Palo Alto Networks was a Gold sponsor of the official side program of the “Cyber3 Conference Okinawa 2015—Crafting Security in a Less Secure World”, an international cybersecurity conference hosted by the Government of Japan in Okinawa from 7-8 November 2015.
The event was moderated by William H. Saito, Special Advisor to Japan’s Cabinet office who is also Vice Chairman and CSO of Palo Alto Networks Japan. The conference featured three separate themes which were closely interconnected and interdependent: Cyber Connection,Cyber Security, and Cybercrime.
Held concurrently with the conference, the official side program, which included two Education track sessions, offered the opportunity for conference participants and global leading companies in the cyberspace to discuss comprehensive security measures.
In addition, Palo Alto Networks held a press conference to announce its 2015 Application Threat Usage Report (AUTR) as well as several media interactions. Last but not least, Palo Alto Networks also hosted dinner and networking events throughout the conference.
The event was a great success. Take a look at some of the photos from the event below!
Application Usage and Threat Report (AUTR) press conference
Cyber3 Conference Okinawa 2015
Vice Chairman of Nissan, Toshiyuki Shiga (center), together with Hiroshi Alley, Chairman and President of Palo Alto Networks Japan K.K. (far right)
Navigating the Digital Age books were widely distributed at the Conference. Download your copy.
Did you attend Cyber3 Conference Okinawa 2015? Share your thoughts from the event in the comments below.
Former US President John F. Kennedy once said, “There are risks and costs to action, but they are far less than the long-range risks and costs of comfortable inaction.” He was speaking about ways to decrease antagonism among nuclear powers, but I think there’s a lesson in what he said for those of us in the business world as well. Specifically, sometimes things arise that seem risky in the short term; we’re nervous about doing them because of potential short-term risks or disruption to the organization. But when these potential downsides are weighed against the status quo (i.e., the “comfortable inaction” Kennedy was talking about), taking the short-term risk might very well be the more optimal path when viewed over a longer horizon.
This can be seen very acutely when it comes to adoption of new technologies. New technologies have the potential to be transformative to the organization—in both positive and negative ways. Positive benefits vary depending on the technology, but possible negative impacts could be disruption to business operations, potential erosion of the value of existing technology investments (for example, adopting a new technology would decrease the value of what we have in place now), and potential new technical risks as “kinks” are ironed out of the technology and organizations figure out how to safeguard usage of it.
Despite all this, pulling the trigger and adopting a new technology is often still the optimal path. Consider two hypothetical organizations competing in the same niche market. One organization implements a change that enables it to produce goods faster at lower cost; the other decides that it cannot or will not implement that same change because the short-term risks are too high. What are the logical consequences should the first organization adopt successfully?
Clearly, the organization that realized potential benefits becomes more competitive: it can satisfy more of the market, has the option to reduce price given the lower overhead, and can potentially focus attention and resources on other areas. In short, it has an edge. Even if the change carries with it some degree of potential risk initially, the potential upside trivializes the short-term downside risks by comparison.
The point I’m making here is that looking solely at the technical risks associated with a particular change misses a huge part of the equation. In evaluating the holistic risk to our organizations and making recommendations, we absolutely need to consider risks that may be introduced through adoption of new technologies, but we need to consider the risks of inaction as well. Nowhere is this more true than when it comes to Big Data analytics.
Big Data analytics is the use of advanced analytics techniques to operate on large sets of business data. This could be data derived from existing business processes and tools, data that exist independently of the organization such as social media, or new sources of data entirely. For many in the ISACA community, we know this can present risks. We know, for example, that there are privacy and security risks that can occur as a result of the adoption of big data analytics; in fact, ISACA has published quite a bit of guidance on exactly these issues. However, to evaluate risk holistically, we need to weigh these risks against the risks to the business should we choose not to adopt and adapt. Do the business gains outweigh the technical and other risks? Do the risks to competitiveness eclipse in the long term the short-term additional risk we take on? Good questions.
To help organizations answer them, ISACA evaluated Big Data Analytics—along with a number of other business trends—using anew methodology that attempts to objectively score risk and value impacts of business trends. The goal: find a reproducible and systematic way to find out what “megatrends” have the highest value potential in light of possible technical and other risks. Much like measurements such as “signal-to-noise ratio” or “earnings-per-share” provide an objective unit of measurement that organizations can use to inform data-driven decision-making, the goal here was to find a way that organizations can systematically assess and analyze these tough questions.
Of all the trends we investigated, Big Data analytics scored the highest in terms of business value created relative to potential negative risk impact.
Now, obviously every organization is different, so your particular organization may have unique factors that impact either the risk or the value side of that equation. You’ll certainly want to examine that data point through the lens of your particular organization’s needs, circumstances and business context. That said, given that it could be so impactful, it’s almost certainly a good idea to—at a minimum—ensure that strategic discussions are taking place about the role that Big Data analytics has in your organization.
There are some key questions you should be asking about how you might use this to forward your business goals and how your competitors might be using it to gain a competitive edge. We’ve tried to distill down the most critical questions that you might want to ask in our report covering the findings from our analysis, with the hope being to provide one potential framework around which those conversations can be built and those questions can be asked.
Ed Moyle Director, Emerging Business and Technology, ISACA
On November 3, 2015, ZScaler reported that a Chinese government website hosting the Chuxiong Archives, http://www.cxda[.]gov.cn, had been compromised and contained injected code leading to the Angler Exploit Kit. The report stated that the affected website had appeared to be remediated and cleaned within 24 hours; however, upon scanning the website using our own malicious web content detection system, we discovered that in fact, the website remained compromised. At this time, we advise users to not visit the website in the near future, even though it appears to be clear of malicious code.
Based on our analysis, the malicious code injection on http://www.cxda[.]gov.cn has not been removed, but simply placed in a dormant state. After ZScaler published information regarding this compromise, we continuously scanned and monitored the compromised website, as well as other popular websites and potentially related suspicious targets. What we discovered was that many other websites had been compromised in a similar way, where the malicious code had the ability to be placed by the attacker in a dormant or an active state.
For this article, we chose a few of the additionally discovered compromised sites found by our malicious web content detection system and continued to scan them in high frequency. The following diagram shows the vulnerability status of three of these sites over the duration of a day. The markings on the top portion indicate that the site’s malicious code was active during that time slot while the markings on the bottom portion indicate the site was benign, or dormant, during that time slot.
Figure 1
In what appears to be a technique to evade detection or analysis, the injected malicious code has the ability to hides itself when the user-agent or IP address of the request does not meet specific criteria. Attempts to launch requests from different combinations of IP addresses and user agent strings consistently produced different behaviors (benign vs malicious) depending on what was sent.
During our continuous monitoring for a 24-hour period from November 11, 2015 to November 12, 2015, eight days after the Zscaler report, the Chuxiong Archives website consistently presented malicious content injected by an attacker depending on the source IP and user agent. It is believed that if a user were to visit the compromised website a second time following the initial exposure to the malicious code, the site would recognize the source IP and user-agent and simply remain dormant, not exhibiting any malicious behavior. Because of this anti-analysis/evasion technique, it may easily cause the belief that the threat has been remediated, when in reality, it had not.
At the time of this report, using our malicious web content scanning system, we have already discovered more than four thousands additional, similarly compromised websites globally exhibiting the same ability of being able to be dormant or active depending on source IP and user agent. Investigations regarding this campaign on a larger scale are ongoing and a second report detailing the similarly compromised websites will be published in the near future.
Palo Alto Networks was again named to Deloitte’s Technology Fast 500™, a ranking of the 500 fastest growing technology, media communications, life sciences and clean technology companies in North America.
This is the fourth consecutive year Palo Alto Networks has been called out as a Technology Fast 500 award winner.
See the full 2015 Deloitte’s Technology Fast 500 list here.
Palo Alto Networks partners with some of the most demanding industries to ensure their data and critical infrastructure remain safe from targeted cyberattacks. These organizations have learned firsthand the power of a next-generation security platform when it comes to safely enabling the use of all applications, maintaining complete visibility and control, and confidently pursuing new business ventures, while protecting the organization from the latest cyberthreat. Explore the details of our platform here.
This post is the second in a blog series describing adversaries and their motivations. In part two of the series, we’ll explore the following top-level actor motivations: Cyber Espionage, Cyber Crime, and Cyber Hacktivism.
Adversary Operational Maturity, Targeting, and Key Roles
Before we start, there are some additional concepts that add context to exploring malicious actor motivations:
Operational Maturity: A gauge of the effectiveness and efficiency of a malicious actor
Targeting: How an attacker goes about selecting targets
Key Roles: The expertise required to conduct an attack operation, from inception to meeting objectives
Operational Maturity
Not all malicious actors pose equal threats. Factors that influence operational maturity of an attacker include:
Expertise: Ability to successfully conduct operations
Tradecraft: How well an attacker evades detection and attribution throughout the lifecycle of an attack
Resources: Level of commitment and persistence in launching attack campaigns
Additionally, advanced malicious actors across all motivations have successfully adopted tried-and-true techniques, generalized into repeatable and scalable operations. This facilitates broader targeting with minimized adversarial overhead.
Targeting
Attacks executed by malicious actors can be broken out into two categories:
Indiscriminate: The actor seeks to maximize gains through quantity (i.e., attacking as many entities as possible, leveraging rules of probability to fulfill objectives). Examples include general distribution spam e-mail attacks, drive-by downloads, and exploitation enabled by widely available vulnerability scanners.
Targeted: The actor seeks to maximize gains through quality (i.e., selecting targets most likely to yield desired results to fulfill objectives). Examples include spear phishing, watering hole attacks/strategic web compromises (SWCs), and direct exploitation by advanced actors.
Most motivations lean further into one of these camps than the other; however, in the course of operations, any actor may leverage both methods to meet their objectives.
Key Roles
Successful adversary operations typically rely on one or more key roles that are shared across all top-level motivations:
Sponsors: Ensure adequate resources (e.g., funds, head count, training) are available to support adversarial operations.
Brokers: Facilitate interaction between buyers and sellers for products (e.g., software, information) and services (e.g., development, exploitation).
Malware developers: Develop, buy, and/or sell malware and their corresponding delivery mechanisms.
Controllers: Coordinate different operational campaigns to achieve adversarial objectives.
Attack operators: Execute attack campaigns specified by Controllers, to include arranging for infrastructure and directly conducting attacks and exploitation.
Back office support: Perform pre and post exploitation processing (e.g., research, aggregation, analysis, and staging) towards culmination of success criteria for campaign objectives.
In some scenarios, requisite roles are embodied in a single individual, but for more mature and advanced operations there are often a number of people specializing in distinct roles.
These are just things to keep in mind as we begin exploring each malicious actor motivation in greater depth.
Cyber Espionage
Cyber Espionage includes patient, persistent, and often creative Computer Network Exploitation (CNE) for strategic economic, political, and/or military advantage.
Associated Actors
Actors operating under this motivation are the digital equivalents of the oft-romanticized spies sent to physically infiltrate and conduct collection operations within countries and organizations of interest. The Cyber Espionage motivation can be broken out into two categories:
Nation-state: Nation-state cyber espionage encompasses CNE activities sponsored by the government and/or military of a country to fulfill intelligence collection requirements as prioritized by that nation-state.
Corporate: Corporate cyber espionage focuses on unfair competitive advantage within an industry.
The concept of an Advanced Persistent Threat (APT) describes an attacker aligned with the Cyber Espionage motivation, and historically was synonymous with nation-state actors. The term APT encodes who is behind an attack and why, versus the what, when, or how. Given the fuzziness of establishing high-level actor motivations due to shared Tactics, Techniques, and Procedures (TTPs) and tools, the modern APT can be defined as any actor engaged in longer term espionage-oriented CNE against one or more focal targets.
Their Objectives
Collected information can benefit entities conducting espionage operations in various ways, including:
Unfair competitive insight: Adversaries conducting CNE against nation-states and corporations can benefit from detailed views into the strengths and weaknesses of existing capabilities and offerings, as well as visibility into the strategic roadmap for future efforts. For nation-state sponsored activity, gleaned information complements other intelligence gathering methods, including traditional physical infiltration by human spies and monitoring of additional communications mediums. Unlike the legal practice of business competitive intelligence gathering, corporate espionage enables unfair competitive advantages for market positioning through illegal means.
Boosts to innovation: As a secondary benefit of unfair competitive insight, theft of intellectual capital (i.e., products, services, expertise) can benefit the receiving entity by considerably reducing Research and Development (R&D) costs and allowing for innovative leapfrogging through derivative adaptations or extensions. This information can be used to replicate strengths, exploit weaknesses, and develop counter-strategies for competitive roadmaps.
Leverage in negotiations: Access to protected insider information can influence political and organizational negotiations. Examples of this include exploiting the delicate play in terms and concessions regarding military activity based on gleaned knowledge, gaming financial markets using captured non-public information, or determining the ideal bid for organizational acquisitions or work contracts through prior knowledge of competing bids or key bid evaluation factors.
Progressive targeting: Operations may identify platforms, business units, and/or individuals against which subsequent, progressive attack campaigns can be launched. In some cases, progressive targeting may identify personnel for coercion, leading to insider threats within organizations.
Additional Context for this Motivation
While there are considerable overlaps in TTPs and tools, nation-state and corporate CNE espionage-oriented operations differ in terms of targeting, scale, and extent of benefit. Nation-state sponsored CNE entails global campaigns across multiple industries, with a number of longer-term impacts, which can easily extend out for several decades and be difficult to quantify in terms of damage. Most corporate sponsored CNE includes nearer-term objectives, where damage is usually easier to quantify for a singular, competitive industry or company.
Most APTs are well resourced (i.e., funding, head count), leverage established infrastructure (whether purchased or compromised/subverted), and can be categorized as moderate to high sophistication in terms of capabilities and tradecraft. The term APT is a bit of a misnomer, as most attackers under this motivation do not employ “advanced” capabilities. Instead, they often only apply sufficient resources as required to achieve their objectives. In most attacks, a combination of social engineering and clever delivery of simple malicious payloads continues to serve adversaries well. Zero day exploits and advanced attack tools are typically held in reserve to minimize their exposure and potential detection, and only brought into play for high value strategic or tactical targets.
Cyber Crime is an extension of traditional criminal activity, focused on the theft of personal and account information and/or establishment of leverage over a target to achieve illicit monetary gains.
Associated Actors
The Cyber Crime motivation includes a wide range of actor sub-types, each enabling some form of fraud and theft to be carried out. Media coverage of cybercrime activity often cultivates an image of incidents such as major data breaches being associated with traditional organized crime. While it is true that there are a number of highly organized and skilled international cybercriminal groups, the availability of open source tools and respective online tutorials has lowered the cost of entry for aspiring cybercriminals as well. Still, successfully converting stolen information into sought-after payouts and avoiding attribution (and jail time) require a number of scheme-related roles and refined tradecraft.
Their Objectives
Actors operating under this motivation focus on direct or progressive monetary gains across various criminal scheme types:
Digital robbery: Whether through a banking trojan or a data breach of financial or payment card account information, cybercrime actors seek this information to siphon and sometimes completely exhaust victim accounts. This attack scheme applies equally to businesses and individuals, with some advanced actors aiming for the larger payouts of attacking financial institutions directly.
Exploitation of PII: Clearinghouses, processors, or even individuals managing personally identifiable information (PII) present ideal targets for cybercriminals. This information consists of established commodities typically used directly (i.e., identity theft) or sold in the criminal underground towards financial gain. Both alternatives can lead to progressive attacks leveraging key pieces of that information towards higher yield gains for one or more malicious actors.
Extortion: This type of scheme encompasses holding data for ransom, either towards restoring it for its rightful owner (e.g., ransomware such as CryptoWall) or potentially threatening to expose sensitive information to the public or other unauthorized parties unless demands are met. This is another area where Cyber Crime mirrors Cyber Espionage benefits: depending on the sensitivity of stolen information, there also remains a probability of victim coercion towards progressive attacks in support of an adversary’s ultimate objectives.
Additional Context for this Motivation
Similar to the Cyber Espionage motivation, attacks executed by Cyber Crime actors tend towards not-so-advanced methods, relying on social engineering and simple malware. The bulk of indiscriminate cybercrime attacks relies on social engineering to either trick someone into sharing sensitive information or executing malicious code on their device. Advanced actors operating under the Cyber Crime motivation are similar to Cyber Espionage operators in terms of higher degrees of targeting, resources, and tradecraft. This is not a coincidence, as there is a significant overlap between espionage and criminal activities for a number of malicious actors, to include TTPs and tools employed.
Surprisingly, variants on financial and PII theft scams that play on the greed and/or sympathy of targets remain viable for cybercriminals to collect funds from “willing” victims. Whether it comes down to claiming a windfall inheritance from a distant relative, assisting someone with liberating major funds in a foreign bank account, or helping out a new virtual acquaintance made online with a financial bind, the probability of success for such schemes keeps them in circulation.
Cyber Hacktivism entails activist cyber attacks that seek to influence opinion and/or reputation for specific organizations, affiliations, or causes.
Associated Actors
The broader concept of activism encompasses both legal and illegal activities. Actors operating under the Cyber Hacktivism motivation are activists using that medium to express themselves in the latter fashion. These actors are first and foremost individuals who share a common belief or cause. In some cases, they can operate independently; in others, they may cultivate affiliations with collectives or groups.
Due to the often anti-authoritarian leanings of hacktivists, loose collectives, such as Anonymous, are the norm. Such collectives do not employ a formal leadership hierarchy; usually power within the collective gravitates towards contributors with stronger reputation and popularity. More cohesive malicious actor groups under this motivation tend to be aligned with political causes, typically advertising sympathetic or fanatic allegiance to associated governments or parties. Additionally, not all members within collectives or groups are technically proficient; some contribute in other areas such as public relations, analysis of pilfered content, or simply amplifying the impact of attacks that they support using tools provided for that purpose.
Their Objectives
The predominant objective of malicious actors under the Cyber Hacktivism motivation is to send a message for or against a cause, which can range across political and moral polarities. The underlying goal of most associated activity is to embarrass, shame, or otherwise negatively impact confidence or trust in an organization that opposes the attacker’s views. Some common attack methods used by hacktivists follow, along with context on respective objectives:
Denial of Service (DoS): DoS remains a favorite for hacktivists because it doesn’t require sophisticated skills or tools. Often, it is employed in its distributed form, which maximizes the scale of mounted attacks by leveraging greater numbers of botnet or other attacking assets. The purpose of this type of attack is to disrupt operations of a target, whether strictly messaging available on websites or services exposed to users (e.g., e-mail, web portals, processing platforms). Anti-DoS service offerings have thrived due to the increasing popularity of this style of attack.
Release of sensitive information: This attack method, also referred to as doxing or doxxing, involves gaining unauthorized access to a target’s owned or entrusted sensitive information and releasing it to the public. This activity has a number of potential impacts, such as causing revenue loss due to disruption of e-commerce or other transactional services core to an organization’s business, degrading public confidence and trust in the target, and exposing embarrassing and potentially illegal aspects of the target.
Website and social media defacement: Ubiquitous web presence through websites and social media platforms makes them a hot target for adversaries. Government, military, businesses, organizations, and individuals use these platforms to advertise services, share views, and otherwise support certain initiatives or causes. Targeted disruption of these platforms is one end objective of this attack method; however, for indiscriminate attackers, compromise of any vulnerable platform to spread their message is acceptable.
Additional Context for this Motivation
The difference between Cyber Hacktivism and other top-level malicious actor motivations is that their anticipated payout is measured in the currencies of guided public perception and satisfaction in having dealt a blow to contrary causes. In cases where purportedly hacktivist activities shift to seeking compensation of any sort, this motivation shifts from Cyber Hacktivism to another, accordingly.
The broad set of tactical options open to hacktivists makes defending against them especially challenging. They only need to affect public perception on an incident to send their message, versus confirming quantified damage (typically easier to establish for other malicious actor motivations, such as Cyber Crime and Cyber Espionage). Actors under this motivation mostly use open source or widely available tools and tend to exploit well-known (i.e., usually patched) vulnerabilities.
Given the globally distributed qualifier of a DDoS attack, the range of technical/tradecraft proficiency for attackers using respective tools and botnets can make tracing incidents back to individuals challenging. Often, attackers with weaker technical and tradecraft proficiencies are more easily attributed and face criminal charges. Attackers stronger in those areas tend to evade attribution and indictments.
Examples
Some examples of Cyber Hacktivism activity follow:
The next blog for this series will take a closer look at the three remaining top-level malicious actor motivations: Cyber War, Cyber Terrorism, and Cyber Mischief.