Palo Alto Networks was at Bloomberg’s The Year Ahead 2016 conference in New York earlier this month where over 250 Business Development Managers and c-level professionals were in attendance.
While we were there, Davis Hake, our Director for Cybersecurity Strategy, was interviewed by Bloomberg Radio to discuss Palo Alto Networks technology, a prevention mindset to cybersecurity, and how companies can make the right investments in training, people and processes by involving the c-suite in the security discussion. Listen to the interview.
There is a lot of information on the web about preventing and recovering from CryptoWall or ransomware attacks in enterprise environments, but most don’t answer this basic question:
“How do I determine which CryptoWall-infected PC encrypted all the documents in one of my network-shared drives? I don’t have audit logging enabled on my file server.”
Although many organizations are working on migrating their document storage to the cloud, most still rely upon individual Microsoft network shares as a document repository for each business department. For example, the financial controller’s office may have a network share dedicated to that department, the HR department has a different one, etc. When a user’s PC in one of these departments becomes infected by CryptoWall, the ransomware iterates through all files on all folders on all local and mapped network drives and encrypts certain file types that the user has permissions to modify.
As a security lead for a hospital network, I created the following CryptoWall response plan specifically to deal with impacted department shared drives:
Identify the user account that modified (encrypted) the shared drive files.
Identify the infected PC and restrict network access.
Create inventory of all network share directories impacted.
Restore impacted directories from backup.
Identifying the user account in Step 1 can be challenging if you don’t know where to look. The best way to identify the user account used to encrypt the files is to examine the “owner” attribute of one of the instruction files created by the ransomware. Here are the steps to identify the owner:
1. Right click on the instructions file (i.e., HELP_DECRYPT.txt) created by the ransomware on the network share, and select Properties.
2. Select the Security tab –> Advanced –> Owner, and view the Current Owner attribute. The Current Owner attribute is likely the username used to encrypt the files in the directory.
Once you know the username used to encrypt the files, you can reset the user’s password, attempt to contact the person, and identify the user’s assigned PC in order to block it on the network. Once the PC is blocked, the server team can then identify the impacted directories on the network share (Tip: Use PowerScript to identify directories containing the instructions file). Finally, the Backup team can restore the files in all of the identified directories.
Marketing and advertising technologies have always been at the forefront of finding new ways to identify and track data, and security threats are never far behind. So, with 2016 looming, there’s no better time to look at Forbes’ “The Top 7 Online Marketing Trends That Will Dominate 2016” and the resulting security implications. Forbes’ list is as follows:
Video ads will start dominating.
App indexing will lead to an explosion of apps.
Mobile will completely dominate desktop.
Digital assistants will lead to a new kind of optimization.
Virtual reality will emerge.
Wearable technology and the Internet of Things (IoT) will pave new ground.
Advertising will become more expensive.
One thing is for sure: some of these trends open new avenues for cybercriminals. Three key trends that stand out as potential security issues are: the explosion of apps as a replacement for regular websites, the emergence of virtual reality, and the expansion of wearable technology. Let’s take a closer look at just how each of these three trends could impact web-based attacks in 2016.
Explosion of apps
There are already apps for everything from accounting to web posting, with more popping up every day. The fact that most apps can do exactly what websites can do – and in many cases better – will lead to a volume challenge, considering how the sheer number of apps can potentially degrade security and be open to exploitation.
Emergence of virtual reality
A new phenomenon, with little regulation and standardization, virtual reality opens the door to new, never-before-experienced cyberattacks. Virtual reality platforms will connect to the web or web-based apps, again resulting in a broader base to launch cyberattacks for cybercriminals.
Expansion of wearable technology
The Internet of Things (IoT) is moving beyond its infancy. Many wearable gadgets offer access to the web and very little control for secure access. Yet, most devices will somehow connect to a larger corporate network. This provides cybercriminals with the benefit of a lower barrier to entry into any connected organization.
While all of these changes are important, I do not expect to see a major shift in web-based attacks during 2016. Instead, we will see an adjustment in the behavior of cybercriminals and their use of the cyberattack lifecycle, mainly in how they infiltrate companies.
It’s hugely important for companies to deploy good application identification capabilities within a security platform that offers a holistic and comprehensive approach to security, with web security providing a part of the overall protection. Focusing on web security alone will not be sufficient. Securing an enterprise or government means architecting security to both detect and prevent known and unknown attacks while safely enabling applications.
Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.
Palo Alto Networks was a Gold sponsor of the official side program of the “Cyber3 Conference Okinawa 2015—Crafting Security in a Less Secure World”, an international cybersecurity conference hosted by the Government of Japan in Okinawa from 7-8 November 2015.
The event was moderated by William H. Saito, Special Advisor to Japan’s Cabinet office who is also Vice Chairman and CSO of Palo Alto Networks Japan. The conference featured three separate themes which were closely interconnected and interdependent: Cyber Connection,Cyber Security, and Cybercrime.
Held concurrently with the conference, the official side program, which included two Education track sessions, offered the opportunity for conference participants and global leading companies in the cyberspace to discuss comprehensive security measures.
In addition, Palo Alto Networks held a press conference to announce its 2015 Application Threat Usage Report (AUTR) as well as several media interactions. Last but not least, Palo Alto Networks also hosted dinner and networking events throughout the conference.
The event was a great success. Take a look at some of the photos from the event below!
Application Usage and Threat Report (AUTR) press conference
Cyber3 Conference Okinawa 2015
Vice Chairman of Nissan, Toshiyuki Shiga (center), together with Hiroshi Alley, Chairman and President of Palo Alto Networks Japan K.K. (far right)
Navigating the Digital Age books were widely distributed at the Conference. Download your copy.
Did you attend Cyber3 Conference Okinawa 2015? Share your thoughts from the event in the comments below.
On November 3, 2015, ZScaler reported that a Chinese government website hosting the Chuxiong Archives, http://www.cxda[.]gov.cn, had been compromised and contained injected code leading to the Angler Exploit Kit. The report stated that the affected website had appeared to be remediated and cleaned within 24 hours; however, upon scanning the website using our own malicious web content detection system, we discovered that in fact, the website remained compromised. At this time, we advise users to not visit the website in the near future, even though it appears to be clear of malicious code.
Based on our analysis, the malicious code injection on http://www.cxda[.]gov.cn has not been removed, but simply placed in a dormant state. After ZScaler published information regarding this compromise, we continuously scanned and monitored the compromised website, as well as other popular websites and potentially related suspicious targets. What we discovered was that many other websites had been compromised in a similar way, where the malicious code had the ability to be placed by the attacker in a dormant or an active state.
For this article, we chose a few of the additionally discovered compromised sites found by our malicious web content detection system and continued to scan them in high frequency. The following diagram shows the vulnerability status of three of these sites over the duration of a day. The markings on the top portion indicate that the site’s malicious code was active during that time slot while the markings on the bottom portion indicate the site was benign, or dormant, during that time slot.
Figure 1
In what appears to be a technique to evade detection or analysis, the injected malicious code has the ability to hides itself when the user-agent or IP address of the request does not meet specific criteria. Attempts to launch requests from different combinations of IP addresses and user agent strings consistently produced different behaviors (benign vs malicious) depending on what was sent.
During our continuous monitoring for a 24-hour period from November 11, 2015 to November 12, 2015, eight days after the Zscaler report, the Chuxiong Archives website consistently presented malicious content injected by an attacker depending on the source IP and user agent. It is believed that if a user were to visit the compromised website a second time following the initial exposure to the malicious code, the site would recognize the source IP and user-agent and simply remain dormant, not exhibiting any malicious behavior. Because of this anti-analysis/evasion technique, it may easily cause the belief that the threat has been remediated, when in reality, it had not.
At the time of this report, using our malicious web content scanning system, we have already discovered more than four thousands additional, similarly compromised websites globally exhibiting the same ability of being able to be dormant or active depending on source IP and user agent. Investigations regarding this campaign on a larger scale are ongoing and a second report detailing the similarly compromised websites will be published in the near future.