Showing posts with label Cyber Kill Chain. Show all posts
Showing posts with label Cyber Kill Chain. Show all posts

Wednesday, 7 October 2015

How to minimise the risks of LinkedIn - The Hackers Research Tool [Link - SC Magazine]

I'm very proud the article I wrote was used by SC Magazine.

http://www.scmagazineuk.com/how-to-minimise-the-risks-of-linkedin--the-hackers-research-tool/article/443248/

===============

Staff need ongoing training in defending against the latest threats - which currently includes LinkedIn says Andrew Tang, service director, security at MTI Technology

LinkedIn, the social media platform, is proving to be a very useful networking tool for business professionals, with a growing database of approximately 380 million users worldwide. The site encourages members to freely share their CV, not just with their network but publically online.

It is also becoming an attractive platform for organised crime gangs.  Recently, there have been several cases where hackers have used information gathered from LinkedIn to plan targeted attacks on companies.

Hackers have been found posing as large corporations on the site to entice unsuspecting executives to divulge useful information. Sometimes the hackers don't even need to lure victims by posing as large corporations, they can gather enough personal information from public profiles to scam money or access sensitive corporate data.

These forms of attacks are proving to be a headache for security professionals. Despite having the best tools and processes in place, it is particularly hard to protect information that sits outside of the company network. It can also take months or even years to find the leak.

Risky business

Most employees are now well aware of the security risks associated with revealing too much personal information on social media sites such as Facebook. However, they often don't realise that revealing corporate information on LinkedIn can be equally risky to businesses.

LinkedIn pages can provide a considerable level of detail to potential cyber attackers: names, job titles, email addresses, partnering organisations, upcoming projects, and even hobbies and interests. At first glance, this information might seem relatively trivial but it can form part of the ‘cyber kill chain' and lead to malicious attacks.

LinkedIn informs the ‘plan of attack'. Employee and company profile pages can help hackers identify a target; source the names of executives and department heads; learn the email structure; as well as the names of affiliated companies. This leaves organisations vulnerable to a range of cyber-attacks including spear phishing.

Human error

Most worryingly perhaps, this issue isn't one that can be simply remedied with protective software. No technical solution can prevent an attacker from conducting an Internet search.

LinkedIn and other social media profiles are often among the first to appear in a list of search engine hits. Once the attacker has deployed the malicious software, cajoled an employee and gained remote access, the key goal is theft, whether the gain is more information, financial or data theft.

Education is the answer

As our virtual presence continues to grow, organisations need to make all employees aware of the potential risks of company details falling into the wrong hands. In order to mitigate the risks of social media sites, without blocking them, which will only frustrate employees, organisations must establish a clear security policy.

To safeguard company information and data, enterprises should educate employees about attending more closely to what they wish to make visible to whom.

If employees are informed then they are far more likely to be consciously aware of the risks as they go about their daily duties and knowing the rational, they are less likely to breach the policy.

The world of IT and security is certainly not static and training should not be a one off activity for new employees. Organisations should consider a continuing programme of education, updating the employees on new threats and breaches on a regular basis.

As more of our private lives are made public and readily available on the Internet, education becomes the vital component.

Monday, 28 September 2015

LinkedIn – the hacker’s research tool [Link - MTI Bytes]

Here is a repost of a piece I wrote for our work blog: http://www.mtibytes.com/post/LinkedIn-the-hackers-research-tool

=================

As of July 2015, LinkedIn has approximately 380 million users worldwide, a number that is continuing to grow. The social media platform is very useful for networking in the business world. It invites users to share their online CV with other industry professionals and establish contacts, publish industry commentary, and research potential employers or candidates.

Reconnaissance
The security risks of sharing personal details on other social media platforms like Facebook have been well documented, but for enterprises, LinkedIn can be equally dangerous. LinkedIn pages can provide a considerable level of detail to potential cyber attackers: names, job titles, email addresses, partnering organisations, upcoming projects, and even hobbies and interests. At first glance, this information might seem relatively trivial, but it forms part of the ‘cyber kill chain’ and can lead to malicious attacks.

For hackers, LinkedIn can inform the ‘plan of attack’. Employee and company profile pages can help hackers identify a target; source the names of executives and department heads; and learn the email structure; as well as the names of affiliated companies.

This leaves organisations vulnerable to a range of cyber attacks. One example is spear phishing: a targeted person receives an email inviting them to access a link, which initiates the installation of malicious software.

Socially engineered access
Emails from known sources (a colleague, for example) and information about hobbies, can instill confidence in the targeted individuals, making them more likely to click on the link.

The name drop of the company CEO could create a false air of familiarity, which might spur someone to act hastily and neglect to follow the correct channels. It’s not hard to imagine that an IT helpdesk might grant a ‘known employee’ remote access in response to a pleading call or email to finish time-sensitive work on a Friday afternoon.

This might provide the hacker with the name, job title, and email address of a company employee, all of which are readily accessible on LinkedIn. In return, he stands to make financial gains, steal data, or simply obtain secure company information.

Human error
Most worryingly perhaps is this issue isn’t one that can be simply remedied with protective software. No technical solution can prevent an attacker from conducting an Internet search. LinkedIn and other social media profiles are often among the first to appear in a list of search engine hits. Once the attacker has deployed the malicious software, cajoled an employee, or gained remote access, the key goal is theft, whether for more information, financial remuneration, or data.

Education is the answer
As our virtual presence continues to grow, there needs to be more awareness made inside organisations about the potential risks of basic company details falling into the wrong hands. To safeguard company information and data, enterprises should attend more closely to what they wish to make visible to whom.

As more of our private lives are made public and readily available on the Internet, education becomes the vital component. Organisations should be looking to provide this level of training to all employees, or risk the consequences.

Wednesday, 22 July 2015

Morality vs Criminality: Ashley Madison Hack

As you may have read in the press, that the Ashley Madison website was hacked.   What's the big deal, you may think, it's another compromised website.  Ashley Madison,as it says on their website, "is the online personals & dating destination for casual encounters, married dating, discreet encounters and extramarital affairs", with the tagline is "Life is short, have an affair".  There are 37 million users, across over 50 countries, with around 1.2 million of whom live in the UK.


What was lost?

Personal data that was lost includes, names, postal addresses, credit card numbers and sexual fantasies.  Made worse is the organisation charged a $19 fee to carry out a "full delete" on user accounts, which appears to have not been the case.


Who did it?

The hackers taking responsibility are the Impact Team, where the database was comprehensively stolen.  In a recent article from The Guardian, it states that it was an insider threat, where the compromise was carried out by someone who had access to the systems, but was not an employee, highlighting the need for control on third party access.


Morality?

I've read a few comments that said that people should not be using these sorts of sites.  A crime has been committed in the database being stolen, but we are judging the victim for the crime.  Who is to blame if your house is broken into?  The criminal or the victim?  


Advice

Be aware that there is no safe place on the internet.  The internet is effectively a public place, where a majority of people will have access.  You are entrusting a third party to look after your data, so in this case, a secure and unique password would not have helped the users.

The fault here lies with Ashley Madison.  Some security technologies would have prevented this from happening:  

  • A Privileged Account Security solution would have prevented the third party from recycling their access to the system, and with some solutions recorded the sessions of compromise.
  • A database encryption solution would have prevented the data from being used.
  • A Data Leak Prevention (DLP) solution would have prevented the data from exfiltrating the organisation.
  • A Security Analytics solution would have seen and prevented this.
I have mentioned the Cyber Kill Chain in the past, and these solutions would have stopped the compromise, and the data leaving the organisation.

For me, this is not a case about morality, but we allow that to cloud our thoughts and allow a criminal act to be downplayed because of it.  This is a crime, but worse a crime that could have been prevented.  The right solutions configured correctly, supported by polices and procedures would have prevented this hack from happening.

Monday, 29 June 2015

Duqu 2.0

Introduction
On the 9th June 2015, Kaspersky announced to the world that they had been a victim of a cyber attack that targeted their own corporate network.  If an organisation like Kaspersky can become a victim of a cyber attack of this magnitude, all organisations can potentially become victims.  Data is the lifeblood of any organisation and the loss of critical data could mean the demise of that organisation.

Analysis
Kaspersky, a Moscow-based security company, disclosed details of a cyber attack that they had been victim of.  After its discovery, Kaspersky launched an extensive investigation, gathering the facts and sharing the findings with the world.  The attack was dubbed Duqu 2.0, due to its similarity to an attack known as Duqu which was first spotted in 2011.  The use of Duqu and Duqu 2.0 is attributed to nation-state sponsored attacks, in this case trying to discover intellectual property, such as research into advanced persistent threats (APTs).

Cyber Kill Chain
The comprehensive nature of the attack meant it was highly likely to succeed.   Lockheed-Martin’s Cyber Kill Chain breaks down a cyber attack into seven steps.  Some attacks may only use some of these steps, while others will repeat them when attacking multiple systems prior to attacking the intended target.  The Duqu 2.0 attack not only followed the kill chain, but there were also elements repeated to make the attack more covert.

Reconnaissance/Weaponisation/Delivery /Exploitation
It is believed that an employee in one of the APAC offices was a target of a spear-phishing email, with a lure and redirect to a malicious dropper file that exploited a specific unpatched zero day vulnerability.  The attack was thorough, ensuring emails and browser history were cleared of all traces of the compromise.  Kaspersky confirm the machine was fully patched leading to the assumption of a zero day exploitation.

Installation/Weaponisation/Delivery/Exploitation/Installation
Once on the network, the attacker was able to escalate unprivileged credentials to that of the Windows domain administrator using another zero day vulnerability. The attacker was then able to explore the network by moving laterally and deciding which machines to compromise.  Microsoft Windows Installer Packages were used to deploy Duqu 2.0 into the network.  The attack software runs in memory, where most modern production servers have high uptimes and are rarely power cycled.  Had the machine been power cycled, it would have quickly been re-infected.

Command and Control/Action on Objectives
Once the desired information was found by the attacker, the data was exfiltrated out of the network.  Kaspersky have reported that non-critical information was taken as part of the attack.

Prevention
By analysing the sequence of the attack, a number of mitigating controls could be used to prevent the Duqu 2.0 and similar attacks.  Many of these elements may have been caught in isolation, but the prevention of the attack would need a more integrated approach to security.  The end goal for the attacker is to steal data.

Spear-phishing
The entry point to the network was to specifically target an individual or small group of people.  This highlights the need for user education at every level and every department of an organisation.  In conjunction with education, an email security gateway with sandboxing technology may have prevented Duqu 2.0 from entering the network.

Web Access
An exploit kit would have been introduced to the network to check for unpatched and zero day vulnerabilities.  This was delivered through the web vector as a malicious link or a compromised site with a malicious file.  The presence of this could have been detected with a web security gateway, ideally with a sandboxing solution to check the functionality of the file.

Zero Day vulnerabilities
The patching of operating systems, browsers, third party software and plug-in is highly recommended, although this will not prevent zero day vulnerabilities from being exploited.  The removal of non-essential software from a computer will help reduce the surface area of attack, and the use of host based firewalls and host intrusion protection system can help.

Administrative Credentials
The administrative credentials within the network were compromised, which allowed the lateral movement within the network.  This is a shortcoming of using static passwords for a period of time before being cycled; giving a window of exposure if the password is compromised.  A privileged access management solution, would cycle the administrative credentials after each use and video record each session.  This would give a greater level of security to the credentials and traceability on what each administrative session had executed.

Lateral Movement
Many networks are segmented using VLANs, which offer limited security.  Micro-segmentation would provide protection to the servers or groups of servers, with security controls to prevent the East-West movement within a network.  When coupled with a security analytics engine, this would give context to the abnormal traffic within the network.

Resident in memory
As Duqu 2.0 resides in memory, there are a number of mitigations that could have prevented this.  The simple act of rebooting the server would have cleared the application from memory, although this can be difficult to routinely perform on critical production servers.  Whitelisting application control solutions would have stopped the MSI from executing into memory by simply preventing the unknown application from running. 

Data Exfiltration
A gateway data loss prevention solution would have seen the data leaving the network.  It is especially important that the solution is able to analyse the data being drip fed out, piecing together many smaller exfiltrations to gain visibility of the overall loss and give context to the data leaving.

The Future
The Duqu 2.0 attack follows the seven stage cyber kill chain. Preventing the attack at any one of those steps would have ultimately stopped data loss.  Kaspersky caught the attack before critical data loss had occurred.  As attacks such as these are published it raises the profile for both vendors and attackers.  These techniques could still be used against any organisation, with the ultimate goal of stealing data.

To prevent these attacks, security vendors will need to take a more holistic view of security working with other vendors to specialise in the areas they don’t.  We see this collaborative working with technical partnerships by vendors, and with OEM agreements in the supply point solutions.  Alternatively security vendors need to take a more comprehensive approach tackling all the stages of the kill chain with integrated solutions.

The solutions need to become less reactive to the known and more proactive to the unknown.  There needs to be more focus on how security solutions deal with anomalies, where prevention and remediation is far more important than notification.  With a security staff shortage and the gap growing year on year, the vendors have the supply security intelligence in their solutions. The future for these solutions is not to supply data logs and notifications, but to provide context and proactive remediation through intelligent analytics.

In the short term, ensure endpoint security solutions are running the latest versions, with the latest updates and the recommended features are enable.  There needs to be a focus on running supported operating systems, with the latest patches, and to ensure that third party software and plugs-ins are updated as well.  Any web and email security solutions need to be updated and the security policies regularly reviewed.  The final piece is user education, which should be ongoing process, where the learning is engaging, flexible and relevant.

As these attacks become more mainstream where vertical and size no longer matter, look to future solutions that are able to tackle all stages of the kill chain, providing intelligence and context; and ultimately prevent the organisation’s data from entering the wrong hands.

Thursday, 25 September 2014

Securing the virtual you

I blogged recently about the Cyber Kill Chain where I look at each of the steps.  Many of the steps can be dealt with using technology, except one stage, the reconnaissance stage.

Who's the target?

As the bad guys need to be more specific in targeting individuals, research is the key.  Knowing who someone works for, who their friends are, their hobbies and pastimes, they all help construction a picture of the target.  If you know your target, you can try to exploit it by sending emails with specific topics and links to lure your target to click on a link which can compromise their machine.

Spear-Phishing

People who are normally target to a "spear-phishing" (if phishing is a wide indiscriminate attack to get users details, spear phishing is targeting a very group or an individual person) are people who will have more rights than a typical user.  Why?  Well I mentioned in previous posts that a compromise will involve administrative credentials 100% of the time.  So the target will often be members of the executive team (who often have more rights than a user) or members of the IT team.

Research/Googling?

How would I find out more about someone?  Use Google (other internet search engines are available) and search for them.  As an example, I'll use me and see what's available out there...


LinkedIn

The second hit is for LinkedIn and most of the posts that follow are for a Singaporean racing driver (I'll give you a hint, I'm not a racing driver!).  For those who are unfamiliar with LinkedIn, it's a social networking site for "professionals" effectively giving a CV online.

So following the link, it takes me to a number of people called Andrew or Andy Tang internationally, but LinkedIn handily gives a link at the top to refine this list to Andrew or Andy Tangs based in the United Kingdom.  



So if you knew who I worked for (MTI by the way), then you'd know to click on the top link.  If you didn't, then you probably won't target me!  So now I can see a public profile of Andrew Tang, and even without a LinkedIn account I can gather a lot of information.



Now you know who I work for and have worked for, along with people who I must be linked with in some fashion, as people looking for my profile have also looked at these profiles.  That already creates links with people or organisations I would potentially trust, or would not find odd if I received a communication from them.  Additional information such as company websites and blogs may also be there and give more clues.

Google+/Blogger

Following out to the blog, it can be seen that the URL to my blog (that you're reading by the way, thank you) is http://blog.andytang.com which gives us similar information to the LinkedIn profile, as well as a link to my public LinkedIn profile.  There is also a link to my Google+ profile as the blog use Blogger which is a Google company.  

Twitter

Information we already have like company and LinkedIn details.  There is a link to Twitter, along with some people who have put me in their circles.  Again, more people that I would not find odd if I received communications from them.  Let's follow the link to Twitter...


No real insights here, except that I say I live in Surrey.  That may have been assumed as current and previous employers are in Surrey as well.  

WhoIs?

Maybe time to get a little cleverer!  We know the domain I own andytang.com, so there must be some information around that domain.  A WhoIs will find out who has registered this domain:


No real information here either!  

Facebook

I've tried looking for a Facebook page, but struggle to find myself, even if I spread the net wider with more information than can be found above.  None of the profiles below are me, but then I have locked down my privacy settings.


I thought I'd try a different way to get to the profile.  I know who Andrew Tang works for and I know they have a Facebook page.  Having a quick look through would show up any posts Andrew Tang may have liked, and from there I can access the profile and gather more information:


This shows my Facebook privacy settings work!

Corporate Website

Most corporate websites have a who's who on it, but I'm not currently on it.  Although if I were, it would probably show a photograph and a brief about me, which  could uncover hobbies or pastimes.

So what?

A lot of information can be uncovered very quickly about people.  If I were a target to an attack, I would hope that my privacy settings and IT awareness would help.  If the communication was more targeted from people I know or around a hobby or pastime, I may well click on them.

Our virtual presence keeps growing, but do we keep tabs on what's out there.  I did the above with no special access or logins.  The only site that needed an account was Facebook, but the rest is there to be discovered.

Take the time to secure and protect your information, and make sure there's not too much out there.

Googling yourself is no longer about vanity, it's about security!

Monday, 15 September 2014

Lockheed Martin Cyber Kill Chain

When I first saw the the Cyber Kill Chain, it wasn't actually the Cyber Kill Chain.  What I saw was the Websense 7 Stages of Advanced Threats.

The Lockheed Martin Cyber Kill Chain states there are seven stages of a cyber attack, and your organisation can be protected, if the chain is stopped at any of the stages.  The higher up the chain it can be stopped, the better the protection to your network.

The stages are as follows:

  1. Reconnaissance
  2. Weaponise
  3. Deliver
  4. Exploit
  5. Install
  6. Command & Control
  7. Act on Objectives

Websense 7 Stages of Advanced Threats


Websense have taken the phases above, and mapped them to the Websense 7 Stages of Advanced Threats.

Recon

Prior to a breach, some research (or recon) will need to be done.  This research will include the company and its people.  By way of checking yourself, a quick internet search of your organisation or you will bring up a lot of information.  The use of LinkedIn helps pinpoint people to organisations, as well as organisations that work together.  While Facebook and Twitter will help with hobbies and out of work activities.

Lure

If hobbies or working relationships are known, the lure containing information regarding hobbies or an organisation you work with will be of interest.  The lures can use email and social media from seemingly trusted sources.

Redirect

Emails and social media can contain links, which then redirect the target, scan a system or prompt for software to be installed.

Exploit Kit

The links can be for compromised websites, where an exploit kit located there can scan the users computer for vulnerabilities.  The exploit kit is effectively looking for a path into the computer.

Dropper File

The dropper file is the malware that is used to infect the users computer.  The software when executed can immediate start gathering data, it can sit dormant for a period of time to mask it's true intentions, or may be used to deliver malware in the future.

Call Home

The malware can then call home, contacting a Command & Control server to receive instructions, or additional software and tools.

Data Theft

What as the point of all of this effort?  To steal data!

Stopping the Attack


Not all attacks will contain will seven stages.  Some attacks will only involve three of these stages, but it highlights the sooner in the chain the attack is prevented, the less damage that will be done to the network.

Working in a technical environment, I see a number of solutions that only focus on some of these stages, which is no good if the attack skips those steps.  I have worked with the Websense solutions for over seven years, and see that their solutions can prevent attack at all levels (expect the "Recon", but no technical solution can prevent an attacker from carrying out an internet search on people or organisations!)

MTI is a Websense Platinum Partner in the UK, and can help secure your network against cyber attacks.

Compromise the security (looking back at the RSA breach)

I had an interesting conversation with family this weekend, where I was talking about securing iCloud using two-step verification.  Someone mentioned that with personal data it's not really important, but from a work perspective (they use to work for a large US company based globally) that RSA tokens protected them.

Back in 2011, RSA was compromised and is pretty much well documented.  As a summary, here's happened:

  • Targeted emails were sent to the HR team at RSA
  • Prior to the compromise only 11 emails were sent, but all of them were caught by the SPAM filtering solution
  • One of these emails were released to the HR team as it looked important
  • When the attachment was opened, it installed malware onto the computer exploiting a vulnerability in an Adobe product
  • With this access, the hackers were able to pivot onto other servers, eventually getting to the token database, allowing them to generate the "secret" code of a token with a specific serial number
This breach is said to have cost RSA $66 million, but beyond the actual costs, there reputation of RSA as a security vendor was brought into question.  It seems that this wasn't the end goal of the hackers, but rather the start to something much more spectacular!

Lockheed Martin is supplies military and aerospace technology to a number of organisations, including the Pentagon.  This in itself would make Lockheed Martin an obvious target for attackers, but as an organisation concerned about security, they used RSA tokens to protect their network.

It would seem that Lockheed Martin were potentially victim to a state-sponsored attack from the Chinese government.  Knowing that the target organisation were protected with RSA tokens, make it difficult to compromise them.  Much easier would be have access to the RSA tokens, or at least the codes it would generate.

I appreciate that it is speculation that the Chinese nation state were behind the attack, but I would suggest that you do an internet search for two images and play "spot the difference":
  • Lockheed Martin F-22
  • Chengdu J-20
After the breach, Lockheed Martin created the Cyber Kill Chain, which shows the various steps of a compromise to your network.  Many security vendors have taken this methodology on board, and their solutions can be seen to help during certain stages of an attack.  I'll blog about this in more detail soon.

Wednesday, 21 May 2014

eBay compromised...

Today, eBay made the news as it was announced that their database had been compromised.  Personal information had been stolen, including names, addresses, email address, phone numbers, date of birth and an encrypted copy of the users password.  The breach was believed to have occurred between late February to early March.

If you have an eBay account, the first thing to is change your password.  

Depending on the level of encryption, all that is needed to crack the password is time and processing power.  Although the PayPal database is separate and has not been compromised, I would highly recommend changing that password, if it matches your eBay account.

Although my PayPal account rarely has much money left in it, it was only protected with a password.  After today, this was changed to send me a code via SMS when I log in, so I require my password and my mobile phone to gain access to the account now.  You can activate that on your account here,

How was eBay compromised?  Some of the eBay user credentials were obtained and used to carry out the compromise.

We've yet to find out how, but I suspect that it was either someone aware of the eBay way of working, or it obtained via a spear-phishing attack.  Spear-phishing is where specific people are targeted, where the people are either known, or information has been gathered from public sources, such as social media.  Once aware of information relating to the user, they can be targeted by many means, including email.  Typically when the user falls for the trap, software will be deployed onto their computer and the target monitored.  Credentials can be gathered and then used against the organisation the hacker is targeting.

Lockheed Martin pioneered the Cyber Kill Chain where there are seven steps to the potential compromise, and the aim is to break the chain at any one of the seven points.  The sooner, the better.

Another concern is that most organisations would require users to have privileged (such as system administrator) access to be able to access such information.  There are solutions out that that can could have prevented this by managing the password on behalf of the user. 

I'm sure more information regarding the compromise will come to light over next few weeks.  It's surprising that more protection and prevention hasn't been deployed, but being a large organisation like eBay they will always be targeted.