physical security, youre doing it wrong

111
Physical Security (You’re Doing It Wrong) A.P. Delchi Saturday, July 3, 2010

Upload: others

Post on 16-May-2022

8 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Physical Security, Youre Doing it Wrong

Physical Security(You’re Doing It Wrong)

A.P. Delchi

Saturday, July 3, 2010

Page 2: Physical Security, Youre Doing it Wrong

# whois delchi

‣ Infosec Rasputin

‣ Defcon, HOPE, Pumpcon, Skytalks

‣ Minister of Propaganda & Revenge, Attack Research

Saturday, July 3, 2010

Page 3: Physical Security, Youre Doing it Wrong

# whois delchi

$DIETY

Grant me the serenity to accept people who will not secure their networks,

the courage to face them when they blame me for their problems,

and the wisdom to go out drinking afterwards

Saturday, July 3, 2010

Page 4: Physical Security, Youre Doing it Wrong

“You’re Doing It Wrong”

A phrase meaning that

the method you are using is not

creating the desired result

Saturday, July 3, 2010

Page 5: Physical Security, Youre Doing it Wrong

Your MissioN

Saturday, July 3, 2010

Page 6: Physical Security, Youre Doing it Wrong

Your MissioNDesign and implement a physical security system for a new facility, to include multi-factor authentication and video surveillance.

Saturday, July 3, 2010

Page 7: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 8: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 9: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 10: Physical Security, Youre Doing it Wrong

“Proper Previous Planning Prevents Piss Poor Performance”

Dick Marcinko,

“The Rogue Warrior”

Saturday, July 3, 2010

Page 11: Physical Security, Youre Doing it Wrong

Physical Security

Saturday, July 3, 2010

Page 13: Physical Security, Youre Doing it Wrong

Physical SecurityPhysical security describes both measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media and guidance on how to design structures to resist various hostile acts.en.wikipedia.org/wiki/Physical_security

Measures to reasonably ensure that source or special nuclear material will only be used for authorized purposes and to prevent theft or sabotage.www.nrc.gov/reading-rm/doc-collections/cfr/part110/part110-0002.html

Saturday, July 3, 2010

Page 14: Physical Security, Youre Doing it Wrong

Physical SecurityPhysical security describes both measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media and guidance on how to design structures to resist various hostile acts.en.wikipedia.org/wiki/Physical_security

Measures to reasonably ensure that source or special nuclear material will only be used for authorized purposes and to prevent theft or sabotage.www.nrc.gov/reading-rm/doc-collections/cfr/part110/part110-0002.html

The measures used to provide physical protection of resources against deliberate and accidental threats.www.tsl.state.tx.us/ld/pubs/compsecurity/glossary.html

Saturday, July 3, 2010

Page 15: Physical Security, Youre Doing it Wrong

Physical Security

Saturday, July 3, 2010

Page 16: Physical Security, Youre Doing it Wrong

Methodology

• Assessment

• Assignment

• Arrangement

• Approval

• Action

Saturday, July 3, 2010

Page 17: Physical Security, Youre Doing it Wrong

MethodologyASSESSMENT

A thorough examination of the facility to be protected.

Saturday, July 3, 2010

Page 18: Physical Security, Youre Doing it Wrong

MethodologyASSESSMENT

•Scope of property to be protected•Established points of entry and egress•Potential points of entry and egress•Existing security measures•Evaluation of physical property•Risk assessment

Saturday, July 3, 2010

Page 19: Physical Security, Youre Doing it Wrong

MethodologyASSIGNMENT

Establish the required level of security for specific areas and

assets within the facility.

Saturday, July 3, 2010

Page 20: Physical Security, Youre Doing it Wrong

MethodologyASSIGNMENT

•High level ✓Data Centers✓Executive Offices✓Finance & Accounting

• Medium Level✓ Entry & Egress✓ Reception✓ Elevators

• Low Level✓ Common Areas✓ Cubicle Farms

Saturday, July 3, 2010

Page 21: Physical Security, Youre Doing it Wrong

MethodologyASSIGNMENT

•Considerations✓ Insurance requirements✓ Compliance requirements✓ Fire code requirements✓ Business requirements

Saturday, July 3, 2010

Page 22: Physical Security, Youre Doing it Wrong

MethodologyARRANGEMENT

Establish the most effective locations for security devices

based on their requirements.

Saturday, July 3, 2010

Page 23: Physical Security, Youre Doing it Wrong

MethodologyARRANGEMENT

•Cameras ✓Field of view✓Redundancy✓Tracking

• Doorways✓ Type of locks✓ Multi factor authentication✓ Time based restrictions

• Central Control✓ Cabling limitations✓ Power, archiving, and disaster planning

Saturday, July 3, 2010

Page 24: Physical Security, Youre Doing it Wrong

MethodologyAPPROVAL

Submit all plans, costs, schedules and related data to management.

Saturday, July 3, 2010

Page 25: Physical Security, Youre Doing it Wrong

MethodologyAPPROVAL

•Hardware ✓Quotes form multiple vendors✓Lifetime requirements✓Service plans

• costs✓ Plan A, B, and C✓ Flexibility✓ Options

• Schedule✓ Time frame for completion✓ Interference with business operations

Saturday, July 3, 2010

Page 26: Physical Security, Youre Doing it Wrong

MethodologyACTION

Implementing the physical installation and configuration of

the approved system.

Saturday, July 3, 2010

Page 27: Physical Security, Youre Doing it Wrong

MethodologyACTION

•Construction ✓Oversee construction ✓Oversee inspections by state / local govt✓Manage corrections

• Training✓ Security officers✓ Users✓ Establishing policy & procedure

• Testing✓ Ensuring the system works as planned✓ Compliance testing

Saturday, July 3, 2010

Page 28: Physical Security, Youre Doing it Wrong

What Could Possibly Go

Wrong?

Saturday, July 3, 2010

Page 29: Physical Security, Youre Doing it Wrong

"No plan of operations extends with certainty beyond the first encounter with the enemy's main strength."

Count Helmuth von Moltke

Saturday, July 3, 2010

Page 30: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 31: Physical Security, Youre Doing it Wrong

MethodologySaturday, July 3, 2010

Page 32: Physical Security, Youre Doing it Wrong

Methodology

TRAINING

Saturday, July 3, 2010

Page 33: Physical Security, Youre Doing it Wrong

Methodology

TRAINING

Experience

Saturday, July 3, 2010

Page 34: Physical Security, Youre Doing it Wrong

Methodology

TRAINING

Experience

Planning

Saturday, July 3, 2010

Page 35: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 36: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 37: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 38: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 39: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 40: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 41: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 42: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 43: Physical Security, Youre Doing it Wrong

Management

Saturday, July 3, 2010

Page 44: Physical Security, Youre Doing it Wrong

Management

Saturday, July 3, 2010

Page 45: Physical Security, Youre Doing it Wrong

ManagementPROS :

✓ Provide Budget✓ Set Requirements✓ Sign your paycheck✓ Run the show

Cons :

✓ They know this

Saturday, July 3, 2010

Page 46: Physical Security, Youre Doing it Wrong

Strife

Saturday, July 3, 2010

Page 47: Physical Security, Youre Doing it Wrong

Strife“I want a state of the art high tech system. FBI, CIA kind of security”

Saturday, July 3, 2010

Page 48: Physical Security, Youre Doing it Wrong

Strife“I want a state of the art high tech system. FBI, CIA kind of security”

“I can do that. Based on your needs, and the floor plan it will cost $54,875.”

Saturday, July 3, 2010

Page 49: Physical Security, Youre Doing it Wrong

Strife“I want a state of the art high tech system. FBI, CIA kind of security”

“I can do that. Based on your needs, and the floor plan it will cost $54,875.”

“Can’t you just buy something from Costco?”

Saturday, July 3, 2010

Page 50: Physical Security, Youre Doing it Wrong

Strife“I want a state of the art high tech system. FBI, CIA kind of security”

“I can do that. Based on your needs, and the floor plan it will cost $54,875.”

“Can’t you just buy something from Costco?”<REDACTED>CEO of Information Security Firm

Saturday, July 3, 2010

Page 51: Physical Security, Youre Doing it Wrong

≠Saturday, July 3, 2010

Page 52: Physical Security, Youre Doing it Wrong

Strife

Saturday, July 3, 2010

Page 53: Physical Security, Youre Doing it Wrong

Strife“I went to Best Buy and saw a HDMI cable for $50. I went home and surfed the internet for a while and found the same cable for $2 from a web site in China. If I can do that for a cable I expect you to do the same thing for my security system.”

Saturday, July 3, 2010

Page 54: Physical Security, Youre Doing it Wrong

Strife“I went to Best Buy and saw a HDMI cable for $50. I went home and surfed the internet for a while and found the same cable for $2 from a web site in China. If I can do that for a cable I expect you to do the same thing for my security system.”

<REDACTED>CEO of Fortune 500 Security Firm

Saturday, July 3, 2010

Page 55: Physical Security, Youre Doing it Wrong

Be knowledgeable on the equipment , methodology and best practices for your industry.

Understand the impact that your project will have on business & user activity

Rely on facts, not speculation , theory, rumors, or maybes.

Present facts, support with documentation, explain risk and impact, prove mitigation

Present in a factual & respectful manner, showing your work and explaining your reasoning behind the design

If you don’t know, you don’t know. State that you will research and return with the answers

Be prepared to loose gracefullySaturday, July 3, 2010

Page 56: Physical Security, Youre Doing it Wrong

SUCCESS

Saturday, July 3, 2010

Page 57: Physical Security, Youre Doing it Wrong

SUCCESS

“This is one hell of a security system. Whoever did this knew what the hell they were doing.”

Saturday, July 3, 2010

Page 58: Physical Security, Youre Doing it Wrong

SUCCESS

“This is one hell of a security system. Whoever did this knew what the hell they were doing.”<REDACTED>Visitor, Friend of CEO of information security firm

Saturday, July 3, 2010

Page 59: Physical Security, Youre Doing it Wrong

“Shut up, get it done, failure is not an option.”

Charles Rawls

VP of ass kicking

dorsai Embassy, Earth

Saturday, July 3, 2010

Page 60: Physical Security, Youre Doing it Wrong

Vendors

Saturday, July 3, 2010

Page 61: Physical Security, Youre Doing it Wrong

Vendors

Saturday, July 3, 2010

Page 62: Physical Security, Youre Doing it Wrong

VendorsPROS :

✓ Provide Cool Toys✓ Will Let You PLay with The Cool Toys✓ Have historical info onproduct quality

Cons :

✓ Will expect you to buy From Them

Saturday, July 3, 2010

Page 63: Physical Security, Youre Doing it Wrong

“The Ferengi Rules Of Acquisition”

$6.99

ISBN : 0671529366

Saturday, July 3, 2010

Page 64: Physical Security, Youre Doing it Wrong

RULE # 1There are many , many, many vendors

out there

Saturday, July 3, 2010

Page 65: Physical Security, Youre Doing it Wrong

RULE # 2You do not always need the latest,

greatest state of the art item

Saturday, July 3, 2010

Page 66: Physical Security, Youre Doing it Wrong

RULE # 3Always deal with vendors between

11 AM & 2 PM

Saturday, July 3, 2010

Page 67: Physical Security, Youre Doing it Wrong

Reality

Saturday, July 3, 2010

Page 68: Physical Security, Youre Doing it Wrong

Reality

Requirements

Saturday, July 3, 2010

Page 69: Physical Security, Youre Doing it Wrong

Reality

Requirements

Saturday, July 3, 2010

Page 70: Physical Security, Youre Doing it Wrong

Reality

Requirements RFQ

Saturday, July 3, 2010

Page 71: Physical Security, Youre Doing it Wrong

Reality

Requirements RFQ

Saturday, July 3, 2010

Page 72: Physical Security, Youre Doing it Wrong

Reality

Requirements RFQ

Quote

Saturday, July 3, 2010

Page 73: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 74: Physical Security, Youre Doing it Wrong

Never rely on a single vendor

Do not get caught up in vendor wars

Ensure that the vendor is knowledgeable on the products they are selling

Do your own product research

Beware of unnecessary up-selling

Get details on all aspects ... warranty, service , training ....

Do not be afraid to revise your RFQ

Do not be afraid to READ your RFQ

Keep all paperwork, quotes, and RFQ revisions

Saturday, July 3, 2010

Page 75: Physical Security, Youre Doing it Wrong

Prioritize your needs to make a balance between budget and equipment

Look for hidden costs, cost creep, feature creep, and after contract expenses

If you work with multiple vendors for components of a system it is YOUR responsibility to ensure that the products will work together

Know up front if sub-contracting will happen, and if so do due diligence on the sub contractors

A high price support contract does not always mean high quality support

Saturday, July 3, 2010

Page 76: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 77: Physical Security, Youre Doing it Wrong

"There are no honorable bargains involving exchange of qualitative merchandise like souls. Just quantitative merchandise like time and money."

William S. Burroughs“Words Of Advice For Young People”

Saturday, July 3, 2010

Page 78: Physical Security, Youre Doing it Wrong

People Who THINKThey Know More Than You

Saturday, July 3, 2010

Page 79: Physical Security, Youre Doing it Wrong

People Who THINKThey Know More Than You

Saturday, July 3, 2010

Page 80: Physical Security, Youre Doing it Wrong

People Who THINKThey Know More Than You

PROS :

✓ They Usually Don’t✓ Make You Look Good ✓ Annoy Management

Cons :

✓ Rarely Shut Up

Saturday, July 3, 2010

Page 81: Physical Security, Youre Doing it Wrong

“Of course the alarm says it’s 105 degrees. The sensor is on the ceiling, and heat rises. It’s 105 up there, but down here where the servers are it’s nowhere near 105.”

<REDACTED>

CEO, MIT MBA,

Said 20 Minutes before servers automatically shut down due to thermal alarms

Saturday, July 3, 2010

Page 82: Physical Security, Youre Doing it Wrong

“Of course the alarm says it’s 105 degrees. The sensor is on the ceiling, and heat rises. It’s 105 up there, but down here where the servers are it’s nowhere near 105.”

<REDACTED>

CEO, MIT MBA,

Said 20 Minutes before servers automatically shut down due to thermal alarms

Saturday, July 3, 2010

Page 83: Physical Security, Youre Doing it Wrong

Know the difference between water cooler talk and factual discourse.

Refute with facts, experience, and a even tone

Do NOT use personal attacks, vulgar insults, or questionable phrases or terms

If they start playing the brownie points game, stop.

If they start playing politics, stop.

If they cite something they heard on AM talk radio, RUN!

Saturday, July 3, 2010

Page 84: Physical Security, Youre Doing it Wrong

Cut sheets from the vendor are a better point of reference than something told to a coworker by their barber who heard it from his cousin who works on the loading dock where the publish that technology magazine .

Do not play buzzword bingo

Know what the terms, acronyms, and technological phrases you use mean.

Let them kiss ass, while you kick ass.

Saturday, July 3, 2010

Page 85: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 86: Physical Security, Youre Doing it Wrong

“What about biometrics?”

Saturday, July 3, 2010

Page 87: Physical Security, Youre Doing it Wrong

“What about biometrics?”

“Biometric three phase multi-homed active authentication is the best!”

Saturday, July 3, 2010

Page 88: Physical Security, Youre Doing it Wrong

“What about biometrics?”

“Biometric three phase multi-homed active authentication is the best!”

“I am not paid to listen to this drivel. You are a terminal fool.”

Saturday, July 3, 2010

Page 89: Physical Security, Youre Doing it Wrong

“What about biometrics?”

“Biometric three phase multi-homed active authentication is the best!”

“*Ahem*”

“I am not paid to listen to this drivel. You are a terminal fool.”

Saturday, July 3, 2010

Page 90: Physical Security, Youre Doing it Wrong

“What about biometrics?”

“Biometric three phase multi-homed active authentication is the best!”

“*Ahem*”

Saturday, July 3, 2010

Page 91: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 92: Physical Security, Youre Doing it Wrong

“What about biometrics?”

Saturday, July 3, 2010

Page 93: Physical Security, Youre Doing it Wrong

“What about biometrics?”

“Biometric three phase multi-homed active authentication is the best!”

Saturday, July 3, 2010

Page 94: Physical Security, Youre Doing it Wrong

“What about biometrics?”

“Biometric three phase multi-homed active authentication is the best!”

“As per your requirements the RFQ contains two factor authentication with an option for biometrics as a third, pending budgetary constraints. The cut sheets are in your copy of the RFQ.”

Saturday, July 3, 2010

Page 95: Physical Security, Youre Doing it Wrong

NO!

Saturday, July 3, 2010

Page 96: Physical Security, Youre Doing it Wrong

YES!

Saturday, July 3, 2010

Page 97: Physical Security, Youre Doing it Wrong

CONSTRUCTIONWORKERS

Saturday, July 3, 2010

Page 98: Physical Security, Youre Doing it Wrong

CONSTRUCTIONWORKERS

Saturday, July 3, 2010

Page 99: Physical Security, Youre Doing it Wrong

CONSTRUCTIONWORKERS

PROS :

✓ Reliable Timing✓ Know Trade Secrets✓ Tell Good Jokes

Cons :

✓ Will Do EXACTLY what You Tell Them To Do

Saturday, July 3, 2010

Page 100: Physical Security, Youre Doing it Wrong

Know the work schedule for the construction team

Meet the foreman. Get his contact information.

Read the blueprints.

Read the blueprints again, with the foreman.

Supervise the construction. Look for things that are not quite right.

Expect to find surprises.

Expect to pay to fix them.

Saturday, July 3, 2010

Page 101: Physical Security, Youre Doing it Wrong

Construction workers and their foreman are the first line of defense when it comes to building inspections.

They know what needs to be done, and why.

They deal with the same state/county/city building inspectors on multiple projects.

Listen to them. Do what they say. This is their area of expertise, even if the only adjective they know is “fucking”

“The fucking wiring is not hooked up to the fucking switch correctly, so it’s not going to fucking work. It’s fucked.”

-NJ construction worker

Saturday, July 3, 2010

Page 102: Physical Security, Youre Doing it Wrong

Construction workers on your project may not

speak English.

If this is a problem , deal with it before work

begins.

Consult with HRbefore bringing up the

subject.

If you can not communicate with each

other there is no way to indicate problems, make changes, or share dirty

jokes

Saturday, July 3, 2010

Page 103: Physical Security, Youre Doing it Wrong

Saturday, July 3, 2010

Page 104: Physical Security, Youre Doing it Wrong

Things WIll Go wrong

Saturday, July 3, 2010

Page 105: Physical Security, Youre Doing it Wrong

Not all problems can be solved with a clever work-around.

A quick fix today can be a problem

tomorrow.

Saturday, July 3, 2010

Page 106: Physical Security, Youre Doing it Wrong

Pizza and beer is cheaper than

overtime.

Saturday, July 3, 2010

Page 107: Physical Security, Youre Doing it Wrong

USERS

Saturday, July 3, 2010

Page 108: Physical Security, Youre Doing it Wrong

USERS

Saturday, July 3, 2010

Page 109: Physical Security, Youre Doing it Wrong

USERSPROS :

✓ The Reason You Are Here✓ Love To Take Classes✓ Attracted To New Tech

Cons :

✓ Will Expect Your System To Act The Way They Want It To

Saturday, July 3, 2010

Page 110: Physical Security, Youre Doing it Wrong

"If you have responsibility for security but have no authority to set rules or

punish violators, your own role in the organization is

to take the blame when something big goes wrong."

Professor Gene Spafford"Practical Unix and Internet Security"

Saturday, July 3, 2010

Page 111: Physical Security, Youre Doing it Wrong

"Be comforted that in the face of all aridity and disillusionment,

and despite the changing fortunes of time,

There is always a big future in computer maintenance."

"Deteriorata" - National Lampoon, 1972

Saturday, July 3, 2010