<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Overhack</title>
	<atom:link href="http://threatthoughts.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://threatthoughts.com</link>
	<description>Logs or it didn&#039;t happen.</description>
	<lastBuildDate>Wed, 08 May 2013 21:03:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='threatthoughts.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Overhack</title>
		<link>http://threatthoughts.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://threatthoughts.com/osd.xml" title="Overhack" />
	<atom:link rel='hub' href='http://threatthoughts.com/?pushpress=hub'/>
		<item>
		<title>Ethics versus economics for security research</title>
		<link>http://threatthoughts.com/2013/03/07/ethics-versus-economics-for-security-research/</link>
		<comments>http://threatthoughts.com/2013/03/07/ethics-versus-economics-for-security-research/#comments</comments>
		<pubDate>Fri, 08 Mar 2013 03:23:53 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Manifesto]]></category>
		<category><![CDATA[Active Defense]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Intelligence]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1351</guid>
		<description><![CDATA[Independent security researchers often have a reputation as narcissistic vulnerability pimps (true or not), but the environment which has evolved around information security largely drives this. This came to a head for me tonight in a Twitter discussion kicked off &#8230; <a href="http://threatthoughts.com/2013/03/07/ethics-versus-economics-for-security-research/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1351&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='500' height='312' src='http://www.youtube.com/embed/pzcLTPy8yDQ?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>Independent security researchers often have a reputation as <a href="http://securityblog.verizonbusiness.com/2010/04/22/redefining-security-researcher/">narcissistic vulnerability pimps</a> (true or not), but the environment which has evolved around information security largely drives this. This came to a head for me tonight in a Twitter discussion kicked off by Steve Werby:</p>
<blockquote class='twitter-tweet'><p>CTFs are awesome, but if we can teach students how to articulate recommendations in a way non-technical staff can understand, even better.&mdash; <br />Steve Werby (@stevewerby) <a href='http://twitter.com/#!/stevewerby/status/309855713038049280' data-datetime='2013-03-08T02:38:53+00:00'>March 08, 2013</a></p></blockquote>
<p>Creating an exploit can often pay anywhere between 1k and 100k (or possibly more in specific circumstances), depending on the researcher&#8217;s choice of market and product (or technology). This even affects areas that many users believe unrelated, like <a href="http://www.technologyreview.com/view/512031/military-malware-may-have-killed-the-iphone-jailbreak/">mobile OS jailbreaks</a>, which essentially consist of exploits to gain root control despite the operating system&#8217;s best efforts to the contrary.</p>
<p>No equivalent market exists for threat-related research. Freelance malware analysts don&#8217;t have similar economic drivers because organizations with an interest in this information generally do the research themselves. You can&#8217;t monetize malware or attribution the same way. Put another way, nobody believes that Krebs and Danchev get rich from what they do. I don&#8217;t think we can &#8220;fix&#8221; this with the market, although I&#8217;d welcome discussion of ideas or evidence to the contrary. But we need to recognize this when thinking about issues around software security and threat identification.</p>
<p>Believing that security, on its own, adds value often turns into a <a href="http://techbuddha.wordpress.com/2010/02/09/the-broken-windows-economics-of-it-security/">form of the broken windows fallacy</a>. And creating artificial demand for threat intelligence could lead to all sorts of perverse incentives. Some of the same organizations interested in purchasing vulnerabilities and exploits might have an interest in highly-focused intelligence, such as espionage on particular threat groups, but at this point the line between &#8220;offense&#8221; and &#8220;defense&#8221; becomes very fuzzy.</p>
<p>I&#8217;d love to hear alternate viewpoints and suggestions on where this can go.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1351/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1351&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/03/07/ethics-versus-economics-for-security-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>
	</item>
		<item>
		<title>Pizza with a bad taste: BHEK intel</title>
		<link>http://threatthoughts.com/2013/03/06/pizza-with-a-bad-taste-bhek-intel/</link>
		<comments>http://threatthoughts.com/2013/03/06/pizza-with-a-bad-taste-bhek-intel/#comments</comments>
		<pubDate>Thu, 07 Mar 2013 04:36:04 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Black Hole Exploit Kit]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[thug]]></category>
		<category><![CDATA[VirusTotal]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1376</guid>
		<description><![CDATA[I got some spam today that made me hungry (even after eating real spam so many times as a kid). You've just ordered pizza from our site [snipped yummy but long listing of pizzas and drinks including crappy beer] If &#8230; <a href="http://threatthoughts.com/2013/03/06/pizza-with-a-bad-taste-bhek-intel/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1376&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.memecenter.com/fun/152408/pizza-fail"><img class="aligncenter size-large wp-image-1392" alt="pizza fail" src="http://overhack.files.wordpress.com/2013/03/pizza-fail_o_152408.jpg?w=500&#038;h=399" width="500" height="399" /></a>I got some spam today that made me hungry (even after eating real spam so many times as a kid).</p>
<p><code>You've just ordered pizza from our site</code></p>
<p>[snipped yummy but long listing of pizzas and drinks including crappy beer]</p>
<p>If you haven&#8217;t made the order and it&#8217;s a fraud case, please follow the link and cancel the order.<br />
CANCEL ORDER NOW!</p>
<p>If you don&#8217;t do that shortly, the order will be confirmed and delivered to you.</p>
<p>With Respect<br />
AZZO`s Pizzeria</p>
<p>However, I wasn&#8217;t really worried about the fraud possibility, so I decided to ignore the spam and instead to take the opportunity to run the URL through <a href="https://github.com/buffer/thug">thug</a>. It performed spectacularly well, grabbing the page, finding the exploits (at least some of them, anyway), and keeping everything neat, orderly, and secure.</p>
<p><strong>hxxp://sweety-angel[.]de/local.htm</strong> redirects to <strong>hxxp://gimalayad[.]ru:8080/forum/links/column.php</strong>, which loaded a Java applet, a Flash file, and two PDF documents. At the time I ran them, VirusTotal hadn&#8217;t seen them before but a few engines identified the PDFs and the Flash file as part of the Black Hole Exploit Kit. I found the use of old Adobe Reader vulnerabilities (2010 vintage) a little humorous. Contact me via <a>Twitter</a> or <a href="mailto:kylem@xwell.org">email</a> if you&#8217;d like the actual files. I published the <a href="https://docs.google.com/document/d/1TQo9wV9ERieW_33so_9a0b0_vULeRUvHvPkLJrRtz9E/pub">IOCs as a Google Doc</a> for reference.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1376/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1376/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1376&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/03/06/pizza-with-a-bad-taste-bhek-intel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/03/pizza-fail_o_152408.jpg?w=500" medium="image">
			<media:title type="html">pizza fail</media:title>
		</media:content>
	</item>
		<item>
		<title>Brain dump of DFIR and network security research ideas</title>
		<link>http://threatthoughts.com/2013/03/03/brain-dump-of-dfir-and-network-security-research-ideas/</link>
		<comments>http://threatthoughts.com/2013/03/03/brain-dump-of-dfir-and-network-security-research-ideas/#comments</comments>
		<pubDate>Mon, 04 Mar 2013 01:46:36 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Notes]]></category>
		<category><![CDATA[Active Defense]]></category>
		<category><![CDATA[DDOS]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[Honeypots]]></category>
		<category><![CDATA[Indicators of Compromise]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Threat Intelligence]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1368</guid>
		<description><![CDATA[I&#8217;ve seen several people talk about lacking ideas for research projects, often around DFIR or network security. Personally, I have the opposite problem: endless ideas for projects, often with the barest hint of a start, but not enough time to &#8230; <a href="http://threatthoughts.com/2013/03/03/brain-dump-of-dfir-and-network-security-research-ideas/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1368&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<div id="attachment_1370" class="wp-caption alignright" style="width: 224px"><a href="http://overhack.files.wordpress.com/2013/03/rro2q8r.jpg"><img class=" wp-image-1370  " alt="Maybe I could get more of these done with this." src="http://overhack.files.wordpress.com/2013/03/rro2q8r.jpg?w=214&#038;h=300" width="214" height="300" /></a><p class="wp-caption-text">Maybe I could get more of these done with this.</p></div>
<p>I&#8217;ve seen several people talk about lacking ideas for research projects, often around DFIR or network security. Personally, I have the opposite problem: endless ideas for projects, often with the barest hint of a start, but not enough time to pursue them all. So I thought I&#8217;d publish a bit of a brain dump. I actually have made good progress on a few of these, and I have concrete plans around others (beyond just &#8220;wouldn&#8217;t it be cool if&#8230;&#8221;), but in any case I&#8217;d love to see other people pick them up and run with them.</p>
<p>If you <em>do</em> happen to get interested in any of the following, I wouldn&#8217;t mind a quick note to touch base to see about possibilities for collaboration or at least an acknowledgement in whatever you publish. Don&#8217;t interpret that as any sort of requirement, though; <a href="http://www.doawesomethings.com/post/9762996759/great-ideas-are-worthless-without-execution">ideas have no value without execution</a>, so all the hard work hasn&#8217;t even begun.</p>
<ul>
<li>Malware
<ul>
<li>Classification across a large corpus</li>
<li>Automated IOC extraction and publication</li>
</ul>
</li>
<li>Threat Actors
<ul>
<li>Profiling systems, particularly based on OSINT</li>
<li>Underanalyzed crime groups (e.g. drug cartels involvement in malware, spam, and fraud)</li>
<li>Hacktivism motivations and methods</li>
</ul>
</li>
<li>Passwords
<ul>
<li>Cracking lab setups</li>
<li>Useful entropy calculations</li>
</ul>
</li>
<li>Quantitative analysis of incidents
<ul>
<li>DDOS attacks (hard to get numbers on these)</li>
<li>Defacements and low-level leaks</li>
</ul>
</li>
<li>Active Defense
<ul>
<li>Honeypots and honeyclients</li>
<li>Vocabulary or taxonomy on various methods</li>
<li>Callback Trojans in documents</li>
<li>C2 / RAT vulnerability research</li>
</ul>
</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1368/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1368/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1368&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/03/03/brain-dump-of-dfir-and-network-security-research-ideas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/03/rro2q8r.jpg?w=356" medium="image">
			<media:title type="html">Maybe I could get more of these done with this.</media:title>
		</media:content>
	</item>
		<item>
		<title>CFAA and foreign computers</title>
		<link>http://threatthoughts.com/2013/02/27/cfaa-and-foreign-computers/</link>
		<comments>http://threatthoughts.com/2013/02/27/cfaa-and-foreign-computers/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 01:46:05 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Notes]]></category>
		<category><![CDATA[Active Defense]]></category>
		<category><![CDATA[Aurora]]></category>
		<category><![CDATA[CFAA]]></category>
		<category><![CDATA[Computer Fraud and Abuse Act]]></category>
		<category><![CDATA[EFF]]></category>
		<category><![CDATA[Google]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1355</guid>
		<description><![CDATA[As part of some research into &#8220;active defense&#8220;, I decided to review the actual text of the Computer Fraud and Abuse Act (CFAA). This law has a number of well-documented problems, which I don&#8217;t plan to address in this post, &#8230; <a href="http://threatthoughts.com/2013/02/27/cfaa-and-foreign-computers/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1355&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2013/02/25/opinion/heng-cartoon-chinas-hackers.html"><img class="aligncenter size-large wp-image-1360" alt="25iht-heng25-articleLarge" src="http://overhack.files.wordpress.com/2013/02/25iht-heng25-articlelarge.jpg?w=500&#038;h=353" width="500" height="353" /></a><br />
As part of some research into &#8220;<a href="http://www.crowdstrike.com/blog/active-defense-time-new-security-strategy/index.html">active defense</a>&#8220;, I decided to review the actual text of the <a href="http://www.law.cornell.edu/uscode/text/18/1030">Computer Fraud and Abuse Act (CFAA)</a>. This law has a number of <a href="https://www.eff.org/issues/cfaa">well-documented problems</a>, which I don&#8217;t plan to address in this post, partly because <a href="http://ask.metafilter.com/56257/IANAL-and-IDKWITA">IANAL</a> and partly because I want to focus on how the Act describes a &#8220;protected computer&#8221;:</p>
<blockquote><p>the term “protected computer” means a computer—<br />
(A) exclusively for the use of a financial institution or the United States Government, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the United States Government and the conduct constituting the offense affects that use by or for the financial institution or the Government; or<br />
(B) which is used in or affecting interstate or foreign commerce or communication, including <strong>a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States</strong></p></blockquote>
<p>(Emphasis mine.) Specifically, I want to think about the implications related to a &#8220;computer located outside the United States&#8221;. Assuming that such a system doesn&#8217;t affect US commerce or communications (whether or not that activity takes place <em>within</em> the US), would it fall under the definition of a protected computer? For example, if a US person gains access to a command-and-control system in another country and takes some action that would otherwise certainly violate the CFAA were the C2 in the United States, perhaps the CFAA does not apply. Or maybe somebody accesses an exploit server or malware host to gather additional information: does the CFAA cover this? (Other statutes, particularly in the host country, may apply, so don&#8217;t do anything that might get you thrown in prison, kids. We&#8217;re just thinking about what the law may cover.)</p>
<p>Google may have possibly done something akin to this when investigating the <a href="http://en.wikipedia.org/wiki/Operation_Aurora">Aurora incident</a>. According to the <a href="http://www.nytimes.com/2010/01/15/world/asia/15diplo.html">New York Times</a> story after the incident, Google:</p>
<blockquote><p>&#8230;<strong>managed to gain access to a computer in Taiwan</strong> that it suspected of being the source of the attacks. <strong>Peering inside that machine</strong>, company engineers actually saw evidence of the aftermath of the attacks, not only at Google, but also at at least 33 other companies, including Adobe Systems, Northrop Grumman and Juniper Networks, according to a government consultant who has spoken with the investigators.</p></blockquote>
<p>(Emphasis mine again.) So, according to this story, Google somehow accessed a system that presumably did not belong to them. Depending on that system&#8217;s function, perhaps this didn&#8217;t violate the CFAA. Certainly, the USSS or the Department of Justice or Secretary Clinton did not publicly express concern about this. As far as we know, they didn&#8217;t shut down the system or otherwise damage it, so while they could have concerns about Taiwanese law if they actually did any of this, they might not have to worry about the CFAA.</p>
<p>This post does not advocate so-called <a href="http://www.honeynet.org/taxonomy/term/280">hack back</a> retaliation, but my initial non-lawyerly analysis makes me wonder if other people already depend on this interpretation for various sorts of activities.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1355/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1355&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/02/27/cfaa-and-foreign-computers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/02/25iht-heng25-articlelarge.jpg?w=500" medium="image">
			<media:title type="html">25iht-heng25-articleLarge</media:title>
		</media:content>
	</item>
		<item>
		<title>Speaking Schedule page</title>
		<link>http://threatthoughts.com/2013/02/24/speaking-schedule-page/</link>
		<comments>http://threatthoughts.com/2013/02/24/speaking-schedule-page/#comments</comments>
		<pubDate>Sun, 24 Feb 2013 21:31:05 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Meta]]></category>
		<category><![CDATA[Presenting]]></category>
		<category><![CDATA[Scott Thomas]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1348</guid>
		<description><![CDATA[I took an idea from my buddy Scott Thomas and now have a page listing my upcoming speaking engagements. At the moment, it&#8217;s a bit light, but I have sent quite a few other CFP responses for events that haven&#8217;t &#8230; <a href="http://threatthoughts.com/2013/02/24/speaking-schedule-page/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1348&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I took an idea from my buddy <a href="http://www.secureholio.com/">Scott Thomas</a> and now have a page listing my <a href="http://threatthoughts.com/speaking-schedule/">upcoming speaking engagements</a>. At the moment, it&#8217;s a bit light, but I have sent quite a few other CFP responses for events that haven&#8217;t closed yet. And I expect that work-related stuff will fill it up quickly as well. Some of those will be private but I&#8217;ll at least try to list the city in case anybody wants to get together for a drink or something.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1348/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1348/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1348&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/02/24/speaking-schedule-page/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>
	</item>
		<item>
		<title>Comments on Comment Crew</title>
		<link>http://threatthoughts.com/2013/02/21/comments-on-comment-crew/</link>
		<comments>http://threatthoughts.com/2013/02/21/comments-on-comment-crew/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 02:18:03 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[CISPA]]></category>
		<category><![CDATA[Comment Crew]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Indicators of Compromise]]></category>
		<category><![CDATA[Jeffrey Carr]]></category>
		<category><![CDATA[Krypt3ia]]></category>
		<category><![CDATA[Mandiant]]></category>
		<category><![CDATA[Threat Intelligence]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1332</guid>
		<description><![CDATA[Everyone paying any attention to security this week noted Mandiant&#8217;s report on the Comment Crew. If you haven&#8217;t, go read it first. I&#8217;ll wait. Although I work for a competitor[1], I believe Mandiant did the right thing here. Others may &#8230; <a href="http://threatthoughts.com/2013/02/21/comments-on-comment-crew/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1332&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Everyone paying any attention to security this week noted <a href="www.mandiant.com/apt1">Mandiant&#8217;s report</a> on the <a href="http://www.nytimes.com/2013/02/19/technology/chinas-army-is-seen-as-tied-to-hacking-against-us.html?pagewanted=all">Comment Crew</a>. If you haven&#8217;t, go read it first. I&#8217;ll wait.</p>
<p><a href="http://overhack.files.wordpress.com/2013/02/u7unqgo.gif"><img src="http://overhack.files.wordpress.com/2013/02/u7unqgo.gif?w=500" alt="Why You Make Groundless Accusations?"   class="alignright size-full wp-image-1335" /></a>Although I work for a competitor[1], I believe Mandiant did the right thing here. Others may <a href="http://krypt3ia.wordpress.com/2013/02/20/apt-1-the-good-the-bad-and-the-ugly/">disagree</a> to an extent for good reasons, while others simply <a href="http://jeffreycarr.blogspot.com/2013/02/mandiant-apt1-report-has-critical.html">went too far in their assumptions and criticisms</a>. (And some folks just need to take off the <a href="http://cybernonsense.blogspot.com/2013/02/chinese-hackers-and-security-malware_4130.html">tinfoil hats</a>). I don&#8217;t really care that much about what makes the sekrit skwirl cabal happy, and in fact it tickles me when they get frustrated by &#8220;outsiders&#8221; (inasmuch as Mandiant is one, anyway) not playing by their rules. In any case, healthy skepticism regarding someone else&#8217;s conclusions keeps them honest, but don&#8217;t miss the big picture out of myopia. The relative prevalence of espionage and APT relative to regular criminal activity remains an open research question and a valid area of debate, but I&#8217;ve seen some really smart people this week falling into the clich&eacute; of missing the forest for the trees.</p>
<p>Instead, this means the adversary can&#8217;t dictate the pace and terms of the conflict, whether or not they completely retool. By driving up the cost to the attacker over time, you start to make headway. That works both ways, of course, and at the moment that balance leans decidedly in their favor. Releasing the IOCs will also allow defenders to discover additional compromises. Remember that opponents make mistakes, and so we can capitalize on the opportunity for ongoing intel gathering as they transition to new infrastructure (assuming they even bother). </p>
<p>Sharing information has more than just tactical value. In my view (obviously not one shared by Congress), this points out that we don&#8217;t need the government to get in the way with CISPA or other information-sharing that stays behind walls of overclassification or possibly creates additional privacy and civil rights issues. We can do this the right way and improve things. Partisan politics lies way outside the scope of this blog, but I certainly see this as &#8220;we&#8217;re from the government and we&#8217;re here to help&#8221; territory. </p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='500' height='312' src='http://www.youtube.com/embed/FhsU85fDmTc?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>[1]: As usual, these represent my opinions only. And that&#8217;s only good for today anyway because I may change my mind as new facts come to light or I think about topics more thoroughly.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1332/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1332/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1332&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/02/21/comments-on-comment-crew/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/02/u7unqgo.gif" medium="image">
			<media:title type="html">Why You Make Groundless Accusations?</media:title>
		</media:content>
	</item>
		<item>
		<title>PDD21 FUD from Stiennon</title>
		<link>http://threatthoughts.com/2013/02/14/pdd21-fud-from-stiennon/</link>
		<comments>http://threatthoughts.com/2013/02/14/pdd21-fud-from-stiennon/#comments</comments>
		<pubDate>Fri, 15 Feb 2013 02:17:30 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[Barack Obama]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Executive Order]]></category>
		<category><![CDATA[PDD 21]]></category>
		<category><![CDATA[Richard Stiennon]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1327</guid>
		<description><![CDATA[With the release this week of President Obama&#8217;s executive order on Improving Critical Infrastructure Cybersecurity and the accompanying detail in Presidential Policy Directive 21, lots of people have commented on the implications. Jack Whitsitt appears to have some solid commentary &#8230; <a href="http://threatthoughts.com/2013/02/14/pdd21-fud-from-stiennon/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1327&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>With the release this week of President Obama&#8217;s <a href="http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity">executive order on Improving Critical Infrastructure Cybersecurity</a> and the accompanying detail in <a href="http://www.whitehouse.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil">Presidential Policy Directive 21</a>, lots of people have commented on the implications. Jack Whitsitt <a href="http://sintixerr.wordpress.com/2013/02/14/omabas-executive-order-on-cyber-security-frameworkstandards-clarification-from-nist/">appears</a> to have some solid commentary coming.</p>
<p>However, a <a href="http://www.forbes.com/sites/richardstiennon/2013/02/14/ppd-21-extreme-risk-management-gone-bad/">piece</a> by Richard Stiennon on Forbes caught my eye, not because of the information in it, but because of the FUD it contains.</p>
<p> <a href="http://overhack.files.wordpress.com/2013/02/sparrow-oooh.gif"><img src="http://overhack.files.wordpress.com/2013/02/sparrow-oooh.gif?w=500&#038;h=200" alt="sparrow-oooh" width="500" height="200" class="alignright size-full wp-image-1328" /></a></p>
<p>First, he attacks the concept of risk management:</p>
<blockquote><p>But risk management does not work in unpredictable environments. Risk management is the framework that most banks, hedge funds and trading desks use when addressing financial risks like those present in the real estate, commodities or derivatives markets. We know how well that worked. Management consultants and bureaucrats love risk management. It foists responsibility away from individuals and onto a process.</p></blockquote>
<p>Here&#8217;s a hint: yes, it does work in &#8220;unpredictable environments&#8221;, when performed properly by responsible managers. (Whether the DHS can provide this is a separate question, and one on which I suspect Stiennon and I would likely agree.) This stems from the concept of <a href="https://en.wikipedia.org/wiki/Uncertainty">uncertainty</a> from statistics and related sciences. And simply saying &#8216;risk management is bad because bankers&#8217; (obviously a paraphrase) isn&#8217;t wry sniping, as Stiennon later commented, but FUD.</p>
<blockquote><p>How will an uber-map of critical infrastructure be kept out of the hands of the very threat actors that are targeting these systems? PPD 21 will, in effect, create yet another critical information asset that will end up at the top of the list of critical vulnerable assets.</p></blockquote>
<p>I don&#8217;t know what this means. By this logic, we shouldn&#8217;t ever create an inventory of our assets. Does he not keep financial records? Would he have counseled the government during the Cold War not to keep track of nuclear launch sites? Yes, of course the documents detailing these things require appropriate controls, but to conclude that the government should not analyze and sort critical infrastructure because adversaries would love to have this information doesn&#8217;t make any sense.</p>
<blockquote><p>Centralized information collection and dissemination is a natural requirement for risk management. It is akin to the economic data collection and analysis that command economies resort to in place of free markets.</p></blockquote>
<p>Yes, he basically just said that centralized databases are communism. I have nothing to add here because it speaks for itself.</p>
<p>Stiennon concludes this way:</p>
<blockquote><p>PPD 21 makes previous unfunded mandates seem simple by comparison. Its breath and scope is a giant overlay on top of the existing system of Federal agencies that, if executed as directed, will turn what was a of collection of connected puddles of government regulatory bodies into a single giant quagmire. It is a top down solution that expresses the frustration of good intentions to “do something.”  Even if all the hurdles of implementing an over arching risk management framework were overcome there would still be the <a href="http://en.wikipedia.org/wiki/Northeast_blackout_of_2003">errant tree branch</a> or targeted  malware that could shut down the power grid.</p></blockquote>
<p>Yes, bad things will still happen. That is not an excuse to do nothing. Stiennon proposes no alternatives here, other than the implied idea of leaving a &#8220;collection of connected puddles of government regulatory bodies&#8221; as they are. The current system doesn&#8217;t work that well, and whereas I&#8217;m not convinced right now that PDD 21 will actually do anything, I also believe that we as professionals and citizens should find ways to improve things rather than simply shoot down anything that isn&#8217;t perfect &#8216;because reasons&#8217;.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1327/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1327&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/02/14/pdd21-fud-from-stiennon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/02/sparrow-oooh.gif" medium="image">
			<media:title type="html">sparrow-oooh</media:title>
		</media:content>
	</item>
		<item>
		<title>Maltrieve: retrieving malware for research</title>
		<link>http://threatthoughts.com/2013/02/07/maltrieve-retrieving-malware-for-research/</link>
		<comments>http://threatthoughts.com/2013/02/07/maltrieve-retrieving-malware-for-research/#comments</comments>
		<pubDate>Thu, 07 Feb 2013 21:42:22 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Notes]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[Maltrieve]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[mwcrawler]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1310</guid>
		<description><![CDATA[As I continued to hack on mwcrawler over the last month, I found that it didn&#8217;t really meet my needs for various reasons: slowness, difficulty of maintaining and adding sources, repeated grabbing of the same URL, and lack of response from &#8230; <a href="http://threatthoughts.com/2013/02/07/maltrieve-retrieving-malware-for-research/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1310&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://oncampus.osu.edu/2011/08/charles-csuri/"><img class="alignright  wp-image-1313" alt="Threads" src="http://overhack.files.wordpress.com/2013/02/csuri_threads-476x357.jpg?w=180&#038;h=135" width="180" height="135" /></a>As I continued to <a href="http://threatthoughts.com/2013/01/04/getting-into-the-guts-of-mwcrawler/">hack on mwcrawler</a> over the last month, I found that it didn&#8217;t really meet my needs for various reasons: slowness, difficulty of maintaining and adding sources, repeated grabbing of the same URL, and lack of response from the original author. So I&#8217;ve rewritten it and released <strong><a href="https://github.com/technoskald/maltrieve">Maltrieve</a></strong>, which (as the name indicates) retrieves malware directly from the sources listed at a number of sites. Improvements listed in the README include:</p>
<ul>
<li>Proxy support</li>
<li>Multithreading for improved performance</li>
<li>Logging of source URLs</li>
<li>Multiple user agent support</li>
<li>Better error handling</li>
</ul>
<p>Right now, Maltrieve only looks at four meta-sources because two of the six in mwcrawler appear offline. But I have at least four more on deck, and mwcrawler didn&#8217;t parse all of its meta-sources correctly in any case. I also know of a few bugs that I haven&#8217;t figured out how to squash yet, but the core functionality works and it needs a broader audience to bang on it. Thus, I&#8217;ve tagged this version &#8220;beta-1&#8243;. Don&#8217;t rely on this for serious production, please.</p>
<p>If you use it, please let me know just so I can bask in the warm glow of productivity. The project itself remains under the GPL, of course. Suggestions, bug reports, etc. also would make me happy, whether via issues and pull requests on Github, <a href="https://twitter.com/kylemaxwell">contacting me on Twitter</a>, or comments here.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1310/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1310/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1310&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/02/07/maltrieve-retrieving-malware-for-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/02/csuri_threads-476x357.jpg?w=300" medium="image">
			<media:title type="html">Threads</media:title>
		</media:content>
	</item>
		<item>
		<title>Chinese government attacking American journalism?</title>
		<link>http://threatthoughts.com/2013/02/02/chinese-government-attacking-american-journalism/</link>
		<comments>http://threatthoughts.com/2013/02/02/chinese-government-attacking-american-journalism/#comments</comments>
		<pubDate>Sat, 02 Feb 2013 18:47:59 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[Brian Krebs]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Colin Powell]]></category>
		<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[Iraq]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Leon Panetta]]></category>
		<category><![CDATA[New York Times]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[Robert David Graham]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Wall Street Journal]]></category>
		<category><![CDATA[Washington Post]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1297</guid>
		<description><![CDATA[What a week: disclosure of compromises at the New York Times, Wall Street Journal, and Washington Post. A Java update released on a Friday evening 18 days early due to active exploitation. Twitter compromised affecting 250k users, including me. I &#8230; <a href="http://threatthoughts.com/2013/02/02/chinese-government-attacking-american-journalism/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1297&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>What a week: disclosure of compromises at the <a href="http://www.nytimes.com/2013/01/31/technology/chinese-hackers-infiltrate-new-york-times-computers.html">New York Times</a>, <a href="http://online.wsj.com/article/SB10001424127887323926104578276202952260718.html">Wall Street Journal</a>, and <a href="http://www.washingtonpost.com/business/technology/chinese-hackers-suspected-in-attack-on-the-posts-computers/2013/02/01/d5a44fde-6cb1-11e2-bd36-c0fe61a205f6_story.html">Washington Post</a>. A <a href="http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html">Java update</a> released on a Friday evening 18 days early due to active exploitation. <a href="blog.twitter.com/2013/02/keeping-our-users-secure.html">Twitter compromised</a> affecting 250k users, including me. I may have more to say about the Twitter compromise later.</p>
<div id="attachment_1304" class="wp-caption alignright" style="width: 230px"><a href="http://www.theepochtimes.com/n2/china-news/repression-and-violence-against-journalists-in-china-on-increase-42042.html"><img class="size-medium wp-image-1304" alt="Journalists in China" src="http://overhack.files.wordpress.com/2013/02/journalist.jpg?w=220&#038;h=300" width="220" height="300" /></a><p class="wp-caption-text">If they don&#8217;t respect them there, they won&#8217;t respect them here.</p></div>
<p>I&#8217;ve assumed for some time that state-sponsored attackers have long targeted major media outlets, especially those who regularly report on national security issues. While we don&#8217;t need to start putting on tinfoil hats, the ill-fated Wikileaks partnership with the NYT should have provided a pretty obvious starting point for people to think about these issues. Even more obviously, at least to me, journalists have had to take OPSEC seriously for a very long time, whether due to <a href="http://www.guardian.co.uk/world/2012/oct/13/mexico-drug-wars-target-journalists">drug cartels</a> or US presidents unhappy with <a href="http://www.washingtonpost.com/watergate">political and legal revelations</a>. I wouldn&#8217;t characterize these incidents as an assault on our way of life, exactly, because the Fourth Estate has always had conflicts with power. We should become far more suspicious when governments don&#8217;t concern themselves with the press, because that says something about their relationships with it or, perhaps, their views of popular opinion.</p>
<blockquote><p><a href="http://en.wikipedia.org/wiki/Marcello_Truzzi#.22Extraordinary_claims.22">An extraordinary claim requires extraordinary proof.</a></p></blockquote>
<p>Others have <a href="http://erratasec.blogspot.com/2013/01/the-nytimes-article-was-content-free.html">criticized the reporting</a> and the <a href="http://krebsonsecurity.com/2013/02/source-washington-post-also-broadly-infiltrated-by-chinese-hackers-in-2012/">completeness of the stories</a>. For what it&#8217;s worth, as noted above, I certainly don&#8217;t think claiming that governments have tried to attack journalists really presents an extraordinary claim. And I have seen enough evidence first-hand to believe that Chinese-based actors actively exploit networks around the world. Combining the two, we know how the Chinese government regards free speech and a free press.</p>
<p>But if you want us to believe that this represents the <a href="http://www.youtube.com/watch?v=JOFk44yy6IQ">greatest transfer of wealth in history</a> and all the other hyperbole that surrounds discussion of &#8220;the APT&#8221; and &#8220;China&#8221; and &#8220;cyberwar&#8221;, you need to present evidence. Declassify it, make it public, show it to the American people. If you&#8217;re a news outlet dedicated to informing the public, give us the facts. When the government wants to make a case for war, it discusses specific <a href="http://en.wikipedia.org/wiki/Niger_uranium_forgeries">incidents</a> and <a href="http://articles.cnn.com/2005-08-19/world/powell.un_1_colin-powell-lawrence-wilkerson-wmd-intelligence?_s=PM:WORLD">presents intelligence</a>. If we face such a great threat, don&#8217;t just <a href="http://www.foreignpolicy.com/articles/2012/11/19/panettas_wrong_about_a_cyber_pearl_harbor">assert the threat</a>, prove it. (Note: I don&#8217;t actually expect any of this to happen.)</p>
<p>Whether the intelligence will amount to proof, however, remains to be seen.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1297/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1297&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/02/02/chinese-government-attacking-american-journalism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/02/journalist.jpg?w=220" medium="image">
			<media:title type="html">Journalists in China</media:title>
		</media:content>
	</item>
		<item>
		<title>Konig: malware, graph theory, and fuzzy hashes</title>
		<link>http://threatthoughts.com/2013/01/28/konig-malware-graph-theory-and-fuzzy-hashes/</link>
		<comments>http://threatthoughts.com/2013/01/28/konig-malware-graph-theory-and-fuzzy-hashes/#comments</comments>
		<pubDate>Mon, 28 Jan 2013 16:00:53 +0000</pubDate>
		<dc:creator>Kyle Maxwell (@kylemaxwell)</dc:creator>
				<category><![CDATA[Notes]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[GitHub]]></category>
		<category><![CDATA[Graph theory]]></category>
		<category><![CDATA[Konig]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[Vxcage]]></category>

		<guid isPermaLink="false">http://threatthoughts.com/?p=1286</guid>
		<description><![CDATA[As a small personal research and learning project, I spent a few hours this weekend writing Konig. This is intended to evolve into a framework for investigating relationships between fuzzy hashes (e.g. a corpus of malware gathered with mwcrawler) using &#8230; <a href="http://threatthoughts.com/2013/01/28/konig-malware-graph-theory-and-fuzzy-hashes/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1286&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>As a small personal research and learning project, I spent a few hours this weekend writing <a href="https://github.com/technoskald/konig">Konig</a>. This is intended to evolve into a framework for investigating relationships between fuzzy hashes (e.g. a corpus of malware gathered with <a href="https://github.com/technoskald/mwcrawler">mwcrawler</a>) using graph-theoretical methods. Underneath, it basically just marries <a href="http://networkx.github.com/">NetworkX</a> and <a href="http://ssdeep.sourceforge.net/">ssdeep</a>.</p>
<p>At the moment, the code is fairly barebones: create the hash library based on files in a particular directory, then construct a graph of the relationships between those files where the similarity exceeds a user-specified threshold. Also, please keep in mind that my Twitter bio for a while just said &#8220;I write bad code&#8221;, and for good reason: <strong>I do.</strong> The GUI purely consists of a matplotlib window and needs a lot of work. (I have less experience with interfaces than almost anything, so keep your expectations even lower). I&#8217;ve added some very basic information on the properties of the graph (order, density, etc.), as well as the ability to select the <a href="http://en.wikipedia.org/wiki/Connected_component_(graph_theory)">connected component</a> that includes a node (file) of interest.</p>
<p>Example output:<br />
<code><br />
kmaxwell@gauss:~/src/konig$ python konig.py -d ~/data/mwcrawler/unsorted/PE32 -t 90 -i PE32.json<br />
Loading saved hash database<br />
Calculating fuzzy hashes for all files in /home/kmaxwell/data/mwcrawler/unsorted/PE32...<br />
Creating graph structure for files with similarity &gt;= 90...<br />
Name:<br />
Type: Graph<br />
Number of nodes: 2932<br />
Number of edges: 265625<br />
Average degree: 181.1903<br />
Graph density:  0.0618185990375<br />
Preparing plot of graph structure...<br />
</code></p>
<p><a href="http://overhack.files.wordpress.com/2013/01/konig-screenshot-1.png"><img src="http://overhack.files.wordpress.com/2013/01/konig-screenshot-1.png?w=500&#038;h=262" alt="Konig screenshot" width="500" height="262" class="alignright size-large wp-image-1291" /></a></p>
<p>The goals here include refreshing my knowledge of graph theory, as the last time I seriously studied this stuff, I think the OJ Simpson verdict hadn&#8217;t come back. Also, this code will help pave the way for some related work I have slated to use mwcrawler and <a href="https://github.com/cuckoobox/vxcage">vxcage</a> together. In fact, I really think of Konig as a proof-of-concept implementation to <a href="http://c2.com/cgi/wiki?PlanToThrowOneAway">throw away</a> before doing something more useful and robust.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/overhack.wordpress.com/1286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/overhack.wordpress.com/1286/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=threatthoughts.com&#038;blog=13120065&#038;post=1286&#038;subd=overhack&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://threatthoughts.com/2013/01/28/konig-malware-graph-theory-and-fuzzy-hashes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/939b8eed161be8e245c4bad4659c8a05?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">krmaxwell</media:title>
		</media:content>

		<media:content url="http://overhack.files.wordpress.com/2013/01/konig-screenshot-1.png?w=500" medium="image">
			<media:title type="html">Konig screenshot</media:title>
		</media:content>
	</item>
	</channel>
</rss>
