Why Hiring CCSPs Will Help the C-Suite Sleep at Night

A few short years ago, cloud computing was considered a relatively new concept inherent with risks that many IT professionals weren’t comfortable taking. I’ll avoid the debate about who coined the term cloud computing, but I’m old enough to remember how we formerly referenced the cloud in telecommunications as a way to simplify and abstract the details of the external network that’s connected to internal devices. Today, the concept of cloud computing is intended to simplify communication by eliminating the need to know all of the specifics of the cloud provider’s underlying software and infrastructure. The cloud provides benefits to businesses and consumers alike by offering consolidated services, quicker delivery time and decreased costs.

As we look toward the future of IT, cloud computing hovers over us at the forefront. Adoption rates are soaring, and cloud computing must integrate with in-house IT infrastructure and data assets. According to nearly 14,000 respondents from the 2015 (ISC)² Global Information Security Workforce Study (GISWS) by Frost & Sullivan, 43 percent state that cloud is a priority for their organizations and 57 percent of total respondents state it will become even more of a priority over the next two years.

Though it may be obvious to some, the growing adoption of cloud services will increase the demand for security professionals who can apply the proper controls to public, private, community and hybrid cloud models. Cloud computing was identified as the top area of information security with growing demand for education and training within the next three years, according to the (ISC)² GISWS. IT professionals who understand how cloud services can be securely implemented and managed within their organization’s IT strategy and governance requirements are essential. In fact, 73 percent of GISWS respondents believe leveraging cloud-based solution and services will require information security professionals to develop new skills.

(ISC)² and the Cloud Security Alliance (CSA) teamed up in an effort to address the need to establish a common global understanding of professional knowledge and best practices in design, implementation, management and service orchestration of cloud computing systems. CSA’s Certificate of Cloud Security Knowledge (CCSK) provides a very solid baseline of cloud security. Working together, (ISC)² and CSA developed a cloud security credential for those requiring a deeper understanding and demonstrated experience. The Certified Cloud Security Professional (CCSPSM) validates that professionals have met the highest standard for cloud security expertise. The combined initiative addresses the expanded information security complexities as organizations begin to leverage cloud-based infrastructure, software and services more frequently.

So why should organizations take note? With breaches rife and the C-suite increasingly aware of the implications of inadequate security, hiring CCSPs will help the C-suite sleep at night. Companies will benefit from employing CCSPs because they possess the knowledge, skills and abilities needed to address the security and business issues associated with the complexities of cloud computing. CCSP is vendor-neutral and requires practical knowledge and skills covering a broad set of cloud security capabilities necessary for cloud professionals to effectively carry-out their responsibilities and contributes to the overall security of their cloud environment.

Those in the C-suite at organizations who have decided to take advantage of recurring savings related to leveraging cloud solutions and services should consider what a modest investment in staff training and certification could mean for near-term and long-term success in relation to recurring operating cost savings, while ensuring cloud security best practices. Cloud security should be more of a science than an art. Leveraging the cloud should be predictable and repeatable, versus becoming an area of self-expression across an organization’s business units.

Had I been able to employ CCSPs during my early cloud implementation days, I know I certainly would’ve slept easier at night. For more information about CCSP, please visit https://www.isc2.org/ccsp/default.aspx.
-David Shearer, CISSP, PMP, CEO, (ISC)²

Palo Alto Networks Traps Protects From Latest Flash Zero-Day Vulnerability CVE-2015-5119

Following this week’s headline-grabbing breach, we all learned of an exploit utilizing CVE-2015-5119, a zero-day vulnerability in Adobe Flash. Successful exploitation of this vulnerability allows an attacker to take control of an affected endpoint, making it a critical threat. Various security researchers have since reported that the zero-day was indeed exploited in active attacks.

CVE-2015-5119 can be exploited against all commonly used browsers, including Google Chrome, which is considered to be much harder to exploit relative to other browsers.

This disclosure provides us a rare glimpse into the advanced attack tools market. From my perspective, the critical lesson to take from this incident is not the specific zero-day vulnerability itself, but the acknowledgment that this is merely the tip of the iceberg. One live zero-day exploit was disclosed by chance, but many others are and will be developed, marketed and utilized worldwide.

CVE-2015-5119 is part of an increasing trend of exploiting Flash vulnerabilities. Earlier this year we have referred in this blog to zero days CVE-2015-0311 and CVE-2015-0313, as well as a deep technical analysis of a new Flash vulnerability exploitation. Most recently  was the CVE-2015-3113 zero-day, disclosed a week ago. Additional patched Flash vulnerabilities were rapidly reversed by attackers and integrated in the leading exploit kits.

To counter trends like these, the endpoint security paradigm must shift towards a proactive approach, capable of preventing known and zero day exploits. Palo Alto Networks Traps prevents memory corruption exploits in real time, obstructing the core techniques used in exploitation without needing to rely on any prior knowledge of attacks. Traps successfully prevented exploitation zero-day CVE-2015-5119, and users of Traps as part of the Palo Alto Networks Security Platform were already protected from exploitation of these vulnerabilities prior to the disclosure and patch.

Exploits are the default attack vector in the current threat landscape. Traps is the only solution that provides proactive protection from this vector.

Read more about Traps advanced endpoint protection here.

[Palo Alto Networks Blog]

If You’re Trying To Find a Needle In A Haystack, Use A Metal Detector!

I don’t usually blog about specific product features, but I’m so excited about our new correlation objects, released in our 7.0 update to PAN-OS, that I really can’t help myself. It’s been a month now since we released 7.0, and I’m still particularly jazzed about this new feature!

Correlation objects, available in our PA-5000 Series, PA-3000 Series, the PA-7050, andPanorama, accurately identify infected devices based on patterns of network behavior that are correlated to characteristics of specific threats. So, for example, if a device is infected, the correlation engine can identify a pattern of a behavior: a host having visited a malware URL, then a vulnerability being exploited, and then abnormal DNS requests generated from said host.

Maybe a user took a corporate laptop home and inadvertently picked up some known malware (looks like GlobalProtect wasn’t activated!). When this user reconnects to the network, the correlation object correlates suspicious activities stemming from that device, which may not be of any concern individually, but taken together, alert the security team that this laptop needs to be remediated.

Meanwhile, the infection is stopped from spreading because Threat Prevention IPS, AV, and anti-spyware protections have blocked the malware from moving laterally inside the network and ended its outbound command and control beacons.

What’s really cool about this, though, is how it works with WildFire to dynamically correlate network activities based on zero-day malware.

Take the same concept of looking for patterns of abnormal behavior that point to infection, and from there, factor in zero-day malware that WildFire discovers. As soon as WildFire analyzes new file behavior, which only takes a few minutes for completely unknown files, a report on the file’s malicious behavior is sent back to the security platform. Our correlation engine consumes that report and looks for patterns of behavior specific to the newly discovered malicious file across the device from which it originated and other devices in the network, both going forward (analyzing in real time) and looking back through logs from 96 hours before the file was forwarded to WildFire.

At Palo Alto Networks, we believe that prevention isn’t futile – in fact, it’s central to stopping breaches. However, quick mitigation is also important to limit the damage and learn from threats that get past your defenses. With the right ecosystem of detection, intelligence, and prevention, infection doesn’t have to turn into a catastrophe.

There are currently five correlation objects available: three static objects that were created from Unit 42 research and two that are dynamically fed information from WildFire submissions. These five correlation objects are just the beginning. Our threat research teams, including Unit 42, will eventually be able to create new correlation objects based on their ongoing research into new attack campaigns and deliver them to deployed platforms through weekly content updates.

To learn more about the automated correlation engine and correlation objects, please visithttps://www.paloaltonetworks.com/products/features/correlation-engine.html.

[Palo Alto Networks Blog]

Using COBIT 5 to Audit Knowledge Management

As an African proverb reminds us, “Knowledge is the only treasure you can give entirely without running short of it.” Knowledge is recognized as the most important strategic asset for every organization. According to the Journal of Knowledge and Process Management, knowledge management is a holistic process that optimizes intellectual capital to achieve organizational objectives by leveraging information and expertise. The main purpose of knowledge management practice is to mitigate the possible loss of extensive tacit and explicit knowledge due to loss of employees.

Knowledge management practices enhance the capability of an organisation to identify, capture or acquire, share, reuse and internalization of knowledge. Audits of knowledge management practices are rarely undertaken by audit functions, and this gap has been identified as one of the contributing factors in knowledge management initiatives.

COBIT 5 introduced a new defined process—BAI08:Manage Knowledge process. This process fits well in one of COBIT 5’s information technology goals: “ knowledge, expertise and initiatives for business innovation.” The process provides guidelines on how to facilitate information system knowledge management within an IT organisation. For a detailed look at it, download ISACA’s BAI08 Manage Knowledge Audit Assurance Program.

What is knowledge management audit?
In an article from The Hong Kong Polytechnic University, “Re-Thinking knowledge audit: its values and limitations in the evaluation of organizational and cultural asset ,” knowledge management audit is defined as the systematic investigation, examination, verification, measurement and evaluation of explicit and tacit knowledge resources and assets, in order to determine how efficiently and effectively they are used and leveraged by the organisation . A knowledge management audit provides an opportunity to understand the current state of the knowledge management capability of an organization and a direction of where and how to improve the capability to provide the knowledge for quality decision making and enhanced productivity.

Planning for knowledge management audits for IT function
Before planning to undertake knowledge management audits, professionals should understand the knowledge management landscape within the entire organisation, and not just the IT function. It goes without saying that understanding the bigger picture of the organisation is critical in planning IT knowledge management audits. Noted in the Journal of Knowledge and Process Management, the knowledge management landscape of any organisation will involve people culture, processes, structures and technology that support its initiatives. The following knowledge management elements should be reviewed at the audit planning stage.

Knowledge Management (KM) Elements Why review this document at planning stage
Knowledge management strategy The document provides the long-term vision and objectives of the organisation as far as knowledge management is concerned. KM elements like KM structure, resources, projects, roles and responsibilities and roadmaps will be highlighted in this document.
Knowledge management policy To understand the high-level management commitment and support for knowledge management within the organisation
Interview those responsible for knowledge management (Knowledge Management Officers) To understand current knowledge management initiatives, structures and challenges within the organisation
Walk through existing collaborative tools (intranet, online community of practice, knowledge- sharing platforms, document management systems, etc.) To understand the available collaborative tools used across the organisation for knowledge management
Preliminary social network analysis to map the major information flows within an organisation To understand knowledge flow within the organisation. This aids the auditor to identify the key nodes of knowledge creation, sharing, reuse and storage.

Audit Reporting
Knowledge management audit reports should provide the following outputs: an assessment of current levels of knowledge management practice and knowledge sharing; identification and analysis of knowledge management opportunities that have not been explored; isolation of potential problems and existing gaps; and an evaluation of the perceived value of knowledge management within the IT organisation. The report should highlight the existing knowledge management gaps and offer recommendations on four key perspectives: people culture, processes, structures and technology.

By auditing knowledge management processes, you will be able to identify gaps in an organization’s knowledge management practices and activities, build from what is working, and identify areas that require improvement. The outcome should be a blueprint for moving forward in developing organizational knowledge management best practices.

John Masika
IS Audit Manager at Kenya Airways Ltd

[ISACA]

Use “Tap Mode” To See ICS/SCADA Traffic and Risks More Clearly

A firewall by any other name…

I often speak with ICS asset owners who are just at the beginning of their next-generation firewall learning curve.  They are usually pleasantly surprised at the capabilities it provides in identifying traffic at Layer 7, i.e. application, users and threat/content.

Beyond just being able to see network traffic at this very detailed level, the fact that these key pieces of information are intrinsically correlated — a unique advantage of our single-pass, parallel processing architecture (SP3) — is a major draw.  The proverbial “light bulb” turns on very quickly and they understand why this approach means easier anomaly detection, faster forensics and better auditability in their ICS environment.

Understandably, the word “firewall” in the product name often invokes the question of whether the device can be used in a more passive, detection-only model.  To support such monitor-only deployments, the Palo Alto Networks Next-Generation Firewall offers a deployment mode called “Tap Mode.”  Using this deployment, the next generation firewall can be connected to a SPAN/mirror port on a network device, like a switch or router, to passively monitor the traffic going through this “hub.” Doing this provides not only better visibility, but more importantly, correlated visibility into useful pieces of network traffic information.

Why “monitor-only”?

Why not deploy the device inline as a firewall is meant to be deployed?  A common reason in ICS is that the owner has a monitor-only mindset or policy for critical areas of the ICS.  Consider, for example, the core of a Distributed Control System (DCS) where there may be zero tolerance for any potential accidental blocking of traffic.  They want to avoid any additional inline devices aside from the main equipment needed to run the process and provide connectivity.  While this organization may put a security device inline at the IT-OT perimeter, they would never do so within the DCS core.  However, a non-invasive visibility tool could prove useful and hence could be considered for deployment.

Another reason for putting the device in passive mode, even at the perimeter of the ICS, such as between corporate and the PCN (process control network), is because the asset owner is not quite ready to do a rip-and-replace of his existing security architecture.  While the asset owner may admit that the existing system will need to be replaced eventually due to lagging capabilities, he still prefers a more gradual migration path that feels less disruptive.  A device that can be easily dropped in with minimal impact to the current production system, while providing high value, is ideal.  Eventually the owner may swap out the old with the new as he validates the new product and gets more comfortable with the technology.

Shedding the light on plant floor traffic

Users of Palo Alto Networks next-generation firewalls now have access to a variety of rich and natively correlated network traffic information including the following:

  • ICS Protocols and Applications – For example to Modbus, DNP3, OPC, ICCP, OsiSoft Pi, Schneider OASyS, Cygnet, etc. For some protocols, the visibility is provided at the function code level (i.e. Modbus Reads and Writes)
  • Business/Administrative Applications – Database applications like MSSQL, Remote management, Network management,
  • SaaS & Social Media – Applications which typically should not be allowed in ICS environments but are sometimes found, e.g. Dropbox, P2P file sharing, TeamViewer due to irresponsible use by employees
  • Custom Traffic – Custom “App-IDs” can be easily created using the firewall itself to identify homegrown applications.
  • User / User Group – The next-generation firewall can utilize different sources of IP-to-user mappings and events to enable user and user-group visibility. These include directory services, authentication events, and even via the API.  The user-information will be tied to the application/protocol traffic thereby providing user-based access logs.
  • Content – The firewall can be used to identify files, strings, URLs.
  • Known Threats – Network-borne known exploits, malware, and command and control traffic. Again threat information is contextually tied to application/protocol and user information.
  • Zero-day Malware – If the firewall is connected to the Wildfire service, the device can also be used to identify zero-day malware in as little as 5 minutes for the on-premises Wildfire offering.

Several areas where users are typically interested in gaining more situational awareness and capabilities for auditing traffic include:

  • ICS core – Monitor traffic off of a switch interconnecting the HMIs, workstations and automation servers on the plant floor. This should mostly be repetitive machine-to-machine traffic so anything out of the ordinary is likely to jump out.
  • IT-OT perimeter – Use the Next-generation firewall to augment any existing access control device like a Router (ACL) or stateful inspection firewall (limited visibility at the port and IP address level)
  • 3rd party connections – Similar to the IT-OT perimeter, make sure to monitor the connectivity you have with third parties like partners and ICS vendors and systems integrators

Moving beyond monitor-only

In practice, many users start off in tap mode then eventually move into one of two inline deployments modes (VWIRE “bump-in-the-wire”, L2/L3 Firewall Replacement), realizing the powerful network segmentation capabilities of the device.  In other scenarios they may deploy the devices in a hybrid model where  some areas the firewall is inline with access controls and in some areas the device is in tap mode.

Not all organizations have the same network architecture or the same view on security posture.  Our next-generation firewall’s support for multiple deployment modes highlights one of the ways our platform provides flexibility.  In fact the multiple ports on a Palo Alto Networks firewall could be configured to support multiple deployment modes simultaneously (Tap, VWIRE, and L2/L3).

Practicing What We Preach – Application Visibility and Risk Report

Interestingly enough, Palo Alto Network field teams often use the firewall in tap mode when conducting free Application Visibility and Risk (AVR) assessments.  We basically connect the device in passive mode to the network cluster of interest then provide a report back to the end user on what applications and risks may be present in their network today.

It’s rare to have an AVR which does not result in immediately useful information regarding security risks. It is free and is an easy way to understand the value of correlated, layer-7 visibility and also perhaps to discover any exposures to your organization.  Contact your local Palo Alto Networks representative to learn more or sign up for an AVR online.

To learn more about our platform approach to securing industrial control systems, please access the free white paper on 21st century SCADA security.

[Palo Alto Networks Blog]

English
Exit mobile version