Gearing Up for the Collegiate Cyber Defense Competition

It’s that time of the year when we get to root for our alma mater or favorite college competing in the Collegiate Cyber Defense Competition (CCDC). This year, Palo Alto Networks is supporting all 10 regional competitions, and the national competition, through the donation of our next-generation firewall, which CCDC teams will use to defend their networks. The Academy Team has set up a Moodle training course for competing teams to learn how to deploy and configure our next-generation firewall to defend their competition networks. Currently, there are more than 800 participants from CCDC teams on our Moodle training site. We also have teamed with the Network Development Group to provide CCDC competing teams with access to our NETLAB+ VM-100 lab pod. Teams are accessing these resources now to prepare for this competition.

Just like the “Sweet 16,” the winning team at each of the regional competitions goes on to compete in the National CCDC, where the winning team is crowned the national champion. This year, the national competition will take place from April 13 to 15, 2017 in the Henry B. Gonzalez Convention Center in San Antonio, Texas.

The national CCDC website includes the mission of the program and a brief description of the competition framework: “CCDC competitions ask student teams to assume administrative and protective duties for an existing “commercial” network – typically a small company with 50+ users, 7 to 10 servers, and such common internet services as a web server, email server and e-commerce site.

Each team begins the competition with an identical set of hardware and software and is scored on its ability to detect and respond to outside threats; maintain the availability of existing services, such as mail servers and web servers; respond to business requests, such as the addition or removal of additional services; and balance security needs against business needs. Throughout the competition an automated scoring engine is used to verify the functionality and availability of each team’s services on a periodic basis, and traffic generators continuously feed simulated user traffic into the competition network.  A volunteer red team provides the “external threat” all internet-based services face and allows the team members to match their defensive skills against live opponents.

When students enter their competition area, they are told they are replacing an IT staff that was fired for negligence and incompetence. As a result, the clients and servers on their networks may be infected with malware and/or configured insecurely, allowing easy access to external attackers. The CCDC competitions last for 20 hours spread over two to three days. The winner of the competition is the team that can keep its services up the longest and scores the highest points for correctly answering the business “injects.”

The competition is organized into color-coded teams. The Blue Team is the student team consisting of five to eight students, two of which can be graduate students; there are multiple such teams in each competition. The Red Team provides the external threat for the Blue Team. Red Team members are usually professional penetration testers. Last year Raphael Mudge, the developer of Armitage for Metasploit, was a Red Team member at the Northeast CCDC. The White Team provides the referees for the competition and generates the business tasks for the Blue Team. At the end of the competition, the White Team determines the winner based on up-time and business inject points. The Orange Team provides customers with whom the Blue Team interacts. The Black Team is responsible for setting up the competition environment for the Blue Team.

Representatives from our Academy and Delivery teams will be at all 10 regional CCDCs in addition to the National CCDC. They will provide technical advice to the competition teams, information about our college internship opportunities, and information about our great academy program. Additionally, Rinki Sethi, our Senior Director of Information Security, will be a member of the White Team at the Midwest CCDC.

Here is the CCDC competition schedule:

  1. Rocky Mountain CCDC, March 10–11, Regis University, Denver, Colo.
    • Regis University
    • Colorado State University
    • Brigham Young University
    • Utah Valley University
    • Southern Utah University
    • LDS Business College
    • Front Range Community College
    • USAF Academy
    • University of New Mexico
    • University of Nebraska/ Kearney
  1. Northeast CCDC, March 17–19, RIT Rochester, N.Y.
    • Champlain College
    • Harvard University
    • Northeastern University
    • Rochester Institute of Technology
    • Syracuse University
    • University at Buffalo
    • University of Maine
    • University of New Hampshire
    • Utica College
    • Westchester Community College
  1. Midwest CCDC, March 17–18, Moraine Valley Community College, Palos Hills, Ill.
    • Participating teams to be announced.
  1. Southwest CCDC, March 17–19, University of Tulsa, Tulsa, Okla.
    • Participating teams to be announced.
  1. Pacific Rim CCDC, March 24–26, Highline College, Des Moines, Wash.
    • Central Washington University
    • Clover Park Technical College
    • Columbia Basin College
    • Green River College
    • Lewis & Clark College
    • Peninsula College
    • Spokane Falls Community College
    • The Evergreen State College
    • University of Idaho
    • University of Washington, Bothell
    • University of Washington, Seattle
    • University of Washington, Tacoma
    • Western Washington University
    • Whatcom Community College
  1. Western Regional CCDC, March 24–26, Cal Poly Pomona, Pomona, Calif.
    • Arizona State University
    • UC Berkley
    • Cal Poly Pomona
    • CSU Northridge
    • CSU San Bernardino
    • Stanford University
    • UC Riverside
    • University of Advancing Technology
  1. At Large CCDC, March 24–26, Online
    • Participating teams to be announced.
  1. Mid Atlantic CCDC, March 30–April 1, John Hopkins University, Laurel, Md.
    • Participating teams to be announced
  1. North Central CCDC, March 30–31 Dakota State University, Madison, S.D.
    • Participating teams to be announced.
  1. Southeast CCDC, April 5–6 Kennesaw State University, Kennesaw, Ga.
    • Participating teams to be announced.
  1. National CCDC, April 13–15, Henry B. Gonzalez Convention Center, San Antonio, Texas
    • The winners from the 10 regional CCDCs.

[Palo Alto Networks Research Center]

Traps “Can Can” Prevent RanRan Ransomware

A recent Unit 42 blog post breaks down the newly identified ransomware “RanRan,” targeting multiple Middle Eastern government organizations. Driven by what appear to be political motives, the RanRan attacker encrypts data until victims make a negative public statement against a particular political leader.

Prevention against ransomware, like RanRan, is possible with Palo Alto Networks Traps advanced endpoint protection. Traps prevents malicious executables with one-of-a-kind multi-method malware prevention, which provides multiple kill points throughout the attack lifecycle.

Reduce the Attack Surface

Traps has a number of features that allow admins to proactively reduce the attack surface, including execution restrictions and admin override policies. Restrictions can be set using rules for folders (like temp directories), external media (such as USB drives), child processes and others.  Admin override policies give admins granular control over which applications should or should not be able to execute.

Superior Threat Intelligence and Automated Prevention

In real time, Traps cross-references our WildFire threat intelligence cloud to determine if the hash has already been identified as malicious elsewhere within the broader Palo Alto Networks community. If the file has been seen before and identified as safe, it proceeds to execute. If the file is identified as malicious, Traps instantly prevents it from executing.

Better Approach to Preventing Unknown Threats

If an executable is unknown, Traps uses static analysis to identify whether it contains malicious characteristics or not. Rather than utilizing a signature-based approach, Traps uses local static analysis to identify malware characteristics derived through machine learning. Should the executable contain malicious characteristics, Traps prevents it from executing.

Verdicts, benign or malicious, are fed back into the threat intelligence cloud so that any other endpoint that tries to execute this file is informed and protected instantly.

 

The Traps multi-method malware and exploit prevention enables protection against known, unknown and zero-day threats, including new ransomware such as RanRan.

Learn more about Traps advanced endpoint protection.  

Ignite ’17 Security Conference: Vancouver, BC June 12–15, 2017

Ignite ’17 Security Conference is a live, four-day conference designed for today’s security professionals. Hear from innovators and experts, gain real-world skills through hands-on sessions and interactive workshops, and find out how breach prevention is changing the security industry. Visit the Ignite website for more information on tracks, workshops and marquee sessions.

[Palo Alto Networks Research Center]

Palo Alto Networks Unit 42 Vulnerability Research March 2017 Disclosures

As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have discovered three code execution vulnerabilities affecting Adobe Flash (APSB17-07) that were addressed in Adobe’s monthly security update release:

  1. CVE-2017-2997: Tao Yan
  2. CVE-2017-2998: Tao Yan
  3. CVE-2017-2999: Tao Yan

For current customers with a Threat Prevention subscription, Palo Alto Networks has also released IPS signatures providing proactive protection from these vulnerabilities. Traps, Palo Alto Networks advanced endpoint solution, can block memory corruption based exploits of this nature.

Palo Alto Networks is a regular contributor to vulnerability research in Microsoft, Adobe, Apple, Google Android and other ecosystems. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing the information with the security community, we are removing weapons used by attackers to threaten users, and compromise enterprise, government, and service provider networks.

Ignite ’17 Security Conference: Vancouver, BC June 12–15, 2017

Ignite ’17 Security Conference is a live, four-day conference designed for today’s security professionals. Hear from innovators and experts, gain real-world skills through hands-on sessions and interactive workshops, and find out how breach prevention is changing the security industry. Visit the Ignite website for more information on tracks, workshops and marquee sessions.

[Palo Alto Networks Research Center]

Connecting Business and IT Goals Through COBIT 5

Business leaders must take accountability for governing and managing IT-related assets within their units and functions just as they would other assets, such as those involving physical plant or human resources.

This is critical as achieving enterprise goals becomes increasingly interconnected with successfully managing and governing its technology. COBIT 5 provides the framework needed to connect business goals with IT goals while utilizing non-technical, business language, as explored in a recent ISACA podcast. John Jasinski, a COBIT certified assessor, discusses the framework’s core principles and enablers, and ways in which enterprises can successfully leverage them.

“The main purpose of the governance of enterprise IT is to achieve strategic alignment of information and related technology with the goals of the enterprise,” Jasinski said. “However, a continuing challenge for enterprises is how to achieve and maintain the alignment as stakeholder needs and enterprise goals change. The COBIT goals cascade provides context, structure and content for consistency of goals and meeting stakeholder needs.”

The COBIT 5 goals cascade provides a model to define and link enterprise goals and IT goals in support of stakeholder needs.

Decisions on how to utilize IT assets and resources should be made by business managers in an overall governance and management context, according to Jasinski. Directors should govern IT through three main tasks:

  1. Evaluate the current and future use of IT;
  2. Direct implementation of plans and policies to ensure the use of IT meets business objectives;
  3. Monitor conformance to policies and performance against the plans.

COBIT 5, which aligns with other relevant standards and frameworks used worldwide, provides a technology-agnostic common language to more effectively address information and cyber security, risk, vendor management, cloud controls and many other challenges faced by enterprises. Distinctions between governance and management also are addressed.

“If you’re looking for context, structure and content to address your biggest digital business challenges and opportunities, you must have an understanding the COBIT goals cascade, enabling processes and the entire COBIT library,” Jasinski said. “COBIT can help you understand how to connect all the dots, and fit the puzzle pieces together. This is important stuff.”

Further ISACA insights on the topic can be found in the white paper, “COBIT 5 Principles: Where Did They Come From?”

Editor’s note: The ISACA Podcast is now available on iTunes, Google Play and SoundCloud. Listen to experts in cyber security, audit, governance and more as they explain the latest trends and issues facing professionals.

[ISACA Now Blog]

Three Questions with Daymond John

Editor’s note: Daymond John, the FUBU clothing founder, Shark Tank reality TV judge and a self-made multimillionaire, will deliver the closing keynote address at ISACA’s North America CACS 2017 conference, which will take place 1-3 May in Las Vegas, Nevada, USA. John visited with ISACA Now about what innovation means to him, his approach to taking business risks and the Shark Tank experience. The following is an edited transcript:

ISACA Now: The word ‘innovative’ is thrown around a lot. What does that mean to you, and in what ways has that kind of mindset allowed you to achieve such a high level of success with FUBU and your other ventures?
Innovation is the process of creating something new, which oftentimes is just a newer version of something that already existed. For example, to me, Twitter was a note on a pigeon’s leg hundreds of years ago. It’s just a new form of delivery.

There’s a huge misconception about innovation, which is that it starts with some grand idea. The truth is that it typically begins with people collaborating and working together on ordinary ideas that transform into something innovative.

When I started FUBU, I didn’t put three sleeves on my T-shirts. I didn’t start trying to be “innovative.” I just did what I could with what I had, and the brand became more than what even I imagined it could be.

ISACA Now: What advice would you give somebody who has a business idea that he or she is excited about but is nervous about taking that entrepreneurial plunge?
Take affordable steps. You don’t need to take great leaps of faith. Again, start with whatever you can afford to lose.

The idea is not to get over your fear of taking a plunge – it’s not to take a plunge at all. Baby steps; that way, you don’t hurt yourself too much when you run into problems. That way, you can survive your mistakes and live to take another step.

ISACA Now: What has it been like to be involved with Shark Tank, and what aspects of the show do you think resonate most with viewers?
It has been a great learning experience for me. I learn as much from the entrepreneurs as they learn from me sometimes.

What resonates with people? I think the show illustrates that the American Dream is still achievable. It shows that ordinary people can do extraordinary things if they’re willing to act on their ideas.

[ISACA Now Blog]

English
Exit mobile version