Navigating the Breach Regulatory Maze: Proper Incident Risk Assessment and Response

Cyber attacks. Lost paper files. Third-party snafus. Misdirected emails. Endless are the ways in which sensitive personal information is accidentally or deliberately exposed. Despite best efforts, it is impossible to stop sensitive data from falling into the wrong hands.

According to a new report, Risk Based Security identified 3,930 data breaches reported during 2015, exposing more than 736 million records. Poorly managed, these data security and privacy breaches put organizations at high risk for regulatory fines, lawsuits, lost business and reputational harm. In addition, customers, patients and employees affected by the exposure of their sensitive information fall prey to identity theft and other forms of fraud.

The Challenges of Incident Risk Assessment
No incident is alike. The types and sensitivity of data exposed, the root cause of the incident, the nature and intent of the recipient of the exposed data—these and other variables make consistency of incident risk assessment a difficult challenge for privacy, compliance and risk professionals.

For example, the Risk Based Security report found that:

  • Hacking accounted for 64.6 percent of breaches and 58.7 percent of exposed records.
  • Nearly half of breaches involved passwords and more than 45 percent exposed email addresses.
  • The breaches reported covered more than a dozen industry sectors, from technology to government to retail to healthcare.

In addition to incident variability, data breach laws are a maze of growing complexity and ambiguity. There are 51 state and territory breach notification laws that have different definitions of personal information, allow varying exceptions and have different requirements regarding notification thresholds, content and timing. And these laws are rapidly changing and getting stricter:  In 2015 and the first part of 2016, 10 states enacted new addendums or breach laws. Adding to the complexity is a plethora of federal regulations and standards—HIPAA, GLBA and PCI to name a few—as well as international laws and the long awaited European Union’s General Data Protection Regulation (GDPR).

The primary struggle for privacy and compliance professionals is lack of consistency given the manual and highly subjective methods of conducting the required multifactor risk assessments. This is understandable, given the challenge of assessing the unique nature of each incident against this backdrop of complex breach notification regulations and lack of purpose-built and automated incident risk assessment tools. And if such a homegrown tool is developed, many organizations find it doesn’t scale, it can’t keep up with the changing regulations and is difficult to use.

Four Steps to Successful Incident Risk Assessment and Response
In order to reduce the risks from unavoidable privacy or security incidents, organizations need an automated and highly consistent process for incident risk assessment. This process must allow each unique incident to be assessed with the latest updates to breach notification laws. To help you accomplish this, consider these four tips:

  1. Understand the difference between an event, an incident and a breach. These terms are often used synonymously or incorrectly, but important distinctions exist. For example, an incident is an event that violates an organization’s security or privacy policies involving sensitive information. A breach, on the other hand, is an incident that meets the legal definition of a breach and requires notification to affected individuals.
  2. Develop a scalable process for reporting incidents. Timely and efficient reporting of suspected incidents by employees, customers and third-party entities is critical for implementing a successful incident response process. Use web forms to efficiently and securely capture incident information and to automatically route the information to the appropriate professionals for investigation and incident risk assessment.
  3. Automate data breach risk assessment. Given the short time line for notifications based on a multifactor incident risk assessment, you need a system that is agile and provides a multifactor risk assessment based on the latest in breach notification laws across all jurisdictions where you have regulatory obligation.
  4. Track trends in incident categories and root causes. Learn from your incidents. Accurately identifying weaknesses in your systems, departments or processes can reduce the number of incidents and your organizational risk. Automation is key to ensuring proper analysis and risk mitigation.

Organizations can ill afford to underestimate the importance of consistent incident risk assessment and response. Done right, this process provides a road map for successfully responding to potential breaches, meeting regulatory requirements and protecting the people who trust us with their most confidential information.

Join Mahmood Sher-Jan at ISACA’s North America CACS in New Orleans 2-4 May. Sher-Jan will present Navigating the Data Breach Regulatory Maze (session 234/Privacy Track) in depth on Tuesday, May 3.

Mahmood Sher-Jan, CEO, RADAR® business unit, ID Experts

[ISACA Now Blog]

New on Security Roundtable: Cyber Insurance is a Misnomer

Security Roundtable is a community designed to share best practices, use cases, and expert advice to guide executives on managing cybersecurity risks. In this article, excerpted below, Scott Kannry, CEO of Axio Global, dives into why attention to detail is key when evaluating cyber insurance.

“My title is not meant to suggest that cyber insurance is flawed.  To the contrary; it’s a valuable risk transfer instrument that has performed as advertised in the vast majority of loss situations and often provides policyholders with a gateway to a host of response and mitigation providers that otherwise might be too costly or unavailable when most needed.  Most articles questioning the viability of the product are usually centered on denied claims from types of insurance policies that were not designed to cover emerging cyber risks, or written by folks whose knowledge of actual policy language harkens back to earlier generation policies that sometimes contained strict stipulations about maintaining consistent levels of security.

Rather, my title intends to raise awareness that ‘cyber insurance,’ as is commonly offered by the insurance industry, is not an “all-risk” type of policy that covers anything and everything resulting from a cyber event…”

Read the full article at Security Roundtable.

[Palo Alto Networks Research Center]

Is Cybersecurity Everyone’s Concern?

Is your business connected to the Internet for any services? Do you shop online or purchase any products or services online? Are you on Facebook, Twitter, LinkedIn or any other social networking web sites? Do you have a high-end mobile phone and use chat applications such as WhatsApp? If so, cybersecurity is an issue about which you should be concerned.

If you think that you could never be a victim of an attack originating on any of these platforms, you should think twice, because cybercriminals are keenly tracking your identities and researching your shopping behavior, watching what you do online and, ultimately, profiling the very devices through which you are connected to cyberspace. Since you are part of the bigger, interconnected network, you are a potential target of a cyberattack.

If you are thinking to yourself, “What do I possess that will interest a cybercriminal?,” think of it this way:  You are targeted, not to steal anything specific, but to possibly build in-roads to a bigger trusted network to which you belong. Once your systems and networks are compromised, it may appear that the cyberattack has originated from your organization while it was actually performed by an invisible cyberattacker from your IP addresses using your system signatures.

Even if your interconnected networks are protected through a firewall or other security measures, a persistent hacker could still closely footprint your activities, e.g., when have you scheduled your next maintenance of systems and networks, the security behavior of users, or the tools and technologies deployed in your organization. In many cases, cybercriminals operate in stealth mode for a period of time before attacking. Once they are inside a network, they quickly adapt to the network behavior, making it difficult for the existing intrusion detection system to flag them. People are the weakest link that is targeted by a cyberattacker.

Essentially, every organization in cyberspace has to rethink with whom and how they are connected in cyberspace and prepare for any threats that can appear because of these interconnections. It is possible that something is already in place; it may just need strengthening through anti-hacking measures such as user awareness, firewalls, patch management, incident response, authentication, authorization and other controls.

Read Sanjiv Agarwala’s recent Journal article:
“Quick Fixes for Improving Cyberdefenses,” ISACA Journal, volume 2, 2016.

Sanjiv Agarwala, CISA, CISM, CGEIT, BS25999/ISO 22301 LA, CISSP, ISO 27001:2013 LA, MBCI

[ISACA Journal Author Blog]

Python-Based PWOBot Targets European Organizations

We have discovered a malware family named ‘PWOBot’ that is fairly unique because it is written entirely in Python, and compiled via PyInstaller to generate a Microsoft Windows executable. The malware has been witnessed affecting a number of Europe-based organizations, particularly in Poland. Additionally, the malware is delivered via a popular Polish file-sharing web service.

The malware itself provides a wealth of functionality, including the ability to download and execute files, execute Python code, log keystrokes, spawn a HTTP server, and mine Bitcoins via the victim’s CPUs and GPUs.

There are at least 12 variants of PWOBot, and the malware has been observed in attacks dating back to late 2013. More recent attacks have been observed affecting organizations between mid-to-late 2015.

Targeting

Over the past year, we have witnessed PWOBot affecting the following organizations:

  • Polish national research institution
  • Polish shipping company
  • Large Polish retailer
  • Polish information technology organization
  • Danish building company
  • French optical equipment provider

The majority of the PWOBot samples were downloaded from chomikuj.pl, which is a popular Polish file sharing web service. The following unique URLs have been observed providing copies of PWOBot:

s6216.chomikuj[.]pl/File.aspx?e=Pdd9AAxFcKmWlkqPtbpUrzfDq5_SUJBOz
s6102.chomikuj[.]pl/File.aspx?e=Hc4mp1AqJcyitgKbZvYM4th0XwQiVsQDW
s8512.chomikuj[.]pl/File.aspx?e=h6v10uIP1Z1mX2szQLTMUIoAmU3RcW5tv
s6429.chomikuj[.]pl/File.aspx?e=LyhX9kLrkmkrrRDIf6vq7Vs8vFNhqHONt
s5983.chomikuj[.]pl/File.aspx?e=b5Xyy93_GHxrgApU8YJXJlOUXWxjXgW2w
s6539.chomikuj[.]pl/File.aspx?e=EH9Rj5SLl8fFxGU-I0VZ3FdOGBKSSUQhl
s6701.chomikuj[.]pl/File.aspx?e=tx0a8KUhx57K8u_LPZDAH18ib-ehvFlZl
s6539.chomikuj[.]pl/File.aspx?e=EH9Rj5SLl8fFxGU-I0VZ3ISlGKLuMnr9H
s6539.chomikuj[.]pl/File.aspx?e=EH9Rj5SLl8fFxGU-I0VZ3OFFAuDc0M9m0
s6179.chomikuj[.]pl/File.aspx?e=Want-FTh0vz6www2xalnT1Nk6O_Wc6huR
s6424.chomikuj[.]pl/File.aspx?e=o_4Gk0x3F9FWxSDo4JWYuvGXDCsbytZMY

Additionally, in one instance the malware was downloaded from http://108.61.167.105/favicon%5B.%5Dpng. This IP address is associated with the tracking.huijang[.]com domain, which was also used by a number of PWOBot samples.

The following filenames were observed being used to deliver PWOBot:

  • favicon.png
  • Quick PDF to Word 3.0.exe
  • XoristDecryptor 2.3.19.0 full ver.exe
  • Easy Barcode Creator 2.2.6.exe
  • Kingston Format Utility 1.0.3.0.exe
  • uCertify 1Z0-146 Oracle Database 8.05.05 Premium.exe
  • Six Sigma Toolbox 1.0.122.exe
  • Fizjologia sportu. Krtkie wykady.exe [Physiology of sports. Short lectures.exe]

As we can see from the filenames used, a number of the PWOBot samples purport to be various software utility programs. In some instances, the Polish language is used for what appears to be a more targeted filename.

It is unclear how this malware was originally delivered to the end-user. Inferences can be made based on the filenames witnessed, as this malware may have been delivered to end-users who believed they were downloading other software. Alternatively, it’s possible that phishing attacks were used in order to entice victims into downloading these files.

Malware Analysis

As originally mentioned, PWOBot is written completely in Python. The attackers leverage PyInstaller to convert this Python code into a Microsoft Windows executable. However, as Python is being used, it can easily be ported to other operating systems, such as Linux or OSX.

Upon initial execution, PWOBot will first uninstall previous versions of PWOBot should they be found. It will query Run registry keys searching for instances of previous versions. The majority of versions use a format of ‘pwo[VERSION]’ for the Run registry key, where [VERSION] is the version number of PWOBot.

Figure 1 PWOBot uninstalling previous versions

After the previous versions are uninstalled, PWOBot will install itself and create a copy of its executable in the following location:

%HOMEPATH%/pwo[VERSION]

It will then set the following registry key to point to this newly copied executable:

HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Run/pwo[VERSION]

If this is the first time the malware is run, PWOBot will execute the newly copied file in a new process.

After installation completes, PWOBot will hook various keyboard and mouse events, which will be used for subsequent keylogging activities. PWOBot is written in a modular fashion, allowing the attacker to include various modules during runtime. Based on the number of samples currently identified, the following services and their accompanying descriptions have been observed being included with PWOBot:

  • PWOLauncher : Download/execute file, or execute local file
  • PWOHTTPD : Spawn a HTTP server on the victim machine
  • PWOKeyLogger : Log keystrokes on the victim machine
  • PWOMiner : Mine bitcoins using the victim CPU/GPU
  • PWOPyExec : Execute Python code
  • PWOQuery : Query remote URL and return results

PWOBot also is equipped with two configuration files, one of which specifies various settings the malware should use, while another specifies what remote servers PWOBot should connect to during execution.

Figure 2 PWOBot settings configuration

Figure 3 PWOBot remote server configuration

As is visible in the settings configuration (Figure 2), PWOBot includes various windows executables that are included when the attackers compile the code using PyInstaller. These executables are used to perform Bitcoin mining and to-proxy requests via Tor. The Bitcoin miner is a compiled version of minerd and cgminer. These files are used for CPU and GPU Bitcoin mining respectively.

PWOBot also makes use of Tor to tunnel all traffic to the attacker’s remote server(s). While this provides both encryption and anonymity, it also should raise alerts to an organization’s network administrators if viewed, as such traffic likely violates said organization’s policies.

PWOBot uses a Python dictionary as it’s network protocol. Every specified period of time PWOBot will send a notification message to the remote server. An example of this notification can be seen below:

Enumerations are configured to represent the various number encountered in the previous example. Once replaced with their respective enumeration, we see a more complete picture of what data is being sent.

After notifications are sent, the attacker may opt to provide a command instructing PWOBot to perform one of the previously defined services. Results from said actions are then uploaded to the attacker using the same format.

In total, 12 variants of PWOBot appear to exist, based on the lastest versions identified by Palo Alto Networks Unit 42. Of the 12 versions, we have witnessed versions five, six, seven, nine, 10, and 12 in the wild. Changes between versions appear minimal, and are likely performance improvements.

Conclusion

PWOBot is interesting as a malware family because it is written entirely in Python. While it has historically been seen affecting Microsoft Windows platforms, since the underlying code is cross-platform, it can easily be ported over to the Linux and OSX operating systems. That fact, coupled with a modular design, makes PWOBot a potentially significant threat.

This malware family has not previously publicly disclosed. It has currently been witnessed affecting a number of European organizations.

Palo Alto Networks customers are protected from this threat in the following ways:

  • All PWOBot samples are properly categorized as malicious by the WildFire service.
  • Domains related to the PWOBot threat have been appropriately categorized as malicious.
  • AutoFocus customers may use the PWOBot tag to monitor this threat.

For a list of SHA256 hashes of PWOBot, please refer to the following file.

[Palo Alto Networks Research Center]

Maximizing your Panorama Deployment, Part 3

The Importance of Looking Forward When Deploying Panorama

In this blog series on maximizing your Panorama deployment, we covered the benefits of Panorama and how to customize your Panorama deployment to meet your needs. This final blog post will explain the importance of taking the future into consideration when deploying Panorama.

Panorama provides streamlined management, great visibility and excellent rule management across distributed networks of next-generation firewalls.

When deploying their network security management solutions, most customers deploy them in a way that is optimized for their current situation without consideration of future company or traffic growth. It is, however, critically important to plan a Panorama deployment strategically to optimize processing speeds and logging capacity/retention, as well as availability.

For example, deploying Panorama as a Virtual Machine (VM) makes a lot of sense for smaller companies who don’t have to manage too many logs or firewalls. However, adding just one or two more firewalls to your distributed network, may result in the VM servers being overloaded with the number of logs being generated. A small step to add either a dedicated management appliance or a log collector can ensure that log ingestion and retention won’t reach limits, and processing speeds won’t get impacted.

Thanks to the flexible deployment options of Panorama, you can ensure you maximize the performance of your network security management solution by adding dedicated management appliances and log collectors, or deploying Panorama in High Availability (HA) pairs.

Learn more about Panorama by downloading the datasheet.

Thanks for reading my series on maximizing your Panorama deployment. If you have additional questions or suggestions for future topics, leave a comment for me below.

[Palo Alto Networks Research Center]

English
Exit mobile version