Friday, May 17, 2019

Achieving end-to-end auditability and verifiability in Philippine automated elections

The design of the transparency server which is under COMELEC control as an interface that provides media outlets and election watchdogs copies of election returns (ERs) transmitted from the VCMs poses an architectural pseudo-security flaw. When I say pseudo-security flaw, I do not mean that it introduces an actual security flaw that can be exploited to alter the results of the election. I am talking about the potential security flaws as perceived by observers because the Transparency Server was not transparent enough. Regardless, this cast doubt among the people on the trustworthiness of the election results.
Unlike the Transmission Router which supposed to store and forward encrypted ERs in their unaltered form to local CCSs and the Transparency Server, the Transparency Server (which if I may add had been subjected to a code review) transforms ( read as decrypted and combined with other pieces of information such precinct codes, etc.) the encrypted ERs before forwarding them to media outlets and watchdog organizations [1]. This design breaks the verifiability of information flow from the VCM to the media outlets that publish unofficial results.
A better design is to remove this indirection and allow media outlets to get their copies of ERs directly from the VCMs via the Transmission Router and have them verify the integrity of the transmitted ERs themselves. This design will require more technical investment on the part of media outlets. However, this will undoubtedly make the intended purpose of the Transparency Server true to its name. If done this way, the transparency server is no longer a "single" server controlled by COMELEC but is the collection of servers controlled by independent 3rd parties. This approach will also unburden COMELEC a little bit because now, the responsibility of showing the transparency of the entire election process is shared with the media outlets and other organizations accredited by COMELEC.
The COMELEC can go even a step further and let anyone who is interested verify election results. This can be done by adding to the AES a tamper-proof verifiable public bulletin board containing verifiable election data that are needed to verify election results. How to build this? Blockchain could be part of the solution. But the most important bit here is that the bulletin board is public. Is the Transparency Server in the current AES a verifiable bulletin board? It could be. But is it a verifiable public bulletin board, as it stands, IT IS NOT.
I recently learned that the digital ERs outputted by VCM's do not contain all the necessary information (i.e., not self-contained) to be interpreted completely. With respect to the Transparency Server, the TS needs to first decrypt the ER and link the information it contains to an Oracle database (Original post by Doc Pablo Manalastas [2] ).
Doing so minimized the size of the ERs and improved overall performance, but it sacrificed their verifiability. As mentioned previously, this design adds additional layers of transformations which could lead to more vulnerabilities if left unchecked/audited.
This issue could have been easily avoided by packing all the information needed to "interpret an ER as intended" in the transmission package itself, making it self-contained. However, obviously doing increases the size of the transmission package and could impair performance. But one can't also ignore the benefit that a self-contained transmission package provides. In the current implementation, there's a possibility of gaps in the verification chain. I feel it's safe to say that the code the processes a self-contained transmission package would be less complex and easier to review.
A self-contained transmission package would also mean that ERs in their "pristine" form can be easily shared to 3rd party observers e.g., media outlets, election watch organizations, etc. for the purpose of allowing independent verification of results increasing the level of transparency of the entire election process. Accredited 3rd party election observers will be able to verify the integrity of the ERs themselves, independently from the COMELEC. Perhaps this is what NAMFREL was after when demanded access to more election data from the COMELEC. The use of a proprietary data format would result in some legal implications in terms of copyrights, etc. Hopefully, in future elections, COMELEC opts for an AES solution that generates election data using open data format to allow free exchange and independent verification of election results by 3rd parties, if it is not yet done this way in the current system.
It would be great if the COMELEC opens the design of the AES and its components to review, just like what they did with code review. Most of the issues that have been discussed in posts about the AES stemmed from architectural decisions that went into the implementation of the AES components. Unfortunately, some of these decisions preferred to prioritize system performance while sacrificing the simplicity, verifiability, and transparency of election data.
Some people claimed that the use of Blockchain is the solution to the problem. However, they failed to identify the problem that Blockchain is supposed to solve. It’s possible that Blockchain gets used in future versions of our country’s Automated Election System, but not for the right reasons. The COMELEC should discern what is lacking in the current system. Because in the end, all engineering solutions will not matter until the AES is designed in a way that empowers ordinary citizens with reasonable technical know-how to verify election results.

Sunday, May 26, 2013

Thoughts about Vote Buying in the Philippines

Vote-buying in the Philippines can be understood as an instance of the classical prisoner's dilemma problem.On the assumption that a certain class of voters vote for the candidate who gives them money, then:Let's say you have two candidates, A and B. The strategy of candidate A while taking into consideration the assumption about voter behavior would follow this train of thought:

1. If Candidate B does not give out money to voters, then it will be better for me to give money to voters because this would increase my chances of winning their votes.

2. If Candidate B does give out money to voters, then it will be better for me to give out money too, in that way, candidate B won't have a definite edge over me. ( Note that this is a simplistic assumption because one could argue that the amount of money given by a candidate also matters in swaying a voter's decision. )

3. Regardless of whether candidate B gives out money or not, it is in A's best interest to give out money, because either way, this strategy would increase his chances of winning a voter's vote.

And candidate B would actually goes through the same analysis.

My observation with vote buying in certain towns in Samar showed that this kind of strategy actually works. Perhaps the assumption about voter behaviour used in this analysis is true. For the 2nd case, the one who wins is the one who gives out more money. So for this case, an 'auction' model becomes the appropriate model to describe vote-buying in most towns.


This analysis provides two classes of solutions (voter-centric or candidate-centric) that can be used in addressing this issue. The first one is a class of strategies that aims to change voter behaviour so that receiving money from the candidates won't affect their decisions on whom to vote. The second set of options follows a strategy whose theme is to make candidates be more honest in their methods.

Logistics wise, I'd personally select the second option because you only have to deal with relatively fewer people (towns in provinces) i.e.  100s candidates as compare to thousands of voters that you will have to re-educate and whatnot. This is a more viable solution, as compare to voter's education program currently used by COMELEC. If COMELEC really wants to curb vote buying, they should focus their resources on solving on the side of the candidates. Possible approaches are:

1) maybe thrrough the use of marked money. 

2) maglagay ng surveillance sa mga kandidato at mga tauhan nito especially a day before the election.
3) through candidate education, baka naman makonsensya sila hindi na mamimgay.

Does this make any sense?

Thoughts On Election Verifiability and the use of E-voting Systems in Philippine Election

I believe that precinct level manual counting provides very nice security properties that are important in ensuring election results integrity. At each polling precinct, counting is performed publicly and observed by representatives from different political parties and concerned organizations. At the end of the canvassing, election returns (ERs) are validated and then signed by different officials. This means that a malicious party needs to corrupt all of the election officials plus official observers who need to sign an ER in order to commit fraud. This possibility is assumed to have a very insignificant chance of happening considering the fact that official election observers are working for different political parties and have different interests to protect.

This process is inherently secure, except for polling precincts which the COMELEC do not have any kind of control e.g. isolated barangays and the likes.

In my opinion, the step that has the highest risk of being compromised is the "transmission" of these ERs from the polling precincts to the municipalities, provinces and the national board of canvassers. This is all where the magic of ballot box/ER switching occurs.

We don't need to implement a fully automated counting of ballots in our election because I believe that the current manual counting process still and already provides an adequate level of security.

However, it is in the transmission of ERs from polling precincts to the different aggregation sites where an e-voting technology could be put to good use. We could design and implement a system for transmission of ERs in electronic form, similar to the Consolation/Canvassing System (CCS).

With respect to our country's election, at the very least, aggregated election results should be verifiable up to the polling precinct level. This level of granularity might not give the same level of verifiability as in individual verifiability but I believe this is good enough given the inherent limitations in the way our national election is conducted.

Imagine that we could verify election results up to the precinct level. If the results are verified by individuals i.e. voters, located at different precincts all over the country, that could give us a higher level of confidence that votes from different precincts were counted and carried over correctly to higher levels up to the national level canvassing. For example, one could create a Facebook application which is populated with the electronic election returns publicly available in the COMELEC's election results server. An observer can verify that the recorded tally of votes posted in the COMELEC servers is the same with results showed in the official ERs posted in polling precincts. Board of Election Inspectors (BEIs) are required by law to post the ERs for their respective precincts within the vicinity of the precinct. So an observer could flag the results transmitted to the COMELEC server as either correct or incorrect.

Tuesday, July 19, 2011

on IP: IPv4 and IPv6

IP is the main protocol at the network layer of the Internet. Essentially, every data sent by any top level layer i.e. transport and application layer, gets sent as IP datagrams over the Internet. IP datagrams is the building block for internetwork communications provided by IP. IP is meant to be a best effort protocol for sending data over a network, hence it is inherently unreliable. An advantage of this particular design decision is that implementation of IP in network interfaces and routers is relatively simple. Moreover, IP is also connectionless, meaning that IP does not maintain any state information of the datagrams coming its way. Each datagram is handled independently from one another. Datagrams of the same message gets delivered to its destination on possibly many different paths and may arrive at its destination out of order [1]. Hence, a protocol like TCP is needed on top of IP to provide a reliable service needed by most Internet applications.

An IP address identifies uniquely each device i.e. hosts, routers, connected to or in the Internet. IP uses a rather simple and intuitive mechanism in routing datagrams from a source to its destination. Routing is done on a hop-by-hop basis. A routing table is maintained by hosts and routers which they use in forwarding a datagram to the next-hop router or network interface indicated in the routing table entry associated with the datagram’s destination IP address. Using ICMP, a router can build its routing table through advertisement and solicitation messages from other routers [1].

The current widely deployed version of IP, IPv4, uses 32-bit IP addresses amounting to approximately 4.3 billion addresses. With the rapid growth in the deployment of applications, services, hosts, etc. on the Internet, exhaustion of available addresses in IPv4 seems inevitable. As an answer to this likely possibility, the Internet Engineering Task Force developed IPv6, which offers a much larger address space, to succeed IPv4 [3]. IPv6 uses a 128-bit addressing scheme allowing about 2128 unique IP addresses. Aside from having a much larger address space and changes in the IP datagram format, other changes were incorporated to IPv6 which include among others: IMCPv6 for automatic host configuration upon connection to a IPv6 network and network level security through mandatory IPSec implementation [2]. Initial deployment of the service has been performed in countries like the USA, CANADA, JAPAN, and CHINA with JAPAN enjoying full government support while CHINA showcased it in the 2008 Beijing Summer Olympics.

References:

[1] Stevens ,W. R. (1993). Internet Protocol. In B. Kernighan (Ed.). TCP/IP Illustrated Volume 1 (). Addison Wesley.

[2] Das, K. IPv6 – The Next Generation Internet. IPv6.com [@http://ipv6.com/articles/general/ipv6-the-next-generation-internet.htm]

[3] IPv6. Wikipedia. [@http://en.wikipedia.org/wiki/IPv6]

Tuesday, July 5, 2011

on "Congestion Avoidance and Control [2]"

The paper describes a congestion avoidance/control algorithm which has following features:

1. a connection re/starts slow, packet transmission rates starts low and then gradually increases, until such time the connection achieves its state of 'equilibrium'. This prevents the connection from sending big bursts of packets which makes it prone to failure because of constant packet retransmissions.

2. has a 'better' round-trip time variance estimation, which allows it to estimate a more realistic retransmit timeout interval, rto, for succeeding packets. This leads to the variability of the RTT variance used of the rto computation with respect to the medium of communication i.e. satellite links, which leads to increase in performance.

3. when congestion really happens, it employs an exponential retransmit timer backoff, which allows the system to really come into its normal state, no matter what.

4. for congestion avoidance, it uses an increase/decrease algorithm with additive increase and multiplicative decrease components. Unlike in [1] which uses a binary feedback mechanism (incorporated as a bit information in the packet header) in determining the state of the system, their algorithm depends on some assumptions about the inherent properties of "lost packets". That is, lost packets are lost essentially because, the network is congested. So if a connection experiences lost packets, this means that the network is experiencing congestion and it should decrease its load. On the other hand, if the connection continuously receives ACKs, then that means it can try increasing its load. To achieve fairness, the gateway would just have to dropped packets coming from mis-having (abusive) hosts, which in turn would 'trick' the host into believing that the network is experiencing congestion, thus have to decrease its load. Just curious, did this solution work? I still prefer [1], in terms of the feedback mechanism.

Ref:

[1] D.-M. Chiu and R. Jain, "Analysis of the Increase and Decrease Algorithms for Congestion Avoidance in Computer Networks", Computer Networks and ISDN Systems, Vol. 17, 1989, pp. 1-14.

[2] V. Jacobson, "Congestion Avoidance and Control", SIGCOMM '88, Sept. 1988, pp. 314-329.

on the "Analysis of the Increase and Decrease Algorithms for Congestion Avoidance in Computer Networks[1]"

The paper presented a mathematical analysis of increase/decrease algorithms for congestion avoidance in computer networks. Congestion avoidance algorithms allow a network to operate at an optimal level of low delay and high throughput. The authors evaluated the set of increase/decrease algorithms based on the following criteria:

1. the algorithm should allow the communication system to operate at a level of optimal resource utilization (high efficiency).
2. the algorithm not only ensures efficient utilization of shared network resources, but see to it that there is fairness in the allocation of such resources among the users of the system.
3. the algorithm should be distributed to make the tasks of the system and the users simple as possible.
4. the algorithm, starting from an arbitrary initial state, should achieve goal 1 and 2 as fast as possible.


They focused their analysis to a set of increase/decrease algorithms which uses linear controls as control functions. A control function is used by a user of the system in increasing or decreasing its load utilization.

Their analysis used graphical vector representation of the different control combinations to identify the configurations of feasible linear controls that would allow the system to reach the goal of optimal resource utilization and fairness resource allocation as fast as possible. Using this approach, they found out that a simple linear control with an additive increase and multiplicative decrease components is enough for the system to achieve high efficiency and fairness.


Ref:

[1] D.-M. Chiu and R. Jain, "Analysis of the Increase and Decrease Algorithms for Congestion Avoidance in Computer Networks", Computer Networks and ISDN Systems, Vol. 17, 1989, pp. 1-14.

Tuesday, June 28, 2011

on the 'Rethinking the design of the Internet: 2 The end to end arguments vs. the brave new world'

The author of the paper reiterates the design principles that have been guiding the development of the Internet up to the present, called end-to-end arguments. End to end arguments in the context of the Internet, follow the notion of making the functions of the lower layers of the Internet infrastructure as simple as possible. Any application-specific features should be pulled out of the core infrastructure and should be implemented at the end systems instead. It proceeds by arguing that these design principles have been the key driving factor of the advances and innovations that the Internet has been experiencing since its early days. This position paper was written in the face of increasing interests of third parties i.e. private entities, governments, demanding the inclusion of new features which would allow more “better” mechanisms for providing security, privacy, accountability, etc. The paper cited a situation wherein implementing “eavesdropping” mechanism at the lower level of the infrastructure would still proved useless, after the fact, that end to end points of the communication are free to apply any available mechanism i.e. encryption, etc., to the messages being exchanged. Instead of providing the benefits one expected from it, it would only add complexity to the core network which in turn would increase the cost of deploying new applications to the Internet.

on the 'The Design Philosophy of the DARPA Internet Protocols'

The paper enumerated and described the various goals behind the DARPA Internet Project which gave birth to what we know now as the Internet; at the same time discussed their relations to the mechanisms which were chose to achieve those goals. The Internet started out as a military funded research project under the Defence Advanced Research Projects (DARPA) of the DoD of the USA.

The main goal of its inception was to provide a way for multiplexed internetwork communications among existing heterogeneous and disparate network infrastructures. Packet switching was chose as the technique for multiplexing since most of the existing networks employ packet switches.

Several second level goals were considered in its design, which proved to have great effects to what have become of it now. Survivability which relates to service availability and continuity tops among the second level goals of the design of the Internet. For example, any interruptions in some part of the network should not disrupt the usability of the whole infrastructure. Also interruptions at the lower layers of the infrastructure should be hidden or abstracted from the application level. Support for multiple services came second. So the designers of the Internet wanted to bring as many services to the Internet as possible. If we remember, reliability was the critical design requirement of the TCP. For some services i.e. real-time applications, the reliability of the TCP comes with a cost, performance degradation. The decision to formally define the boundary (layering) between TCP and IP was made, and another transport layer protocol was created, which is the User Datagram Protocol. UDP provides application a low level interface in performing their needs of internetwork communications, resulting to better control, flexibility and performance. Also, they wanted that the Internet will be able to accommodate various types of networks. Other goals which set at the bottom of the Internet priority list where (4) a mechanism for distributed management of its resources should be provided, (5) it must be cost effective, (6) host attachment must be easy, (7) resources in the Internet must be accountable. Interestingly, (7) has not been fully realized until now.

Surprisingly, there was no explicit mention of security in the original design of the Internet. Survivability was there, but I believe its notion relates more on the physical aspect of the infrastructure. The inclusion of the idea of a datagram as a building block element I think is one of the great realizations of the designers of the Internet. It gives developers better control and flexibility in meeting the networking aspects of the applications that they develop. Fate-sharing is another design decision that has proved to be critical in the development of the Internet. The notion of maintaining state information of communications at the end points only, enabled hosts to be less dependent on the performance of intermediary points in the networks. This provides service continuity on cases when some disruption happens at subset of the network.

on the 'A Protocol for Packet Network Intercommunication'

It was 37 years ago when Turing awardees Vinton Cerf and Robert E. Khan published the seminal paper describing TCP (with implicit mention of IP) which eventually led to the development of the Internet.

The paper proposed a protocol which would allow internetwork communications between processes on hosts residing in different packet switching networks. The paper stated the issue of how would such protocol handles communications between existing and planned packet switching network infrastructure, which would likely be different from one another. So it was here that the idea of having a standard protocol, which is as simple and reliable as possible, for inter process and network communications came in. Since reliability is one of the top concerns of the protocol, a mechanism for detection of ‘lost’ packets and their retransmissions was also included. A sender TCP will wait first for the receiver TCP to acknowledge bytes of messages it previously sent. If it does not receive such acknowledgment within a defined timeout, it re-transmits the unacknowledged bytes. State information of the connection between two communicating processes are kept only at both ends of the communication link, thus making the tasks of intermediary points as simple as possible i.e. only handles forwarding of packets and fragmentation if needed. Provisions for flow control was also included which is based on a window strategy. With this flow control mechanism, the receiver TCP will be able to advertise the number of bytes of data (the window) it can handle to the sender TCP, hence controlling the amount of data that flows between the receiver and sender TCP. One should really appreciate the completeness of the mechanisms or features of the protocol suggested in this paper, considering that most of them were given entirely in their pure theoretical sense. Amazing!

Sunday, September 5, 2010

On “Finding Security Vulnerabilities in Java Applications using Static Analysis”

Security in applications is important especially on web applications which handle confidential customer information and financial transactions like banking and e-commerce websites. A simple programming mistake can cause vulnerabilities in application which when exploited can caused irreparable damage to the company and its stakeholders [1].

The most common vulnerabilities in web applications nowadays exploit weak input validation implemented on applications. Attackers can enter specially crafted inputs to the application, making it perform actions which can caused breach of confidential information stored in back-end servers, bring down applications causing denial of service to legitimate users, reveal user credentials to attackers, etc. Examples of attacks are SQL injection and Cross-site Scripting, which belongs to the OWASP top 10 web applications security risks [2].

The paper describes a tool which could be used in probing Java applications for security vulnerabilities stemming from not properly validated input from the user, which they called tainted propagation problems. The tool performs a static analysis on the applications’ byte-code. It tries to determine possible sources of vulnerabilities within the application based on a detailed specification crafted using PQL, a program query language. Because their tool uses improved object naming scheme and more precise context-sensitive pointer analysis, it produces more accurate results, with less false-positives.

One of the strengths of the tool is that, it can be used by developers during the actual development cycle, which in a way cut costs of the development, because it minimizes costs coming from activities like code reviews. The authors also suggested that their approach can be used to implement the same static analysis tool for other byte-code based languages like C#.

REFERENCES

[1] V. Benjamin Livshits and Monica S. Lam. Finding Security Vulnerabilities in Java Applications using Static Analysis.
[2] OWASP Top 10 – 2010: The Ten Most Critical Web Applications Security Risks. The Open Web Security Project. At [www.owasp.org]

Thursday, August 26, 2010

On “Why Cryptosystems Fail” and “Father Guido Five Minute University”

In the context of computer security, or security in general, I think that the saying, “A system’s security is as strong as the weakest link”, summarized the relationship of the video “Father Guido Five Minute University” to the gist of the article “Why Cryptosystems Fail”.

The point of Father Guido in his idea of a Five Minute University is that the value of education we get over the years of our stay in a learning institution is relevant to their usability in dealing with the realities we face in the outside world. He says that we usually remember just the things that are actually of use to us (in our job for example), and tend to forget everything else.

In the same manner, the quote above implicitly states the real value/strength of any security system how complex or simple it may be. It’s very common to implement multi-level security system these days. And the value of these security systems is just as good as the weakest component in the chain. A single hole is enough to enable attackers to break into the whole system. In the article, it was stated that most of the attacks on cryptosystems do not exploit their technical weakness, but rather directed to other aspects of the system i.e. physical implementation, poor management, quality control.

So the author suggested a shift in the way we think, in our evaluation of the strength of computer security systems. He said that efforts should be diverted on strengthening the competence of the people involved in implementing other aspects of a security system.


References:

[1] Anderson, Ross. Why Cryptosystems Fail.
[2] _____. Father Guido Sarducci Five Minute University. @[youtube.com]

Monday, July 5, 2010

On "Setuid Demystified" and "Understanding Android Security"

The article entitled “Setuid Demystified” tried to demystify the inner workings of the uid-setting system calls, which are inherent and commonly used on Unix-based operating systems.

The first paper, as its name implies, tried to unravel the way uid-setting systems calls in Unix-based operating systems work. What are these uid-system calls anyway? Well, it’s a sort of an API which one could use/call in Unix-based systems to set or to drop, temporarily or permanently, the privileges i.e. resources, a program can access. For example, when you want a program to run with root privileges, then you’ll probably call one of the functions within this API.

One of the key issues that the researches tried to address on their study is the inconsistencies of the behaviour of these system calls on several Unix-based operating systems. The researchers attributed this to the “ambiguous” or lack thereof, of a specification documenting what these system calls do and how should they do it i.e. the rules or invariants that concern each function. This could possibly lead to some serious security and portability issues on applications developed for such systems as described in the article.

On their study, the researches first tried to determine the behaviour of these system calls across several implementations by examining their actual source files. After trying such approach, they eventually realized the impracticality of what they’re doing, and then they decided to build a more formal methodology. They have implemented a Finite State Automaton (FSA) that covers the different possible states of a particular process altered by the uid-system calls made within it [1]. They tried to automate the process of building such FSA model for each uid-system calls through simulation. Their simulator allowed them to create FSA models faster and less tedious. This in turn enabled them to easily compare the differences of the different FSA model generated from each uid-system call implementation. This lead to a much faster detection of the inconsistencies present in several implementations of each uid-system calls. Moreover, their formal method makes the automation of such detection mechanism possible. The formal method also led to the discovery of some security vulnerabilities in some implementation of the uid-system calls.

The one thing that caught my interest in this paper is the way by which the researchers developed a formal method for an activity that is rather tedious if done manually. Of course they being successful in their study clearly intensifies the possibility of developing formal models for things that may appear so complex at times. Development of such formal methods also enables a deeper understanding of what’s happening “inside” albeit some necessary abstractions are employed.

The other article, “Understanding Android Security”, discussed the core security mechanisms employ on Android, a mobile operating system.

They discussed the mechanism by which Android manage the privileges of the different application running in it. The security framework employed by Android developers follows a permission labeling scheme. An Android developer assigns permission labels to his application by explicitly specifying them on an XML manifest file [2]. These permission labels specify how this particular application handles accesses made by other application to its components. This manifest file is use to set an application’s permission labels during installation and stays permanent until a new installation is made.

Although such security framework is inherent on the Android platform, programming errors made by security-unaware developers are still the major concerns which influenced the existence of security vulnerabilities on Android applications. In this regard, the researchers developed a tool, called Kirin, which automates the verification of consistency of the set of permissions defined in an application.
Automation seems everything, isn’t it?

References:
[1] H. Chen, D. Wagner, and D. Dean. “Setuid Demystified”.

[2] W. Enck, M. Ongtang, and P. McDaniel, “Understanding Android Security”. IEEE Security and Privacy. 2009, pp. 50-57

Wednesday, June 23, 2010

On Buffer Overflow Attacks

In programming jargon, a buffer is an area in memory which is usually used to temporarily store data. Buffers are usually local variables of a function which are stored in the runtime stack of a program in a way that would make manipulation of such values easier. Other data like address of the next program instruction which will be executed when a function returns from execution are also stored in the stack. Since a stack is a contiguous area of memory which usually grows towards lower memory addresses, the possibility of buffer overflows, which is overwriting other memory area beyond the size of the buffer being write onto, is high especially for programs which perform poor bound checking. In most cases, non-deliberate buffer overflows lead to the corruption of important program data making the behaviour of the program unpredictable or the program will simply crash because of segmentation fault. On the other hand, a typical, deliberate buffer overflow is crafted in such a way that the program control flow is altered which enable an attacker to make the program point to a memory address containing malicious code and gets it executed[1].

Although the issue of buffer overflows existed as early as the 1980s, it gained popularity as an immediate security threat only after when the wrath of the infamous Morris Worm [1] took in. As the first well-known computer worm to have made use of the concept behind buffer overflow, Morris Worm set the sail for an effort among computer professionals to develop tools and techniques that would mitigate and prevent further exploitations of such a common vulnerability.

Several efforts had been made that aim to prevent, and stop exploitation of such vulnerabilities. Each of them was proven to be successful in their own rights [1, 4]. But as time goes by, these preventive mechanisms were seen to have loop holes also, which defeated the security they provide [4, 5].

Although new programming technologies i.e. type safe languages, engrained bound checking in languages like Java, decreased if not completely eradicated such a threat, the existence of legacy systems and the continued support to it, keep the risks pose by such attacks at the highest level. I believe, in fairness to a language like C, that the problem is not really in the language per se; rather it is on the individuals who write programs using it. In general, without proper awareness and the surge of different factors during software development, it becomes harder for software developers to examine each of the different aspects of a computer program. Unfortunately, program security is one such aspect which is simply forgotten during development. Although some studies are being conducted on this particular area, for example [3], it still lacks major breakthroughs that would enable the adaptation of a standard security framework for building secured software applications.

Because it is in the nature of computer hackers to unravel vulnerabilities in existing systems widely used by the computing community and exploit them “for fun and profit” [2], it is a constant struggle for security professionals to cope and move ahead of them.



References:

[1] Crispin Cowan, Perry Wagle, Calton Pu, Steve Beattie, and Jonathan Walpole. Buffer Overflows: Attacks and Defences of the Vulnerability of the Decade

[2] “Aleph One”. Smashing The Stack For Fun And Profit. Phrack, 7(49), November 1996

[3] Gary McGraw, Brian Chess, Sammy Migues. Software [In]security: The Building Security In Maturity Model (BSIMM). InformIT, at [http://www.informit.com/articles/article.aspx?p=1332285]. March 16, 2009

[4] Alexander Sotirov, Mark Dowd. Bypassing Browser Memory Protection – Setting back browser security by 10 years.

[5] Bulba and Kil3r. Bypassing Stackguard and Stackshield. Phrack, at [http://www.phrack.org/issues.html?issue=56&id=5], May, 2000

Saturday, June 12, 2010

On the CRS Report for Congress “Botnets, Cybercrime, and Cyberterrorism: Vulnerabilities and Policy Issues for Congress” [6]

At present, pressing issues regarding Internet security is one of the major concerns of different institutions, large companies and governments alike. I believe any institution which depends on any computer network, most likely the Internet, on keeping their respective businesses going are aware of these problems. And if they are still not aware, then they should be because there’s a great possibility that their networks are being used to pursue illegal activities.


The report articulated several different scenarios by which how institutions and groups of individuals who have interest against the US government can make use of existing technologies to cripple the country’s economy. The report explored the possibilities of a coordinated attacked against US government-owned IT infrastructures. Although possibilities exist, concerned agencies downplay the extent of the real damage they can cause. They argued that recovery from such attacks can be handled in a way similar to how they handled natural calamities i.e. flooding, earthquake, or random machine breakdown in the past. Also, they argued that the cost of such attacks out-weighs the benefits they give, so these would deter anyone from even doing such things.


Another concern discussed in the report is the commercialization of the tools and the technical skills necessary to do cybercrimes. The ease by which one can earn from stealing financial information, trade secrets, etc. and selling them to underground markets lure more “brilliant” individuals into this kind of activity. The motivation of these attacks are no longer pure financial in nature. Some are initiated by groups to push political and social reforms [6].


The report made mention of Botnets all throughout. Russian-based Kaspersky Lab reported that the major threat plaguing the Internet today is the threat of botnets [1]. Botnets (Bot networks) are networks of compromised machine controlled by an attacker called the “bot master” [2]. Botnets are mostly responsible for the spread of malwares across the Internet that leads to theft of personal information and other sensitive data from government institutions and companies who store confidential customer information. Furthermore, botnets had been used in DDoS attacks and proved to be very efficient [4]. In most cases, computers which are generally infected are home-based personal computers which are usually unprotected or whose owners are not well aware of these security threats.


One of the major problems that security researchers faces in dealing with botnets and other security threats alike is the high level of technical proficiency of the individuals behind these threats. The technical complexities of the tools and techniques i.e. code encryption and obfuscation, which these hackers are using, gets higher such that security researchers are not able to get close at them. In most cases, such individuals monitor the activities of security researchers who are hitting on them which enable them to develop even better ways to avert and prevent detection [5].


Another factor is the severity of the infection it already caused to the Internet. The large number of infected computers and established C&C servers makes the complete take down of these networks much more difficult [3]. The use of peer-peer network architecture instead of the traditional C&C structure on botnets surfacing nowadays makes even harder for security professionals to alleviate the severity of the threats they cause.


In most cases, proliferation of malicious programs or Trojan horses (which turn a computer into a zombie) can be attributed largely to unsuspecting Internet users who are unaware of the different security risks lurking in the World Wide Web. I believe that a sufficient and massive information campaign of these security risks to the majority of the population of Internet users should be considered. I think it is safe to assume that majority of Internet users are not really aware of these prevailing security issues which make them even more vulnerable. We should increase everyone’s awareness about these security trends. Preventive security should be initiated at the end-user/client level. I don’t mean to cause paranoia among individuals who does not really want to be bothered of these things. But since it is the case that unsuspecting Internet users play major player in the spread of these botnets, we don’t have a choice but to force the issue on them. I am not saying also that this will put a stop to this kind of cyber-attacks. But at the very least, this initiative should at least decrease the number of infected systems and possibly prevent further infections in the future. And during these times, every bit of help we can get counts.

References:
1. [http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci1030284,00.html]

2. Grizzard, Julian B. , et al., “Peer to peer Botnets: Overview and Case Study”. UneNix.org, at
[http://www.usenix.org/ event/hotbots07/tech/full_papers/grizzard/grizzard_html/]

3. Fisher, Dennis. “Botnets using ubiquity as security”. ThreatPost.com, at [http://threatpost.com/ en_us/blogs/botnets-using-ubiquity-security-060710]

4. “Robot Wars – How Botnets Work”. WindowSecurity.com, at [http://www.windowsecurity.com/ articles/Robot-Wars-How-Botnets-Work.html]

5. VitalyK. “Gumblar: Farewell Japan”. Securelist.com, at [http://www.securelist.com/en/blog/2132/Gumblar_Farewell_Japan].

6. Wilson, Clay, “ Botnets, Cybercrime, and Cyberterrorism: Vulnerabilities and Policy Issues for Congress”. CRS Report for Congress. January 29, 2008.

Tuesday, June 8, 2010

On Ken Thompson's Reflection on Trusting Trust

Early on, one can hear the humbleness from his voice. He expressed the importance of team work by recognizing other individuals who had collaborated and worked with him. When individuals in a team perform in a synergetic manner complementing the weaknesses of each other and taking advantage of each others strength, it leads to a situation where “ the whole is greater than the sum of its parts” 1.

By following his lecture closely, one can see that his delivery was invigorating in a way that he showed the build-up of his capability as a programmer in a gradual manner. It seems that he is saying implicitly that anyone, who has the interest and determination, can excel in the field as long as he/she is persistent. For the purpose of progress and advances of the literature in our field, this thought is very welcoming. The real issue comes when the intentions of such individuals possessing such valuable knowledge is questioned. Are they the bad or the good guys?

On the subject of security, specifically in programming or software development, one can see the dilemma that we are facing. In our field where “don’t reinvent the wheel” is the common mantra, we are faced with trust issues each time we decide to use a 3rd party application or API in the application that we developed. When we reuse a piece code, it’s easy for us to check if it contains malicious instruction. But when question on the integrity on the low level aspects i.e. compiler, assembler, etc. of the programming environment we are using, there comes the problem esp. if it’s not open-source2 . I think it’s safe to say and very unfortunate that many of us in the field never really thought of this as an issue especially if these 3rd party libraries, tools or software came from "trusted" institution. Honestly, I never really have thought of this up until I read the article. When we become part of projects building software used in fields where human life will be at risk, then I believe we should take this more seriously and with greater responsibility.

Ken Thompson’s choice of topic to discuss in his lecture during a time when practitioners in our field faces moral and ethical issues because of the boom of individuals who called themselves hackers who undermine the integrity of the majority was very timely. He expressed vividly his position regarding the importance of honesty and trust in our kind of profession. His lecture was more of an open challenge to us practitioners of becoming morally and ethically ready when we work.


1 by Aristotle

2 Reflection on Trusting Trust