Current INFOCON status

Follow Us

Showing posts with label Musings. Show all posts
Showing posts with label Musings. Show all posts

Wednesday, February 25, 2015

And the grammy goes to.... "Angler Exploit Kit"



As we look at the trends for February 2015, it becomes apparent that MALWARE attacks are front and center. The concerning item as we dig deeper on reported attacks is that they have a common thread. The majority of distribution appears to be originating from Angler EK, using Adobe Flash vulnerabilities CVE-2015-0310, CVE-2015-0311 and CVE-2015-0313 dropped in numerous ways. Through Malvertising links, through distributed Mobile Android Apps, and through Watering holes and directed links. After infection, the goal is to insert a Bedep Trojan and turn victim into botnet malvertiser, or more commonly reported, establish the Critroni Ransomeware.

Any version of Internet Explorer or Firefox with any version of Windows will get owned if Flash up to 16.0.0.287 (included) is installed and enabled. It is a good idea to disable flash player, use Chrome browser, disable JAVA, avoid use of Android Web APPS, Run EMET 5.1 on IE browsers, Run fully patched MS Windows 7 or 8.1 with a new version of Firefox (33 or newer) or Internet Explorer 11

Thursday, August 22, 2013

Defense Against the Dark Arts; DDoS 101


Getting information about “who” is attacking and their motivations behind the attack are why this site was created, with the intent to help administrators and network defenders proactively take action based upon attacks occurring. As shown in trending reports of this site, groups such as Al Qassam Cyber Fighters, Syrian Electronic Army, or Anonymous have been using DDOS as a weapon to bring attention to the cause de jour. A collection of these reports show complex efforts that combine DDOS with account compromise but using traditional SYN and DNS floods that in many cases have used application layer high volume attacks that can be filtered. These seem to point to the use of tools such as Low Orbit Ion Cannon (LOIC) and rent-a-botnet services, like Zeus and SpyEye. This brings us to the two crucial defense points in attacking the Kill Chain for these types of attacks.

1. Tune your filters. Well-written firewall rules can filter out most traffic from DDOS attacks by LOIC and drop packets from suspect IP ‘s. For a list of current suspect botnet servers (see Harvester IPs on the right side of this blog) this site provides from Project Honeypot. Filtering out UDP and ICMP traffic helps to address LOIC attacks in an efficient way but require working with your ISP to address upstream filtering as dropping packets at your gateway only will still clog your bandwidth from your ISP to your gateway.

2. Consider a dedicated DDOS mitigation appliance. Isolate and remediate attacks with this appliance to cope with volumetric and application methods of this type of attack and use syslogs to identify the source. Firewalls and intrusion prevention systems are critical to the mitigation effort, and DDoS security devices provide an additional layer of defense through specialized technologies that identify and block advanced DoS activity in real-time. Administrators can also configure their on-premise solutions to communicate with cloud scrubbing service providers to enable automated route away during attack. Having a scrubbing service or ‘cleaning provider’ to handle large volumetric attacks can maintain sufficient bandwidth to cope with attacks of large size. When faced with DDoS incidents, an organization needs to consider is the option to route their Internet traffic through a dedicated cloud-based scrubbing provider that can remove malicious packets from the stream and clean network traffic so that DDoS packets are stopped in the cloud and regular business as usual traffic is allowed.

Getting specific reporting about raw log data for clues about these attacks is still a challenge, however there are multiple methods that can be used for presenting a harder target to would-be attackers.

Tuesday, August 20, 2013

Monkey See... Monkey Do


In this month’s trending, readers of this site may have noticed DDoS being used to prevent democracy in Zimbabwe. It goes to show that it is not the direct attack that you must be concerned with but also your critical supporting systems or in this case ISPs.


Also in this months reporting, the continued trend of Monkey-see, monkey-do seems to be in play for Automobile manufacturers.
The industry continues to see overseas websites targeted in defacing type attacks.

Similarly, Law Enforcement Community portals gathered a bit of the same unwanted attention with the latest at time of this post occurring

News organizations continue to see social media based attacks even with the new two factor authentication twitter recently introduced.
Trending continues to show watering hole based attacks as a growing concern.

These types of attacks use an indirect attack method by getting a victim to browse a site that has been compromised and is used to run malicious software against the victim. Clients normally protected by an enterprises infrastructure are subject to attack through business partner portals, vendor sites, and even unsecured wifi hotspots at the local coffee shop they frequent. Defense is reduced to user awareness and the effectiveness of virus signatures on the users PC. (Assuming a zero-day is not used) Plugging this newly infected box back into the enterprise now introduces a foothold for the would-be attacker effectively bypassing direct filtering and leading to a bad day at the office.

One has to wonder with all the money being spent on front door protection mechanisms (Enterprise filtering software), why more importance is not placed on virtualized machines that are used to browse the unfriendly web.

Monday, July 22, 2013

Whack-a-mole defense


One of my pet peeves with current defense methodology employed by defenders is the continued approach to a problem set that has shifted to a new paradigm. We treat IT defense like healthcare. Continuing to put all effort compliance based defense of general health checkups that reduces our practice to checking our temperature and blood pressure while we are hemorrhaging. We are bleeding to death and focusing on symptoms verses attacking the root cause. Sole focus on components such as dynamic DNS hostnames or phishing attempts with a Remote Access Tool (RAT) like Poison Ivy, leads to a whack-a-mole approach to defense. Whack - block a C2 IP or domain at the gateway. Whack-filter for malware signatures on a workstation. Whack- harden assets with latest compliance requirements. Monitoring of bad IPs and domains are necessary for preventative healthcare but triaging the hemorrhage falls short and puts defense in jeopardy of bleeding out. Playing defense in this paradigm is reactive. Breaking the vicious cycle of Whack-a-Mole requires changing the approach we use in combating adversaries. To break from this cycle, an organization must utilize threat analysis to proactively anticipate and monitor an adversary. How has an adversary attacked in the past? Which adversaries must I be concerned with? What attributes can I focus on to identify an attack? All these come into play as we then fine tune our existing defenses to specific targets. Identification of our threat data sets closes the GAP for specific adversaries of concern and then includes a true threat based defense posture for our networks. Stepping off of soap box….

Wednesday, July 10, 2013

Constructing a "Kill Chain" for Threat-Based Defense


Cyberattacks from various threats are growing in scope and increasing in frequency as shown in AV vendor threat reports such as Symantec’s Global Threat Report. Current defensive strategies of mitigating prolonged and determined attackers leveraging advanced techniques fall short by relying on a patch and signatures approach. Most organizations continue to focus on defending against vulnerabilities and zero-day exploits by relying on commercial security products to block bad sites and software and by patching systems to correct vulnerabilities in installed software. Even in instances where browser or application plug-ins are fully hardened and patched, a GAP persists within a vendor vulnerability lifecycle (e.g. discovery, disclosure, exploit, patch-date) between when mitigation patches are available, and when a patch is deployed within an organization (e.g. testing, deployment, validation) vulnerability lifecycle.

While patching is still necessary, these approaches do not attack the root cause or reduce the threat, rather they counter the vulnerabilities discovered. Threat-based defense maximizes the knowledge gained from single, often disparate attacks and related events, and uses that knowledge to reduce the likelihood of success of future attacks. Cyber threat intelligence analysis, strives to better positioning cyber defenders to prevent or quickly contain cyber intrusions that occur by the attack lifecycle model built upon the kill chain framework. Defenders collect and analyze data and work to correlate it against the stages of an attack.

Threat based computer network defense is a risk management strategy that addresses the threat component of risk, incorporating analysis of adversaries, their capabilities, objectives, doctrine and limitations and deconstructs attacks into various stages used to target and engage an adversary to create desired effects.

Kill Chain=
Reconnaissance
Weaponization
Delivery
Exploitation
Installation
C2
Actions Objective

By removing any one of these paths, an attacker is unable to execute their objective. Further, a defender is better equipped to define indicators for events of concern. While not all encompassing, the chart below provides an example.


Defending against these paths is constructed similarly and gives insight into a defender’s ability to detect and prevent threat activity within a given category.


As stated above, Patching and signatures remains a necessary component. Using threat based network defense in addition to traditional vulnerability management adds great depth to your defense practices.

Monday, May 20, 2013

Breaking down threat data sets




Placing statistics in front of threat events can be cool but practically useless information. In viewing threat data, one must analyze against specific organizational relevance. As an example, I will utilize data posted from Aprils Monthly report.

Detected Attacks
Intensity
Capability to Defend
Capability to Detect
Apache exploit kit
1


backdoor
1


coldfusion zeroday
1


credit card fraud
1


Data Breach
1


Data Spill
1


DNS poisoning
1


Insider
1


Mobile Malware
1


brute force
2


WEB Defacement
2


Targeted Attack
3


defacement
4


DNS Hijack
5


social Media Hijack
12


SQLi
15


DDoS
23




As noted, the ability to defend and detect are organizational specific. These variables ask you the reader to fill in the blanks. What is your organizations ability to detect a SQLI attack? How are you postured to defend against it? These become useful when attempting to quantify acquisition of new technology for an organization that may be deficient in these various areas.

Another important data set may be to consider industries being attacked.

Targets of Frequency
Intensity
Relevance to Organization Business Practices
Relevance to Organization Business Operations
IND: Energy
1


IND: telco
1


IND: web Hosting
1


ORG: Church
1


ORG: software
1


ORG: sports
1


ORG: Political Party
1


Roadsign
1


IND: automotive
2


IND: online games
2


IND: Retail
2


LEC
2


ORG: Non-Profit
2


Education
3


IND: Computer Software
3


Individual
3


IND: online services
4


news
8


IND: Internet Services
11


GOV
18


Financial
24




Defining relevance to an organization considering business practices and resources provide focus to not only the organization measured, but perhaps business partners and supply chains. As in the example above, you the reader must apply consideration as to which are important to consideration in your business.  Really interesting is further dissection.
Example: If I am an organization that provides Financial Services… In the month of April 24 attacks were captured. Of these attacks, 82% were DDoS, 14% SQLi, and 4% DNS HiJacking. Additionally, 67% where attributed to Hacktivism with the remainder attributed to cybercrime. The threat actor Izz ad din al-qassam cyber fighters associated with the vast majority of these were the actor report was attributed.

As a network defender, given this trend, looking into my financial organizations ability to defend against DDoS begins to look critical. Measuring my current ability to protect and defend against known DDoS methods gives a leg up in the battle to current vectors and threats. As always, if you have any questions or would like data sets for something specific, please feel free to post your questions. Cheers