Navigating the Cybersecurity Threat Landscape

With every day that passes it seems that cybersecurity becomes a bigger and bigger issue for businesses and citizens. General and specialized media are flooded with stories on threats and attacks. On top of that, countless niche cybersecurity vendors out there are fighting to communicate how their products can solve most cybersecurity problems. It all contributes to a collective fragmentation of views on what cybersecurity actually is, creating a fog of information.

In the meantime, executives, security managers and specialists are looking to cut through this fog to find proper and holistic navigation tools. A disciplined information security approach suggests adopting the established views for guiding maps, such as ISO 27001, the Federal Information Security Management Act (FISMA), PCI Data Security Standard (PCI DSS), and new ones, such as the US Cybersecurity Framework. Unfortunately, they are not sufficient to provide enough relevant knowledge for establishing cyberresilient organizations, data centers and information systems.

What is missing in all of this are the connections between actual attack techniques, vulnerabilities, threat actors and further detailed analysis of the domain.

So how to fill this gap properly?
I wish I could say that my beloved Center for Internet Security’s (CIS) Critical Security Controls (CSC) is the right answer. Unfortunately, while it is a useful instrument, it does not provide sufficient guidance.

Recently the European Union Agency for Network and Information Security (ENISA) published its Threat Landscape 2015 (ETL 2015), and I was pleased with what I found in it for cybersecurity strategists and practitioners. For the last two years I have referred people to ETL, also Verizon’s Data Breach Investigation Report (DBIR) and CIS CSC, because they all offer relevant, independent sources for strategic, operational and tactical guidance for cybersecurity.

What is so special about these reports? Here are my thoughts on the recently published ETL; hopefully they will inspire you to read the reports if you have not already.

  1. ETL 2015 (and 2014) provide measurement of the landscape of cybersecurity, connecting strategic and tactical views;
  2. ETL 2015 offers mitigation vectors (controls) for the Top 15 threats. For example, CIS CSC provides aggregated mitigation vectors for all threats in prioritized and increased sophistication levels. Such CSC aggregation is good for overall enterprise vision, however it dilutes details of a particular threat, which are relevant to motivate and prove that a threat can be handled adequately;
  3. Cybersecurity vendors publish quarterly and annual reports on threat analysis; however they have internal conflicts—covering only information that is relevant to vendor product portfolio. ETL 2015 mitigates this conflict nicely by providing links to relevant deeper vendor analysis for particular top threats. I find it so elegant and a valuable resolution!
  4. ETL 2015 provides a separate visual Top 15 threats poster – allowing it to be used as an instrument for discussion on how this information is relevant for a particular environment;
  5. I have been involved previously in a few threat classification efforts. I am happy to see that ETL 2015 has issued their Threat Taxonomy in a mindmap, and also in an elaborated Excel format (after opening Excel, for it to be readable, hide the document comments). It can be a great tool to validate your views and see if any gaps remain in your cybersecurity defense architecture. It also allows you to link to an IT infrastructure resilience theme.

DBIR gathers cybercrime facts, even while it is not clear to what extent European law enforcement agencies can legally analyze cases and share anonymized data. DBIR provides great analysis on what should be changed to improve resilience to cybercrime, and it maps practical guidance to CIS CSC. I hope that future ETLs will connect to CIS CSC as well, and to COBIT and ISACA’spublications.

At the end of the day, most organizations have to work through the fog of hysteria on cybersecurity to choose their own strategy for cyberresilience. I hope that these resources will be valuable anchors for you and your organization to evaluate and choose your own way.

Benetis will present Cybersecurity Skills Audit at EuroCACS 2016 30 May – 1 June in Dublin.

Dr. Vilius Benetis, CISA, CRISC, CEO, NRD

[ISACA Now Blog]

How to Reduce Costs and Security Threats Using Two Amazon Tools

Have you ever gone to see a movie that would have been amazing if not for one person? The plot was engaging, the dialogue was well-written, and there were strong performances from most of the cast. But there was just that one actor who simply didn’t live up to the rest of the film, and it made every scene he was in that much worse? Simply put, that actor was bad, and brought down the whole operation.

That idea of the “bad actor” can be applied to Internet clients, as well. Fortunately, you’re not hurting any feelings by sussing them out: the bad actors are usually automated processes that can harm your systems. The two most common forms are content scrapers, which dig into your content for their own profit, and bad bots, who will misrepresent who they are to get around any restrictions stopping them.

We’d all like to believe that everyone accessing content will use it appropriately. Unfortunately, we can’t always assume the best, and being proactive in dealing with these bad actors will reduce security threats to your infrastructure and apps.

Even better, blocking bad actors will also lower your operating costs. When these bots access your content, you’re serving the traffic to them, whether you want to or not. That adds more to your overall costs. By blocking them, you’re restricting traffic from a number of undesired sources. Luckily, AWS has a pair of tools you can combine to say goodbye to these bad actors: Amazon CloudFront with an AWS web application firewall (WAF).

With AWS WAF, you can define a set of rules known as a web access control list (web ACL). Every single rule contains a set of conditions, plus an action. Any request that’s received by CloudFront gets handed over to AWS WAF for further inspection; if the request matches, the user can access the content as attempted. If the request doesn’t match the conditions in a specified rule, the default action of the web ACL is taken. These conditions will remove quite a bit of unwanted traffic, as you can set filters by source IP address, strings of text, and a whole lot more. As for the web ACL actions, you can count the request for later analysis, allow it, or block it.

Perhaps the best attribute of the WAF is that you can smoothly integrate it within your existing DevOps, and automate workflows to react. Since bad actors are always switching their methods to mask their actions, your proactive detection methods must constantly change, as well. Having those automations in place is immensely helpful in finding bad actors and restricting their access.

There’s a great walkthrough of how to set up this solution on the AWS Security Blog, step-by-step. Feel free to check it out for more information, or get in touch with us if you have any additional questions. And for AWS customers that need even more than what the AWS WAF has to offer, there are services that are complimentary to the AWS WAF that provide enhanced protection for business critical applications on AWS. You won’t even need to thank the Academy when all of those bad actors are removed.

David Lucky, Director of Product Management, Datapipe

[Cloud Security Alliance Blog]

Palo Alto Networks Joins Forces with the White House and Industry Partners to Support Veterans and their Families

Last Thursday I had the distinct honor to attend a special White House event celebrating the 5th anniversary of Joining Forces, an initiative that First Lady Michelle Obama and Dr. Jill Biden launched in 2011 in order to support service members, veterans, and their families through wellness, education, and employment opportunities.  Joining Forces works closely with both the public and private sectors to ensure that service members, veterans and their families have the tools they need to succeed throughout their lives.

The primary objectives of Joining Forces include:

  • Bringing attention to the unique experiences and strengths of America’s service members, veterans and their families.
  • Inspiring, educating, and sparking action from all sectors of society —citizens, communities, businesses, nonprofits faith-based institutions, philanthropic organizations, and government — to ensure service members, veterans and their families have the opportunities, resources and support they have earned.
  • Showcasing the skills, experience and dedication of America’s service members, veterans and their families to strengthen our nation’s communities.
  • Creating greater connections between the American public and the military.

You can find more information about this important and effective initiative here:https://www.whitehouse.gov/joiningforces.

I attended the event as a representative of Palo Alto Networks along with Chuck Konrad, who is our Director of Recruiting, Sales and Engineering at Palo Alto Networks and leads our veteran-focused initiatives.

This event was indeed special for one very important reason. During the ceremony in the White House State Dining Room, First Lady Michelle Obama and Dr. Jill Biden announced a new private sector hiring and training initiative where more than 40 companies have committed to hiring 110,000 veterans and military spouses. In addition, 15 companies and organizations have also committed to lead training programs, sponsor scholarships and support certification courses for nearly 60,000 veterans and military spouses over the next five years, primarily in the fields of aerospace, telecommunications and technology.  You can read the First Lady’s remarks from the event here:  https://www.whitehouse.gov/the-press-office/2016/05/05/remarks-first-lady-joining-forces-fifth-anniversary-employment-event.

As a retired Major General in the U.S. Army with more than 35 years of service, let me tell you that you’re going to want to read the First Lady’s remarks at the website above.  I was deeply moved during Michelle Obama’s remarks, and I can tell you that she spoke from her heart and showed her deep commitment to this effort. Dr. Biden, a proud Blue Star mom, emphasized the importance of supporting our veterans when they return home and how hiring veterans and military spouses is good for both companies and the morale of our military.  It does this old Soldier’s heart good to see such deep respect and support for the welfare, educational and employment opportunities of our current and former military and their families coming from the top, and the First Lady and Dr. Biden set the example magnificently!  I was truly humbled by their leadership.

As a strong supporter of this program, we’re doing our part. Along with our Education Services Team and our Veterans Programs team, we conducted a pilot training program for veterans in February 2016, where we trained 16 veterans in a one-week course for our ACE Accreditation. We’re proud to report that each veteran that took the final accreditation exam passed it, which helped prove to us that the program was successful and scalable.

As a result, we’ve committed to Joining Forces to train 400 veterans and transitioning service members over the next five years through the Palo Alto Networks Academy program. After completion of the coursework and successfully passing the accreditation exam, candidates will receive their Palo Alto Networks ACE (Accredited Configuration Engineer) Accreditation and career guidance on entering the cybersecurity workforce.  More information can be found at: www.paloaltonetworks.com/veterans.

[Palo Alto Networks Research Center]

Ransomware Is Not a “Malware Problem” – It’s a Criminal Business Model

Today Unit 42 published our latest paper on ransomware, which has quickly become one of the greatest cyberthreats facing organizations around the world. As a business model, ransomware has proven to be highly effective in generating revenue for cybercriminals in addition to causing significant operational impact to affected organizations. It is largely victim agnostic, spanning the globe and affecting all major industry verticals. Small organizations, large enterprises, individual home users – all are potential targets.

Ransomware has existed in various forms for decades; but, in the last three years, criminals have perfected the key components of these attacks. This has led to an explosion of new malware families, which make the technique work, and drawn new actors into participating in these lucrative schemes.

To execute a successful ransomware attack, an adversary must be able to do the following:

  1. Take control of a system or device.
  2. Prevent the owner of the controlled device from accessing it, either partially or completely.
  3. Alert the owner that the device has been held for ransom, indicating the method and amount to be paid.
  4. Accept payment from the device owner.
  5. Return full access to the device owner after payment has been received.

If the attacker fails in any of these steps, the scheme will be unsuccessful. While the concept of ransomware has existed for decades, the technology and techniques required to complete all five of these steps at a wide scale were not available until just a few years ago. The resulting wave of attacks using this scheme has impacted organizations all over the world, many of whom were not prepared to prevent these attacks from being successful.

The paper we released today details the history of ransomware and how attackers have spent many years trying to get this business model right. We also delve into what we can expect from future ransomware attacks, which includes the trends that follow.

1. More Platforms

Ransomware has already moved from Windows to Android devices and, in one case, targeted Mac OS X. No system is immune to attack, and any device that an attacker can hold for ransom will be a target in the future.

This concept will become even more applicable with the growth of the “Internet of Things” (IoT). While an attacker may be able to compromise an Internet-connected refrigerator, it would be challenging to turn that infection into a revenue stream. But the ransomware business model can be applied in this or any other case where the attacker can achieve all five steps for a successful ransomware attack. After infecting the refrigerator, the attacker could remotely disable the cooling system and only re-enable it after the victim has made a small payment. 

2. Higher Ransoms

The majority of single-system ransomware attacks charge a ransom between $200 and $500, but the values can be much higher. If attackers are able to determine that they have compromised a system which stores valuable information, and that infected organization has a higher ability to pay, they will increase their ransoms accordingly. We have already seen this in a number of high-profile ransomware attacks against hospitals in 2016, where the ransoms paid were well over $10,000. 

3. Targeted Ransom Attacks

A targeted intrusion into a network is valuable to an attacker in many ways. Selling or acting on stolen information is a common technique, but it often requires additional “back-end” infrastructure and planning to turn that information into cash. Targeted ransomware attacks are an alternative for attackers who may not know how else to monetize their intrusion. Once inside a network, attackers can identify high-value files, databases, and backup systems and then encrypt all of the data at one time. These attacks, using the SamSa malware, have already been identified in the wild and proven lucrative for the adversaries conducting them.

Download your copy of the “Ransomware: Unlocking the Lucrative Criminal Business Model” paper and learn techniques for preventing ransomware attacks.

[Palo Alto Networks Research Center]

Elliptical Curve Cryptography for the Internet of Things

The elliptic curve cryptography (ECC) asymmetric algorithm is widely promoted to developers for new Internet of Things (IoT) advancements. At a first glance, it is easy to see why this is the case. While IoT faces new constraints and challenges that make traditional cryptography difficult to implement, these difficulties also empower ECC to emerge as a front-runner. Constraints in IoT include limitations to computational resources such as the bare minimum processor speed and memory needed as such devices are typically designed for low power consumption. Challenges include the need to reengineer things such as identity management, device and user registration, and cryptography to suit IoT needs.

Is ECC the right cryptosystem to meet the aforementioned constraints and challenges? As ECC offers shorter keys, lower central processing unit (CPU) consumption and lower memory usage for equivalent security strength, it is easy to say yes after a quick glance. However, there are many more concerns that must be deliberated. My recent Journal article, “Can Elliptic Curve Cryptography Be Trusted? A Brief Analysis of the Security of a Popular Cryptosystem,” delves into these concerns by assessing and reviewing the key threats and challenges to the famous asymmetric cryptosystem.

Does ECC provide sufficient security that would satisfy the demanding world of IoT? The potential risk is high, and damages are not limited to data theft or loss. Compromise of an IoT device can lead to significant safety issues when related to vehicles, health care devices and control systems. Such an event, whether it results in loss of vehicle control, malfunctioning medical device or other adverse event, may result in injury or worse. Threats such as unauthorized tracking of individual’s locations, manipulation of financial transactions and compromise of the integrity of highly sensitive data (e.g., health data required for proper diagnosis) are significant enough to cause anybody to pause and think. Does the risk of ECC outweigh the rewards?

Read Veronika Stolbikova’s recent Journal article:
Can Elliptic Curve Cryptography Be Trusted?,” ISACA Journal, volume 3, 2016.

Veronika Stolbikova

[ISACA Journal Author Blog]

English
Exit mobile version