled, resulting in a large drop in events for the month of August.”</em></p>
<p>Related to this trend is the intentional use of security- and privacy-violating technologies to support marketing purposes, e.g. <a href="http://www.huntonprivacyblog.com/2009/06/articles/enforcement-1/sears-settles-ftc-enforcement-action-regarding-consumer-tracking/">FTC’s action against Sears</a> .</li>
<li><strong>The analysis of Cross-site Scripting is confusing at best</strong>.  In the attack section, they say: “Cross Site Scripting (XSS) is one of the most prevalent bugs in today&#8217;s web applications.”  But looking at the graph immediately below (Fig. 13), it doesn’t look like XSS attacks are frequent – numbering in the thousands while other attacks number in the millions.  Looking down to the vulnerabilities section, there is no data or analysis of XSS vulnerabilities as a percentage of the total.</li>
<li><strong>There is no mention of uncertainty or confidence levels</strong> in the analysis or conclusions.   For example, was the TippingPoint attack data adjusted for false positives and false negatives?  It&#8217;s well known that all Intrusion Detection/Prevention Systems (IDPS) are prone to false positives and false negatives, no matter how well designed or tuned.  This doesn’t discredit the data or analysis, but it does add uncertainty and reduce confidence levels. </li>
<li><strong>There was no mention of the limitations of the attack or vulnerability data.</strong>  Of course, all data sources will have limitations.  It’s essential that the authors factor this in to the analysis and make clear that they are not analyzing the full spectrum of cyber attacks or vulnerabilities.  For example, there is no coverage of insider threats, social engineering, combined physical and cyber attacks, or data leakage.  There is also no coverage in the data sets for complex targeted attacks.
<p><strong>Attack data limitations.</strong> As a network appliance, TippingPoint’s Intrusion Detection/Prevention Systems (IDPS) do not detect all types of attacks.  Specifically, they cannot detect attacks within encrypted network traffic, attacks that come through wireless protocols, or attacks that utilize application payload, e.g. code injection.  Also, the IDPS are susceptible to various types of attacks, most involving large volumes of traffic, which can “blind” the IDPS for a period of time.  IDPS appliances also don’t detect authorization or authentication attacks.  (I’m no expert in IDPS or intrusion detection in general, so I’m drawing from other sources, including <a href="http://csrc.nist.gov/publications/nistpubs/800-94/SP800-94.pdf">NIST 800-94: Guide to Intrusion Detection and Prevention Systems</a>.) </p>
<p><strong>Vulnerability data limitations.</strong>  Qualys vulnerability scanning service identifies many vulnerabilities in hardware configuration, operating systems, networking, libraries, platforms (e.g. Adobe Acrobat and Flash), etc., including: Misconfigured or unpatched servers, laptops and desktops; Out-of-date or misaligned security policy; Unauthorized hardware, software or applications; Easily-guessed passwords; and Inadequate controls on traffic from trusted third-party networks.But there are limitations. </p>
<p>Most obvious but unstated, Qualys identifies <em>known vulnerabilities only</em>, not vulnerabilities that have not yet been discovered.  While CERT has been quoted as saying “99% of attacks exploit known vulnerabilities”, this does not mean that there is no risk associated with undiscovered vulnerabilities. </p>
<p>More important is that automated vulnerability assessment scanning doesn’t provide a macro view on the relative riskiness of vulnerabilities. According to a <a href="http://www3.villanova.edu/gartner/research/137400/137499/137499.html">Gartner report</a>, vulnerability assessment scanning systems “provide data on devices within the network, but it remains difficult to understand how the overall network is vulnerable, or how vulnerabilities within a device affect their neighbors. What may appear as a benign or low-priority vulnerability on a host may be used as a launching point for an attacker to penetrate other devices on the network.”   Thus, the prioritization of vulnerabilities in the report seems to be based on their prevalence in the total population, not based on the relative riskiness of each vulnerability in it’s IT and network context.  (That would require other analysis, including attack graphs, penetration testing, etc.) </p>
<p>Finally, Qualys only added Web Application Scanning (WAS) to their QualysGuard Security and Compliance Suite on May 26, 2009. This was half-way through the study period (March – August 2009), and it’s not clear from the report whether WAS produced any data used in this study or how widely it is being used in the customer base.  (Qualys suite is software as a service (SaaS), so new functionality should be immediately available to all subscribers.  Who knows what percentage of customers started using that functionality.)</li>
<li>There was very little explanation of the methodology.  I’m guessing that they drew conclusions based on total number of attacks of various types, compared to the total number of vulnerabilities of various types.  I didn’t see any analysis of the severity of each attack type, or any data regarding how many of these attacks succeeded in exploiting vulnerabilities.</li>
<li>There is insufficient background on the data sets.  For example, what are the demographics of the TippingPoint data (attacks) and the Qualys data (vulnerabilities)?  How many TippingPoint customers are also Qualys customers?  Some of the context information that was listed seemed irrelevant, e.g. &#8220;TippingPoint intrusion prevention systems protect 6,000 organizations&#8221; and &#8220;vulnerability data from 9,000,000 systems compiled by Qualys&#8221;.  Yes, that&#8217;s a lot of organizations and systems, but compared to what?</li>
<li>What was the point of the charts and analysis on the geographic origins and destinations of attacks?  I presume that this could be very important for understanding the attacking parties (“bad guys”) and the resources they use. Maybe it could also to help guide IT managers on the likelihood of certain attacks in their geography.  But the analysis falls short of either purpose.  As it is, these charts simply make me say “hmmmmm….”.</li>
</ol>
<p>As a general comment, the report is poorly organized.  I found it hard to read, and it looked like a “cut and paste” job with no overall editing.  It was especially hard to trace the line of reasoning from the executive summary to the detailed sections.  Also, “&#8230;Four Key Attacks” section is confusing.  They actually list five key attacks, not four, but then say there are really only two categories: Server-side HTTP attacks and Client-side HTTP attacks.  Mis-numbering like this is a basic editing mistake.</p>
<p>Lastly, I wonder if there is any way that this study could be augmented and extended with data from other sources.  I bet that other web application scanning services (White Hat, et al), penetration testing companies, managed security services companies, and forensic analysis services could add a lot to get a more comprehensive picture.  As a professional community, we need to find ways to do this sort of study in a way that can be extended and combined with other data sets and studies.</p>
]]></content:encoded>
			<wfw:commentRss>http://newschoolsecurity.com/2009/09/making-sense-of-the-sans-top-cyber-security-risks-report/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

