More Bad News: The Bad Guys Are Getting Better

If there’s one lesson to be gained from all the security breaches and revelations of major bugs in security protocols in 2014, it’s that attackers are upping their game and finding more opportunities. That’s only reinforced by several new studies.

German security company G Data, for example, reported a huge increase in the number of new malware strains in the second half of the year — on average, a new type was discovered every 3.75 seconds! For the year as a whole, just under six million new malware strains were seen in the wild, some 77 percent more than 2013’s total.

Not all kinds of malware saw an increase. Those using backdoor vulnerabilities in software fell, for example, and worms and spyware remained relatively flat. But rootkits, while still a very small percentage of the overall number of malware, jumped more than ten-fold in the second half of the year.

Rootkits are software included in malware that help to embed the malicious part of the package in a system and ensure the persistence of additional attacks by helping the malware evade the scanners and monitors now used to detect it.

Not surprisingly, malware developers are mainly targeting the ubiquitous Microsoft platforms, with malware programmed as .NET applications continuing to rise. Overall, new variants for Windows platforms made up 99.9 percent of the new malware variants.

More problems could arise with Microsoft’s withdrawal of support for Windows XP in April last year, G Data said, because systems still using this operating system are “unprotected against attacks on existing or newly discovered security holes going forward.”

Akamai Technologies’ most recent State of the Internet survey similarly reported more than double the number of distributed denial of service attacks in the first quarter of 2015 compared to first quarter 2014, and over 35 percent the number in the final quarter.

DDoS attacks may not be such a big deal for the public sector, which gets only around two percent of the total. But Akamai noted a potentially dangerous trend in the 2015 attacks, with peak DDoS attacks of 100 Gbps making up a significantly bigger part of the total. That suggests attackers have been developing better ways to maximize the impact of their work.

At the rate attacks are progressing, Akamai said, security researchers are concerned about what attackers may be able to accomplish by this time next year. Add to that the fact that employing current attacks techniques “has not required much skill,” and even relatively inexperienced attackers could be capable of creating major damage as more potent tools enter the picture and attack bandwidth increases.

And what, then, to make of the recent news that the Defense Department is going to take a “no holds barred” approach with users who threaten security with sloppy cyber habits? Bad cyber hygiene “is just eating our shorts,” according to David Cotton, deputy CIO for Information Enterprise at the Pentagon.

Users will be given a very short time to comply with DOD password-security policies or to change behavior that invites phishing attacks while using  third-party social media accounts. The Pentagon is also pushing vendors to come up with more timely patches for security vulnerabilities, though recent research also points to the need to make sure patches are updated on all hosts at the same time.

The DOD, along with the intelligence agencies, is considered to be better at security than most other parts of the government, so it’s a little startling to read that the Pentagon’s crackdown as aimed at giving department leadership “a consolidated view of basic network vulnerabilities.”

Isn’t this supposed to be the very first thing organizations do when assessing security needs? And if the DOD doesn’t even have this bit of the puzzle sorted out, how is it ever going to successfully defend against the threats indicated by the G Data and Akamai reports?

Perhaps it’s finally time for government organizations to give up on security that is user focused. The Cloud Security Alliance’s “Dark Cloud” project could be one way of doing that.

Posted by Brian Robinson

[GCN]

Cyber Threat Analysis: A Call for Clarity

The general public deserves less hyperbole and more straight talk

I must admit that I’ve grown increasingly weary over the constant harangue in the popular press about the ever-increasing volume and severity of “cyber attacks” worldwide. The apocalyptic language, the fear mongering, and the dearth of clear and simple explanatory language obscures an already complex topic. The general public deserves less hyperbole and more straight talk.

Don’t get me wrong. I’m not downplaying the threats we are facing. Advanced persistent threat actors are homesteading on sensitive federal agency and corporate networks. Cyber threats to industrial control systems (ICS) threaten to hold critical facilities and economic sectors at risk. Denial-of-service attacks, financial compromises, and intellectual property theft disrupt our economy and sow distrust in our banking and commercial sectors.

As analysts, we must better frame this public discussion. We can start by doing what we do best – defining and explaining the nature of the problem we confront. Commentators often lump together a wide range of malicious network activity as “attacks,” disregarding the fact that we can distinguish activity by type, intent, and degree. These differentiations matter; they speak to the nature and intent of the threat actors, which ultimately is what we should be most concerned about.

Espionage & Attack
Traditionally, we differentiate between espionage and attack, and we should do the same with network activity. When the Justice Department indicts a Robert Hanssen, or arrests a group of Russian “illegals” living in the United States, we do not characterize their espionage as “attacks.” Nor should we label the reported intrusions into the White House and State Department networks as “attacks,” lest we conjure up images of combat and destruction that are inappropriate to the event. Perhaps labeling every cyber incident as an “attack” advances some political or corporate purposes. As analysts with a professional commitment to critical thinking, we must play stronger roles in structuring this conversation in ways that advance our collective understanding.

Real network attack modifies the function of a network or a physical system that the network controls. We now witness first-generation network attack capabilities taking the field: industrial control system attacks in Iran (2010) andGermany (2014); and corporate network attacks in Saudi Arabia and Qatar(2012), South Korea (2013) and the United States (2014). Federal agencies and security firms continue to identify industrial control attack tools (some of which had gone unrecognized for years) that may reside on any number of sensitive control systems worldwide. Global proliferation of increasingly destructive network attack capabilities warrants serious attention and should be properly differentiated from espionage.

A Chinese hacker stealing intellectual property from a US defense contractor is qualitatively different from a BlackEnergy implant in a natural gas pipeline control system. Both are malicious activities, but differ substantially in intent and degree of potential impact.

Sometimes clear differentiation eludes us. Espionage and attack often employ similar means of ingress, exploitation, and persistent presence. Some operations—such as the Sony Pictures Entertainment hack—combined elements of both. These challenges should compel us to explore new ways to clearly identify and characterize cyber threats.

A way forward
As analysts with a dedication to tradecraft, we must seek out approaches that better differentiate malicious activity by type and intent. We must move the conversation past malware and digital forensics, which surely play a vital role in cyber intelligence but often offer limited explanatory power for key audiences. Most importantly, we must develop tradecraft that anticipates future threat environments, rather than simply describe and characterize present (or past) ones.

We should resist taking the bait that the popular press offers: to lump together all threat activities under one moniker of “attack.” Failing to offer at least some degree of activity differentiation only contributes to the malaise that strangles our general discussion on the nature of cyber threat.

Do not dismiss the general public as incapable of understanding the technical nuances of cyber threat activity. Our audiences are savvier than we give them credit for; to condescend to them or even write them off altogether is simply high-tech hubris. Even more important, popular understanding matters. An informed public discourse—the cornerstone of any democratic society—forms the basis for developing sound public policy. In our role as analysts, we owe this process the best of our tradecraft, our intellectual rigor, and simple clarity.

Michael McMahon is Director, Cyber Strategy and Analysis at Innovative Analytics & Training, LLC, a Washington, DC-based research consultancy and professional services firm. Mike is a 25-year veteran of the US intelligence community, serving most recently on the National Intelligence Council. He holds Master’s degrees from George Washington University and the National War College, and also serves as an adjunct lecturer in the Liberal Studies program at Georgetown University.

Mike brings his background in political science and international relations theory to the emerging discourse on role of cyber capabilities as an instrument of statecraft. He’ll be glad to get in your face on the problems of deterrence and the security dilemma in cyberspace, or how social contract theory can help us anticipate developments in global network governance, but don’t ask him how to fix your hard drive.

[DarkReading]

Closing the Cybersecurity Gap for Industrial Control Systems

Many of today’s industrial control systems (ICS) are considered to be antiquated, making them vulnerable to a cyberattack, especially if they are interconnected with traditional information and communications technology (ICT). Think about electricity, water and energy production as typical places where ICS are in place.

The problem is that these ICS systems have been isolated—separate and apart from IT. But, in today’s converged system environment, ICS are becoming part of the greater enterprise. This makes ICS and IT vulnerable to the same threat agents and attack vectors.

Risk management and governance are critical, no matter if someone is responsible for defending the infrastructure of a manufacturing plant or the corporate network.

In fact, the current state of ICS cybersecurity is described as “turbulent,” according to ISACA’s new, comprehensive white paper about ICS and related risks, titled: “Industrial Control Systems: A Primer for the Rest of Us.”

The guide looks at the current environment of ICS, and discusses the differences and similarities between ICS and IT. The guide points out that while ICS people are operational in nature, IT professionals have a focus that is system or task- specific. An understanding of these cultural differences provides a context where it is possible to explore similarities and distinctions.

The guide suggests there are many advantages to creating and sustaining cross-functional teams of ICS and IT cybersecurity professionals, including:

  • Opportunity to for cybersecurity professionals to share their unique perspectives
  • An agreed understanding of risk management and governance
  • Establishment of a dialogue about shared assets and associated risks

The good news is that much positive work has already been done to create standards, offer training, hold conferences and create relevant certifications.

Monica Jain, CGEIT,CSSBB, CSQA, GSLC
Senior program/project manager

[ISACA]

ISACA International President: The Nexus of Cybersecurity News

Information is powerful. In today’s fast-moving world, timely information is critical to keeping cybersecurity plans and programs current.

But, having the time and diligence to filter massive amounts of information to a digestible, actionable form is nearly impossible. Besides myriad global regulations and other developments, all manner of cybersecurity breaches are frequently in the news. In fact, the growing rate of breaches around the world has organizations preparing for when they will be attacked, rather than wondering if they will be.

To provide a concise source for the industry trends and latest developments cybersecurity experts need to know about most, ISACA has launched a new free newsletter. The Nexus, which is part of ISACA’s Cybersecurity Nexus (CSX) program, features original CSX thought leadership and knowledge, news and updates related to cybersecurity, and a collection of cybersecurity articles from around the web .

Recent articles in The Nexus include:

  • Cybersecurity table stakes for companies: The bare minimum needed to survive by Doug Steelman.
  • 5 Costly consequences of SMB cybercrime from CIO Magazine.
  • Simple steps go a long way in cybersecurity by Rolf von Roessing, CISA, CISM, CGEIT

Visit The Nexus subscription page of the ISACA web site to subscribe to this valuable monthly e-newsletter.

Robert E Stroud, CGEIT, CRISC
ISACA International President

[ISACA]

Protecting The Data Lifecyle From Network To Cloud

Enterprises are pushing more sensitive and regulated data into the public cloud than ever before. But the journey carries many new risks.

When thinking about protecting data in the cloud, there are three areas of use that security and privacy professionals need to consider: data in motion, data at rest and data in use. In a nutshell, the data leaves your environment and goes from to point A (your network) to B (the cloud); within point B it gets initially processed and stored within a database, and then is pulled out of that database for processing. Each of these phases carries risk:

  • The first area, data in motion, is the most well known and understood. The goal of protecting data in motion is to prevent a third party from eavesdropping on a conversation on the transmission wire.
  • The next key area, data at rest, is also relatively well understood. Data at rest is essentially the data that is stored persistently in some form, as a file, in a database, etc. The goal of protecting data at rest is to prevent a third party from reading the data, should they gain access to the data in its persistent form (for example, when an attacker gains access to the file system and opens or copies the files).
  • Data in use is, effectively, the data that has been loaded into a process and is in the memory of the program that is running. In general, this data is in the clear while being processed and is typically not protected by techniques such as the in-cloud based encryption provided by Cloud Service Providers (CSPs).

In each of these three phases, there are security mitigation techniques that address the corresponding issues. Several approaches need to be evaluated, and at minimum, enterprises need to explore what their CSPs have to offer:

Data in Motion: Cryptographic protocols, such as Secure Sockets Layer (SSL) or Transport Layer Security (TLS), are typically used for protecting data in motion by establishing an encrypted and authenticated channel. Note that the data payload inside the transportation layer is still in the clear, so exploring encrypting the data itself versus (or in addition to) encrypting the wrapper should be evaluated.

Data at Rest: To protect this data, database solutions used by CSPs offer a variety of tools for encryption operations, such as transparent data encryption (which encrypts the database blocks on disk) or column encryption (which directly encrypts the column values). Moreover, there are several techniques that can be employed to encrypt file contents including encrypted file systems and block level encryption techniques.

You should note that a big concern regarding the encryption of data at rest in a cloud environment is who owns the keys, and where the keys physically reside. The benefits of data at rest protection are somewhat weakened if the data, and the key used to encrypt the data, are both stored in a less trusted security zone, such as the CSP’s environment. In response, CSPs are innovating in this space and are developing techniques whereby the enterprise, not the cloud service provider, can at least virtually owns the keys securing data at rest (even though they physically reside elsewhere).

Data in Use:  In this case, data is in the clear while being processed and is not protected by techniques such as the in-cloud based encryption provided by the CSP. The Cloud application actually needs to decrypt data from its encrypted at rest state in order to perform any and all required application processing within the CSP datacenter.  A new category of technologies focusing on data protection — dubbed by Gartner as cloud access security brokers (CASB)  — is a solution to explore here. These solutions can encrypt data before it leaves the enterprise to provide protection during the data in use phase, as well as the other data lifecycle phases. Enterprises considering these technologies should ensure that they evaluate them to identify any impact they may have on the functionality of their cloud applications. (Disclosure: Perspecsys is one of many CASB vendors with this technology).

As cloud adoption pushes greater volumes of sensitive and regulated data into cloud-based SaaS applications, it’s more important than ever for security and compliance professionals to ask the right questions about where cloud data is flowing, who has access to it and what protection mechanisms can be put in place to mitigate risks.

Gerry Grealish

[Dark Reading]

English
Exit mobile version