Preventing Cyber-War: CASP Guards Against Global Cybersecurity Threats

F-22 Raptor stealth fighters tore across the tranquil, picturesque desert sky of Hill Air Force Base in northern Utah as Patrick Lane, senior manager of product management at CompTIA, prepared to discuss high-level IT security with a conference room full of information assurance workers. He took in the sights, awed by the planes’ high-tech acrobatics; they flew at what seemed like impossibly slow speeds, then impossibly fast ones, banked and turned on a dime over the mountain-ringed valley abutting the Great Salt Lake. It was breathtaking, all the more so because of the danger involved. Hill Air Force Base is one of the few live-fire Air Force training ranges in the country.

But what brought Lane to Hill Air Force Base was a facet of national security more intangible than such impressive machines. Invited to speak on behalf of the Armed Forces Communications and Electronics Association, he was there to present on unauthorized network entry, newly evolving malware threats and the tools an advance IT pro can use to fight both.

Lane’s visit to Hill Air Force Base’s is but one of the steps he’s taken to increase the nation’s level of cybersecurity preparedness, a critical goal given disconcerting news about both the increasing sophistication of malware and its increasingly invasive uses. For Lane, there is only one solution to the growing problem – the CompTIA Advanced Security Practitioner (CASP) certification.

Lane said, “If [someone has] a CASP certification, they can be hired by a state – hopefully by the U.S. – to fight the fight that’s going on all around us.”

So what, exactly, is that fight? While there has been no out-and-out declaration of cyber-war by one state against another, there has nevertheless been a proliferation of hacking cases targeting both state and corporate enterprises suspected to have been ​executed by nation-state actors. The spate of point-of-sale malware attacks that plagued U.S. retail enterprises over the past few years seems to have, according to Lane, given way to espionage malware focused on gaining access to and harvesting intellectual property and state secrets.

Recent headlines reflect this. The hack of Sony’s email servers, which led to the theft and public release of private emails between Sony employees, celebrities and others, was eventually attributed to North Korea – though North Korea denies involvement. More recently, some have pointed the finger at China regarding a breach at the U.S. Office of Personnel Management (OPM) that resulted in the personal data of at least four million current, prospective and former federal employees – possibly up to 18 million people – being compromised. The attack appears to have been under way for a protracted period of time and the fallout from it remains to be seen.

The obvious similarity between these two attacks is the alleged involvement of state actors. But these attacks also both used a specific type of technology. The espionage malware used in both attacks represents a newer, more sophisticated form of cyber-attack known as an advanced persistent threat (APT). APTs are adept at infiltrating, then residing undetected on networks. They can hide themselves in the essential APIs of a system, quietly sending information back to a command-and-control server.

“Whereas it used to be [hackers would] walk up, break the window, walk in and leave, now it’s almost as if someone broke into your house and is waiting in the cabinet,” Lane said.

Lane sees hope, though, for the government wrapping its mind around this malware model. That’s where CASP comes in.

Unlike some other certifications, CASP is meant to assess – in addition to the knowledge of specific tools – experience. It tests the sort of deductions an IT professional with 10 years of overall IT experience or five years of security experience should be able to make.

“[CASP] is unique because we’re focusing on the people [who] are actually going to have to sit there and figure out the problem and try to fix it,” Lane said. “Our certification is built to assess workers [who] have a chance of defeating these attacks or at least scattering them.”

Lane is similarly confident that cyberattacks on government infrastructure, like what occurred with OPM, could be limited with widespread CASP certification.

“What you’re trying to defend against is the hacker’s ability to extract targeted information,” Lane said. “In theory, if you had a bunch of CASP guys there [in the case of OPM], they would have been using CASP ideas. They would have understood that users are the biggest problem as far as launching malware into networks. So you would hope that the attack would have been detected and stopped before the breach took place.”

The U.S. military sees the importance of having a certification that assesses an IT professional’s ability to identify and combat advanced persistent threats. CASP was developed at the request of the U.S. Navy and since then it has been adopted by the broader Department of Defense for Directive 8570.01-M.

The CompTIA advisory committee for CASP, which is constantly revising the requirements for the certification to make sure its skills assessment remains on the cutting edge, features some of the biggest names in technology, business and government. Target, RICOH, the U.S. Navy Center for Information Dominance and the U.S. Department of Veterans Affairs are only a few of the names on the list. These organizations contribute their hands-on cybersecurity expertise to the CASP exam.

And so, despite cyberattacks growing in target size and technical sophistication, according to Lane, it’s possible to stay ahead of these threats. If these attacks can be understood as acts of quiet aggression in a pervasive, decentralized cyber war, Lane believes that CASP will play a big role in making sure it’s a war we can win.

“To tell you the truth, the stuff that they’re doing isn’t difficult to stop, necessarily,” Lane said. “You just have to figure out what they’re doing.”

Matthew Stern is a freelance writer based in Chicago who covers information technology, retail and various other topics and industries.

[CompTIA]

Consumer IoT Security Impacts

Within the CSA Internet of Things (IoT) Working Group, we are researching various topics related to securing IoT implementations within an enterprise. One of the more interesting aspects to consider on this subject is the role that consumer IoT devices play in regards to enterprise security.

News of exploits against consumer IoT devices is common, and research into vulnerabilities related to poor development and configuration choices continues. Rapid7 recently published a significant research report on baby monitor exposure and vulnerabilities, which showed that many leading brands are still highly vulnerable. Download their report.

Another interesting aspect of consumer IoT security is the apparent inability to rely upon the consumer to safeguard the underlying network that IoT devices use to communicate. Consumers are often proponents of usability over security, and in the past some consumer IoT device makers have purposefully chosen to value usability over security. This is somewhat understandable, as most people would prefer not to have to configure unique security credentials for each IoT device that operates within their home. Of concern though is that adding new (non-secure) points of connection into the home provides an ability for malicious parties to gain access to other computing resources in the home – potentially leaving sensitive data such as passwords exposed. This is concerning for an enterprise security practitioner because many people choose to use the same passwords to protect both corporate and personal information and application access.

What’s interesting also is that consumer IoT devices do not always stay within the home. A report this year by OpenDNS provided a great deal of data that showed that IoT devices, or the associated applications installed on staff computers, were often found to be communicating with services over the internet from the Corporate network. In some cases, Smart TVs were brought into the enterprise, and these devices were pre-configured to talk with service addresses/ports on the internet. In other cases, fitness trackers were associated with applications that were loaded onto laptops or mobile phones, and then those applications began communication with the manufacturer through the corporate network. Read the OpenDNS report.

At this point, education is likely the best defense against the exposures that consumer IoT devices introduce to the enterprise. Security staff should be educated to identify when inappropriate devices and software is being used on the network, and all staff should be educated on the need to secure their connected home systems as part of a larger effort to keep data secure.

Join the CSA IoT Working Group.

By Brian Russell, Co-Chair, CSA IoT Working Group
Brian Russell is the Chief Engineer/CyberSecurity for Leidos.

[Cloud Security Alliance Blog]

Palo Alto Networks Researcher Discovers Critical IE Vulnerability

Palo Alto Networks researcher Hui Gao was credited with discovery of a new critical Internet Explorer (IE) vulnerability affecting IE versions 6, 7, 8, 9, 10 and 11. CVE-2015-2548 is included in Microsoft’s October 2015 Security Bulletin and documented in Microsoft Security Bulletin MS15-109.

In our continuing commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors. (As of this writing, Microsoft researcher Bo Qu was also credited with critical IE vulnerability discoveries in August and July, acknowledged in revisions to Microsoft Security Bulletins MS15-065 and MS15-079.)

Palo Alto Networks is a regular contributor to vulnerability research. Previous critical IE vulnerability discoveries from the past 18 months included three in September, one in Augustthree in July (revised from two), three in Junethree in Mayone in Marchfive in February (revised from three), three in November 2014one in October 201415 in September 2014three in August 201410 in July 2014, and 22 in June 2014 (revised from 21).

By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.

[Palo Alto Networks Blog]

The Value of Shared Threat Intelligence

In a recent column for SecurityWeek, Scott Simkin examines the challenge of sharing threat intelligence among security vendors, but notes how vendors who treat threat intelligence as intellectual property are doing more harm than good when it comes to stopping cyber attacks.

As Scott writes, “When vendors and individuals try to keep threat intelligence private, they limit the ability of the entire group to identify and mitigate new threats as they are developed and launched against organizations.”

Read Scott’s article at SecurityWeek.com here.
Learn about Palo Alto Networks AutoFocus and actionable threat intelligence here.
Learn more about the Cyber Threat Alliance here.

[Palo Alto Networks Blog]

The Definition of Cloud Computing

What is the cloud and why should I go there?
The transition to cloud services offers major opportunities for your organisation. Significant scalability, flexibility and cost-efficiency can all be achieved through the adoption of cloud-based solutions. Migrating to the cloud can be a scary prospect for many organizations. In fact, the question is often asked: What actually is cloud computing, and why do I need to go there? Drawing on our consultants’ wealth of knowledge, we have put together a comprehensive definition of cloud computing, outlining how to get the best out of this new technology.

Cloud Computing Defined
On Demand Self Service
At the touch of a button your cloud environment should be there for you. For example, if your IT team were to come under pressure to add or change software, platforms or infrastructure and make them available to your users, they should be able to make these additions instantly. It’s an instant access environment provision.

Ubiquitous Network Access
This is the beauty of cloud – you can access it from anywhere via the Internet. You don’t need any specialized ingress point into your environment; it’s readily accessible for anyone with Internet access. You can access it anytime, from anywhere. This benefit is crucial to all aspects of your organization. All your team needs is an Internet connection and they can log in and use all their enterprise applications and systems, including all their data and resources from any location. This can be vital for remote workers, such as salespeople on the road who are trying to close that quarter-defining sale.

There are risks with this of course; companies need to keep control of who has access to the cloud and what data they are able to access. The benefits that come from having ease of access also create risks. Our experts regularly work with organizations to define the criticality of their data and then categorize it, based on their requirements. It’s important to apply controls to your environment to ensure the right people are accessing the right data.

Location Transparent Resource Pooling
The cloud allows you to pool your resources, so an organization can exploit its assets 24 hours a day. By pooling your resources in a cloud you can utilize your software, platforms and infrastructure through shared services, allowing your users to get the most out of your assets. Pooling strategies include the likes of data storage services, processing services and bandwidth provision services. This provides huge economies of scale for organisations and provides the means to really embrace the global office. As your workforce shuts down for the day on one side of the world, your team on the other side can get up and continue working from the same platforms, applications and infrastructure. The cloud allows you to sweat your assets from anywhere.

Rapid Elasticity
The beauty of being in the cloud is the ability to scale up and scale down your infrastructure at a moment’s notice. The ability to auto-scale in the cloud eliminates much of the risk associated with scoping requirements for technology projects. With traditional environments on premise, if you under-scope the design for an environment and the demands on it prove higher than expected, you lose revenue. Conversely, if you over-scope and sales are lower than expected, you increase costs unnecessarily. The ability to scale your infrastructure at will allows you to design environments with a degree of confidence not available with traditional models.

Once again, this benefit comes with its own risks. It’s imperative that this is monitored on a regular basis. The ease of scaling up and down environments brings financial rewards but also heightens the risk. If an environment is scaled up to meet peak demand and left as such when it’s not needed, this can have negative implications.

Proper, consistent management of this service is the key to success.

Measured Pay Per Use
When in the cloud, you only pay for what you use. This means you can offset your operational savings against your capital expenditure and truly reap the financial benefits. Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service. In addition, this allows for a much more predictable and closely-controlled method of financial accounting, moving from Cap-Ex to Op-Ex budgeting.

Ross Spelman, Group Technical Services Manager, Espion

[Cloud Security Alliance Blog]

English
Exit mobile version