Some Clarifications and Commentary on Network Security and Covert Channels

This week, a security researcher posted a blog about the security implications of how next-generation firewalls handle TCP session setups. SC Magazine also published an article that included similar technical claims provided by the security researcher. We’d like to take the opportunity to clarify the content of these articles for our customers and the industry, because both of these writings included some inaccurate claims that may sound concerning.

One claim from the researcher is that next-generation firewalls “…are designed to permit full TCP handshake regardless of the packet destination … bypassing the firewall to any destination on the Internet, regardless of firewall rules and client restrictions” (emphasis in the original).

This claim, as written in the blog and SC Magazine article, is false. Firewall policy is never violated. Before even a SYN is allowed through, the firewall rule base is evaluated to check if a TCP setup should be allowed at all.

After some conversation with the researcher, it appears the actual concern is that if an administrator creates a typical web browsing policy on a next-generation firewall, this allows a SYN (and in fact a complete 3-way handshake) from allowed web clients out to the internet on the standard HTTP service (tcp/80). This is true of any firewall, and anything that does otherwise is a proxy—and only if that proxy happens to already know the host is malicious.

To put this in context, it is helpful to remember that this technique is not new. Information hiding in TCP/IP is nearly as old as the stack itself (see references). This is essentially a covert channel, and as with any covert channel, it requires the adversary to already have control over both ends of the connection. This is simply one example, and in general, covert channels are limited only by the creativity and patience of the adversary. For example, data can simply be carried over normal HTTP payloads to a recently compromised WordPress site (this actually happens every day). Far simpler and more efficient, without bothering with TCP trickery—and nothing about the act of proxying does anything to stop this.

That is why it is important to focus on prevention, a key tenet of the Palo Alto Networks next-generation security platform. The layers of security provided by App-ID, Content-ID, WildFire, Traps, and the complete combination of Palo Alto Networks platform security capabilities are important in denying the adversary access to the network and endpoints at every stage in the attack lifecycle. The game of endless incident response, covert signaling, steganography, and inventorying data lost after a breach is unwinnable.

Palo Alto Networks customers are encouraged to reach out to customer support for any additional questions about this topic or any product security matter.

— Palo Alto Networks product security team

*****

The original researcher blog post is available at: http://www.bugsec.com/news/firestorm/

The SC Magazine article is available at: http://www.scmagazine.com/firestorm-vulnerability-in-firewalls-let-attackers-extract-data-from-cc-servers/article/458817/

T. Handel and M.Sandford., “Hiding data in the OSI network model,” (Cambridge, U.K.), First International Workshop on Information Hiding, May-June 1996. Retrieved from: http://chemistry47.com/PDFs/OSI%20Model/Hiding%20Data%20in%20the%20OSI%20Network%20Model.pdf

[Palo Alto Networks Blog]

Palo Alto Networks Researchers Discover Critical Vulnerabilities in Internet Explorer and Microsoft Edge

Palo Alto Networks researchers Bo Qu and Hui Gao were credited with the discovery of three new critical Microsoft vulnerabilities affecting Internet Explorer (IE) versions 7, 8, 9, 10 and 11 and Microsoft Edge. These vulnerabilities are covered in Microsoft’s December 2015 Security Bulletin and documented in Microsoft Security Bulletins MS15-125 and MS15-124. 

In our continuing commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors.

Palo Alto Networks is a regular contributor to vulnerability research and have discovered 80 critical Microsoft vulnerabilities over the past 18 months. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing weapons used by attackers to compromise enterprise, government and service provider networks.

[Palo Alto Networks Blog]

Living With the Paradox of PCI DSS

With the next generation of customers embracing the use of new technologies, the use of “dirty money” is becoming less popular. In its place, people are increasingly choosing to use payment cards.

Problem:
This makes for some difficult decisions and consequences for merchants. If they choose not to embrace taking payments by payment card, they likely miss out on customer revenues. If they opt to take payments via payment cards, they have a duty to their acquiring banks, and even more importantly to their customers, to ensure that these payments are as secure as they can be.

However, the experience of trying to ensure that level of security is frequently perceived as extremely complex, difficult to achieve, time consuming, extremely expensive and near on impossible to maintain. Given that the supporting environments are extremely dynamic, it is a “war of attrition” trying to defend against ever-changing attacker tactics and involving multitudes of varying factors (technology, people and processes).

Cause:
The increasing preference for paying for goods and services via a piece of plastic or technology makes for a greater attraction to the criminal underworld, whether from organised crime or the opportunist hacker. If a business has not identified a vulnerability in its payment card business operations, it is very likely that a hostile entity soon will.

Securing the payment card data life cycle becomes increasingly difficult when you consider the potential attack and vulnerability vectors:

Front-end operations:

  • eCommerce web pages
  • Mail order, telephone orders (MOTO)
  • Point of sale (POS) systems
    • PIN transaction security (PTS) devices
    • Contactless
    • Mobile
  • Automated teller machines (ATMs)
  • Receipts
  • Found payment cards

Back-end operations:

  • Networks
  • Systems
  • Storage
    • Databases
    • Files
    • Paper
      • Receipts
      • Chargebacks
    • CCTV
    • Call recordings
    • Backups
  • Transmissions
  • Vulnerability management
  • Change control
  • Software development
  • Access control
  • Data centers
  • Monitoring systems use
  • Security testing

Kinetic (external) attack vectors:

  • Organized crime
  • Opportunist hackers
  • Foreign intelligence services
  • Cyber terrorism
  • Industrial espionage

Non-kinetic (internal) attack vectors:

  • Insider Threats
    • Deliberate actions by authorized persons
    • Negligent actions by authorized persons
    • Accidental actions by authorized persons

When you start adding all these together, plus all the connecting infrastructures of a business’s payment card operations, it becomes instantly apparent just how difficult securing these operations can be. The figure below shows a simplistic overview of how a typical business’s payment card operations might look. However, in reality this is often far more complex.

Actions
To help businesses improve their payment card operations, the card brands and the PCI Security Standards Council have produced a suite of controls that provides a baseline upon which a foundation of secure operations may be forged.

In truth, without prior specialist knowledge and skills, this can be extremely difficult to successfully achieve. This can be likened to expecting anyone to be able to build a house, having given them all the tools and materials they need (sand, cement, water, bricks, tools, etc.). However, in truth, this is rarely the case and, in reality, such a scenario would often lead to the application of expensive underpinning or to even demolish the building and start again.

Consequently, before commencing any sort of improvements to any existing payment card operations, it is essential that businesses familiarize themselves with the latest version of the Payment Card Industry Data Security Standard (PCI DSS) and engage with a reputable and experienced PCI DSS professional (PCI Qualified Security Assessor [QSA]).

Additionally, ISACA has just produced an extremely informative PCI DSS guide A Practical Guide to the Payment Card Industry Data Security Standard (PCI DSS), covering a comprehensive overview of PCI DSS and some of its associated complexities. It provides valuable support for anyone involved in delivering secure card payment operations and meeting the high standards required for PCI DSS compliance.

Net Benefits
It goes without saying that PCI DSS compliance is essential for the protection of a business’s payment card operations and to help safeguard customers’ payment card details. The popularity of paying products and services via a payment card is only going to increase. Consequently, having a well-planned and implemented compliance framework is critical to the success or failure of any such projects.

Having access to ISACA’s useful reference guide and the continued support from a trusted and knowledgeable QSA will help ensure, amongst others, the following benefits:

  • Improved security
  • Improved understanding
  • Informed decision making
  • Better alignment with business strategy
  • Efficiency
  • Timely progress
  • Cost-savings
  • Clarity
  • Success
  • Fines avoidance

James Seaman, CISM, CRISC
Senior Security Consultant, Nettitude Inc.

[ISACA Now Blog]

Frost & Sullivan Recognises Palo Alto Networks as Network Security Vendor of the Year in Australia

Last week, Palo Alto Networks received the 2015 Australia Network Security Vendor of the Year award from Frost & Sullivan. Armando Dacal, vice president for Palo Alto Networks Australia/New Zealand, attended the awards banquet in Sydney to accept the award.

The awards recognise ‘exemplary practices and best-in-class companies’ in Australia, across four markets, including ICT, Healthcare, Energy and Environment, Chemicals and Materials. This year was particularly special as it marked the 10th year that Frost & Sullivan hosted the excellence awards in Australia to recognise and celebrate exemplary practices and best-in-class companies in the country.

What a great way to close 2015. Congratulations Australia team!

Armando Dacal, vice president for Palo Alto Networks Australia/New Zealand

[Palo Alto Networks Blog]

Mobile Security: Variations on a Theme

Niccolò Paganini’s Caprice No. 24 in A Minor is a famous and notoriously difficult composition that only the most advanced violinists can play. It’s made up of a theme, along with Paganini’s own variations. But as respectable as it is on its own, it’s been discovered and rediscovered by a large number of composers and artists over the years for new audiences, many of whom may not have realized they were listening to Paganini in the first place.

Each variation on a theme can provide new insights, because they challenge the audience to hear things that they may not have otherwise noticed. But without knowledge of the original theme, there’s also a chance of missing out on the big picture. In some ways, the discussion around mobile security takes on its own variations of a theme, because many people share common concepts on risk but their priorities on what must be done vary greatly.

I’ve had discussions with people who see mobile security as a data at rest issue, namely how to protect and remove data once it reaches the mobile device. That argument may address some of the issues with lost and stolen devices, but it does not address what happens if there is a malicious adversary trying to control the device.

Then there are networking teams who see mobile security as a network blocking issue, namely that they’ll do whatever they can to keep BYOD and unsanctioned devices off their corporate network. That may be a way to keep infected mobile devices out of sight, out of mind, but it doesn’t really make the sanctioned devices any safer to use.

There are also networking teams who see mobile security as being a remote access issue, but as applications move to the cloud, the use case for remote access becomes fuzzy, and the use of standalone VPN appliances even fuzzier.

It’s important to ask whether you’re addressing the problem itself, or a variation of the problem. For example, while each of the problems above are valid in their own right, the bigger issue is that organizations often lack ways to enforce security policies that could prevent improper application traffic and threats from reaching the device in the first place.

These thoughts come to mind as I read through NIST Special Publication 1800-4, which outlines the problem in mobile security. Section 4.4.1 discusses threats (including mobile malware) and Section 4.4.2 discusses exploitable vulnerabilities, both of which are at the heart of modern cyberattacks.

At Palo Alto Networks, we believe that prevention is a necessary and critical measure to prevent exploits and malware from reaching the device in the first place. The next-generation security platform provides an integrated approach toward the use of global threat intelligence to stop threats in application traffic. With GlobalProtect, all corporate application traffic is inspected by the next-generation security platform, regardless of where the user is located. This enables the organization to take a prevention-first approach by applying security policy to stop both known and unknown mobile threats.

As mobile security becomes better understood, it is important to develop strategies and frameworks that will help foster broader understanding of the issues at play – not just one or two variations. Stopping threats won’t come from solving the variations of the theme, but rather by addressing the core of the problem itself. Plan for prevention first in order to strengthen your mobile security strategy.

[Palo Alto Networks Blog]

English
Exit mobile version