Home Blog Page 81

4 Immediate Measures to Execute After a Cyberattack

CEO, cybersecurity, CISO, Future of the CISO

Whether it is a global pandemic or the new normal, cybercriminals always find ways to target organizations and individuals for valuable digital assets. Most organizations fall victim to cyberattacks despite having robust security defenses in place.  From leaking sensitive data, phishing attacks, selling user data on the dark web to threatening victims for ransom, threat actors leverage various attack vectors to pilfer sensitive data or obtain access to business-critical infrastructure.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Most companies avoid disclosing a data breach or cyberattack incidents citing penalties from law enforcement bodies, loss of customer trust, reputational damage, and financial impact. Organizations should always have an incident response plan in place to get the compromised networks back and recover from the damage as early as possible.

Here are the four immediate steps to follow when dealing with a cyberattack:

1. Contain

The primary step is to immediately contain and isolate the critical systems. Temporarily suspend all the systems after discovering the attack. This will help stop the spread of the attack to all business-critical networks. Look for any strains of ransomware or malware on the affected systems and isolate them from the main network immediately. Also, changing the passwords of all critical accounts will help mitigate the risks. A well-organized approach of isolation and containment will certainly help regain control of the affected systems and eliminate the risks.

2. Report

Reporting the cyberattack to the customers, clients, and especially to the law enforcement authorities immediately after it happens will create a sense of trust and transparency in the organization.

Most enterprises are often judged based on their incident handling capabilities during a ransomware or data breach attack. Organizations could encounter severe negative consequences for any delays or coverups in disclosing the incident. Besides, companies are liable under various data privacy regulations to report any security data breach incident and can attract a huge penalty from regulatory agencies if failed to report.

Last month, the Netherlands Data Protection Authority slammed a fine of €475,000 (around $560,860) on Booking.com for failing to report a data breach that affected the personal data of thousands of users.

3. Investigate and Recover

It is necessary to have an effective disaster recovery plan for organizations to restart the affected business operations smoothly. Report and engage with law enforcement authorities to investigate the incident to find out the cybercriminals responsible for the attack. Organizations can even hire a digital forensic team to inspect the security incident to understand the actual cause of the attack, what data, and how many have been affected.

Last year, Microsoft, along with government CERTs and its partners across 35 countries came together to legally disrupt one of the world’s nefarious botnets called Necurs. The disruption took place after the U.S. District Court for the Eastern District of New York issued an order enabling Microsoft to take control of the Necurs infrastructure.

4. Remediate

Organizations must learn from their mistakes after sustaining a cyberattack. Analyze the attack to know if there are any unpatched vulnerabilities or security loopholes in the organization’s cybersecurity posture. Come up with a set of efficient remedial measures to boost security and deal with the potential cyberattacks in the future.

Towards the end of 2020, when the SolarWinds supply chain attack took the digital world by storm, FireEye released a free tool, dubbed Azure AD Investigator, on GitHub to help alert security administrators to artifacts that may require further review to determine their legitimacy.

Wrap Up

No individual or company is 100% immune to cyberattacks. Organizations must bolster their security standards to defend against evolving cyberthreats. Cybersecurity precautions like encouraging employees to use strong passwords, training them to identify phishing, and other attacks ultimately improve organizational security.

About the Author:

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

 

High Volume of Security Alerts Emotionally Overwhelm 70% of SOC Teams: Trend Micro Study

soc

The talent crunch in the cybersecurity industry is by now a known fact globally. The issue is far more serious in under-developed countries. A report last year stated that a lack of skilled and qualified cybersecurity workforce meant a sweeping majority of West African banks were left vulnerable to cyberattacks including bank card fraud, phishing, intrusions, etc. However, a new study from Trend Micro suggests that it is not just the staffing shortage, but an overwhelming number of security alerts are equally responsible for the stress and fatigue of SOC and IT teams in organizations.

in Security Alert Volumes = in Emotional Stress

Work and stress are always interlinked, and this is quite evident in Trend Micro’s study too. A striking majority of 70% of respondents complained that their personal lives were being emotionally impacted by their work of managing IT threat alerts. This is further proven by the fact that 51% of the surveyed individuals feel their team is being overwhelmed by the volume of alerts and another 55% admit that they are no more entirely confident about prioritizing and responding to these alerts.

These findings are corroborated by a recent Forrester study, which found that “security teams are heavily understaffed when it comes to incident response, even as they face more attacks. Security operations centers (SOCs) need a more effective method of detection and response; thus, XDR takes a dramatically different approach to other tools on the market today.”

This fatigue caused by the high volume of alerts leaves many SOC managers irritable with friends and family and work, forcing them to:

  • Turn off alerts or walk away from their computer (43% do so occasionally or frequently)
  • Hope someone else from the team steps up (50%)
  • Ignore what is coming in entirely (40%)

Of all surveyed respondents, 74% said that they are already dealing with a breach or expecting one within the year. Given the estimated average cost per breach of $235,000, the consequences of such actions could be disastrous and need immediate attention.

Bharat Mistry, Technical Director for Trend Micro, said, “SOC team members play a crucial role on the cyber frontline, managing and responding to threat alerts to keep their organizations safe from potentially catastrophic breaches. But as this research shows, that pressure sometimes comes at an enormous personal cost. To avoid losing their best people to burnout, organizations must look to more sophisticated threat detection and response platforms that can intelligently correlate and prioritize alerts. This will not only improve overall protection but also enhance analyst productivity and job satisfaction levels.”

Related News:

NCSAM: Hybrid Workforce and its Cybersecurity Implications

Use SOC 2 Examinations to Keep Your Security Program in “Chek”

How SolarWinds Hackers ‘Nobelium’ Used Constant Contact in Mass Phishing Campaign

SolarWinds Microsoft

Nation state-backed cyberattacks have become widespread more than ever.  They often leave a bad impression on the cybersecurity readiness of a nation. For instance, the infamous SolarWinds supply chain attacks targeted several U.S. government agencies and compromised the networks of nine government agencies and 100 private organizations globally. While investigations are still ongoing, Microsoft recently revealed that Nobelium, the Russian-based cybercriminal group behind the SolarWinds hacks, is now targeting government agencies, think tanks, consultants, and non-governmental organizations globally.

Nobelium targeted over 3,000 email accounts of more than 150 global organizations. Around 25% of the targeted organizations were involved in international development, humanitarian, and human rights work.

“Many of the attacks targeting our customers were blocked automatically, and Windows Defender is blocking the malware involved in this attack. We’re also in the process of notifying all of our customers who have been targeted. We detected this attack and identified victims through the ongoing work of the MSTIC team in tracking nation-state actors. We have no reason to believe these attacks involve any exploit against or vulnerability in Microsoft’s products or services,” Microsoft said.

Sophisticated Email-based Attack

Microsoft stated that the Nobelium group launched its attack by illicitly gaining access to the Constant Contact account of USAID, a service used for email marketing. Using this, the attackers were able to send phishing emails with a malicious link that, when clicked, downloads a malicious file used to distribute a backdoor dubbed NativeZone. The backdoor allowed attackers to launch various cybercriminal activities from stealing data to infecting other computers on a network.

As per Microsoft, the attacks from the Nobelium group are notable for three reasons:

  1. When coupled with the attack on SolarWinds, it’s clear that part of Nobelium’s playbook is to gain access to trusted technology providers and infect their customers.
  2. Nobelium’s activities and that of similar actors tend to track with issues of concern to the country from which they are operating.
  3. Nation-state cyberattacks aren’t slowing. There is a dire need for clear rules governing nation-state conduct in cyberspace and clear expectations of the consequences for violation of those rules.

“The Microsoft Threat Intelligence Center (MSTIC) observed NOBELIUM attempting to compromise systems through an HTML file attached to a spear-phishing email. When opened by the targeted user, a JavaScript within the HTML wrote an ISO file to disc and encouraged the target to open it, resulting in the ISO file being mounted much like an external or network drive. From here, a shortcut file (LNK) would execute an accompanying DLL, which would result in Cobalt Strike Beacon executing on the system,” Microsoft added.

“Attacks on manufacturing and the supply chain increased during the pandemic”

X-Force research

According to the IBM Security 2021 X-Force Threat Intelligence Index, in 2020 threat actors sought to profit from the unprecedented socioeconomic, business, and political challenges brought on by the COVID-19 pandemic.

In an interview with Brian Pereira, Editor-in-Chief, CISO MAG, Prashant Bhatkal, Security Software Sales Leader, IBM Technology Sales, India/South Asia takes us through the findings of the report and comments on the top threat vectors, security trends, and the most targeted sectors.

Edited excerpts from the interview follow:

What threat vectors have been dominant during the pandemic? What kinds of attacks are escalating? And what does the X-Force research tell us about the reasons for these attacks?

We witnessed that targeting and tactics shifted through 2020 from spamming consumers to attacks on manufacturing and the COVID-19 supply chain.

The top three attack types observed by X-Force are:

1. Ransomware represented 23% of all 2020 attacks (a 7% increase since 2019.

2. Data theft represented 13% of attacks (160% increase in attacks since 2019).

  • Emotet attacks, largely in Asia, made up 46% of the data theft activity X-Force research remediated in 2020. X-Force uncovered new features in Emotet malware samples such as anti-analysis capabilities, indicating that Emotet continues to pose a threat to organizations globally.
  • Manufacturing bore the brunt of data theft attacks accounting for 33% of all data theft incidents. Energy followed at 21% of attacks, with finance and insurance third at 17% of data theft attacks.

3. Server access attacks represented 10% of attacks (233% increase in attacks since 2019).

  • The exploitation of a path traversal Citrix flaw largely drove this trend (CVE-2019-19781).
  • 36% of the server access attacks X-Force observed targeted the finance and insurance sectors, with business services (14%), manufacturing (7%), and health care (7%) also getting impacted.

What were the most common “Entry Points” into victim environments, as observed by X-Force research?

The top three initial access vectors observed by X-Force are:

1. Scan-and-exploit led to 35% of attacks, compared to 30% in 2019.

  • Known vulnerabilities continue to soar with the total number of vulnerabilities reaching nearly 180K in 2020 (17.5K new ones just in 2020).
  • Scanning and exploiting requires few resources and can be automated and scaled to target a wide variety of victims, which may account for why this vector saw such a high volume, while defenders struggle to keep up with patching.
  • Attackers exploited the Citrix vulnerability CVE-2019-19781 in almost 60% of January 2020 attacks alone that X-Force responded to, and was directly related to 15% of incidents in the first half of 2020.

2. Phishing led to 33% of attacks, compared to 31% in 2019.

  • Despite its slight drop, phishing remains a top concern for legitimate organizations, with spear phishing and spoofing remaining effective ways to infiltrate environments without raising suspicions of authoritative organizations.

3. Credential theft led to 18% of attacks, compared to 29% in 2019.

  • Vulnerabilities may have been attackers’ primary vector of choice, but credential theft remains a major threat.
  • A possible cause of this is the increasing use of MFA and behavioral analytics/biometrics, making unauthorized use of credentials more easily detected/blocked.

Can you briefly comment on some of the trends indicated in the X-force research report?

Cybercriminals Accelerate Use of Linux Malware – Linux currently powers 90% of cloud workloads and adoption is only accelerating amidst shifting business needs during the pandemic. Almost 70% of organizations using cloud services today plan to increase their cloud spending in the wake of the disruption caused by COVID-19 (Gartner). Attackers follow the trend: Of all the Linux crypto-miners Intezer saw in 2020, over 13% was new code – attackers are exploiting the expandable processing power that cloud environments provide and incurring heavy cloud usage charges on organizations. Of all the Linux ransomware and Trojans, 6% was new, previously unobserved code. Attackers who once were focused primarily on Windows malware are now expanding to Linux, scaling these attacks to increase effectiveness. From just nine Linux-related malware families in 2010 to 56 in 2020. In 2020 alone the report (Intezer) observed a 40% increase from the previous year.

Investment in Open Source Malware Threatens Cloud Environments – Attackers may be looking for ways to improve their margins — possibly reducing costs, increasing effectiveness, and creating opportunities to scale more profitable attacks. X-force highlights various threat groups such as APT28, APT29, and Carbanak turning to open source malware, indicating that this trend will be an accelerator for more cloud attacks in the coming times.

Pandemic Drives Top Spoofed Brands – During the onset of the pandemic, more than ever, people turned to technology tools and social networks to stay in touch with friends and family during an isolating time. With more companies shifting to collaboration tools to maintain their operations amidst the pandemic, spoofing followed suit. We saw attackers impersonate tools that were used as alternatives to in-person activities from work collaboration, to paying for goods, and to ordering online.

Cybercriminals Disguised as Celebrity Brand – Social engineering techniques have been successfully used by scamsters and the trend continues – we have seen scamsters target the trust and demand from consumers to lure them to visit sites disguised as well-known brands.

Vulnerabilities Surpass Phishing as Most Common Infection Vector – X-force observed that more attacks last year used vulnerability exploits to access victims surpassing phishing as the most successful infection vector.

Ransomware Groups Cash in On Profitable Business Model – The most successful ransomware groups in 2020 were focused on not only stealing and leaking data but also create Ransomware-as-a-Service cartels and outsourcing key aspects of their operations to cybercriminals that specialize in different aspects of an attack. Ransomware also employed double extortion tactics that helped the malware families to further increase their profitability. These various tactics together have helped Ransomware groups to become more profitable in 2020.

Ransomware dominates 2020 as the most common attack vector. And looking at the incidents that occurred this year, it looks like ransomware will continue to be a major security issue not just for private organizations but also for governments. What is the industry doing to fight ransomware? Can we expect to see some new standards (for decryption) emerging this year to fight ransomware?

Organizations can take the following measures to protect against ransomware:

  • Backing-up data remains essential – While defenders may not have the same leverage with back-ups when dealing with double extortion tactics, this remains a baseline security requirement they must follow.
  • Encrypt your data – Encryption removes the criminals’ leverage because they can’t sell or leak your data to encourage you to pay. So, if a bad guy gets their hands on your data and it’s unexploitable to them, they can’t make money off it, they’ll move on.
  • Monitor what kind of cloud storage/file sharing solutions is being used in their environment. Most companies use a single solution, so anything that is being used that is not that solution would be worth investigating and blocked if possible.
  • Leverage AI to identify and contextualize suspicious activity or access to data:
    • Use the principle of least privilege to limit who has access to sensitive data to those that absolutely require it. They should also have archiving processes in place for data that no longer needs to be active on the network.
    • Protect highly privileged accounts that are essentially allowed to go anywhere in the network and access any type of data. It’s essential to have Privileged Access Management (PAM) and Identity & Access Management (IAM) in place.

Per the report, which sectors are commonly being targeted? What do you observe specific to India?

In India, finance and insurance were the top attacked industry in India (60%), followed by manufacturing and professional services with threat actors targeting organizations that could not afford downtime owing to the nature of their services.

RELATED STORY

COVID-19 and the Current Cyberthreat Landscape in India


About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Researchers Uncover Four New Malware Tools Designed to Exploit Pulse Secure VPNs

Chinese actors target telecom

Unpatched security flaws always cause a potential threat to organizations. Cybercriminals often target unpatched vulnerabilities to gain access to victims’ data and networks. Recently, cybersecurity researchers from FireEye revealed that Chinese threat actors are exploiting the vulnerabilities in Pulse Secure’s Virtual Private Network (VPN) and Secure Connect (PSC) devices. Pulse Connect Secure VPN provides TLS and mobile VPN solutions to organizations globally.

The researchers found intrusions by Chinese advanced persistent threat (APT) groups, dubbed UNC2630 and UNC2717, targeting various sectors including government, defense, technology, transport, and financial entities in the U.S. and Europe.

“We now assess that espionage activity by UNC2630 and UNC2717 supports key Chinese government priorities. Many compromised organizations operate in verticals and industries aligned with Beijing’s strategic objectives outlined in China’s recent 14th Five Year Plan. While there is evidence of data theft at many organizations, we have not directly observed the staging or exfiltration of any data by Chinese espionage actors that could be considered a violation of the Obama-Xi agreement,” FireEye said.

Tradecraft of UNC2630 and UNC2717

According to FireEye, both UNC2630 and UNC2717 threat actor groups display advanced tradecraft to avoid detection by modifying file timestamps, edit, or delete forensic evidence like logs, web server core dumps, and files staged for exfiltration.

“They also demonstrate a deep understanding of network appliances and advanced knowledge of a targeted network. This tradecraft can make it difficult for network defenders to establish a complete list of tools used, credentials stolen, the initial intrusion vector, or the intrusion start date,” FireEye added.

Threat actors are inconsistently using a combination of tools and command and control IP addresses with four additional malware families specifically designed to manipulate Pulse Secure devices.

The newly discovered four malware families linked to UNC2630 and UNC2717 include:

  1. BLOODMINE – A utility for parsing Pulse Secure Connect log files. It extracts information related to logins, message IDs, and web requests and copies the relevant data to another file.
  2. BLOODBANK – A credential theft utility that parses two files containing password hashes or plaintext passwords and expects an output file to be given at the command prompt.
  3. CLEANPULSE – A memory patching utility that may be used to prevent certain log events from occurring. It was found in close proximity to an ATRIUM web shell.
  4. RAPIDPULSE – A web shell capable of arbitrary file read. As is common with other web shells, RAPIDPULSE exists as a modification to a legitimate Pulse Secure file. RAPIDPULSE can serve as an encrypted file downloader for the attacker.

Attackers are leveraging these four malware families to harvest credentials and sensitive system data, allowing arbitrary file execution, and removing forensic evidence.

Warning from CISA

Last month, the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Homeland Security (DHS) warned about the actively exploited vulnerabilities: CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, and CVE-2021-22893 in Ivanti Pulse Connect Secure (PCS) VPN appliances on their network systems.

Supply Chain Attacks is APAC’s Biggest Application Security Challenge: Barracuda

application security, API, API Security

For modern businesses, application security has become an essential concern. Every organization uses a triage of web, software, and mobile applications to serve customers and execute internal functions. However, as per the latest research from cybersecurity firm Barracuda, organizations across the Asia Pacific (APAC) are struggling with a multitude of application security challenges including bad bots, broken APIs, and supply chain attacks. Let us have a look at some of their top concerns.

 Key Highlights 

  • On average, 38% of the respondent organizations in APAC were successfully breached twice in the past 12 months as a direct result of an application vulnerability.
  • With 46%, software supply chain attacks are regarded as the top application security challenge in APAC, closely followed by vulnerability detection and bad bot attacks.
  • 51% of APAC respondents quoted that the attacks through a web application are the highest AppSec risk for your organization.
  • Bot-based attacks are the most likely contributor to successful security breaches resulting from application vulnerabilities in the past 12 months.

Overall, the findings indicate that more work needs to be put in towards protection against application security threats. The report reveals that the range of application security-related challenges may extend far beyond difficulties in securing multiple attack vectors.

Supply chain attacks have been making rounds since the SolarWinds attack. Its ripples were felt by the world, and this is evident in Barracuda’s survey too. 46% of APAC respondents identified software supply chain attacks as their top application security challenge. This was closely followed by vulnerability detection at 43% and bot attacks at 39%. Another 37% stated that securing APIs was also a considerable challenge when it comes to application security.

application security challenges in APAC
Image Credit: Barracuda

Other Findings

The research also revealed web application vulnerabilities and zero-day vulnerabilities as the primary causes of the majority of the security breaches (55%) in the last 12 months. Also, an API-based application is significantly more exposed than a traditional web-based application, due to the way it is deployed with direct access to all the sensitive data for the application. This makes 68% of the APAC organizations believe that security is a primary concern while deploying APIs.

Mark Lukie, Systems Engineer Manager at Barracuda, Asia-Pacific said,

Applications have been steadily rising as one of the top attack vectors in recent years, and the rapid shift to remote work in 2020 has only intensified this trend. Organizations in APAC are struggling to keep up with the pace of these attacks, particularly newer threats like bot attacks, API attacks, and supply chain attacks, and they need help filling these gaps effectively and urgently.

Earlier, another survey from Barracuda delved deeper into the adoption trends for public cloud, network and application vulnerabilities, and a variety of security concerns related to cloud technology. Read the complete story here.

Related News:

Scammers Use Bots and Automation to Make Cyberattacks Effective: Barracuda Report

Most Phishing Emails Originate from Eastern Europe: Barracuda

Two New Attack Techniques Discovered to Alter Certified PDFs

Altering certified PDF Documents, FIN7 Hackers

It is better to be proactive in finding loopholes in the field of security. Fixing or discovering unpatched vulnerabilities or any security flaws before cybercriminals exploit them will certainly help protect critical data. Threat actors often come up with new attacking techniques to compromise targeted individuals or networks. Detecting such potential attacks in advance will help mitigate the damage.

Recently, cybersecurity researchers from the Ruhr University Bochum have unveiled two new attack techniques on certified PDF documents that could allow an attacker to change the certified content and replace it with malicious content without altering its digital signature.

The two new attacks, dubbed the Evil Annotation Attack (EAA) and the Sneaky Signature Attack (SSA), exploit the flexibility of PDF certification by adding annotations to certified documents. While the EAA initiates the attack by altering a certified document by adding a malicious code, the SSA manipulates the appearance of the certified content by adding overlaying signature elements to a document. The researchers claimed that an attacker could change the legitimate content in 15 of 26 viewer applications by using EAA and in eight applications using SSA by using PDF specification compliant exploits.

“By inserting a signature field, the signer can define the exact position of the field, and additionally, its appearance and content. This flexibility is necessary since each new signature could contain the signer’s information. The information can be a graphic, a text, or a combination of both. Nevertheless, the attacker can misuse the flexibility to stealthily manipulate the document and insert new content,” the researchers said.

According to the research, 15 of 26 PDF applications were found vulnerable to EAA attacks, allowing an attacker to alter the content in the PDF document. Multiple issues were found in Adobe Acrobat Reader (CVE-2021-28545 and CVE-2021-28546), Foxit Reader (CVE-2020-35931), and Nitro Pro, which could lead to EAA attacks. In addition, Soda PDF Desktop, PDF Architect, and six other PDF applications were found vulnerable to SSA attacks.

“Although neither EAA nor SSA can change the content itself – it always remains in the PDF – annotations and signature fields can be used as an overlay to add new content. Victims opening the PDF are unable to distinguish these additions from regular content. And even worse: annotations can embed high privileged JavaScript code that is allowed to be added to certain certified documents,” the researchers added. 

Sanitize PDFs to Avoid Risks

Cybercriminals often focus on harvesting sensitive data from poorly sanitized PDFs. PDF sanitization is the process of removing classified and sensitive data from a protected document before its publication. An analysis found that security agencies do not sanitize PDF docs before sending them to others. The analysis collected a corpus of 39,664 PDF files published by 75 security agencies, from 47 countries, to find out the quality and quantity of data leaked from these PDF files.

5 Cybersecurity Approaches All Businesses Should Consider

Penetration Testing, continuous testing, security testing

In Googling the “worst year in history,” you might come across the year 536. It was a year dubbed “the worst year to be alive” by a medieval scholar because of extreme weather events. This was probably due to a volcanic eruption early in the year, creating lower average temperatures in Europe and China, resulting in crop failures and famine for yet another year. Future scholars may look at 2020 similarly, for myriad reasons, including the pandemic.

By Aaron Reason, Senior Director of Information Security, Consolidated Communications

But how will 2020 be evaluated in the eyes of technology watchers and cybersecurity experts? The year 2017 competes, with the WannaCry ransomware attacks, one of the largest cybersecurity attacks in history. But looking back at 2020, in the way of cybersecurity, it was undoubtedly a fast-paced and hectic year, with a multitude of new threats, some created by the pandemic. More ransomware gangs formed, and they upped the stakes from simply encrypting systems to holding data hostage. 2020 was chaotic, with new vulnerabilities that empowered cybersecurity criminals.

As the rest of the business world makes strides toward normalcy, the prognosis for network security is a challenging one. Consolidated Communications foresees more attacks and the potential for more disruption than ever. If you are like me, this underscores an exciting opportunity. Cybersecurity forces us to stay sharp and is continually challenging us to be better at what we do.

Ounce of Prevention Equals a Pound of Cure

Regardless of business size, attacks will be initiated in the same way, including phishing (payload delivery or credential theft), a vulnerable internet-facing host, drive-by download of malware due to work from home self IT, social engineering, or one of a dozen other methods.

In 2021, the critical tasks remain: We will need to stay on top of tuning our SEIMs, keeping up with our vulnerability scanning and mitigation programs, making sure hosts on our networks have proper endpoint detection and response, and maybe even building out new runbooks for our SOARs (Security Orchestration, Automation, and Response). There are a million things to keep our security engineers and us busy, so I wanted to mention a few ideas which might be a bit outside the box.

The top five cybersecurity approaches you should consider are:

1. Teams/Slack Notifications for Critical Issues

This is an easy win. Figure out some malicious activity indicators and alert your top security engineers via post to a Critical Channel when they trigger. This goes beyond everyday SEIM offenses, and there are ringer alerts for the most critical events for which time is of the essence. Challenge your team to develop a few indicators each, such as misuse of service accounts (service account being used on a non-approved machine), or alert them when a regular user account tries to RDP into a domain controller from a non-bastion host. You could build a firewall policy for known command and control IPs/URLs, and if it hits, have your firewall post to the channel. When your EDR has a critical alert (menterperter, C&C, PowerShell abuse), post it to the channel. If you have SOAR, these alerts might be easy; if not, a little python and API goes a long way.

2. Start Learning Incident Response

This will enable you to know when to cash in on your IR retainer hours and when not to. We have all had those moments when you see something that might not amount to much, or it could be the beginning of a hectic day/week/month. Having some tools in your toolbox to know the difference between a false alert and a potential breach is helpful. Maybe your EDR has everything you need to do forensics, or perhaps you can spend some time building out a Velociraptor instance for querying machines and dumping memory. Regardless of how you do this, it is worth the time spent learning some forensics. IR dollars are expensive, and they can disappear quickly; if you can tackle the basics on your own, it will be well worth it.

3. Harden Your Critical Infrastructure

We spend much time on all the security tools and policies and sound designs to kill the attack chain…To read the full story, subscribe to CISO MAG.

This story first appeared in the January 2021 issue of CISO MAG.


About the Author

Aaron ReasonAaron Reason is the Senior Director of Information Security at Consolidated Communications. Before his work at Consolidated, he led a team providing cybersecurity services for government contracts and has worked in education, utility, federal and nonprofit verticals. Aaron is skilled in SIEM, Networking, Data Center, Cyber Security, DDOS Mitigation, MSSP, and Information Assurance.

Disclaimer

All views are personal and attributed to the author(s). The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

The Wild Evolution of Ransomware

Ransomware attacks, LockBit Ransomware

This past year, I have spent much time researching and writing about ransomware attacks as well as conducting ransomware simulation exercises. I’ve come across many fascinating and even bizarre facts that I wanted to share with the CISO community.

By Tari Schreider, C|CISO, CRISC, MCRP, ITILF, Senior Analyst at Aite Group

Doctor Ransomware, I Presume

It was 32 years ago this past December that the first acknowledged ransomware attack occurred. In 1989, a ransomware operator using the alias of “The PC Cyborg Corporation” mailed 20,000 attendees at the World Health Organization (WHO) AIDS conference a ransomware-laden floppy disk. The computer attack used social engineering by packaging the disk as AIDS education materials. Although the code (Trojan) used in this first ransomware was relatively primitive, the result was the same, pay a ransom to decrypt your data or else. To receive decryption instructions, users had to send $189 to a Panamanian post office box. The brain behind this first ransomware attack was Dr. Joseph L. Popp, a Harvard Ph.D., an Evolutionary Biologist. His master plan was to send two million infected floppy disks using various hijacked mailing lists of medical professionals and institutions. It did not end well for the good doctor. He was arrested at Amsterdam airport in 1990, deported to the U.S., and detained by the FBI. Under a warrant by Scotland Yard, he was extradited to the U.K. to stand trial for blackmail. However, he was found mentally unfit for trial.

Eerily similar to the tactics used by Dr. Popp, ransomware operators today are using the COVID-19 pandemic to social engineer users to open infected malware through email. An email with a tagline referencing pandemic, stimulus, or vaccine proves too alluring for users not to click open. Ransomware operators feel that attacking companies in the vaccine supply chain would lead to quick and unfettered ransom payments. Just as we did not heed the lessons from an earlier pandemic, the Spanish Flu, we equally ignored the first ransomware lesson. As you will read, ransomware is evolving, but unfortunately, we are not. This example is a what was once old is now new again moral.

Jurassic Park

Leave it to science, they say. Just as in Jurassic Park, where scientists genetically created dinosaurs — mad scientists created the architecture for ransomware. Well, not really, but that was fun to say. One could say that ransomware is a Non-GMO (non-genetically modified organism). Ok, that was fun too. But in reality, ransomware was born from scientific curiosity when a former hacker met with an academic cryptographer at Columbia University in 1995. Here the pair pondered if they could accomplish a data kidnapping. They referred to it as cryptoviral extortion, the basis for ransomware today. The following is the attack scenario they presented at the 1996 IEEE Security and Privacy Conference:

“In cryptoviral extortion, the attacker generates a key pair for a public key cryptosystem and places the “public encryption key” in the cryptovirus. The corresponding “private decryption key” is kept private. The cryptovirus spreads and infects many host systems. It attacks the host system by hybrid encrypting the victim’s files: encrypting the files with a locally generated random symmetric key and encrypting that key with the public key. It zeroizes the symmetric key and plain-text and then puts up a ransom note containing the asymmetric ciphertext and a means to contact the attacker. The victim sends the payment and the asymmetric ciphertext to the attacker. The attacker receives the payment, decrypts the asymmetric ciphertext with his private key, and sends the recovered symmetric key to the victim. The victim deciphers his files with the symmetric key.

At no point is the private key revealed to the victims. Only the attacker can decrypt the asymmetric ciphertext. Furthermore, the symmetric key that a victim receives is of no use to other victims since it was randomly generated. (Young & Yung, 2017, p. 24).

Wow, right? Yes, this is essentially the same framework that ransomware operators worldwide use to this very day…To read the full story, subscribe to CISO MAG.

This story first appeared in the February 2021 issue of CISO MAG.


About the Author

Tari SchreiderTari Schreider is a distinguished technologist and nationally known expert in the fields of cybersecurity, risk management, and disaster recovery. He is currently a Senior Analyst with Aite Group covering cybersecurity technologies and practices for Aite Group, LLC. He was formerly Chief Security Architect at Hewlett-Packard Enterprise and National Practice Director for Security and Disaster Recovery at Sprint E|Solutions. Schreider is an instructor for EC-Council where he teaches advanced CISO certification and risk management courses.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Vendor Relationships: Soft Skills for CISOs

ZingBox

A CISO has the responsibility of building a solid relationship with their peers and staff. Building this rapport takes time and is built on mutual trust, open communication, and mostly similar goals – organizational success. The Certified Chief Information Security Officer (C|CISO V1 and V3) program builds on these skills. Vendor relationships need similar attention.

By Chuck McGann, COO, The McGann Group

Every organization has some level of dependence on, or interaction with, a vendor or vendors at some point. Most use vendors all the time. It doesn’t matter what the sector, business function, or geographic location. This article provides advice and tips for addressing requirement needs, vendor selection, negotiations, and role and responsibility swim lanes.

I’ll state this upfront: This article will not delve into these areas but provide some helpful tips to consider, whether in your public or private life. This is not a primer on the procurement process, developing Statements of Work (SOW), Service Level Agreements (SLA), or Master Service Level Agreements (MSA).

The definition of Vendor Management from Gatekeeper: “… we define vendor management as the process by which relationships with your vendors, and the documentation that underpins them, are actively created, monitored and cultivated to ensure that yours and their business objectives are achieved. It’s both a formal and informal process.” View   www.gatekeeperhq.com/blog/what-is-vendor-management for details.

My additions to the accepted definition focus on overall value, creating a high level of trust, Strategic Plan inclusion, Tactical accountability, and total value added to all parties in the relationship. Yes, there is contract language to ensure compliance with the Terms and Conditions, but where is the “trust” accountability of the relationship measured? Thus, the change to Vendor Relationship Management – it is a relationship, not just a business transaction.

Soft Skills in Vendor Relationships

A CISO can leverage the Procurement office for many of the details referenced in the definition. It’s important to understand how the CISO interacts with vendors to ensure the trust relationship is protected and the strategic roadmap for the organization is followed, to deliver the expected tactical solutions interfacing with existing tools, technologies, and processes.

The C|CISO (V1 and V3) course presents Vendor Management in Domain 5 and provides a good review and solid foundation for Vendor interaction and contract management, some of this information is referenced.

Our goal of this article is to advise on the development of the “Soft Skills” a CISO needs in a Vendor Relationship – trust, strategic alignment, tactical implementation/integration, all at a high level. How does a CISO do this? Through communication, by making the vendor a partner in “your” success. It’s important to recognize the partnership. Your success is the vendor’s success – you each benefit from a trusted working relationship.  A botched alignment resulting in installation, integration, or relationship failures impacts the vendor in many ways, not just with your organization.

Vendors are a part of everyday life – we expect service for compensation – whether that is delivered in some finance system, cash, or using a barter system.  We identify a need, develop requirements, seek out a viable supplier, and “make the deal.” This can be a one-time “arrangement,” but in business, it is likely to be frequently recurring contract agreements and for longer terms – three to five years!  Some complementary relationships last decades.

Contract language should exist to ensure satisfaction with our dealings and overall transactional relationship.  Putting this into perspective, it’s important to understand the limitations of the “managing” of the relationship.  There may be limited alternatives to service providers and therefore boundaries on what can be “managed.” The CISO must guard against putting the organization in a potentially perilous position – avoid sole source and custom-built solutions where possible.  Sole source providers have the leverage, and custom-built solutions are costly to maintain and replace once ingrained into your infrastructure.

Forging Vendor Relationships

Vendor Management starts with the Requirements Statement – and that includes the typical – when, where, why, and how.  The “Who” is what we expect to generate after an evaluation of suppliers to determine the capabilities of those wishing to satisfy these stated needs! When building out the requirements you need to consider your current state – do you have existing trusted providers that can add on services to meet your needs, or will these new needs interface with your existing technologies and process and enhance some current capability?

The Vendor relationship starts with the development of the Requirements Statement but starts in earnest with the selection.  You might be asked to provide input and if you have a personal relationship with the vendor, steer clear of any discussions, utilize other team resources to avoid perception issues.  Meeting with the vendor support team is critical – adherence to the Statement of Work and the Service level agreements become the measuring tools for performance of both teams. Positive performance assessments add value to the relationship.

The Relationship can start before the procurement process – frequently from a meeting at a conference, trusted introduction, or peer usage recognition.  The first meeting between Vendor and CISO can either make or break the relationship and start the trust factor meter.  This first impression is critical and infrequently challenging.  Each party goes into the encounter with a different set of filters, and not all of them accurate or of significance to the transaction – be professional.

CISO Strategies for Vendor Relationships

CISOs need to be open and honest on their needs and biases, and how they think the vendor can support those needs while interfacing with the existing environment. Vendor evaluations…To read the full story, subscribe to CISO MAG.

This story first appeared in the January 2021 issue of CISO MAG.


About the Author

Chuck McGannChuck McGann is currently the COO of The McGann Group, small security consulting LLC in Raleigh, NC. He is a former CISO for the U.S. Postal service retiring in late 2014 (27 years of service) and moved on to the private sector as a VP and Chief Security Strategist for CRGT and then Salient CRGT – starting The McGann Group, LLC in 2017.  Chuck’s focus is to educate potential and current Security Professionals through his affiliation with EC Council and Learning Tree International, delivering multiple courses for senior leaders and practitioners.  Having spoken at numerous conferences and workshops, he continues to help grow the profession and educate the next generation of Risk Managers and Security Leaders in the skills needed for success. He holds an MBA, and an undergrad degree from the University of Massachusetts in Computer Science and Management, two Associate Degrees.  His Certifications include the CISSP, C|CISO, CISM, and IAM certificate.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.