Article or Troll? Securing the 'Net

There's an article over on SecurityFocus by Tim Mullen titled " Stop Being a Victim". I'm undecided as to whether it's a troll or not. He appears to be suggesting that the way to improve the security for Internet users is for those users understand and care enough to secure their computers.... It's a nice idea, but having been a network admin in the past and having supported a lot of users in my time, my initial thought on reading it was "BWA HA HA HA HA"
The idea of getting the X million people currently connected to the Internet to understand what is required to secure a computer on the Internet is quite amusing, given that professional IT people in large corporations regularly get it wrong looking at the ease with which hackers like Adrian Lamo have penetrated their networks.
So, what is the answer then?? There are a couple of ideas which come to my mind.
1. Make ISPs and network access providers responsible (and legally liable) for traffic from their networks. Of course, the knock on effect of that would be a huge rise in Internet access costs and greatly reduced functionality as ISPs would have to install outbound filtering to stop attacks originating from their networks infecting others...
2. Split the Internet. One answer for some users would be for the recreation of walled Internet communities (like AOL and CompuServe of old). Where there is no access to the mainstream Internet from the community (or very controlled access). That would, however, need to be combined with more control over the end-users of the service.... and again far higher charges for access as the provider provided security services to the subscribers...
3. Improve software to make it more secure, and less vulnerable to attack.... This is the one that's currently being tried out by Microsoft, with them improving software quality and adding security feature to their operating systems. However I'm not convinced that this will ever really have the desired effect... At the moment, my perception is that Worm/Virus attacks are on the up and also the number of patches coming out of Redmond is going up, not down....
I'd mention the idea of regulation as a concept, except for in a global Internet, the chances of getting all the worlds governments lined up behind decent legislation is what I can only describe as, extremely unlikely...
So where does that leave us? The answer is, I'm not sure. Sorry, this isn't some published article so I don't have to have a silver bullet solution ;op

MetaSploit redux

Well I had a chance to download and have a quick test of the metasploit framework which I talked about earlier.
It definately does what it says on the tin! I downloaded it, ran the web server version (one command), fired up a known vulnerable Virtual machine, and very soon had a remote administrator exploit against IIS5 launched.
I think it could be very useful in the securtiy industry from the point of view of convincing companies that level of technical knowledge required to hack into their systems is not high.... This is needed as a common reason given by management in companies for not doing things like patch management of internal servers is that "well no-one would know how to do that" with the thought that hacking a server requires a high level of technical expertise...

Prelude IDS

There's an interesting article over at Local Area Security which talks about the prelude IDS framework. It's a application which provides, amongst other things, a console for viewing alerts which can be pulled in and aggregated from a number of sources...

The end of ROSI, one can but hope

information security: RoSI: R.I.P.
There's an interesting link over at Axel Eble's blog to a report that, hopefully, people are geting round to the throught that security is not something that you calculate the R.O.I on, more that you view it like insurance or fire control system, as loss avoidance.
The problem with calculating ROSI has always been quantification, and it's always struck me that people that suggest it as a good way of justifying security spend, come up very short on specifics when asked, how it would actually be implemented.....

Spyware in the corporation

An interesting article over at computerworld Spyware in the office .
The existance of spyware on corporate networks is definately not a good thing. Apart from the obvious reasons or potential leaks of confidential information or excess traffic being generated, there is the problem that deploying code on a complex platform could cause other, business critical, applications to stop working...

Portknocking resources

Slashdot | Port Knocking in Action
there's a story on slashdot.org covering a port knocking proof of concept. Ironically there's better links in one of the early comments than in the story itself! I've made a list of them below for reference.
portknocking.org
An article at Linux Journal
An article at Linuxsecurity.com
A tutorial at Librenix
For those of you wondering "what the stuff is port knocking anyway?" here's a definition I got from the UNIX FAQ at aplawrence.com
" Port knocking is a security technique to allow access to people who know the "secret knock". The basic idea is this: packets addressed to certain ports are silently ignored but are logged. If you contact the right series of ports in the right sequence, possibly with the additional condition of holding the ports open for a certain period of time, the firewall rules will be adjusted to allow you access.
The interesting things about this technique include the fact that you can obviously transmit information with the pattern or duration of the "knocks". That means that you could request that some other ip be allowed access, or just request that certain information be sent to you. Another interesting aspect is that because the packets are silently dropped, there's no way to scan a host and determine that it is using a port knocking technique. Even if you knew that it was using such a technique, but didn't know the algorithm, any brute force attempt would be effectively impossible"