New COBIT 5 Book Helps Enterprises Realize IT Benefits

When a majority of enterprises report that less than half of their IT initiatives actually deliver the expected business benefits, it is time to take a closer look at what businesses can do to attain those sought after benefits.

Enterprises make investments in technology as part of their daily operations, so the need for business benefits realization from those investments is ongoing. That need—and the general failure of businesses to meet it consistently—is the driving idea behind the creation of COBIT 5 for Business Benefits Realization, a new book from ISACA.

The book details how the COBIT 5 framework can help businesses achieve the benefits from their technology investments as envisioned when those investment decisions were made.

Barriers to IT Benefits
So why are a majority of businesses seeing less than stellar returns from their IT initiatives? The answer lies in three common barriers to benefits realization. First, it is difficult to determine exactly which IT benefits are realized due to the significant lag between the decision to invest in technology and the realization of benefits. Next, common misperceptions can compromise benefits realization. For example, enterprises often believe benefits realization management is a simple, easy process. It is not. Lastly, a paradoxical gap arises between the knowledge of good management practices and the actual application of those practices. Business benefits realization management is no exception.

Drivers to Business Benefits Realization
What actually drives benefits realization? A study by John Ward and Elizabeth Daniel identified the following issues:

  • Complex, sophisticated IT systems and applications require increasing levels of skill to deliver/use effectively.
  • IT industry expectations for proven benefits and time to realize them are unrealistic.
  • Enterprise-wide applications impact a wide range of internal and external stakeholders, and rely on active cooperation to achieve benefits.
  • IS/IT benefits are increasingly diverse and difficult to identify, describe and measure.
  • It is difficult to relate business performance improvements to specific IS/IT projects because they are usually a combination of improved technology and other changes.
  • An increasing focus on short-term financial returns prevents many longer-term benefits of a coherent, sustained IS/IT investment strategy.
  • Benefit reviews are not consistently performed when projects end, so lessons learned are not transferred to future projects.

COBIT 5:  A Framework for Achieving Objectives
As a comprehensive framework that helps organizations achieve their objectives for the governance and management of enterprise IT, COBIT 5 enables businesses to optimize value by balancing benefits realization, risk optimization, and resource use.

COBIT 5 for Business Benefits Realization builds on COBIT 5 by focusing on governance and management of business benefits realization to provide contextualized guidance for consultants, experts in governance and business management, IT professionals, and other interested parties.

The book outlines the key characteristics of effective business benefits realization management, as identified by Steve Jenner and APMG International. They include:

  • Actively searching for benefits versus passively tracking against forecast.
  • Evidence-based forecasting and practices.
  • Transparent forecasting and reporting with a clear line of sight from strategic objectives to business benefits.
  • Forward-thinking that emphasizes learning and continuous improvement.
  • Managing across the full business change lifecycle, rather than as an add-on at the end of a project.

COBIT 5 enables these key success characteristics through its specific governance and management processes, practices and activities that contribute to benefits realization, and risk and resource optimization.

Benefits of COBIT 5 for Business Benefits Realization
COBIT 5 for Business Benefits Realization provides the following benefits:

  • Better understanding of increasingly complex but significant areas of business benefits realization
  • Better understanding of key links between business benefits realization and enterprise and IT strategy, and enterprise architecture
  • Clarity on the application of COBIT 5 governance and management principles to business benefits realization
  • Details on how each COBIT 5 enabler supports business benefits realization
  • Contextual references to industry best practices from leading benefits realization authors and researchers

Members can download the book here.

Peter Tessin, Technical Research Manager, ISACA

[ISACA Now Blog]

The Pervasiveness of COBIT

COBIT—which turned 20 this year— not only has technical value, but is also an enabler that can improve our careers and our networking opportunities.

ISACA offers IT professionals education, conferences and training to take our careers to a higher level. These activities allow us to create and maintain rich professional contacts and, of course, friendships. In my case, ISACA and COBIT allow me to participate in IT governance and management publications, audit conferences and sustainability events.

As a COBIT follower, I think its 20th birthday is a great moment to remember how many projects have been made better because of COBIT. Or, in other words, how pervasive is COBIT?

Assessing, Identifying Organizational Risks
When you are an auditor or information systems professional, you know very well that the use of IT creates risks for your organization. As an auditor, you must assess those risks and identify and review the effectiveness of the controls that are in place to mitigate them. For example, if your business is supported by IT, you must ensure service availability, accurate and timely information, reliable IT and applications controls, physical security, regulatory compliance, competent and motivated personnel, an appropriate decision-making structure, and well-implemented government and management practices.

But when you use COBIT to audit an accounting system, questions arise:  Why are you doing this audit? For what? For whom? Of course, you use it to benefit the company, because you need to know the financial and economic situation, value of their investment, and achieved profitability.

But there are also other stakeholders, including shareholders and banks that invest or lend money, employees and customers providing and receiving services, the state and its watchdogs that ensure transparency and, finally, society in general.

Considering Sustainability and Social Responsibility
At this point, sustainability and social responsibility considerations are added to the mix, and the field of enterprise IT comes to the forefront. What is the primary role of IT? What should it be? How do IT decisions impact the economic, social and environmental aspects of the enterprise? How does IT help in an earthquake? How much does it help children to study, communicate with others, or simply imagine a better future? Can we measure that? Probably, and COBIT can help. COBIT aligns IT with business needs, whatever the business’s mission or core values are. It evaluates, directs and monitors how IT is, and will be, used.

COBIT also allows enterprises to plan, build, run and monitor all IT resources. But its value increases when a life is saved or a planet is protected by specialized or green IT:  As the International Telecommunication Union’s (ITU) 5th Green Standards Week Declaration stated:

Think sustainable:  Bridge the gap between experts from the ICT, environment, urban planning, energy sectors and policy makers, to encourage the integration of ICTs into environmental, urban and energy policies in order to improve knowledge on the catalytic role that information and communication technologies (ICTs) can play in reducing energy consumption, increasing environmental resilience, tackling climate change impacts, and enhancing energy efficiency and promoting a circular economy.”

In other words, COBIT 5:

  • Improves governance:  COBIT 5 ensures that all stakeholders are identified and their needs are evaluated to determine the enterprise’s overall goals and its associated IT-related goals.
  • Improves measurement, monitoring and evaluation systems:  COBIT 5 uses indicators as management tools at various levels and in various sectors to improve monitoring and information systems at different scales.
  • Assesses the roles of public and private actors:  COBIT 5 recognizes different stakeholders with different needs and obligations.
  • Increases the resilience of human and natural systems:  COBIT 5 suggests stakeholder needs are related to sustainability and, thus, allows the use of its goals to cascade to ensure the identification of enterprise goals and the evaluation of possible risks that can hurt their achievement. So, the implemented

IT process will be capable of delivering outcomes even if the risk factors materialize and the conditions are not the best.

What has COBIT done for you and your organization? Please share your thoughts with ISACA’s online COBIT community.

Braga will present Using the COBIT 5 Assessment Program to Improve the Work Process Capability at the 2016 Governance Risk and Control Conference (GRC), 22-24 August 2016, in Fort Lauderdale, Florida USA.

Editor’s note:  The ISACA Now Blog section is celebrating Women in Technology Month throughout June by featuring female bloggers. If you are a female blogger and would like to contribute a blog, please contact us at news@isaca.org.

Graciela Braga, CGEIT, COBIT 5 Foundation Certificate, CSX Fundamentals Certificate

[ISACA Now Blog]

Securing Data In The Data Center: Reducing the Attack Surface and Preventing Threats

Attacks against corporate and government data centers continue to evolve at a substantial rate, and center on three major categories:

  • Cybercriminals attacking retail and commercial enterprises
  • Hacktivists seeking to deface or cause harm to companies to which they’re opposed.
  • State-sponsored attacks targeting government or commercial enterprises.

With Palo Alto Networks® Next-Generation Security Platform you can protect your data center assets with an effective Zero Trust security model and work to achieve the ultimate goal of threat prevention in the data center.

Download our whitepaper to learn more about how to secure data in the data center.

[Palo Alto Networks Research Center]

Palo Alto Networks Researcher Discovers 3 New Critical IE Vulnerabilities

Palo Alto Networks researcher Tao Yan is credited with the discovery of three new critical Microsoft vulnerabilities in June‘s bulletinCVE-2016-3205, CVE-2016-3206 and CVE-2016-3207 — affecting VBScript engine versions 5.7 and 5.8. These vulnerabilities are documented in Microsoft Security Bulletin MS16-069  and MS16-063.

In our continued commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors.

For current customers with a Threat Prevention subscription, Palo Alto Networks has also released IPS signatures providing proactive protection for these vulnerabilities.

Palo Alto Networks is a regular contributor to vulnerability research and has discovered more than 100 critical vulnerabilities over the past two years in the Microsoft, Apple, Android and other ecosystems. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.

[Palo Alto Networks Research Center]

New Sofacy Attacks Against US Government Agency

The Sofacy group, also known as APT28, is a well-known threat group that frequently conducts cyber espionage campaigns. Recently, Unit 42 identified a spear phishing e-mail from the Sofacy group that targeted the United States government. The e-mail was sent from a potentially compromised account belonging to the Ministry of Foreign Affairs of another government entity and carried the Carberp variant of the Sofacy Trojan. The developer implemented a clever persistence mechanism in the Trojan, one which had not been observed in previous attacks. The focus of this blog will be on the attacks and the infrastructure associated with Sofacy using the new persistence mechanism as a correlation point.

The Delivery

On May 28, 2016, attackers sent a spear-phishing e-mail to a U.S. government entity using an email address belonging to the Ministry of Foreign Affairs of another country. Analysis of the attack revealed a high likelihood that the sender’s email address was not spoofed and is instead a result of a compromised host or account belonging to that Ministry.

The targeted email had a subject of “FW: Exercise Noble Partner 2016”, which is a reference to a joint NATO training effort between the United States and Georgia. The email contained an RTF file as an attachment, with the filename “Exercise_Noble_Partner_16.rtf,” reflecting the same training exercise. We have also seen related delivery documents with filenames that have a Russian military theme (Putin_Is_Being_Pushed_to_Prepare_for_War.rtf and Russian anti-Nato troops.rtf), purportedly targeting organizations in Poland according to a blog published byPrevenity.

The RTF file is a weaponized document that attempts to exploit CVE-2015-1641 to drop two files to the system, specifically, “btecache.dll” and “svchost.dll”. The “btecache.dll” file is a Trojan that loads and executes “svchost.dll”, which is a Carberp variant the Sofacy Trojan. Surprisingly, unlike many other espionage actors who display decoy documents after successful exploitation, this RTF document does not drop or open a decoy document after exploiting the vulnerability.

In the installation process, we observed the delivery document creating a very interesting registry key that it uses for persistence to run the Trojan. The path to the “btecache.dll” file is added to the following registry key:

Software\Microsoft\Office test\Special\Perf\: “C:\Users\[username]\AppData\Roaming\btecache.dll”

This registry key is interesting, because unlike traditional methods of maintaining persistence, it does not automatically run the “btecache.dll” file at system start up. Instead, this registry key will cause the DLL to load only when the user opens any Microsoft Office application, such as Word or Excel. This is the first time Unit 42 has seen the Sofacy group, or any other threat group for that matter, use this tactic for persistence purposes. An added benefit for the threat actor to using this specific tactic for persistence is that it requires user interaction to load and execute the malicious payload, which can cause challenges for detection in automated sandboxes.

The Carberp variant of Sofacy

The “btecache.dll” file is the loader Trojan that is responsible for loading the “svchost.dll” DLL and executing it. Both the “btecache.dll” and “svchost.dll” files contain code from the leaked Carberp source code, specifically the API resolution functions, as well as the RC2 key. The Sofacy group has used the Carberp source code in the past, specifically discussed in a blog by F-Secure, which is the reason we call this Trojan the Carberp variant.

The “svchost.dll” file contains the bulk of the functionality of this Trojan, which at a high level is a downloader that allows the threat actors to gain an initial foothold on the system. The Trojan sends network beacons to its command and control (C2) serverallowing the threat actors to identify targets of interest. The threat actors can then respond to these network beacons to download and execute additional secondary payloads on the system.

The Trojan delivered in this attack contains two network locations that it will send network beacons to, specifically “google.com” and “191.101.31.6”. These beacons are sent to the legitimate website google.com as an attempt to hide the true C2 beacons sent to the actual C2 server hosted at 191.101.31.6.  The network beacons are sent using HTTP POST requests with URLs created largely with random characters. There are two exceptions where random characters are not used to construct the URL, specifically the file extension that is randomly chosen from .xml, .pdf, .htm or .zip and the base64 encoded value at the end of the URL. The base64 encoded data is a string (“J04aLsxVhHBkr19CYr0”) hardcoded within the Trojan that it will then encrypt using a custom algorithm. Figure 1 shows an example beacon sent from the Trojan to the C2 server during analysis.

Figure 1 Network Beacon Sent from Carberp variant of Sofacy

The POST data seen in the beacon in Figure 1 is base64 encoded and encrypted using the same custom algorithm used to encrypt the data in the beacon URL. We decrypted the data to determine its purpose and found the cleartext seen in Figure 2.

,^Bid=I,;<&w@[System Process]
System
smss.exe
csrss.exe
wininit.exe
csrss.exe
winlogon.exe
services.exe
lsass.exe
lsm.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
spoolsv.exe
svchost.exe
taskhost.exe
userinit.exe
dwm.exe
explorer.exe
svchost.exe
cmd.exe
conhost.exe
reader_sl.exe
svchost.exe
cmd.exe
conhost.exe
SearchIndexer.exe
SearchProtocolHost.exe
SearchFilterHost.exe
SearchProtocolHost.exe
explorer.exe
svchost.exe
svchost.exe
disk=IDE\DiskMAXTOR_HARDDISK_________________________2.2.1___\5&2770a7af&0&0.0.0
build=0x7caa0e19

Figure 2 Decrypted HTTP POST Data Shows System Information

The clear text of the data sent in the network beacons contains information regarding the compromised system, as well as malware-specific information. The data is comprised of the following fields of data:

id = The serial number of the storage device

w = This parameter (whose name ‘w’ could change to any character between samples) begins with a one byte value denoting the OS version followed by a one byte value for the CPU architecture. These values are immediately followed by a new line delimited list of running processes on the system.

disk = The name of the system’s hard drive, obtained from the registry key “SYSTEM\CurrentControlSet\Services\Disk\Enum\0”

build = The hardcoded build identifier for the Trojan version

inject = (Optional, not displayed in Figure 2) If the Trojan injected its code into other processes to interact with the C2 server

This callback data allows the threat actors to determine if the infected machine is a target of interest, as the beacon contains a list of running processes and the name of the storage device that could be used to filter out analysis systems or researchers. If the actors believe the system is of interest, they will respond to these network beacons to download and execute additional secondary payloads on the system. The Trojan parses the response to the beacons for two actions “Execute” and “Delete” between the tags “[file]” and “[/file]”, as well as settings labeled “FileName”, “PathToSave”, “Rundll” and “IP” between the tags “[settings]” and “[/settings]”. This allows the threat actors to download additional files to the system, execute both executables and DLLs and delete files.

The Infrastructure

The initial analyzed sample in this attack only contained a single malicious command and control location, 191.101.31.6. We have not observed this IP address used by the Sofacy group in any previous attack campaigns, and examining passive DNS data showed no other correlations to potentially related attacks. The sample also seen by Prevenity appeared to only have a single primary C2 domain, servicecdp[.]com. This domain also appears to be newly created for this specific attack campaign, with no strong links to any previous attacks.

Pivoting off the unique registry key used for persistence revealed links to a previously observed Sofacy campaign, from mid-2015. Two additional payloads with recent compile dates of March 7, 2016, were discovered using the same persistence mechanism, and analysis of those payloads revealed one primary C2 domain, munimonoce[.]com, and three secondary C2 domains, http://www.wscapi[.]com, http://www.tabsync[.]net, and storsvc[.]org. The secondary C2 domains may appear familiar, as they were widely publicized in a report from iSight Partners in July 2015 as C2 domains related to the Sofacy group aka Tsar Team.

In addition, the primary C2 domain munimonoce[.]com previously had resolved to the IP 66.172.11.207, which was previously identified as a primary C2 IP for a Sofacy payload with a compile timestamp of June 11, 2015. This particular sample also happened to use the exact same secondary C2 domains of www.wscapi[.]com, www.tabsync[.]net, and storsvc[.]org, but lacked the newly discovered persistence mechanism.

The Sofacy group often re-uses infrastructure components across multiple attack campaigns, whether to speed the flow of attacks, for a lack of available resources committed, or out of sheer laziness. In this case, the newer attack campaign appears to use newly created infrastructure, but still maintains some overlap with previous Sofacy-related C2s. We believe this overlap could possibly be due to an oversight when adapting a previous code base with the new persistence method discussed in this blog for the new attack campaign.

The threat appears to be moving toward deployment of one-off infrastructure that can make analysis of attack campaigns and correlation more challenging. This shift stresses the importance of analysts and researchers being able to pivot on all artifacts of a given attack, not simply relying on network indicators. In this case, we were able use AutoFocus to pivot on a common registry key unique to this attack campaign to quickly identify where it correlates with characteristics of previous attacks.

Conclusion

The Sofacy group continues its attack campaigns on government organizations, specifically the U.S. government in this latest spear-phishing example. The threat group added a new persistence mechanism that requires user interaction by loading its payload into Microsoft Office applications when opened, which may help the actors to evade detection. The use of this new persistence method shows the continued development of tactics and techniques employed by this threat group, often times in clever ways as we observed in this instance.

Palo Alto Networks customers are protected from the new Sofacy Carberp variant and can gather additional information using the following tools:

  • WildFire detection of all known samples as malicious
  • All known C2s are classified as malicious in PAN-DB
  • AutoFocus tags have been created SofacyCarberp

Indicators

Delivery Documents

03cb76bdc619fac422d2b954adfa511e7ecabc106adce804b1834581b5913bca (Exercise_Noble_Partner_16.rtf)
12572c2fc2b0298ffd4305ca532317dc8b97ddfd0a05671066fe594997ec38f5 (Putin_Is_Being_Pushed_to_Prepare_for_War.rtf and Russian anti-Nato troops.rtf)

Loader Trojans

c2551c4e6521ac72982cb952503a2e6f016356e02ee31dea36c713141d4f3785 (btecache.dll)
be1cfa10fcf2668ae01b98579b345ebe87dab77b6b1581c368d1aba9fd2f10a0 (bitsprex3.dll)
fbd5c2cf1c1f17402cc313fe3266b097a46e08f48b971570ef4667fbfd6b7301 (amdcache.dll)

Payloads

69940a20ab9abb31a03fcefe6de92a16ed474bbdff3288498851afc12a834261 (svchost.dll)
aeeab3272a2ed2157ebf67f74c00fafc787a2b9bbaa17a03be1e23d4cb273632 (clconfg.dll)
dfa8a85e26c07a348a854130c652dcc6d29b203ee230ce0603c83d9f11bbcacc (iprpp.dll)
57d230ddaf92e2d0504e5bb12abf52062114fb8980c5ecc413116b1d6ffedf1b (clconfg.dll)

Command and Control

191.101.31.6
munimonoce[.]com
wscapi[.]com
tabsync[.]net
storsvc[.]org
servicecdp[.]com

and

[Palo Alto Networks Research Center]

English
Exit mobile version