What is Automated Cybersecurity?

These days, cyberattacks are heavily automated by machines. If organizations try to defend against these attacks manually, the fight becomes man versus machine, with highly unfavorable odds for the organization. To successfully protect against automated attacks, it is essential to fight fire with fire – or in this case, machine against machine – by incorporating automation into cybersecurity efforts. Automation levels the playing field, reduces the volume of threats, and allows for faster prevention of new and previously unknown threats.

Many security vendors look at automation as a way to become more efficient and a means to save in manpower or headcount. However, automation is a tool that can, and should, be used to better predict behaviors and execute protections faster. If implemented appropriately and with the right tools, automation can prevent successful cyberattacks. The following are four ways automation should be used:

1. Correlating Data
Many security vendors collect substantial amounts of threat data. However, data provides little value unless sense is made of it – with actionable next steps. First, organizations need to collect threat data across all attack vectors and security technologies within their own infrastructure, as well as global threat intelligence. They need to identify groups of threats that behave the same way within that large amount of data and predict the attacker’s next step; combined with dynamic threat analysis, this is the only way to accurately detect sophisticated and never-before-seen threats. When it comes to sequencing, the more data the better. Groups identified from small amounts of data might be considered a mistake or an anomaly. The amount of data needs to be large enough, and analysis must have enough compute process to scale. This can’t be done manually, and organizations that attempt to do so learn that it takes a significant amount of time and resources, and it is impossible to scale to meet today’s threat volume. With machine learning and automation, data sequencing can become faster and produce more effective and accurate threat analysis results.

2. Generating Protections Faster Than Attacks Can Spread
Once a threat is identified, protections need to be created and distributed faster than an attack can spread in the organization’s networks, endpoints or cloud. Because of the time penalty that the analysis adds, the best place to stop the newly discovered attack is not at the location where it was discovered but, most likely, at the attack’s predicted next step. Manually creating a full set of protections for the different security technologies and enforcement points capable of countering future behaviors is a lengthy process that not only moves slowly but also is extremely difficult when correlating different security vendors in your environment and not having the right control and resources. Automation can expedite the process of creating protections without straining resources, all while keeping pace with the attack.

3. Implementing Protections Faster Than Attacks Can Progress
Once protections are created, they need to be implemented to prevent the attack from progressing further through its lifecycle. Protections should be enforced not only in the location the threat was identified but also across all technologies within the organization in order to provide consistent protection against the attack’s current and future behaviors. Utilizing automation in the distribution of protections is the only way to move faster than an automated and well-coordinated attack, and stop it.

With automated, big data attack-sequencing and protections — generation and distribution — you are more accurately able to predict the next step of an unknown attack and move fast enough to prevent it.

4. Detecting Infections Already in Your Network
The moment a threat enters the network, a timer starts counting down until it becomes a breach. To stop an attack before data leaves the network, you have to move faster than the attack itself. In order to identify an infected host or suspicious behaviors, you are required to be able to analyze data from your environment, backward and forward in time, looking for a combination of behaviors that indicate a host on your environment has been infected. Similar to analyzing unknown threats attempting to enter the network, manually correlating and analyzing data across your network, endpoints and clouds is difficult to scale. Automation allows for faster analysis and, should a host on your network be compromised, faster detection and intervention.

Attackers use automation to move faster and constantly deploy new threats. The only way to keep up and defend against these threats is to employ automation as part of your cybersecurity efforts. Integrating automation provides significantly stronger security and has the added benefit of using your manpower more effectively. A next-generation security platform automatically and rapidly analyzes data and turns unknown threats into known threats, creates an attack DNA, and automatically creates and enforces a full set of protections throughout the organization to stop an attack from successfully progressing through its lifecycle.

Learn more about our next-generation security platform and how to protect your environment.  

[Palo Alto Networks Research Center]

2017 Cybersecurity Predictions: Price of Ransomware Continues to Increase in Asia-Pacific

2016 was a challenging year for organisations particularly as cyber adversaries achieved high-profile success, mainly with ransomware. Organisations in Asia-Pacific are no exception. The year also taught a valuable lesson that no industry vertical is safe; if there is a hole in your security, a determined adversary will find it.

2017 should be an opportunity for organisations to instigate a regular program of security risk assessments to stay ahead in cybersecurity. New technologies and ever-increasing levels of connectivity are transforming businesses and unlocking business development opportunities across the region.

Being aware of security concerns doesn’t mean avoiding new technology altogether. It’s about being sensible and trying to stay ahead of cybercriminals by understanding current and potential threats and what can be done to mitigate the risk.

What are my predictions for Asia-Pacific in 2017?

1. Industrial control systems may turn against you

Industrial control systems (ICS) are an integral part of any business, especially in Asia-Pacific. These include building management systems, heating ventilation and air conditioning (HVAC), and security doors, just to name a few.

Most businesses outsource their building management requirements so they don’t necessarily know whether the third-party provider has adequate security in place. It’s not impossible for a malicious actor to execute an attack that could cause significant damage.

For example, an attacker could turn the heating up in a company’s server room or data centre to 50°C and then disable all the building access points so no one can get in to physically remove hardware to a safer location. The hardware would eventually overheat, causing significant disruption to a business, its customers and its partners.

What you need to consider:

  • When you think about it, nearly all businesses could be at risk of an attack like this. Business leaders have to consider security beyond the basic steps of protection. Organisations need to gain an overarching view of their potential weak spots through third parties as well as their own network. Additionally, they need to put a plan in place that would help counter any potential attacks.
  • Have you checked what non-IT equipment your business depends on and what security they have enabled? Are they connected to the internet, managed by a third party?
  • When outsourcing to a third party, what level of security assurance do they have in place? Are they able to provide information to you on how they secure themselves and, ultimately, how they secure and manage your network and systems?

2. The Internet of Things (IoT) devices will be a target for cybercrime

Market research firm Gartner predicts that the number of connected ‘things’ will rise from 6.5 billion in 2015 to almost 21 billion by 2020. This will result in better customer experiences, with connected devices providing information on everything from when the brakes on a bus need to be replaced to whether all the machines on a mine site are running within acceptable parameters.

However, connected devices will also be a target for cybercrime, even more so because people place enormous trust in third-party vendors being safe. These endpoint devices provide thousands of potential entry points to an organisation’s network. They need to be secured. In 2016, we saw the first real challenges appear where compromised devices were connected together in a botnet to launch attacks against banks and key parts of the internet infrastructure.

Anything that you connect into your computer or network is a potential risk. The types of devices range from CCTV cameras to tiny sensors attached to complex machinery, and they may not always be top of mind for security professionals. But if they are connected to the internet or managed by a third party, then they could put the business at risk.

Committed cybercriminals will use every trick in the book and be creative in trying to access the information they want, and look at what ways they can gain entry.

What you need to consider:

  • It is important to understand that the IoT is not a possibility or a project of the future – it is a current reality. Make a point to ask suppliers involved in security assurance how they can assure the security of the devices they provide. As we have seen many times, there may be no security, or the devices could be using some default username or password. These should be changed from the moment they are on your network.
  • Any devices using factory settings for security are simply asking to be compromised. IT managers must change those standard administrator passwords to avoid being targeted.
  • These devices should also be regularly checked to see if they adhere to the company’s security policy.

 

3. We may see a ransomware vortex with a nasty surprise

Ransomware involves attackers locking up a business’s data and demanding a ransom for its release. If you thought 2016 was bad for ransomware – where attackers access data and ransom it back to the victim – then 2017 will be worse. We can expect to see a higher attack volume, using more sophisticated technologies. If the discovery of Locky ransomware was anything to go by, financial malware will continue on an upward trajectory in 2017.

The kicker will be that, because enterprises and individuals have previously paid, more than likely the prices will increase. There have been cases where the ransom was paid, the data was unlocked, and then the victim was hit again. Paying to unlock one or more machines in your organisation doesn’t provide immunity from a threat that could be spreading in your environment. Our advice has always been: don’t pay.

What you need to consider:

  • If you have fewer than 72 hours to respond, do you have a comprehensive backup strategy and response ready to counter these attacks?
  • When was the last time you tested and verified the backup?
  • Have you applied basic file blocking to prevent threats from entering your organisation? Certain file types can be a risk to your organisation. Ask yourself, “Should we allow all files or should we manage the risk by not allowing malicious files types that may cause an issue?”

 

4. We will have serious data trust issues

People will continue to be too trusting or fooled into thinking something is safe when it really isn’t. For example, confidential data can be exposed, or made available, that looks like it comes from an organisation, when it was actually planted by a malicious party. Either way, there’s a business reputational risk and a monetary price to pay.

For years, information security professionals have been focused on a model known as the CIA triad, which looks at Confidentiality, Integrity and Availability and is designed to guide policies for information security within an organisation. Many organisations have long looked at confidentiality as a means to protect their data from theft or availability as a means to ensure they can access their data or systems, but how much time has been spent focusing on the integrity of the data or systems?

Imagine a data project, years in the making, where the data an organisation has been collecting and analysing is corrupted. For example, a resource company that has invested heavily in research and development is prospecting for the next drill site where they collect petabytes of data, but an attacker manipulates the information, rendering it worthless. If the integrity of the data is manipulated, where a few bits of information are changed, the company might drill in the wrong spot, wasting time and money and potentially creating an environmental disaster. This could cause companies to make incorrect decisions with significant ramifications. The same could be said about cases where systems have been wiped after an attack, removing all traces that it happened.

Another frightening example is personalised medicine, where the genetic makeup of a person is known and so well-understood that, rather than doing trial and error on which medication works, doctors can tailor exactly the right mix and dosage. If an attacker changed the data on a program such as this, it not only has an impact on the effectiveness of the drug but also could have a lasting negative impact on patient, or even threaten their life, so the stakes are incredibly high.

So What Can Be Done?

Firstly, any business should welcome these changes as they are a way to further digitise services and enhance our way of life. But with any move to further digitising services that we offer or are offered to us, we need to ensure that the data is protected. Verification should be at the centre of all platforms, at every stage of development, and at the core of every provider-customer relationship. Its integrity must be protected from being modified by unauthorised parties. Data must only be made available to authorised parties to access the information when needed.

What you need to consider:

  • Businesses need to look at two key things: where their sensitive data resides and what data is critical to the business to operate. Somewhat surprisingly, many organisations struggle to answer this question. This can lead to misappropriation of resources in the form of security controls being used broadly across the entire organisation, rather than being targeted to where they’re needed most. This then results in increased cost to acquire and use security measures.
  • Who amongst our employees has access to our sensitive data? Simply knowing who has access to documents or big data stores stops short of understanding to what they have access.
  • A key way to reduce risk to sensitive information is to also understand how the data is protected. Is there protection in place, and does it meet the right level to mitigate risk for something that could be mission-critical to a business?

What are your cybersecurity predictions for 2017? Share your thoughts in the comments.

[Palo Alto Networks Research Center]

2017 Cybersecurity Predictions: Machine Learning and AI-Driven Frameworks Shape Cloud Security

This post is part of an ongoing blog series examining “Sure Things” (predictions that are almost guaranteed to happen) and “Long Shots” (predictions that are less likely to happen) in cybersecurity in 2017.

Here’s what we predict for cloud in 2017:

Sure Things

A multi-cloud, hybrid security strategy will be the new normal among InfoSec teams

In the last few years, the digital footprint of organizations has expanded beyond the confines of the on-premise data center and private cloud to a model that now incorporates SaaS and public clouds. To date, InfoSec teams have been in a reactive mode while trying to implement a comprehensive security strategy across their hybrid architecture. In 2017, we will see a concerted effort from InfoSec teams to build and roll out a multi-cloud security strategy geared toward addressing the emerging digital needs of their organizations. Maintaining a consistent security posture, pervasive visibility, and ease of security management across all clouds will drive security teams to extend their strategy beyond security considerations for public and private clouds and also focus on securely enabling SaaS applications.

Shifting ground within data privacy laws will impact cloud security choices

Cross-border data privacy laws play a significant role while considering cloud computing options for organizations across the globe. With recent developments, such as Brexit and the expansion of cross-border data flow restrictions in Asia-Pacific, IT security leaders will look for flexibility and adaptability from their cloud security vendors in 2017. Cloud security offerings need to address the diversity among clouds, enforce consistent security policy, and adapt to the data privacy laws of the resident nation-state. The WildFire EU cloud is a great example of enabling regional presence to comply with local data residency requirements. It is a global, cloud based, community-driven threat analysis framework that correlates threat information and builds prevention rulesets that can be applied across the public, private and SaaS footprint of organizations based out of Europe.

Large-scale breach in the public cloud

The excitement and interest around utilizing the public cloud reminds us of the early days of the Internet. Nearly every organization we talk to is using or looking to use either Amazon Web Services (AWS) or Microsoft Azure for new projects. And it is based on this observation that we predict a security incident resulting in the loss of data stored in a public cloud will garner international attention. The reality is that, given the volume of data loss over the past year, one or more successful breaches has likely occurred already, but the specific location (private, public, SaaS) of where the data was located is rarely, if ever, disclosed. But that is bound to change as more companies move their business-critical applications to the public cloud.

The basis of the prediction is twofold. Public cloud vendors are more secure than most organizations, but their protection is for underlying infrastructure, not necessarily the applications in use, the access granted to those applications, and the data available from using those applications. Attackers do not care where their target is located. Their goal is to gain access to your network; navigate to a target, be it data, intellectual property or excess compute resources; and then execute their end goal – regardless of the location. From this perspective, your public cloud deployment should be considered an extension of your data center, and the steps to protect it should be no different than those you take to protect your data center.

The speed of the public cloud movement, combined with the “more secure infrastructure” statements, is, in some cases, leading to security shortcuts where little to no security is being used. Too often we hear from customers and prospects that the use of native security services and/or point security products is sufficient. The reality is that basic filtering and ACLs do little to reduce the threat footprint, whereas opening TCP/80, TCP/443 allows nearly 500 applications of all types including proxies, encrypted tunnels and remote access applications. Port filtering is incapable of preventing threats or controlling file movements, improving only slightly when combined with detect and remediate point products or those that merely prevent known threats. It is our hope that, as public cloud projects increase in volume and scope, more diligence is applied to the customer piece of the shared security responsibility model. Considerations should include complete visibility and control at the application level and the prevention of known and unknown threats, with an eye toward automation to take what has been learned and use it to continually improve prevention techniques for all customers.

Long Shots

Autonomic Security: Rise of artificial intelligence and machine learning-driven security frameworks

2016 introduced self-driven cars and selfie drones to consumers. The technology behind these innovations was heavily driven by artificial intelligence (AI) and machine learning (ML). AI and ML usage within cybersecurity is not new. Cybersecurity vendors have been leveraging them for threat analysis and big data challenges posed by threat intelligence. But, the pervasive availability of open source AI/ML frameworks and automation simplicity associated with them will redefine the security automation approaches within InfoSec teams. Today, security automation is about simplifying and speeding up monotonous tasks associated with cybersecurity policy definition and enforcement. Soon, artificial intelligence and machine learning frameworks will be leveraged by InfoSec teams for implementing predictive security postures across public, private and SaaS cloud infrastructures. We are already seeing early examples that reflect the above approach. Open source projects, such as MineMeld, are shaping InfoSec teams’ thinking on leveraging externally sourced threat data and using it for self-configuring security policy based on organization-specific needs. In 2017 and beyond, we will see the rise of autonomic approaches to cybersecurity.

Insecure API: Subverting automation to hack your cloud

Application programming interfaces (APIs) have become the mainstay for accessing services within clouds. Realizing the potential problems associated with traditional authentication methods and credential storage practices (hard-coded passwords anyone), cloud vendors have implemented authentication mechanisms (API keys) and metadata services (temporary passwords) as alternatives that streamline application development. The API approach is pervasive across all cloud services and, in many cases, insecure. It provides a new attack vector for hackers, and in 2017 and beyond, we will hear about more breaches that leverage open, insecure APIs to compromise clouds.

What are your cybersecurity predictions around cloud? Share your thoughts in the comments and be sure to stay tuned for the next post in this series where we’ll share predictions for Asia-Pacific.

, and

[Palo Alto Networks Research Center]

Fishing vs. Hunting for an IT Assurance Job

The Internet is awesome, isn’t it? At any moment, you have the ability to see hundreds of job postings and post your resume for all to see. However, if the only thing you are doing to find a job is fishing by dropping your resume “lure” in the water hoping for a hiring manager to bite, you will be waiting a while.

You need to get out and hunt for your next job. Know the terrain, have spotters in the field, pick the right tree to sit under. Truth be told, I know nothing about actual hunting but, after nearly 10 years of helping IT assurance professionals find new opportunities, I know a few things about hunting for a job.

Here are my top three tips:

Don’t Post Your Resume Online
Monster, CareerBuilder, Indeed, Dice; I have nothing against these services, but you are not their target audience. If the service is free, you are the product, right? The main problem with posting online using these types of sites is that you immediately lose control over where your resume ends up.

One of the pitfalls of the typical recruiting firm is what I call the shotgun approach. They fire your resume in every direction to every client they have, hoping that someone will want to interview you. Now you are faced with a potential situation where your resume is in front of a hiring manager (if it makes it there, more following) from multiple sources, and you start to look desperate.

There are ways you can safely post your resume online anonymously. But, it is hard to do, and even the most “scrubbed” resume can still be figured out. (Word document author metadata, anyone?) Yes, I even see professionals in the information security space get it wrong. It is safer just not to mess with it.

Instead:

Use Your Relationships
The common belief is that only a small percentage of jobs are actually posted online. Not sure if that is completely true anymore, but I can tell you that most hiring managers have an idea of who they want to hire long before the posting goes up. You want to be the person they think of.

Make sure your personal brand in the marketplace is a positive one. I am always surprised at just how small our IT assurance world is. Make sure people know you for being honest, self-motivated, dependable and collaborative, and word will start to spread about the positive impacts you have had on your organization. Be intentional about networking. Seek out people at ISACA events who work at companies you are interested in. Don’t just add people on LinkedIn, take them to coffee. Make relationships and use them.

Applying Directly Online
It should be your very last option. I’m not telling you to never apply online. What I am saying is use what I’m about to tell you first, and if you still come up empty, that is the only time I would suggest applying directly online. The companies that pay to advertise their job openings will not even be upset at this. Their goal is to make sure they see qualified candidates, and if you became aware of their opening through their online listing, then their money was spent wisely.

I hear it all the time: “I applied to this job online but never heard anything back.” I know for a fact that job-seekers who could have gotten the job they applied for do not get contacted at all because the resume never makes it to the right person. Most companies have talent acquisition teams with increasingly complex systems that are heavily dependent on keyword filtering. I don’t blame HR or talent acquisition teams for wanting to use these filters. Their job is tough. They have to work on potentially hundreds of jobs at the same time. They can’t possibly dig into the level of detail it would take to understand what it takes to be successful in an ISACA-related position.

Applying to a job without an external or internal advocate will more than likely result in silence. You need someone who knows your values, personality and skill set who can help you get visibility with the hiring manager, the real decision-maker in the hiring process. It all comes back to reputation and relationships.

This is just the very tip of the iceberg on how to successfully navigate an IT assurance job hunt, and the first in a series of ISACA Now blog posts I am planning on IT assurance interviewing and hiring. If you have additional questions or a topic you would like to see discussed in the future, feel free to post them in the comments section.

Author’s note: What tips for successful job hunting have I missed? What is the best or worst piece of job search advice you have ever been given?

Brad Owens, Recruiting Director, Duval Search

[ISACA Now Blog]

SamSa Ransomware Attacks: A Year in Review

In March of this year, Unit 42 investigated the SamSa actors that were attacking the healthcare industry with targeted ransomware. With this group being active for roughly one year, we decided to revisit this threat to determine what, if any, changes had been made to their toolset. In doing so, we discovered that it’s been a very profitable year for SamSa, with an estimated $450,000 in ransom payments from samples we have identified. This blog serves to discuss changes made by this group and the SamSa malware family since we last discussed them.

Updates to Malware Toolset

In the past 12 months, Unit 42 has collected and analyzed 60 unique samples that have been identified as belonging to the SamSa malware family. SamSa has a very small number of samples overall when compared to more common ransomware families such as Locky, Cerber, and CryptoMix. This is simply a byproduct of the targeted nature of SamSa, which targets specific organizations instead of a wide number of Internet users.

During the past 12 months, a number of changes were made by the authors to make analysis and reverse-engineering more difficult. While we classify all of these samples as “SamSa,” the attackers have used various names to identify their projects. The following chart shows the various internal .NET project names used by SamSa from December 2015 until November of 2016.

Figure 1 Versions of SamSa Ransomware over time

The following list of internal .NET project names were witnessed, in order:

  • samsam
  • MIKOPONI
  • RikiRafael
  • showmehowto
  • wanadoesme
  • wanadoesme2
  • gonomore
  • gotohelldr
  • WinDir

The majority of the name changes took place after April of this year. When discussing changes made internally to the code base, we witnessed the following events since we last discussed SamSa:

Figure 2 SamSa modifications over time

  1. A number of internal .NET name changes, starting with RikiRafael.
  2. A number of changes to the encrypted filename extensions used after encryption took place.
  3. Changes to the format of the encrypted file header.
  4. Modifications to the dropped helper HTML file that informs the victim of what has occurred.
  5. Different temporary folder names used to hold SamSa while it is running.
  6. Encryption of embedded strings using the AES-128 algorithm.
  7. Internal PDB debug strings obfuscated.
  8. Internal PDB debug strings removed altogether.

Profits

When we originally discussed SamSa, there were confirmed profits of $70,000 for the threat actors, with estimates by other researchers as high as $115,000. Unlike most ransomware, SamSa ransomware executables often contain the Bitcoin Wallet address victims are supposed to use to pay the ransom. Since March 24th 2016, we’ve witnessed 24 unique SamSa samples containing 19 unique Bitcoin (BTC) addresses. This allows us to monitor the blockchain for transfers to those wallets and identify ransom payments.  In one unusual case, we saw a version of SamSa where the BTC address was input as a second argument, preventing us from seeing what payment, if any, was received by the actors. This not only makes tracking monetary payments extremely difficult, but also is yet another example of how the SamSa actors take a very targeted approach to their victims, generating unique data for each victim they infect.

Of those 19 unique BTC addresses we observed since March 24th, 14 of these have received payments totaling roughly 394 BTC. Prior to March 24, 2016, we observed roughly 213 BTC received, giving us a total of 607 BTC received by the SamSa actors. Using today’s current BTC rate of $744.43, this allows us to estimate that the attackers have obtained roughly $450,000 since their operations began. It’s important to also note that there are likely a number of samples that exist, which we were unable to obtain, causing the actual figure to likely be much higher. A visual of the money obtained by the SamSa actors can be seen in the following figure:

Figure 3 SamSa BTC profits over time

As we can see, there is a large gap in between June and September of 2016. This is most likely due to the sample set used during research, as there were only a few samples obtained in recent months.

Conclusion

In the past year, the SamSa actors have showed no sign in stopping their attacks. They’ve successfully compromised a number of organizations, and continue to reap significant rewards for their efforts. In the past year alone, they’ve collected an estimated $450,000 from their scam. As the group continues to make money, it is unlikely we shall see them stop in the near future. Palo Alto Networks customers are protected from this threat via the following ways:

  1. All malware is classified as malicious in WildFire.
  2. Domains used by SamSa have been flagged as malicious in Threat Prevention.
  3. AutoFocus users can track this family using the SamSa tag.

A full list of indicators of compromise (IOCs) related to SamSa can be found here.

[Palo Alto Networks Research Center]

English
Exit mobile version