The Technology Services Industry Association (TSIA) and J.D. Power have recognized us for our ability to deliver exceptional customer support to our customers. These prestigious industry awards include the TSIA Star Award in 2014 for Innovation in the Delivery of Support Services, TSIA Worldwide Rated Outstanding Assisted Certification and, most recently, Palo Alto Networks, North America Assisted Support, has been recognized by J.D. Power for providing outstanding customer service for its Assisted Technical Support.
Read on for details:
2015 J.D. Power Certified Assisted Technical Support Program
Palo Alto Networks is the first to have achieved the 2015 Certified Assisted Technology Support (CATS) Certification under this new program from J.D. Power for providing exceptional commitment and support to our customers.
Palo Alto Networks, Inc. North America Assisted Support has been recognized by J.D. Power for providing outstanding customer service for its Assisted Technical Support
J.D. Power 2015 Certified Assisted Technical Support Program, developed in conjunction with TSIA. Based on successful completion of an audit and exceeding a customer satisfaction benchmark for assisted support operations. For more information, visit www.jdpower.com orwww.tsia.com.
2015 TSIA Global Rated Outstanding Assisted Certification
TSIA certification recognizes that Palo Alto Networks has achieved Global Rated Outstanding Assisted Support. Customers can purchase Palo Alto Networks products with confidence knowing that Palo Alto Networks meets the highest industry support standards.
2014 TSIA Star Award for Innovation in the Delivery of Support Services
This award recognizes the company that has embraced innovation in people, process and technology to increase agent productivity, service levels or customer satisfaction; increase problem avoidance; or effectively handle more interactions using unassisted channels.
Palo Alto Networks takes great pride in delivering an exceptional customer experience, and we are very proud to receive recognition from both TSIA and J.D. Power. We will continue our commitment to delivering an exceptional support experience for our customers.
Please let me know if you have any comments or questions, or contact me via Twitter anytime at @CicconeScott.
One of the important components baked into the Palo Alto Networks next-generation security platform is our API. You can use our API to interact with and automate the various components of our platform, such as bulk searches, push and pull configurations, leveraging third-party applications and services, and more.
In this post, I’ll explain, step-by-step, how to use our API with AutoFocus utilizing the Postman app. Postman is a useful development and testing client for REST API, creating complex HTTP requests and giving you the ability to interact with the API as it presents a friendly GUI for constructing requests and for reading responses. We’ll be using this application to demonstrate Palo Alto Networks AutoFocus API capabilities.
Prerequisites
Before you can start using the AutoFocus API, there are a few steps needed to ensure things run smoothly:
Make sure you have portal access credentials to AutoFocus (Contact your Palo Alto Networks representative or partner if you’d like to purchase or trial AutoFocus)
In this example, we want to find all the Dridex instances in our network that WildFire convicted as malware and where the destination files are the United States. We want those results in JSON format so we can use this data any way we want: parse it, use parts of it, export it to third-party-services or applications, or integrate the information into the SOC.
Many of the resources in the AutoFocus API require API calls to two resources. The first call is to initiate a search and the next is to check for the results of that search. Take the following steps to configure the Postman Application.
Step 1: Configuring the search query
As mentioned before, you need to craft two API calls to two different resources. The first call is the query itself to pull the data and the second one is to fetch and present the results. Both calls use the POST method. Crafting the AutoFocus query itself can get complicated depending on the query you want to design.
The best way to create your own query is to use the AutoFocus search option and then export the query into a file using the following process:
Log in to the AutoFocus portal
Create the query as described
Use the export option to export your search
You can then copy the search or save it to a file and use it later when you need it
As a side note, the same rule applies when you want to create an API call using a shell/python script using the CLI instead of the Postman Application.
In the query field, use the API Key you copied into the “apiKey”: “XXXXX”
Type in the query and click the “Send” button
If everything went well and the apiKey value you have entered is correct, you will get the query result values in the results window.
The specific value you need to look for is the af_cookie. Once you find it, copy the value.
The af_cookie expires 120 seconds after the search results are complete (when af_complete_percentage is 100) or after you view completed search results.
Step 2: Viewing the Results
To view the results and retrieve the af_cookie, you need to configure Postman to perform the second POST method and point it to the results link.
In the query field, paste the API Key you copied into the “apiKey”: “XXXXX”
Click the “Enter” button
You should be able to view the output in the results/output window at the bottom of the Postman Application.
Then copy and search the results you pulled from AutoFocus. You can also save the output to a file and perform regular expression and parsing as needed, export the data, etc…
Conclusion
This was just one example of the different ways you can leverage and use the AutoFocus API to perform automation and link between various third-party-tools and streamline your threat
intelligence analysis, perform bulk searches, import and export queries, leverage IOC, and so on. AutoFocus is a powerful tool for performing threat intelligence, leveraging the rich data Wildfire provides and shortening the analysis time needed to reach a quicker resolution and root cause analysis. By adding the power of the API, you achieve integration and automation between the Palo Alto Networks platform and your existing infrastructure, further streamlining analysis and getting the results you need, quickly and easily.
For more information, visit the AutoFocus API website to find different examples, configurations, prerequisites, rate limits, and other resources.
The holiday season is a time for friends and family, as well as for heightened levels of consumer shopping. It’s also a time of year when threat actors get especially opportunistic, and the 2015 holiday season was no different.
Let’s take a closer look at recent holiday season-themed attacks.
Happy Festivus!
Unit 42 examined the time period from November 25, 2015 through December 29, 2015 and identified nearly 4 million phishing attacks containing malicious attachments using AutoFocus. Out of these phishing email messages, we then searched specifically for holiday-themes, using keywords such as “Christmas,” “holiday,” “Santa,” etc. Amongst the results, 92 percent of the attacks identified to be holiday themed were already found to have a Unit 42 tag associated with it, providing additional context around the malware family in use, indicator sets, and any references that may be of use.
It’s important to note that we did not include keywords related to “package delivery notification” themes in this analysis. While these can certainly be characterized as holiday-related, we find these themes are abused year-round by attackers and no longer specific to the holiday season.
Among the observed sessions positively identified as holiday-themed, a single organization in higher education generated the significant majority, roughly 80 percent of those sessions, primarily containing the Bartallex/Dridex macro malware families delivering payloads containing Pony, Rodecap, and Zeus.
This data seems to indicate that a significant campaign was put in place at the affected organization, and the adversaries specifically leveraged holiday themes in an attempt to attack as many victims as possible. Subject lines for the phishing lures were made up of mostly shopping-related topics, such as advertisements for sales or giveaways. Other lures included invitations to holiday festivities; simple greetings or well wishes; and, strangely, alcohol addiction-themed lures.
Other industries did experience similarly themed attacks, but not in nearly as high volume as higher education due to the one largely affected organization.
Figure 1 Holiday-Themed Phishing Attacks by Date
Figure 1 shows the general trend of holiday-themed phishing attacks, which loosely corresponds to work weeks (little to no activity on Friday, Saturday, and Sunday), as well as the tapering off in activity as workers began to take days off for the holidays.
Examining the possible motivations by the adversaries involved in holiday-themed attacks, the vast majority appear to be motivated by profit – cybercriminals seeking to generate revenue using malware, such as banking Trojans designed to steal credentials, botnet malware that causes the victim to unwittingly join a botnet often put up for sale, and ransomware that can encrypt a victim’s data and hold it hostage.
The most common delivery methods used a weaponized Microsoft Office document using a macro, or macro malware, to retrieve additional malware once launched on the victim host. These generally fell under the Dridex or Bartallex families and made up 50 percent of all holiday-themed malware. Other delivery mechanisms were generally much simpler, arriving in the form of a portable executable attachment in a holiday-themed email message with the hope that a victim would launch it.
Figure 2 Breakdown of malware families
“WISH U A MERRY CHRITMAS DAY”
Although most of the activity of holiday-themed attacks appeared to be for-profit, at least one targeted attack was observed during the season. The attack used a malicious RTF file exploiting an older, but well-known vulnerability in Microsoft Word, CVE-2012-0158. This vulnerability has been exploited in multiple cyber espionage operations, including Lotus Blossom, but does not indicate an attack by any particular group. The malicious document contained a Christmas-themed graphic (Figure 3) and used a Christmas-themed filename, “Christmas Letter&sponsors.doc.”
Once executed, the file would drop a self-extracting RAR file containing a legitimate executable that would then be used to sideload malicious DLLs. The malware ultimately installed onto the victim host has been identified as LURK0, a variant of the well-known Gh0st RAT. Gh0st RAT is a fairly old, but effective remote access Trojan, and the source code is freely available on the Internet. Because of this, it is quite popular and has been observed in use by multiple nation-state groups as well as cybercriminals. Additionally, the variants and modifications to the original source code are numerous. The one constant of Gh0st and its variants is their network communications – they always begin with a “magic word,” using “Gh0st” in the default configuration. Roughly 50 or so magic words have been discovered, with each variant being named after that magic word. This particular sample uses “LURK0” as the magic word, hence the name.
Figure 3 Image from Weaponized RTF
Conclusion
As we have indicated in multiple previous blog articles, staying situationally aware of ongoing events in our everyday lives is vital in effective defense against the adversary. For specifically holiday-themed attacks, the motivations appear primarily profit-driven. The holiday season can be a high-stress time, and consumers may be more likely to pay an adversary if, for example, their data was encrypted by ransomware. There may also be a higher level of banking activity as funds are transferred and exchanged at a higher volume due to the additional shopping that occurs. Of course, that does not mean targeted attacks leveraging this seasonal event do not occur, as described previously.
Ultimately, the overall trend continues: our end users are constantly faced with a barrage of attacks on both their personal and professional resources. Taking a prevention-first approach to security is crucial in reducing the attack surface to more effectively defend ourselves and our organizations from all adversaries.
Emerging Approaches in a Cloud Connected Enterprise: Containers and Microservices
Presenter: Anil Karmel, Co-Founder and CEO of C2 Labs
Date: Jan 28–10:30am PT (6:30 GMT)
Containers such as Docker and CoreOS Rkt deliver incredible capabilities to developers and operators and are powering the DevOps revolution in application development and deployment. Docker in particular has taken industry by storm, resulting in over 400 million downloads and 75,000+ containerized applications in this open source platform. With all this new found power come significant challenges and concerns. Come learn how containers and micro-services work, understand the security challenges with approach, and strategies to address the same.
Presenters: Salim Hafid and Neal Mhaskar, Bitglass
Date: Feb 3rd–10:00am PT (6:00 GMT)
BYOD is an adoption, not a rollout. In fact, 57% of employees refuse MAM or MDM on their personal devices. What are the drawbacks of MDM? How can your organization both drive adoption and effectively secure BYOD?
In this webinar, we’ll answer those questions and discuss next-generation mobile security solutions that can help secure corporate data across managed and unmanaged mobile devices.
Presenter: John DiMaria, BSI
Date: Feb 11th–9:00am PT (5:00 GMT)
With Japan’s introduction of the quartz wristwatch in 1969, the majority Swiss market share dropped from 80% at the end of World War II to only 10% in 1974 . Ironically, it was the Swiss who had invented the quartz watch but failed to see its potential.
When a paradigm shifts, you cannot ignore change and count on past success. New technology, like the quartz in watchmaking, can revolutionize a market, creating a tectonic shift in accepted practice. The advent of the Cloud is such an advancement in technology and optimization of its capability – the new paradigm. Technological developments, constricted budgets, and the need for flexible access have led to an increase in business demand for cloud computing. Many organizations are still wary of cloud services, however, due to apprehensions around security issues. There is a real concern across the globe about the accelerated rate that companies are moving information to the cloud and the subsequent demise of physical boundaries and infrastructure. How organizations evaluate Cloud Service Providers (CSPs) has become key to maximizing that optimization. CSA STAR Certification has proven to be the security standard of excellence in the cloud security market.
In this first of three modules being offered by the co-authors of CSA STAR Certification – The British Standards Institution (BSI) and The Cloud Security Alliance, you will learn the history behind the vision and take the journey down the road to the certification, but more importantly review data on how it helps organizations optimize processes, reduce costs and meet the continuing rigorous international demands on cloud services.
Presenter: Doug Lane, Vaultive
Date: Feb 17th–9:00am PT (5:00 GMT)
Microsoft Office 365 adoption skyrocketed in 2015, but security and compliance questions are still keeping many organizations on the sidelines. What built-in security features does Microsoft provide, and under what circumstances are they good enough? Which industries and use cases call for a third party Office 365 security solution? Join us as we discuss these questions and provide an overview of the state of Office 365. You’ll walk away with everything you need to jump start your Office 365 security planning efforts in 2016.
The dynamic world of cybersecurity continued its rapid pace of change in 2015, creating new challenges and opportunities for ISACA and our 140,000 global constituents. Of course, 2016 will be no different. ISACA professionals across the globe expect to see an evolving mix of cyberthreats, regulatory issues, and an ongoing shortage of qualified cybersecurity workers needed to address these issues, according to the January 2016 Cybersecurity Snapshot survey.
Nearly 3,000 IT professionals from 121 countries voiced their opinions in the Cybersecurity Snapshot, and the results say much about where cybersecurity is headed in 2016. Respondents said their top cyberthreat concerns for 2016 were social engineering, insider threats and advanced persistent threats (APTs). Fully 84 percent believe there is a medium to high likelihood of a cybersecurity attack disrupting critical infrastructure (e.g., electrical grid, water supply systems) this year. Nearly a third said there will be some increased risk of insider threats (privileged users) vs. last year.
ISACA’s well-trained, knowledgeable professionals do not lack for recommendations on how to best tackle these cyberthreats. Adding two-factor authentication was considered the best response for improving security in the virtualized data center, followed by adding dual-person approvals for certain actions. Other suggested solutions included using a password manager for checking in/out password access to systems, and adding air gaps for different types of workloads (e.g., sensitive or non-sensitive).
Another area where ISACA constituents had consistent opinions involved government regulations and privacy issues. We saw significant activity in these areas in 2015, and I believe we can expect to see more of the same in 2016. A majority (63 percent) of respondents believe governments should not have backdoor access to encrypted information systems. A similar majority think privacy is being compromised by stronger cybersecurity regulations.
From an organizational standpoint, 84 percent favor regulation requiring companies notify customers within 30 days of a data breach discovery. Interestingly, only a third of respondents believe their organization would voluntarily share cyberthreat information if it experienced a breach.
These issues make a strong case for organizations to have certified, well-trained cybersecurity personnel. Finding well-qualified cybersecurity professionals, however, is an ongoing, global issue. Nearly half of global organizations are planning to hire more cybersecurity personnel in 2016, and 94% say they will expect to have a difficult time finding skilled candidates.
Not surprisingly, 81 percent say they would be more likely to hire a cybersecurity job candidate who holds a performance-based certification. That’s where ISACA and Cybersecurity Nexus (CSX) come in.
ISACA launched CSX in 2014 and expanded its certification offerings in 2015 with the introduction of the CSX Practitioner (CSXP) certification. CSXP is a vendor-neutral, performance-based cyber certification—the first of its kind—that focuses on key cybersecurity skills and requires demonstration of skills in a virtual lab environment in the Identify and Protect domains.
CSX has big plans for 2016, kicking off today with the introduction of the Cybersecurity Career Roadmap, which will help cybersecurity professionals identify new opportunities for career advancement. It provides the resources to continuously hone your skills, expand your knowledge, and start (and keep) your career on a trajectory toward achieving your goals.
ISACA is committed to all four of its core focus areas— audit/assurance, governance, risk and cybersecurity—and we will be delivering new resources in all of these areas over the course of the year. There has never been a more challenging or rewarding time to be in our field than right now.
I wish you a happy and successful 2016. It’s going to be an exciting year.
Christos Dimitriadis, Ph.D., CISA, CISM 2015-2016 ISACA International President