LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-20-2008, 10:20 AM   #1
the_gripmaster
Member
 
Registered: Jul 2004
Location: VIC, Australia
Distribution: RHEL, CentOS, Ubuntu Server, Ubuntu
Posts: 364

Rep: Reputation: 38
Question Career in Internet/Network Security


(I am not sure if this is most appropriate place to post this silly(?) question, please bear with me.)

If someone wants to pursue a career in Internet/Network Security (tiger team), what fields should he/she concentrate on?

Is it absolutely essential for him/her to have detailed knowledge of Cisco stuff (like the Cisco IOS)?

Thanks.
 
Old 06-20-2008, 10:48 AM   #2
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
There was a show called "Tiger Team" that only had two episodes. They had people who specialize in various areas. Someone who was good social engineering people, someone who was an expert in physical security devices, and someone who was an expert at technical hacking.

A lot of businesses don't have as secure of a network infrastructure as they probably should. Also, security researchers are targeting Cisco equipment such as routers more now by developing exploits to run arbitrary code, and creating proof of concept rootkits for IOS. So I would think it's going to become more important over time, and being familiar with Cisco would help if you want to become a technical hacker.
 
Old 06-20-2008, 10:58 AM   #3
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
I wouldn't narrow it down to just Cisco gear though, you should have general knowledge of Networking fundamentals, along with OS knowledge. There are certification tracks like Security+, Network+ and so on you can take.

Also you should keep up with security vulnerabilities and exploits. Good security practices and learn the other many ways people gain access to environments outside of computers as well. Security isn't limited to just computers.
 
Old 06-20-2008, 12:10 PM   #4
alan_ri
Senior Member
 
Registered: Dec 2007
Location: Croatia
Distribution: Debian GNU/Linux
Posts: 1,733
Blog Entries: 5

Rep: Reputation: 127Reputation: 127
Quote:
Originally Posted by trickykid View Post
and learn the other many ways people gain access to environments outside of computers as well. Security isn't limited to just computers.
Maybe he should buy a gun... .
 
Old 06-20-2008, 12:40 PM   #5
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Quote:
Originally Posted by alan_ri View Post
Maybe he should buy a gun... .
Nah, that just gives the other people a reason to shoot back!
 
Old 06-20-2008, 03:10 PM   #6
the_gripmaster
Member
 
Registered: Jul 2004
Location: VIC, Australia
Distribution: RHEL, CentOS, Ubuntu Server, Ubuntu
Posts: 364

Original Poster
Rep: Reputation: 38
Quote:
Originally Posted by alan_ri View Post
Maybe he should buy a gun... .
?
 
Old 06-21-2008, 05:08 AM   #7
alan_ri
Senior Member
 
Registered: Dec 2007
Location: Croatia
Distribution: Debian GNU/Linux
Posts: 1,733
Blog Entries: 5

Rep: Reputation: 127Reputation: 127
I'm just kidding,gripmaster.
 
Old 06-27-2008, 02:18 AM   #8
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
First off, security is not nearly as glamorous as it appears in hacker movies and security vulnerability mailing lists. A whole lot of it is about boring audits, controls, and processes. You have to be extremely detail-oriented and process-driven to work in the security field, just a warning...

From a practical standpoint, research the Common Body of Knowledge. It's used for the CISSP certification. There are tons of books and websites that have study material. Note that I'm not necessarily recommending you try to achieve the certification, but the study material for it is very useful. It covers things like business continuity planning, incident response, physical security, cryptography, etc... Note that the most important things you'll learn about security are the processes and methodologies. Being able to configure a firewall is great, but being able to quantify in dollar value what a particular firewall is worth to your company is even better.

Take some time to study programming/software development security practices. It's important to know what sort of things to keep in mind when developing software and how to be security-conscious. If you don't understand how applications become vulnerable, you won't be able to understand how attackers are exploiting them. One of the biggest things you'll learn in that process is to write human-readable code with plenty of documentation. Most security vulnerabilities occur when technology is poorly understood, or misinterpreted. The more/better you document things, the less chance for error.

There are so many different security applications, and the market is changing so quickly, that there isn't really any point in learning any one product or area right now. Just concentrate on the principles and you'll be able to pickup the specifics as you go along.

Oh yeah, and the #1 thing to understand: The "most secure" thing is almost never the "right thing" to do from an employer's standpoint. Why? Because it prevents work from getting done, which prevents them from making money. You'll need to accept the fact that you often have to compromise on "ideal" security to get something that is acceptable to the business. There's no point in complaining about it, that will just get you labeled as a trouble-maker. Instead, try to understand what your company does to make money and think of ways that security can cooperate with that and make it easier as well as safer. Then you'll be a hero instead of an outcast.
 
Old 07-13-2008, 01:51 PM   #9
shroomy_bee
Member
 
Registered: Feb 2008
Posts: 36

Rep: Reputation: 15
Right but you need to actually be employed in the company to begin with in order to do any of that.
 
Old 07-13-2008, 02:47 PM   #10
custangro
Senior Member
 
Registered: Nov 2006
Location: California
Distribution: Fedora , CentOS , RHEL
Posts: 1,979
Blog Entries: 1

Rep: Reputation: 209Reputation: 209Reputation: 209
Quote:
Originally Posted by chort View Post
Oh yeah, and the #1 thing to understand: The "most secure" thing is almost never the "right thing" to do from an employer's standpoint. Why? Because it prevents work from getting done, which prevents them from making money. You'll need to accept the fact that you often have to compromise on "ideal" security to get something that is acceptable to the business. There's no point in complaining about it, that will just get you labeled as a trouble-maker. Instead, try to understand what your company does to make money and think of ways that security can cooperate with that and make it easier as well as safer. Then you'll be a hero instead of an outcast.
I know this all to well...There are a lot of things that I wish I could implement...but it just won't allow work to happen...

-C
 
Old 07-13-2008, 05:59 PM   #11
simonapnic
Member
 
Registered: Jul 2008
Posts: 70

Rep: Reputation: 16
Post

If you want a career in Internet/Network security, you must be an expert in these fields.
Here's an useful site for you:
http://www.penetration-testing.com/
The Open Source methodology knowledge is required in order to get a job at most companies.
 
Old 07-14-2008, 04:30 PM   #12
shroomy_bee
Member
 
Registered: Feb 2008
Posts: 36

Rep: Reputation: 15
This might be useful for you, it lists & describes a lot of different job specialisation areas in security:

http://www.networkintrusion.co.uk/Recjobs.htm
 
Old 07-15-2008, 08:04 AM   #13
dguitar
Member
 
Registered: Jun 2005
Location: Portland, ME
Distribution: Slackware 13, CentOS 5.3, FBSD 7.2, OBSD 4.6, Fedora 11
Posts: 122

Rep: Reputation: 17
Quote:
Originally Posted by simonapnic View Post
The Open Source methodology knowledge is required in order to get a job at most companies.
Really? A lot of the major corporations in the US could care less about Open Source Methodology. (Not saying you shouldn't, just saying that required isn't really true... )
 
Old 07-15-2008, 12:22 PM   #14
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by dguitar View Post
Really? A lot of the major corporations in the US could care less about Open Source Methodology. (Not saying you shouldn't, just saying that required isn't really true... )
Gonna have to agree with this one.
 
Old 07-17-2008, 10:52 PM   #15
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally Posted by simonapnic View Post
The Open Source methodology knowledge is required in order to get a job at most companies.
Not all all. The last 4 companies I've worked at have made extensive use of Open Source software, but none of them made source code available to the public and some of them spent quite a bit of time with lawyers making sure they could keep all their stuff secret.

Most companies don't give a damn about "Open Source methodology", they only care about "software that we don't have to pay huge license fees for", so they can in turn make higher profit margins when they turn around and sell it to someone else.

Even companies like IBM that seemingly "contribute" a lot to Open Source projects are only doing it out of greed: Investing a little bit in community projects is much cheaper than employing an army of employees to build the same thing. They can devote only a few employees to making just the changes they want, while the rest of the community maintains all the necessary, but very mundane features that IBM doesn't care that much about.

Don't buy into the gibberish that RMS spews. GNU isn't making any headway in the corporate world--free software is.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Security clue_less Linux - Newbie 2 05-03-2007 09:17 AM
Internet security subodh Linux - Security 1 04-25-2007 01:43 PM
Internet Security? hopesfall Linux - Newbie 3 08-05-2005 02:07 AM
Internet/security Software Andy@DP Linux - Software 3 04-12-2004 05:39 PM
Career in Internet Security Kalyani Linux - Security 3 06-26-2001 09:06 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration