2016 Prediction #6: The Rise of Mobility in the Industrial Internet of Things

This is the sixth in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

This was originally posted on EnergyCentral.com.

The future, modernized state of Industrial Control Systems goes by many names.  Some are general such as “Industrial Internet of Things (IIoT)” and “Industry 4.0.” Others are more sector-specific names, such as “Smart Factories” (Manufacturing), “Smart Grid” (Electric), and “Digital Oilfield” (Oil & Gas). Modernization not only includes the deployment of enabling technologies but also broader and deeper connectivity.

Both will be great for economics, but with them will come an increase in potential attack vectors. One technology that I feel should be of particular concern to asset owners is mobility.  Not only do I see it gaining adoption in 2016, I believe that attackers will also start to use it as a stepping stone for compromising the automation environment.

Read the full prediction on EnergyCentral.com:
http://energycentral.com/utilitybusiness/informationtechnology/articles/3303

We’ve Got You Covered for Mobility in the IIoT

As a Palo Alto Networks user, you already have the infrastructure to help you securely adopt mobility in your IIoT architecture with our GlobalProtect mobile security technology. It extends your next-generation security posture out into the mobile environment, ensuring consistency of access control and threat prevention.  This is just one of the many integrated components of our security platform, which was designed to work cohesively with the rest. Learn more about GlobalProtect.

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

Adversaries and Their Motivations (Part 3)

In part three of the Adversaries and Their Motivations blog series, we’ll explore the following top-level actor motivations: Cyber Warfare, Cyber Terrorism, and Cyber Mischief.

Even Fuzzier Boundaries

The high-level actor motivations covered earlier in this blog series introduced challenges in identifying and attributing activity between Cyber Espionage, Cyber Crime, and Cyber Hacktivism.

Analysis of the remaining motivations covered in this blog post can be even fuzzier considering the following:

  • Political debate on definitions: Especially when it comes to international activity that directly results in loss of life, physical destruction of facilities, or negative economic hits, arguments persist over how these should be treated by nation state governments, military, and law enforcement agencies. The most serious debate concerns whether computer network related incidents constitute acts of war between countries.
  • Hand-off between motivations: A number of motivations benefit from leveraging Tactics, Techniques, and Procedures (TTPs) and associated tools of another motivation either before or after focal activity. For example, Cyber Espionage can benefit Cyber Warfare operations, and Cyber Hacktivism can extend into Cyber Terrorism.

Cyber Warfare

Cyber Warfare describes operations that alone or complementary to kinetic military activityeliminate or degrade capabilities of a nation-state oriented target.

Associated Actors

Actors operating under this motivation include:

  • Military units: Nation states recognize that computer warfare contributes to successful overt and covert operations against traditional military targets, such as adversary command and control (C2) systems, defense networks, and weapons systems.
  • Intelligence services: These services often operate distinctly or in conjunction with military units to enable Cyber Warfare objectives through covert means.

Their Objectives

Associated actors seek to accomplish the following, on a nation state level:

  • Disrupt operations: Established and critical military and civilian capabilities within a nation can present high value targets to an adversary, especially when combined with concurrent kinetic operations.
  • Degrade / corrupt underlying capabilities: This includes sabotage that reduces the effectiveness or resilience of a capability to enable exploitation of that vulnerability in future kinetic and non-kinetic operations.
  • Destroy key physical targets: Some attacks leverage Computer Network Attack (CNA) to destroy facilities for political and/or military advantage.

Additional Context for this Motivation

While this blog post attempts to simplify the definition of Cyber Warfare, political and military debate persists over how to define and respond to this class within the international community. Most operations that fall under this motivation are well funded, assessed as highly sophisticated, and backed by government, military, and intelligence resources. Associated activity is often paired with or conducted concurrent to Cyber Espionage operations to maximize effectiveness in progressive targeting, identification of associated weaknesses, and development of attack strategies. Otherwise, none of the other top-level malicious actor motivations typically mixes with Cyber Warfare operations.

Examples

Some examples of Cyber Warfare activity follow:

Cyber Terrorism

Cyber Terrorism is the convergence of cyberspace and terrorism, distinguished by the threatened or realized loss of life, severe economic damage, and/or disruption of core infrastructure.

Associated Actors

Actors operating under the Cyber Terrorism motivation include:

  • Officially recognized terrorist groups: Official terrorist organizations usually maintain public facing venues for communications and marketing.
  • Government, military, or intelligence services: The end goal of these services is similar to that of officially recognized terrorist groups; however, it usually focuses internally to the originating country. As an example, in countries known for their human rights violations, respective agencies often use all available mediums to discourage dissent and identify (and “neutralize”) perceived opposition.
  • Destructive black hat groups and individuals: The moment a malicious actor employs a virtually or physically destructive CNA method to affect an end goal or send a message their associated motivation is at least partially Cyber Terrorism.

Their Objectives

Actors operating under this motivation focus on:

  • Disruption of opposing assets or services: This tactic is mostly used to gain visibility and potential media coverage for an organization based on the inconvenience or material damages accomplished through attacking various government, military, or corporate infrastructure targets. It is most often associated with extremist forms of hacktivism.
  • Intimidation of a populace: This can take several forms, depending on the target country, culture, industry organization, and/or circumstances. Some associated attacks go so far as to leverage Computer Network Exploitation (CNE) to expose dissidents and their families to severe consequences within certain countries, extending as far as enabling assassination of key opposing personnel for political and/or military advantage.

Additional Context for this Motivation

These are the extreme cyber bullies of the world, relying on fear and destruction as their preferred tools. Similar to Cyber Warfare, public agreement on a definition for this motivation remains elusive. Kevin G. Coleman of the Technolytics Institute took a commendable stab at a definition:

“The premeditated use of disruptive activities, or the threat thereof, against computers and/or networks, with the intention to cause harm or further social, ideological, religious, political or similar objectives. Or to intimidate any person in furtherance of such objectives.”

Yet, even this definition generates significant overlap across subsets of malicious activity found within other motivations. Focusing on the context and severity of associated activity will often disambiguate underlying motivation; however, certain outliers will always fall in a mixed category and/or rely on less than moderate levels of confidence.

Enlisted participants in affecting campaign objectives can range in technical ability and sophistication. From contractors to hacktivists, certain third parties may be recruited to affect principle actor objectives in attack campaigns associated with this motivation.

While most actors under this motivation currently focus on disruption through techniques such as Distributed Denial of Service (DDoS), we’ve seen some lean towards destructive activity. This includes the use of tools such as wiper malware to perform the digital equivalent of sacking a city – but in this case, sacking an enterprise. In the future, similar tools and techniques as those successfully employed by Cyber Espionage and Cyber Warfare actors may lead to more devastating attacks against Cyber Terrorism targets.

Examples

Some examples of Cyber Terrorism activity follow:

Cyber Mischief

Cyber Mischief encompasses a majority of the remaining cyber threat noise on the Internet.

Associated Actors

In general, Cyber Mischief is associated with any malicious actor that doesn’t fit into the other high-level motivations. Examples include:

  • Fledgling hackers: Individuals or groups that are new to the malicious hacking discipline and typically use publicly available attack tools without a deeper comprehension of underlying concepts and techniques. These parties are sometimes referred to as “script kiddies,” and in some cases they may cause damage but they generally do not harbor malicious intent.
  • Internet nuisances: Individuals or groups that are experimenting with their TTPs and tools in arbitrary or capricious ways that do not directly lead to objectives of other motivations. Instead, these parties are often cultivating their skills and proficiencies to eventually apply them towards another top-level malicious actor motivation when they feel suitably prepared and confident.

Their Objectives

The objectives of actors that fall under the Cyber Mischief motivation can include:

  • Small-scale personal benefit: Some actors execute related activity for minor tangible and/or intangible gains.
  • Seeking to learn and/or teach: Knowledge and excellence in execution require extensive practice. Once comfortable enough, this practice often moves to the wild (i.e., Internet), to test an actor’s skill against live targets.
  • Refining tradecraft: In the course of navigating through and beyond the fledgling hacker stage, some actors focus on strengthening their associated skills and proficiencies to elude detection and attribution.
  • Exploring identity: The modern Internet offers a medium for bonding and integration of new experiences that can lure susceptible personality types and age ranges into this category of behavior.
  • Just to be a nuisance: As in the physical world, some folks just like to stir up trouble.

Additional Context for this Motivation

A tricky aspect of Cyber Mischief is that it builds up the Internet noise that defenders must wade through to find threats posed by other high-level malicious actor motivations. As actor experience and competence increases, respective activity may begin to look more like the progressive high-level motivation that the party is evolving towards. Additionally, savvy actors under other motivations may tailor certain activity to blend in with this noise or employ these techniques to distract defenders.

Examples

Some examples of Cyber Mischief activity follow:

Closing Thoughts

As with any attempt to standardize or generalize, exceptions and outliers are a very real possibility. It’s often better to be approximately right than precisely wrong when it comes to tailoring a framework for any environment. Regardless of how you might break out and define categories of malicious actors attacking a network, one thing should remain consistent: assessment methodology. This ensures a basis for comparative analysis and subsequent prioritization of threats.

Finally, it can often be just as important to eliminate a given motivation or attribution from consideration as it is to isolate those with the highest confidence. After all, it’s about making the best-informed decisions possible about these threats given incomplete situational awareness and limited resources, such as people, technology, and – often the most critical – time.

Happy hunting and tracking!

[Palo Alto Networks Blog]

2016 Predictions #5: Industrial IoT and NFV/SDN Growth and Public Cloud to Yield Emerging Security Opportunities for Service Providers

This is the fifth in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

Service providers are in the thick of major changes, all of which have significant security implications. As we close out 2015, let’s take a look at major trends that will gain prominence for service providers in 2016.

Rapid Growth in the Industrial Internet of Things (IIoT)

Gartner predicts the Internet of Things (IoT) market will grow from about 4.8 billion connected devices in 2015 to 25 billion in 2020. While growth in the consumer space (e.g., personal gadgets, sensors in the home) is rapid, IoT in the industrial realm may, in fact, be the bigger story. Electric utilities, manufacturers, automotive, and governments will make major IoT investments to bring their respective industries into the IoT age. The potential for returns in operational efficiencies are compelling, but these returns come with risk.

For example, utilities and manufacturing facilities have, for the most part, been isolated from public networks to date. Cybersecurity was mostly a matter of maintaining that isolation – ensuring SCADA systems were kept apart from the general purpose network used by the rest of the enterprise. The IIoT is changing that paradigm and service providers have a critical role to play in securing that infrastructure. Some of the new requirements to emerge from this:

  • Service providers will need to elevate network security past the network layer and into the application layer to identify and isolate compromised endpoints.
  • IIoT systems are often highly time sensitive (ultra-low latency requirements). Service providers will need to ensure quality of service and protect against attacks that would degrade performance.
  • Increased segmentation. With industrial systems in effect “on the Internet,” Service providers will need to replace the physical isolation these systems used to enjoy with logical isolation based on ensuring only authorized traffic gets into these networks. They will need to ensure only authorized applications, users, and content have access to these critical systems.

More Virtualized Network Services – NFV/SDN Taking Off

In 2015 we saw the commercial release of virtualized services by major service providers. In fact, Infonetics forecasts a fivefold increase in the NFV/SDN market by 2019. With many more projects in the pipeline and more of the service provider infrastructure being virtualized, 2016 will see the release of more SDN/NFV-based services. Key security elements of this trend:

  • Look for greater availability of virtualized “security-as-a-service” offerings. Public cloud offerings (e.g., AWS) are already available. Look for more private offerings from service providers, such as virtual CPE and virtualized hosted security. Competition among service providers will heat up, and customers will gain the benefits of more choices in plans and pricing, along with faster provisioning and improved service. The winners: providers who build services on tightly integrated security platforms with strong hooks into orchestration, OSS, and BSS.
  • Security will be become part of the DNA of NFV-enabled network services. As service providers leverage SDN/NFV to move up the customer value chain, security will be embedded as a VNF (virtualized network function). And, as core infrastructure is virtualized, service providers will gain new capabilities to embed security into the network.
  • In order to transform networks from hardware- to software-centric, service providers face a skills gap that threatens to emerge on the critical path of major projects. Vendor partnerships will be key in mitigating this gap. Service providers will look to NFV suppliers with well-integrated solutions and a successful track record with early adopters.

Emerging Security Opportunities for Service Providers

Security concerns have been longstanding barriers to adopting cloud technologies by larger enterprises. While large enterprises have embraced private cloud, public and hybrid cloud adoption are running into headwinds due to security concerns. A survey conducted by the Cloud Security Alliance found security to be the top concern holding back cloud projects.

Service providers have an opportunity to move up the value chain with their enterprise customers by deploying comprehensive security solutions for the cloud-enabled enterprise. These security offerings will include:

  • Secure network connectivity to the public cloud.
  • Secure employee access to cloud services.
  • Breach protection for cloud assets.
  • Policy management and enforcement for cloud-hosted services and data.

Customers will demand integrated offerings that deliver comprehensive security and can be tailored to their needs. They will require a security architecture that treats the assets they hold in the cloud with at least the same security as those assets receive in house. They will need security assurance that public cloud services do not open new attack vectors into the private network. The key to operational and financial success with these service initiatives will be integrated security platforms that address the full range of security requirements enterprises are demanding.

 

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

Global IT Audit Study Says Emerging Tech is Top Challenge

The ever-changing nature of complex emerging technology and infrastructure changes, including transformation, innovation and disruption, is the top challenge faced by IT audit executives and professionals around the world, according to a new survey from global consulting firm Protiviti and ISACA.

The fifth annual IT Audit Benchmarking Survey, titled A Global Look at IT Audit Best Practices, examines where IT audit functions stand in their ability to address complex challenges. More than 1,200 respondents shared their perceptions of top technology challenges currently facing their organizations

Top 10 Challenges
According to the survey, the top 10 global technology challenges facing IT audit professionals are:

  1. Emerging technology and infrastructure changes: transformation, innovation, disruption
  2. IT security and privacy/cybersecurity
  3. Resource/staffing/skills challenges
  4. Infrastructure management
  5. Cloud computing/virtualization
  6. Bridging IT and the business
  7. Big data and analytics
  8. Project management and change management
  9. Regulatory compliance
  10. Budgets and controlling costs

Interestingly, regulatory compliance and budgets/controlling costs have moved down significantly on the list compared to last year, indicating that IT departments are getting better at managing compliance costs.

Notable Takeaways
This year’s study indicated that audit professionals have significant concerns about finding qualified resources and skills. Not only was this noted by respondents as a top-three IT challenge, but numerous results suggest that finding the right people with the right knowledge/skills for the right job remains a significant challenge.

The study also serves as a reminder that IT audit risk assessments are an absolute must.There are small but meaningful numbers of companies that are not conducting any type of IT audit risk assessment. For these organizations, this is a significant risk given the cybersecurity threat environment. Other organizations are adhering to best practices by conducting these risk assessments more frequently.

IT Audit Reporting Structures Still Off the Mark
According to the survey, 60 percent of the largest public companies have a designated IT audit director or equivalent position within their organizations, and yet, in half of all companies, these individuals do not attend audit committee meetings. Furthermore, many companies still have established reporting structures that are less than optimal. Having the IT audit director report to the CAE or equivalent is a best practice, yet 28 percent of companies in North America and Asia use another, less ideal reporting line. This number is as high as 33 percent in Latin America and 41 percent in Europe.

Organizations need to address effective IT audit management through a number of controls, including treating IT and cybersecurity risks as strategic-level risks, operating as a truly independent and impartial function, and allotting the necessary resources and expertise, whether internal or external, to help the organization identify and manage its IT risks effectively.

COBIT Is the Go-to Framework
Respondents cited COBIT as the most accepted industry framework on which the IT audit risk assessment is based, followed by COSO, ISO and ITIL. Organizations may use a combination of frameworks to complete risk assessments.

Looking Ahead
ISACA is committed to helping you face the challenges identified in this survey. From recent reports on emerging technology, to more cybersecurity guidance, to audit and assurance career tools coming in 2016, we aim to help you face these issues head-on and succeed.

Christos Dimitriadis, Ph.D., CISA, CISM, CRISC
ISACA International President

[ISACA Now Blog]

Exploitation Demystified, Part 2: Overwrite and Redirect

In Part 1 of this series, we laid the foundation of memory corruption exploitation and presented the basic exploitation framework:

This post will cover the implementation of Overwrite and Redirect in the context of stack based buffer overflow vulnerabilities.

Memory Address Space Revisited

In its simplest form, the memory space is divided by the executable code region and the data region. The executable region contains both the program’s unique code as well as the DLLs the operating system provides to all processes. Data region, as its name implies, contains the data on which the code operates. The data region is comprised of the stack and the heap, which we will describe in detail below.

The attacker is interested in the data region since the shellcode by definition will be embedded in what will be loaded to the data region. This means once the file with the shellcode runs, the shellcode resides either in the stack or in the heap.

The Attacker’s Challenge

From the attacker’s perspective, inserting the shellcode to the data region is still far from satisfactory because the shellcode is an executable code. Remember – the shellcode’s role is to be executed and to open a connection between the attacker and the targeted machine. This is the fundamental exploitation challenge:

  1. The shellcode is by default loaded to data region.
  2. The shellcode needs to be executed.
  3. Residing in the data region means that the memory addresses populated by the shellcode will never be fetched to the CPU for execution.

The Attacker’s Solution

The attacker’s main objective is to manipulate the CPU into executing content of memory addresses which under normal circumstances do not get executed. This is wherevulnerabilities come into play.

To recap: when we say that an application has a vulnerability we mean that a crafted input file will cause the execution flow to deviate from its predesignated course. In other words, the CPU is fetched an address it was not meant to receive.

Let’s tie it all together now. The attacker has managed to insert a shellcode to the data region of the process memory, and what it seeks now is a way to get that shellcode executed. To achieve that, the attacker will craft the file in such a way that the deviated address will contain instructions to jump to the shellcode address. Now, the CPU receives an address containing executable code and it will follow the instructions, jump to the shellcode address and execute it.

(Very) Brief Vulnerabilities Overview

Vulnerabilities are tightly related to the overwrite part in the exploitation flow. Different vulnerabilities enable the attacker to overwrite addresses in different parts of the process address space.

The first type of vulnerability we will cover is stack based buffer overflow. This class of vulnerability can be considered a classic exploitation pattern. It is also one of the oldest patterns to be exploited in the wild and is still a prominent part of the current threat landscape.

The Stack

A typical computer program is comprised of a main program and functions or subroutines. When a subroutine is called, it performs its task and returns control to the main program. From the memory address space perspective, the addresses of the main program reside in the code region. When a subroutine is called, a stack is invoked to store its local variables (which roughly correlates to what we refer to as the data). The subroutine then performs its designated task and when it is done, hands over control back to the main program.

From the attacker’s perspective there are three interesting features:

  • Fixed size: The size of the stack is fixed and determined at the time of the call. For example, let’s assume that the subroutine declared an array of 10 characters. This will be the size of the stack regardless of the arguments we will pass to it.
  • Return address: The return control mechanism works like this: the stack is invoked with a fixed memory size. Let’s say our 10 characters stack is assigned to address 100. This means that addresses 91 to 100 are assigned to this stack. In addition, address 90 contains the address in the main program to which the CPU should return after the subroutine has fulfilled its task. This memory location is known as the return address.
  • The stack grows downward: when we provide the actual arguments to the stack, the first goes to the highest address and is then pushed downwards by its followers. So if we provide a 3 character input to our simplified stack, the first one will go to address 100. After that the second one will populate 100 pushing the first to 99. Then the third will go to 100 pushing the second to 99 and the first to 98. Since our input ends here and there are no more arguments, the return address will be fetched to the CPU, which will follow its instructions and jump back to the main program.

Stack Based Buffer Overflow

So far we have described the stack architecture with no malicious context. Now we will explain how this architecture can be maliciously leveraged.

The inherent security flaw in the stack architecture is that it implicitly assumes that the input will match the predesignated size. It works well when the input is either smaller than or identical to this size. The problem arises when the input is larger than the predesignated stack boundaries.

Let’s go back to our simplified stack. Suppose we give the subroutine an input larger than 10 characters. Remember that addresses 91 to 100 are assigned for the input and that address 90 is already populated with the return address. If our input is 11 characters, the first character will go to address 100 and will be pushed downwards. When it reaches 90 it will overwrite the return address. The CPU will try to follow the instructions in address 90 but because they do not exist anymore, it will break the execution flow and the process will crash. This is known as Stack Overflow.

Let’s also remember that the shellcode resides in the stack and the attacker attempts to cause it to be executed.

In order to leverage stack overflow for its purposes, the attacker will craft the subroutine input in a way that the return address will be overwritten with new instructions which will redirect the CPU to the shellcode location.

In our simplified stack example, the attacker will craft an 11 character size input. The shellcode resides in characters 11 and 10. Character 1 contains instructions to jump to 11 and execute. In that case when the subroutine is called, character 1 will be pushed down, overwrite the return address and redirect the CPU to address 100 where the shellcode is. The CPU will blindly follow the instructions and execute the shellcode.

Zoom Out on Exploitation Architecture

As you can see in our example above, the exploitation parts are not connected to each other: embedding a shellcode is totally decoupled from crafting the input file to trigger a certain vulnerability. The triggered vulnerability enables the return address to be overwritten. The instructions, which overwrite the return address, redirect the CPU to the shellcode but other than do not relate to the shellcode’s functionalities in any way.

The art of exploits is to orchestrate these independent parts to work together. In a similar way, the art of protection against exploits is to obstruct either the independent parts directly or the orchestration among them.

Conclusion

We have learned how the basic exploitation framework is implemented on stack based buffer overflows vulnerabilities. Despite its age (the earliest documented attack was the Morris Wormin 1988), this class is still a prominent part of the threat landscape. We encounter exploitations of these vulnerabilities in various readers, players and Microsoft office documents but also in industrial protocols and services.

In the next Exploitation Demystified post, we’ll cover implementation of the exploitation framework on heap-based vulnerabilities.

[Palo Alto Networks Blog]

English
Exit mobile version