Home Blog Page 275

Payment Security Compliance Declines – 1 in 3 Companies Make the Grade

one million card data exposed

Payment security compliance has declined for the second year in a row, with organizations based in the Americas lagging behind worldwide counterparts, Verizon’s 2019 Payment Security Report (2019 PSR) flags.

When Visa Inc. initially launched the PCI DSS in 2004, many assumed that organizations would achieve effective and sustainable compliance within five years. Now, 15 years on, the number of businesses achieving and maintaining compliance has dropped from 52.5 percent (2018 PSR) to a low of just 36.7 percent worldwide. Geographically, organizations in the Asia-Pacific (APAC) region show a stronger ability to maintain full compliance at 69.6 percent, compared to 48 percent in Europe, Middle East and Africa (EMEA) and just 20.4 percent (1 in 5) in the Americas.

PCI DSS helps businesses that offer card payment facilities protect their payment systems from breaches and theft of cardholder data, as shown in the Verizon Data Breach Investigations Report series. Compliance is measured on an organization’s ability to meet — and importantly, maintain — the standard.

“After witnessing a gradual increase in compliance from 2010 to 2016, we are now seeing a worrying downward trend and increasing geographical differences,” said Rodolphe Simonetti, global managing director for security consulting at Verizon. “We see an increasing number of organizations unable to obtain and maintain the required compliance for PCI DSS, which has a direct impact on the security of their customers’ payment data. With the latest version of the PCI DSS standard 4.0 launching soon, businesses have an opportunity to turn this trend around by rethinking how they implement and structure their compliance programs.”

New Verizon framework helps businesses navigate payment security compliance

Data protection and compliance present daily challenges. Many organizations believe they can use a one-size-fits-all script to achieve effective and sustainable data protection. However, in the real world, security is more complicated.

Simonetti continues, “Many organizations spend a lot of time and money creating data protection compliance programs, but often these are ineffective — looking good on paper but not able to withstand the scrutiny of a professional security assessment. We still see Chief Information Security Officers focusing on how to maintain baseline control activities rather than looking at data protection competency and maturity. What is needed is a clear and easy-to-understand navigational guide to help them deliver measurable results and predictable outcomes.”

In previous Payment Security Reports, Verizon developed methodology to help organizations manage their Data Protection Compliance Programs (DPCPs). These have now been combined to form the Verizon 9-5-4 Compliance Program Performance Framework — a guideline which helps develop and improve capability and process maturity.

The 9-5-4 Framework is designed to help organizations achieve repeatable, consistent and predictable outcomes by offering guidance on how to map, monitor and report the status of sustainability and effectiveness for each of the 9 Factors of Control Effectiveness and Sustainability — including control environment, control design, control risk, control robustness, control resilience, control lifecycle management, performance management, maturity measurement and self-assessment. This is across each of the essential 4 lines of assurance — individual accountability, risk management and compliance teams, internal audit, external audit and regulators — and is achieved by evaluating the 5 Constraints of Organizational Proficiency  — capacity, capability, competence, commitment and communication.

Link reinforced between lack of compliance and breaches

The report also includes data from the Verizon Threat Research Advisory Center (VTRAC), which demonstrates that a compliance program without the proper controls to protect data has a more than 95 percent probability of not being sustainable and is more likely to be a potential target of a cyberattack.

“For years, we have discussed the close correlation between the lack of PCI DSS compliance and cyber breaches,” concludes Simonetti. “In this year’s report, we included even more data from the Verizon VTRAC team, the authors of Verizon’s Data Breach Investigation series, to add more depth to this discussion. Our data shows that we have never investigated a payment card security data breach for a PCI DSS compliant organization. Compliance works!”

About the Verizon 2019 Payment Security Report

This year’s report focuses on performance visibility, control and maturity of DPCPs. It includes results from 302 PCI DSS engagements for a range of organizations, including Fortune 500 and large multinational firms in more than 60 countries. The assessments were conducted by Verizon’s team of PCI Qualified Security Assessors (QSAs), as well as large third-party QSAs, including ControlScan, Foregenix, MegaplanIT and Schellman.

Similar to Verizon’s Data Breach Investigations Report series, the 2019 PSR is based on actual casework with a specific focus on financial services (50.7 percent); IT services (17.5 percent), retail (19.9 percent) and hospitality (10.6 percent). Geographies include the Americas (50.0 percent), APAC (20.0 percent), and EMEA (30.0 percent).

Researchers Uncover Mass Malware Attack

Rootkits, Mobile Malware in Asia

Security experts discovered a Mass Malware Distribution campaign that using popular political personalities in the U.S. including President Donald Trump, Hillary Clinton with a series of ransomware, screen lockers, RATs, and other malicious applications.

Researchers from security firm Talos stated that the malware authors are motivated by their political beliefs and turned into malware distribution in different forms. It’s believed that the attackers developed malware to infect the victims with ransomware, implant a backdoor in organization networks with political motivation.

“Some of the applications are designed to coerce victims into paying ransom demands, while others could be used to gain backdoor access to systems and provide attackers the ability to operate within organizational networks. In many cases, it is clear that the authors of these applications were motivated by their political beliefs, which were reflected in the software that they created,” Talos said in a statement.

How the Malware Infects

The attackers deliver malware via malspam email campaigns with fake content related to banking fraud alerts and with a malicious attachment that contains RTF files. Once opened, the RTF documents retrieve a malicious PE32 executable from an attacker-controlled server and downloads it into the victim’s device.

“Research into these campaigns originally began with a malspam campaign that attempted to deliver malware to victims. The emails associated with this campaign purport to be related to banking fraud and are made to appear as if they were sent by the director of Global Risk for credit card company Visa. Compressed archives are attached to these emails containing RTF files. The RTF files contain information related to fraud prevention,” Talos stated.

In a similar kind of news, researchers from Kaspersky revealed an ongoing Android malware campaign dubbed ViceLeaker that has been active since 2016. According to the researchers, a hacker group has been found targeting Israel citizens and other Middle East countries with surveillance malware named Triout.

The malware is designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge. Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and make calls or send messages to specific numbers, according to the researchers.

Multiple Security Flaws Detected (and fixed) in Cisco Small Business Routers

Beware! Counterfeit Cisco Switches Bypass Network Authentication

 

Potential vulnerabilities in Cisco’s small business routers could allow a remote attacker to exploit the devices to get sensitive data. Cisco, the networking hardware company, stated that the issue existed in its RV320 and RV325 Dual Gigabit WAN VPN business routers.

According to the official statement, the Cisco Small Business Routers exhibited numerous security issues. Specifically, three major security bugs were discovered in the Cisco RV320 and RV325 Dual Gigabit WAN VPN Routers firmware named as CSCvq34465, CSCvq34469, and CSCvq34472.

The routers affected by these bugs are facing issues like, Static certificates and keys, Hardcoded password hashes, and Multiple vulnerabilities in third-party software (TPS) components. If exploited, the vulnerabilities allow anyone to get access to the base operating system to easily gain root access on the target device, according to the statement.

Cisco stated that its developers unintentionally shipped the certificates with the firmware. “The inclusion of these certificates and keys in shipping software was an oversight by the development team for these routers,” Cisco stated.

Since Cisco has now fixed the bugs, the users must quickly update their devices to the latest firmware to prevent possible threats.

Cisco faced a similar issue last year when a flaw in its Smart Install Client routers was misused by a group of cyber miscreants to bring down internet services on a global scale. Over 200,000 router switches across the world were affected by this attack, of which 3,500 were from Iran. According to Iran’s IT Minister, Mohammad Javad Azari-Jahromi, Europe, India, and the U.S. were among those countries affected by the attack. The screens of the hacked machines had an image of the U.S. flag with the message: “Don’t mess with our elections.”

Also, the company recently released patches for critical security vulnerabilities that existed in its Aironet Access Point Software. Security pros at Cisco stated that the vulnerabilities could lead bad actors to remote code execution.

Up on exploit, the vulnerabilities, named CVE-2019-15260, CVE-2019-15261, and CVE-2019-15264, could allow an attacker to gain access to view sensitive information, meddle with wireless network configurations, and cause a denial of service. However, Cisco has released fixes for all the three high-severity flaws targeting its Access Point Software.

Thwarting Graboid and Protecting Containers with Zero Trust

zero trust

By Dan Perkins, director of product management, Edgewise Networks

Recently, security researchers discovered a new worm that targets unsecured Docker daemons that are exposed to the Internet. The Unit 42 researchers at Palo Alto Networks estimate that it has already infected more than 2,000 containers, downloading a malicious Docker image that contains cryptomining software. The worm then queries for other vulnerable hosts, replicates itself and infects them as well.

The Unit 42 researchers at Palo Alto Networks named the worm “Graboid” in honor of the 1990 Kevin Bacon film because, as they write, it “behaves similarly to the sandworms in the movie, in that it moves in short bursts of speed, but overall is relatively inept.” That said, the researchers note that Graboid could easily be adapted as a delivery mechanism for other attacks, such as ransomware or data exfiltration, so it’s well worth looking into how to defend against it.

Certainly, the best way to protect Docker containers from this worm is to ensure they’re properly configured and not exposed to the public Internet. But relying on perfect configuration for container security isn’t a strong security stance — people make errors, so it’s critical to take measures that will secure the containers even if they are misconfigured.

Zero trust in containers through software identity

Zero trust provides a good model for defending against this worm and similar threats, because it treats all internal communications as potentially hostile and, so, can stop unauthorized lateral movement inside networks. In Zero Trust, all communications between two network assets must be explicitly pre-authorized.

Zero trust is enabled by microsegmentation, but that’s very difficult to do in containers because traditional methods of microsegmenting a network depend on trusted IP addresses, and in autoscaling environments like containers and the cloud, IP addresses are ephemeral. IT would have to constantly update policies as IP addresses change, which is not only labor-intensive, but also carries a high risk of error, which could result in the creation of a vulnerability. The end result is a set of highly complex policies that are extremely cumbersome to manage.

There is a new model for microsegmentation, however, that relies on the identity of software, hosts and devices. In this way, we can separate the control plane from the network layer to enable the creation of policies that don’t break when the network changes. In this approach to microsegmentation, each network asset is assigned an immutable, unique identity based on dozens of properties of the asset itself, such as a SHA-256 hash of a binary, the UUID of the bios or serial numbers of processors. Because the identity is based on intrinsic attributes, this method prevents spoofed or altered software, devices and hosts from communicating.

The process for microsegmenting Docker environments

Here’s how microsegmentation for zero trust would work for containers using an identity model. First, IT needs to conduct an asset and communications pathway inventory, a complex task that’s best automated using artificial intelligence (AI) or machine learning (ML). Once complete, the security team should then identify unnecessary pathways and eliminate them to reduce the attack surface. Typically, more than 90 percent of a network’s communications pathways can be shut down without having any impact on the production environment. Next, IT must build identity-based policies that will essentially act as micro-perimeters around each asset. Again, policies are best created by leveraging AI and ML to ensure that the smallest number of policies cover the greatest number of sensitive assets.

To combat Graboid and other worms aimed at containers, the goal should be to prevent self-propagation through policies that block all inbound connections to the Docker daemon and protect against unauthorized access via secure shell (SSH) and other admin tools, such as Swarm and Kubernetes. The focus is to control admin tool access when managing Docker hosts at scale, blocking everything else from accessing Docker servers. Additionally, through behavioral analysis, the ML / AI platform could identify cryptomining containers as malicious based on network scanning behavior.

With the advent of identity-based microsegmentation, security teams can finally extend zero trust to autoscaling environments such as containers, which will not only stop Graboid, but also any other threat from laterally moving from one host to another. It should become a standard security measure for protecting workloads in all enterprise networks, whether on-premises, in the cloud or in containers.

About the Author

Dan PerkinsDan Perkins is Director of Products and Solutions for Edgewise Networks, where he oversees the direction and development of Edgewise’s zero-trust platform. Prior to Edgewise, Dan was Director of Product Management at Infinio, where he was responsible for product vision and the ongoing quality and applicability of Infinio’s solution. He also previously served in several software engineering and quality assurance roles for Citrix. Dan holds a B.S. in computer engineering from Northeastern University.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Failure in HIPAA Compliance Costs URMC $3 million fine

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

The University of Rochester Medical Center’s (URMCs) ignorance towards HIPAA compliance has costed them a $3 million fine. Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) held URMC responsible for two separate counts of HIPAA compliance violation that took place in 2013 and 2017.

URMC reported of a data breach in 2013 when it lost an unencrypted flash drive (USB drive) which contained protected health information (PHI) of its patients on February 15, 2013. In response to this data breach reporting, OCR notified URMC that it was initiating an investigation regarding URMCs HIPAA compliance.

On January 26, 2017, OCR again received a notification from URMC regarding another data breach. This time, URMC reported that an unencrypted personal laptop of one of its resident surgeons containing 43 PHI records of its patients was stolen from its treatment facility. OCR once again carried out HIPAA compliance audit on URMC for this incidence.

During their audit, OCR found URMC flouting HIPAA compliance rules on both the instances and the following were the parameters:

Risk Analysis: URMC failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all PHI patient records under URMCs physical and virtual custody, including the ePHI records on the lost flash drive and stolen laptop computer.

Security Measures Definition: Failed to implement the required security measures essential to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with HIPAA.

Security Policies Implementation: URMC failed to implement and exercise device and media control in its facility.

Device and Media Encryption: It failed to implement the required encryption and decryption mechanisms to keep PHI records safe.

Not just this, but OCR termed URMC as a repeated offender of HIPAA compliance. Why? Back in 2010, URMC was involved in another lost unencrypted flash drive that resulted in a data breach incidence. Despite OCR’s recommendations and assistance back then, URMC permitted the use of unencrypted mobile devices and flash drives.

In a stern statement, Roger Severino, OCR Director said, “Because theft and loss are constant threats, failing to encrypt mobile devices needlessly puts patient health information at risk. When covered entities are warned of their deficiencies, but fail to fix the problem, they will be held fully responsible for their neglect.”

In addition to the $3 million fine, OCR also directed URMC to undertake a corrective action plan which includes two years of monitoring their compliance with the HIPAA Rules.

Two Ex-Employees of Twitter Caught Spying for Saudi Arabia

Surveillance Legislation (Identify and Disrupt) Amendment Bill

Two former employees of Twitter have been recently charged for spying on thousands of Twitter user accounts on behalf of the Saudi Arabian government.

According to the indictment, two of the defendants, Ahmad Abouammo, an American citizen who left Twitter in May 2015, and Ali Alzabarah, a Saudi citizen who left Twitter in December 2015, are accused of spying likely with the purpose of exposing the identity of protesters.

And a third person, Saudi citizen Ahmed Almutairi, is also indicted for acting as an intermediary between the two Twitter employees and the Saudi government officials.

It’s said that both the former employees were recruited in 2014 by officials from the Saudi government with close ties to the Saudi prince, Mohammed bin Salman, to access sensitive information of Twitter users associated with Saudi critics.

“The FBI will not stand by and allow foreign governments to illegally exploit private user information from U.S. companies.  These individuals are charged with targeting and obtaining private data from dissidents and known critics, under the direction and control of the government of Saudi Arabia,” said FBI Special Agent in Charge John F. Bennett.  “Insider threats pose a critical threat to American businesses and our national security.”

The indictment stated that Alzabarah allegedly accessed sensitive data of more than 6,000 Twitter users. While, Abouammo was accused of deleting data from the social media platform, unmasking the identities of some users, and shutting down Twitter accounts on request of the Saudi government officials. He has also been separately charged for providing the Federal Bureau of Investigation (FBI) with fake records to obstruct the federal investigation.

The information they accessed includes users’ email addresses, devices used, browser information, user-provided biographical information, birthdates, user’s location, IP addresses, and phone numbers.

Twitter stated that they cooperated in the investigation and it’s going to limit access to sensitive account data only to vetted employees. “We understand the incredible risks faced by many who use Twitter to share their perspectives with the world and to hold those in power accountable. We have tools in place to protect their privacy and their ability to do their vital work,” Twitter said in the statement.

“If convicted, all three defendants face a maximum statutory sentence of 10 years in prison and a $250,000 fine for acting as an agent of a foreign government without notification to the Attorney General, in violation of 18 U.S.C. § 951.  In addition, Abouammo faces an additional 20 years in prison and a $250,000 fine for destroying, altering, or falsifying records, in violation of 18 U.S.C. § 1519.  Further, the court may order restitution, if appropriate, and additional periods of supervised release,” the U.S. Department of Justice (DoJ) said in a statement.

Gone Phishing: Stealth Hits the Corner Office

active directory
active directory

By Alex Artamonov, Systems Engineer and Cybersecurity Specialist, Infinitely Virtual

Mimicking the boss, in most organizations, is the very definition of insubordination. But ordering supplies or a job requisition in the top dog’s name is “BEC” – business email compromise – a growing (and worrying) cybersecurity trend that is too much of a euphemism for my liking.

BEC is polite language for CEO fraud, where, via email, someone (not necessarily an actual employee or underling but rather a bad actor posing as one) invokes senior management to get a recipient to take some action, typically sending money and/or downloading an attached Excel file that just happens to contain malware.  It’s a virtual way of walking through the front door, with employees unwittingly clearing the path.

While phishing itself isn’t new, CEO fraud is a relatively recent arrival on the hacking scene.  How insidious is this new-fangled extortion-like scheme?  The FBI puts cumulative losses to businesses from BEC in at $13 billion. According to CPO Magazine, BEC has hit more than 80,000 companies globally in the last five years.

Growing BEC incidents

Perpetrators are once again several steps ahead of their marks: “As BEC continues to drive record-high losses, cybercriminals are devising new tactics for swindling corporate targets out of millions,” Dark Reading recently noted.  “The number of reports describing BEC incidents has rapidly grown from a monthly average of nearly 500 in 2016 to more than 1,100 in 2018, the Financial Crime Enforcement Network (FinCEN) says in its July 2019 Financial Trend Analysis. The total value of attempted BEC threats climbed from an average of $110 million per month in 2016 to $301 million per month in 2018.”

The source of an enormous percentage of these messages is surprisingly obvious, per Help Net Security: 84 percent of BEC messages used free webmail services for distribution; 12 percent used spoofed company domains and 4 percent elected to employ misspelled or lookalike domain names to deceive recipients.

So why is BEC getting worse?  Why aren’t organizations wising up, and what should they be doing to stanch the bleeding?  Is this a case of collective naiveté, or is there something more pernicious about CEO fraud?

It’s getting worse in part because hackers abhor a vacuum.  While there are a handful of proven strategies and common-sense policies that organizations need to adopt – now – to begin to gain the upper hand on CEO fraud, actions are by their very nature reactive, chewing up precious time as bad actors go about their mischief.  More and more of them are going the BEC route; they exploit any new form of attack while the getting is good–and their M.O. is to propagate the pain by sharing the how-to’s of CEO fraud on hacker forums.

Authentication strategies

It’s also getting worse because the user community has let its guard down… if it was ever even up.  Still, there are three accessible, cost-effective email authentication strategies for the taking; users simply need to deploy them:

  • SPF Records– A Sender Policy Framework (SPF) record identifies legitimate mail servers – those that are allowed to send email on behalf of your domain.  Adding an SPF TXT record detects and prevents spammers from sending messages with forged “From” addresses on your domain.  It’s basic and, increasingly, is becoming a requirement for antispam filters.
  • DKIM Signatures– DKIM (DomainKeys Identified Mail) Signatures permit senders to associate a domain name with an email message, essentially affirming its authenticity. A sender creates the DKIM by “signing” the email with a digital signature, which is located in the message’s header.  Like SPF records, DKIM signatures are a snap to add.
  • Personal Digital Certificates– Think of a Digital Certificate as an electronic “password” that enables an individual or an organization to exchange data securely over the Internet using the public key infrastructure (PKI).  As with the other two methodologies, the cost of deployment is low.

So, while these approaches aren’t especially new, they’re suddenly growing in popularity because they work, and organizations ignore them at their peril.  When all three are in force–and all should be–it’s possible to knock off nearly 99 percent of BEC threats.

But the simplicity and availability of these solutions don’t mean we’re out of the woods.  IT has typically put the burden on antispam filters, a view I believe is misplaced.  While these filters are aimed to some extent at fraudulent emails, that’s not why they exist.  An organization can be hip-deep in spam filters and still get burned.  If someone’s email is compromised, it’s still possible to log in and send hacked-but-seemingly legit emails to colleagues, and antispam won’t save them.

Using two-factor authentication might, however, which is why Microsoft has recently taken up the cause, modifying Office365 in a way that acknowledges just how big a deal CEO phishing has become.  As Krebs on Security reported in June: “It might be difficult to fathom how this isn’t already mandatory, but Microsoft Corp. says it will soon force all Cloud Solution Providers that help companies manage their Office365 accounts to use multi-factor authentication. The move comes amid a noticeable uptick in phishing and malware attacks targeting CSP employees and contractors.”  And in early August, Microsoft made it official.

While every technical effort to address CEO fraud is welcome, the human factor must be front and center.  That means educating users to be both vigilant and skeptical. Make it second nature to take a moment to ask why a message was sent or why a request was made.  CEO phishing can’t be beaten by rote instructions but by attitude, and by an understanding that change is a constant.  What’s true today won’t be true tomorrow.

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Researchers find vulnerability in Amazon’s Ring Video Doorbells

Amazon’s Ring Video Doorbells

Security researchers stated that a flaw in Amazon’s Ring Video Doorbell Pro IoT device could have given hackers unauthorized access to the user’s wi-fi network and potentially to other connected devices on it.

The vulnerability was discovered by researchers at cybersecurity firm Bitdefender. The researchers stated that all Ring Doorbell cameras have now received a security patch from Amazon to mitigate the issue.

Ring Doorbells are internet-connected doorbells that provide motion-sensing and video surveillance capabilities. It allows the users to see and communicate with the people outside their doors via an app, even if they’re outside.

According to researchers, the vulnerability stems when the Ring smartphone app sends the wireless network connections to the Amazon Ring servers in the cloud. It’s found that this process is taking place in an insecure manner, which can be exploited by an attacker.

“When entering configuration mode, the device receives the user’s network credentials from the smartphone app. Data exchange is performed through plain HTTP, which means that the credentials are exposed to any nearby eavesdroppers,” Bitdefender said in a statement.

“Another important step in exploitation is a fact that a hostile actor can trigger the reconfiguration of the Ring Video Doorbell Pro. One way to do this is to continuously send reauthentication messages so that the device gets dropped from the wireless network. At this point, the mobile app loses connectivity and instructs the user to reconfigure the device,” the statement added.

The Internet of Things (IoT) has become a primary target for cybercriminals, exploiting vulnerabilities in them. Recently, a Milwaukee-based couple suffered a horrifying incident after their Smart Home setup was hacked by unknown intruders. The couple had installed a Nest system, (a setup of camera, doorbell, and thermostat) in their home last year.

According to Fox 6 News, the couple Samantha and Lamont Westmoreland stated that hackers took over their smart home by compromising the connected devices. The attacker played disturbing music from the video system at high-volume while talking to them via a camera in the kitchen and changed the room temperature to 90 degrees Fahrenheit by exploiting the thermostat, the couple stated.

Initially, the couple thought it was a technical glitch and changed their passwords, but the issue continued. The duo later changed their network ID, after realizing that someone hacked their Wi-Fi or Nest system.

Lock Down the Endpoint with Cyber Deception

Cyber Deception

By Carolyn Crandall, Chief Deception Officer and CMO at Attivo Networks

Every device that connects to a network creates a security risk. There are many forms of defenses designed to protect these endpoints including anti-virus, firewalls, HIPS, endpoint detection and response (EDR), and other forms of access control. Most of these solutions require installed agents to manage authorizations and authentication, track device activities, and detect and remove viruses and malware. Despite the efforts applied to endpoint protection and EDR solutions, it is inherently insufficient. Even if you could find every endpoint, manage every agent, and keep every device consistently patched, there are fundamentally too many attack vectors to keep up with.

However, what if you were able to change the game and create an environment where every path an attacker takes to move off from a system leads them away from their target and into a deception environment? What if every endpoint became a decoy? What if you could lock down the lateral movement of an attacker so that they could not conduct network discovery, Active Directory reconnaissance, credential theft, Man-in-the-Middle attacks, or services exploitation? Seems farfetched? Fortunately, with modern cyber deception, it is not a vision but a capability that is available today.

The Attivo Networks ThreatDefend Cyber Deception Platform brings forward innovation that changes the game so that attackers can’t successfully break out from the endpoint. The solution works by not only interweaving deception throughout the network but also by making every endpoint a decoy designed to disrupt an attacker’s ability to break out. It also does this without requiring agents on the endpoint or disruption to network operations. The attack methods that the solution derails include, but are not limited to:

  • Stealing local credentials
  • Looking for file shares and connected systems
  • Network reconnaissance as they look for production assets and available services on these hosts
  • Active Directory Reconnaissance to query AD for privileged domain accounts, system, and other high-value objects
  • Man-in-the-Middle attacks where attackers steal credentials in transit

The benefits are material in detecting threats early and accurately. In a recent EMA survey, deception customers cited 5-day dwell times and high confidence in detecting threats. These results reflected a more than 90 percent improvement over non-deception technology users. Survey respondents also cited deception as the top tool of choice for detecting insider threats compared to 12 other security controls. Insiders using legitimate credentials are often hard to detect. Deception reduces this risk by removing exposed attack paths and through the use of decoys, which are extremely effective in detecting policy violations and attempts at unauthorized access.

What you need to know

A modern cyber deception platform provides the ability to lock down lateral movement from the endpoint in an efficient and agentless manner. This capability results in early detection of threat activity and in the facilities to gather company-centric threat intelligence for stopping an attack, threat hunting, and faster remediation. One should not view cyber deception as a replacement for prevention controls, but instead as a force-multiplier in that it can detect threats from all vectors, do so non-disruptively, and through native integrations share attack data for automated system isolation and remediation.

Deception credentials install on endpoints, which appear identical to those of the system user. They are crafted to mirror-match and are dynamic so that their timestamps refresh. Notably, the solution can also plant cloud deceptions for improving identity access management.

Endpoint deceptions can deploy with such a high degree of authenticity that even advanced Red Teams and tools like HoneypotBuster can’t tell the difference. With attempted use of a deception bait, the deception platform raises a high-fidelity alert, and the credentials breadcrumb the attacker into the deception decoy environment where defenders can study the forensics and attack activity.

Deceptive mapped shares attract an attacker into the decoy environment, generate an alert, and through native integrations with existing endpoint solutions, can automatically quarantine the infected system from the network. The solution also proactively stalls the attack by feeding the attacker reams of data, so they remain occupied, and security teams gain valuable time to respond.

Network discovery gets derailed as the deception fabric interweaves decoy endpoints throughout the environment, with support for real Microsoft, Linux, and Mac OS and a wide variety of applications. Running both endpoint and network deceptions provides the most comprehensive and in-depth detection for organizations. For optimal protection, organizations typically deploy both endpoint and network solutions together.

Active Directory queries get derailed as the deception solution hides real credentials and system data and returns deceptive content, creating an altered reality for the attacker. In this case deception ventures into prevention as even the mere act of observation can trigger an alert. This method of prevention can also be invaluable in that attackers can no longer trust what they see or the tools they typically rely on.

Lateral path exploration based on exposed or orphaned credentials can get identified and remediated quickly, shutting down attack paths. This knowledge helps reduce risk and the overall available attack surface.

In addition to early lateral movement detection, defenders also uniquely gain visibility into the attacker’s tools, the use of malicious software, and the ability to quickly quarantine infected systems. Additionally, because deception can direct activities into the deception environment, teams can also safely study the attack and gather indicators of compromise (IOCs), forensics, and Tactics, Techniques, and Procedures (TTPs), along with company-specific threat intelligence.

There is really no other security control quite like the cyber deception for reducing the risk associated with endpoints. Detections are early and accurate, forensic evidence substantiates alerts, and as such, the technology is making a material impact on reducing the time an attack goes undetected from initial compromise. Plus, it is straightforward to deploy and manage for organizations of all sizes.

Carolyn Crandall is the Chief Deception Officer and Chief Marketing Officer at Attivo Networks. A technology-marketing executive with over 25 years of experience in building emerging technology markets in security, networking, and storage industries, Carolyn also has a demonstrated track record of successfully taking companies from preIPO through to multibillion-dollar sales, and has previously held leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate.

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Facebook Reports Data Breach, Yet Again!

Facebook Cambridge Analytica Scandal, Facebook data breach

Data breach woes for Facebook don’t seem to be ending. Facebook yet again admitted a data breach involving roughly 100 third-party app developers who had improper data access. In a blog post, Facebook’s Konstantinos Papamiltiadis, Director of Platform Partnerships revealed that app developers had access to user data such as group member names and profile pictures through the Group API.

Prior to April 2018, app developers had unrestricted access to group members’ information. But with changes made in Group API posts in April 2018, this has changed. The app developers now only have limited access to group information such as group name, the number of users, and the content in group posts. For additional information, group members are asked specific permissions that can be accepted or denied as per preference.

According to Facebook’s new framework designed on the guidelines of their agreement with the Federal Trade Commission (FTC), Facebook is required to conduct timely and scheduled audits of all its products and services for factors such as data breach, privacy adherence, etc.

Papamiltiadis said, “As part of our ongoing review, we recently found that some apps retained access to group member information, like names and profile pictures in connection with group activity, from the Groups API, for longer than we intended. We have since removed their access. Today we are also reaching out to roughly 100 partners who may have accessed this information since we announced restrictions to the Groups API, although it’s likely that the number (of developers) that did (access) is smaller and decreased over time. We know at least 11 partners accessed group members’ information in the last 60 days. Although we’ve seen no evidence of abuse, we will ask them to delete any member data they may have been retained, and we will conduct audits to confirm that it has been deleted.”

Just a week back, Facebook had agreed to pay £500,000 (around US$ 645,000) penalty imposed by ICO, the U.K.’s data protection watchdog, for a data breach carried out by a political data firm Cambridge Analytica. It gathered user data and used it to potentially change the outcome of 2016 US Presidential Elections and Brexit.

Owing to this, Facebook announced that it is tightening its security for the 2020 U.S. elections. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.