As an African proverb reminds us, “Knowledge is the only treasure you can give entirely without running short of it.” Knowledge is recognized as the most important strategic asset for every organization. According to the Journal of Knowledge and Process Management, knowledge management is a holistic process that optimizes intellectual capital to achieve organizational objectives by leveraging information and expertise. The main purpose of knowledge management practice is to mitigate the possible loss of extensive tacit and explicit knowledge due to loss of employees.
Knowledge management practices enhance the capability of an organisation to identify, capture or acquire, share, reuse and internalization of knowledge. Audits of knowledge management practices are rarely undertaken by audit functions, and this gap has been identified as one of the contributing factors in knowledge management initiatives.
COBIT 5 introduced a new defined process—BAI08:Manage Knowledge process. This process fits well in one of COBIT 5’s information technology goals: “ knowledge, expertise and initiatives for business innovation.” The process provides guidelines on how to facilitate information system knowledge management within an IT organisation. For a detailed look at it, download ISACA’s BAI08 Manage Knowledge Audit Assurance Program.
What is knowledge management audit? In an article from The Hong Kong Polytechnic University, “Re-Thinking knowledge audit: its values and limitations in the evaluation of organizational and cultural asset ,” knowledge management audit is defined as the systematic investigation, examination, verification, measurement and evaluation of explicit and tacit knowledge resources and assets, in order to determine how efficiently and effectively they are used and leveraged by the organisation . A knowledge management audit provides an opportunity to understand the current state of the knowledge management capability of an organization and a direction of where and how to improve the capability to provide the knowledge for quality decision making and enhanced productivity.
Planning for knowledge management audits for IT function Before planning to undertake knowledge management audits, professionals should understand the knowledge management landscape within the entire organisation, and not just the IT function. It goes without saying that understanding the bigger picture of the organisation is critical in planning IT knowledge management audits. Noted in the Journal of Knowledge and Process Management, the knowledge management landscape of any organisation will involve people culture, processes, structures and technology that support its initiatives. The following knowledge management elements should be reviewed at the audit planning stage.
Knowledge Management (KM) Elements
Why review this document at planning stage
Knowledge management strategy
The document provides the long-term vision and objectives of the organisation as far as knowledge management is concerned. KM elements like KM structure, resources, projects, roles and responsibilities and roadmaps will be highlighted in this document.
Knowledge management policy
To understand the high-level management commitment and support for knowledge management within the organisation
Interview those responsible for knowledge management (Knowledge Management Officers)
To understand current knowledge management initiatives, structures and challenges within the organisation
Walk through existing collaborative tools (intranet, online community of practice, knowledge- sharing platforms, document management systems, etc.)
To understand the available collaborative tools used across the organisation for knowledge management
Preliminary social network analysis to map the major information flows within an organisation
To understand knowledge flow within the organisation. This aids the auditor to identify the key nodes of knowledge creation, sharing, reuse and storage.
Audit Reporting Knowledge management audit reports should provide the following outputs: an assessment of current levels of knowledge management practice and knowledge sharing; identification and analysis of knowledge management opportunities that have not been explored; isolation of potential problems and existing gaps; and an evaluation of the perceived value of knowledge management within the IT organisation. The report should highlight the existing knowledge management gaps and offer recommendations on four key perspectives: people culture, processes, structures and technology.
By auditing knowledge management processes, you will be able to identify gaps in an organization’s knowledge management practices and activities, build from what is working, and identify areas that require improvement. The outcome should be a blueprint for moving forward in developing organizational knowledge management best practices.
I often speak with ICS asset owners who are just at the beginning of their next-generation firewall learning curve. They are usually pleasantly surprised at the capabilities it provides in identifying traffic at Layer 7, i.e. application, users and threat/content.
Beyond just being able to see network traffic at this very detailed level, the fact that these key pieces of information are intrinsically correlated — a unique advantage of our single-pass, parallel processing architecture (SP3) — is a major draw. The proverbial “light bulb” turns on very quickly and they understand why this approach means easier anomaly detection, faster forensics and better auditability in their ICS environment.
Understandably, the word “firewall” in the product name often invokes the question of whether the device can be used in a more passive, detection-only model. To support such monitor-only deployments, the Palo Alto Networks Next-Generation Firewall offers a deployment mode called “Tap Mode.” Using this deployment, the next generation firewall can be connected to a SPAN/mirror port on a network device, like a switch or router, to passively monitor the traffic going through this “hub.” Doing this provides not only better visibility, but more importantly, correlated visibility into useful pieces of network traffic information.
Why “monitor-only”?
Why not deploy the device inline as a firewall is meant to be deployed? A common reason in ICS is that the owner has a monitor-only mindset or policy for critical areas of the ICS. Consider, for example, the core of a Distributed Control System (DCS) where there may be zero tolerance for any potential accidental blocking of traffic. They want to avoid any additional inline devices aside from the main equipment needed to run the process and provide connectivity. While this organization may put a security device inline at the IT-OT perimeter, they would never do so within the DCS core. However, a non-invasive visibility tool could prove useful and hence could be considered for deployment.
Another reason for putting the device in passive mode, even at the perimeter of the ICS, such as between corporate and the PCN (process control network), is because the asset owner is not quite ready to do a rip-and-replace of his existing security architecture. While the asset owner may admit that the existing system will need to be replaced eventually due to lagging capabilities, he still prefers a more gradual migration path that feels less disruptive. A device that can be easily dropped in with minimal impact to the current production system, while providing high value, is ideal. Eventually the owner may swap out the old with the new as he validates the new product and gets more comfortable with the technology.
Shedding the light on plant floor traffic
Users of Palo Alto Networks next-generation firewalls now have access to a variety of rich and natively correlated network traffic information including the following:
ICS Protocols and Applications – For example to Modbus, DNP3, OPC, ICCP, OsiSoft Pi, Schneider OASyS, Cygnet, etc. For some protocols, the visibility is provided at the function code level (i.e. Modbus Reads and Writes)
SaaS & Social Media – Applications which typically should not be allowed in ICS environments but are sometimes found, e.g. Dropbox, P2P file sharing, TeamViewer due to irresponsible use by employees
Custom Traffic – Custom “App-IDs” can be easily created using the firewall itself to identify homegrown applications.
User / User Group – The next-generation firewall can utilize different sources of IP-to-user mappings and events to enable user and user-group visibility. These include directory services, authentication events, and even via the API. The user-information will be tied to the application/protocol traffic thereby providing user-based access logs.
Content – The firewall can be used to identify files, strings, URLs.
Known Threats – Network-borne known exploits, malware, and command and control traffic. Again threat information is contextually tied to application/protocol and user information.
Zero-day Malware – If the firewall is connected to the Wildfire service, the device can also be used to identify zero-day malware in as little as 5 minutes for the on-premises Wildfire offering.
Several areas where users are typically interested in gaining more situational awareness and capabilities for auditing traffic include:
ICS core – Monitor traffic off of a switch interconnecting the HMIs, workstations and automation servers on the plant floor. This should mostly be repetitive machine-to-machine traffic so anything out of the ordinary is likely to jump out.
IT-OT perimeter – Use the Next-generation firewall to augment any existing access control device like a Router (ACL) or stateful inspection firewall (limited visibility at the port and IP address level)
3rd party connections – Similar to the IT-OT perimeter, make sure to monitor the connectivity you have with third parties like partners and ICS vendors and systems integrators
Moving beyond monitor-only
In practice, many users start off in tap mode then eventually move into one of two inline deployments modes (VWIRE “bump-in-the-wire”, L2/L3 Firewall Replacement), realizing the powerful network segmentation capabilities of the device. In other scenarios they may deploy the devices in a hybrid model where some areas the firewall is inline with access controls and in some areas the device is in tap mode.
Not all organizations have the same network architecture or the same view on security posture. Our next-generation firewall’s support for multiple deployment modes highlights one of the ways our platform provides flexibility. In fact the multiple ports on a Palo Alto Networks firewall could be configured to support multiple deployment modes simultaneously (Tap, VWIRE, and L2/L3).
Practicing What We Preach – Application Visibility and Risk Report
Interestingly enough, Palo Alto Network field teams often use the firewall in tap mode when conducting free Application Visibility and Risk (AVR) assessments. We basically connect the device in passive mode to the network cluster of interest then provide a report back to the end user on what applications and risks may be present in their network today.
It’s rare to have an AVR which does not result in immediately useful information regarding security risks. It is free and is an easy way to understand the value of correlated, layer-7 visibility and also perhaps to discover any exposures to your organization. Contact your local Palo Alto Networks representative to learn more or sign up for an AVR online.
To learn more about our platform approach to securing industrial control systems, please access the free white paper on 21st century SCADA security.
Unit 42 discovered a new family of Android malware that successfully evaded all antivirus products on the VirusTotal web service. We named this malware family “Gunpoder” based on the main malicious component name, and the Unit 42 team observed 49 unique samples across three different variants. This finding highlights the fine line between “adware,” which isn’t traditionally prevented by antivirus products, and malware, with its ability to cause harm.
Samples of Gunpoder have been uploaded to VirusTotal since November 2014, with all antivirus engines reporting either “benign” or “adware” verdicts, meaning legacy controls would not prevent installation of this malware. While researching the sample, we observed that while it contained many characteristics of adware, and indeed embeds a popular adware library within it, a number of overtly malicious activities were also discovered, which we believe characterizes this family as being malware, such as:
Collecting sensitive information from users
Propagating itself via SMS message
Potentially pushing fraudulent advertisements
Ability to execute additional payloads
Gunpoder targets Android users in at least 13 different countries, including Iraq, Thailand, India, Indonesia, South Africa, Russia, France, Mexico, Brazil, Saudi Arabia, Italy, the United States, and Spain. One interesting observation from the reverse engineering of Gunpoder is that this new Android family only propagates among users outside of China.
Unit 42 investigated Gunpoder using the Palo Alto Networks AutoFocus service, and released protections for users of WildFire, Threat Prevention and Mobile Security Manager for all currently known Gunpoder variants. Thanks to Palo Alto Networks unique prevention capabilities across the attack lifecycle, future members of the Gunpoder malware family could also potentially be blocked.
Evading Detection
By examining the reverse-engineered samples, we found the malware author applied several unique techniques to evade antivirus detection:
Gunpoder samples include aggressive advertisement libraries, such as Airpush, within the samples. Those ad libraries are easily detected and may also include aggressive behaviors. The malware samples successfully use these advertisement libraries to hide malicious behaviors from detection by antivirus engines. While antivirus engines may flag Gunpoder as being adware, by not flagging it as being overtly malicious, most engines will not prevent Gunpoder from executing. Figure 1 shows the VirusTotal scan results on one sample.
Users who have executed Gunpoder are shown a notification that includes the Airpush library. We believe the notification was intentionally added in order to use the Airpush library as a scapegoat.
Gunpoder samples embed malicious code within popular Nintendo Entertainment System (NES) emulator games, which are based on an open source game framework (http://sourceforge.net/p/nesoid/code/ci/master/tree/). Palo Alto Networks has witnessed a trend of malware authors re-packaging open source Android applications with malicious code. Gonpoder makes use of this technique, which makes it difficult to distinguish malicious code when performing static analysis.
Gunpoder targets users not residing in China. Samples observed support online payments, including PayPal, Skrill, Xsolla and CYPay.
Figure 1. Gunpoder sample pretends to be adware and successfully passes the antivirus scan
Let the Gunpoder Begin
Gunpoder samples pretend to be NES games. After installation, the malware will present a declaring statement when opened for the first time (Fig 2). This statement explicitly tells users that this app is ad-supported and allows Airpush to collect information from the device. We strongly believe that the malware author intentionally added the Airpush library as the scapegoat so that it could inconspicuously attribute its malicious behaviors to the Airpush library.
Figure 2. Gunpoder uses Airpush as the scapegoat
Once launched, the app will actively pop up a dialog to ask users to pay for a “lifelong” license of this game (Fig 3). If the user clicks the “Great! Certainly!” button, a payment dialog will pop up, including PayPal, Skrill, Xsolla (the transaction link is no longer active) and CYPay. Users need to register a new PayPal or Skrill account or log in in to their existing account to pay $0.29 or $0.49. The CYPay supports offline gift voucher redeeming. Additionally, this payment dialog will pop up when users click the “Cheats” option within this app. In fact, the malware author added this malicious payment function into this “Cheats” option, which is free in the original app.
By comparing the code between Gunpoder and the open source project, it was determined that the malware author added the payment functionality, as shown below (Fig 4). The payment dialog is shown in Fig 5.
CyPayUtil.payByAdvance(((Context)this));// add by malware author
}
</syntax highlight java source>
Figure 4. Payment code added by the malware author into the open source framework
Figure 5. Dialog pop up for payment (the charge will be USD 0.29)
Propagation via SMS and Google Short URLs
This Gunpoder family propagates by sending SMS to selected contacts with links to download Gunpoder. Due to the size of SMS messages, the download links are Google short URLs:http://goo.gl/KVhRwC (active in June 2015), http://goo.gl/OpnVHv (not active in June 2015).
The propagation SMS messages will be sent out in two scenarios. The first is when the main activity is paused by the user. This makes it very difficult for most dynamic analysis antivirus engines to trigger the sending behaviors (Fig 6).
The second scenario occurs when the user refuses to make a payment to activate the cheating mode (i.e. clicking the “Next Time” button in Fig 3). In this case, Gunpoder will ask the user to share a “fun game,” which is actually a variant of this malware family (Fig 7).
Interestingly enough, the Gunpoder sample will detect the country of the user. If the user is not located in China, this app will automatically send an SMS message, which contains a variant downloading link, to random selected friends in the background (Fig 8).
MainActivity.java
1
2
3
4
5
6
7
<syntax highlight java source>
publicvoidonPause(){
super.onPause();
MobclickAgent.onPause(((Context)this));
newShareTool(((Activity)this)).share();
}
</syntax highlight java source>
Figure 6. Sending SMS when the main activity is paused
Figure 7. Sharing the malware variants with friends
Figure 8. Send a downloading link of variants to randomly selected contacts
Country-Based Application Promotions
The Gunpoder samples will also pop up advertisements to promote other applications. In the code, we see the malware sample targeting as many as 13 different countries. For each country, the author uses specific URLs for downloading promoted applications. However, these download links are not active at the time of writing this post. From the debug code identified within the same sample, the name “Wang Chunlei” (Chinese) was discovered. This name is quite possibly the name of the malware author (Fig 9).
The Gunpoder malware family was discovered to aggressively push fraudulent advertisements to victims via the real Airpush library (Fig. 11). A fraudulent advertisement is one that attempts to trick a victim into clicking on it using subversive techniques. The fraudulent advertisement page attempts to mimic a Facebook page. It requests that victims finish a number of surveys and asks them to install various applications in order to receive a gift.
The captured Gunpoder logs were found to include information about these logs as well (Fig. 10). The malware collects and uploads very detailed user/device information from the victim. We have removed sensitive information from the URL in Fig 10. The commented out information includes the victim’s device id, device model, current location, etc.
Additionally, Gunpoder will collect information about all installed packages on the victim’s device. It also provides capabilities for executing payloads. The dynamic code for loading and executing the payload after decrypting reside in “com.fcp.a” and “com.fx.a” components.
Impact
Thus far, Palo Alto Networks has observed 49 unique samples of the Gunpoder family. We have found three different groups of variants within this family. By comparing samples of the various Gunpoder variants, we were able to make many observations about the evolution of Gunpoder.
Specifically, variants of group 1 (12 samples) can propagate via SMS and entice users to make a payments. Variants of group 2 (16 samples) can only entice users to make a payment, and variants of group 3 (21 samples) do not contain SMS propagation or entice users to make payments. Group 3 was discovered to be the newest of the Gunpoder malware variants.
Furthermore, the same certificate signed the first and second variants, while a different certificate signed the third variant. While the certificate varies between these groupings of variants, we highly suspect that the same malware author wrote all of these samples. A number of constant variables remain consistent between all three variants, such as the following that was identified in “Constants.java.”
Users will have a large bill, if they are tricked. The fake payment costs users only about $0.49 or $0.29, but the bill caused by sending SMS is much more than this. The total amount of the SMS bill depends on how many contacts reside in users’ devices.
Conclusion
Overall, the Gunpoder malware family contains a number of activities associated with adware. However, as we’ve previously discussed, a number of malicious functionalities exist as well. Examples of this include the ability to collect very sensitive information from victims, propagation via SMS messages, and the ability to execute other payloads.
The inclusion of the Airpush advertisement library causes many antivirus programs to simply label Gunpoder samples as adware, which is often not blocked by default. This allows some of the more malicious activity present in Gunpoder to continue unnoticed.
Protections
Palo Alto Networks released protections for users of WildFire, Threat Prevention and Mobile Security Manager for all currently known Gunpoder variants. Due to Palo Alto Networks unique prevention capabilities across the attack lifecycle, future members of the Gunpoder malware family could also potentially be blocked.
Everyone who has experienced a breach has had to have an “uncomfortable talk” with their employees or customers at some point. Telling people who know and trust your brand that they are at heightened risk is never a fun or easy discussion. I know, as in my past life at the U.S. Department of Homeland Security and serving the National Security Council, I shared in the thankless mission of helping agencies and companies to respond to, and recover from exactly these kinds of breaches.
It’s a glaring reality for businesses and government agencies that, despite upgrades to their IT infrastructure, security hasn’t kept pace. Networks could be protecting millions of customers’ data or enabling global operations, but most often organizations still have struggled with moving beyond legacy architectures and appropriately addressing their risk posture. For example, businesses that have undergone mergers and acquisitions face circumstances where old networks are bolted on to existing architectures, joining legacy systems to modern IT environments often with little thought to the new risks that are introduced. The fallout is that breaches repeatedly continue to take place exposing bank accounts, e-mail correspondence, and personally identifiable information.
The solution from both a government and a business standpoint is to work to simplify and strengthen network architecture, risk management practices, and cybersecurity strategy.
Architecting a network to focus on preventing breaches is the first step. Beyond static perimeter defenses, organizations need to think about disrupting cyberattacks at multiple points along their lifecycles. At Palo Alto Networks, our platform approach looks to safely enable applications and provide heightened visibility into user access and content across the network from the perimeter to the endpoint. This integrated approach allows for multiple opportunities to prevent initial intrusions, as well as stop the damaging release of private data.
The second step is for organizations to simplify and strengthen their risk management practices. Leadership should be fully aware of the business and mission risks cyber threats pose and work to focus appropriate resources toward addressing these risks. In corporations this means that CEOs should take an active role in building a risk management approach to cyber threats. Many governments are also moving important legislation forward. In the U.S., government agencies received two new legislative tools earlier this year that codify DHS as the lead for identifying and addressing cybersecurity risks, backed up by OMBs budgetary and oversight hammer to drive stronger cyber risk management practices across the Federal IT enterprise.
Finally, organizations must build a cybersecurity strategy focused on preventing, rather than simply responding to, breaches. In order to disrupt modern adversaries, organizations have to leverage advanced analytics and automation to clear away the cyber threat noise and focus on addressing the biggest risks first. The Palo Alto Networks Security Platform uses our threat intelligence cloud to enable automated prevention of breaches. Security elements such as ourWildFire service and AutoFocus analytics tool enable automated prevention and advanced threat detection for our private sector and government customers.
As more and more organizations suffer breaches involving customer or employee personal data, we must address these cybersecurity challenges by finding effective ways to simplify our security efforts making them accessible to a wide range of organizations. Whether government agency or pizza parlor, these organizations all hold our personal data and face similar challenges that can be addressed by developing sound network architectures, risk management policies, and cybersecurity strategies. The alternative is a world where we are forced to walk away from the benefits of a digitally connected society. Imagine having that talk with your customers…
To use Panorama for managing Palo Alto Networks firewalls, you must add the firewalls as managed devices and then assign them to device groups and templates. Panorama Templates allow you manage the configuration options on the Device and Network tabs on the managed firewalls. Using templates you can define a base configuration for centrally staging new firewalls and then make device-specific exceptions in configuration, if required. For example, you can use templates to define administrative access to the device, set up User-ID, manage certificates, set up the firewalls in a high availability pair, define log settings, and define server profiles on the managed firewalls.
How can I create a template?
Until you add a template on Panorama, the Device and Network tabs required to define the network set up elements and device configuration elements on the firewall will not display.
When creating templates, make sure to assign similar devices to a template. For example, group devices with a single virtual system in a one template and devices enabled for multiple virtual systems in another template, or group devices that require very similar network interface and zone configuration in a template.