Not All Next-Generation Firewalls Are Created Equal

As cybersecurity threats increase in sophistication, the security solutions used to defend against these threats must also evolve. Developers no longer adhere to standard port/protocol/application mapping; applications are capable of operating on non-standard ports, as well as port hopping; and users are able to force applications to run over non-standard ports, rendering first-generation firewalls ineffective in today’s threat environment. Enter the “next-generation firewall” (NGFW), the next stage of firewall and intrusion prevention systems (IPS) technology.

A common understanding of an NGFW is a network platform that combines the traditional firewall functionalities with IPS and application control. However, merely bundling traditional firewalls with IPS and application control does not result in an NGFW. A true NGFW emphasizes native integration, classifies traffic based on applications rather than ports, performs a deep inspection of traffic and blocks attacks before a network can be infiltrated. Here is a list of key features of a true NGFW to better inform your next purchase decision.

Identify and control applications and functions on all ports, all the time

An NGFW should identify traffic on all ports at all times, and classify each application, while monitoring for changes that may indicate when an unpermitted function is being used. For example, using Citrix GoToMeeting for desktop sharing is permitted but allowing an external user to take control is not.

Identify users regardless of device or IP address

Knowing who is using which applications on the network, and who is transferring files that may contain threats, strengthens an organization’s security policies and reduces incident response times. An NGFW must get user identity from multiple sources – such as VPN solutions, WLAN controllers and directory servers – and allow policies that safely enable applications based on users, or groups of users, in outbound or inbound directions.

Identify and control security evasion tactics

There are two different classes of applications that evade security policies: applications that are designed to evade security, like external proxies and non-VPN-related encrypted tunnels (e.g., CGIProxy), and those that can be adapted to achieve the same goal such as remote server/desktop management tools (e.g., TeamViewer). An NGFW must have specific techniques that identify and control all applications, regardless of port, protocol, encryption or other evasive tactics and know how often that firewall’s application intelligence is updated and maintained.

Decrypt and inspect SSL and control SSH

An NGFW should be able to recognize and decrypt SSL and SSH on any port, inbound or outbound; have policy control over decryption; and offer the necessary hardware and software elements to perform SSL decryption simultaneously across tens of thousands of SSL connections with predictable performance.

Systematically manage unknown traffic

Unknown traffic represents significant risks and is highly correlated to threats that move along the network. An NGFW must classify and manage all traffic on all ports in one location and quickly analyze the traffic, known and unknown, to determine if it’s an internal/custom application, a commercial application without a signature, or a threat.

Protect the network against known and unknown threats in all applications and on all ports

Applications enable businesses, but they also act as a cyberthreat vector, supporting technologies that are frequent targets for exploits. An NGFW must first identify the application, determine the functions that should be permitted or blocked, and protect the organization from known and unknown threats, exploits, viruses/malware or spyware. This must be done automatically with near-real time updates to protect from newly discovered threats globally.

Deliver consistent policy control over all traffic, regardless of user location or device type

An NGFW should provide consistent visibility and control over traffic, regardless of where the user is and what device is being used, without introducing performance latency for the user, additional work for the administrator, or significant cost for the organization.

Simplify network security

To simplify and effectively manage already overloaded security processes and people, an NGFW must enable easy translation of your business policy to your security rules. This will allow policies that directly support business initiatives.

Perform computationally intensive tasks without impacting performance

An increase in security features often means significantly lower throughput and performance. An NGFW should deliver visibility and control including content scanning, which is computationally intensive, in high-throughput networks with little tolerance for latency.

Deliver the same firewall functions in both a hardware and virtualized form factor

Virtualization and cloud computing environments introduce new security challenges, including inconsistent functionality, disparate management and a lack of integration points. An NGFW must provide flexibility and in-depth integration with virtual data centers in private and public cloud environments to streamline the creation of application-centric policies.

To learn more about what features a NGFW must have to safely enable applications and organizations, read the 10 Things Your Next Firewall Must Do white paper.

[Palo Alto Networks Research Center]

Ransomware Growing More Common, More Complex; Modern Endpoint Backup Isn’t Scared

The growing ransomware threat isn’t just about more cybercriminals using the same cryptoware tools. The tools themselves are rapidly growing more sophisticated—and more dangerous.

Ransomware growing exponentially, with no signs of slowing
A new report from InformationWeek’s Dark Readinghighlights key trends in the ransomware landscape, starting with the dramatic increase in total ransomware attacks. Ransomware attacks increased by 165 percent in 2015 (Lastline Labs), and this trend isn’t letting up. Anti-spyware company Enigma Software reported a 158 percent jump in the number of ransomware samples it detected between February and March 2016—and April 2016 was the worst month on record for ransomware in the U.S.

It’s also clear that ransomware growth is independent of the overall increase in cyberattacks over the past several years. The 2016 DBIR reported that phishing attacks are more common than ever, and Proofpoint found that in the first quarter of 2016, nearly 1 in 4 (24%) of all email attacks using malicious attachments contained just one strain of ransomware (Locky).

Not just more common—ransomware growing stronger and more effective
Most alarmingly, DarkReading reports that cyberattackers are rapidly evolving and diversifying their ransomware arsenal. Ransomware has become big business, and with that cash flow comes development of more complex ransomware strains and more clever techniques for infecting targets. In an ironic twist, creators of popular ransomware such as Locky are now working to “protect” their cryptoware from enterprising copycats who create knockoff versions and variants. No honor among thieves, indeed.

Better phishing lures, more brute-force attacks
DarkReading spotlighted two examples of this increasing sophistication. On the one hand, cybercriminals are developing new, more obscure ways of luring a user to install ransomware. From personalized landing pages to actually hacking a device’s boot-up process, stopping these techniques is much more complicated than just saying, “Don’t click suspicious links.”

At the same time, attackers increasingly skip the phishing lure and go straight to brute-force attacks on internet-connected remote desktop servers. For the skilled hacker, this technique is more reliable than phishing, and immediately gets the attacker much deeper into an enterprise network, allowing them to compromise more devices and ransom more data.

“No backup, no protection”
With ransomware mutating into an even bigger threat, Dark Reading encouraged companies to go back to basics, citing data backup as the essential first step in enterprise ransomware defense. We couldn’t agree more. No matter how complex and advanced the ransomware, modern endpoint backup isn’t scared. Modern endpoint backup gives you guaranteed recovery in the face of ransomware. But its protection goes beyond backup: Modern endpoint backup sees your endpoint data, sees your users’ endpoint activities, and gives you the visibility to identify and neutralize an attack as soon as it hits.

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about selecting a modern endpoint backup solution in a dangerous world.

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

Whaling Goes After the Big Phish

The bigger the phish, the fatter the payoff for cybercriminals. That thinking is driving a spate of whaling cyberattacks targeting C-level executives and their employees around the globe.

Whaling attacks go far beyond the typical phishing expedition in that perpetrators do their homework and learn everything they can about their intended C-suite victims and their organizations to ultimately convince them or their associates to give up credentials, information and/or financial assets. They produce believable emails that appear to be from trusted internal or external business partners that actually contain malware and URLs to download malicious payloads and link to dubious web sites all in hopes of a handsome payday. Whaling uses social engineering to prey on the weakest link in cyberdom:  humans.

I expect the surge in whaling to continue because cybercriminals are having success duping top executives and their associates. Similar to advanced persistent threats (APTs), whalers study how people write, what their email looks like and whatever else they need to know to show potential victims the personal touches that really sell the impersonation. Producing genuine-appearing email is how the criminals succeed in convincing top executives the requests are real. A key part of the ruse is the request for confidentiality and the need to bypass approval channels.

Whaling Costs Enterprises Plenty
Successful whaling attempts are so believable and seemingly trustworthy that executives who should probably know better are clicking on links and attachments that appear to be from fellow executives, employees or business partners. One stellar example of this includes a senior executive with a security firm who received an email that appeared to be from an underling but was actually from a whaler. He was tricked into giving up employee W-2 data.

Another incident involved an executive from a major soft drink company that was in talks to choose a bottler in a highly profitable, under-serviced country. Before negotiations were completed, someone working under the executive was spear phished, and the whaler was able to harvest all email related to the negotiations, jeopardizing the talks and putting the company at a distinct disadvantage.

A third case involved a top executive of a 40-year-old company that made a unique product that had just one competitor in the world. One day the executive noticed the sudden appearance of a new competitor that was selling a nearly identical product but at a significantly lower price. It turned out that the man had been whaled. Through social media, the cyberattackers learned he had a passion for antique cars. They concocted an email with a link to a fake online auto trading ad for a car deal that was too good to be true. Excited by the car and the unbelievable deal, he double clicked on the link and almost immediately 40 years of research, development and blueprints were in the hands of an unknown competitor. The company was unaware that their information had been compromised until the new competitor showed up on the market six months later.

One whaling email can sink a company or cost top leadership their jobs. A January 2016 whaling attack against an Austrian aircraft parts manufacturer resulted in the loss of US $45,693,480 and the firing of both its CFO and CEO.

Challenges Go Deep
Email is the lifeblood of business today, so living without it is not an option. But addressing the whaling problem presents a number of challenges thanks primarily to the human factor. For example, employees who receive emails from high-ranking executives are often hesitant to question their validity. They want to handle any and all requests from higher ups quickly and efficiently to gain favor with their boss. On top of that people are often overworked, so the last thing on their mind is whether or not an email is legitimate. Finally, employees today are often less committed to their organizations than we would like. Allegiance to employers can be weak or nonexistent, so why should they care about whaling attempts? Your company’s whaling defenses are only as good as your least knowledgeable and dedicated employee.

Training, Training, Training
What can be done to protect organizations against whaling? In a word:  training. Training to increase education and awareness of cyber schemes such as whaling, phishing and the like, is critical to combatting these incidents. For email requesting out of the ordinary access to data or assets, secondary verification is critical. A quick phone call is all it takes. And always check the sender’s email address. Security should never be weakened in exchange for speed or expediency.

Training should be regular, engaging and include every person in the organization, including C-suite personnel. Poor or condescending training can be worse than none at all, so make sure you develop effective training and do not talk down to employees. Training and awareness efforts should be ongoing and can include weekly email blasts to reinforce training and maintain and increase awareness.

Obviously, if your organization has an IT professional with cybersecurity credentials such as a CSX Cybersecurity, Fundamentals,Practitioner, Specialist or Expert certificate, they can provide invaluable resources to ensure effective training.

Daniel Libby, Director and Chief Examiner, Digital Forensics Inc.

[ISACA Now Blog]

The Cybersecurity Canon: Rise of the Machines: A Cybernetics History

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Bob Clark: Rise of the Machines: A Cybernetics History (2016) by Thomas Rid

Executive Summary

As cybersecurity practitioners we have a lot to read simply to stay current in our industry. However, after reading the latest threat reports, flash releases, CERT notifications, CVEs and products on emerging technology, we should seek to develop ourselves as complete practitioners. This is one of those books. Understanding our history, and how we got here, makes you a better practitioner with a broad base of knowledge. And hell, who doesn’t love a book that talks about the HAL9000, Arthur C. Clarke, Playboy articles, Omni magazine, AT-ATs, Terminator, Karel Čapek’s R.U.R. (the 1920 Czech play that gave us the word “robot”), Blade Runner, Whole Earth Catalog, Mary Pranksters and acid trips, the counterculture of San Francisco, and finally, finally, lets us all quote the real origins of that much-maligned term “cyber.” Rise of the Machines: A Cybernetics History covers it all, including the arts, literature, and trends in pop culture.

The author, Thomas Rid, is a professor in the Department of War Studies at King’s College London and the author of Cyber War Will Not Take Place and War and Media Operations. Professor Rid’s research is extensive as he takes us through the history of cybernetics, the merging of man and machine starting with cybernetics foundations in Norbert Weiner’s writings in the 1940s and moving through each subsequent decade, including the West Coast techno-libertarians’ addition to the theory, ending with an extensive look at what Rid calls the first cyberwar.

As Matthew Kirschenbaum states in his review:

Rise of the Machines is a sweeping intellectual history, engagingly written and brought to life by numerous details and anecdotes. Cybernetics and its progression of offshoots — cybernation, cyberculture, cyborgs, cyberspace, cyberpunk, cypherpunk, and finally cyberwar — are all disentangled and demystified in its pages.

Cybersecurity Canon candidate books are supposed to be essential to the cybersecurity practitioner, and it’s great to be steeped in your specific knowledge that makes you an expert. However, it is well-rounded practitioners who will distinguish themselves among their peers; reading this book will definitely accomplish that goal.

Review

I confess, any book that can properly define the word “cyber” – I’m all for it, especially with so many practitioners and policy wonks misusing the term. Rid recognizes this and, therefore, uses this historical look to help us all understand where, when and how to use the prefix “cyber.” Rid immediately helps the industry, correctly stating that “cyber” is a prefix being slapped onto anything to make it more techie or interesting. He goes on to answer the oft-asked question, “where did cyber come from?” He slams the door shut on that perpetuated myth we’ve all heard and repeated that cyber is the child of William Gibson’s Neuromancer. “Cyber” was first used as in “cybernetics” a general theory of machines from the early 1940s; it was about computers, control, security, and the ever-evolving interaction between humans and machines.

Rid builds the book’s narrative through eight main chapters that are organized chronologically: Automation, Organisms, Culture, Space, Anarchy and War. Cybernetics found its beginnings in Norbert Wiener’s foundational Cybernetics or Control and Communication in the Animal and the Machine (1949) that became improbable bestsellers. Using this as a launching point, Rid looks at cybernetics through the decades to include not only the technological advances but also the philosophical developments dealing with advances in merging machines with humans. Others mentioned, who come and go along the way, include John von Neumann, Gregory Bateson, Stewart Brand, Timothy Leary and Jaron Lanier.

Developed from the mind of MIT mathematician Norbert Wiener amid the devastation of World War II, the cybernetic vision looked at the merging of man with the future of machines. This need to combine man and machine to improve our defenses and man’s capability to fight looks at the early advances in war-fighting capabilities, not only man becoming engaged with various machines but also computer systems developed, such as our air defense system SAGE – one would say, the predecessor to NORAD.

The 50s and early 60s see the same focus, making technology that can increase man’s power and strength to include fighting devices developed for the war in Vietnam and walking machines that never got past prototypes but preceded the AT-ATs of Star Wars. Ultimately cybernetics finds two competing factions: some seeking to make a better world – Bay Area denizens/libertarians hoping for a new unregulated and uncontrolled digital space – and some seeking to control it (i.e., Washington, DC).

In the 60s and 70s the technology side of the cybernetics movements, changes with the Bay Area’s introduction into drugs, rock and computers. Rid details the rise of this movement including the numerous influencers from the West Coast, including the birth of the Electronic Frontier Foundation, a great organization for defending civil liberties in the digital world.

As the Bay Area movement subsides, the 80s did bring us Gibson’s cyberpunks and “Rid takes us back inside the green machine — the military, specifically the U.S. Department of Defense, aligning the precepts of the AirLand Battle that was supposed to defeat Warsaw Pact tank armies in the 1980s and the post-Desert Storm revolution of military affairs with cybernetic arts of war.” We also see the rise of unfulfilled promises of cool “virtual reality” devices, the prototypes of which were clunky at best and looked like “Dark Helmet” from Mel Brooks’Spaceballs. And let us not forget what the 90s brought us, of course: the crypto wars and introduction of cypherpunks.

Finally, Rid finishes up with a topic near and dear to his heart and extensively researched: moonlight maze, as many U.S. government folks called the first state-on-state cyberwar. (Cyber-espionage is what it should have been classified.) Ironically Matt Kirschenbaum compares Rid’s discussion on this subject with Fred Kaplan’s in Dark Territory, also reviewed by me and on the Canon website. Kirschenbaum believes Rid presents this information much more deeply than Kaplan. And while I know Rid’s research is extensive, I thought both covered it equally well with Kaplan painting the Russian’s actions much better. Then again, I think it fit better into Kaplan’s book and was treated appropriately in Rid’s.

Of course “the climax of the book is its discussion of the complex of public fears around an Electronic Pearl Harbor (the language is Hamre’s), a phrase whose staying power Rid sees as evidence of the machines at their apogee.”

Conclusion

Rise of the Machines: A Cybernetics History will not make you more proficient in your cybersecurity job, unless you’re a policy wonk. What this book will do is make you a better practitioner, well-versed in “the rise of the machine.” And if your promotion comes down to advancing an SME who can speak solely to his/her area of expertise or promoting one that, all things being equal, is more well-rounded then this book will definitely accomplish that and give you knowledge to be used as a cyber-professional. (See how I did that? I used “cyber” as a prefix before “professional.” Tom Rid would be proud – I think.)

[Palo Alto Networks Research Center]

LabyREnth Capture the Flag (CTF): First Set of Winners Announced

We’ve had more than 4,000 threat researchers join us for LabyREnth, the first Unit 42 Capture the Flag (CTF) challenge, and we still have two more weeks to go before the challenge closes. The community has put forth an amazing effort across the 6 challenge tracks, and we want to recognize the herculean effort of the select few who were first to complete all challenges and individual tracks. It is a testament to their skill, commitment and time, and we hope they enjoy the $16,000 worth of prizes to which they are entitled. We are holding an exclusive gathering to celebrate the winners at DEF CON this week, and we look forward to seeing them in Las Vegas!

For those of you who didn’t win the grand prizes, LabyREnth is open until 11:59 p.m. Pacific Time on August 14, 2016. It’s a great way to try your hand at challenges, have fun, win prizes, and learn something new.

Please join us in congratulating the initial winners:

Overall winners:

  • 1st to solve all challenges: KT (@koczkatamas) and also 1st to solve the Random track
  • 2nd to solve all challenges: F4b (@0xf4b)
  • 3rd to solve all challenges: Dan Raygoza (@danielvx)

Track winners:

  • 1st to solve Windows track: Wayrick
  • 1st to solve Unix track: Sine (@73696e65)
  • 1st to solve Docs track: Sin__ (@mztropics)
  • 1st to solve Mobile track: n0n3m4
  • 1st to solve Threat track: Nxgr (@Nxgr_l)

[Palo Alto Networks Research Center]

English
Exit mobile version