What is NetFlow and How Can it Help Me Monitor Traffic?
Do you want to know how much traffic is flowing through your network, where it’s coming from and going to, and who is generating it?
Palo Alto Networks firewalls support NetFlow v9, an industry-standard protocol for exporting information about IP traffic flows as they enter or exit an interface. You can use this information to gain real-time situational awareness of all users, devices, and traffic in your network.
The firewall sends the flow information as NetFlow records to a NetFlow collector. A flow is a unidirectional sequence of packets that have common attributes such as ingress interface, source/destination IP address, IP protocol, source/destination port, and IP type of service. In the Palo Alto Networks implementation, the NetFlow records also include application names and usernames that the App-ID and User-ID features identify. The NetFlow collector processes the flow records to present traffic analysis in a user-friendly format. This traffic analysis enables you to discover patterns in bandwidth usage and device performance. It also helps you detect traffic anomalies so you can improve firewall policies to protect your network while allowing users to access useful applications.
For example, if users complain about slow or sporadic access to services, NetFlow can help you identify which users, endpoints, applications, and protocols use the most bandwidth and at what times. Identifying the top “talkers” and predicting spikes in activity can help you plan bandwidth expansion. If DoS or other attacks target your network, NetFlow can help you to detect these before they escalate and cause a network outage.
Using NetFlow is Easy!
To start using NetFlow to analyze traffic:
Define access to a NetFlow collector by configuring a NetFlow server profile.
Assign the profile to each firewall interface that carries the traffic you want to monitor.
Use the NetFlow collector to analyze the traffic.
For detailed configuration instructions and a list of supported NetFlow templates and fields, refer to NetFlow Monitoring in the PAN-OS 7.0 Administrator’s Guide.
This blog is the first in a series describing adversaries and their motivations. This part in the series presents underlying concepts and the value proposition for exploring who is attacking a network and why.
Intelligence Driven Computer Network Defense
The modern Computer Network Defense (CND) staple of intelligence driven operations (PDF) is based on the observation that incidents are not singular events, but rather phased progressions. In this model, defenders benefit from a cohesive view of adversaries operating inside of a network (also referred to as viewing an adversary in the aggregate). This enables defenders to not only detect today’s threats but also leverage a scientific, evidence-based approach to engage tomorrow’s evolving threats. At its roots are the identification, analysis, and tracking of instances an actor interacted with a network and their respective direct and indirect activity as they worked towards one or more objectives.
For networks with strongly architected and implemented security, an abundance of information is available to support preventive strategies and enable more efficient and effective CND. Organizations focused on the development and continuous improvement of their CND people, processes, and technology can glean significant intelligence from this information, which can then be incorporated into a continuous feedback loop for progressively stronger defense.
For any incident, there’s an inherent trade-off between completeness of investigation (i.e., qualification, quantification) and time to closure (i.e., point of containment, lasting remediation). Organizational leadership traditionally focuses on answering the “what”, “when”, “where”, and “how” questions surrounding a security event or incident, which is understandable, considering that this information helps explain risk in quantifiable terms to key stakeholders across the business. However, the sometimes overlooked “who” and “why” questions for an incident are also valuable and – if properly applied – can significantly benefit an organization on both strategic and tactical levels, leaning into proactive (versus reactive) territory.
Maximizing the Benefits of Threat Intelligence
Optimizing integration of the 5 W’s and 1 H into CND operations allows an organization to maximize the benefits of its threat intelligence capabilities. Each of these factors augments and further qualifies the others to various degrees. Specifically, answers to “who” and “why” can be extremely useful to a network defender towards additional context on an attack, whether responding to an alert for a proactive network block or identifying the next generation of malware found through automated dynamic analysis or incident forensics. Specifically, these factors support more informed decision-making to find a sweet spot where defenders have enough information backed by actionable context to make the best decisions possible regarding defensive priorities, controls, processes, and activities.
Integrating “who” and “why” into the equation contributes to:
Isolating employed Tactics, Techniques, and Procedures (TTPs)
Detecting and mitigating attacker tools
Assessing actor sophistication and funding
Gauging attacker commitment and persistence
Tracking actively targeted technology, information, and personnel
The broader implications of these gains include:
Refined prioritization of resources (e.g., personnel, assets, funding)
More efficient and effective CND operations (i.e., working smarter, not harder)
Improvement of overall security posture (i.e., increasing the resource cost for an adversary)
Malicious Actor Motivations
At the end of the day, malicious actors are people too. Underlying motivations drive their activities in support of respective objectives. Unit 42 recognizes six top-level motivations:
Cyber Espionage: Patient, persistent and creative computer network exploitation for strategic economic, political and military advantage
Cyber Crime: Extension of traditional criminal activity, focused on personal and financial data theft
Cyber Hacktivism: Activist cyber attacks seeking to influence opinion and / or reputation for specific organizations, affiliations or causes
Cyber Warfare: Cyber operations that alone or in complement to kinetic / physical operations destroy or degrade a target country’s capabilities
Cyber Terrorism: The convergence of cyberspace and terrorism, causing loss of life or severe economic damage
Cyber Mischief: Arbitrary and / or amateur cyber threat “noise” on the Internet
Figure 1. High-level malicious actor motivations
We prepend “Cyber” to each of these not so much due to a fondness for this oft-overused term, but rather as a reminder that these core motivations existed long before their use with regards to computer networks and systems. In short, “cyber” is just another medium over which malicious actors have chosen to achieve their objectives.
An important take-away is that these top-level motivations are not mutually exclusive. Think of them as “hats” an attacker can wear at any given time. In other words, an attacker might wear one or more “hats” for any single attack. As an extension of this view, they can choose to operate based off of multiple motivations across one or more attack campaigns. Additionally, dynamic factors may influence actor motivation for a given attack, such as integration of information gleaned from progressive operations and identification of targets of opportunity. More advanced and/or creative adversaries may actively engage in misdirection and suggest one motivation, when in reality their objectives are based on another.
Although motivations may shift for a single actor, most actors will often employ the same Tactics, Techniques, and Procedures (TTPs); malware and tools; and/or other resources (e.g., infrastructure providers) across all of their operations. This majority will often not stray far from a core set of capabilities and methods. However, the following trends have added to the complexity of identifying malicious actor motivation and establishing attribution:
Success experienced by one malicious actor group in attacking the people, processes, and/or technology of an organization emboldens and inspires others to integrate similar or evolved methods
Adoption and customization of publicly-available malware and tools, shared across many actor motivations and groups
Closed source sharing of malware, tools, and infrastructure
Levels of Attribution
When it comes to the concept of attribution, isolating who is behind a security event or incident, there are potential benefits to keeping track of even the most fundamental characteristics of an attacker. An organization doesn’t need to jump straight in to identifying individuals to benefit from information collected on a malicious actor; in fact, gradually building out attribution capabilities is a more sustainable practice.
Figure 2. Levels of attribution
Attribution can occur at varying granularity and applies to each “hat” an adversary might wear at any given time. The conceptual levels (from least to most granular) behind this idea follow:
High-Level Motivation: Previously described above and typically the easiest level to establish
Qualifiers: Include aspects such as preferred targeting (e.g., industry, affiliation, types of information, etc.), activity sponsorship (i.e., scale and funding), and potential correlation / relationship with other threat actor groups or events (e.g., real world or virtual; security event related or otherwise newsworthy such as politics or legislation)
Group: Includes isolation of TTPs, distinguishing malware and / or tools, attack infrastructure, and degree of cohesion (i.e., formal organization versus self-identifying / collective)
Individual: The most difficult level to establish, especially for advanced / sophisticated adversaries; may include deeper threat intelligence aspects gleaned or leaked for very specific attack operators (e.g., distinguishing “calling cards”, competitor doxing, law enforcement operations)
Bringing It All Together
When viewed holistically in conjunction with other information security activities (e.g., broader risk assessment), even just recognizing a high-level motivation can assist in tailoring defenses accordingly. Tying this concept back to viewing an adversary in the aggregate, each contact with that adversary is an opportunity to further track and refine attribution. Progressively finer granularity of attribution allows for an increasing degree of focus in defensive operations. This in turn reduces the resources required for reactive incident response and gives defenders enough breathing room to expand on proactive defensive measures.
Coming Up…
The next blog for this series will take a closer look at three top-level malicious actor motivations: Cyber Espionage, Cyber Crime, and Cyber Hacktivism.
Sit back and relax. Let us do the information gathering and give you the channel scoop.
We have 6-business days left in Q1. We have countless folks around the globe ready to help you maximize your Q1 close. If you still need help please email your question/request tonextwave@paloaltonetworks.com.
Need a little extra help getting your customer to upgrade from the PA-2000 Series to PA-3000 Series or from the PA-4000 Series to PA-5000 Series? Don’t forget we recently launched the Customer Care Upgrade Program, designed to provide an incentive to help fuel the conversion of our customer install base. Click here to learn more.
Customer success stories are key to accelerating the sales cycle. What if you could easily take a Palo Alto Networks customer testimonial to your next customer meeting? Now you can with our new prevention e-story, which allows you to see and hear from Palo Alto Networks customers. Click here to access the web version of our e-story or to be able to download the e-story to your smartphone or tablet via the Android or Apple App stores.
Looking for that key data point or research fact to help move your customer to close. Our2015Application Usage and Threat Report has new and compelling data. For example, over 40% of email attachments examined by WildFire were found to be malicious. Click hereto access the report and to learn more, including a quick 90 second summary video.
Need help convincing your customer that security is a top priority for today’s executive leadership? Click here to access the Governance of Cybersecurity Report for 2015infographic, which you can quickly share with your customers.
What topics you’d like the scoop on next? Let us know by commenting on this blog.
Frost & Sullivan recently named Palo Alto Networks the recipient for Asia Pacific Technology Innovation Leadership Award for Security.
Held annually in Singapore, the Awards program recognizes best-in-class companies in Asia Pacific. This program has identified many outstanding companies from the automotive, energy, building & environment industries to the healthcare, information communication technologies and logistics sectors in the region.
Palo Alto Networks achievement was evaluated based on market performance indicators and research conducted by Frost & Sullivan’s analysts.
KP Unnikrishan, Marketing Director, Asia Pacific & Japan for Palo Alto Networks was present at the Award ceremony. Do check out some of the photos from the event below!
(Left) Vivek Vaidya, Vice President, Frost & Sullivan presenting the award to KP Unnikrishnan, Marketing Director, Asia Pacific & Japan for Palo Alto Networks (right).
Mobile app creators are often looking for ways to monetize their software. One of the most common ways to do this is by displaying advertisements to users or by offering in-app purchases (IAPs). Mobile monetization platforms create software libraries that authors can embed into their apps to start earning money quickly. We previously highlighted the dangers of installing apps that enable IAPs using SMS messages, as these apps typically have access to all SMS messages sent to the phone.
While not all SMS-based IAP applications steal user data, we recently identified that the Chinese Taomike SDK has begun capturing copies of all messages received by the phone and sending them to a Taomike controlled server. Since August 1, Palo Alto Networks WildFire has captured over 18,000 Android apps that contain this library. These apps are not hosted inside the Google Play store, but are distributed via third party distribution mechanisms in China.
Background
WildFire captures many samples of mobile malware that intercept and upload SMS messages. Most of these are created by malware authors who set up command and control (C2) servers with third party hosting providers and frequently update their locations to avoid detection.
Among these malware we have found many that are created by “mobile monetization” companies who distribute apps that provide little value but have a high cost to the user. These apps are often installed by tricking users into clicking a pop-up, only to find later that a charge has appeared on their phone bill. Antivirus programs typically identify these apps as malware, the topic of this blog is something different and harder to detect.
Taomike is a Chinese company that aims to become the biggest mobile advertisement solution platform in China. They provide an SDK and services to help developers display rich advertisements with a high pay rate. Taomike has not previously been associated with malicious activity, but a recent update to their software added SMS theft functionality. The apps this library is embedded in may be legitimate and have significant functionality, but their developer’s choice to use this library has put them at risk.
Technical Details: SMS Theft
Not all apps that use the Taomike library steal SMS messages. Our analysis indicates that only samples that contain the embedded URL, hxxp://112.126.69.51/2c.php have this functionality. This is the URL to which the software uploads SMS messages, and the IP address belongs to the Taomike API server used by other Taomike services. We have captured around 63,000 Android apps in WildFire that include the Taomike library but only around 18,000 include the SMS theft functionality.
We believe there are different versions of the Taomike SDK and only some of them include SMS uploading behavior. Based on our data, the version that contains the SMS stealing functions is newer and was released around August 2015. Apps that use earlier versions of the library appear to be safe.
The Taomike library is called “zdtpay” and is a component of Taomike’s IAP system.
Because Android apps are required to list the permissions they need in their manifest file, we can see that this library requires both SMS and network related permissions. The library also registers a receiver named com.zdtpay.Rf2b for both the SMS_RECEIVED and BOOT_COMPLETED actions with highest priority of 2147483647.
Figure 1. Registered receiver for SMS_RECEIVED
The registered receiver Rf2b reads SMS messages whenever they arrive. The message body and sender phone number are collected as shown in Figure 2.
Figure 2. SMS body and sender number read
If the device has just booted, it will start the service MySd2e, which then registers a receiver for Rf2b as shown in Figure 3.
Figure 3. MySd2e Service registers receiver for Rf2b
SMS information collected by the receiver is saved in a hashmap with “other” as the key and sent to a method that uploads the message to 112.126.69.51 as shown in Figure 4.
Figure 4. Information uploaded to IP Address used by api.taomike.com
All SMS messages sent to the phone are uploaded, not just those that are relevant to Taomike’s platform. Figure 5 shows a packet capture of a test message upload. The message content is “hey test msg” as circled with dashed red box.
Figure 5. SMS uploaded via HTTP in pcap
The Taomike library makes contact with the following URLs, but only the “2c.php” path is used to capture SMS messages. The rest appear to be used for other parts of the IAP functionality in the library.
We have captured over 18,000 samples that contain the SMS stealing library since August 2015, meaning the number of affected users is considerable. We expect the number of affected apps and users to increase as more developers incorporate the newer version of Taomike library.
The infected apps are not limited to a single developer or third party store as many developers appear use the Taomike library. Some of the infected apps purport to contain or display adult content.
We do not know how Taomike is using the stolen SMS messages, but no library should capture all messages and send them to a system outside the phone. In version 4.4 of Android (KitKat) Google began preventing apps from capturing SMS messages unless they were defined as the “default” SMS app.
Users outside of China and those that only download apps from the official Google Play store are not at risk from this threat.
To protect Palo Alto Networks customers from the Taomike SMS stealer, we’ve made the following protections available:
Palo Alto Networks WildFire will automatically identify and block malicious APK samples containing the SMS stealing Library
Threat Prevention signature 14798 will detect and block the malicious C2 communication, including the SMS upload traffic from Taomike library
Palo Alto Networks AutoFocus users can identify and investigate this threat using theTaomike tag
Conclusion
Even popular third party monetization platforms are not always trustworthy. When developers incorporate the libraries into their apps they need to carefully test them and monitor for any abnormal activities. Identifying monetization and advertising platforms that behave poorly and abuse their users is something that our industry must to do ensure the safety of all mobile devices and their users.
Acknowledgement:
We greatly appreciate the help from Rongbo Shao from Palo Alto Networks in working on the Threat Prevention signature. We would also like to thank Ryan Olson, Benjamin Small, Richar Wartell, and Chris Clark from Palo Alto networks in publishing the discovery.