Showing posts with label SCAP. Show all posts
Showing posts with label SCAP. Show all posts

Wednesday, October 2, 2013

US partial Government shutdown

The US government shutdown means that the following are affected:
 
  • NIAP - closed until further notice.
    13/10/07 - 
    NIAP Returns from Furlough

    As of 7 October 2013, NIAP operations are resumed. Please feel free to contact us with inquiries. We thank you for your continued support.
  • CMVP (NIST) - closed until further notice, but CSEC (Canada) CMVP 
    will continue operations, however no validations will be completed 
    without a NIST signatory
  • CAVP (NIST) -  closed until further notice. 
  • SCAP -  closed until further notice.
  • GSA and TWIC are also probably affected, 
    but we don't have official word from those programs yet. 
 
atsec continues to work on IUT and evaluation projects in the atsec labs as normal, but obviously progression through scheme/program milestones may be affected.
atsec customers in evaluation under other schemes such as BSI or CSEC (Sweden) are not being affected. 
atsec customers with questions about their projects should contact their atsec representative. 

Monday, April 1, 2013

atsec information security Introduces Ant-based Software Delivery

Austin, TX – While research organizations around the world are working hard on topics like DNA computing, biological computers, and molecular circuitry, atsec information security once again has proven itself a vanguard of bold scientific progress in the IT sector.

During his 2011 trip to Cape Town, South Africa, atsec chief scientist Helmut Kurth spent his days in an ISO plenary meeting and his evenings in the mountains where he obtained a wild strain of ophiocordyceps unilateralis (colloquially known as the “zombie ant fungus”). Known for its curious ability to take over an ant’s brain and direct it to a different location, the fungus has been a bit of a mystery in the world of Myrmecology; but Kurth had specific plans for the fungus, subjecting it to a mixture of 3-quinuclidinyl benzilate and highly concentrated espresso used to trigger an unusual nesting behaviour of dorylus nigricans – the West African driver ant.

Kurth was able to program the ants to locate computer systems within a range of 5 miles, detect the versions of drivers installed in those systems (via version-based pheromones) and hence, whether a driver update was required and, if this was the case, get into the computer and install the driver update they carry. This effectively solves the problem of a computer that has potentially been subverted by malware and therefore is not installing the required driver updates or installing tainted updates.

Kurth commented: “People have always been afraid of new technologies. They said fire was a bad idea. They said the wheel would bring down humanity. Now they say using trained ants to deliver driver updates is crazy. But when this delivery channel is proven, the naysayers will be forced to acknowledge its obvious benefits.”


Picture: A driver ant delivering a driver update for a graphic card.

Fiona Pattinson, CISO of atsec information security corporation, added: “Keeping your device drivers up to date on all computers in an organization is one of the great challenges that many companies face today, especially in the context of supply chain security. Standards like the Security Content Automation Protocol (SCAP) try to address this issue, but I believe our ant-based solution – working title DriverAnt - will become best practice in no time.

Driver ants are known for their collaborative talent, relentless work ethic, and a strong sense of duty. From a security perspective, they are ideal as their mandibles are well capable not only of carrying the chips, but also of dealing with any attempted information tampering or man-in-the-middle attacks.”

DriverAnt might already be in your area, but will soon be available all across America since our intern forgot to close the terrarium door.

Monday, October 10, 2011

Impressions from the 12th International Common Criteria Conference

by Courtney Cavness

atsec had several presenters and attendees at the 12th annual ICCC in Kuala Lumpur, Malaysia.

As a presenter, I can say it was an honor to speak at the conference, and have the extended opportunity to exchange ideas with other experts in the security industry. The host of the event, CyberSecurity Malaysia, graciously shared with us a taste of their country's culture and cuisine, which includes Malay, Chinese, and Indian cultures, and to a lesser extent Persian, Arabic, and British influences. Their theme, "One Malaysia," was the perfect embodiment of the CC itself; several different interests and cultures coming together in harmony to create a unique and diverse environment. It was a wonderful and beneficial experience to be there.

I attended many presentations in each of the three different track sessions: CC formalities, technical use of the CC, and aspects of CC application. The sessions varied from many interesting topics such as how SCAP can be used with the CC, industry-stated issues with supply chain security, and updates from the schemes of various countries. Also of interest to me personally were talks on foreseen problems with cloud computing, attribute similarities between the CC and FIPS 140-2 evaluations, and different countries' experiences with implementing CC training in unique and different ways.

Above and beyond the presentations, the conference offered the invaluable opportunity to put a name to a face. Many attendees were able to meet with vendors, lab representatives, and country delegates and get an understanding of what they need the CC to do. The task now is to take that input and help ensure that everyone who has a stake in the CC is being heard and appropriate updates are made.

What was surprising to me was that there was a vast majority of agreement between schemes, vendors, and delegates as to what the issues are with the CC. The conference gave us a platform to share these ideas, as well as our individual successes in working with the CC -- a global standard meant to meet global security needs.

My personal take-away from this conference is that having a standard that is accepted and successfully implemented by product vendors requires a balance between process and common sense. If you eliminate the steps required in a standard for the sake of expediency, you could easily lose some evidence of due diligence. By the same token, if too many checklists are in place, then certification could risk becoming a series of hoops to jump through for reasons that may be lost on the parties involved.

How then is balance best achieved? When many and diverse stakeholders have a voice in enforcing and updating the standard. This is another benefit of attending the ICCC conference.

atsec is invested in seeing the CC thrive and remain a vital part of the security industry, and will continue to attend these conferences and do our part to help raise security awareness, contribute to meaningful updates of the CC, and be a part of the CC community to strengthen and empower all of its constituents.

You can find atsec’s presentations from the ICCC on our website.