CIO, CISO and CTO: The Next-Generation of IT Leadership

I am very excited that Naveen Zutshi joined us today as our CIO. A few weeks ago we hiredLucas Moody as our first-ever CISO. The three of us will closely work together on pushing the IT envelope at Palo Alto Networks and expanding our security architecture in a way that not only will benefit us, but also very much benefit our customers.

Today, the relationship between the CTO, the CIO, and the CISO is evolving to one that is highly complementary. As organizations are moving to a prevention-first security architecture, it is imperative that technology, people, processes, operations, and policy are streamlined such that the outcomes become highly predictable and automated. Having Naveen and Lucas join the company is a natural step in our evolution. As more of our own infrastructure is moving into the cloud, and more of the services we provide to our customers are moving there too, we need to demonstrate leadership in how we address that challenge.

I’m also very excited to go on the road with Naveen and Lucas to share our experiences as best practices with our customers.

Welcome Naveen!

[Palo Alto Networks Blog]

2016 Prediction #9: Threat Landscape Affects the Presidential Election, Multifactor Authentication, and Data Destruction

This is the ninth in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

As 2015 comes to a close, it’s time to look ahead to next year and consider the sorts of changes we can expect in the threat landscape. Predictions of this nature are almost always based on two main factors:

  1. Continuation of a trend we’ve seen in the current year leading to small incremental changes.
  2. A significant shift away from the status quo based on a technological, cultural or political change that is underway.

Predictions based on continuing trends are highly likely to come true, while those based on significant shifts are more uncertain. Reluctant prognosticators, like myself, prefer to rely on data rather than speculate broadly about the future, but that doesn’t lead to very interesting predictions. So, this year, I’m going to split the predictions into two sections: “sure things” and “long shots” – and spend more time on the latter.

Sure Things

Based on the patterns I’ve seen in the last year, the following are “sure things” in 2016:

  • There will be more mobile malware, and most of it is going to both originate in and have the most impact in China. If you look at some of my team’s discoveries in 2015, you’ll see that China is a hotbed of mobile security research and attacks.
  • Attackers will continue to deploy ransomware for financial gain, and they will become increasingly specialized. In 2015 we saw widespread infections from ransomware, which encrypts files and demands a ransom for their safe return. Next year I expect attackers to use this technique in more specialized attacks, targeting high-value files and demanding ransoms much larger than the typical $500-700 we see today.
  • Human beings and their passwords will continue to be the weakest link. Malware and exploit code are common attacker tools, but they aren’t always necessary to successfully accomplish a task. At some point in almost any major network breach, a human makes a mistake (clicks a link, opens a file, etc.) and that person’s password is captured and used for malicious purposes. This trend is not going away unless something significant changes in the world of passwords (See: Long Shot 2).

Long Shots

Now that the easy bets are out of the way, let’s move on to predictions that probably aren’t better than a coin flip but will be more interesting for you to discuss with your colleagues at the water cooler.

Long Shot #1: A cyberattack will impact the 2016 presidential election

While U.S. citizens don’t vote online (like Estonians), there are many ways that a cyberattack could impact the outcome of the election either directly or indirectly. For example:

  • An attacker might release embarrassing information about a candidate at a critical junction, swaying public opinion or forcing that person to exit the race. Releasing private email messages, photos or documents could be very damaging and could be accomplished using a simple phishing email.
  • A candidate’s social media account could be hijacked to spread false information about a candidate.
  • A major news source could be hijacked to display false information about a candidate’s view.
  • Voting machines are far from immune to attack, but I suspect this is the least-likely way the election will be impacted.

The impact on the election may not tip the scales in the favor of one candidate or another; but, between now and November 4, the political process could experience a significant cyber “nudge.”

Long Shot #2: Multifactor authentication will become common and expected

Passwords are the keys to nearly every lock on the Internet, yet attackers steal them every single day. Authentication systems that require only a username and password for access are known as “single factor.” “Multifactor” authentication systems require an additional form factor, typically something you “have” (a token) or something you “are” (biometrics.) These additional factors are most-often used by systems that require higher levels of security; but, in 2016, they may finally make it to the mainstream.

The most common form of two-factor authentication (2FA) in place today involves tokens that generate random numbers every 30 to 60 seconds. These are either physical tokens, which you might attach to your keychain, or software tokens installed on your smartphone. They are offered by a multitude of companies, sometimes for free, and offer an excellent mechanism to prevent a simple password theft from resulting in an account compromise. In other cases token 2FA systems are replicated using SMS messages that contain the token code and offer a similar level of protection. Companies across nearly every industry offer 2FA options, but some still lag behind.

How often do you use a fingerprint reader? If I’d posed this question at the end of 2014, a small number of people may have said occasionally, but very few, daily. With the addition of fingerprint readers to the iPhone 5S (announced 3 years ago) and many more smartphones since, this technology has begun proliferating widely, and I suspect many readers have a fingerprint reader in their pocket right now.

At the moment fingerprint readers are mostly used as a convenient way to avoid typing a pin code. Fingerprints generally should not be used as a primary form of authentication (you leave fingerprints everywhere); but, as these devices become ubiquitous, they will offer a two-factor opportunity that was not previously feasible at scale.

While biometric authentication is unlikely to become ubiquitous in 2016, demand for 2FA options will force more and more companies to support token-based systems and some will require 2FA to keep their users safe. Widespread adoption of 2FA would be one of the greatest blows the security community could deal to cyberattackers around the world.

Long Shot #3: Data destruction and modification take center stage

Data theft is always in the headlines. Organizations are breached, and attackers steal private information for their own benefit. Of course, “theft” isn’t the only action an attacker can take once they enter a network. Some attackers destroy log files or modify records to cover their tracks, but what about those who have no intention of stealing information in the first place?

Director of National Intelligence, James Clapper, recently stated that he expects the next wave of attacks to manipulate or delete data, rather than just steal it.

A data destruction attack, like the Shamoon malware attack against Saudi Aramco in 2012, could temporarily or permanently shut down an entire organization. Viewers of Mr. Robot (I highly recommend it.) will note that the fictional attack that plays out in the first season is all about destroying the financial records of a major corporation to erase debt and throw the financial system into chaos.

Subtle data manipulation attacks are much less common (or less publicized). Students break into school district systems to change their grades, but this likely isn’t the type of attack that worries General Clapper. The OPM breach disclosed earlier this year is a more likely concern. Modification of OPM records could be used to help someone gain, or to be denied, a top-secret security clearance.

While I don’t expect these types of attack to surpass data theft in volume, we may find that the top cyberattack headline of 2016 isn’t about how many records were stolen, but how many were silently modified or deleted.

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

NIS Directive: One Small Step for Man, One Giant Leap for Digital-Society-Kind

The Internet is often referred to as the Wild West, a relatively ungoverned space, yet this week the European Union (EU) took a huge step forward in coming to agreement on what should be included in the forthcoming Network and Information Security (NIS) Directive. This landmark directive – the first time the EU has legislated on cybersecurity – aims to raise cybersecurity and resilience capabilities across the EU’s 28 member nations. First proposed in 2013, it may have seemed the directive was a long time in discussion, which is really validation of how important it was to society. Carefully defining what is required and who is included was critical to encourage confidence in the ever-growing digital world, bolstering potential GDP growth with a more secure and resilient cyberspace.

What does this mean for businesses?

First and foremost, the December 7 agreement now moves the directive into the more formal steps – it will progress from concept into application via the development of national implementing regulations. Until now it’s been easy to view this as a distant goal, timelines immediately become more predictable. Furthermore, with a defined scope of what types of organisations are covered and how, each should be looking to define their own plan now to ensure relevant compliance. Although the final text is yet to be released, much of the content has been long decided.

Who does it apply to?

The NIS directive has requirements at both a member state level and for businesses. Member states must have a defined national cyber strategy and capabilities to manage incidents that could impact digital society, by establishing (if they don’t already have one) a national CSIRT or computer security incident response team.

The directive specifically calls out obligations for “operators of essential services”, or those entities that are generally part of a country’s Critical National Infrastructure. The directive lists those essential services, which include as examples finance, healthcare, and energy, and requires them to have state-of-the-art cybersecurity that notifies, without undue delay, when they have significant incidents that could impact the continuity of the services they provide. Moving forward, member states will determine exactly which entities fall into these categories.

Also included are digital service providers (which was an area of much debate) and include the likes of e-commerce platforms, search engines, and cloud service providers. While the plan is that the requirements will be lighter on this group, their inclusion is a clear reflection of just how core these services are becoming to our increasingly digital society.

It’s worth noting that there are strong rumours that the Data Protection Regulation reforms under negotiation are to be finalised before the end of the year which would move the reform into the closing stages.

What should you do next?

  • Now that the scope has been settled, you should be able to clearly validate if you, your business partners, and/or your supply chain will be covered, so you can validate what the implications will be for your business.
  • Closely monitor implementation, especially by member states. Once the directive is published in the Official Journal of the European Union (which should occur shortly), member states will have 21 months to enact implementation regulations or laws. Timelines will become much clearer, which will allow you to define your plan for compliance.
  • At the same time, monitor for the General Data Protection Regulation to similarly reach agreement in the coming months. Although a separate piece of legislation, it is on a parallel track, and its conclusion will likely add to your requirements – pay attention to its scope and timelines.

The right mindset is key when thinking about compliance.

In my experience, as businesses review the implications of the legislation, they can easily over focus in on the new requirement to notify. This is due to response being the largest gap for many in their current capabilities; to date, many had no mandate to do so. However, before focusing your energies on response, you should first determine if you are effectively doing all you can to prevent cyber incidents from occurring in the first place. The more you prevent, the less you will require responsive capabilities.

Cybersecurity continues to evolve at a rapid pace, yet it’s very easy to slip into the habit of taking the same security measures that worked in the past. Ask yourself when you last changed a security process, or reviewed your capabilities, and whether they remain state of the art. More rudimentary is: how do you measure success; just what is the yardstick that allows you to validate the need for change? In the dynamic cybersecurity arena, continuing to do the same old things because they worked in the past typically means you are slowly slipping away from state-of-the-art capabilities.

In summary, it may seem obvious to tackle the new requirement of notification, but the greatest business benefit comes from stopping the incident in the first place. Finding the right balance between prevention and response is critical.

[Palo Alto Networks Blog]

VLAN Insertion: Become Secure and Compliant with Network Segmentation

In the past when I was architecting/implementing for ICS ecosystems I found out very early that one of the major steps to securing an ICS/SCADA, or any other network, is segmentation. During my efforts to secure these ecosystems, I learned that with network segmentation in place and a little forethought, it is possible not only to secure these environments but also build a scalable and compliant network that is future-proof. Segmentation, in my opinion, could be the single most important thing that a network practitioner can do to protect not only ICS environments but all network components from attacks and/or cross-contamination. Segmentation takes us back to a point where, if needed, a cable can be pulled and a device or network in jeopardy can be completely isolated from the rest of the world until the time and resources are available to correct the situation.

On the IT side of the company, segmentation is a known and accepted best practice and has been for some time. Operating Systems manufacturers have been aware of the need for years and have built tools into their products to help manage these processes. For the enterprise, in many cases, the task of segmenting a network (re-IPing and VLAN creation/assignment) can be done quickly and easily because of the many off-the-shelf solutions available to handle this task. More importantly, enterprise systems are not deterministic like ICS/PCN/DCS, so the possible consequences of changing these systems are not as impactful. Lose an email server and no one is happy; lose your controlling HMI and being unhappy is the least of your worries.

On the OT side of the company, the re-IPing and segmenting of control systems networks is a costly endeavor in both time and resources; and, if done incorrectly or a key system is missed or misconfigured, it can affect production for an extended period of time, resulting in the loss of product and/or revenue and, in worst-case scenarios, life and/or property. It is for these reasons that control systems networks are left as is by many operators. The risk associated with fixing the lack of separation between the enterprise and controls is not worth the possible cost. Instead many opt for solutions that only mask the problems.

The good news is the Palo Alto Networks security platform offers a method to allow operators to segment and separate their critical control systems networks from the enterprise with minimal impact to the control systems network.

The technology is native to the next-generation firewall and is available in every model from the PA-200 to the PA-7080. The name of the technique is called VLAN Insertion. What it does is allow for the logical insertion of one device between two other devices without the need for the physical re-cabling of the original devices or the introduction of additional switches, providing a method to segment a control systems network without the need to re-IP.

Examples of how this technology can be leveraged in a SCADA environment would be the separation of the HMIs from business machines that have been placed on the same network segment or an instance where incident response to a possible breach or contaminated machine has been found within the SCADA ecosystem, but the machine is required to control the system/process. VLAN insertion is a quick and safe method of separating/isolating these systems. However, the best part of this technology is that you can use it to meet compliance mandates.

Besides becoming compliant and secure, the additional gains of using this technique are:

  • High visibility into the network.
  • Converting from stateful firewalls to application-based firewall technology and positive enforcement.
  • Protection of these critical assets with AV/IPS/Malware/URL detection.
  • Ability to scale up or down as needed.
  • Ability to safety migrate to a new IP address structure as time permits.
  • Becoming compliant with internal and government mandates.
  • Access control over these assets, using AD, LDAP, TACACS Plus, etc.
  • Granular control over at-risk protocols and their function codes like MODBUS, DNP3.

What I found, and what I think all network/security practitioners and security architects would agree with, is that this is a crucial tool to have in one’s toolbox.

Watch the How to Architect “Zero Trust” Network Segementation in Industrial Control Systems webcast to learn more about how to use this powerful tool and the ways it can be leveraged in ICS.

[Palo Alto Networks Blog]

Some Clarifications and Commentary on Network Security and Covert Channels

This week, a security researcher posted a blog about the security implications of how next-generation firewalls handle TCP session setups. SC Magazine also published an article that included similar technical claims provided by the security researcher. We’d like to take the opportunity to clarify the content of these articles for our customers and the industry, because both of these writings included some inaccurate claims that may sound concerning.

One claim from the researcher is that next-generation firewalls “…are designed to permit full TCP handshake regardless of the packet destination … bypassing the firewall to any destination on the Internet, regardless of firewall rules and client restrictions” (emphasis in the original).

This claim, as written in the blog and SC Magazine article, is false. Firewall policy is never violated. Before even a SYN is allowed through, the firewall rule base is evaluated to check if a TCP setup should be allowed at all.

After some conversation with the researcher, it appears the actual concern is that if an administrator creates a typical web browsing policy on a next-generation firewall, this allows a SYN (and in fact a complete 3-way handshake) from allowed web clients out to the internet on the standard HTTP service (tcp/80). This is true of any firewall, and anything that does otherwise is a proxy—and only if that proxy happens to already know the host is malicious.

To put this in context, it is helpful to remember that this technique is not new. Information hiding in TCP/IP is nearly as old as the stack itself (see references). This is essentially a covert channel, and as with any covert channel, it requires the adversary to already have control over both ends of the connection. This is simply one example, and in general, covert channels are limited only by the creativity and patience of the adversary. For example, data can simply be carried over normal HTTP payloads to a recently compromised WordPress site (this actually happens every day). Far simpler and more efficient, without bothering with TCP trickery—and nothing about the act of proxying does anything to stop this.

That is why it is important to focus on prevention, a key tenet of the Palo Alto Networks next-generation security platform. The layers of security provided by App-ID, Content-ID, WildFire, Traps, and the complete combination of Palo Alto Networks platform security capabilities are important in denying the adversary access to the network and endpoints at every stage in the attack lifecycle. The game of endless incident response, covert signaling, steganography, and inventorying data lost after a breach is unwinnable.

Palo Alto Networks customers are encouraged to reach out to customer support for any additional questions about this topic or any product security matter.

— Palo Alto Networks product security team

*****

The original researcher blog post is available at: http://www.bugsec.com/news/firestorm/

The SC Magazine article is available at: http://www.scmagazine.com/firestorm-vulnerability-in-firewalls-let-attackers-extract-data-from-cc-servers/article/458817/

T. Handel and M.Sandford., “Hiding data in the OSI network model,” (Cambridge, U.K.), First International Workshop on Information Hiding, May-June 1996. Retrieved from: http://chemistry47.com/PDFs/OSI%20Model/Hiding%20Data%20in%20the%20OSI%20Network%20Model.pdf

[Palo Alto Networks Blog]

English
Exit mobile version