Here Are 5 Things Your Cybersecurity Team Must Do

Cybersecurity is a hot topic these days. Corporate breaches in the headlines have turned hackers into the new super villains. “Revenge of the Nerds” is alive and well, and hacking is their super power. It’s no wonder that every customer meeting I attend starts with a concerned voice: “what can we do to protect ourselves and our customers” from these new super villains? Secretly, they’re wishing to hear about a shiny new product that will solve all of their security problems, providing new protection for every new attack.

We all want our data and networks to be secure, with no effort or risk, but there are no shortcuts to success in the territory of cybersecurity.

As surprising as it may sound, these villains’ new tactics are not as new as you might think; in fact, many of the so-called new attacks could have been prevented by correctly using existing security technologies as part of an end-to-end cybersecurity plan.

What is the plan? Think like a hacker.

  1. Change the way you approach protection, what would you steal?

Start by thinking about what you need to protect, not about protecting the road to it. In other words, build protection to match your data and your processes, not just the network architecture. Learn about your business’s unique patterns of people-data interaction; what and how it needs to be protected, who needs access to it and when, and what is the expected interaction they will have with the data. Only then can you start building your data-centric security.

  1. Look for the gaps – what is the easiest way to get your data?

All networks are built to provide a service that is dependent on multiple systems both internally and externally. Hackers look for gaps, the path of least resistance. Why break down the front door, if you can easily get in through an open window? Your security solution must prevent as much as possible across multiple phases of the cyberattack lifecycle.

2.1 When you think about gaps, look at the borders of your systems and processes internally and externally, as gaps have more to do with interoperability and less with physical objects (Internet of Things). Work to close those gaps and think outside of the security box. Your inventory list should include computing, storage and network equipment.

2.2 The human factor: social engineering attacks are rising, with high success rates. Training and education is the key to defending on this front. Adding tools and scripts to catch users’ mistakes can help reduce the risk.

  1. Uncover deception – what and whom do you trust?

Your answer should be nothing and no one. Look to uncover and inspect as many compression and encryption protocols as possible, making sure that the data entering your network is what you expect it to be, and from whom you expect it to arrive. You must detect new unknown attack components across all traffic.

  1. Look holistically, what are your blind spots?

As you plan to add new products or processes, strive to reduce complexity and keep it simple: simple to manage, simple to monitor, simple to update, and simple to control. Any blind spot or unattended system can and will be used against you, especially in multi-step attacks. Keeping it simple is probably the most challenging aspect of this process. It is a daunting task. As you look under the hood of many customers’ networks, most have been built over long periods of time with highly heterogeneous platforms, languages and tools. Remember that you have more than one environment to manage, as mobile devices and public/hybrid cloud infrastructure are two of the biggest attack vectors. Your solution should detect new, unknown attacks across all traffic.

  1. Keep getting better – how can you be even more secure tomorrow?

New security protections can become outdated quickly, if they are not attended to and updated regularly. Threats are constantly changing, requiring continuous monitoring, tracking and assessments in order to keep your security up to date. Timing is everything. You must be able to turn detection data into prevention very quickly.

Sun Tzu and his “The Art of War” guidelines are more relevant than ever. In order to beat cybercriminals, you need to understand the battlefield, know the enemy and know yourself. Build a security ecosystem designed to fit your unique data mix and data consumption patterns, predict the enemies’ next move, counter it, and strive to be one step ahead of them.

Learn more

[Palo Alto Networks Blog]

Introducing the Definitive Cybersecurity Buyer’s Guide

Architecting a cybersecurity solution that dynamically adapts to constant change is crucial. It can be difficult for even the most seasoned cybersecurity professionals to figure out where to start when evaluating solutions.

That’s why we’ve prepared the definitive Cybersecurity Buyer’s Guide, complete with recommended criteria for choosing a cybersecurity solution that can block cyber attacks and protect allowed traffic from known and unknown threats.

The Cybersecurity Buyer’s Guide offers guidance on how to effectively evaluate cybersecurity solutions through the RFP process – to help you determine and prioritize what 10 things your cybersecurity solution must do.

Download the buyer’s guide today to find out everything you need to know to make an informed cybersecurity decision.

Chad Berndtson

[Palo Alto Networks Blog]

80% of Healthcare Executives Report Compromised IT Systems Due to Cyberattacks

“Four-fifths of executives at healthcare providers and payers say their information technology has been compromised by cyber-attacks,” according to a survey of healthcare executives conducted by KPMG.  This was the most compelling finding from the survey, which polled 223 healthcare executives in the U.S., covering both for-profit (56%) and non-profit (44%), as well as payers and providers.

What this means is that 20 percent of responders claimed none of their IT systems had been compromised in the past two years.  That is quite a bold claim!  All of the responders had revenues of at least $500 million (70% had revenues over $1 billion), so they must have quite a few endpoints to manage. 

From my perspective, having led a security operations team at a large hospital network, it’s hard to believe they were able to fend off all malware attacks for two years. No one in their organization fell prey to the phishing email campaigns that enticed users to listen to their “Voicemail Recording.wav.exe”? I highly doubt that.

The answer is revealed in another finding of the survey:

44 percent of responders said their organization tracked between 1 and 50 cyberthreat attempts in the last 12 months. “This is indicative of [healthcare] organizations not understanding, tracking, reporting and managing threats effectively.”

So, the 20 percent of responders who claimed that none of their IT systems had been compromised in the past two years must be a subset of this group who do not have the visibility into cyberthreats to detect them in the first place.  This makes more sense.  Many healthcare organizations don’t have the capability to detect or prevent malware and exploits in real time.

There are many best practices to consider in the effective protection of today’s hospital networks, which can help prevent threats to connected medical devices, patient data, and overall patient care, including being able to:

  • Maintain visibility, effective control, and the enablement of applications and activity to reduce the threat footprint and minimize needless bandwidth consumption.
  • Virtually segment your network to prevent the movement of malware through the network using a Zero Trust approach.
  • Protect and defend systems at all places in the network, across all network traffic on endpoints, in data centers, in remote locations, and at major Internet gateways.
  • Maintain advanced malware detection to identify and prevent zero-day as well as known malware attacks.
  • Include off-network endpoint protection and ongoing defense, regardless of location or device.
  • Ensure timely reporting to enable IT, cybersecurity and intelligence professionals to coordinate actions.
  • Ensure immediate and automatic sharing and distribution of threat intelligence between systems.

Read more about how the Palo Alto Networks next-generation security platform can help your healthcare organization. Stay tuned for a soon-to-be-released healthcare reference architecture that will elaborate on these security principles in more detail, and how best to apply them, using Palo Alto Networks next-generation security platform.

[Palo Alto Networks Blog]

KeyRaider iOS Malware: How to Keep Yourself Safe

Earlier this week we published an analysis of KeyRaider, which is an iOS malware family and a reminder of the risks users take when they choose to jailbreak their mobile devices.

Attackers used KeyRaider malware to steal more than 225,000 Apple accounts. KeyRaider targeted only jailbroken Apple devices, primarily through Chinese websites and apps that provide software for those jailbroken phones.

The best way to keep a mobile device safe is to keep it up to date with the latest software updates. That also means not jailbreaking your phone in the first place, as today there aren’t any Cydia repositories that perform strict security checks on apps or the tweaks used to change them.

But if your device is already jailbroken, what steps can you take to protect it against KeyRaider?

Determine if your account was stolen. WeipTech has provided a service on their websitehttp://www.weiptech.org/ for potential victims to query whether their Apple account was stolen. But this is not comprehensive; WeipTech was only able to recover around half of stolen accounts before the attacker fixed the vulnerability.

Determine if your iOS device was infected.

  1. Install openssh server through Cydia
  2. Connect to the device through SSH
  3. Go to /Library/MobileSubstrate/DynamicLibraries/, and grep for these strings to all files under this directory:
    1. wushidou
    2. gotoip4
    3. bamu
    4. getHanzi

Delete the malware. If any dylib file contains any one of these strings, we urge you to delete it and delete the plist file with the same filename, then reboot the device.

Change your password. We suggest all affected users change their Apple account password after removing the malware, and enable two-factor verifications for Apple IDs.

What should you do if your phone is being held for ransom?

In this case, your best chance of recovering your phone is if you already have OpenSSH installed on the device. If so, log in and delete the malware following the steps above. If you don’t already have Open SSH installed, it’s going to be much more challenging to get around this particular ransomware. The standard Apple password reset and rescue are not going to function properly with this attack.

Beyond KeyRaider, what steps can a user with a jailbroken phone take to protect themselves?

Jailbreaking an iOS device removes a lot of the protection that Apple has put in place to prevent malware infections. Once those are gone, the responsibility is really on the user to avoid getting infected. Don’t install pirated software and only install software from sources you trust. Even then, your device is at risk so you should avoid using it for sensitive transactions like online banking.

For full details on KeyRaider, check out this week’s research blog post.

[Palo Alto Networks Blog]

Watch: Redefining Endpoint Security

With cyberattacks on the rise, traditional endpoint protection technologies simply can’t keep up with the rapidly evolving threat landscape. Watch this video to understand how Traps can prevent the most sophisticated known — and unknown — attacks and how to safeguard your organization using the full power of Palo Alto Networks next-generation security platform.

For more

[Palo Alto Networks Blog]

English
Exit mobile version