<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Roger Halbheer on Security &#187; Law Enforcement</title>
	<atom:link href="http://www.halbheer.ch/security/tag/law-enforcement/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.halbheer.ch/security</link>
	<description>Information Security Discussion by Microsoft&#039;s Worldwide Chief Security Advisor.</description>
	<lastBuildDate>Wed, 16 May 2012 18:03:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>10 Years of Trustworthy Computing at Microsoft</title>
		<link>http://www.halbheer.ch/security/2012/01/12/10-years-of-trustworthy-computing-at-microsoft/</link>
		<comments>http://www.halbheer.ch/security/2012/01/12/10-years-of-trustworthy-computing-at-microsoft/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 10:33:15 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Processes]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Cybersecurity Agenda]]></category>
		<category><![CDATA[Development Lifecycle]]></category>
		<category><![CDATA[Ecosystem]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Incident Sharing]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Security Updates]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Trustworthy Computing]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/?p=2598</guid>
		<description><![CDATA[<p> <p>Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2012/01/12/10-years-of-trustworthy-computing-at-microsoft/">10 Years of Trustworthy Computing at Microsoft</a></span>]]></description>
			<content:encoded><![CDATA[<p><a href="http://aka.ms/twcnext"><img style="margin: 0px 10px; display: inline; float: left" border="0" alt="TwC Next" src="http://blogs.technet.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-50-43-twcnext/1488.TwC_2D00_Tile_5F00_148x148_2D00_wShadow.png" width="148" height="148" /></a>
<p>Before joining Microsoft a little bit more than 10 years ago, I ran a team at PricewarehoureCoopers on e-Business Risk Management – classical security consulting in the Internet bubble time. When I announced that I will leave PwC and join Microsoft, I got interesting reactions (and remember, this was 2001). Mainly they were along two lines:</p>
<ul>
<li>Oh, you are joining a desktop company? Why? </li>
<li>A security guy? Joining Microsoft? hmm… </li>
</ul>
<p>So, these reactions came from the time immediately before we launched Windows XP (you are not on XP today, are you? If you are, read <a href="http://www.halbheer.ch/security/2011/12/22/10-reasons-to-migrate-off-windows-xp/" target="_blank">this article</a>). Microsoft was not perceived as an enterprise player and was not seen as secure – they were wrong back then in the first case but right in the second one I guess. I joined being part of the consulting organization but soon met the country manager and I was having a chat with him about the perception on Microsoft’s security in the market. We (say: he <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.halbheer.ch/security/wp-content/uploads/2012/01/wlEmoticon-smile.png" />) then decided that we need to work on that and that I shall draw a job description – the job then was called Chief Security Officer and Chief Security Advisor later on. And then Nimda hit! And then Blaster hit! And then Slammer hit! I had the “privilege” back then to run the incident response team in Switzerland and had the privilege to have customers screaming at me, tell me that we fucked up (that was a quote). </p>
<p>Interestingly in the meantime the famous <a href="http://www.microsoft.com/Presspass/Features/2012/jan12/GatesMemo.mspx" target="_blank">Bill Gates’ Memo</a> hit the streets, saying:</p>
<blockquote><p>There are many changes Microsoft needs to make as a company to ensure and keep our customers’ trust at every level – from the way we develop software, to our support efforts, to our operational and business practices. As software has become ever more complex, interdependent and interconnected, our reputation as a company has in turn become more vulnerable. Flaws in a single Microsoft product, service or policy not only affect the quality of our platform and services overall, but also our customers’ view of us as a company.</p>
</blockquote>
<p>and even more important:</p>
<blockquote><p>In the past, we’ve made our software and services more compelling for users by adding new features and functionality, and by making our platform richly extensible. We’ve done a terrific job at that, but all those great features won’t matter unless customers trust our software. So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. </p>
</blockquote>
<p>This memo led to the creation of Trustworthy Computing with Scot Charney running the organization since it’s beginning and Scott then created the Chief Security Advisor community, the community I was in since the beginning and have the honor to run today globally. </p>
<p>Coming back to the beginning: I remember the first keynote I did for Microsoft was on Trustworthy Computing immediately after this announcement. People approached me in the breaks and asked me whether I really believe what I just said: that Microsoft is going to change. And I confirmed that. I have never seen (not before nor after) a company stopping development for almost four months to address issues and then change the way the company operates – that radically. I would never ever put my name and my credibility at risk if I would not have believed back then and I am still convinced that we did and still do an outstanding job and that we are leading the industry today. Interestingly I do not get these questions anymore…</p>
<p>So, what happened over these 10 years of Trustworthy Computing? What were significant achievements? Well, there are numerous and I have to apologize to the teams I am not mentioning here upfront…</p>
<ul>
<li>Immediately after SQL Slammer in 2003 we span up a process called <a href="http://www.microsoft.com/security/msrc/whatwedo/responding.aspx">Software Security Incident Response Process</a> (SSIRP), a process which is still in place today and we constantly adapt it to new threats and especially new challenges. This was a huge effort as we needed to be able to ramp up an incident organization all across the globe 24*7 – and we still are today. </li>
<li>Probably the biggest and most fundamental change was the way we develop software. We introduced the <a href="http://www.microsoft.com/security/sdl/default.aspx">Security Development Lifecycle</a> (SDL) and constantly keep it updated. Not only did we change the development process internally, we make this information available to the industry for free. Others shall be able to learn from our learning from the past. What concerns me is the slow adoption of such methodologies from a vendor side as well as from a customer side. Who really asks for a process? Typically customers ask for product certification but not for a sound process – something we as an industry need to continue on changing. </li>
<li>Different teams were spun up to address security re-actively like the Microsoft Security Response Center and the Malware Protection Center. </li>
<li>Since 2006 we publish our <a href="http://www.microsoft.com/sir" target="_blank">Security Intelligence Report</a> – the most comprehensive report in the market. </li>
<li>Our <a href="http://www.microsoft.com/presspass/presskits/dcu/" target="_blank">Digital Crimes Unit</a> is fighting cybercrime from a legal as well as from a technology perspective. We are working closely with the Council of Europe and other organizations improving the legal situation. We are taking down botnets like <a href="http://blogs.technet.com/b/microsoft_blog/archive/2010/09/08/r-i-p-waledac-undoing-the-damage-of-a-botnet.aspx" target="_blank">Waledac</a>, <a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2011/03/17/taking-down-botnets-microsoft-and-the-rustock-botnet.aspx" target="_blank">Rustock</a> and <a href="http://blogs.technet.com/b/microsoft_blog/archive/2011/09/27/microsoft-neutralizes-kelihos-botnet-names-defendant-in-case.aspx" target="_blank">Kelhios</a> in close collaboration with the authorities.&#160; We are providing technology to fight sexual exploitation of children like <a href="http://www.microsoft.com/presspass/press/2009/dec09/12-15PhotoDNAPR.mspx" target="_blank">PhotoDNA</a>. </li>
</ul>
<p>A lot of things happened over the course of the years and there is still a lot to do. These are just some highlights (besides the creation of the Chief Security Advisor community). </p>
<p>If you want to see a condensed version of the “life” of Trustworthy Computing”, here you go:    <br /><a href="http://www.microsoft.com/presspass/gallery/imageviewer.mspx?3AMBwaEoKCAtQ%2bsNlzHVTXml3CAzGFCzjJXqTjDzvT134nbww9YZda8RzXCvADDYwAqVTt%2fh0ZP%2fzA2w%2fqABecg%2ftNsl3fbo5j5Yn2FF%2b6TnnJ67AaewjqseaPeFm8Twpac4pFl64kHoXdBuVIlJlrStNYXNCFq7Uq1hnBn%2bD%2fEqi0rTj%2bfTFt5BadhKGnKfYA4jQNkimkBijs%2fTWfJ7cgAc412D0AG21ND1YwseIRwN4mI7nt2YKaUVH1ij64jgzP7GZMh%2fYSWDUxYuhUjMWnQtE67etqOIFdqnWG6o0HNGhsNFFylHku1M%2bHFDfrq39QMgnwOgaH0OtSYTWsDYuTFMbBYM4N1RB0ndC%2brB1zg%3d" target="_blank"><img src="http://www.microsoft.com/presspass/images/features/2012/01-12twc10years_lg.jpg" width="619" height="480" /></a></p>
<p>And the official story on the news center: <a href="http://www.microsoft.com/presspass/features/2012/jan12/01-12TwC.mspx" target="_blank">At 10-Year Milestone, Microsoft’s Trustworthy Computing Initiative More Important than Ever</a></p>
<p>Sometimes I am asked how many people work at Microsoft on security. And the answer is &quot;everybody” (well, almost <img style="border-bottom-style: none; border-left-style: none; border-top-style: none; border-right-style: none" class="wlEmoticon wlEmoticon-smile" alt="Smile" src="http://www.halbheer.ch/security/wp-content/uploads/2012/01/wlEmoticon-smile.png" />). It is not something we separate and put into a team labeled security. It is part of all our lives to one extent or another and this is the way it should be.</p>
<p>If I would have a wish for 2012, it would be that the industry would stand together much closer to address the issues of today and the future. I do not see that security is something the industry should compete on – rather collaborate to fight the criminals &#8211; together with the governments and the governments together with us. I was already fairly vocal about this in the <a href="http://www.halbheer.ch/security/2011/11/23/council-of-europe-octopus-conference-some-thoughts-2/" target="_blank">Octopus Conference</a> and will continue to ask for it. To help with this dialogue, we published a model called <a href="http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/" target="_blank">Cybersecurity Agenda for Governments</a> and will soon publish a book on it as well. </p>
<p>In parallel, the teams internally will continue their great work to bring Trustworthy Computing to the next level. All of this is needed, when we think that there will be a third billion devices added to the Internet in the next five years!</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2012/01/12/10-years-of-trustworthy-computing-at-microsoft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Council of Europe Octopus Conference- Some Thoughts</title>
		<link>http://www.halbheer.ch/security/2011/11/23/council-of-europe-octopus-conference-some-thoughts-2/</link>
		<comments>http://www.halbheer.ch/security/2011/11/23/council-of-europe-octopus-conference-some-thoughts-2/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 11:21:49 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Policies]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/11/23/council-of-europe-octopus-conference-some-thoughts-2/</guid>
		<description><![CDATA[<p>l am still sitting in the parliament room of the Council of Europe at the celebration event for the Budapest Convention. It was another very good event advancing the challenges fighting Cybercrime. Let me try to summarize a few thoughts:</p> The Budapest Convention is probably the best convention out there allowing a wide adoption of <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/11/23/council-of-europe-octopus-conference-some-thoughts-2/">Council of Europe Octopus Conference- Some Thoughts</a></span>]]></description>
			<content:encoded><![CDATA[<p>l am still sitting in the parliament room of the Council of Europe at the celebration event for the Budapest Convention. It was another very good event advancing the challenges fighting Cybercrime. Let me try to summarize a few thoughts:</p>
<ul>
<li>The Budapest Convention is probably the best convention out there allowing a wide adoption of a harmonized legislation to fight Cybercrime internationally. </li>
<li>A lot of countries outside the Council adopted or are in the process adopting the convention </li>
<li>It balances the fight against criminals with the protection of Privacy and Human Rights. </li>
<li>The willingness and the activities to collaborate internationally increase </li>
<li>The idea of <a href="http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/">the Cybersecurity Agenda</a> as a mechanism to land and integrate Cybercrime and Cyberscurity resonated extremely well </li>
</ul>
<p>A lot of good signs. There are some caveats however:</p>
<ul>
<li>There are countries rejecting adoption mainly because Council of Europe does not have a global mandate or because it is called Budapest Convention. I guess the criminals like this approach </li>
<li>The economical challenges esp. in Europe decreases the amount of money available for this. The call then was, that the private sector has to do more. We are committed continuing supporting these activities but typically if governments are financially challenged- well they are our customers as well </li>
<li>Where is the private sector? I just meet a few companies at these events: Some security vendors, some credit cad companies and us. <strong><em>Where are the others? Where is Google? Where is Apple? What about IBM? Amazon? The big Telcos? Why do they not participate in addressing crime and helping governments to get better and carry the burden? Do they not care?</em></strong> </li>
</ul>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/11/23/council-of-europe-octopus-conference-some-thoughts-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cooperation against Cybercrime- Octopus Conference</title>
		<link>http://www.halbheer.ch/security/2011/11/21/cooperation-against-cybercrime-octopus-conference/</link>
		<comments>http://www.halbheer.ch/security/2011/11/21/cooperation-against-cybercrime-octopus-conference/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 09:45:49 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Associations]]></category>
		<category><![CDATA[Events/Trainings]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/11/21/cooperation-against-cybercrime-octopus-conference/</guid>
		<description><![CDATA[<p>lt is time again! The Council of Europe Octopus Conference on Cooperation against Cybercrime is taking place this week. This year it is even the 10th anniversary of the Budapest Convention. Therefore a broad country of legal, law enforcement and private sector organizations are discussing the current state and the future of the collaboration to <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/11/21/cooperation-against-cybercrime-octopus-conference/">Cooperation against Cybercrime- Octopus Conference</a></span>]]></description>
			<content:encoded><![CDATA[<p>lt is time again! The Council of Europe Octopus Conference on Cooperation against Cybercrime is taking place this week. This year it is even the 10th anniversary of the Budapest Convention. Therefore a broad country of legal, law enforcement and private sector organizations are discussing the current state and the future of the collaboration to fight Cybercrime.</p>
<p>If you are interested, the agenda can be found <a href="http://www.coe.int/t/DGHL/cooperation/economiccrime/cybercrime/cy_Octopus_Interface_2011/Interface2011_en.asp">here</a>. The presentations should be uploaded as well. Finally there should be a live stream <a href="http://tv.coe.int/webcast">here</a>. I will be an a panel an Tuesday between 9:30-13:00 and again an Wednesday 9:00 -13:00 where we will run a special session on the anniversary</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/11/21/cooperation-against-cybercrime-octopus-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity&#8211;More than a good headline</title>
		<link>http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/</link>
		<comments>http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 13:47:03 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Cybersecurity Agenda]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Policy Makers]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Situational Awareness]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/</guid>
		<description><![CDATA[<p>A lot of governments all across the globe are working on starting, restarting or pushing their Cybersecurity initiative. What often concerns me is, that the last real headline has more impact on the strategy and the themes to be addressed than a structure or a plan or a strategy.</p> <p>This made us thinking about what <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/">Cybersecurity&#8211;More than a good headline</a></span>]]></description>
			<content:encoded><![CDATA[<p>A lot of governments all across the globe are working on starting, restarting or pushing their Cybersecurity initiative. What often concerns me is, that the last real headline has more impact on the strategy and the themes to be addressed than a structure or a plan or a strategy.</p>
<p>This made us thinking about what is needed to run a successful Cybersecurity Agenda within a country? What themes ought to be addressed and in which form.</p>
<p>We came up with a fairly simple model:</p>
<p><a href="http://www.halbheer.ch/security/wp-content/uploads/2011/10/image4.png"><img style="background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border-width: 0px;" title="image" src="http://www.halbheer.ch/security/wp-content/uploads/2011/10/image_thumb4.png" alt="image" width="644" height="363" border="0" /></a></p>
<p>To explain the model, we just published two papers about it:</p>
<ul>
<li><a href="http://download.microsoft.com/download/B/D/1/BD154F33-58E5-4034-89AB-F67E7FAB0AC6/MSPSCybersecurityAbstract.pdf">Cybersecurity white paper abstract</a> – a one pager with a high-level description</li>
<li><a href="http://download.microsoft.com/download/F/1/7/F176D7BF-AAD6-4295-A400-0C6DD8E4A8F4/MSPSCybersecurityWhitepaper.pdf">Cybersecurity: More than a good headline</a> – a few more pages going deeper into the discussion of the different subjects.</li>
</ul>
<p>In parallel we are working on a book about this, giving much more examples and background – so stay tuned.</p>
<p>The only thing I really know: When I do a presentation explaining Cybersecurity and at the end show the slide above, governments love it. Typically they approach me asking for the deck – if they are not politically correct they tell me that they just want to get this slide.</p>
<p>Comments are very welcome. If you need/want further information, get in touch with me. Happy to help</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/10/27/cybersecuritymore-than-a-good-headline/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>German&#8217;s Government-Created Trojan Vulnerable</title>
		<link>http://www.halbheer.ch/security/2011/10/11/germans-government-created-trojan-vulnerable/</link>
		<comments>http://www.halbheer.ch/security/2011/10/11/germans-government-created-trojan-vulnerable/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 08:42:27 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/10/11/germans-government-created-trojan-vulnerable/</guid>
		<description><![CDATA[<p>It is not that rare for Law Enforcement that they use software to spy in the case of severe accusations like terrorism. What is kind of surprising is the level of sophistication some of these Trojans seem to have – and not necessarily to the good side.</p> <p>The German Chaos Computer Club analyzed the Trojan <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/10/11/germans-government-created-trojan-vulnerable/">German&#8217;s Government-Created Trojan Vulnerable</a></span>]]></description>
			<content:encoded><![CDATA[<p>It is not that rare for Law Enforcement that they use software to spy in the case of severe accusations like terrorism. What is kind of surprising is the level of sophistication some of these Trojans seem to have – and not necessarily to the good side.</p>
<p>The German Chaos Computer Club analyzed the Trojan used by some state police force in Germany and found things like hard-coded keys, self-written encryption (well, they call it obfuscation at best) etc.</p>
<p>You can read the article on the CCC website: <a href="http://www.ccc.de/en/updates/2011/staatstrojaner">Chaos Computer Club analyzes government malware</a></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/10/11/germans-government-created-trojan-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Less Spam? Another Successful Botnet Takedown!</title>
		<link>http://www.halbheer.ch/security/2011/09/28/less-spam-another-successful-botnet-takedown/</link>
		<comments>http://www.halbheer.ch/security/2011/09/28/less-spam-another-successful-botnet-takedown/#comments</comments>
		<pubDate>Wed, 28 Sep 2011 13:30:33 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Law Enforcement]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/09/28/less-spam-another-successful-botnet-takedown/</guid>
		<description><![CDATA[<p>Our Digital Crimes Unit just took down another one: After Rustock and Waladec, now comes Kelihos.</p> <p>This is another great success in fighting criminals. If you want to read more: Microsoft Neutralizes Kelihos Botnet, Names Defendant in Case</p> <p>Roger</p> ]]></description>
			<content:encoded><![CDATA[<p>Our Digital Crimes Unit just took down another one: After Rustock and Waladec, now comes Kelihos.</p>
<p>This is another great success in fighting criminals. If you want to read more: <a href="http://blogs.technet.com/b/microsoft_blog/archive/2011/09/27/microsoft-neutralizes-kelihos-botnet-names-defendant-in-case.aspx" target="_blank">Microsoft Neutralizes Kelihos Botnet, Names Defendant in Case</a></p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/09/28/less-spam-another-successful-botnet-takedown/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Special Intelligence Report on the Rustock Takedown</title>
		<link>http://www.halbheer.ch/security/2011/07/06/special-intelligence-report-on-the-rustock-takedown/</link>
		<comments>http://www.halbheer.ch/security/2011/07/06/special-intelligence-report-on-the-rustock-takedown/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 07:27:38 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incidents]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Law Enforcement]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/07/06/special-intelligence-report-on-the-rustock-takedown/</guid>
		<description><![CDATA[<p>As you might remember, on Match 16th Microsoft together with other industry players was successfully able to take down the Rustock botnet and thus significantly reducing the spam level.</p> <p>We now just published a special Intelligence Report on this botnet:</p> <p>Read an overview of the Win32/Rustock family of rootkit-enabled backdoor Trojans background, functionality, how it <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/07/06/special-intelligence-report-on-the-rustock-takedown/">Special Intelligence Report on the Rustock Takedown</a></span>]]></description>
			<content:encoded><![CDATA[<p>As you might remember, on Match 16th Microsoft together with other industry players was successfully able to take down the Rustock botnet and thus significantly reducing the spam level.</p>
<p>We now just published a special Intelligence Report on this botnet:</p>
<blockquote><p>Read an overview of the <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32%2fRustock">Win32/Rustock</a> family of rootkit-enabled backdoor Trojans background, functionality, how it works, and threat telemetry data with analysis for 2010 to May 2011. This document provides legal and technical action used to takedown the Rustock botnet and how to detect and remove the threat using Microsoft antimalware products. </p>
</blockquote>
<p>You will find it <a href="http://www.microsoft.com/security/sir/story/default.aspx#!rustock" target="_blank">here</a>.</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/07/06/special-intelligence-report-on-the-rustock-takedown/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Security: The Road Ahead</title>
		<link>http://www.halbheer.ch/security/2011/04/14/cyber-security-the-road-ahead/</link>
		<comments>http://www.halbheer.ch/security/2011/04/14/cyber-security-the-road-ahead/#comments</comments>
		<pubDate>Thu, 14 Apr 2011 10:04:19 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Associations]]></category>
		<category><![CDATA[Crime]]></category>
		<category><![CDATA[Critical Infrastructure Protection]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Terrorism]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/04/14/cyber-security-the-road-ahead/</guid>
		<description><![CDATA[<p>This paper by the Geneva Centre for the Democratic Control of Armed Forces (DCAF) was just brought to my attention. A piece of work, which is definitely worth working through. It lays out the problem space and then does a deep dive into the different sections:</p> Governments Legislative Bodies The Armed Forces Law Enforcement Judges <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/04/14/cyber-security-the-road-ahead/">Cyber Security: The Road Ahead</a></span>]]></description>
			<content:encoded><![CDATA[<p>This paper by the Geneva Centre for the Democratic Control of Armed Forces (DCAF) was just brought to my attention. A piece of work, which is definitely worth working through. It lays out the problem space and then does a deep dive into the different sections:</p>
<ul>
<li>Governments</li>
<li>Legislative Bodies</li>
<li>The Armed Forces</li>
<li>Law Enforcement</li>
<li>Judges and Prosecutors</li>
<li>The End User</li>
<li>The Private Sector</li>
<li>The IT Sector</li>
<li>Banks and Financial Services</li>
<li>Critical National Infrastructure</li>
<li>WikiLeaks</li>
</ul>
<p>The interesting one is the last one – a whole chapter on WikiLeaks.</p>
<p>The paper is very well structured and gives always a structured view on the different challenges. If I would have to pick a few of them, those would be my highlights:</p>
<p><strong>From a strategic challenge perspective:</strong></p>
<blockquote><ul>
<li>The threats to cyber security are the greatest national and economic security threats states face. Cyber security will evolve into a key challenge, economically, politically, socially, and militarily. Yet it remains the least understood and most underestimated threat.</li>
<li>The very complexity of the threat deters a full understanding of its implications and hinders a comprehensive debate on the strategic responses needed.</li>
</ul>
</blockquote>
<p>I recently had a discussion with a government and everybody was talking about “Cyber” and “Cybersecurity”. Have you ever dared to ask what Cyber means to them? It is the number one theme and the number one theme people do not understand. Especially for politicians it is far away from their world as the theme we are talking of is even hard to grasp for specialists.</p>
<p><strong>Challenges for governments:</strong></p>
<blockquote><p>Of particular concern, are the often meagre resources available in developing countries, least developed countries and failed states to establish and implement an effective cyber-security regime. Without the participation of all countries, the overall system remains vulnerable to attack. International cooperation is hampered by these large discrepancies between national cyber capabilities.</p>
<p>[…]</p>
<p>With few exceptions, governmental responses to the threats and risks of cyberspace have taken two tracks: legal and organisational. Neither has been very well unified or coherent, rather, they have been more organic in their development and, consequently, less cohesive than one would wish. A lack of leadership, organisational stability and expertise are the main factors limiting the capacity to respond.</p>
</blockquote>
<p>It sometimes really makes me feel sad, seeing different organizations within governments fighting each other for the leadership in Cyber. Even worse: We see this within international bodies as well. Guess who wins: The Criminals.</p>
<p>We simply do not have the resources nor the energies available to afford this. Microsoft wants to collaborate and support organizations which drive a cybersecurity agenda but we cannot afford (we simply do not have the people) to help a lot of organizations, which fight each other.</p>
<p><em>If you are out there from a government or an international organization, you should definitely think about this! This is <u>your</u> responsibility. Ours is to provide our help.</em></p>
<p><strong>Challenges for legislative bodies:</strong></p>
<blockquote><ul>
<li>The technical complexity of the issue, which surpasses the professional experience of most members of parliament and requires highly specialized staffers that few parliaments can afford. </li>
<li>The fact that cyber security is a cross-cutting issue, which cannot easily be fitted into existing committee structures. To put it simply: Who is in charge—the armed forces committee or the security committee? Justice, police, or the committee for homeland security? Telecommunications? Or all of them? And what role is there for Foreign Affairs?</li>
</ul>
</blockquote>
<p>Governments, have you read the point above? We need to fix this and we need to fix this now as…</p>
<blockquote><ul>
<li>Cyber security is addressed, fully or partially, by many countries through their military and/or intelligence structures—i.e. through agencies that are, by their very nature, more exclusive and nontransparent.</li>
</ul>
</blockquote>
<p>Another challenge, which goes in the same direction: A lot of governments fear the collaboration with the private sector. Sometimes I hear statements like “we cannot work with you too closely because it would be politically incorrect if Microsoft helps us too far with our Cybersecurity strategy” – these are statements from people who listened to us and understood the value we can bring to the table (not selling products, fixing problems). Still, this fear blocks creative solutions between the public and the private sector.</p>
<p>There are good examples where this works but unfortunately there are not too many because of this fear. Interestingly enough it often works better in developing countries rather than developed – and again there are exceptions to the rule.</p>
<p><strong>Challenges for the armed forces:</strong></p>
<p>That’s a hard one as Cyberwar completely changes the world of the armed forces. One is:</p>
<blockquote><ul>
<li>The military has become completely dependent on cyberspace for its activities. Any threat in the cyber domain is of fundamental consequence for the armed forces.</li>
</ul>
</blockquote>
<p>They have to rely on the critical infrastructure but are often not part of the government’s CIP program.</p>
<blockquote><ul>
<li>The traditional conservatism of the military is a hindrance (historical examples include the difficulties that militaries have had with the introduction of the machine gun, the dreadnought, the tank, or aircraft carrier). There is some truth in the saying that the military always tends to prepare for the last war.</li>
</ul>
</blockquote>
<p>I am seeing some where good initiatives from people who understand that they are challenged. This then comes back to the collaboration between private and public sector. Us from the private sector, let’s help these people to move forward in their defensive capabilities. At least we will not engage in offense.</p>
<p>and finally:</p>
<blockquote><ul>
<li>Cyberspace presents the military with questions for which there are not only no answers, but for which we might not even have understood the questions yet.</li>
</ul>
</blockquote>
<p>Well and we did not touch on the Cloud yet as it is worse there…</p>
<p><strong>Challenges for law enforcement:</strong></p>
<p>This is kind of a pet theme for me especially when it come to international collaboration and international harmonization of laws. The paper raises similar challenges:</p>
<blockquote><ul>
<li>While Internet criminality is international in nature, cyber crime legislation varies from country to country.</li>
</ul>
<p>[…]</p>
<ul>
<li>A country is, under international law, not responsible for the cyber activities of its citizens, even if those activities constitute de facto the equivalent of an act of war against another country. The situation invites cyber ambitious countries to hide their own cyber activities behind the cover of allegedly anonymous hackers or hacktivists.</li>
</ul>
</blockquote>
<p>This is actually an interesting approach and could solve the attestation problem. If a country can be held accountable internationally for not reacting on an attack which originates from within their boarders, this might significantly change the way governments treat such attacks as nobody can hide behind an activity, which is then concealed as a private activist group exercising the activity.</p>
<p><strong>Challenges for judges and prosecutors:</strong></p>
<p>In my experience, we have a significant knowledge problem with judges and prosecutors. Having digital evidence in court is in a lot of countries a real challenge as it always comes down to experts testifying.</p>
<blockquote><p>Judges, prosecutors and law enforcement agencies often lack sufficient knowledge to effectively bring cyber criminals to justice. More must be done in training and education to ensure that these officials have the knowledge, skills, and capacity to properly fight cyber crime and to make their charges stick.</p>
</blockquote>
<p><strong>Private Sector:</strong></p>
<p>The private sector is not much better, though:</p>
<blockquote><p>If the government response to cyber security can be characterized as ad hoc, the private sector response to cyber security can best be characterised as unstructured.</p>
</blockquote>
<p>And I do not think that they are wrong.</p>
<p><strong>The IT Sector</strong></p>
<blockquote><p>The quality of software also needs to improve. Much attention has been on operating system security, but the target has now moved to the application layer, which has had insufficient security focus. Beyond the application layer, lower level software such as firmware is poised to be the next target of attack. There has been little to no attention aimed at reducing the vulnerabilities in this space, which must change.</p>
</blockquote>
<p>There are different things we are working on but basically our Security Development Lifecycle is a sound, proven and I would even say auditable basis to go forward. The challenge here will be that you find much more application providers than Operating System Manufacturers.</p>
<p><strong>Banks and Financial Services</strong></p>
<p>What is interesting is that they are separating banks, the IT sector from the Critical Infrastructure, which you cannot in my opinion. They/we are a key part of it – and especially the banks showed it during the crisis.</p>
<blockquote><ul>
<li>Due to the massive amount of money being transferred electronically around the globe every second, financially motivated cyber criminality is on the rise.</li>
<li>The situation is rendered even more attractive for criminals by the fact that banks, more often than not, do not report successful attacks.</li>
</ul>
</blockquote>
<p>The last point is a call I make often to the banks but at the end of the day to everybody: We have to start to report attacks to the police. Otherwise, it is the Wild West out there. The problem currently is that we have a legal system, which works, we have Law Enforcement in a lot of countries doing a great job fighting cybercrime – often focused on child porn, which is great – but attacks on our infrastructures are not followed through as they are not reported. A fairly safe bet for the criminals.</p>
<p><strong>Critical National Infrastructure</strong></p>
<p>That’s a really complex thing and a lot of governments struggle with this. In my opinion for different reasons: </p>
<ul>
<li>Constantly changing governments makes it hard to build trust between the private and the public sector</li>
<li>Often the focus of governments is providing the key infrastructure like roads, power, internet but protection comes, once it is here</li>
<li>Partly this is a cultural thing as well as it depends to a certain point on the way the government and the society is structured. How trustworthy is the government from a citizen perspective? How far is the government willing to work with the private sector in a trusted way or how far is the government in the position to invest a lot of money to build the competency on its own? Even in Western Europe, where such initiatives grew already fairly far, there are a lot of different models in place already and you see that societies with similar cultures (e.g. Switzerland and The Netherlands) come up with fairly similar approaches, whereas different cultures (Switzerland and Germany) come up with fundamentally different way of tackling the challenge.</li>
</ul>
<p>What does the paper see as the big challenges? Here you go:</p>
<blockquote><ul>
<li>The protection of CNI, has been recognized by most countries, as a priority. This basic awareness alone does, however, not translate into effective mechanisms for actual protection.</li>
</ul>
<p>[…]</p>
<ul>
<li>To create a genuine private public partnership in protection of CNI, the private sector would have to perceive a clear-cut, measurable advantage in reporting to law enforcement agencies, and to subsequently develop together with them a coherent defensive system. Currently, it does not.</li>
</ul>
<p>[…]</p>
<ul>
<li>The problem is exacerbated by the fact that, as examples prove, cyber malware has already been planted into some of the world’s critical infrastructure systems. The corresponding need to develop intelligent systems able to check automatically and regularly for the presence of highly sophisticated malware, is only about to be understood. It will be a costly enterprise in the best of circumstances and likely to be unevenly applied, thus reducing the eventual positive effects of select countermeasures for the overall system of interlinked critical infrastructures.</li>
<li>Comprehensively coherent and harmonized national approaches are indispensable in this domain; without international coordination no progress will be possible.</li>
</ul>
</blockquote>
<p>It is so obvious but so hard to achieve: International cooperation is key (and this means e.g. outside the EU as well) and one cannot address CIP without the private sector (which kind of runs the critical infrastructure…)</p>
<p><strong>WikiLeaks</strong></p>
<p>The final chapter, which comes back to ethics and freedom of speech. My position is clear here: <a href="http://www.halbheer.ch/security/2010/10/04/freedom-of-speech-does-not-mean-you-can-say-everything/">“Freedom of speech” does not mean you can say everything!</a></p>
<hr />
<p>Finally, what I really like with this paper is, that is comes down to the point to state, what they think the response could be:</p>
<p>Not surprising, the start with the <strong>Public Private Partnership</strong>. Now, I stopped to use this term, simply because it is often loaded with formal contracts and MoUs etc. What I think we need is a collaboration/cooperation between the sectors, where the public sector has to learn as well that collaboration with governments should not be to the disadvantage of the companies doing it. E.g. if we spend a lot of time and money working with the governments to pave the way for the industry, is this very good but we have the investment and the competition the benefit. At least the public acknowledgment of such a collaboration happens sometimes helps.</p>
<p>Where is the challenge we need to overcome? Well….</p>
<blockquote><ul>
<li>The private sector is understandably reluctant to share sensitive proprietary information about intrusions, actual damage, theft and crime, as well as prevention practices, with either government agencies or competitors because information sharing is a risky proposition with less than clear benefits. No company wants information to surface that they have given in confidence, since such an event could jeopardize their market position, customer base or capital investments.</li>
<li>Nor would private companies risk voluntarily opening themselves up to costly and time-consuming litigation. Industry fears that breaches on innocent customers might inadvertently occur during investigations. Negative publicity or exposure as a result of reports of information infrastructure violations could lead to threats to investor and consumer confidence in a company’s products. Moreover, companies fear revealing trade secrets to competitors, and hence are reluctant to share proprietary information. They also fear that sharing this information with government may lead to increased regulation of the industry or of e-commerce in general. </li>
</ul>
<p>[…]</p>
<ul>
<li>On the other hand, many private sector mechanisms for information sharing already exist without the need for government intervention. For example, both the “white-hat hacker” and the security researcher community provide a valuable private sector service. They are active information sharers which head off a vast number of attacks and identify vulnerabilities before harm occurs. Particularly on the technical level, information sharing about vulnerabilities and remediation happens routinely in the private sector. This is not because of a mandate from government. Rather the impulse to share is based on a well-grounded exchange of network-protective information done by engineers of, for example, the major telecom companies. And if the government wants to join in the sharing, they would be welcome—that is, if they bring added value to the arrangement. </li>
<li>There is an urgent need for active, robust, and credible liaison of government with the private sector. Government agencies have to respect the confidentiality as well as the value of the information and secrets that the private sector may give them to do their job. In order to do the job on both sides, real-time feedback on information sharing is essential. All partners engaged in ensuring IT security will not share information unless they have a high degree of confidence that this information will be protected from disclosure. Hence, all partners must take steps to protect sensitive data as a precursor to information sharing. Only then will it be possible to form trusted relationships and begin data sharing. Similar principles apply to information sharing between governments and international organisations.</li>
</ul>
</blockquote>
<p>I think that governments have to learn in the cyberspace that a partnership is not unilateral only. It should work both ways. I often see governments talking about partnerships but mean us sharing information. I want intelligence back – not about single cases but trends and maybe real-time intelligence as well, where our technology is concerned. However, more often than not it is a one-way street and the reason is trust again.</p>
<p>And the second way to approach the challenge is naturally <strong>International Cooperation</strong>. This comes natural if you read the statement above but is absolutely key. There are a lot of intergovernmental organizations trying to address the issue but unfortunately I see them often competing rather than collaborating. We need solutions and we need them fast – not in 2020 but in 2012. </p>
<p>  <br clear="all" />
<p>All in all, a very good read, which in my opinion lays out the problems extremely well and gives a few natural approaches to possible solutions. </p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/04/14/cyber-security-the-road-ahead/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Libya Violence Exploited by Scammers</title>
		<link>http://www.halbheer.ch/security/2011/02/28/libya-violence-exploited-by-scammers/</link>
		<comments>http://www.halbheer.ch/security/2011/02/28/libya-violence-exploited-by-scammers/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 16:27:22 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Scammers]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/02/28/libya-violence-exploited-by-scammers/</guid>
		<description><![CDATA[<p>It is a repeating pattern but not the less disgusting. Whenever bad things happens on the globe, the criminals are not far. This happened during hurricane Katrina, the tsunami in Indonesia, the earthquake in Haiti and now, not surprisingly in Libya as you can read in this blog post by Sophos: Violence in Libya exploited <span style="color:#777"> . . . &#8594; Read More: <a href="http://www.halbheer.ch/security/2011/02/28/libya-violence-exploited-by-scammers/">Libya Violence Exploited by Scammers</a></span>]]></description>
			<content:encoded><![CDATA[<p>It is a repeating pattern but not the less disgusting. Whenever bad things happens on the globe, the criminals are not far. This happened during hurricane Katrina, the tsunami in Indonesia, the earthquake in Haiti and now, not surprisingly in Libya as you can read in this blog post by Sophos: <a href="http://nakedsecurity.sophos.com/2011/02/28/violence-libya-exploited-email-scammers/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29" target="_blank">Violence in Libya exploited by email scammers</a> </p>
<p>Exploiting the willingness of people to help, is terrible. We should be able to get this persons and then send them to jail for a loooooooooooooong time</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/02/28/libya-violence-exploited-by-scammers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Wild West on the Internet&#8230; A Crime Story</title>
		<link>http://www.halbheer.ch/security/2011/02/10/the-wild-west-on-the-internet-a-crime-story/</link>
		<comments>http://www.halbheer.ch/security/2011/02/10/the-wild-west-on-the-internet-a-crime-story/#comments</comments>
		<pubDate>Thu, 10 Feb 2011 15:20:53 +0000</pubDate>
		<dc:creator>Roger Halbheer</dc:creator>
				<category><![CDATA[Crime]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Law Enforcement]]></category>
		<category><![CDATA[Legislation]]></category>

		<guid isPermaLink="false">http://www.halbheer.ch/security/2011/02/10/the-wild-west-on-the-internet-a-crime-story/</guid>
		<description><![CDATA[<p>A fairly interesting thriller on the Internet. It just shows that we need better ways to collaborate between private and public sector and to hunt criminals: How one man tracked down Anonymous—and paid a heavy price</p> <p>Scary…</p> <p>Roger</p> ]]></description>
			<content:encoded><![CDATA[<p>A fairly interesting thriller on the Internet. It just shows that we need better ways to collaborate between private and public sector and to hunt criminals: <a href="http://arstechnica.com/tech-policy/news/2011/02/how-one-security-firm-tracked-anonymousand-paid-a-heavy-price.ars" target="_blank">How one man tracked down Anonymous—and paid a heavy price</a></p>
<p>Scary…</p>
<p>Roger</p>
]]></content:encoded>
			<wfw:commentRss>http://www.halbheer.ch/security/2011/02/10/the-wild-west-on-the-internet-a-crime-story/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

