Home Blog Page 113

In Action: Lazarus Group Develops New AppleJeus Malware for Cryptocurrency Theft

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

Federal agencies are warning about potential cyber threats posed by the infamous North Korean hacking group Lazarus. In a joint advisory, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Treasury (DoT) revealed that the Lazarus hacking group is using different kinds of AppleJeus malware to target cryptocurrency exchanges and crypto-wallets.

The agencies stated the Group developed seven fake cryptocurrency trading applications to include AppleJeus malware variants to steal cryptocurrency. The seven malicious apps include Celas Trade ProJMT TradingUnion CryptoKupay WalletCoinGoTradeDorusio, and Ants2Whale. The Group used these malicious apps to bypass international sanctions imposed on the North Korean government and targeted individuals, cryptocurrency exchanges, and financial service companies across 30 countries last year.

Active since 2018, the Lazarus group leveraged multiple cyberthreat vectors like phishing, social networking, and social engineering attacks to trick unwitting users into downloading the malware.

Lazarus’ Timeline of Attacks

The Lazarus hacking group was involved in multiple cyber-espionage and cyber-sabotage campaigns earlier.

  • December 2019: Researchers discovered a malware dubbed “Fileless” distributed by the Lazarus group.
  • 2018: Kaspersky uncovered the AppleJeus malicious operation by Lazarus Group to intrude on cryptocurrency exchanges and applications.
  • 2017: The malicious activities of the group include the creation of malware used in the WannaCry0 global ransomware attack.
  • 2016: Theft of $81 million from Bangladesh Bank.
  • 2014: Attack on Sony Pictures Entertainment and numerous other intrusions on the entertainment, financial services, defense, technology, virtual currency industries, academia, and electric utilities.

How to Defend Against AppleJeus Malware

The federal agencies urged organizations to report in case they identify AppleJeus malware within their networks. They also recommended certain security measures for cryptocurrency users and organizations to combat AppleJeus malware. These include:

  • Verify the source of cryptocurrency-related applications.
  • Use multiple wallets for key storage, striking the appropriate risk balance between hot and cold storage.
  • Use custodial accounts with multi-factor authentication mechanisms for both user and device verification.
  • Patronize cryptocurrency service businesses that offer indemnity protections for lost or stolen cryptocurrency.
  • Consider having a dedicated device for cryptocurrency management.

Insiders Threats: The Achilles Heel of Organizations

Insider Threats

Information security expert and author Jason Coulls often keeps an eye on cybersecurity issues related to Canadian banks and telecommunication companies in his spare time. In June 2017, while browsing Github, an online code sharing and version control service where coders often share their open-source projects, he spotted a huge trove of sensitive documents of several American, Canadian, and Japanese financial institutions on the platform. The repository in the public domain contained migration plans, estimates, presentations, and other sensitive data that could have put those companies at risk. He counted the data of six Canadian banks, two American financial organizations, a multinational Japanese bank, and a multibillion-dollar software company.

By Augustin Kurian, Senior Feature Writer, CISO MAG

Further research into the breach revealed that the data leak was either an accidental mistake or a rather enormous failure of the common-sense of a developer working with Indian IT service giant Tata Consultancy Services (TCS). Coulls immediately notified the banks about the leak. “This was a new level of monumental head scratching activity, as you could literally fork or clone an entire repository of containing architecture details and roadmaps for some of the largest financial institutions in North America,” he wrote in his blog.

“The good news is that none of it was banking customers’ data, it was mainly auxiliary data,” Coulls told The Register post the incident. “But there was still a lot of useful stuff there – not just for hackers but for the firm’s competitors. The first bank that gets in to look at it gets to see what everyone else is doing.” Coulls also roasted TCS for not firing the employee immediately once the incident was discovered.

There are some takeaways from this incident. First, you’re only as strong as your weakest link. And sometimes your weakest link can be your employee making horrible mistakes, or it can be someone working for a third-party organization or a vendor.

The incident highlights what havoc accidents can wreak, but it might be even more staggering to find out that one in four employees have intentionally leaked confidential data. This surprising stat was discovered when data privacy and risk management company Egress Software Technologies did a survey of 2,000 UK workers. It’s probable that even the researchers didn’t anticipate such a dramatic result.

The report highlighted that employees who leaked information were likely to share data with their new or former employers or even competitors. The shared information, according to the report, ranged from bank details to customer information. Nearly half the respondents also stated that they had either already deleted or will delete emails from their sent folder if they felt the need for a cover-up.

Whether intentional or unintentional, insider threats are way bigger than we anticipate. A survey by Vanson Bourne concluded that insider threats pose a greater risk to companies than external threats by vectors like breaches and hackers. In fact, it pointed out that 74 percent of cyber incidents occur from within organizations. Here, 42 percent of the threats come from employees alone. “When considering the extended enterprise, meaning employees, customers, suppliers, or even previous employees, the number increases to 74 percent. Although most companies, 65 percent, believe that these inside incidents are accidental, that data still suggests a serious need for more extensive security education within businesses,” a report on ITPRO suggested.

According to an earlier Insider Threat Report by CA Technologies, nearly ninety percent of organizations feel vulnerable to attacks from insider threats. According to the report, the major risk factors were users with excessive access privileges, employees bringing their own devices to work, and the increasing complexity of the information security space. More than half of the respondents confirmed insider attacks against their organization in the last one year, where a quarter felt the insider attacks are becoming more frequent.

On the brighter side, a vast majority of companies are deploying insider threat programs. Companies are shifting their focus to the detection of insider threats, as well as deterrence methods, analysis, and forensics. “Thirty-six percent have a formal program in place to respond to insider attacks, while 50% are focused on developing their program,” the survey suggested.

Nipping it in the bud

Threats like insider attacks need to be nipped in the bud right from the beginning – in other words, during the hiring process. This is where the role of HR becomes crucial. “As with many organizational behaviors, HR has a role to play in ensuring the workplace culture is aware of issues around data. One thing HR could do to minimize the malicious leaking of information is ensure concerns are both raised and dealt with in a fair way that does not compromise the overall employee experience,” said David D’Souza, the CIPD’s head of London to People Management. “There will always be a minority of people who are opportunistic, so there should be a shared responsibility between HR and IT on how to deal with such incidents, depending on their severity. Steps that can be taken to minimize the risk could be as simple as reminding people at the point they resign about rules on data protection around other organizations and information.”

There are several touch-points throughout an employee’s career that HRs must focus on. The CERT Insider Threat Center has listed best practices to be adopted by organizations to safeguard themselves from insider threats. These include: maturing your insider threat programs, tracking terminated employees, improving employee engagement, developing a watchlist of employees with behavioral indicators, and adding insider threat awareness training to overall security awareness training.

Renee Brown Small, CEO, Cyber Human Capital, and Author, Magnetic Hiring in her earlier columns in CISO MAG talked about methods on new hire on-boarding.

“During on-boarding, the new employee is provided with mandatory training. Insider threat awareness training should be added to the training deck an employee must complete. It can also be administered during the times of the year that there may be higher cases of security breaches or insider threats,” she writes. She also writes about the importance of expanding mandatory vacation policies, “Many organizations have roles–– typically in finance, payroll, or trading––where the employee is subject to mandatory vacation. These policies should be expanded to some high-risk IT roles where employees have access to admin rights that could be a threat to the company if used maliciously.”

Authentication and the future of biometrics

As far as insider threats are concerned, it is evident that they are as big as any other threat. To counter this, there is the need for risk-based authentication technology that relies on things like proximity, behavior, biometrics, and more. Jeff Carpenter, Vertical Market Director – Authentication, Crossmatch, in one of his interviews with CISO MAG explained how authentication technologies like behavioral keystroke might be helpful in combating insider attacks.

“It works like this: as you’re typing your password, the software can look at how you’re typing a password, your lift, your movement across the keyboard, your stroke, your press. With this keystroke behavioral biometric, we are able to distinguish between one user and another. To a casual observer watching two users type in the same password, the differences are almost impossible to detect; but to a computer algorithm, the difference between the two users is completely distinguishable. We can again feed that into the risk engine and that becomes one more factor that will determine whether that user should get the access or not.”

According to him, behavioral biometrics will also enable continuous authentication and will gradually eliminate the need for the user to log in time and again.

He also discusses how several other innovations are driving the authentication space, where unique actions by the users are tracked and traced to create exclusive biometrics using artificial intelligence and machine learning. These can be simple tasks like how you hold your cell phone. “The gyroscopic sensors inside of your mobile device create a unique biometric with how you hold that phone. Mouse movements are another biometric: how you move your mouse, for example, to wake up your PC when it goes to sleep, is very unique to you. Machine learning can pick up the differences. Innovations like this are very exciting in the future and have the potential to provide even more convenience for users and more security for organizations,” he elaborates.

Machine learning

AI has already been deployed for the greater good. AI can be taught to understand the behavioral patterns of employees and companies, these may include regular file transfers off corporate networks onto physical media. It can also be taught to find those strange anomalies which often may seem very different from regular work shifts. It may be a rather newer phenomenon, but unsupervised machine learning is catching up. “This method is much like learning by observation, whereby a computer ingests data and distinguishes patterns on its own,” suggests Venture Beats.

Aaron Tuor, Samuel Kaplan, of Western Washington University Bellingham, and Nicole Nichols, Sean Robinson of Pacific Northwest National Laboratory Seattle in a study titled “Deep Learning for Unsupervised Insider Threat Detection in Structured Cybersecurity Data Streams,” presented an online deep learning architecture which produced “interpretable assessments of anomaly for the task of insider threat detection in streaming system user logs.”

They pointed out that insider threats don’t tend to fit one particular template, many at times takes new and different forms, which was why it was impractical to model it. The system they deployed developed instead modeled “normal” behavior and uses finds anomalies to highlight potential malicious behavior. “Our approach is designed to support the streaming scenario, allowing high volume streams to be filtered down to a manageable number of events for analysts to review. Further, our probabilistic anomaly scores also allow our system to convey why it felt a given user was anomalous on a given day (e.g. because the user had an abnormal number of file uploads between 6 pm and 12 am). We hope that this interpretability will improve human analysts’ speed and accuracy.”

Conclusion

In conclusion, insider threats are very real and complex. Having a healthy relationship with employees and monitoring their actions during and after their tenure can contribute toward a certain level of security. Authentication and innovation in the realm can also compliment many of the already existing standard security methods most companies deploy today.

In the aftermath of an insider threat incident, organizations spend an average of $4.3 million annually to mitigate, address, and resolve incidents. In the most severe cases of insider threat, organizations spend up to up $17 million annually. Many times post an incident, companies end up appearing less attractive to hostile bidders due to lower values on the stock market and higher level of debts post an incident. There will be causalities in process, and it may seem like the only option left is to adopt a scorched earth policy. But here’s the thing: A scorched earth policy might sometimes end up being a suicide pill for the company. While insider attacks may seem inevitable, always build higher walls, have a plan of action, and never resort to a scorched-earth policy post an incident.

Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

WatchDog Cryptojacking Campaign Running for Over Two Years

Cryptojacking

Cyberattacks on cryptocurrency exchanges and crypto wallets have become rampant as cybercriminals often target cryptocurrencies, whose net-worth is increasing day by day. Numerous hacks and heists have been reported in the cryptocurrency sector, where threat actors target crypto exchanges to deploy crypto-mining botnets on unsecured systems to siphon the crypto assets.

Security researchers from Palo Alto have recently uncovered a cryptocurrency-mining malware dubbed WatchDog targeting Monero cryptocurrency for more than two years.

WatchDog is one of the largest and longest-lasting Monero cryptojacking operations known to exist. It was found that the WatchDog mining operation is active since January 27, 2019, and its threat actors harvested over 209 Monero (XMR), valued to be around $32,056. They compromised and exploited around 476 Windows and Linux systems for mining Monero cryptocurrency.

The WatchDog Infection

Researchers found that the WatchDog operation uses Go binaries to perform its mining operations across different operating systems using the same binaries. They have identified 18 root IP endpoints and seven malicious domains, which serve at least 125 malicious URL addresses used to download its toolset.

“The WatchDog miner is composed of a three-part Go Language binary set and a bash or PowerShell script file. The binaries perform specific functionality, one of which emulates the Linux Watchdog daemon functionality by ensuring that the mining process does not hang, overload, or terminate unexpectedly. The second Go binary downloads a configurable list of IP addresses net ranges before providing the functionality of targeted exploitation operations of identified NIX or Windows systems discovered during the scanning operation. Finally, the third Go binary script will initiate a mining operation on either Windows or NIX operating systems (OS) using custom configurations from the initiated bash or PowerShell script,” the researchers said.

Reports also suggest that malicious cryptojacking operations are currently estimated to affect 23% of cloud environments, up from 8% in 2018. This increase is primarily caused by the meteoric rise in cryptocurrencies’ valuation.

What is Cryptojacking?

In cryptojacking, cybercriminals perform malicious crypto-mining operations on systems that are not owned by the mining operators. Malicious crypto-mining happens when threat actors compromise computers, laptops, and mobile devices by deploying malicious software to mine or steal cryptocurrencies owned by others.

CrowdStrike Introduces New eCrime Index to Shed Light on Intensity of Cybercriminal Market

Cybercrime

CrowdStrike Inc., the developer of cloud-delivered endpoint protection solutions, announced the release of the 2021 CrowdStrike Global Threat Report. The findings from the report reveal that during 2020, supply chain attacks, ransomware, data extortion, and nation-state threats prove to be more prolific than ever. Besides, the report uncovered the rising ransom demands from various eCrime actors, further adding that eCrime attacks made up 79% of all intrusions through hands-on-keyboard activity.

CrowdStrike stated that the supply chain sector is the most targeted vector for threat actors as it allows them to penetrate multiple targets from a single intrusion. Threat actors have improved their hacking strategies to evade detection and disguise into networks to perform data exfiltration, enabling the weaponization of sensitive data through threats of leaking proprietary information.

Key Findings

  • The health care sector will continue to face significant threats from criminal groups as CrowdStrike Intelligence confirmed 18 Big Game Hunting enterprise ransomware families infected 104 health care organizations in 2020.
  • Adversaries from the Democratic People’s Republic of Korea (DPRK) will be motivated to enhance cyber operations in 2021 due to COVID-19, and a resulting food shortage.
  • Data extortion techniques will continue to accelerate through the introduction of Dedicated Leak Sites (DLS).
  • China will focus on supply chain compromises and the targeting of key western verticals in support of the 14th Five Year Plan and the COVID-19 vaccine including academic, health care, technology, manufacturing, and aerospace.

CrowdStrike’s eCrime Index  

Due to the unprecedented rise in eCrimes, CrowdStrike has introduced a new eCrime index (ECX) along with the 2021 CrowdStrike Global Threat Report. The ECX exhibits the strength, volume, and sophistication of the cybercriminal market, and is updated weekly in real-time based on 18 unique indicators of criminal activity.

“There is a human being behind every attack, and cyber actors are getting bolder and more astute day-to-day. As such, it is critical to employ comprehensive cloud-native technology for increased visibility and prevention capabilities including threat intelligence and expert threat hunting to stay one step ahead of modern-day attacks. Additionally, today’s rapidly changing remote work environment highlights that identity protection is central to the defense of any enterprise’s infrastructure. Organizations must take decisive action to control access and protect data to outmaneuver adversaries,” said Adam Meyers, senior vice president of intelligence at CrowdStrike.

CrowdStrike’s “1-10-60” Rule

Preventing threats from sophisticated nation-state and eCrime adversaries requires a mature process that can prevent, detect, and respond to threats with speed and agility. CrowdStrike recommends organizations pursue the “1-10-60 rule” to effectively thwart cyberthreats.

1-10-60 rule recommends organizations to:

  • Detect intrusions in under one minute.
  • Investigate in 10 minutes.
  • Contain and eliminate the adversary in 60 minutes.

Organizations that meet this benchmark are much more likely to eradicate the adversary before an attack spreads from its initial entry point, ultimately minimizing organizational impact.

European Commission Initiates Process to Allow Personal Data Flow to U.K.

EU cybersecurity CISOMAG

The U.K. withdrew from the European Union on January 31, 2020. The transition period of the withdrawal lasted until December 31, 2020, and thus all laws applicable to the EU Member States were in effect during this period. But, effective January 1, 2021, U.K.’s sovereign state laws (U.K. GDPR and Data Protection Act 2018) came into power, which meant personal data transfers between the U.K. and EU nations no longer had a legal channel as the two now acted as separate entities.

However, it is to be noted that the U.K. “retained EU law,” which includes Regulation (EU) 2016/679 in its entirety (including its recitals). All the provisions and governance, which are applicable in EU’s laws for personal data protection are adopted by the U.K. as it is. Thus, considering this, the European Commission has initiated a process for transfers of personal data to the U.K. from other EU countries under two adequacy decisions: the General Data Protection Regulation (GDPR) and the other for the Law Enforcement Directive (LED).

Related News:

“Invalidation of the EU-U.S. Privacy Shield was a long time coming”

Draft for Personal Data Transfer to U.K.

The publication of the draft decisions on behalf of the European Commission is a step towards their adoption. The draft will be opinionated by the European Data Protection Board (EDPB) and shall require a go-ahead from a committee that includes representatives from the EU Member States. The European Commission has already found the U.K.’s law and practice on personal data protection fit and equivalent to the one guaranteed under the GDPR and, for the first time, under the LED.

Didier Reynders, Commissioner for Justice, said, “A flow of secure data between the EU and the U.K. is crucial to maintain close trade ties and cooperate effectively in the fight against crime. Today we launch the process to achieve that. We have thoroughly checked the privacy system that applies in the U.K. after it has left the EU. Now European Data Protection Authorities will thoroughly examine the draft texts. EU citizens’ fundamental right to data protection must never be compromised when personal data travels across the Channel. The adequacy decisions, once adopted, would ensure just that.”

Citing that adequacy findings may require modifications in the future and that the U.K. will no longer be bound by EU privacy rules, the commission will adopt the two adequacy drafts for the first period of four years. Post this, it would be reviewed and renewed if the level of personal data protection in the U.K. continues to be adequate.

In the Meanwhile

Until the comitology procedure, which involves consent from the EU Member States, is completed, data flow between the European Economic Area and the U.K. will continue and remain safe under the conditional interim regime that was agreed in the EU-UK Trade and Cooperation Agreement. This interim period will expire on June 30, 2021.

The draft adequacy decisions presented to the EDPB talks about the flow of data from the EU to the U.K. However, data flows in the other direction – from the U.K. to the EU – are regulated by the U.K. legislation, which is in effect since January 1, 2021. The U.K. unanimously decided that the EU’s measures provide adequate protection and therefore data can flow freely from the U.K. to the EU uninterrupted.

Related News:

EU-U.S. Privacy Shield Regarded Invalid by ECJ

Accellion Hack Continues! U.S. Retailer Kroger Admits Data Breach

CISA vulnerabilities, Microsoft Vulnerabilities, HP Device Manager Susceptible to Dictionary Attacks

Kroger, the U.S.-based supermarket chain, is the latest victim of a data breach through Accellion’s legacy file transfer software. In an official notice, the retail giant admitted that it was impacted by a security breach after an unauthorized third-party illicitly gained access to certain Kroger files that affected some of its customers’ information.

The data breach occurred due to a bug in Accellion’s file-sharing software, which was also used by New Zealand’s Reserve Bank that recently faced a cyberattack. Based in California, Accellion is a private cloud solutions company that provides software for third-party secure file transfers.

The Impact

The security incident affected Accellion’s services and did not impact Kroger’s IT systems. Based on the primary investigation, the exposed information includes certain associates’ HR data, pharmacy records, and money services records. Kroger also clarified that no credit/debit cards, digital wallet information, or customer account passwords were affected by the incident. Upon discovery, Kroger discontinued the use of Accellion’s services and reported the incident to federal law enforcement for further investigation.

While there is no evidence of any misuse of personal information, Kroger stated that it is directly notifying the impacted customers and offering them free comprehensive credit monitoring services.

The Ripples of Accellion’s Bug

Cybercriminals attacked several organizations globally by exploiting the Accellion vulnerability.  Several critical organizations like the Office of the Washington State Auditor (SAO), the Australian Securities and Investment Commission (ASIC), and New Zealand’s Reserve Bank suffered security breaches.  Recently, Singapore telco giant Singtel issued a statement confirming that over 129,000 of its customers’ data has been breached after attackers exploited the bug in Accellion’s software used by the company.

“Threat intelligence teams are struggling to integrate external data with internal security telemetry”

Cyberthreat Intelligence Strategies

To drive an effective security program, businesses need to have visibility into the organization’s threat landscape. But to do this, they need to consume Threat Intelligence. Many security and risk professionals are disappointed in the results of their cyberthreat intelligence efforts.

In an exclusive interview with CISO MAG, Brian Kime, senior analyst at Forrester, explains why users have not reached maturity in the adoption of threat intelligence solutions.  He explains the challenges and shortcomings faced by threat intelligence teams. And he offers some recommendations to take the correct approach and tackle these challenges.

At Forrester, Kime is serving security and risk professionals. He covers cyber threat intelligence, vulnerability risk management, and industrial control system security. In this role, he helps organizations identify, assess, and prioritize cyber and physical threats; prepare for emerging attack vectors; and reduce cyber risk in enterprise IT and operational technology (OT) environments.

This interview is basis the Forrester report titled “How to Integrate Threat Intelligence into Your Security Program”.

Edited excerpts from the email interview follow:

Cyberthreat intelligence (CTI) is not a new concept. Where is it today in the maturity curve? How far have organizations progressed in their CTI programs today? What are the challenges and deficiencies?

Vendors are around the peak of the maturity curve while end-users are significantly less mature. The vendors are doing well at deriving insights about cyberthreats from the multitude of raw telemetry they can obtain. However, threat intelligence teams in our end-user organizations are struggling to integrate external data with internal security telemetry.

One of the biggest challenges is the ill-founded notion that end-user threat intelligence teams are to be focused externally only. The value of internal security telemetry to a threat intelligence team cannot be overstated. If an end-user threat intelligence team is being denied internal security telemetry, they are effectively being denied visibility into the threats most relevant to the organization. That internal security telemetry is a primary source of intelligence – direct observations. All that external intelligence (secondary source intelligence) should be acquired to fill in gaps in the intelligence collection plan and to enrich and contextualize internal data.

Tooling available to end-user threat intelligence teams is highly deficient. On the market today there are many threat intelligence “platforms” that most often aggregate external data and disseminate that data to other security controls. I don’t consider these tools to be platforms since they do very little. They don’t help manage intelligence requirements and the collection plan. They don’t provide robust tools to analyze raw intelligence data. They don’t help writing finished intelligence reports or in collecting and analyzing feedback from stakeholders. This is an area where the vendors have shown increasing maturity. Most vendors have built their proprietary tools.

In these uncertain times, businesses need to predict or foresee risks and react quickly to shifts, to minimize negative impact. That requires insights from the organization’s threat landscape. What strategies do you recommend for gaining those insights? What does an organization need to have or do?

Forecasting threat activity is a large objective of a threat intelligence capability. That isn’t so easy, of course. I recommend organizations begin at the tactical level (supporting the SOC and DFIR), then at the operational level (clustering of events, trending data, threat actor modeling), and then produce quarterly and annual forecasts of threat activity.

What’s the importance of strategic threat intelligence in today’s context?

Boards of directors and C-suites – a business’s strategic leaders – are most concerned about reputational and regulatory risk. Cyberthreat intelligence can help identify, track, and assess threats to the brand’s reputation or uncover leaks of regulated data before Brian Krebs reports the data breach.

How does threat intelligence drive cyber risk management processes? Can you give us some business use cases?

We all (or all should) know that risk = threat x vulnerability x consequence. If risk managers lack awareness of the relevant threats, we misallocate resources and controls. Using the SolarWinds compromise as an example, the news around a current threat may drive improper allocation of security resources to detect that once-in-several year’s state-nexus campaign. A competent threat intelligence team can point to their strategic forecast to show all the other more relevant threats and scenarios to devote security resources to.

What are the priorities for a robust threat intelligence program? Why do you emphasize on Internal Security Telemetry?

Identify your stakeholders. Start with the CISO, SOC, and DFIR managers. Then grow your network of stakeholders to include the profit and loss centers. If you are in manufacturing, get familiar with that business unit and learn what business processes a cyber threat could affect. Then develop a collection plan to answer the requirements of those stakeholders beginning with data you already have.

Internal security telemetry is direct observations of threat activity against your assets and information. In other words, your data is primary source intelligence. Everything external is secondary and should be collected to enrich and contextualize primary sources, and to fill in gaps that cannot be answered by internal telemetry. But the best feature of internal security telemetry is that it’s free! You already paid for it!

What are the metrics an organization needs to measure/track its threat intelligence program?

The goals of a threat intelligence program should be to reduce the number and impact of breaches. Metrics like “adversary dwell time”, “mean time to recovery”, “breaches discovered by threat intelligence”, “detections generated by threat intelligence”, and “average cost of breach” are useful.

In summary, what is your best advice for integrating threat intelligence into a security program?

Keep your stakeholders at the forefront of your program. Empathize with their role in the organization. Elicit their requirements and feedback. Then exploit all your internal security telemetry, SOC alerts, and post-incident reports to make sense of your threat landscape.


About the Author

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

DDoS Attacks Intensify in 2020 — Driven in Part by COVID-19 and 5G

DDoS Attacks

Cybercriminals had a busy year in 2020, with rapidly increasing numbers of distributed denial of service (DDoS) weapons, widespread botnet activity, and some of the largest DDoS attacks ever recorded. As COVID-19 drove an urgent shift online for everything from education and healthcare, to consumer shopping, to office work, hackers had more targets available than ever — many of them under-protected due to the difficulty of maintaining security best practices in an emergency scenario. At the same time, the ongoing rollout of 5G technologies has accelerated the proliferation of IoT and smart devices around the world, making unsuspecting recruits available for botnet armies to launch crushing attacks on a massive scale.

By Sanjai Gangadharan, Regional Director for SAARC, A10 Networks, and Babur Khan, Technical Marketing Engineer, A10 Networks

In our ongoing tracking of DDoS attacks, DDoS attack methods, and malware activity, A10 Networks has observed a steady increase in the frequency, intensity, and sophistication of these threats, most recently in our State of DDoS Weapons Report for H2 2020, which covers the second half of the past year. During this period, we saw an increase of over 12% in the number of potential DDoS weapons available on the internet, with a total of approximately 12.5 million weapons detected. The good news is that proven methods of protection continue to be effective even as threat levels rise. In this article, we’ll talk about recent trends in DDoS activity and how to defend your organization against this common and highly damaging type of attack.

Botnets drive DDoS attack levels to new heights

While organizations of all sizes fell victim to DDoS last year, two of the world’s largest companies made headlines for suffering unprecedented attacks.

In June 2020, Amazon revealed a DDoS attack on its public cloud earlier that year that peaked at 2.3 Tbps, almost twice the size of the previous largest recorded attack. Soon afterward, Google revealed details of an even larger DDoS attack that peaked at 2.5 Tbps. A10 Networks has also been privately notified of even larger attacks, underscoring the perennial threat and growing impact of this type of cybercrime.

Unlike other types of cyberattacks that depend on concealment, DDoS attacks aim to simply overwhelm an organization’s defenses with a massive flood of service requests delivered from a large number of sources. The distributed nature of the attack makes it especially difficult to repel, as the victim can’t simply block requests from a single illicit source.

In recent years, hackers have evolved their methods and broadened their base of attack by using malware to hijack vulnerable compute nodes such as computers, servers, routers, cameras, and other IoT devices and recruit them as bots. Assembled into botnet armies under the attacker’s control, these weapons make it possible for attacks to be sourced from different locations across the globe to suit the attacker’s needs. In the second half of 2020, the top locations where botnet agents were detected include India, Egypt, and China, which together accounted for approximately three-quarters of the total. Activity sourced from DDoS-enabled bots in India spiked in September 2020, with more than 130,000 unique IP addresses showing behavior associated with the Mirai malware strain. A10’s most recent State of DDoS Weapons Report explores our findings of the largest contributor to this botnet activity, a major cable broadband provider, which accounted for more than 200,000 unique sources of Mirai-like behavior.

Blocking botnet recruiters

The identification of IP addresses associated with DDoS attacks gives organizations a way to defend their systems against questionable activity and potential threats. To protect services, users, and customers from impending DDoS attacks, companies should block traffic from possibly compromised IP addresses unless it is essential for the business, or rate-limit it until the issue is resolved. Automated traffic baselining, artificial intelligence (AI), and machine learning (ML) techniques can help security teams recognize and deal with zero-day attacks more quickly by recognizing anomalous behavior compared with historical norms.

Another important step is to make sure that your organization’s own devices are not being recruited as bots. All IoT devices should be updated to the latest version to alleviate infection by malware. To detect any pre-existing infections, monitor for unrecognized outbound connections from these devices, and check whether BitTorrent has ever been seen sourced or destined to these devices, which can be a sign of infection. Outbound connections should be blocked as well. This will prevent the device from making the call required for the installation of malware such as mozi.m or mozi.a as part of the bot recruitment process.

Amplification attacks and how to prevent them

The scope of a DDoS attack can be vastly expanded through amplification, a technique that exploits the connectionless nature of the UDP protocol. The attacker spoofs the victim’s IP address and uses it to send numerous small requests to internet-exposed servers. Servers configured to answer unauthenticated requests, and running applications or protocols with amplification capabilities will then generate a response many times larger than the size of each request, generating an overwhelming volume of traffic that can devastate the victim’s systems. Capable of leveraging millions of exposed DNS, NTP, SSDP, SNMP, and CLDAP UDP-based services, amplification reflection attacks have resulted in record-breaking volumetric attacks and account for the majority of DDoS attacks.

The SSDP protocol, with more than 2.5 million unique systems, led the list of amplification attack weapons exposed to the internet in 2020. With an amplification factor of over 30x, SSDP is considered one of the most potent DDoS weapons. The most straightforward blanket protection against such attacks is to simply block port 1900 traffic sourced from the internet unless there is a specific use case for SSDP usage across the internet. Blocking SSDP traffic from specific geo-locations where a high-level botnet activity has been detected can also be effective for more surgical protection.

As recent trends make clear, the DDoS threat will only continue to grow as rising online activity across sectors, a rapidly expanding universe of IoT devices, and increasingly sophisticated methods offer new opportunities for cybercriminals. Organizations should take an active approach to defense by closing unnecessary ports, using AI and ML to monitor for signs of compromise or attack, and blocking traffic from IP addresses known to have exhibited illicit behavior.

About the Authors

Sanjai Gangadharan is the Regional Director for SAARC, the South Asian Association for Regional Cooperation. He has more than 19 years of experience in the field of IT and Security. Gangadharan previously worked at F5 Networks, Palo Alto Networks, and several global infosec companies.

 

Babur Nawaz Khan is a technical marketing engineer at A10 Networks. He primarily focuses on the company’s enterprise security solutions, including Thunder® SSL Insight for TLS inspection and Cloud Access Proxy, which is a SaaS access security and optimization solution.

 

Disclaimer

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

 

Rethinking Penetration Test Requirements in Cybersecurity Compliance

Cybersecurity is standard business practice for most large companies: Survey

When you hear the phrase “penetration test,” what do you think of? I’ve asked this question to dozens of security professionals and I received a different answer from each person I asked. Penetration tests are well-known requirements in the cybersecurity industry however they mean something different depending on who you are talking to and the organization they work for. This article discusses how we should reconsider the evaluation of penetration tests in cybersecurity compliance assessments.

By AJ Yawn, Co-Founder and CEO of ByteChek

Requirements to complete a cybersecurity compliance assessment are unavoidable whether you’re working with the government, financial institutions, health care providers, software companies, or any entities that care about protecting their sensitive information. The assessment type will vary depending on your customers, your business model, and your company’s maturity. There are plenty of common frameworks and standards every security leader is familiar with, such as SOC2, ISO 27001, HIPAA, HITRUST, CMMC (NIST-800-171), FedRAMP, and CSA STAR.

Each of these compliance standards or frameworks requires similar controls, one of those control activities being penetration tests. But what exactly does that mean? Auditors have accepted blanket penetration tests to meet compliance requirements for far too long. The level of depth between a penetration test taken by one auditor sometimes completely varies from other assessors. This leaves a confused reader of compliance reports to ask this question:

What does it mean when your compliance report says, “A penetration test is completed on at least an annual basis”?

Hackable by Ted Harrington, a #1 best-selling book, discusses how to ensure application security is completed correctly and adds value. Harrington outlines the key differences between a penetration test, vulnerability scan, and vulnerability assessments. I consider Hackable a must-read for every security professional as application security is important to understand, regardless of your role or expertise.

Why should auditors rethink evaluating penetration tests?

An audit is an activity focused on evaluating controls and their operating effectiveness. Each control serves a specific purpose – to mitigate risk. When an organization undergoes a penetration test, they are generally looking to gain a comprehensive understanding of the weaknesses of their application’s security posture to ultimately reduce the risk of a breach or malicious event from a bad actor.

When we think about an annual penetration test activity, does it reduce this risk? What does it even mean? The term itself is no longer clear, as different providers mean different things when they use it.  When you think about penetration testing, keep two things in mind:

  • Security is never done. An annual scan or test will only be useful for a short timeframe after the test, and modern technical environments are changing by the second.
  • A penetration test control without a detailed methodology outlining the type of test (white box vs. black box) does not provide enough information to the readers of the report if the test that was performed reduced the risk of vulnerabilities in the application.

Good security requires context; good compliance requires the same

Context is critical in security. Security professionals worldwide understand that there is no one-size-fits-all approach to security, but we have accepted this mindset in cybersecurity compliance. For more mature organizations with a robust vulnerability management program (which probably includes regular, tailored vulnerability assessments), a penetration test makes a ton of sense. Ted did a great job explaining when a penetration test makes sense versus a vulnerability assessment or a scan, so I won’t dive into those details here.

Most companies need vulnerability assessments. A vulnerability assessment is a “comprehensive, rigorous, manual effort to discover security vulnerabilities, assign severity ratings to them, and determine how to fix them. The objective is to find as many as possible and remediate them. As a result, you understand and reduce risk.” Hackable, p. 50

The above quote from Hackable is a perfect description of what auditors should be looking for instead of the blanket penetration tests. A vulnerability assessment provides a more detailed view into whether or not an application is appropriately mitigating risks, which is ultimately the compliance assessment goal to determine if the organization has controls to mitigate risk properly.

Security professionals around the world are lifelong learners, addicted to finding new ways to solve security problems. As a security practitioner, I immediately think about my customers and the security community when I find out further information. I want to run out, scream, and tell everyone I know the new knowledge I gained so that they are more secure and informed. At ByteChek, we are updating our control statement for our platform and SOC2 examinations. We will no longer include a generic penetration test control and transition to a vulnerability assessment control statement. We are only a small piece of the large cybersecurity compliance space, but we must take small steps to improve the industry. Cybersecurity compliance assessments should add security value to the organizations undergoing audits. The only way this will occur is if compliance professionals are consistently evaluating controls from a security point of view. Security evolves, and compliance assessments should evolve too.


About the Author

AJ Yawn - ByteChek

AJ Yawn is the Co-Founder and CEO of ByteChek. He is a seasoned cloud security professional that possesses over a decade of senior information security experience with extensive experience managing a wide range of cybersecurity compliance assessments (SOC 2, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers.

AJ advises startups on cloud security and serves on the Board of Directors of the (ISC)2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and (ISC)2.

Disclaimer

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.