Palo Alto Networks at Bloomberg’s The Year Ahead 2016

Palo Alto Networks was at Bloomberg’s The Year Ahead 2016 conference in New York earlier this month where over 250 Business Development Managers and c-level professionals were in attendance.

While we were there, Davis Hake, our Director for Cybersecurity Strategy, was interviewed by Bloomberg Radio to discuss Palo Alto Networks technology, a prevention mindset to cybersecurity, and how companies can make the right investments in training, people and processes by involving the c-suite in the security discussion. Listen to the interview.

Davis also participated on a panel focusing on Cybersecurity and the CEO, discussing some of the hot topics from Navigating the Digital Age, The Definitive Cybersecurity Guide for Directors and Officers which we recently produced in partnership with the New York Stock Exchange. Get a copy of this book and take a look at the photos from the event below.

[Palo Alto Networks Blog]

Network Shared Drive Encrypted by CryptoWall? How to Track Down the Infected PC

There is a lot of information on the web about preventing and recovering from CryptoWall or ransomware attacks in enterprise environments, but most don’t answer this basic question:

How do I determine which CryptoWall-infected PC encrypted all the documents in one of my network-shared drives? I don’t have audit logging enabled on my file server.

Although many organizations are working on migrating their document storage to the cloud, most still rely upon individual Microsoft network shares as a document repository for each business department. For example, the financial controller’s office may have a network share dedicated to that department, the HR department has a different one, etc. When a user’s PC in one of these departments becomes infected by CryptoWall, the ransomware iterates through all files on all folders on all local and mapped network drives and encrypts certain file types that the user has permissions to modify.

As a security lead for a hospital network, I created the following CryptoWall response plan specifically to deal with impacted department shared drives:

  1. Identify the user account that modified (encrypted) the shared drive files.
  2. Identify the infected PC and restrict network access.
  3. Create inventory of all network share directories impacted.
  4. Restore impacted directories from backup.

Identifying the user account in Step 1 can be challenging if you don’t know where to look. The best way to identify the user account used to encrypt the files is to examine the “owner” attribute of one of the instruction files created by the ransomware. Here are the steps to identify the owner:

1. Right click on the instructions file (i.e., HELP_DECRYPT.txt) created by the ransomware on the network share, and select Properties.

2. Select the Security tab –> Advanced –> Owner, and view the Current Owner attribute. The Current Owner attribute is likely the username used to encrypt the files in the directory.

Once you know the username used to encrypt the files, you can reset the user’s password, attempt to contact the person, and identify the user’s assigned PC in order to block it on the network. Once the PC is blocked, the server team can then identify the impacted directories on the network share (Tip: Use PowerScript to identify directories containing the instructions file). Finally, the Backup team can restore the files in all of the identified directories.

For more information on the latest CryptoWall threat, take a look at a detailed analysis of CryptoWall v3 authored by the Cyber Threat Alliance, cofounded by Palo Alto Networks.

[Palo Alto Networks Blog]

2016 Prediction #1: Online Marketing Trends Will Change Web-Based Threats… Slightly

This is the first in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

Marketing and advertising technologies have always been at the forefront of finding new ways to identify and track data, and security threats are never far behind. So, with 2016 looming, there’s no better time to look at Forbes’ “The Top 7 Online Marketing Trends That Will Dominate 2016” and the resulting security implications. Forbes’ list is as follows:

  1. Video ads will start dominating.
  2. App indexing will lead to an explosion of apps.
  3. Mobile will completely dominate desktop.
  4. Digital assistants will lead to a new kind of optimization.
  5. Virtual reality will emerge.
  6. Wearable technology and the Internet of Things (IoT) will pave new ground.
  7. Advertising will become more expensive.

One thing is for sure: some of these trends open new avenues for cybercriminals. Three key trends that stand out as potential security issues are: the explosion of apps as a replacement for regular websites, the emergence of virtual reality, and the expansion of wearable technology. Let’s take a closer look at just how each of these three trends could impact web-based attacks in 2016.

Explosion of apps

There are already apps for everything from accounting to web posting, with more popping up every day. The fact that most apps can do exactly what websites can do – and in many cases better – will lead to a volume challenge, considering how the sheer number of apps can potentially degrade security and be open to exploitation.

Emergence of virtual reality

A new phenomenon, with little regulation and standardization, virtual reality opens the door to new, never-before-experienced cyberattacks. Virtual reality platforms will connect to the web or web-based apps, again resulting in a broader base to launch cyberattacks for cybercriminals.

Expansion of wearable technology

The Internet of Things (IoT) is moving beyond its infancy. Many wearable gadgets offer access to the web and very little control for secure access. Yet, most devices will somehow connect to a larger corporate network. This provides cybercriminals with the benefit of a lower barrier to entry into any connected organization.

While all of these changes are important, I do not expect to see a major shift in web-based attacks during 2016. Instead, we will see an adjustment in the behavior of cybercriminals and their use of the cyberattack lifecycle, mainly in how they infiltrate companies.

It’s hugely important for companies to deploy good application identification capabilities within a security platform that offers a holistic and comprehensive approach to security, with web security providing a part of the overall protection. Focusing on web security alone will not be sufficient. Securing an enterprise or government means architecting security to both detect and prevent known and unknown attacks while safely enabling applications.

 

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

English
Exit mobile version