Don’t Let Your Users Unknowingly Be the Weak Link in Your Security Infrastructure

Hackers are becoming increasingly stealthy and creative, relentlessly trying to gain access to sensitive data, while organizations work tirelessly to prevent security breaches and data theft. In this complex game of cat and mouse, security practitioners are being forced to rethink how they identify and control traffic on the network, shifting to an application-focused approach, rather than port- and protocol-based policy, to defend against successful cyberattacks and uphold business integrity.

User-based access controls, based on user identity information, rather than IP address, allow organizations to safely enable applications traversing the network, make informed decisions on network access, and strengthen overall network security. Here are four reasons why you should take advantage of user-based access controls, called User-ID, on your Palo Alto Networks next-generation firewall (NGFW):

1. Complete Network Visibility

Improve network visibility by mapping network traffic to users, rather than IP address. Application visibility based on users provides an organization with a more relevant picture of network activity, along with the power to quickly determine associated risks and respond accordingly. User-based access policies can be applied to application, URL, and file type accessibility, reducing the organization’s risk of initial attack, lateral threat movement, and insider threats by ensuring that data movement to and from users is both allowed and approved.

2. Simple Security Policy; Simple Life

Security practitioners do not have the time nor resources to invest in tracking thousands of IP addresses and complex security rules. Access controls based on User-ID, user identity, who is allowed or required to do what, dramatically simplifies the rules and safely enables applications, while simultaneously reducing the administrative effort associated with end-user moves, adds and changes. User-based access policy eliminates the need for a multitude of location-specific rules, as well as the need to dynamically adapt to the most appropriate policy for individual users and user groups, even as users move around the office, or outside the corporate network with various devices on different network addresses.

3. Minimum Access; Maximum Control

End users – employees, customers, partners – must be able to access required information repositories, as well as the Internet, to perform various functions of their jobs. Leveraging user-based access controls to analyze application threats and web surfing activity in terms of individual users, or groups of users, ensures access to mission-critical resources, and restricts access beyond the scope of approved means. When determining accessibility parameters, align application usage with business requirements following the principle of least privilege – minimum access based on job requirements – and, if appropriate, inform users that they are in violation of policy, or even block their application usage outright. User-based policy follows users regardless of location or device.

4. Increased Security; Better Forensics

It’s important to have the right user-based access controls in place to manage the identities and access of both internal and external employees, customers and partners. Knowing who is using each of the applications on your network, and who may have transmitted a threat or is transferring files, reduces incident response times and allows for damage control if an attacker does successfully infiltrate. In addition, user-based access policy ensures an attacker will only gain access to a small portion of data on the network, rather than the entire net worth of information. For maximum security protection and breach prevention, employ the right user access to mechanisms not only on the applications and endpoints that users access, but also on the organization’s next generation firewall infrastructure.

To learn more about the benefits of leveraging User-ID, user-based access controls, on your Palo Alto Networks NGFW:

[Palo Alto Networks Research Center]

Campaign Evolution: pseudo-Darkleech in 2016

Darkleech is long-running campaign that uses exploit kits (EKs) to deliver malware. First identified in 2012, this campaign has used different EKs to distribute various types of malware during the past few years. We reviewed the most recent iteration of this campaign in March 2016 after it had settled into a pattern of distributing ransomware. Now dubbed “pseudo-Darkleech,” this campaign has undergone significant changes since the last time we examined it. Our blog post today focuses on the evolution of pseudo-Darkleech traffic since March 2016.

Chain of events

Successful infections by the pseudo-Darkleech campaign have generally followed a set sequence of events. This happens regardless of the EK used or the payload delivered. The sequence is:

  • Step 1: Victim host views a compromised website with malicious injected script.
  • Step 2: The injected script generates an HTTP request for an EK landing page.
  • Step 3: The EK landing page determines if the computer has any vulnerable browser-based applications.
  • Step 4: The EK sends an exploit for any vulnerable applications (for example, out-of-date versions of Internet Explorer or Flash player).
  • Step 5: If the exploit is successful, the EK sends a payload and executes it as a background process.
  • Step 6: The victim’s host is infected by the malware payload.

In some cases, the pseudo-Darkleech campaign has used a gate between the compromised website and the EK landing page. However, we far more frequently see injected script from the compromised website lead directly to the EK landing page. To get a better idea of the relationship between EKs and campaigns, see our previous blog on EK fundamentals.

Figure 1: Chain of events for the pseudo-Darkleech campaign.

EKs used by pseudo-Darkleech

The pseudo-Darkleech campaign used Angler EK until that EK disappeared in mid-June 2016. Like many other campaigns, pseudo-Darkleech switched to Neutrino EK after Angler EK disappeared.

Pseudo-Darkleech stayed with Neutrino EK until mid-September 2016. At that point, Neutrino EK ceased operations. The pseudo-Darkleech campaign then switched to Rig EK, and it has stay with Rig since then. We still see indications of a Neutrino EK variant, but at much reduced levels compared to before.

Searching for EK activity in AutoFocus, we saw a significant drop in Neutrino and a corresponding rise in Rig activity starting in mid-September 2016.

Figure 2: Hits on Neutrino and Rig EK activity in September 2016.

Payloads sent by pseudo-Darkleech

When we last reviewed the pseudo-Darkleech campaign in March 2016, it was delivering TeslaCrypt ransomware. Since that time, pseudo-Darkleech has changed the ransomware payloads it delivers. In April 2016, this campaign switched to CryptXXX ransomware after TeslaCrypt shut down and released its master decryption key. By August 2016, pseudo-Darkleech had switched to a new variant of CryptXXX ransomware dubbed CrypMIC.

By October 2016, pseudo-Darkleech switched to distributing Cerber ransomware, and it has continued sending Cerber as of early December 2016. Below is a summary of EKs and payloads used by the pseudo-Darkleech campaign so far in 2016.

  • Jan 2016: Angler EK to deliver CryptoWall ransomware
  • Feb 2016: Angler EK to deliver TeslaCrypt ransomware
  • Apr 2016: Angler EK to deliver CryptXXX ransomware
  • Jun 2016: Neutrino EK to deliver CryptXXX ransomware
  • Aug 2016: Neutrino EK to deliver CrypMIC ransomware
  • Sep 2016: Rig EK to deliver CrypMIC ransomware
  • Oct 2016: Rig EK to deliver Cerber ransomware

Patterns of injected script

Any EK infection chain almost always starts with injected script from a particular campaign in a page from a compromised website. These pages are from legitimate websites that have been compromised and are being used by the campaign.

When we last examined injected script by the pseudo-Darkleech campaign, it was a large block of heavily-obfuscated text that averaged from 12,000 to 18,000 characters in size. It remained large and obfuscated through June 2016.

Figure 3: Start of injected pseudo-Darkleech script in page from compromised website in June 2016.

Figure 4: Middle of injected pseudo-Darkleech script in page from compromised website in June 2016.

Figure 5: End of injected pseudo-Darkleech script in page from compromised website in June 2016.

But by July 1st 2016, injected pseudo-Darkleech script stopped using obfuscation and became a straight-forward iframe. This iframe has a span value that puts it outside the viewable area of your web browser’s window.

Figure 6: Example of injected pseudo-Darkleech script from July 2016.

The injected script has changed slightly since then, but it remains short and unobfuscated as of early December 2016.

Figure 7: Example of injected pseudo-Darkleech script from December 2016.

Conclusion

With the recent rise of ransomware, we continue to see different vectors used in both targeted attacks and wide-scale distribution. EKs are one of many attack vectors for ransomware. The pseudo-Darkleech campaign has been a prominent distributer of ransomware through EKs, and we predict this trend will continue into 2017.

Domains, IP addresses, and other indicators associated with this campaign are constantly changing. Customers of Palo Alto Networks are protected from the pseudo-Darkleech campaign through our next-generation security platform, including Traps, our advanced endpoint solution that prevent EKs from compromising a system. We will continue to investigate this campaign, inform the community of our results, and further enhance our threat prevention.

[Palo Alto Networks Research Center]

TechDocs: Protect Your SaaS with the Latest Aperture Features

The Aperture team is working hard to make your life easier and keep your SaaS applications secure. New features introduced recently include:

  • Automatic Risk Remediation: The Aperture service introduces a powerful new feature that can automatically discover and remediate risks. You can create policy rules that automatically quarantine compromised assets, change sharing to maintain network security, and notify owners when an asset is vulnerable. When you automatically remediate risks, the Aperture service can process and fix large volumes of risks in record time with minimal overhead. Aperture supports automatic remediation on Outlook 365, Google Drive, Box, and Dropbox.
  • Support for Salesforce Sandbox: SaaS applications supported by the Aperture service now include Salesforce Sandbox applications. A Sandbox creates copies of your Salesforce organization in separate environments. You can use them for development, testing, and training, without compromising the data and applications in your Salesforce production account.
  • Enhanced Administrator Roles: Account choices in the Aperture service include a new Read Only administrator role. There are now three administrator roles you can manage to give you greater control over which tasks administrators can and cannot perform.

As always, you can find our content on our Technical Documentation page under the Aperture documentation page.

Happy reading!
Your friendly Technical Documentation team

Have questions? Contact us at: documentation@paloaltonetworks.com

[Palo Alto Networks Research Center]

Tech Docs: Introducing the New Palo Alto Networks Compatibility Matrix

The Tech Docs team just rolled out the new Palo Alto Networks Compatibility Matrix (PDF). We produced this document to address feedback about the “findability” of compatibility and support information for our various next-generation security devices.

The new central Compatibility Matrix covers different compatibility and interoperability considerations for Palo Alto Networks devices. For example, it covers supported operating systems for each version of the GlobalProtect app, supported endpoint operating systems for User-ID and TS agents, PAN-OS version support by model (including WF-500, M-100 and M-500 appliances), Traps and ESM operating system support, and VM-Series hypervisor support.

All content in this new guide is fully vetted by Engineering and Product Management. The Tech Docs team will continue to keep this content up to date and add new sections as necessary.

Make a pit stop at Technical Documentation to find our content.

Happy reading!

Your friendly Technical Documentation team

Have a question? Email us at: documentation@paloaltonetworks.com

[Palo Alto Networks Research Center]

UK’s “National Cyber Security Strategy”: Contributing to Increasing Cybersecurity and Prosperity in the UK and Worldwide

The UK government recently released its new National Cyber Security Strategy 2016-2021. Recognizing that cyberattacks on the UK are a top threat to the UK’s economic and national security, the strategy outlines a vision and goals to create a UK that is secure and resilient to cyberthreats, as well as prosperous and confident in the digital world. The UK has always been at the forefront of cybersecurity activities, and its new strategy is an important contribution to and model for global efforts.

The strategy lays out a substantive set of goals, actions and metrics mapped to three important pillars:

  • Defend: The government will strengthen its own IT defenses and work with industry to ensure UK networks, data and systems are protected against evolving cyberthreats.
  • Deter: The UK will strengthen law enforcement’s capabilities to increase the cost of cybercrime.
  • Develop: The government will help to develop the UK’s critical capabilities, including cyber skills, as well as the country’s growing cybersecurity industry, to keep pace with cyberthreats.

The strategy includes an impressive set of plans, based extensively on working with the private sector.  While all parts of the strategy are laudable, highlighted below are a number of its forward-looking approaches that will surely contribute to greater cybersecurity in the UK.

First, the strategy immediately puts into action its stated goal of partnering with industry. For example, as part of his strategy, the UK has created a new National Cyber Security Center (NCSC), which is a single, central government body bringing together many of the government’s cybersecurity functions, including CERT-UK. The NCSC will be the UK’s authoritative voice on cybersecurity and aims to build effective cybersecurity partnerships between government, industry and the public. The NCSC’s commitment to direct industry engagement will help to deliver many elements of the strategy. The NCSC will manage national cyber incidents, provide expertise and deliver tailored support and advice to government and industry.

Second, the strategy aims to prevent and reduce the impact of cyberattacks on the UK, reflected in a new “Active Cyber Defence” program. Described in a blog by Ian Levy, technical director of the NCSC, this effort aims to make a significant proportion of UK networks more robust through automated prevention, ensuring UK citizens are protected by default from the majority of large-scale commodity cyberattacks. For example, the government plans to provide automated protections to citizens accessing online government services and states that, where possible, “similar technologies should be offered to the private sector and the citizen.” Using automation to prevent successful cyberattacks is wise, given that attackers themselves deploy sophisticated, automated attacks. Responding with manual defenses just won’t scale: we won’t keep up and, in fact, will continue to fall behind. The UK’s prevention-focused calculus will change the dynamic that currently favors attackers, tilting the balance to help the UK government, businesses and individuals better protect their networks. The strategy envisions the development and deployment of automated cyber defense in partnership with industry.

Third, the strategy strongly endorses cyberthreat information sharing. In fact, one of the NCSC’s initial emphases will be on facilitating such sharing, including ensuring UK government organizations have easy access to cyberthreat information and improving government-industry sharing. The goal is to “ensure that citizens, businesses, public and private sector organizations and institutions have access to the right information to defend themselves.” Sharing threat intelligence on advanced cyberattacks, cybercriminal motivations, and the tactics of malicious actors is essential to defend networks and prevent successful attacks. The UK also plans to move toward automated cyberthreat information sharing to allow organizations to act swiftly on relevant information, an important measure that will support the aforementioned automated prevention goal.

Fourth, the strategy focuses heavily on helping industry to raise its cyber resilience. The government plans to work with critical national infrastructure (CNI) but also will expand outreach to many more firms: the “UK’s most successful” companies, companies that hold a large amount of data, high threat targets, digital service providers, insurers, and others. While the exact risks to these companies may differ, they all require cybersecurity for competitiveness and efficiency. Although the government plans to continue its practice of helping via investing in innovation and encouraging industry’s voluntary action, the strategy acknowledges a role for regulation, noting that the UK plans to use the forthcoming General Data Protection Regulation (GDPR) to drive standards of cybersecurity across the economy.

Fifth, augmenting the cyber resilience goals above, the strategy stresses that whether in industry or government, cybersecurity now needs to be viewed as a C-level or board-level concern, not simply an IT issue. The strategy notes responsibility for cybersecurity in the private sector lies with boards, owners and operators, while security of UK public sector organizations lies with Ministers, Permanent Secretaries and Management Boards. Palo Alto Networks agrees on the need for senior leadership involvement, and we are helping educate corporate directors and board members worldwide on these responsibilities through our recent book, Navigating the Digital Age. The UK version, including chapters by almost a dozen UK thought leaders, is slated for launch in early 2017. It is critical for modern corporations to have the capacity not just to understand the opportunities but also to understand and mitigate the risks inherent in our digital age, and we are pleased to contribute to that discussion in the UK.

Finally, the strategy stresses that the UK will work internationally. We wholeheartedly support this approach by all governments. Neither the global digital infrastructure nor the threats attacking it know national boundaries. We are only as strong as the weakest link. We appreciate that the UK will continue to play a strong role in global cybersecurity capacity building and use its influence in multilateral organizations, such as the European Union (EU), NATO and the G20.

These are only some of the many important activities in the UK’s new strategy, which also details plans to tackle cybercrime, develop cybersecurity skills across the population, and support a thriving UK cybersecurity sector. The UK’s National Cyber Security Strategy 2016-2021 sets out how the UK will become one of the most secure places in the world to do business in cyberspace. This framing is important. Cybersecurity must be viewed as an enabler, and the UK’s strategy, while acknowledging the growing threats, focuses on the benefits to the UK of better cyber resilience. As the sixth largest economy in the world, strong cybersecurity in the UK has multiplier effects around the globe. Palo Alto Networks looks forward to working with the UK government and private sector to realize the goals of its 2016-2021 Cyber Security Strategy and improve the UK’s – and hence the world’s – cybersecurity.

[Palo Alto Networks Research Center]

English
Exit mobile version