New Traps v3.4 Features Improve Protection in Healthcare Environments

With all the recent ransomware attacks, the healthcare industry can use some help in the area of endpoint security. As we’ve seen in the past few months in ransomware attacks on hospitals in WashingtonCalifornia and Kentucky, malware and software exploits are commonly used together by malware operators to deliver a payload and compromise a system or, worse, a group of systems at the same time. As part of Palo Alto Networks Next-Generation Security Platform, Traps advanced endpoint protection plays a key role in a cyberattack prevention strategy by preventing malware and exploits. Traps was recently enhanced and now uses a “multi-method prevention” approach that combines the most effective, purpose-built malware and exploit prevention methods to protect endpoints from known and unknown threats.

Let’s look at Traps capabilities and highlight several new ones recently added to Traps v3.4 that eliminate the need for a traditional antivirus, and are especially beneficial to healthcare organizations.

Traps multi-method prevention for malware incorporates the following five techniques:

  1. Static Analysis via Machine Learning: (new for v3.4): This malware prevention method evaluates an executable file before it is allowed to run by examining several characteristics of the file itself to determine if it is likely to be malicious or benign. The threat intelligence available through WildFire is used to train a machine learning model to recognize malware, especially variants that have never been seen before, with high accuracy.

Medical practitioners are increasingly working remotely and disconnected from the hospital network. This new method of analysis is especially effective in healthcare environments, for this reason, as offline devices cannot take advantage of the multiple prevention methods that are available through WildFire.

  1. Quarantine of malicious executables (new for v3.4): Prior versions of Traps killed malicious processes. Traps v3.4 now immediately removes malicious files to prevent further propagation or execution attempts of infected files.
  1. WildFire Inspection and Analysis: Traps works with WildFire to determine whether an executable file is malicious. WildFire can eliminate the threat of the unknown by transforming it into known, in about 300 seconds. The automatic reprogramming of Traps, and the conversion of threat intelligence into prevention, all but eliminates the opportunity for an attacker to use unknown and advanced malware to infect a system.
  1. Trusted Publisher Execution Restrictions (new for v3.4): This malware prevention method allows healthcare organizations to identify executable files that are among the “unknown good” because they are published and digitally signed by trusted publishers, or entities that Palo Alto Networks recognize as reputable software publishers (i.e., Microsoft). These executable files are considered benign and, therefore, allowed to run.

Hospitals will often have a number of self-signed applications in their environment. Now you can optionally select to trust certain untrusted signers (like your local signature authority). Any unsigned apps or untrusted signers are tested with other capabilities, like WildFire and local analysis.

  1. Policy-Based Execution Restrictions: Healthcare organizations can easily define policies to restrict specific execution scenarios, thereby reducing the attack surface of any environment. An example would be to prevent the execution of a particular file type directly from a USB drive.
  1. Admin Override Policies: This method allows healthcare organizations to define policies, based on the hash of an executable file, to control what is allowed to run in any environment and what is not.

Traps Multi-Method Prevention for Exploit Prevention includes the following three approaches:

  1. Memory Corruption/Manipulation Prevention: Memory corruption is a category of exploitation techniques where the exploit manipulates the operating system’s normal memory management mechanisms for the application opening the weaponized data file that contains the exploit. This prevention method recognizes and stops these exploitation techniques before they have a chance to subvert the application.
  1. Logic Flaw Prevention: Logic flaw is a category of exploitation techniques that allow the exploit to manipulate the operating system’s normal processes that are used to support and execute the target application opening the weaponized data file. For example, the exploit may alter the location where dynamic link libraries (DLLs) are loaded from into an application’s execution environment so that the exploit’s malicious DLLs can replace legitimate ones. This prevention method recognizes these exploitation techniques and stops them before they succeed.
  1. Malicious Code Execution Prevention: In most cases, the end goal of an exploit is to execute some arbitrary code — the attacker’s commands that are embedded in the exploit data file. This prevention method recognizes the exploitation techniques that allow the attacker’s malicious code to execute and blocks them before they succeed.

Biggest Benefits of Using Traps in Healthcare Environments

  • Traps mitigates risks of EoL operating systems: Although efforts were launched in many hospitals to upgrade or replace end-of-life operating systems running on hospital workstations (Windows XP and Server 2003), there are still many in service today. Those machines most likely have not been removed yet due to application dependencies. Traps can be installed as a compensating control to EoL operating systems by preventing the exploitation of both known and unknown vulnerabilities.
  • Traps mitigates risks of falling behind in your patch management: Software patch management of endpoints is an ongoing challenge for healthcare institutions. Keeping up to date with the monthly Adobe Acrobat, Flash and Microsoft patches is a very complicated task and many fall behind. Although you should still patch monthly, Traps offers protection from exploitation of both known and unknown vulnerabilities in case you fall behind.
  • Traps may be accepted as a PCI compensating control: Many customers tell us that their PCI qualified security assessor (QSA) accepts Traps as a compensating control for unpatched systems. Talk to your QSA to see if they will accept it too.

Learn more about Traps:

[Palo Alto Networks Research Center]

A Powerful Combination: New Cyber Breach Prevention Offering

Palo Alto Networks, Accenture, Splunk, and Tanium have teamed up to create an advanced managed cyber defense offering that makes it easier, more efficient and effective to identify, prevent, detect, and respond to attacks.

Accenture has integrated the Palo Alto Networks Next-Generation Firewalls and Traps Advanced Endpoint Protection offering, Tanium’s endpoint visibility software, and Splunk Enterprise Security with its own operating model and cyber defense architecture to construct the new Accenture Cyber Defense Platform.

This combination of technologies will help organizations better defend their networks, protect their endpoints, gain insight into the security behaviors within their enterprise, and effectively automate breach detection, prevention, response and recovery efforts.

Incident response is often too little, too late to effectively deal with increasingly sophisticated attackers. This collaboration will help organizations transition to the necessary prevention-minded security approach, as well as expand visibility, enhance analytics capabilities, and protect from the latest cyberthreats.

To learn more, please visit the Accenture Cyber Defense Platform.

[Palo Alto Networks Research Center]

Not All Next-Generation Firewalls Are Created Equal

As cybersecurity threats increase in sophistication, the security solutions used to defend against these threats must also evolve. Developers no longer adhere to standard port/protocol/application mapping; applications are capable of operating on non-standard ports, as well as port hopping; and users are able to force applications to run over non-standard ports, rendering first-generation firewalls ineffective in today’s threat environment. Enter the “next-generation firewall” (NGFW), the next stage of firewall and intrusion prevention systems (IPS) technology.

A common understanding of an NGFW is a network platform that combines the traditional firewall functionalities with IPS and application control. However, merely bundling traditional firewalls with IPS and application control does not result in an NGFW. A true NGFW emphasizes native integration, classifies traffic based on applications rather than ports, performs a deep inspection of traffic and blocks attacks before a network can be infiltrated. Here is a list of key features of a true NGFW to better inform your next purchase decision.

Identify and control applications and functions on all ports, all the time

An NGFW should identify traffic on all ports at all times, and classify each application, while monitoring for changes that may indicate when an unpermitted function is being used. For example, using Citrix GoToMeeting for desktop sharing is permitted but allowing an external user to take control is not.

Identify users regardless of device or IP address

Knowing who is using which applications on the network, and who is transferring files that may contain threats, strengthens an organization’s security policies and reduces incident response times. An NGFW must get user identity from multiple sources – such as VPN solutions, WLAN controllers and directory servers – and allow policies that safely enable applications based on users, or groups of users, in outbound or inbound directions.

Identify and control security evasion tactics

There are two different classes of applications that evade security policies: applications that are designed to evade security, like external proxies and non-VPN-related encrypted tunnels (e.g., CGIProxy), and those that can be adapted to achieve the same goal such as remote server/desktop management tools (e.g., TeamViewer). An NGFW must have specific techniques that identify and control all applications, regardless of port, protocol, encryption or other evasive tactics and know how often that firewall’s application intelligence is updated and maintained.

Decrypt and inspect SSL and control SSH

An NGFW should be able to recognize and decrypt SSL and SSH on any port, inbound or outbound; have policy control over decryption; and offer the necessary hardware and software elements to perform SSL decryption simultaneously across tens of thousands of SSL connections with predictable performance.

Systematically manage unknown traffic

Unknown traffic represents significant risks and is highly correlated to threats that move along the network. An NGFW must classify and manage all traffic on all ports in one location and quickly analyze the traffic, known and unknown, to determine if it’s an internal/custom application, a commercial application without a signature, or a threat.

Protect the network against known and unknown threats in all applications and on all ports

Applications enable businesses, but they also act as a cyberthreat vector, supporting technologies that are frequent targets for exploits. An NGFW must first identify the application, determine the functions that should be permitted or blocked, and protect the organization from known and unknown threats, exploits, viruses/malware or spyware. This must be done automatically with near-real time updates to protect from newly discovered threats globally.

Deliver consistent policy control over all traffic, regardless of user location or device type

An NGFW should provide consistent visibility and control over traffic, regardless of where the user is and what device is being used, without introducing performance latency for the user, additional work for the administrator, or significant cost for the organization.

Simplify network security

To simplify and effectively manage already overloaded security processes and people, an NGFW must enable easy translation of your business policy to your security rules. This will allow policies that directly support business initiatives.

Perform computationally intensive tasks without impacting performance

An increase in security features often means significantly lower throughput and performance. An NGFW should deliver visibility and control including content scanning, which is computationally intensive, in high-throughput networks with little tolerance for latency.

Deliver the same firewall functions in both a hardware and virtualized form factor

Virtualization and cloud computing environments introduce new security challenges, including inconsistent functionality, disparate management and a lack of integration points. An NGFW must provide flexibility and in-depth integration with virtual data centers in private and public cloud environments to streamline the creation of application-centric policies.

To learn more about what features a NGFW must have to safely enable applications and organizations, read the 10 Things Your Next Firewall Must Do white paper.

[Palo Alto Networks Research Center]

Ransomware Growing More Common, More Complex; Modern Endpoint Backup Isn’t Scared

The growing ransomware threat isn’t just about more cybercriminals using the same cryptoware tools. The tools themselves are rapidly growing more sophisticated—and more dangerous.

Ransomware growing exponentially, with no signs of slowing
A new report from InformationWeek’s Dark Readinghighlights key trends in the ransomware landscape, starting with the dramatic increase in total ransomware attacks. Ransomware attacks increased by 165 percent in 2015 (Lastline Labs), and this trend isn’t letting up. Anti-spyware company Enigma Software reported a 158 percent jump in the number of ransomware samples it detected between February and March 2016—and April 2016 was the worst month on record for ransomware in the U.S.

It’s also clear that ransomware growth is independent of the overall increase in cyberattacks over the past several years. The 2016 DBIR reported that phishing attacks are more common than ever, and Proofpoint found that in the first quarter of 2016, nearly 1 in 4 (24%) of all email attacks using malicious attachments contained just one strain of ransomware (Locky).

Not just more common—ransomware growing stronger and more effective
Most alarmingly, DarkReading reports that cyberattackers are rapidly evolving and diversifying their ransomware arsenal. Ransomware has become big business, and with that cash flow comes development of more complex ransomware strains and more clever techniques for infecting targets. In an ironic twist, creators of popular ransomware such as Locky are now working to “protect” their cryptoware from enterprising copycats who create knockoff versions and variants. No honor among thieves, indeed.

Better phishing lures, more brute-force attacks
DarkReading spotlighted two examples of this increasing sophistication. On the one hand, cybercriminals are developing new, more obscure ways of luring a user to install ransomware. From personalized landing pages to actually hacking a device’s boot-up process, stopping these techniques is much more complicated than just saying, “Don’t click suspicious links.”

At the same time, attackers increasingly skip the phishing lure and go straight to brute-force attacks on internet-connected remote desktop servers. For the skilled hacker, this technique is more reliable than phishing, and immediately gets the attacker much deeper into an enterprise network, allowing them to compromise more devices and ransom more data.

“No backup, no protection”
With ransomware mutating into an even bigger threat, Dark Reading encouraged companies to go back to basics, citing data backup as the essential first step in enterprise ransomware defense. We couldn’t agree more. No matter how complex and advanced the ransomware, modern endpoint backup isn’t scared. Modern endpoint backup gives you guaranteed recovery in the face of ransomware. But its protection goes beyond backup: Modern endpoint backup sees your endpoint data, sees your users’ endpoint activities, and gives you the visibility to identify and neutralize an attack as soon as it hits.

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about selecting a modern endpoint backup solution in a dangerous world.

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

Whaling Goes After the Big Phish

The bigger the phish, the fatter the payoff for cybercriminals. That thinking is driving a spate of whaling cyberattacks targeting C-level executives and their employees around the globe.

Whaling attacks go far beyond the typical phishing expedition in that perpetrators do their homework and learn everything they can about their intended C-suite victims and their organizations to ultimately convince them or their associates to give up credentials, information and/or financial assets. They produce believable emails that appear to be from trusted internal or external business partners that actually contain malware and URLs to download malicious payloads and link to dubious web sites all in hopes of a handsome payday. Whaling uses social engineering to prey on the weakest link in cyberdom:  humans.

I expect the surge in whaling to continue because cybercriminals are having success duping top executives and their associates. Similar to advanced persistent threats (APTs), whalers study how people write, what their email looks like and whatever else they need to know to show potential victims the personal touches that really sell the impersonation. Producing genuine-appearing email is how the criminals succeed in convincing top executives the requests are real. A key part of the ruse is the request for confidentiality and the need to bypass approval channels.

Whaling Costs Enterprises Plenty
Successful whaling attempts are so believable and seemingly trustworthy that executives who should probably know better are clicking on links and attachments that appear to be from fellow executives, employees or business partners. One stellar example of this includes a senior executive with a security firm who received an email that appeared to be from an underling but was actually from a whaler. He was tricked into giving up employee W-2 data.

Another incident involved an executive from a major soft drink company that was in talks to choose a bottler in a highly profitable, under-serviced country. Before negotiations were completed, someone working under the executive was spear phished, and the whaler was able to harvest all email related to the negotiations, jeopardizing the talks and putting the company at a distinct disadvantage.

A third case involved a top executive of a 40-year-old company that made a unique product that had just one competitor in the world. One day the executive noticed the sudden appearance of a new competitor that was selling a nearly identical product but at a significantly lower price. It turned out that the man had been whaled. Through social media, the cyberattackers learned he had a passion for antique cars. They concocted an email with a link to a fake online auto trading ad for a car deal that was too good to be true. Excited by the car and the unbelievable deal, he double clicked on the link and almost immediately 40 years of research, development and blueprints were in the hands of an unknown competitor. The company was unaware that their information had been compromised until the new competitor showed up on the market six months later.

One whaling email can sink a company or cost top leadership their jobs. A January 2016 whaling attack against an Austrian aircraft parts manufacturer resulted in the loss of US $45,693,480 and the firing of both its CFO and CEO.

Challenges Go Deep
Email is the lifeblood of business today, so living without it is not an option. But addressing the whaling problem presents a number of challenges thanks primarily to the human factor. For example, employees who receive emails from high-ranking executives are often hesitant to question their validity. They want to handle any and all requests from higher ups quickly and efficiently to gain favor with their boss. On top of that people are often overworked, so the last thing on their mind is whether or not an email is legitimate. Finally, employees today are often less committed to their organizations than we would like. Allegiance to employers can be weak or nonexistent, so why should they care about whaling attempts? Your company’s whaling defenses are only as good as your least knowledgeable and dedicated employee.

Training, Training, Training
What can be done to protect organizations against whaling? In a word:  training. Training to increase education and awareness of cyber schemes such as whaling, phishing and the like, is critical to combatting these incidents. For email requesting out of the ordinary access to data or assets, secondary verification is critical. A quick phone call is all it takes. And always check the sender’s email address. Security should never be weakened in exchange for speed or expediency.

Training should be regular, engaging and include every person in the organization, including C-suite personnel. Poor or condescending training can be worse than none at all, so make sure you develop effective training and do not talk down to employees. Training and awareness efforts should be ongoing and can include weekly email blasts to reinforce training and maintain and increase awareness.

Obviously, if your organization has an IT professional with cybersecurity credentials such as a CSX Cybersecurity, Fundamentals,Practitioner, Specialist or Expert certificate, they can provide invaluable resources to ensure effective training.

Daniel Libby, Director and Chief Examiner, Digital Forensics Inc.

[ISACA Now Blog]

English
Exit mobile version