Navigation
The Black Book of Identity Access Mgmt
This form does not yet contain any fields.
    « Now that I'm here, I forgot why I came | Main | RFI's are a PITA »
    Friday
    Dec102010

    Don't mind me, I'm just robbing the place

    It doesn't take much to ruin a country's entire diplomatic posture, its sense of security, its standing in the world, its dignity. All it takes is two guys: one self-righteous guy to publish a bunch of secret documents, and another guy to steal them.

    And this is Wikileaks. Mr. Assange feels that he's somehow making the world a better place by spilling a whole lot of secrets to which he wasn't entitled. While some of this stuff actually bears being submitted to the light of day, it turns out a whole lot of it is stuff that could set back efforts to fight piracy, fight corruption, push the North Koreans and the Burmese to the table, and so on.

    Regardless of his motives, it took a willing accomplice, in this case a young simpleton in the military, with WAY too much access and not nearly enough supervision. He downloaded untold thousands of documents, then transmitted them to Assange. HOW did this moron get his hands on all this intelligence? How was he able to download so MANY docs and move them into the wrong hands?

    Sure there are plenty of people who need access for one reason or another (although I kinda wonder why this 23-year-old dweeb was one of them). But it's not always just WHO you are or WHAT you are. It's also WHAT YOU'RE DOING. Think back to basic access management, like an OIM or a Siteminder. Policies match up id, origin, and request. Okay, so you could say that an access policy gives this goober access to these docs. But let's add that other dimension, HOW you're doing WHAT you're doing.

    Is he allowed to download this stuff? Looks like it. Should he be allowed to download ALL of it? Holy crap, Batman!

    At some point, you need to examine BEHAVIOR. Why do you care? How often does classified stuff fly off the shelves? No idea. But in the business world? All the time. Here's the business case:
    Poindexter downloads five or six docs a week. Today, he's downloading dozens. Oh, and after hours. There's TWO red flags, in fact. Does he ever do stuff after hours? No. Does he normally download this kind of volume? No. Zzzzzzt. Something's wrong. Shut down his session and send out an alert.

    Maybe he's got a perfectly legit reason for doing so. So you're interrupting him. He'll be back online soon enough, IF it's legit. But maybe he's leaving, and wants to take a bunch of IP with him to the competitor. Maybe he's being paid by industrial spies. Maybe he wants to start his OWN competitive business (I know a guy who did this very thing, and kind of got away with it). An old customer of mine monitoring for anomalies caught an employee downloading THOUSANDS of design docs (telecomm hardware), and discovered that he had less than good intentions.

    There are various products out there that handle this kind of behavioral monitoring, in conjunction with the usual id-origin-time of day - request policy matchup. The one I've got the most experience with is the horrendously named Oracle Adaptive Access Manager, or OAAM. Pronounce the acronym phonetically, and it sounds like you've got gas pains. Anyway, you can put users into behavioral buckets, based on title, location, whatever, and when a member of the bucket acts in a way that doesn't fit the usual pattern, OAAM automatically shuts them down. If it's found to be chronic yet anomalous behavior, that user might get moved into another bucket.

    Another cool thing is to just turn on OAAM and let it build those buckets. You don't know what you don't know, right? So let it monitor for a few weeks and  tell you what those patterns are, and then start applying those policies.

    In the wake of Wikileaks, the US military is also banning flash drives and other removable media. There's a solution for that as well, but maybe we'll cover that next time. In the meantime, it's WHO, WHAT, from WHERE, and HOW. Sure, now we know that the president of Afghanistan tends to go off his meds, but did we really need to?

    PrintView Printer Friendly Version

    EmailEmail Article to Friend

    Reader Comments (1)

    Este Laudermac cosmetics wholesale,discount mac cosmetics Guerlainwholesale mac cosmetics,Mac PigmentClarinsMac Concealer, Mac EyelinerChannelMac Eyeshadow,Mac Lipstick DiorMac Mascara, Mac FoundationMacChanel Cosmetics,Mac Makeup Bags Bobbie BrownMac Venomous Villains,All ShookUp OPI CollectionSo you want to write a children's bookopi wholesale.discount opi nail polish Greatwholesale opi nail polish!opi nail polish Writing for children is a wonderful hobby or occupation OPI India(NLI41)(OPI India(NLI45)as in my caseOPI India(NLI51))OPI Sunbeleivable(NLD28).OPI LightMySapphire(NLB60)But where does one startSouth Beach OPI Collection?Hong Kong OPI Collection What does one need to do to become a children's authorHoliday Whishes OPI Collection?Katy Perry OPI CollectionThis year we have heard rumors of a new styler with the tag lineCheap Ghd Hair "Hair Straighteners SaleChoose Your Own DestinyDiscount GHD Straighteners"Ghd Hair Straighteners Sale.GHD Radiance Set WellGold Classic styler,GHD IV Hot Pink Hair Straighteners it turns out this is not just one new stylerPure Limited Edition GHD IV Styler,GHD Gold IV Styler Hair Straighteners but 4 brand new glossy stylers which have been made available in redGHD Mini IV Styler Hair Straighteners,New ghd Rare Iv styler Limited Edition blueGHD midnight Gift Set-includes the ghd Gold Classic, New ghd Limited Edition Precious Iv styler & gift setgreen and purpleGHD Midnight Deluxe Gift Set with ghd's sleekest ever styler. the rather colorful Custom Nike High nike shox sko-billige nike shox sko Back to the Future II Horrible Pack and the Nike 6.0 Dunk High Black Coralnike sko nettbutikk;nike shox norge to name but a few of the numerousAirMax TN Men_27 'Nike Shox Men SkoHighAirMax TN8 Men_01' Nike Shox R2 WomenNike DunksNike Shox TL3 Women.Nike Shox Navina Sko Of all Nike Dunks that I have gotten to use over my lifetimeNike Shox NZ Plating Men -Nike Shox R4 Rival Sko and they are quite a number Nike Air Max 2009 Men- Nike Air Max 2012 WomenI have to confess that it is Nike Supreme Blue that I have gotten most enchanted with.
    http://shuijin0024.blog.163.com
    http://hi.baidu.com/shuijin0024/blog
    http://blog.sina.com.cn/u/2417426977
    http://blog.sohu.com/people/!c2h1aWppbjAwMjRAaG90bWFpbC5jb20=
    http://shuijin12.blog.com
    http://shuijin12.2logs.com
    http://shuijin12.over-blog.com
    http://17278441.blog.hexun.com
    http://www.equestrianblogging.com/blogs/shuijin0024
    http://shuijin0024.insanejournal.com
    http://www.blurty.com/users/shuijin0024
    http://shuijin0024.mylivepage.com/blog/index
    http://shuijin12.nipox.com
    http://shuijin12.allmyblog.com
    http://www.adultblogs.com/users/shuijin0024
    http://shuijin0024.inube.com
    http://www.holatu.com/user/shuijin0024/blogs
    http://yu123456.manablog.jp
    http://shuijin.sexusblog.com
    http://shuijin12.blogdetik.com
    http://shuijin12.bloggd.org
    http://shuijin12.eklablog.com
    http://shuijin12.podbean.com
    http://shuijin123.blogoak.com
    http://blog.cnfol.com/shuijin12
    http://myindiacafe.com/blogs/shuijin12
    http://shuijin13.blogfa.com
    http://gvrl.com/blogsearchresults.asp?basicsearch=shuijin123
    http://www.shuijin0024.19dog.com
    http://phlog.net/shuijin0024
    http://shuijin13.beeplog.com
    http://www.blogstoday.co.uk/bloghome.aspx?username=shuijin123
    http://shuijin123.tiblog.fr
    http://shuijin12.blog.forexstar.com.cn
    http://www.yourlocalinsider.co.uk/pg/blog/owner/shuijin0024
    http://shuijin8567.tumblr.com
    http://www.freedatingsiteahead.co.uk/blogs.php?action=show_member_blog&ownerID=4600
    http://www.tripcafe.pl/blogs.php?action=show_member_blog&ownerID=1907
    http://shuijin12.iciblog.com
    http://shuijin12.pokerweblogs.com
    http://www.blogusers.com/sme_blog.php?u=q123456&action=view_cat&cat=5250
    http://shuijin0024.fotopages.com
    http://www.muslimduniya.com/member/view_blog.php?profile_id=1014
    http://www.metatrader.info/blog/18477
    http://www.igolf.to/view_blog.php?profile_id=9169
    http://hurones.net/blog/4462
    http://www.quiltsnow.com/blog/2166
    http://www.selectify.com/blogs/shuijin12
    http://shuijin.blogg.se
    http://mysolapur.com/extra/?q=blog/4320
    http://www.malibunetwork.com/member/view_blog.php?profile_id=2151
    http://codesnipers.com/?q=blog/13647
    http://obshestvo.ru/blog/1644
    http://www.dinmo.me/space.php?uid=3981&do=blog&view=me
    http://www.kerchoonz.com/user/shuijin8567/blogs
    http://www.filipinopeople.com/user/shuijin12/blogs
    http://nga.phpfoxcustomization.com/user/shuijin12/blogs
    http://pamplonaempleo.socialgo.com/members/profile/1373/blog
    http://gem.socialgo.com/members/profile/4945/blog
    http://gritosverticais.socialgo.com/members/profile/239/blog
    http://motomodders.socialgo.com/members/profile/802/blog
    http://mujerdehoy.socialgo.com/members/profile/2408
    http://www.newar.com.np/blog.php?user=shuijin12
    http://shuijin12.blogbus.com
    http://shuijin8567.sweetcircles.com
    http://blog.zol.com.cn/shuijin0024
    http://www.shuijin0024.un165.com
    http://www.spanishmusic.biz/user/shuijin123/blogs
    http://askmilton.com/community1/blogs/posts/shuijin12
    http://gfdgamestudios.com/blogs/posts/shuijin12
    http://www.redcarpettonight.com/index.php?do=/public/user/blogs/name_shuijin12
    http://www.jenshouseofscrap.com/blog/2122
    http://shuijin12.sier.no
    http://www.portalpirata.com/blog/17563
    http://blog.bitcomet.com/17049287
    http://truckarmy.com/user/shuijin12/blogs
    http://shuijin13.blogdedag.nl
    http://www.homepage-dienste.com/blog/shuijin13?
    http://www.mein-blog.net/b-shuijin12
    http://www.xxllove.net/blogs_view.php?id=103680
    http://www.liverpoolfc.lu/blog/shuijin12
    http://shuijin13.blog.fc2blog.net
    http://www.kolspot.com/user/shuijin12/blogs
    http://www.cnfblog.com/blogs.php?blog_id=12654
    http://blogsdelagente.com/shuijin12
    http://www.cretaceousworld.com/geobooks/My.asp?User_ID=4451
    http://solobuscame.com/social/blog.php?user=shuijin12
    http://www.freeblognetwork.com/shuijin12
    http://bbs.hkange.com/boke.asp?shuijin12.index.html
    http://shuijin12.blognic.net
    http://shuijin12.blog-libre.net
    http://www.blog2net.com/shuijin12
    http://www.exfling.com/community/blogs/posts/shuijin12
    http://redsocial.redindustrial.com.mx/blog.php?user=cheap444@hotmail.com
    http://www.sanalkahve.com/user/shuijin12/blogs
    http://www.bullshitzone.com/shuijin12/blog

    December 16, 2011 | Unregistered Commenterdiscount opi nail polish

    PostPost a New Comment

    Enter your information below to add a new comment.

    My response is on my own website »
    Author Email (optional):
    Author URL (optional):
    Post:
     
    Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>