Hack on Ukranian Power Grid Highlights the Urgency for Accelerated Threat Intelligence in Industrial Control Systems

Recent and more conclusive reports on the cyberattack of a Ukrainian power grid, such as the article reported in Wired Magazine, confirmed the level of sophistication of this campaign. The net result of a mass power outage for hundreds of thousands of people is mind-blowing, but the highly coordinated events leading up to the outage were, perhaps, even more so. If one could call advanced persistent threats artists, this campaign would be up there as one of the hacking community’s best masterpieces to date.

Considerations for the Operational-Technology Attack Phase  

The components of the OT portion of the combined IT-OT “pivoted” attack (which was the pathway used in the German steel mill hack of 2014) were precisely integrated and serve as evidence of the attackers’ deep knowledge of OT and this particular utility’s infrastructure. From the use of stolen credentials to access remote management applications (e.g., SSH) over VPN, to the use of quietly commandeered SCADA hosts to issue ICS protocols in an effort to open relays and corrupt firmware on serial-to-ethernet converters to the debilitation of remote SCADA systems via the KillDisk malware, all of these cyber components were pretty much unprecedented, at least in terms of a publicly disclosed and successful attack leading to a mass outage.

Reports indicate the utility did have a firewall at the IT-OT perimeter. Questions are raised if there was any more granular segmentation beyond the edge, and whether the firewall logs were being proactively monitored and analyzed. However, an important question is: Just what kind of firewall was this? If it was only a stateful inspection firewall, then it would not be too surprising that the attackers went undetected, given the rudimentary port and IP visibility offered by such legacy technology. Next-generation firewalls, on the other hand, provide visibility (and access control) at the application, protocol, user and content levels while simultaneously applying built-in threat prevention (exploits, viruses, C2 traffic). Perhaps it might have been helpful to identify and stop the OT-specific attacks, which used stolen accounts to maliciously utilize a range of business, remote management, and ICS protocols, and to deploy malware, like KillDisk, during its attack. Maybe. Maybe not. But is this the right area of focus for the post-mortem analysis?

Nip it in the Bud – Stopping the IT Attack Phase

What wasn’t clear in the reports was how quickly the OT portion of the operations was conducted. Given how skilled and knowledgeable these attackers were, it wouldn’t be a surprise if it happened over weeks or days (hours would be really impressive) in terms of the time from the initial OT breach to the time of the outage. What’s interesting is that the campaign seems to have started back in the spring of 2015 with social engineering activities to the IT infrastructure of the utility and its business partners. In other words, the attackers were running their reconnaissance operations for months before actually enacting the physical part of the attack. Rather than talking about how the OT portion of the attack could have been prevented, a more forward-thinking question is: What could have been done to prevent the attackers from breaching the IT network to begin with, and stop the theft of the credentials used to breach the OT?

What made the initial attack of this campaign very evasive was that the attackers used very effective social engineering and zero-day malware, repurposing old-school methods (trick the user to start embedded malicious macro) and pre-existing root kits (BlackEnergy) to successfully establish a beachhead into the utility organization. The simple fact that this particular malicious attachment had never been fingerprinted by host-antivirus or network-antivirus products allowed it to quietly circumvent existing security provisions. It is this zero-day element that many organizations are not capable of addressing because they don’t have the tools that can address attacks never seen before in the wild.

Given the rising ICS advanced-threat landscape and severe consequences involved with a breach to ICS (as was the case here), there is a strong argument to be made that operators of critical infrastructure need to make sure they can address similar campaigns, such as this, in the future, and develop more sophisticated security capabilities.

Accelerating Threat Intelligence in IT and OT with PAN-OS 7.1

We already covered in an earlier blog post how our WildFire and AutoFocus technologies help in detecting and preventing the zero-day threats, including BlackEnergy. With our latest PAN-OS 7.1 release, we are pleased to say that we have made these capabilities even more powerful.

WildFire, the service that allows the user to quickly identify zero-day threats and deploy protective measures has been beefed up with the ability to do these important functions 70 percent faster than before. Users can now detect and prevent zero-day attacks in as little as five minutes. In addition, its capabilities in stopping the universe of unknown threats has been improved with new machine-learning algorithms, which instantly stop variations of known malware, even if they have never been seen by WildFire. These algorithms also reduce analysis time for Personal Executable (PE) variants of known malware.

The new release of AutoFocus received an upgrade, which tightens its integration with PAN-OS 7.1 and Panorama. The new capabilities essentially bring more advanced-threat context to the entire organization, simplifying response efforts for the most critical attacks in a single, easy-to-use console. This puts the largest collection of unknown malware data at your fingertips, allowing you to automatically turn analysis efforts for unique, targeted attacks into proactive protections by blocking malicious domains, IP addresses, and URLs with AutoFocus and PAN-OS dynamic block lists. AutoFocus also adds the ability to bring threat intelligence into your existing security operations workflow with an improved API and support for the STIX information-sharing standard.

Learn More

Advanced network security via a next-generation firewall is necessary; but to combat the more sophisticated threats that utilize zero-day attacks, one needs equally sophisticated capabilities. The threat intelligence cloud component (utilized by the WildFire and AutoFocus services) and Advanced Endpoint Protection of our Next-Generation Security Platform were designed to prevent attacks from such threats with as much automation as possible.

Learn more about our platform capabilities by reading this whitepaper on 21st Century SCADA Security and by visiting the resources below.

[Palo Alto Networks Research Center]

Ignite 2016: Conquering the Cyber Range

The biggest and best Ignite Conference yet is in the books. Our heartiest thanks to everyone who made it so!

Watch this space over the next few days for more from Ignite 2016, from behind-the-scenes photos and video to lots more action from the breakout rooms, exhibit hall and the late night festivities.

For now, however, we’re pleased to highlight this week’s Cyber Range exercises, which took place on Tuesday and Wednesday at Ignite and were sponsored by The Wall Street Journaland The Economist. Each day featured teams of Palo Alto Networks customers going head to head as they were tested on a network generating live traffic and real world malware, honing their skills with the Palo Alto Networks Next-Generation Security Platform.

Congratulations to the Cyber Range Day 1 and Day 2 winners!

Save the Date

Believe it or not, we’re already looking ahead to our next get-together. Join us at Ignite 2017 in Vancouver, British Columbia, June 12-15, 2017

Stay Social

You can continue to follow Ignite activities on @Ignite_Conf and using hashtag #igniteconf16. Over the next few weeks we’ll be adding general session and breakout session videos as well as some of the great conversations captured with our customers onsite in Las Vegas. Don’t forget to check out our Facebook gallery for the latest snaps from the show. We’ve shared a few below as well as what our attendees are saying about their time at Ignite 2016:

[Palo Alto Networks Research Center]

How the New PAN-OS 7.1 Release Benefits Government Organizations

We’ve just announced the newest release of our operating system, PAN-OS 7.1. You can read all of the details about this new release but, for our government customers, I wanted to highlight a few particular things that you have been talking about and deploying.

1. Extending Our VM-Series Private Cloud Support to Hyper-V and Azure

Our government customers are using a breadth of hypervisors within their virtualized data centers, or private clouds. With the release of PAN-OS 7.1, we extend our cloud support to include all major virtualization environments, including VMware, KVM/OpenStack, Amazon Web Services (AWS) and Microsoft with our VM-Series. In fact, a large Western military organization recently chose one of these hypervisor environments for its network, taking full advantage of Palo Alto Networks support for Hyper-V. Other large Western civilian governments have chosen Palo Alto Networks to secure their Microsoft Azure environments.

2. Full Visibility for PFS/SSL Encrypted Communications

Are you thinking about the many encrypted communications that could bring threats into your environments? Hopefully by now you’ve got a plan to decrypt those communications with our onboard SSL decryption (you can read more about how we support SSL decryption for governments in our Uncover SSL-Encrypted Attacks in Government Networks white paper). With this new release, we’re providing PFS/SSL decryption for ECDSA for SSL Forward Proxy. For U.S. and U.K. government customers, this adds yet another capability to the many we support for Suite B crypto ciphers.

3. Five-Minute Signatures and Dynamic Blocking for Highly Targeted Government Networks

The rate at which our government networks are attacked is staggering. So government agencies appreciate that Palo Alto Networks already highly automates the prevention of threats across their networks. Civilian agencies and military services tell us every day how better-protected they are when they turn on their Palo Alto Networks Next-Generation Security Platform. With PAN-OS 7.1, we’ve further reduced the time WildFire takes to identify and prevent zero-day threats to five minutes. In addition, WildFire can analyze Mac OS binaries, so malware that targets Apple products can be prevented. And newly discovered phishing websites are now categorized within 30 minutes. WildFire analyzes email links for indicators of phishing, such as spoofed URLs and credential-seeking form fields, and updates PAN-DB within 30 minutes. For URLs and DNS, we’ve added more block lists. In addition to the block lists based on IP addresses, you can now have URL and DNS block lists.

Note that if you’re attending Ignite 2016, we hope you’ll be participating in Cyber Range. Cyber Range participants will get real, hands-on experience with WildFire as the teams compete to mitigate actual single-vector and multi-vector attacks. If you didn’t get a seat at Cyber Range this year, don’t worry. Ignite 2016 attendees can still observe the teams as they compete to see who can prevent threats the fastest.

4. Deploying on Ships, Tanks, and Elsewhere? Offline NSX Registration

There are numerous examples of how Palo Alto Networks platforms are supporting these tactical deployments. With this release, you can now complete NSX registration offline, which our customers told us is important for their tactical environments.

5. Consolidating Your Insights on IOCs: Consolidated Log Viewer

And speaking of all of those threats hitting government networks today, we’ve consolidated threat, traffic and WildFire logs for you into a single view. We hope you’re already using AutoFocus for your threat intelligence analysis. Now you can query from within AutoFocus across all of our threat insights to simplify the task of tracking an IOC or IP address. You also can query all of your appliances across the network for potential artifacts.

6. Certifications for Government: FIPS 140 and Common Criteria

With PAN-OS 7.1, our government customers are getting FIPS-140 certifications for Panorama, Log Collector and Offline PAN-DB. You’ll also appreciate our compliance with the VPN Gateway Extended Package and the IPsec VPN Gateway Security Characteristics. Finally, for those U.S. agencies having to comply with the DISA Security Technical Implementation Guides (STIGs) for information assurance, you’re getting last login time, last unsuccessful login, accept login banner verification, and classification banners.

Want to learn more? We hope to see you at Ignite 2016, where you’ll learn more about all of these new features in PAN-OS 7.1. But don’t worry if you can’t make it. If you’re a U.S. government agency, we’ll see you at our annual Federal Forum in Washington, D.C. This year’s Federal Forum will be held July 16 at the Newseum. See you there!

For more information, please visit our Technical Documentation page or any of the following resources:

[Palo Alto Networks Research Center]

Ignite 2016: A Next-Generation Security Platform Built for the Prevention Age

You all knew we were just getting warmed up, right?

Tuesday at Ignite 2016 kicked into high gear with dazzling performances of dance and rap – complete with high-energy choreography and glow-in-the-dark lights. In between came the all-star succession of general session headliners, including our own Mark McLaughlin and Lee Klarich.

Following their presentations came a fireside chat between CSI TV franchise creator Anthony Zuiker and actor and former White House official Kal Penn. There were plenty of laughs and a few lighter moments when it came to how cybersecurity gets the “Hollywood treatment,” but Zuiker and Penn also took a few minutes to highlight the importance of cybersecurity education for children – paramount for a generation that grew up with the Internet as a given. They were all followed by the inimitable Nir Zuk, keying in on the importance of prevention and the power of the Next-Generation Security Platform.

Check out the video recap of today’s Ignite action, including highlights from the general session, what resonated with members of our live audience of more than 3,000 security professionals and partners, and the winners of the first of our Cyber Range exercise. And read on for details of the general session and the day’s announcements.

What We Mean By Prevention 

As Mark, Lee and Nir noted, a cybersecurity mindset of detection and remediation is futile in the face of advanced attackers who get ever more creative in the ways they can successfully breach networks and steal critical information. As Mark noted, preventing breaches is in many ways a math problem: figuring out how to interdict the attack lifecycle at each of its stages.

What that means for the industry, as Lee explained, is a true platform that can provide complete visibility, reduce the attack surface area, prevent all known threats, and prevent new threats. And not only do those four things, but in such a way that capabilities are natively integrated to work together, are applied consistently to all users, applications and locations, and offer automated discovery and reprogramming of both the network and endpoint to prevent known and unknown threats.

Hence: the Palo Alto Networks Next-Generation Security Platform – updates to which we announced today in the form of PAN-OS 7.1 and which Lee described in detail. (Watch this space for a lot more on PAN-OS 7.1 in the coming days.)

Today’s Announcements:

Coming Up Tomorrow:

  • Our second Cyber Range exercise, sponsored by The Economist. Join us in the exhibit hall for all the action or follow along at #IgniteRanger!
  • A final day of training and breakout sessions, including our track intended for CISOs and C-level executives managing cyber risk
  • PCNSE6, PCNSE7 and PSE: Platform Professional exams in Brera 3, 4 and 5

Stay Social!

Follow @Ignite_Conf and use #igniteconf16 for the latest from today’s sessions and to get a look ahead to our final day. Keep an eye on our Facebook gallery for new photos. And have a look at what people here at Ignite 2016 are saying about their experiences:

[Palo Alto Networks Research Center]

Announcing PAN-OS 7.1: Extending Breach Prevention to the Cloud

The demand for business to be more agile to meet customer demands and stay competitive is driving a change in the way applications are developed, deployed and adopted. Applications, workloads, and the data that go with them are becoming more distributed among varying environments, including physical networks, virtual private clouds, migrations to public clouds as hybrid deployments or dedicated public clouds, and Software as a Service applications (SaaS). Each type of environment brings its own unique agility benefits – and security issues.

The challenge has become balancing the agility needs of the business with improving the security of the applications and, more importantly, the security of the data as it moves between the various clouds. Gaining visibility and preventing attackers from getting access to data, both from an external location and through a lateral attack, becomes imperative across all of the locations where the applications and data reside. And it has to be done without adding additional complexity or cost to the business.

Today, we’re announcing PAN-OS 7.1 with a set of important advancements to the Palo Alto Networks Next-Generation Security Platform that are designed to extend the breach prevention capabilities of the platform and address the security needs of businesses working with cloud-based environments and SaaS applications. Read on to find out what’s new in PAN-OS 7.1. 

Securing Any Cloud

PAN-OS 7.1 adds even greater public cloud capabilities for the VM-Series with Microsoft Azure support. When combined with the physical firewalls and Aperture SaaS security, the addition of support for Azure enables the most complete security portfolio for Microsoft environments. Private cloud deployments are also expanded with support for Microsoft Hyper-V, enhancements to VMware NSX such as multi-tenancy, and OpenStack controller integration.

This breadth of cloud support enables you to move toward a hybrid environment with workloads that can be securely deployed in a private cloud, or an on-premise data center with the public cloud.

Enable SaaS Applications, Such as Office 365

Palo Alto Networks now adds to its extensive SaaS application capabilities with the release of PAN-OS 7.1, and the newest update to Aperture, to fully enable secure Office 365 deployments. Through App-ID, we’ve added the ability to identify Office 365 applications and how they are being used, even if they are encrypted, as well as the ability to decrypt Office 365 flows to inspect even deeper within the files being exchanged to look for threats. Aperture adds the ability to protect data from exposure and threats in the Office 365 cloud itself, stopping them at the source before they have a chance to move to the network or mobile devices.

Accelerated Threat Intelligence

The common need across all application deployments, no matter their location, is the ability to provide real-time threat protection and visibility. With PAN-OS 7.1, new capabilities supported in WildFire and AutoFocus greatly improve the speed of detection and remediation and improve IT’s ability to respond quickly to those threats.

WildFire malware analysis can now identify and prevent zero-day threats much faster than before – in as quickly as five minutes. Threat analysis has been enhanced with new machine-learning algorithms to instantly stop variations of known malware – even if they have never been seen by WildFire – and reduce analysis time for Portable Executable (PE) variants of known malware. This changes unknown threats into instantly stopped known threats.

New AutoFocus integration with PAN-OS 7.1 and Panorama brings advanced threat context to the entire IT organization, simplifying response efforts for the most critical attacks, in an easy-to-use console. This puts the largest collection of malware data at your fingertips, allowing you to automatically turn analysis efforts for unique, targeted attacks into proactive protections by blocking malicious domains, IP addresses, and URLs with AutoFocus and PAN-OS dynamic block lists. AutoFocus also adds the ability to bring threat intelligence into your existing security operations workflows with an improved API and support for the STIX information sharing standard.

Prevent Breaches with Secure User Credentials

Additionally, among the new features of PAN-OS 7.1 are advancements that help protect user credentials and make them unusable if they are stolen.

Credential theft is a growing concern among many organizations because of an attacker’s ability to bypass security controls and gain full access to the networks and cloud applications once authenticated. These credentials can be obtained in a number of ways, such as a phishing attack, a key logger on an endpoint, a packet sniffer on a network, or breaching a user database.

Once credential theft occurs, an attacker can impersonate the user and gain access to networks, applications and data. Then, once authenticated, further damage occurs from unauthorized access as the attacker initiates lateral movement to compromise other machines or exfiltrate data.

With the new features in PAN-OS 7.1, organizations can deliver protection against credential theft and phishing at all times, no matter where the user goes, and make credentials useless even if they are stolen.

That’s Just the Beginning

There are more than 50 new enhancements in the 7.1 release that are designed to extend the breach prevention capabilities of the platform. For more information on the new capabilities in PAN-OS 7.1, head over to our resources page.

[Palo Alto Networks Research Center]

English
Exit mobile version