Palo Alto Networks Honors Our Wounded Warriors at Army-Navy Football Game

The Wounded Warrior Project’s purpose is to “raise awareness and enlist the public’s aid for the needs of injured service members” in our country. This past weekend, the nation watched the 116th edition of the massive football rivalry between the Cadets of the United States Military Academy and the Midshipmen of the United States Naval Academy. To celebrate that, and to support the Wounded Warrior Project, Palo Alto Networks hosted several injured veterans, and their families, in a luxury suite at the game.

Our Federal Chief Security Officer, U.S. Army Major General John Davis (Retired), and I had the opportunity to thank the brave men and women before the game; and host these Wounded Warriors, their families, and, yes, one good-looking support dog in the suite for the day. We were honored, but humbled, to have the chance to support the Wounded Warrior Project’s critical mission and ongoing work.

These injured veterans and their families have borne the burden of our past wars. They have stood up to fight for the things they believe. Army Chaplain Matthew Pawlikowski, in his opening prayer before the game, said it best:

“Gathered on this gridiron, we are grateful for such rough and rugged souls as these cadets and midshipmen, strong in spirit and in sinew. We are especially mindful of our first-class cadets and midshipmen, bristling on the brink of becoming soldiers, sailors, marines, ready today to happily visit violence on each other, and if need be, some day, sometime soon, on the enemies of the world, so that our citizens, our ally citizens, indeed the same citizens of all countries, can sleep safe and sound in peace.

For those of us who have fought, who can fight, who will fight, our country’s wars pray for peace more than those who have never served can ever know, for we willingly face the horrors from which others are thankfully spared.

But if peace on earth be not granted us in this season of our lives,
then we pray, almighty god, that on these fields of friendly strife,
be sown the seeds that on other fields on other days will bear the fruits of victory.  

Amen.”

Our injured veterans know this story all too well. You can support them and the Wounded Warrior Project by getting involved. Learn how by visiting the Wounded Warrior Project website.

[Palo Alto Networks Blog]

2016 Prediction #10: Cyberthreat Intelligence Sharing Goes Mainstream

This is the tenth in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

There are few areas of cybersecurity that present more promise than the concept of sharing threat intelligence to make online communities, and the Internet as a whole, a safer place.

No single organization is capable of achieving complete visibility into the threat landscape. But by joining together and sharing threat intelligence across the industry, we can enhance our collective immune system. The challenge, as is often the case, has been around putting that into practice.

There have been pockets of innovation, such as the Information Sharing and Analysis Centers (ISACs) or security vendors sharing intelligence between their customers. But as attackers continue to conduct successful cyberattacks around the world, this is clearly not enough. Current efforts provide value, but they are often cumbersome and only accessible to larger and more sophisticated security operations teams. There is essentially a high “barrier to entry,” with manual analysis required to consume, verify, analyze and implement any changes to an organization’s policy, even with adequately shared intelligence.

This requirement has limited the number of organizations who share intelligence, meaning we have less of it available than we should. Now, imagine a world where every security team can turn their network into a sensor and automatically implement protections for new attacks as they happen. This puts malicious actors at a disadvantage, requiring them to spend immense resources to discover new exploits, construct new malware, and employ new techniques.

The past year has shown us early indicators that 2016 will be the year organizations truly embrace – and reap the benefits of – shared threat intelligence. We will see this change the way both security vendors and the security community at large operate. I anticipate three specific changes:

1. Threat intelligence is not intellectual property

Organizations have historically been hesitant to share data on threats. From a security vendor side, this stems from a common belief that their product differentiation is dependent on keeping this intelligence a closely guarded secret.

From a user perspective, many organizations have also operated under the assumption that sharing intelligence with their competitors could expose sensitive information or put them at a competitive disadvantage. But, in 2016, we will see more vendors come to the realization that their users, and the community, have come to expect more from them. In order to offer the best protections possible, vendors will begin to share intelligence with each other on a wider scale.

2. Public and private data sharing

There has never been more focus from the United States government on the sharing of threat intelligence, with President Obama directing the Department of Homeland Security (DHS) to lead the charge to enable public and private entities to share intelligence with each other inExecutive Order 13691.

This coming year will see the result of these efforts formalized and put into practice, withInformation Sharing and Analysis Organizations (ISAOs) being established and intelligence shared across private, non-profit and government agencies. Spurred by this innovation, we will see governments beyond the U.S. adopt similar policies.

3. Campaigns, not samples

We will see an evolution in what is being shared, with a move toward more adversary- and campaign-oriented intelligence. Traditional efforts have been focused on indicators such as hash values, which provide minimal actionable value to the organizations receiving them. Instead, we will see more effort around malware family and adversary attribution, which provide the context needed to understand the threat and develop relevant protections against them. Simply sharing data will no longer be good enough; we have to share the right intelligence, with actionable recommendations.

The coming year represents the fruition of the great promise in threat intelligence sharing. The world is changing, and both vendors and users must adopt a more proactive stance to sharing, lest they risk being left in the dust by those who do.

We have a responsibility as a security community to do everything in our power to prevent cyberattacks, which includes sharing as much intelligence as possible. While there is a great deal of momentum in 2016, we can do more to reap the benefits of this trend. Ask yourself how your organization can integrate and contribute to keeping our community safe online.

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

iOS Trojan “TinyV” Attacks Jailbroken Devices

In October 2015, we discovered a malicious payload file targeting Apple iOS devices. After investigating, we believe the payload belongs to a new iOS Trojan family that we’re calling “TinyV”. In December 2015, Chinese users reported they were infected by this malware. After further research, we found the malware has been repackaged into several pirated iOS apps that are available for download via multiple channels. In this blog, we will discuss how the TinyV Trojan spreads and how it works.

Repackaging and Spreading

TinyV was repackaged into some pirated iOS apps for jailbroken devices. Infected iOS apps include “Watermelon Player (西瓜播放器)”, “Youku (优酷)”, “iQiYi (爱奇艺)” and others. After repackaging, these apps were uploaded to websites for downloading.

The infected Watermelon Player was available from its official website xigua[.]com. It is advertised as an app for watching pirated videos online for free. The infected versions of Youku, iQiYi, and other apps were hosted on third party iOS app download sites such as iosqgg[.]com and piqu[.]com (which belongs to a tool named “PiQu Apple Helper 批趣苹果助手”). They were advertised as modified ad-free versions of those popular video players (in China).

Figure 1. Watermelon Player’s official website hosts the infected app

Figure 2. A third party website hosting infected “ad-free” video players

Figure 3. Another third party iOS app downloading website hosting infected apps

When using an iOS device to access piqu[.]com to download the pirated version of Youku, a URL like the following is accessed:

  • itms-services://?action=download-manifest&url=https%3A%2F%2Fappsre.com%2Fdj_plist_data.php%3Fdata%3DYmlkPWNvbS55b3VrdS5Zb3VLdSZu…

This URL will re-direct the iOS device to download a PLIST file hosted in “appsre[.]com” and then to install an enterprise app described by this PLIST file. According to the PLIST file, the IPA installer file to be downloaded is “pq_com.youku.YouKu.5.0.ipa”, which is also hosted on appsre[.]com.

Figure 4. The infected app installer was actually hosted on appsre.com

TinyV is repackaged differently than prior iOS or OSX malware such as WireLurker. In Watermelon Player’s iOS installer file, “com.xiaoxiaov.ipa”, there are actually two executable files. One is the main executable Mach-O file we expect and the second is Mach-O dynamic library file named “xg.png”. In the main executable file’s import table, the last import entry is “@executable_path/xg.png”. Which means after the app is executed, the xg.png file will be loaded (and the code in it will be executed). Note that the main executable and the xg.png were not compiled in the same environment as the xg.png was infected by the XcodeGhost malware while the main executable wasn’t.

Similarly, in the infected version of Youku, there are some extra Mach-O dynamic library files named “dj.png”, “macro_off@2x.png” and “zippo_on@2x.png” in addition to its main Mach-O executable file “YoukuiPhone”. The TinyV author modified the original YoukuiPhone file, added “@executable_path/zippo_on@2x.png” and “@executable_path/dj.png” to its imports table.

Figure 5. Import table of the infected app’s main executable

The loaded xg.png will invoke its -[hlNDkcAzamMgoaQm downloadDeb] method to connect with the C2 server wx[.]iosyy.me and fetch configuration information. The configuration supplied by the C2 specified a “debUrl” that points to the URL of a ZIP file, and specified a “shName” with the value “zipinstall”.

Figure 6. The extra Mach-O dynamic library accesses a URL supplied by its C2 to download a malicious payload

In the infected Youku, “macro_off@2x.png” will access another page on the same C2 server to get its configuration. This time the “debUrl” value is encrypted with an XOR algorithm. Despite the attempt at obfuscation, after decrypting with the key “0xaf”, the same URL is shown.

Malicious Behaviors

After getting configuration from its C2, TinyV will download a ZIP file from the given “debUrl” value. The ZIP file examined here was hosted on another C2 server, apt[.]appstt.com. While we were writing this report, the URL returned a 404 error. However, when we initially investigated it in late October, the URL was still alive and a “deb.zip” file was downloaded.

In the deb.zip, there are 4 files:

  • safemode.deb, which is the official MobileSafety tweak provided by Saurik
  • freeDeamo/usr/bin/locka, which is a Mach-O executable that implemented malicious behaviors;
  • freeDeamo/Library/LaunchDaemons/com.locka.plist, which is a PLIST file used to config “locka” as a launch daemon in iOS;
  • freeDeamo/zipinstall, which is a shell script file.

After downloading and decompressing this ZIP file, xg.png will execute the zipinstall script to install locka and com.locka.plist as a launch daemon as detailed below.

  1. Copying locka to /usr/bin, changing its user and group to root:wheel, and changing its file permission to 755;
  2. Copying com.locka.plist to /Library/LaunchDaemons/, changing its user and group to root:wheel, and changing its file permission to 644;
  3. Executing /bin/launchctl to load the com.locka.plist.

Figure 7. The malicious executable file is installed as a launch daemon

The locka file implements the main malicious behaviors of TinyV, including:

  • Connecting with its C2 server to get remote commands
  • Installing specified IPA file or DEB file(s) in the background
  • Uninstalling specified IPA app or DEB package(s) in the background
  • Changing the /etc/hosts file

Figure 8. Some of the functions in locka

Just like the previously discovered Trojan YiSpecter, this locka implemented IPA file installation and uninstallation via iOS private APIs is defined in the MobileInstallation framework.

Figure 9. TinyV invokes private APIs

Another interesting characteristic of this Trojan is the code in locka was obfuscated with name mangling and junk code insertion techniques, which made it much harder to reverse engineer.

Figure 10. The malicious code is inserted with a lot of junk code

It’s also worth noting that we found a function named “ClassStaticFunctionHook” that implemented a runtime hook by itself in a piece of repackaged code. Right now the function is only used to hook an advertisement SDK’s code. However, it could be used to implement much more dangerous behaviors in the infected apps. Previously discovered iOS malware uses the CydiaSubstrate framework to hook. This is the first time we have seen a real world iOS malware sample implement standalone hooking functionality.

Infections

On December 12, TinyV began to promote an iOS jailbreak tweak named “XZ Helper (协奏助手)”. Many victims in China found the XY Helper tweak on their iOS devices. Because of TinyV’s code implementation and variety of C2 server commands, even if a victim deleted the promoted tweak, TinyV would immediately install it again. Some victims discussed this abnormal phenomenon in forums including Weiphone and Zhihu. So far we have only observed the malware infecting users in mainland China.

Mitigation

As always, we suggest iOS users do not jailbreak their devices or install any enterprise apps from untrusted sources.

Palo Alto Networks has updated WildFire signatures to block all related C2 domains.

Acknowledgements

We would like to thank CDSQ from WeipTech for sharing infection cases with us.

Appendix

SHA-256 of samples

09fb33e3fe30e99a993dbf834ea6085f46f60366a17964023eb184ee64247be9 deb.zip

b564a919ef7a7f64c5023cbae709a86201e3d78b1604b63296466448167aaba4 locka

bdb452b56b21d3537de252d612b2469c752b2a9f7e0cc0d45624bedf762cfc7b com.xiaoxiaov.ipa

4242b0055bc53125cef00f12320eaaebeb7c55eb54303b21e8a5f9e54cc7735e pq_com.youku.YouKu.5.0.ipa

96f5698271c9b79e78a6f499bd74b4eb78d00f7247db5dcb3b65ba8ecbf4a098 pqcom.qiyi.iphone.ipa

c6ec85a4aedfdd543f1c20fdf1ed15923e257c9664fd8c5ea38826dd47c0322d pq_weixin63820151203.ipa

[Palo Alto Networks Blog]

Palo Alto Networks and Mirantis Collaborate To Make OpenStack Enterprise Class

NFV. VNF. These two terms generate quite the buzz. They have become table stakes in the active trek to the cloud that is well underway in most enterprises and service providers. With the advent of network function virtualization, legacy security technologies that depend on expensive proprietary hardware, legacy network classification and security policy options, and complex and inflexible management are being replaced (or ignored) as the very foundations of the network are being redefined.

As we’ve said many times, virtualization has created a rift in security. There are those who believe that deploying a virtualized version of a legacy security appliance product is ‘good enough’ for now. And then there are those who don’t. We are solidly in that latter camp. We believe that security is both an enabler and an inhibiter of virtualization, in general, and of NFV, in particular. Unless the virtualization technology, networking technology, and security technology are all equally next-generation, we believe that the ensuing system is insecure and, hence, inoperable.

This is why our work with Mirantis is so meaningful. It is clear to us and our customers that OpenStack has found its way into their cloud architectures because of its open approach to innovation and novel ways of driving features, quality and adoption throughout enterprises and service providers. For example, secure OpenStack clouds provide high levels of visibility and control at a user, application, and content level with full carrier-grade network address translation (CGNAT) capability for service providers. It allows enterprises to implement a “Zero Trust” (never trust, always verify) security model that prevents and contains new attacks across the entire attack lifecycle.

Read more about our work with Mirantis.

Our relationship with Mirantis adds to our recognition of the importance of driving next-generation security into next-generation architectures. We already do that with VMware NSX, Amazon Web Services (AWS), Kernel-based Virtual Machine (KVM), Citrix NetScaler SDX, and now with Mirantis OpenStack. Soon, we’ll add Microsoft to this select group of partners.

[Palo Alto Networks Blog]

ISO/IEC 27001 Process Mapping to COBIT 4.1 to Derive a Balanced Scorecard for IT Governance

The balanced scorecard (BSC) initially developed by Kaplan and Norton1, 2, 3, 4 is a performance management system that should allow enterprises to drive their strategies on measurement and follow-up.
In recent years, the BSC has been applied to IT and, currently, the first real-life IT security governance application has been developed based on mapping International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001 control objectives to COBIT 4.1process areas and IT governance focus areas. As a further exercise, the relationships and similarities of COBIT 4.1 and COBIT 5 can be explored to create a mapping for COBIT 5 in future publications.
This article explains how an exercise in instituting controls can be used to establish the IT BSC, which can be linked to the business BSC and, in so doing, can support the IT/business governance and alignment processes as derived from mapping ISO/IEC 27001 and COBIT 4.1 controls.

Balanced Scorecard Introduction

Kaplan and Norton introduced the BSC at the enterprise level. Their basic idea is that the evaluation of an organization should not be restricted to a traditional financial evaluation, but should be supplemented with measures concerning customer satisfaction, internal processes and the ability to innovate. These additional measures should assure future financial results and drive the organization toward its strategic goals while keeping all 4 perspectives in balance. Kaplan and Norton proposed a triple-layered structure for the 4 perspectives: mission (e.g., to become the customers’ most preferred supplier), objectives (e.g., to provide the customers with new products) and measures (e.g., percentage of turnover generated by new products).
The BSC can be applied to the IT function and its processes.5, 6, 7, 8 This article transformed previous visions into actions that can be used to correct any lapses and reduce value in the BSC results. The use of the BSC can also be applied to IT risk management.9

IT Governance Through Controls

This article illustrates how a cascade of scorecards can be instrumental in the development of IT/business governance processes and how this hierarchy of scorecards can support the alignment of business and IT strategy. The IT development BSC and the IT controls/operational BSC are introduced as enablers for the strategic BSC, which, in turn, is the enabler of the business BSC (figure 1).
Governance is established through compliance to standards and control objectives.

Figure 1—IT Balanced Scorecard as a Business Enabler

Source: Christopher Oparaugo. Reprinted with permission.

Controls Through Compliance to Standards

IT governance is part of corporate governance and has to provide the organizational structures to enable the creation of business value through IT, the assurance that there are no IT investments in bad projects and that there are adequate IT control mechanisms established through compliance to the control objectives of COBIT and ISO/IEC 27001.
The methodology of the BSC is a measurement and management system that is suitable for supporting the IT governance process and the IT-business alignment process. Figure 2 shows sample cumulative average scores for the ISO/IEC 27001 control objectives and questions showing inputs for the security policy domain used in the exercise for mapping ISO/IEC 27001 to COBIT 4.1.

Figure 2—Sample Cumulative Average Scores for the ISO/IEC 27001 Control Objectives and Questions Showing Inputs for Security Policy Domain

Source: Christopher Oparaugo. Reprinted with permission.

Figure 3 shows sample cumulative domain scores for the ISO/IEC 27001 control objectives. These results are computed by domain as used in the exercise for mapping ISO/IEC 27001 to COBIT 4.1. The future state results are arbitrary figures that are being aspired to as targets for the exercise.

Figure 3—Resulting ISO/IEC 27001 Compliance Data by Domain

Source: Christopher Oparaugo. Reprinted with permission.

Figure 4 is the bar chart representation of the ISO/IEC 27001 results.

Figure 4—ISO/IEC 27001 Compliance Data by Domain Result in Bar Chart Format

Source: Christopher Oparaugo. Reprinted with permission.

The generic maturity model score was derived from the data of the assessment based on the values that are mapped to the COBIT 4.1 domains (figure 5). These scores are used to create the charts in figures 6 and 7 for maturity benchmark results by domains.

Figure 5—Compliance Output Data to Generic Future Desired State With Generic Maturity Model

Source: Christopher Oparaugo. Reprinted with permission.

Figure 6—ISO/IEC 27001 Compliance Data Results to Generic Future Desired State

Source: Christopher Oparaugo. Reprinted with permission.

Figure 7—COBIT Compliance to Generic Future Desired State

Source: Christopher Oparaugo. Reprinted with permission.

The value inputs of 0% to 100% from the ISO control objectives, sections and control questions are mapped to COBIT 4.1 domains and processes. These are linked to the IT focus areas as shown in figure 8.

Figure 8—Sample Results Showing Mapping of ISO/IEC 27001 Data to COBIT Processes

Source: ISACA, Mapping COBIT 4.1 to ISO /IEC 27001, USA, 2005

These resultant data from the exercise are further employed as COBIT information criteria for primary and secondary grouping. The resultant values of the ISO/IEC 27001 mapping into COBIT processes are linked with the defined IT goals. Exercise results showing the values from the data mapping outputs are shown in figure 9.

Figure 9—Linking COBIT Processes Data Results to IT Goals Showing the Information Criteria for Governance Activities

Source: Christopher Oparaugo. Reprinted with permission.

Based on the data values from the COBIT process linking to IT goals, the IT goals to business goals are derived and the elements of the BSC are developed. Figure 10 shows the results of these links.

Figure 10—Data Linking IT Goals to Business Goals

Source: ISACA, COBIT 4.1: Framework for IT Governance and Control and IT Governance Institute

Information Security Governance Balanced Scorecard

The BSC is a management system (not only a measurement system) that enables organizations to clarify their vision and strategy and translate those into action. It provides feedback around both the internal business processes and external outcomes in order to continuously improve strategic performance and results. When fully deployed, the BSC transforms strategic planning from an academic exercise into the nerve center of an enterprise.
The BSC uses 4 perspectives, develops metrics, collects data and analyzes the data relative to each of these perspectives:

  1. Financial—To succeed financially, how should we appear to our shareholders? 52.38%
  2. Customer—To achieve our vision, how should we appear to our customers? 59.40%
  3. Internal business—To satisfy our shareholders and customers, at what business process must we excel? 61.31%
  4. Learning and growth—To achieve our vision, how will we sustain our ability to change and improve? 55.54%

Conclusion

The vision and strategy driver scores are achieved from the mapping exercise of ISO/IEC 27001 to COBIT 4.1 and these can be used in determinig key permormance indicator (KPI) scores for a department and be drilled down to an individual’s contribution in the overall department success. The results from linking IT goals to business goals and reviewing with the COBIT information criteria helps form a better perspective of the BSC. The assessment results can be drilled and backward review of the mapping values used in determining the root cause of having low values from a set of mapped data in ISO/IEC 27001 control objectives and questions; this will form a basis for developing an action plan as needed by the business.
Successful enterprises understand the risk and exploit the benefits of IT, and find ways to deal with aligning IT strategy with the business strategy, cascading IT strategy and goals down into the enterprise and insisting that an IT control framework be adopted and implemented. IT governance is not an isolated discipline. It is an integral part of overall enterprise governance that drives the business in these days of the Internet of Things. The need to integrate IT governance with overall business governance is similar to the need for IT to be an integral part of the enterprise business.

Christopher Oparaugo, CISM, CGEIT, CRISC

Is the chief technology officer of KATEC Consulting Ltd. He has worked for IBM Global Business Services as an information security consultant. He has also worked in the telecommunication and banking industries in West Africa. Oparaugo has contributed to the ISACA CISM, CGEIT and CRISC Certification Project and Test Enhancement Committee since 2005, setting exam questions and reviewing the manuals.

Endnotes

1 Kaplan, R.; D. Norton; “The Balanced Scorecard—Measures That Drive Performance,” Harvard Business Review. January-February 1992, p. 71-79
2 Kaplan, R.; D. Norton; “Putting the Balanced Scorecard to Work,” Harvard Business Review. September-October 1993, p. 134-142
3 Kaplan, R.;D. Norton; “Using the Balanced Scorecard as a Strategic Management System,” Harvard Business Review. January-February 1996, p. 75-85
4 Kaplan, R.; D. Norton; The Balanced Scorecard: Translating Vision Into Action, Harvard Business School Press, Boston, 1996.
5 Gold, C.; “Total Quality Management in Information Services—IS Measures: A Balancing Act,” research note, Ernst & Young Center for Information Technology and Strategy, USA, 1992
6 Gold, C.; “US Measures—A Balancing Act,” Ernst &Young Center for Business Innovation, USA, 1994.
7 Willcocks, L.; Information Management, The Evaluation of Information Systems Investments, Chapman & Hall, UK, 1995
8 Van Grembergen, W.; D. Timmerman; “Monitoring the IT Process Through the Balanced Scorecard,” Proceedings of the 9th Information Resources Management (IRMA) International Conference, USA, May 1998, p. 105-116
9 Van Grembergen, W.; ”The Balanced Scorecard and IT Governance,” Information Systems Control Journal, vol.2, 2000

[ISACA]

English
Exit mobile version