Palo Alto Networks Day Japan 2017: Evolving Cybersecurity Efforts to Increase Trust in the Digital Age and Prevent Cyberattacks

Palo Alto Networks Day 2017, our third annual global cybersecurity conference in Japan, was a great success, attracting over 2,600 registrations. The number of attendees has more than doubled each year of the conference; and the spike in attendance reflects growing interest in cybersecurity updates on next-generation technology, the current cyberthreat landscape, Japan’s cybersecurity policy, cloud and IoT security, and the protection of critical infrastructure. Keynote speakers repeatedly referred to the importance of agility, automation, and cyberthreat intelligence sharing.

Mark McLaughlin, chief executive officer and chairman of Palo Alto Networks, emphasized in his keynote that we live in the digital age, meaning our businesses rely on digital technologies to increase our productivity on a global basis. Adversaries are taking advantage of the declining costs of launching automated cyberattacks and are doing so at high speeds, whereas defenders are suffering from the growing complexity of cyberthreats and depend on manual responses. This can lead to eroding trust and decreasing productivity. That is why there has been an increased focus on cybersecurity platforms over the last ten years to pursue automation, innovation, orchestration, and cyberthreat intelligence sharing to prevent successful cyberattacks.

No single company can address all of the complexities of cybersecurity and be responsible for all the innovations needed to secure the digital age. The market finds it challenging to access and absorb the latest solutions. Mark shared an example of the disruptive evolution of cybersecurity solutions to address these issues: Palo Alto Networks Application Framework. This offering was launched four months ago to allow any vendor to develop applications for the framework and access a massive amount of data. Users do not need to deploy anything to their environment. All they have to do is turn on the application they want to use. As of today, more than 30 vendors contribute to the Application Framework, and we expect this community of developers to grow.

We also heard from an end-user company, Recruit Technologies Co. Ltd., who shared their IT and cybersecurity journey from the last few years. They consolidated their data centers, increased automation, and shifted from private to public cloud for agility and flexibility. Mr. Hiroshi Hoshina, IT Solutions Control division from Recruit Technologies, explained how his company uses access control, segmentation, and Palo Alto Networks products to enhance their cybersecurity. While network infrastructure used to only focus on its functions and operational stability, consumers now demand more agility after the invention of virtual technologies, and software-defined agility is more appreciated.

We also had two researchers from Unit 42, our threat intelligence team, speak about the current cyberthreat landscape. Brad Duncan shared his observations of the wide-scale distribution of information-stealing malware and ransomware, and encouraged the audience to apply such best practices as patching, regular backup, and browsing restrictions.

Kaoru Hayashi acknowledged the steady growth of cyberthreats, tactics, and tools, and culprits have been able to create an underground ecosystem to divide their work roles and take advantage of online anonymity, and automated and cheap technologies, to launch various attacks. He emphasized that cyberattackers have to be successful all the way through their attack lifecycle to achieve their malicious goal, and defenders need to utilize cyberthreat intelligence to cripple their malicious intent and moves at any of the attack lifecycle stage before they succeed. Without cyberthreat intelligence, leadership can neither elucidate what risks their organization currently faces nor decide on what needs to be done. Organizations need technologies, automation to share cyberthreat intelligence effectively, and people who understand the importance of such intelligence to bridge the gap between engineers and leadership.

Palo Alto Networks would like to thank all of the attendees, speakers, and our sponsors for your contributions to increasing cybersecurity awareness, and for making this a successful event. We look forward to welcoming you all back to Palo Alto Networks Day 2018 in Tokyo next year!

[Palo Alto Networks Research Center]

No End in Sight for Impact of Equifax Breach

It is a terrible time for privacy in the United States. There are very few institutions that we entrust to hold nearly all our financial records, and one of them, Equifax, admits to losing them.

The full impact of the breach will be felt over time, and right now nothing has changed in our lives besides a new worry and uncertainty. Perhaps, like with other breaches such as Anthem and Yahoo, we will have to live in fear for decades with not yet having felt the direct impact.

However, I would argue that Equifax has a potential to be the most impactful breach to its victims. The repositories of data that include personal, financial and confidential information will not dissipate easily over time. Unlike with many medical conditions, or simply stolen passwords, victims of financial and personal information theft do not get better. We can’t escape our credit history and financial situation, so the abusers of the stolen data will be able to pursue us through the years.

How did it happen? We do not have all the details, but one may argue that an organization charged with holding this type of data would not fall to an attack vector that was a known problem for half a year prior. Even with that vulnerability, a breach of a single website should not lead to any stolen data. There must be safeguards.

Let’s say a web server was not patched, but it is the job of intrusion prevention systems to detect an exploit. When hackers were roaming free within a compromised server and its databases, where were the security safeguards identifying the abuse? Further, consider that hackers reportedly stole gigabytes, if not terabytes of data. This type of unusual activity should be noticed by the network traffic monitors, and defensive tools.

Yet, Equifax infrastructure allowed for the data theft without much of an alert. And for us, the victims, what’s the recourse? One year of free credit protection from TrustedID service, owned by Equifax? There is something to be said about a company offering protection against identity theft that could not protect its own data. And what happens after one year? Would hackers delete the stolen data, or would they keep abusing the accounts while the victims resort to paying Equifax for a protection service from the loss that it caused?

There is a lot of angst, and confusion, and too many questions that we do not know how to answer. The scariest thing is that we do not know what is coming and how badly this will impact the victims.

The big question still remains: who do we trust with our data? Do we, the consumers, have any say or choice? Should there be government sanctions for these types of events?

As a security professional, I see another lesson in not-so-good security practice. What could have been done to prevent this? What could have been done during the incident response and investigation?

Time will tell if this is the most impactful breach for us, or if this is a scary event from which the stolen data never sees large-scale abuse. Stay tuned.

Editor’s note: Alex Holden will be presenting on optimizing defenses against invisible threats at CSX North America, to be held 2-4 October in Washington, D.C.

Alex Holden, President and CISO, Hold Security, LLC

[ISACA Now Blog]

When It Comes to Crypto, What You Don’t Know Can Hurt You

Most of us have heard the phrase “What you don’t know can’t hurt you.” While this may hold true for some circumstances, in the case of an audit, the opposite is true.

A large part of an auditor’s job is to discover and know about exposures and gaps that could hurt the organizations for which they work. An auditor’s remit includes finding, analyzing and documenting an ever-increasing list of things that organizations don’t know about but have the potential to cause damage.

This task can be harder than it sounds, particularly when it comes to an organization’s use of technology.  Why? One reason is that auditors need to be alert to the specific risks, threats, issues and other problem areas that can arise related to the specific technologies in use. One area that is particularly challenging is the assessment of cryptographic systems: modules, software, and application components that employ cryptography, and the use of cryptography generally throughout the organization.

Several factors make assessing cryptographic systems more difficult than other technologies.  First, it’s ubiquitous – almost every organization (whether it’s known or not) makes extensive use of cryptography to secure everything from data transmissions to employee remote access. Cryptography is used for authentication, to securely store data, and to prove the integrity of that stored data. But despite its ubiquity, it’s a little like the plumbing in our homes: there when we need it, but not something we stop to think about unless something goes terribly, terribly wrong.

Second, cryptographic assessment is not a skill set in which all auditors have extensive experience.  Many seasoned auditors know the fundamentals of how cryptography works, but implementation details, i.e., the mathematics underpinning its operation and the engineering aspects of authoring a library, toolkit, or component, aren’t generally at the top of an auditor’s tool box.

Because many auditors aren’t deep crypto experts and there are few general assessment guides for audit of these systems, cryptographic assessment may get short shrift during audits. This is a potential security concern, because poorly implemented, ill-used, broken, insufficient, or other operationally deficient use of cryptography can represent significant risk to an organization.

Now, this doesn’t mean that every auditor needs to be the next Alan Turing – just like they don’t need to be Brian Kernighan to assess a business application written in C! But many could benefit from having a guide that explains the basics of cryptographic system assessment to help them find and identify potential risk areas; for example, potential implementation issues, best practices, known weak configurations, etc.

To help address this, ISACA has authored Assessing Cryptographic Systems. This free resource provides information to the IT audit community about commonly occurring issues in cryptographic systems as well as one possible methodology to assess the use of cryptography in an organization. As a companion piece, ISACA released a sample security policy, “Sample Policy on the Use of Cryptographic Controls,” that can be adapted by an organization to supplement or refine its existing policy on this important topic.

Please take a look at these resources, and let us know if they helped you with your audit work by leaving a comment on this post.

Diana Kelley, Chief Security Advisor, SecurityCurve

[ISACA Now Blog]

The Farmer and the Equifax

In the wake of major disasters, companies often retrench to their board rooms and ask questions about the state of their own resilience. These questions follow one of two tracks: First is a retrospective post-mortem of their own company, or preferably an affected competitor. It starts with a question like, “How would we be affected or react if this happened to us?”

In the wake of the Equifax consumer data breach, many of the stories in the past days share well-articulated insights that are nonetheless written with that full 20/20 hindsight in play. There even is evidence that Equifax itself took this path two years ago in the wake of the Experian data breach. While well-intentioned, this hindsight-driven approach is fundamentally flawed.

When penning an article or responding to a board question post-mortem, we are afforded luxuries that our disaster-distressed selves would not be afforded in a real scenario. For example, compare your mental state now versus in a true disaster – the shock and suddenness (then) vs. the quiet reflectiveness (now). One of the greatest underestimations of post-mortems is the effect of imperfect and often conflicting information during a live, unfolding crisis. To illustrate this, consider the following three fictitiously timed statements:

If your blood pressure progressively elevated from “slight nuisance” to “we may lose our company,” then you’re likely in good company with Equifax’s executives as they gleaned more information about the incident from the initial discovery until today. It is much easier to think about your actions for Day 0 when you know what Day 20 looks like, but we almost never do.

Anyone who has read a post-mortem report, though, will attest that it is unlikely that the report captures the nuances of timing and progressive urgency. Instead, the report highlights the diseased final state and what the company should have done to protect itself in the first place, often forgetting about all the other possible infections that could be acquired.

So, if studying Equifax and gleaning lessons learned, even in light of the little we know, is an easy but relatively unproductive sport for our own resilience, what is the alternative?

The second track is the one that we advocate for in our trainings with executives and boards. This track makes a much more natural supposition about the state of risk in cyber security. Instead of assuming perfect hindsight about random one-off events, let’s instead suppose that Equifax treated cyber risk much the way weather risk is accounted for by a large farming cooperative. Our assumptions regarding cyber threats would instantly shift from being unknown and one-off to mitigatable risks.

Figure 1—Cyber risk is an influencer to traditional enterprise risk categories

Farmers understand that crops are their most important assets. They understand and monitor any threats, from weather to insects to hungry predators that might affect those crop assets. They also know the vulnerabilities that their particular crops, in their particular locations, have compared to those of other farmers in other locations, and they have people at the ready to mitigate the impact to their farms, should disaster strike.

The Equifax breach will likely change many upcoming boardroom agendas and spur more communications about cyber breaches among senior executives. Executives, security professionals, and the public at large should then take this opportunity to think about what their most important crops are, what true vulnerabilities exist in them, and learn better how to mitigate against those risks.

Amjed Saffarini, CEO of CyberVista

[ISACA Now Blog]

English
Exit mobile version