Showing posts with label types. Show all posts
Showing posts with label types. Show all posts

DECONTAMINATION

The National Research Council (NRC 1999) defines decontamination as the process of removing or neutralizing a hazard from the environment, property, or life form. However, no consensus nationally or among agencies has been reached on standard operating definitions of decontamination, and existing procedures may contradict best healthcare practices for protecting potentially exposed victims as well as healthcare providers.

For decontamination to be effective, the following three elements must be in place:

  1. The contaminants are correctly identified.

  2. The procedures and equipment are available and properly employed to neutralize (or remove) the contaminant.

  3. The reduction of risk is defensible by scientific or regulatory standards (which is not always possible).

Furthermore, most current decontamination systems are labor intensive and require excessive quantities of water. As Macintyre et al. (2000) note, most decontamination guidelines for treatment of exposed victims were created following military models and are inappropriate in today’s civilian healthcare settings.

This discussion is not intended as an all-inclusive treatment on decontamination dos and don’ts but is meant to alert managers to the potential difficulties and pitfalls in planning procedures for decontaminating victims exposed to hazardous substances.

Types of Decontamination

To protect the healthcare facility, it is important to understand where and how (or if) decontamination is performed outside the medical facility, because the problems associated with decontamination of victims (including secondary contamination) in the ED can often be attributed directly to those factors. The degree to which a patient is decontaminated in the prehospital setting depends on the medical decontamination plan, available resources and medically trained personnel, the weather, and characteristics of the contaminant.

General protocols suggest that patients exposed to a hazardous chemical or biological substance should receive, at a minimum, gross decontamination before transport and treatment. Gross decontamination involves showering clothed patients with copious amounts of water, often conducted by a HAZMAT team with a fire hose or by having victims move through a HAZMAT decon tent or other treatment facility. Patients requiring additional medical attention, antidotes, or other emergency care should receive that care depending on the substance’s effects and the ability of staff to protect themselves during treatment. For some situations, such as a patient exposed to a radiological or nonvolatile chemical substance, use of barrier nursing clothing is ample protection. However, if the chemical is highly volatile or persistent, staff should never attempt care or bring potentially contaminated patients into the hospital without appropriate respiratory protection. This includes admitting patients to ED waiting areas where the possibility of secondary contamination could shut down operations.

Hazardous-materials teams traditionally handle decontamination of the environment and persons exposed to hazardous substances, generally relying on a conservative model that advocates precautionary decontamination of potentially exposed victims. The HAZMAT definition of medical decon or patient decon is what most healthcare providers would consider gross decontamination. The procedures, however, are not much different from those proscribed in hospital settings. The first step is removal and disposal (i.e., bagging and sealing) of patients’ clothing and personal belongings. (Cox [1994] estimates that this simple process removes 70 percent to 80 percent of the contaminant, but little scientific data support that assertion.) Victims are then given a quick overall rinse with water.

Secondary decontamination involves washing rapidly with a decontamination solution—usually a diluted bleach or soap and water—and rinsing again. At this point, victims can be dried, given clean clothes, and sent home or transported to a medical facility. The degree of proficiency will vary depending on equipment, resources, and training. One problem is providing privacy to victims, as not all HAZMAT teams are equipped with individual decontamination units or trailers.

Alternatively, mass decontamination processes victims in one or more groups. Chemical warfare agents can cause large numbers of casualties if dispersed in a vapor or aerosol, as manifested in the sarin incident in the Tokyo subway. Such a situation could also occur in a high-profile event at a stadium, a concert, or an airport. The process requires cordoning off several exits where a decontamination corridor can be set up with fire department aerials and/or deluge guns in close proximity. The nozzles are set at low volume so as not to inflict damage but to maximize the amount of water to which each victim is exposed. Ambulatory victims progress through the deluge so that they may be grossly decontaminated. In conjunction with removal of clothing, this will likely suffice to decontaminate those victims not exhibiting signs or symptoms of chemical agent exposure.

A second method is to set up a sprinkler head near the exit point as a rudimentary decontamination shower. In this scenario, water delivered at 500 gallons per minute will produce 8 gallons per second. If the victim remains in the shower for 3 seconds on average, he or she is exposed to 12 gallons, or the amount used in a normal shower.

In either scenario some clothing is left on, which reduces the effectiveness if vapor has penetrated to the skin. Also at issue is the runoff of wastewater with possible contaminants, the disposal of which must comply with local or state environmental regulations.

Self- and buddy-decontamination techniques can also be employed by first responders, workers in hazardous situations, and groups trained in self-help for emergencies. Such techniques may be needed in situations in which immediate removal of contaminants is essential and no time is available to set up a decontamination operation.

Water temperature is a comfort issue that can affect the time spent showering. Normal fire hydrant water temperature is 55 to 65 degrees Fahrenheit. Discomfort during showering is a particular issue with children and the elderly who may suffer additional distress, especially if the ambient air temperature is much cooler or the weather is windy and cloudy. The outside decontamination process is more traumatic than that conducted in an enclosed environment, especially if victims feel a lack of privacy during the process.

Common Types of Unlawful Acts

In many cases, computer crimes do not involve attacks in the popular sense. Most administrators tend to think of system attacks originating with someone gaining access to a system by breaching outside fortifications. The truth of the matter is that most successful attacks are "inside jobs." The exact numbers depend on the survey or data, but they all state that the most successful and devastating attacks originate within the target organization. Employees, contractors, and former employees use their knowledge of the employer's systems to gain unauthorized access and wreak havoc. Often these acts include theft or denial-of-service attacks, destruction or modification of sensitive data, trafficking in software piracy, and theft of trade secrets and intellectual property. Following is a list of terms with which you should be familiar:

Espionage
Collection and analysis of illicitly obtained information.

Trade secret
Plan, concept, prototype, information, or property that has value by providing a business advantage over competitors who do not have the secret.

Corporate espionage
Theft of trade secrets for economic gain.

Intellectual property
Any product of the human intellect that is unique or novel, having some value in the marketplace. Patent, copyright, trademark, service mark, or trade secret protects intellectual property.

Cyber terrorism
Unlawful use of force against persons or property to intimidate a government or a civilian population in furtherance of political or social objectives. Acts of terrorism usually have the goal of disrupting the public's faith in their institutions.

Economic espionage
Illicit collection of information, sponsored by a foreign government for economic advantage.

Types of Malicious Code Attacks

As a matter of course, investigators are tasked to address rogue code attacks. Handling such an attack presents challenges in terms of priorities. For example, certain types of attacks spread very quickly affecting computers on networks in large numbers. The Morris Internet Worm was one such attack.

There are many demands placed on the responders once they are aware of a potential critical incident. The clear first priority is isolating the attack. Infected computers must be isolated from the surrounding system to prevent the infecting code from spreading to other systems. With this done, responders should ask themselves if it is important to determine the origins of the infection, or not. If the network and its connecting systems are cleansed of the rogue code, the evidence of its origin may be erased; however, if the systems containing the code are isolated, they remain inoperable until the investigation is completed, negatively affecting productivity.

Viruses

In a virus attack, it is very likely the virus has infected many systems. The responder's likely priority is isolating the infected machines, clean them, and return them to their users. In these cases, analyzing the virus and its origins is secondary. Tracing the virus is difficult, if not impossible in a large system, but there are some considerations that can be made:

  • Make a forensically sound copy of one of the infected hard drives.

  • Treat the hard drive as if it were evidence and a crime scene in its own right.

  • Make a second forensic copy of the drive and use it as a work copy for future analysis.

  • If the first infected computer in the system can be identified by timestamp analysis, it may be possible to identify the origin of the infestation.


Experience Note

It is extremely difficult to identify the person who introduced a virus into a network. Anti-virus software must be constantly updated and users trained not to open e-mail attachments. Usually the best that can be done is to isolate the systems, cleanse them, return the systems to the production environment, and train users.

Trojan Horses and Logic Bombs

In many regards, these examples of malware code are easier to handle than viruses because they are usually confined to one machine. The problem is that they might remain dormant or unused on that machine until a triggering event takes place. Triggering events are items such as calendar dates, keystrokes made in a specific order, or the execution of program code. Once the triggering event takes place, the user discovers the malicious code and administrators take appropriate restoration steps. With the malicious code running, it's going to be fairly obvious where it is located. For example, if there is a logic bomb planted in a billing program, it is possible that users will know it when they try to execute the application and it does its damage.

With the execution of a logic bomb, the damage is done. Depending on the extent of possible legal action, the best solution is to cleanse the victim system and reinstall the software with clean backed-up data. It is possible that evidence could be collected, timestamps compared, and an attacker identified. Conducting such an investigation can be very time-consuming and resource intensive; consequently, it must be determined if it is worth the effort or not.

In the event of a suspected logic bomb hidden in an application, there are some specific steps that can be taken to prevent it from executing and doing its damage. It is important that a forensically sound copy of the suspected drive is made and preserved as evidence. Copy the evidence drive for performing all analyses and return a clean drive to the original system. The best way to locate the malicious code is to compare the victim system, where the malicious code is resident, with a clean backup copy. Investigators should review the date of the last change in the target media and compare it to the date of the last change for the same file in the backup copy. Continue to compare backups as far as is practical and compare dates. If there is a timestamp date change that cannot be explained or is not documented, the altered file is probably the guilty one.

If the investigators can gain visibility into the programmer's code (this may or may not be possible) there are editors that will automate the line by line comparison revealing any changes.

In the event of suspected malicious code, here are a few types of event logging that will help:

  • Login and logoff

  • File deletion

  • Privilege changes

  • Access by all root

  • Failed login attempts

  • Unused or dormant account access

  • SU (Switch User) activity in UNIX-based systems

  • System reboots

  • Remote access of target system

  • New user accounts

Things to Do after a Malicious Code Attack

If a system has been the victim of a malicious code attack or denial-of-service attack, either as a result of outside or inside activity, here are a few suggested measures:

  • Contain the potential problem. The most efficient way to accomplish this is to simply remove the Ethernet cable from the NIC card, or isolate the affected systems from the rest of the network by some other means. If this cannot be accomplished, disable the power to the target machine. If you do not disconnect the target machine from the network, infections or attackers will cause havoc because they will continue to have access to the system.


    Experience Note

    Managers should not be lulled into the idea that attackers having penetrated a system will not return. Once in, they will continuously attempt to intrude or deny service.

  • Preserve the target media as evidence. This probably will mean making a forensic copy of the target drive and preserving it for evidence.

  • Cleanse the original drive and return it to service. Make forensic copies of media containing the malicious code and preserve them as evidence. This will preserve the timestamp dates of infection. Cleansing media may consist of media degaussing, reformatting the drive, or launching a forensic erasing tool where the entire drive is overwritten several times destroying the offending code.

  • A completely clean reinstallation will be more time consuming, but will ensure correct functionality rather than running the anti-virus software to delete or quarantine the offender.

Digital Bloodhounds

For matters that are going to be pursued to levels of litigation, it is important for investigators to discover the identities of those responsible for causing system damage. In many cases, civil and criminal legal processes can be, and should be, pursued on parallel tracks. It is not unusual for an individual to be criminally charged while the damaged parties file lawsuits to recover their losses. Considering all the different technologies that can be employed to conceal the attacker's identity such as anonymous e-mail re-mailers and compromised server accounts, it would seem attackers have a definite advantage over investigators.


Experience Note

The Director of Risk Management for a credit card company noted that there were chat rooms dedicated to trading and verifying credit card information. After engaging several of the chat room operators in conversations over the course of many weeks, it was discovered many of them resided in countries that had few, if any, laws making credit card fraud a criminal act. Further, it was discovered the subjects knew they were acting criminally and fully acknowledged they could not be extradited due to a lack of international treaties. Consequently, they knew they could steal credit card information, sell it, commit fraud with it, and not suffer any punishment.

IP Addresses

When investigators begin looking for evidence in an attacked a system, the most logical place to begin searching is the IP address. IP addresses create areas of difficulties when locating the offender.

It is possible, and indeed quite likely, that the source IP address is spoofed and not correctly resolved to the attacker.

It is possible, and indeed likely, that the source IP address used for an attack is many hops away from the actual origin of the attack. Experienced attackers will pass through multiple systems before actually launching an attack. It is very common for investigators to have to obtain information from the administrators of multiple systems in the attack-chain before arriving at the attacker's origin.


Experience Note

Much of IP tracing depends on the investigator's skill and luck. This is not to say it is not successful, but realistically it can be difficult and discouraging.

The IP address is assigned to an individual machine. It may be difficult to determine who was using a particular machine at a particular time in a shared environment like a school or library.

Hardware Firewall Architectures

Firewalls can be configured in many different hardware architectures providing various levels of security with different installation and operation costs. Organizations should match their risks to the type of firewall architecture selected. The following briefly describes firewall architectures.

Multiple-homed host. This is a firewall that has more than one network interface card, NIC. Each NIC is logically and physically connected to separate network segments. A dual-homed host, one with two NICs is the most common example of a multi-homed host. One NIC is connected to the external or untrusted network, like the Internet, and the other NIC is connected to the internal or trusted network. In this configuration, the key point is not to allow computer traffic to be passed from the untrusted network directly to the trusted network. The firewall acts as an intermediary

Screened hosts. Screened firewall architecture uses a host called a bastion host. It usually has two network interface cards, but may have several NICs, making it a multiple-homed device. All outside hosts connect to this device rather than allowing direct connection between inside and outside hosts. To achieve this character, a filtering router is configured in such a fashion as to remove all unnecessary services, thereby earning its name as a hardened host. If superfluous services and features are removed or disabled, they cannot be exploited to gain unauthorized access. In the bastion host, a filtering router is installed and configured so that all connection traffic from between the internal and external networks must pass through the bastion host. No direct internal-network-to-external-network connections are allowed.


Bastion hosts can be deployed to partition sub-networks from other interior networks; for example, an interior network handling company e-mail is partitioned by a bastion host from another interior network where employee records are kept. This architecture is known as a screened sub-network, and adds an extra layer of security by creating a separate but connected internal network or sub-network

Firewall Administration
Firewalls consisting of hardware, software, or appliances have to be the ongoing job of a responsible and senior employee. After all, this employee literally has the "keys to the kingdom." It is a wise business practice to have two firewall administrators, assuring continuity and institutional knowledge in the event of an absence

Firewall Administrators
For each duty-day, it is recommended that two experienced employees are available to address firewall issues. In this manner, the firewall administrator function is constantly covered. It is compulsory that these employees have a thorough understanding of network architectures, TCP/IP protocols, and security policies

Remote Firewall Administration

Firewalls are usually the first line and sometimes the last line of defense against attackers. By design, firewalls are supposed to be difficult to attack directly, causing attackers to attack the accounts on the firewall itself. Additionally, there should be no user accounts on the firewall host other than those of the administrators. User names and passwords must be strongly protected. One of the most common protections is strong physical security surrounding the firewall host and permitting firewall administration from one attached terminal. Only the primary and secondary firewall administrators should have physical access to the firewall host. Depending on the sensitivity of the data stored on the protected network, it is strongly recommended that firewall administrators are not allowed to remotely access firewalls. Depending on the business' operations, it may be prudent to have a firewall administrator on duty constantly. What degree of profit losses will be incurred if users are unable to access information assets because of firewall problems? Although having a firewall administrator on duty full-time, in the long run it provides increased integrity and availability for firewalls and the systems they protect

Internet Firewall Policy

Because the Internet is not trustworthy, an organization's system connected to the Internet is vulnerable to abuse and attack. Enabling a firewall between the organization's local area network and the Internet can go a long way to control access between trusted parties and less-trusted ones. A firewall is not a single component; rather it is a strategy for protecting an organization's Internet-reachable assets. Firewalls serve as gatekeepers between the untrustworthy Internet and the more-trusted organization networks.



The primary function of a firewall is to centralize system access controls. If remote users, authorized or not, can access the internal networks without traversing the firewalls, their effectiveness is diminished. If a traveling employee has the ability to connect to his office workstation, circumventing the organization's firewall architecture, then an attacker can do the same. Firewalls have the ability to allow network services to be passed or blocked; consequently, system administrators must consult with firewall administrators relative to which services are necessary for business operations. All unnecessary services must be disabled, denied, or blocked.

Firewalls provide several layers and types of protection:

- Firewalls can block unwanted traffic, essentially partitioning the inside network from the outside network.

- Firewall can direct incoming traffic to more trustworthy internal systems.

- Firewall can conceal vulnerable systems that cannot be secure from the Internet.

- Firewall can provide audit trails logging traffic to and from the organization's private networks and the Internet.

- Firewalls can conceal information such as system addresses, network devices, and user identification from the Internet.


Authentication

Firewalls located at the perimeter of the organization's network, interfacing between the Internet and the internal networks, do not provide user authentication. Host-based firewalls usually provide these types of user authentication:

User names and passwords. User names and unique passwords are compared against authorized user lists and verified by correct passwords. This is one of the least secure methods.

One-time passwords. One-time passwords using software or hardware tokens produce a new password for each user session. Old passwords cannot be reused if they were stolen, intercepted, or borrowed. This method is one where the user must know something and must possess something before gaining access.

Digital certificates. Digital certificates use a certificate generated using public key encryption from a trusted third party. This access method is one where the user must know something and have something.


Firewall Types
Packet-filtering firewalls are gateways located at network routers that have packet-screening abilities based on policy rules granting or denying access based on several factors:

Information packet source address. It is capable of denying system access from specific source addresses; for example, it is possible to deny outside entry of any information packet having a source address of a competing company.

Information packet destination address. It is capable of denying access to any internal workstation or host based on its IP address; for example, all traffic can be blocked attempting to connect to the client list file server.

Service port. Firewalls are capable of blocking or allowing access to specific services; for example, connection attempts to workstation TCP Port 139 are denied.


Packet-filtering firewalls offer minimum security but very low cost. They can be an appropriate choice for a low-risk network environment. However, there are some drawbacks:

- They do not protect against IP or DNS address spoofing.

- Attackers will have direct access to any host on the internal network once access has been granted by the firewall.

- Strong user authentication is not a feature supported with many packet-screening firewalls.

- They do not generally provide complete or useful logging features.


Application Firewalls
Application firewalls use server programs, called proxies, running on the firewall. These proxies arbitrate transactions between interior and exterior networks. They accept requests, examine them, and forward legitimate requests to internal hosts that provide appropriate service. Application firewalls generally support functions as user authentication and logging features. Application firewalls require that a proxy is configured for each applicable service such as FTP, HTTP, etc.

Application-level firewalls generally offer the solution of network address translation (NAT). This feature may be configured so that outbound traffic appears as if the traffic had originated from the firewall itself. In this fashion, all IP addresses of the hosts behind the firewall are protected from discovery in that once they depart the firewall outbound, they all have the same IP address.

- Application firewalls supporting proxies for different services prevent direct access to internal network services, protecting the business against insecure or poorly configured internal servers.

- Application firewalls generally offer strong user authentication.

- Application firewalls generally provide detailed logging of user activities.

Popular Posts