For Cyberattackers, Time Is The Enemy

Current research in cybersecurity often has a narrow focus, detailing recently successful attacks and how those attacks were accomplished. Attackers are often represented as shadowy, nameless figures, with a special kind of mystique surrounding them. That Hollywood image couldn’t be further from the truth. In a new study released today, “Flipping the Economics of Attacks,” Palo Alto Networks has partnered with the Ponemon Institute to understand not only what motivates these attackers but also how we can turn the tables on them by taking away their financial incentives to attack.

The data also shows us a clear path to shift the economic motivation of attacks with two compelling facts:

  • Increasing the time it takes to breach an organization by less than 2 days (40 hours) will deter 60 percent of attacks.
  • Organizations rated as having “excellent security,” as compared to “typical,” took double the time to breach (140 hours).

To understand how to influence an attacker’s economic motivation, we must consider what I call the “adversary arithmetic,” which boils down to the cost of an attack versus the potential outcome of a successful data breach. If malicious actors are putting in more resources than they are getting out, or we decrease their profit, being an attacker becomes much less attractive. Using the survey findings as a guideline, let’s walk through what we can do to reverse this trend.

An Attacker’s ROI

Here is the situation today: we found that 53 percent surveyed believe that the cost of executing successful attacks has gone down, with more available malware and exploits, better attacker skills, and more effective toolkits as the primary drivers. This is important because as Moore’s Law shows us, increasing computing power over time, and in this case the automation and sophistication of hacking tools, makes launching a successful attack cheaper.

The survey also found that 69 percent of adversaries were motivated solely by profit, meaning that changing the arithmetic to increase the cost of attacks could prevent the majority of them from ever being launched. It is important to note that there is a spectrum of malicious actors, and organizations must always maintain awareness of potentially dangerous, highly targeted attacks, or nation-state led activity such as cyber espionage or cyber warfare. However, if we can de-incentivize anywhere near that number of attackers, we will see seismic change in the threat landscape.

There’s a common notion that attackers are motivated by big potential paydays. We found this to be the exception, rather than the rule, with average annual earnings from malicious activity totaling less than $30,000. This limited earning power becomes even less attractive when you consider the added legal risks, including fines and jail time.

The next step in our equation is how attack targets are selected. We found that the majority of attackers (72 percent) were opportunistic, not wasting time on efforts that do not quickly yield high-value information. While advanced nation-state actors employ lots of planning, think about the average attacker as the mugger on the street, versus the Ocean’s Eleven crew that spends weeks planning a complicated high stakes heist. When put into this context, organizations that prioritize making themselves a harder target will actively prevent a significant number of potential breaches.

Taken together, we have a simple picture of an average adversary: motivated by profit and going after easy targets in an environment where attacks are becoming cheaper. There is reason for hope though, as this same attacker is making a relatively small income, especially compared to cybersecurity professionals, with the added element of risk they face.

Time is the defining factor to change the adversary’s arithmetic. As network defenders, the more we delay adversaries, the more resources they will waste, and the higher their cost will be. We can interrupt the march toward more and more lower-cost attacks by taking a slightly different perspective on the problem. We need a prevention-based focus on the right investments in the right people, process and technology to defend the organization. Working together as a community to shift the economics of this problem, we can hit the core motivation for attackers and shift their behavior over time, bringing us to a world where cyberattacks are the exception, not the norm.

Read the full report for additional findings, including key recommendations for preventing attacks.

[Palo Alto Networks Blog]

SpiderMal: Deep PassiveDNS Analysis with Maltego

One investigative technique for threat analysis involves pulling information from disparate data sources to start piecing together breadcrumbs of data. This technique forms a more holistic picture of a threat. One of the most basic forms of telemetry used to research a threat is the classic IP address/domain record pair, to which the Maltego platform provides an excellent interface to graph these pairs so that interesting links or clusters standout for further analysis. This has historically been a very manual process and often leads to a dead end, as a lot of threat actors commonly take over legitimate systems to carry out campaigns.

Given this, and with a yearning to have more control over the graphing process, we created a new script to facilitate automating the initial building of Maltego graphs using passive DNS (pDNS) data from PassiveTotal. Specifically, SpiderMal is a Python script that can be run from the CLI or, alternatively, pointed to by a Maltego Local Transform. At its core, it uses the PassiveTotal API to connect domain nodes to IP address nodes, and vice versa with their pDNS data. It then recursively crawls from the seeded entity out to a specified level, building out the diagram. This can easily be accomplished through the existing PassiveTotal Maltego transforms by chaining together lookups; however, SpiderMal also includes the ability to filter results based on a temporal range so that only domains or IPs seen within a specified date range are included in the graph. This reduces the noise and allows an analyst to fine tune their results before diving in further.

To illustrate the temporal filtering and recursive search feature we start with a domain and query the PassiveTotal API to pull back all of the resource data for that record. This data is then subsequently passed back to PassiveTotal and their individual resource data is pulled back, so on and so forth until the specified recursive level is reached. This spidering allows one to quickly map out a potential infrastructure or quickly determine that the infrastructure is not actually relevant for a particular threat.

Figure 1: Unfiltered, 3-level, recursive search

Immediately, a few areas jump out as potential points to investigate but there’s a lot of data that may not necessarily be relevant to a threat. To fine-tune this, the same query was run with a filter that limited results to active records in the year 2015.

Figure 2: Temporal filtered, 3-level, recursive search

The ability to jumpstart these graphs, with more control over what goes in them, will hopefully give researchers and analyst more time for the investigative aspect of threat analysis.

Download the SpiderMal.py version 1.0.0, and the Maltego Local Transforms/Machines.

Some additional examples of using the script are included below.

Figure 3: Running the script from the CLI

Figure 4: The graph of the above search

Figure 5: A query seeded with an IP address of a fake Tech Support phishing site

Figure 6: Running the SpiderMal recursive 3 level Machine against an IP within Maltego

[Palo Alto Networks Blog]

5 Ways to Hack Your Leadership Communication

“The art of communication is the language of leadership.” James Humes

Good interpersonal skills are the hallmark of all great leaders. There is no leadership without effective communication. And those who possess the art of delivering thoughts and ideas in meaningful and befitting ways are those who are most successful.

No academic discourse or any business degree can teach you how to become a skillful communicator. It is self-taught and learned by exposing oneself to situations where interpersonal skills are tested the most. Regardless of which leadership style CEOs and managers adopt or have, delivering the right communication is a different matter altogether.

The best communicators are not only those who show the intent to listen to others, but also those who have incredible situational awareness and observation and problem-solving skills. Without being able to critically analyze, process the finer details and evaluate it holistically, leaders will not be able to communicate the “big picture” to their staff, and the business as a result will not grow as it should.

The following are a few ways leaders can uphold effective leadership communication:

Get personal—The positive value of any relationship intensifies the more emotions are involved. While it is important to have disciplined and professional relationships with your staff, it is also essential that leaders communicate with their staff using personalized tones and messages. Cultivating meaningful relationships is thus critical for leaders to communicate effectively.

Be specific—Leaders also need to practice ways of keeping their messages concise and to the point. There is nothing remarkable about making long speeches, if your staff cannot understand and remember half of the things you say. Business leaders are more pressed for time, and it can be very damaging if they do not deliver messages in a summarized and concise manner. The more summarized your messages are, the more clarity your staff will have.

Show empathy—“Leadership today is based on relationships built with trust, hope, love and encouragement,” Billy Cox. It is only natural that those vested with authority will exploit their position to show ego. That, however, is not the mark of a strong leader. A strong leader is one who can show empathy for his or her staff. Empathy contains the human element of compassion and care that can patch up emotional or psychological issues faced by employees in their work routines. Showing empathy means that you value human emotions and doing it enough can be precursor for influencing great motivation levels in your staff.

Demonstrate analytical reasoning—How well you analyze information and events is an important quality for a leader to have. What is more important is getting your employees to think like you and perceive things from your point of you. This does not necessarily mean that they have to agree with you; rather, it is about exercising one’s rational faculties to become better, data-driven staff that can achieve extraordinary results.

Leaders should ask employees to make their research and present their own analysis and solutions to a problem along with a case study, company/department objectives and conclusion. You can then ask a series of questions regarding how the business should quantify the solutions and how it can translate into long term business growth.

This is an important exercise to train your staff to think on their feet, appreciate their rational thinking and arrive at conclusions that can relate to worthwhile business strategies.

Listen and be silent—Listening with an open mind and out of genuine interest is one of the easiest ways to gain trust of your employees. By listening with a sincere heart, your employees feel valued and become encouraged to participate more closely with the activities of the organization. It sparks interest in your staff and allows them to be more at ease with their company culture.

Simon T. Bailey
Author, speaker and Brilliance Enabler

Bailey will be speaking at ISACA’s 2016 North America CACS conference 2-4 May 2016 in Las Vegas, Nevada, USA.

[ISACA Now Blog]

What I Heard at Davos: The Actionable vs. The Alarmist

Every year at their annual Summit in Davos, the World Economic Forum brings together the top leaders across government, business, and academia to share their views on addressing critical problems facing our planet. This year I was lucky enough to join the conversation, on “Mastering the Fourth Industrial Revolution.” I previously wrote about the importance of maintaining trust in the digital systems that are driving this revolution and it’s hard to imagine that we as a society can optimize the value and productivity of this Fourth Industrial Revolution without substantially overcoming the very real security issues that could undermine the trust required to operate our increasingly digital society. After returning from Davos, I am even more convinced of the timeliness of this conversation.

The conversations I heard and participated in at Davos largely mirrored the discussions we are having in the security industry today, which I would parse into two sections: the actionable and the alarmist.

The actionable conversation. In keeping with the goals of the conference to develop global solutions to global problems, there were plenty of discussions and debates on the importance of the trust required in the digital age and the path forward to maintain and regain that trust.  I believe that all attempts to bring people together to chart the path to the future in this regard is helpful.

One of the efforts we started last year at Palo Alto Networks, was to work with the New York Stock Exchange to bring together over 30 senior business leaders, academics, and technical experts to collect best practices and practical advice for corporate directors and officer’s struggling with cyber risks. Many topics raised in this book were echoed in Davos including realizing that cyber is not solely a technical issue.

Rather it is part of an economic fabric that is inherent in all things in the digital age. Because of this criticality it not only requires public private partnerships, but also the development of international norms and behaviors including the protection of privacy and the personal responsibility for cyber hygiene. In this regard, the forums and discussions at Davos continued to help us move the conversation forward.

The alarmist conversation. However, in a number of specific sessions with industry experts across many verticals, the discussion continues to stagnate on the problem, focusing on who can come up with the most frightful scenario.  While its critical to understand these nightmare scenarios, continued focus on those alone are a disservice to our future. It’s the security industry’s responsibility to pivot the dialogue towards finding solutions as opposed to continually rehashing how bad things can get. One example of how we can evolve this conversation is through the Cyber Threat Alliance. Palo Alto Networks and other members of the security industry are sharing information on cyber threat campaigns in order to increase the protection of all our customers. This cooperation has already led to several operational successes, including our recent research on the Scarlet Mimic campaign. This type of cooperative solution needs to be the focus of our conversation in cyber today because the stakes are too high for us to get this wrong.

Cyber risks will always be with us, but we must find ways to make these risks quantifiable, manageable, and insurable. The necessary steps ahead of us will take a lot of work in order to pivot the conversation from the problem to prevention. It will require international norms of personal, corporate, and national behavior, better sharing of best practices and cyber threat information, and continued investments in the development of innovative technology. But these are achievable steps, and by working out solutions together we can secure the future, rather than remain paralyzed be fear of the present.

[Palo Alto Networks Blog]

Flipping the Economics of Attacks

How can an organization make it difficult enough for an attacker that they dissuade or prevent an attack? Time-wise? Cost-wise? Potential profit-wise?

In Flipping the Economics of Attacks, sponsored by Palo Alto and conducted by Ponemon Institute, threat experts in the United States, United Kingdom and Germany were surveyed about what motivates attackers. The research revealed that most attackers are in it for the money.

To fight back against adversaries enterprises need to harden their organizations so it takes attackers longer to achieve their mission. Most malicious attackers are opportunistic when choosing a particular organization to attack and will quit the attack when the targeted organization presents a strong defense. Specifically, the majority of attacks can be stopped if more than about two days are needed for a successful attack.

The following are recommendations from the report that will help steel the organization against malicious actors:

  • Create a holistic approach to cybersecurity, which includes focusing on the three important components of a security program: people, process and technologies.
  • Implement training and awareness programs that educate employees on how to identify and protect their organization from such attacks as phishing.
  • Build a strong security operations team with clear policies in place to respond effectively to security incidents.
  • Leverage shared threat intelligence to identify and prevent attacks seen by your peers.
  • Invest in next-generation technology such as threat intelligence sharing and integrated security platforms that can prevent attacks and other advanced security technologies.

There are many questions that the cybersecurity community needs to answer: What are the typical annual earnings of a cybercriminal? What is the attacker’s cost of conducting a breach? Does crime pay? Are cybercriminals getting rich?

While many attackers may hope for a big payout, the reality can be quite different. The findings of the survey reveal attackers on average receive $28,744 for an average of 705 hours spent on attacks annually. Of course, some attackers do “earn” more than the average. However, this compensation is 38.8 percent, or one-quarter, less than the average hourly rate of IT security practitioners employed in the private and public sector.

We also learned that attacks are increasing because of the availability of low-cost and effective hacker toolkits. Technically proficient attackers are spending an average of $1,367 for specialized tool kits to execute one attack. The only other cost is their time.

For more information attend the ISACA webinar: Flipping the Economics of Cyber Attacks, 11 A.M. (CST), Tuesday, 26 January, presented by Scott Simkin is Sr. Manager, Threat Intelligence at Palo Alto Networks, and Dr. Larry Ponemon is the Chairman and Founder of the Ponemon Institute.

Dr. Larry Ponemon
Chairman & Founder, Ponemon Institute

[ISACA Now Blog]

English
Exit mobile version