Palo Alto Networks Traps Covers Top High Risk Vulnerabilities Highlighted By US-CERT

US-CERT recently issued an alert regarding the 30 most prevalent vulnerabilities in targeted attacks that took place in 2014. Each of these vulnerabilities, when exploited, equals a compromised endpoint.

From this compromised endpoint the attacker will expand to other endpoints and servers in your network until it reaches its goal, possibly stealing the crown jewels it set out for.

The CERT list is a valuable source, reflecting the actual threat landscape. Security decision makers can derive important knowledge from reading between its lines:

The prevailing attack scenario is still a user browsing or opening an attachment.According to the CERT list, the only exceptions are one OpenSSL and four ColdFusion vulnerabilities. The following discussion does not relate to these vulnerabilities.

Memory corruption, logical and Java Vulnerabilities:

CVE ID Targeted Application Vulnerability Type Zero Day
​CVE-2006-3227 Internet Explorer Charset obfuscation
CVE-2008-2244 MS Word Buffer overflow
CVE-2009-3129 MS Excel Excel featherhead record
​CVE-2009-3674 Internet Explorer Uninitialized memory corruption
​CVE-2009-3953 Adobe Reader\Acrobat Array overflow
CVE-2010-0806​ Internet Explorer Use after free yes
CVE-2010-3333 MS Office Stack buffer overflow
​CVE-2010-0188 Adobe Reader\Acrobat Stack buffer overflow yes
​CVE-2010-2883 Adobe Reader\Acrobat Stack buffer overflow yes
CVE-2011-0101 MS Excel Excel record parsing WriteAV
​CVE-2011-0611 Adobe Flash Player Object type confusion yes
​CVE-2011-2462 Adobe Reader\Acrobat Unspecified yes
CVE-2012-0158 MSOffice DOC\RTF Stack buffer overflow yes
CVE-2012-1856 MS Office Use after free
​CVE-2012-4792 Internet Explorer Use after free yes
CVE-2012-1723 Oracle Java Sandbox escape
CVE-2013-0074​ MS Silverlight Double Dereference
CVE-2013-1347 Internet Explorer Use after free yes
CVE-2013-2465 Oracle Java Sandbox escape
​CVE-2013-2729 Adobe Reader Integer overflow
CVE-2014-0322​ Internet Explorer Use after free yes
CVE-2014-1761 Word Object Type confusion yes
​CVE-2014-1776 Internet Explorer Use after free yes
CVE-2014-4114 MS Office logical yes

Credit: US-CERT 

The targeted applications are the most common ones.  This comes as no surprise. The list is solely comprised of Internet Explorer, Silverlight MS Office, Oracle Java and Adobe Flash, Reader and Acrobat.

Vulnerabilities from 2012 and backwards comprise more than half of the list. This tells us more about victims rather attackers. Apparently non-patching is a common practice. Updating vulnerable software is not prioritized. This enables attackers to successfully leverage old vulnerabilities (dating back as far as 2006!) for their purpose.

Browser and attachment attacks are equally distributed. The distribution of these two main attack vectors is around 50/50 with slightly more browser exploits shown. Browser exploits are common in watering hole attacks and are typically integrated in exploit kits. Attachments on the other hand (Office, Adobe Reader etc.) are utilized in spear phishing attacks, targeting specific users. The nearly equal distribution implies that both vectors remain areas of concern..

Half of these vulnerabilities are zero days.  One of the most pressing issues for current cybersecurity strategists is the correlation between sophistication and prevalence. The non -proportional zero day presence in the CERT list implies that today’s zero day is tomorrow’s common attack vector. Of course, there is a natural selection involved which determines which zero-days will spread and which will decline.

Most of the memory corruption vulnerabilities enable exploits to bypass DEP and ASLR. In recent years, Windows integrated exploit mitigations forced attackers to adjust how exploits are written. The CERT list suggests they have succeeded; ROP, for example is common to almost all exploits shown. This illustrates once more the ever changing nature of the cyber threat arena in which whenever a security measure is introduced, attackers reflect, learn, reshape and attack in alternative patterns.

Addressing the Security Gap

Palo Alto Networks Traps directly addresses the security gaps reflected in the CERT list.

Traps prevents exploitation in real time by mitigating the core techniques that are common to all exploits. Exploitations of the vulnerabilities on the CERT list are different from each other but all of them converge into a known pool of techniques. Traps proactively obstructs these techniques, providing protection without relying on signatures or prior knowledge.

Learn more about advanced endpoint protection here.

[Palo Alto Networks Blog]

5 Networking Features to Check Out in PAN-OS 7.0

You asked for networking features, and we listened! Here are the top five networking features that we think have the biggest impact in PAN-OS 7.0.

ECMP

The firewall now supports Equal Cost Multipath (ECMP). With ECMP enabled, the forwarding table can have up to four equal-cost paths to a single destination, which allows you to load balance traffic, use more of the available bandwidth, and have traffic dynamically shift to another ECMP member if one path fails. You can choose one of several load-balancing algorithms to determine which equal-cost path a virtual router uses for a new session to the destination.

Read more about ECMP in the PAN-OS® New Features Guide Version 7.0.

DHCP Option Support

A firewall configured as a DHCP server can now send a full range of DHCP options to clients, including vendor-specific and customized options that support a wide variety of office equipment, such as IP phones and wireless infrastructure devices. Each option code supports multiple values, which can be IP addresses, ASCII text, or hexadecimal values. With the enhanced DCHP option support enabled on the firewall, branch offices do not need to purchase and manage their own DHCP servers in order to provide vendor-specific and customized options to DHCP clients.

Read more about DHCP Options in the PAN-OS® New Features Guide Version 7.0.

Granular Options when Blocking Traffic in Security Policies

When you configure the firewall to block traffic, the firewall either resets the connection or silently drops packets. When the firewall silently drops packets, it causes some applications to break and appear unresponsive to the user. Therefore, we now have new actions to gracefully block traffic and provide a better user experience.

Read more about Granular Actions for Blocking Traffic in Security Policy in the PAN-OS® New Features Guide Version 7.0.

QoS on Aggregate Interfaces

You can now enable QoS on AE interfaces configured on PA-5000 Series, PA-3000 Series, PA-2000 Series, and PA-500 platforms. An AE interface is two or more interfaces linked together for combined bandwidth and link redundancy. When using AE interfaces to scale your network, enable QoS on an AE interface to prioritize, allocate, and guarantee the increased bandwidth supported on the AE interface. Support for QoS on AE interfaces on PA-7050 firewalls began in PAN-OS 6.0.0.

Read more about Quality of Service in the PAN-OS® Administrator’s Guide Version 7.0.

IKEv2

Site-to-site IPSec VPN is enhanced to support Internet Key Exchange Version 2 (IKEv2), in addition to IKEv1. (GlobalProtect Client is not included in this feature support.) IKEv2:

  • Exchanges fewer messages than IKEv1 when setting up the tunnel endpoints.
  • Can negotiate multiple sets of traffic selectors to control which traffic can access the tunnel.
  • Provides a liveness check to determine if a peer gateway and tunnel are still up.
  • Supports NAT Traversal.
  • Supports the Hash and URL certificate exchange, which reduces fragmentation and the potential for IKE to incur DoS attacks.
  • Supports cookie validation of a connection if a threshold number of concurrent IKE SA sessions is exceeded, reducing the potential for DoS attacks.

Read more about IKEv2 in the PAN-OS® New Features Guide Version 7.0.

Can’t Get Enough of PAN-OS 7.0?

Check out the PAN-OS® 7.0 Release Notes and PAN-OS® Administrator’s Guide Version 7.0on the Technical Documentation Site, or select the 7.0 facet (under OS Version) on theDocument Search page!

Happy reading!
Your friendly Technical Publications team

[Palo Alto Networks Blog]

BYOD Makes You Productive, and It’s Also Why Your NAC Deployments Fail

Network Access Control (NAC): everyone wants to do it, and the goals for most programs are noble.

It goes like this: By ensuring only authorized users and devices connect to the network, IT can help alleviate the risk of an intruder bringing a rogue device onto the corporate network, or avoid people connecting their personal devices riddled with malware to the corporate network and infecting corporate-managed devices. Sounds perfectly simple and reasonable, right?

Not quite. The BYOD trend means NAC is no longer a clear-cut issue. Because most IT departments don’t support or keep tabs on users’ personal electronic devices, they need to limit the amount of access users on their own devices have to the environment in order to protect the rest of the network. Users, in turn, argue that limiting their ability to use their own devices on their employer’s network limits the productivity gains made possible by BYOD. 

Traditional NAC employs several technologies working in tandem to provide a solution. A NAC server is deployed that will house the policies, while an agent is deployed on BYOD devices for integrity profiling. If there is a setting or software on a computer, NAC can interrogate the device and report back to the server. The routers will need to be set up with at least a couple of networks: one for fully compliant devices and another for guests. The access switches will be configured to send authentication requests to the NAC server when a device connects. Based on the results of the integrity checks on the host, the NAC server will configure the switches to connect the user either to the fully compliant network or the guest network.

Most NAC deployments fail. We are used to a networking environment where you connect your device and have full access to the network. When NAC is deployed the opposite is true; when your device connects to the network it usually has little to no access by default. Once the device has been interrogated and is compliant with the NAC profile, it may be granted more access.

For example, a NAC policy will often be configured to require specific anti-virus software running and up-to-date on the device, and if someone brings his or her personal computer to work it will be deemed non-compliant by NAC. The moment someone with enough clout can’t get on the network because of this, a flood of the exceptions to the NAC policy start to roll in to IT. The project soon fails.

NAC is yet another “firewall helper” – something to be added on next to a traditional firewall, similar to how standalone URL filtering or Intrusion Prevention Systems are. It is a complicated and expensive proposition to keep adding devices to the network when NAC policies are so easily discarded.

GlobalProtect from Palo Alto Networks offers a simpler approach that can more easily attain the same results leveraging existing infrastructure. GlobalProtect is the remote access VPN client with both SSL and IPSEC connectivity options. GlobalProtect can also be used to perform Host Integrity Posture (HIP) checks.

Consider:

  • You can ensure groups of users are properly defined in your directory server. The more levels of access you want to define, the more groups will need to exist on the directory server. The security appliance obtains the user and group information from the directory server for use in access control policy so it’s important to get this where you want it. This step is true for all NAC deployments.
  • You can decide on what “compliant” means. For example,
    • Fully compliant may mean the user is authenticated to the directory server, the device is connected to the directory server, the device has a certificate, and the device has your standard endpoint protection software running.
    • Partially compliant may mean the user is authenticated to the directory server and has the GlobalProtect software running. These will likely be users on their personal devices who installed GlobalProtect by visiting the VPN portal.
    • Non-compliant users will be users who are not authenticated and do not have the GlobalProtect software installed.
  • You can decide on the levels of access users will get depending on their endpoint posture. Much of this may already be accomplished if you are using User-ID in your Palo Alto Networks security policies. You may have three security policies, as in this basic example;
    • Access for authenticated and compliant users may include typical web browsing and full intranet access with email, file shares, CRM, and development systems.
    • Access for authenticated non-compliant users may include web-browsing and DNS to the Internet and email access internally.
    • Access for unauthenticated non-compliant users may include web-browsing and DNS to the Internet only.

When devices connect from outside the physical walls of the organization, or from inside one of the offices, the network will adapt to the user and device based on what it observes (or doesn’t observe).

This is a clear departure from deploying another NAC server firewall helper that needs to communicate and make dynamic changes to the switching infrastructure to be effective. In this use case we are using a centralized security platform with a single policy engine to identify users and devices and provide appropriate levels of access depending on who they are and what device they are on.

To learn more about how GlobalProtect can help you enable a NAC policy that gives users the freedom to use their own devices, yet still protects your network, please visit our GlobalProtect technology page.

[Palo Alto Networks Blog]

Simplify Policy and Device Management in Panorama 7.0

As part of our PAN-OS 7.0 release, you can now take advantage of many new Panorama features designed to simplify policy and device management. Read more about them in thePAN-OS® New Features Guide Version 7.0 or read on for features that were hand-picked by our staff as having the biggest impact.

Device Group Hierarchy and Template Stacks

Are convoluted and outdated rulebases hindering your productivity? Now, it’s easier than ever to set, group, and manage rules by creating nested device groups in a tree hierarchy—with lower-level groups inheriting the policies and objects of higher-level groups—and template stacks, which push the combined settings of multiple templates to firewalls. These panorama features empower you to organize firewalls based on function and location without necessitating a redundant configuration.

Read more >> Device Group Hierarchy and Template Stacks

Multiple Access Domains for Role-Based Access

As an administrator, your time is precious! That’s why we now enable you to control administrator access to information according to areas or levels of responsibility, providing you increased focus and context. Each Panorama Device Group and Template administrator can now have multiple access domains, each controlling access to device groups and templates, and each paired with an administrative role. This enables administrators to filter the Panorama web interface by domain.

Read more >> Role-Based Access Control

Import a Firewall Configuration into Panorama

If you’ve ever tried to migrate a configuration into Panorama, you might know that the process could be a bit tedious and complex. To alleviate this pain point, you can now import firewall configurations into Panorama and can also clone templates and template stacks. These features save you the effort (and headache!) of deleting, recreating, or renaming configuration elements when only a move or copy is needed.

Read more >> Firewall Configuration Import into Panorama

Log Redundancy Within a Collector Group

Logs provide visibility. They enable you to analyze and correlate network events so that you can detect and respond to threats effectively. In Panorama, you can now enable log duplication for a Collector Group to ensure that, if any one Log Collector becomes unavailable, no logs are lost: you can still display all the logs forwarded to the Collector Group and run reports for those logs.

Read more >> Log Redundancy Within a Collector Group

Can’t Get Enough of Panorama 7.0?

For more information about Panorama features in PAN-OS 7.0, check out the Panorama 7.0 Documentation page on the Technical Documentation Site, or select the 7.0 (under OS Version) and Panorama (under Product Category) facets on the Document Search page!

Happy reading!
Your friendly Technical Publications team

[Palo Alto Networks Blog]

Operation Lotus Blossom: A New Nation-State Cyberthreat?

Today Unit 42 published new research identifying a persistent cyber espionage campaign targeting government and military organizations in Southeast Asia. The adversary group responsible for the campaign, which we named “Lotus Blossom,” is well organized and likely state-sponsored, with support from a country that has interests in Southeast Asia. The campaign has been in operation for some time; we have identified over 50 different attacks taking place over the past three years.

Background and Findings

Unit 42 has linked more than 50 individual attacks across Hong Kong, Taiwan, Vietnam, the Philippines, and Indonesia to the Lotus Blossom group. These attacks share a number of characteristics, including:

  • They are against military and government targets
  • Spearphishing is used as the initial attack vector
  • They use a custom Trojan backdoor named “Elise” to gain a foothold
  • A decoy file appears during initial compromise with Elise, tricking users into thinking they opened a benign file

Attacks by the Lotus Blossom group rely heavily on the use of spearphishing emails that use enticing subject lines and legitimate-looking decoy documents to trick users into opening a malware executable they think is a legitimate document. This document is usually a personnel roster for a specific military or government office.

We believe that the Lotus Blossom group developed the Elise malware specifically to meet the needs of the attack campaigns, and we’ve observed three variants across 50 samples during the three-year period of these attacks. Elise is a relatively sophisticated tool, including variants with the ability to evade detection in virtual environments, connect to command-and-control servers for additional instruction, and exfiltrate data.

Operation Lotus Blossom is a prime example of how a well-resourced adversary will deploy advanced tools, over an extended time period, sometimes years, in order to reach its goals. In this case, the pattern of behavior suggests that the actors behind this group were nation-state sponsored, from a country with an interest in the government and military affairs of Southeast Asian nations.

Unit 42 discovered this attack using the Palo Alto Networks AutoFocus service, which allows analysts to quickly find correlations among malware samples analyzed by WildFire. Palo Alto Networks customers are protected from the malware used in Operation Lotus Blossom via WildFire and our Security Platform’s Threat Prevention capabilities (IPS signature 14358).

We recommend that other security practitioners review the Indicators of Compromise (IoCs) in the full report to ensure they have not been targets in this campaign, and add the appropriate security controls to prevent future attacks.

The full report on Lotus Blossom from Unit 42 can be downloaded here, which includes all IOCs.

Visit Unit 42 for new research and a full list of speaking appearances, as well to subscribe to updates.

[Palo Alto Networks Blog]

English
Exit mobile version