Saturday, January 25, 2014

Red Sky Weekly (1/25/14): Security is not the point.

I'd like to take a moment and introduce the latest  addition to the Red Sky Alliance team. Steve Hunt joined us last week as our new Director of Community Engagement. Steve is one week into this new world of cyber spies, APT, and organized crime.  I thought you might enjoy his fresh perspective as he jumps in feet first. 

--Jeff

BT BT

Security is not the point

Hi everyone.  This is my first blog as a Red Sky’er.  I’m starting to make the rounds, meeting my teammates and you, our members and prospective members.   Together we’ve had lots of interesting conversations, some of which surprised me.

For example, I heard one member describe his job as managing threats when his boss corrected him saying no, his job was to secure the business.  That got me thinking.

It’s an uphill battle to convince the decision-makers in any business that they need to invest in security.  Why? Because deep down, all professional businesspeople think security is an annoying layer of cost and inconvenience. If you walk in and tell them, “We need more security,” they hear, “We need more annoying layers of cost and inconvenience.”

Getting the buy-in for security products and services today means understanding what drives your company’s security purchase decisions—basically, what is going on in the mind of your bosses.  Fear, uncertainty and doubt are not the cleverest tools to use anymore.  Now businesses want something that sometimes seems like a foreign concept to the security profession: value.  If we security professionals don’t adapt and start answering the questions our business is really interested in, if we don’t stop talking about threats and instead talk about creating value for the business, we’ll never get the green light on new projects and improvements.

Remember, nobody wants security; they want the benefits of security.  That means that the housewife doesn’t want the finest deadbolt on the front door because of the excellence of its engineering or its impact resistance.  She wants a comfortable, happy place to raise her family. Businesses also want something other than security.  If a bank manager has a mandate to reduce expenses related to bank tellers, she has a couple of options.  She could fire all the tellers and lock up all the bank branches, but then the bank would have no interface with its customers.  Or she could take all the money, put it in piles on the street corner under a clipboard that says, “Take what you want, but write it down so we can balance your account.” That wouldn’t work either, obviously. The best solution for reducing teller expenses is to take the money, put in on the street corner locked in a box with a computer attached, and give customers a plastic card for authentication and auditing….

Security was never the point.  The bank had a business objective and achieved it by using some security.  That is how we all should think of security: as a way of helping our companies achieve the goals or value they seek.  Business managers, especially executives at the highest levels of an organization, have a very simple view of security: It is a tool in the corporate toolbox for enabling business.

It’s not our job to secure the network. It’s our job to secure the business.

-Steve



Saturday, January 18, 2014

Red Sky Weekly (1/18/14): IRnomics 102: How much will Lifelock for 110 million cost?

Between 2009 - 2012, Target underwent an enterprise-wide forklift upgrade of their entire payment processing systems. Roughly 1700 stores (~360,000 employees) and their entire backend, were refitted, moving from a proprietary system to a system of integrated systems, virtualization, and third party processes. Few IT personnel are left in the stores, and likely no information security personnel.

According to their annual report, Target realized $2.9 billion in net revenues in 2012. I’ll be interested to see what the ‘13 and ‘14 reports look like.

There are costs to the business. Target is only one example.

Nearly any 'corporate' CISO knows the experience of asking  'the business' for money. It's part of the job. The corporate CISO becomes the vendor, having to prove his/her worth. How many times have you gone to one of those business units and hit them up for money to fund your infosec operation, only to be asked "what do I get for it?"

Welcome my friends, to the world of sales... you now have a new customer, and best friend!

Treat that internal VP like an external customer.

Become an internal entrepreneur. The formula is actually pretty simple to say but slightly harder to do. It’s why not everyone makes it to the ranks of the CISO. Here’s what you do...

  • Make that internal VP a company hero. When you do your job, it should make him/her look good.
  • Communicate. Find things and tell him... preferably before everyone else does.
  • Don't take all day about it. Be right, be brief, and be gone.
  • Use the momentum of that small win to find opportunities to find more.
  • Become the trusted advisor. You'll get your money.
  • It works.

A few months ago I had the opportunity to tell a CISO that one of his business units was leaking data. In fact, I gave him a bit more. I told him that the business unit in question had purchased a multi-million dollar computer aided drafting/manufacturing application from another company.  I told him that the business had purchased it several years ago, and since then, they've been losing data.

We believe the application is probably toast, and since installation, has been sending data home to someone else... important stuff. 15 Gb of important stuff that we know of. Likely a third or so of those drawings were re do's of previous work, drafts, or miscellaneous clutter, but for arguments sake, let's call this a 10 Gb loss. Let’s also assume that each drawing takes one engineer, one eight hour day to produce, not including R&D, corrections/QA, etc... 1Mb = 8 hours of labor (with me so far?)

We had hundreds of drawings. What's it worth? Let's do some math…

  • 1 Gb = 1000 Mb, therefore 10Gb = 10,000 Mb
  • Let's assume each drawing was 1Mb in size (1 Mb seems reasonable)
  • If 1Mb = 1 day to produce, then 10,000 Mb = 10,000 days, or 80,000 hours of work.
  • If true, this company lost nearly 45 man-years of work!
  • Depending on the cost of your people, this could represent $4 to 5 million dollars in labor.
  • I'm betting that for every 1Mb of drawings, there's a month (more or less) of engineering time behind each. This loss, could potentially mean an actual loss of roughly 2,400,000 hours of technical R&D, drawing, QA, and possibly, post-integration upgrades that have been lost.

So what’s the value to this business?

This business (that VP) probably wants to know that they're losing intellectual property, at risk, or will find themselves in the headlights.  And more importantly,  how can they take care of it, quickly, efficiently, while still doing business, not losing face, not be investigated, and continue to keep a high goodwill (reputational) value with their current and future customers.  The business gets paid on sales and margins. Infosec takes away from margins. So, how does the corporate CISO handle this issue?

Every business wants three things:

  • What’s going to hurt them?
  • What do they do about it (as inexpensively as possible)?
  • What can you, the CISO show them that will prove their investment in your team helped reduce their costs to produce their goods or services, or made money for them?

In my own case, we started an “APT” shop years ago. We got about a million dollars from the corporate CISO, and another $3 mil from one of the other businesses. They developed tech that a lot of people wanted... and and when the check came, they became our highest value customer. The budget didn't need to grow much to keep us going, but the value resulting from the relationship built on that "highest value customer" premise ended up funding my former team (started in 2006) for almost 10 years... it's still going, and stronger than ever.

We've been getting this question a lot lately.

How does an information security shop get funded in light of advanced attackers, who hunt and kill so skillfully and so quietly?  My formula is actually quite simple. If you're a CISO, and you need to find funding, go read Dr. John Kotter's 8 Steps to Leading Change. It's a simple model, based largely on common sense and intuition, but written down to allow you to actually follow a process (I need process!) It basically says this.. find the first thing you can do. Be successful, and use the momentum to build more champions, find more opportunities, and continue to act. It's the same process in dealing your business unit customers.. find the first thing. Hit it out of the park. Use the momentum to find number two. Don't strike out.

1800 man years of labor.. gone.

110 million Lifelock accounts.

BT BT

Thursday night we hosted about 25 ISSA members in the New Hampshire Chapter. It was a great night. Thank you all for coming! Interesting to me is that we (Red Sky) has members all over the world, but only two in all of New England, and one of them is in New Hampshire, so it was really great to be able to show off a little bit to the local infosec teams.

We're in the throes of analysis. We've probably had a dozen calls on the Target breach, and although we did publish a report for the Red Sky members, we don't post anything externally, and we don't comment to non-members. We're keeping our fingers in it, and have come to our own conclusions on the subject. We're updating our reporting to the members as we speak. I guess first to press wins.. and first to out an attacker gets some sort of prize. We're not worried so much about that. We'll take another day or two, and get a detailed report posted to the membership.  BZ to iSight for getting this out.. Nice job!

Ok folks. That's it for now.
Until next time, have a great week!
Jeff


Saturday, January 11, 2014

Red Sky Weekly (1-11-14): 'IR'nomics 101 (Incident Response Economics 101)

I met with a venture capital company yesterday. We hadn't really thought about meeting with funding sources until this week when one of our incoming members asked if we'd like of have a conversation. Why not? You just never know where new members or referrals, or possible research/analysis for the lab might come from.

I prepared five slides. On the first slide, we described the problem that we solve. The extemporaneous version goes something like this:

Companies everywhere are having their computers broken into.

They lose credit cards, business information, privacy data and intellectual property… all at very high costs in terms of money, reputation, and business operations. In fact, in 2012 we ran what my former boss would call a 'gin and tonic' survey. I asked the question of several dozen CISOs "what did the last targeted or APT attack cost you to clean up?" The smallest number was $1.9 million. The highest was $10 million. Ponema Institute last year reported an average of $1.4 million.

The VC didn't believe the numbers. He couldn't understand how response might cost so much. I don't think he thought I was making it up, but he just had no idea why. 

So let's try this.. for the money guys, business guys, or for you CISOs out there that have to communicate this to your CIO or C-suite, I'm caling this post 'IR'nomics 101.

First let's level-set the field. You need to understand a few variables. In every case, dozens of variables go into even the most basic detection and response. Here are just a few:
  • Heterogeneity - Every environment, even the small ones, are going to be heterogeneous. Chances are you'll have mobile, cloud, connections to sales staff, possibly manufacturing systems, BYOD.. and if you've acquired another company to allow growth, you've acquired their heterogeneity as well, leaving you with a heterogeneous system of interconnected heterogeneous systems. And worse, you don't acquire companies for their impeccable network hygiene, you buy them to make money. And when they stop, you divest. 
  • Complexities in layers (of heterogeneous defense in depth): So now that you understand the heterogeneity in your environment, consider the infosec posture that you've either built, haven't built, or inherited through acquisition. If you've not been through the forklift security upgrade following your first oh sh*t moment, I'm betting your security posture wasn't built purposefully, it was built on the fly to accommodate growth... if at all.
  • Autonomy of businesses: The terms 'division', 'sector', or 'business unit'. All mean the same thing.. autonomous units of business operations. And do you know where the Presidents or VPs of these business operations report? Not to the CISO! They get graded on revenues and margins, not on their impeccable network hygiene. And you know what? There's a good chance your security team (if you have one) doesn't have eyes on all of these autonomous businesses. In fact, I can guarantee it. 
  • Geolocation and connectivity: Even with a system in a building down the road, geolocation adds cost. Administration, monitoring, security and response all require travel, or, having local help desks, administration, and likely at least one local security person. 

Without considering maturity of the team, skill levels, situational awareness, and many others, you understand a small sample of the variables associated with 'IR'nomics lesson...

Let's use 1000 computers for our example. I've operated in the 100,000+ computer space, but those numbers are staggering and my VC friend will absolutely not believe those numbers.. so let's keep it smaller for now.

In our example, the CIO (there may not be a CISO yet) gets a call from the FBI (our call came from NCIS), telling us that there's a problem. So you download a host based tool to check your systems --CarbonBlack, the Maddrix tools, Mandiant (FireEye?), or one of the others. And on your first run, what do you find? You're gonna want a drink. Your stomach will hurt and you, as the CISO will fear for your job. You're going to have at least 10% (this is being REALLY conservative) of your computers being reported compromised.  

So let's assume 100 computers are now being reported compromised. What next? Here's the typical work flow:
  1. Locate the machine: Typically the security team will want a copy of one of the machines, so they'll run it down. This almost always takes time. The scanners don't necessarily give you the location of the computer, but you'll probably look in a global directory of some sort, or possibly call HR. However this happens, it's probably going to take a few hours to locate the first offending device.  
  2. Pull it off line: This isn't as simple as walking into an office and unplugging a machine. In larger companies you may have to call a help desk or a desktop team, to make sure that first employee is taken offline. Maybe this is another couple of hours required by either your own, or another department. Regardless, it costs money. 
  3. Bring it back to the office to tear it apart and figure out what's going on: Here's where the fun starts. Unless you're planning on burning down the machine and rebuilding (as many do), you're probably going to want to know what caused the scanner to flag. Is this real? False positive? How bad is it? How do we keep it from happening again? The first machine gets a day or so of attention. In my last job, the average seemed to be about three days of intrusion analysis in total. This number will drop with experience, but three work days is probably about right.
  4. Moving forward: Now that you know what cause the problem, you've got to come up with a strategy to fix it. In most cases, this will absolutely be a team sport. You still have 99 other machines that you've not looked at, in various parts of the company. 100 machines offline is going to really hurt. Maybe you take a weekend for the clean up. You'll have your entire IT and Infosec teams on board. You'll probably burn and reload all 100. You'll generate rules for your IPS, add a tool or two to your network; maybe reconfigure some security controls. Depending on the response, this can get really expensive --especially when companies don't bring in consultants who've been through this before --and usually they don't. 
Bottom line.. one of our members (who tends to measure everything) says that his average cost to clean up a desktop is about $10,000. The average server cleanup cost is about $40,000. So even in this very simple example, using even basic numbers, the cleanup of this 100 computers, assuming a mix of desktop and servers, $1 million in response time is quickly realized. Now add in strategy, communications, network changes, responses added to intrusion prevention systems, HIPS, antivirus, etc... and we've not even considered losses, fines, or financial remediation for losses of privacy information, credit card data, intellectual property or long term competitiveness. $1.4 million (per Ponema) is an easy number to swallow.

Now consider this. Even the most sophisticated companies will face at least one of these breaches per month. Most say they have at least one every week. And if you've not been through it before, you're more likely to deal with as many as three to five every day

The sky is not falling.

Every company goes through a maturation process. It's probably better described as a growth spurt. (baptism by fire?). All companies start out as consumers of intelligence. Their security team will go to the Internet and start digging for places to get help. Or maybe (the smart companies) will hire a consultant who'll tell them where to get data (usually indicators of compromise). You'll consume as many IOCs as you can get. You won't care about the story behind them. You'll implement them without thinking. And after a while, you'll start producing your own. You'll want to know who's doing it to you. You'll start digging for more information, people to talk to, and you'll share war stories over beers. You'll build an informal network of co-miserates. Comiseration will quickly turn to sharing intelligence and tips. And you'll get better at detection and response. And soon, these events will be your new normal. Those targeted events will become routine. You just do it. 

The idea behind threat intelligence sources is that you can significantly reduce the cycle times discussed above by comparing notes with others. Some folks don't mind doing it on open forums, Google groups, etc. These are usually free sources of good raw, tactical information, and the conversations can often times tip you off to the latest trending attacks. Others, maybe those with regulatory concerns, concerns for intellectual property or just those who don't want to show their cards on the Internet want to get their intelligence in more private locations. Bankers don't like to talk openly to other bankers about a cyber breach if they think there's a government regulator in the room. Healthcare, Energy, Defense, and many others have similar concerns. So they come into Red Sky. They ask questions, compare notes, and share information. And in those conversations, help each other diagnose happenings on their networks. 

The rest of my elevator pitch?


...And there’s a seemingly endless supply of places you can buy or download ‘cyber indicators’ – pieces information that can help you know if you’ve been broken into or protect yourself from future break-ins. But how do you know which of those you should use? Which ones are any good? Which ones are used to protect your type of business? to use to protect yourself from the ones most likely to strike today? Tomorrow? …or the ones most likely to do the most damage to your business?
That requires context. Context comes from intelligence and analysis.

Red Sky and Wapack Labs offer that contextual information that can help the security team decide what to protect against today, then tomorrow, then next week.

Until next time.. 
Have a great weekend!
Jeff



Saturday, January 04, 2014

Red Sky Weekly (1/4/14): "Ya know what we're missing Jeff? Indicator aging."

"Ya know what we're missing Jeff? A way to clean out the old indicators! We need indicator aging processes!"

Indicator aging.. this is one of the questions we get asked ALL of the time. And I've been asked for MANY years... "How do you qualify indicators and clean out the old ones?"  When companies harvest hundreds of thousands of 'IOCs' every month, how do they qualify the good ones over the not so good? When is an IOC outdated? How do you know?

Great questions all. Heck, even my own staff asks this question..  

Here's the deal. Targeted attackers don't pull out the good stuff until they need it. 
  • This week we answered questions about new variants associated with a TTP from early 2012.
  • Every now and again we see WIN XP malware pop up, or better yet, WIN XP VPN! If you've not had the realization yet, nearly every remote access solution associated with Windows XP is compromised. And every now and again, we see them pop up --especially for users who simply don't want to pay for the upgrade (BIG mistake).
If you're using Windows XP SP1 (nobody should be running Windows XP anymore, but if you are...) you're probably suffering silently because you haven't upgraded... or worse, and probably more likely, you're suffering unknowingly. But none-the-less, attackers will use just enough to accomplish their task(s). As soon as you upgrade to SP2, the attacks take on a slightly more complex nature, using attacks designed to get them into SP2 machines. We're in a cat and mouse game.. the cat gets smarter, but so does the mouse. In fact, I sometimes wonder if mice learn faster than cats!

Think nobody uses XP anymore? I wouldn't bet on that. In fact, we came upon a video about six months ago, of an attacker breaking into an ATM. He did it by crashing the underlying OS and going from there.. what was the underlying OS? Windows XP. And what's worse? The bank had just installed the same ATMs in an entire chain of stores.

What about computer aided manufacturing, carousels used to supply parts to manufacturing processes? Robotics? In many cases, the machines that control manufacturing processes run VERY old systems --I've seen them as old as Windows 3.1 and 95.. simple controllers with no networking to speak of. But when these machines get upgraded, often times the simple act of upgrading the OS or patching the current system voids the warrantee on these VERY expensive devices. 

How many times have you gone into your local auto parts store and laughed out loud when you saw the DOS screen that they use to check for the bracket that you need to fix your muffler? Heck, I almost fell out of my chair when I saw the nursing terminal used at the local hospital. Wanna know why healthcare records are at risk? Because hospitals can't afford to upgrade beyond the old systems.  In fact, I saw this in action at two hospitals in the last few weeks. Amazing but real. 

How many consumer electronics are built on Linux? Networking gear, infrastructure, appliances? Yup.. many are stripped down Linux. How often do they get patched and upgraded? Internet of Things and controller area networks going into cars, planes, trains and ships... how old is the code used in these devices, and when was it upgraded last? There's no telling.

So, I ask again.. when should we clean out (ahem) old targeted XP IOCs from our dataset? When XP is no longer used --globally. When all of the code is automatically upgraded to stay current on security patches. Or better yet, when we no longer need them (like YEARS from now?!).

So, when should we clear out are older indicators? 

How many security vendors are built into YOUR environment? My guess? A couple of hundred (probably more!) from bottom of the stack to the top. How many of them are maintained at the most current version?

"Ya know what we're missing Jeff? A way to clean out the old indicators! We need indicator aging processes!"

Here's the problem.

There are some great pieces of work out that help users understand and correlate the all of this information. The taxonomies being developed to classify, prioritize and share indicators are heavy on


detail and give you the ability to sift through all of the information for the things you need. As an example, I've included the architecture of a Mitre developed taxonomy called Structured Threat Information Exchange (STIX for short). STIX is a great way of characterizing all of the information that might help analysts determine the best prioritization for their own use, but at the same time, the idea of its use can be quite overwhelming. It certainly is not for the new user. Why? Look at the blocks. For every block on the diagram, data must be collected, normalized, stored, retrieved, analyzed and correlated. Wow. So today, the likes of Mitre and a handful of large companies with R&D shops, who can afford to build it and integrate it are using this framework. In a few years when the data is more complete, we'll be really glad we have this. For now however, if you need to parse out old indicators because you believe they're no longer relevant, well, I hope you don't filter out the wrong ones. 

What do we do? We keep them all. We present our indicators in full context with a .csv formatted list. If you are a Windows XP SP1 shop, you need XP SP1 IOCs. We don't normally get down to the point where an IOC can be sorted by affected operating systems or components, but it can be quickly derived by going one step further in the kill chain processes. 

My XP SP1 example is highly simplified of course, but in a world of global IOCs being pushed to individual companies, the answer is simply this... you, as the owner of risk management in your organization must decide how to prioritize the indicators and how you deploy protections. Nobody else can do it for you. 

Need help? Ask someone. 

BT BT 

We ended the year with a flurry of activity. Who said the Holiday Season is time to slow down?! We were FLAT OUT! 
  • 12/31/13 - FS-ISAC: Our first piece of work product was delivered to the FS-ISAC on New Years Eve Day, marking the start of what we hope to be a great long-term relationship between Wapack Labs and the FS-ISAC. The submission was a priority intelligence report that was posted to both FS-ISAC and to Red Sky Alliance members, offering warnings of impending New Years Day attacks. 
  • 12/31/13 - Fusion Report 31: In November and December of 2013, Red Sky received information regarding an APT campaign that leveraged a previously unobserved malware. Several infection vectors were observed including the leveraging of Microsoft Word vulnerability CVE2013-3906, a malicious JPG file, and a LNK downloader. The majority of activity appeared to be targeted at Japanese companies; however several additional variants were uncovered and may have affected non-Japanese entities. This report detailed information on the leveraged malware, exploit vectors, and observed targeting. Red Sky has named this new malware family for future tracking and attribution. As with all Fusion Reports, Red Sky members were provided with snort and yara rules, and a list of LM Kill Chain formatted indicators.
  • 12/28/13 - Priority Intelligence Report: In November and December of 2013, Wapack Labs analysts identified a US internet service provider partnering with two Chinese Virtual Private Server (VPS) providers whose infrastructures were used in the Word Zero-day (CVE-2013-3906) attack against a second Asian (non-Chinese) company and a second target, a member of the Red Sky Alliance. Wapack analysts examined and mapped this infrastructure to discover an abundance of malicious activity associated with these infrastructures. Wapack analysts also determined that the US company's Chinese partners are well-connected to US networks, and host well-known hacker clientele. 
  • A Wapack Labs Assessment of Risks to Information Security In IcelandFinally, Wapack Labs delivered the final version of a 40+ page study at the request of an Icelandic Information Security partner Syndis. The study offers a third party perspective of issues associated with Iceland's use as a offshore hosting location for foreign enterprise. The report is being delivered by Syndis to Icelandic officials as we speak, and will be posted in the Red Sky portal sometime next week.
  • ...and we added one new large enterprise financial company to the membership. Welcome!
Whew!
I'm going to the gym. It's been a long week!

Until next time,
Have a great weekend!
Jeff

Saturday, December 28, 2013

Red Sky Weekly (12/28/13): Wrapping 2013 and moving into 2014

There seems to be a never ending line of experts reading tea leaves for 2014, and not wanting to be left out, I'm going to post my own momentarily.

First, I should tell you, I think of risk not only as a negative, but also, what offsetting factors are present. These are positives, and in many cases, positive influences also have risks. In all cases, risk is subjective and needs to be classified and prioritized. Where are you going to spend your money next year? (Of course I hope some of it is spent with Red Sky Alliance!) Regardless, I've ranked my 2014 thoughts in priority order based on presence of leading indicators, probability of the incident actually happening, impact if it does, and the kind of risk (i.e.: Technology, Operations, Enterprise, etc.). Some of these are higher level risks, some are technical, others focus on the actual operation of the business and effects posed by the government or competitors. I've not published the full detail here (because of blogger limitations), but will happily send it to you if asked:

BYOD Exploitation goes mainstream:  
  • High Confidence; Probability Imminent; Impact if successful: HIGH
  • Bring Your Own Device, while sound from a cost perspective creates massive security, and legal challenges. BYOD, especially in the SMB/supply chain enterprise space is a highly sought-after target for access to banking, espionage (military, corporate, competitive) information and infrastructures. BYOD targets are more likely creative or knowledge-based individual contributors. In fact, we in Red Sky see this every day. We track the exploitation of several BYOD targets who are victimized in the hopes their machines may be used for business as well as personal use. This is a LARGE opportunity for attackers to exploit the enterprise's weak link -the user at home where security messaging is often forgotten. 
Exploitation of non-routable space:  
  • High Confidence; Probability: Imminent; Impact if successful: HIGH
  • As users continue to click, code will continue to be installed in the enterprise. Virtual machines and proxy use will grow as a vector of direct log-in into organization networks. This is not new for those who've been dealing with APT/targeted attacks for the last few years, but for those of you reading VirusTotal today for the first time, wondering why that sample you submitted calls home to 8.8.8.5:53 (Google's DNS) and 10.0.0.1:137... well, sorry folks, you're about to earn your t-shirt.
Exploitation of DNS as a VPN:  
  • High Confidence; Highly Probable; Impact if successful: HIGH
  • VPNoverDNS, Iodine and other tools are creeping into the threat landscape and have been commercialized as mobile applications as well as more traditional tools. VPNoverDNS has been identified in multiple locations and touts it's ability to exfiltrate data when all other means are blocked. Companies who have high value information, and high levels of security, will always have DNS available to an attacker, and with tools available, the ability to exfiltrate data via DNS becomes a much stronger reality.
As the Cloud grows, so does its exploitation: 
  • High Confidence, Probability: High, Impact if successful: MEDIUM/HIGH
  • The only reason this doesn't carry a higher risk ratings is because not all have moved to the cloud. Cloud adoption by corporate users continues to grow. As such, so does exploitation of cloud.
Espionage moves to Sabotage:
  • High Confidence, Probability Medium, Impact if successful: TBD
  • Tools used for exploitation can, and have been used for sabotage. Stuxnet created an atmosphere where cyber as a means of destruction should be considered a normal part of the new threat landscape and organizations must be prepared. 
  • Add to this the fact that the need for a military to protect the masses in cyberspace no longer exists, and the idea of NGOs, hactivism organizations, and individuals have far greater cyber firepower than ever before. 
Exploitation of Controller Area Networks:
  • Moderate Confidence, Probability Medium, Impact if successful: TBD
  • Vehicles with OBD have accessible computer ports available today. Last year a DEFCON presentation discussed hacking an automotive CANBUS in the car; another (not at DEFCON) built a handheld device to unlock and start vehicles. This, we believe, is a strong pair of leading indicators, and the topic of vehicular controller area networks will only expand during the course of 2014 and beyond.
    • Areas of concern: Automotive, Aerospace, Trains, and Maritime vessels
The Gloves are off. Cyber is officially a form of warfare:
  • High Confidence, Probability: High, Impact in 2014: LOW/MEDIUM and growing
  • While still new, several countries have built or are building offensive cyber warfare capabilities. Earlier in the year, countries that had a cyber warfare programs in place were the US, UK, Canada, Israel, Germany, China, Iran, Pakistan, South Korea, DPRK, South Africa, and possibly Cuba (informally through partnerships with others).  As of this moment Brazil, Argentina, and Venezuela have begun developing their own cyber capabilities.  Russia is rapidly expanding its capabilities.  Singapore is currently developing theirs, but not much is known about it. It stands to reason that this escalation will continue, presumably at a much faster pace than the last few years. 
  • Countries will define cyber borders. BRIC nations (Brasil, Russia, India and China) formed a coalition to build isolated networks, and the Brazilians have taken to training other South American countries in the use of Cyber as an offensive tool. 
  • Bottom line: NSA, right or wrong, as well as the dozens of other organizations around the world collecting cyber and other technical intelligence (and there are MANY), have caused massive knee-jerk movements toward encryption, TOR, and other means of protecting communications and privacy in cyberspace. At the same time, countries and NGOs are taking stronger defensive positions and bolstering their ability to both attack and fend off attacks through active defensive measures.... this is going to get exponentially worse over the next few years.
Cyber becomes the business equalizer:
  • High Confidence, Probability High, Impact in 2014: Low, growing
  • As companies realize the escalation of formalized government and NGO sponsored offensive capabilities, criminal activities will also escalate and companies will realize the massive competitive equalizer that is cyber through these criminal activities. Several examples exist where companies are exploited by those who believe they can get away with stealing high tech data, money, etc. Again, a bit of a no-brainer, but this is going to get MUCH worse. Businesses as an operation must consider competitive forces in their cyber defense plans moving forward into '14 and beyond. 
  • Not only must the criminal impact be considered but the goodwill impact must also be considered. Goodwill actually carries value on the financials, and must include a company's ability to sell based on their investments in information security. Goodwill on the balance sheet will be impacted if the organization is blocked from working with a specific industry segment (government, banking, healthcare, etc.) because of their lack of security or activities. 
  • Need an example? Target is already subject to law suits for losses --and they've not even been quantified yet! Think Goodwill will be affected? Absolutely. While CFOs have not yet fully realized it, this is a new reality... 

Hackers will find alternative means of malware delivery and installation beyond spearphishing, wateringholes, etc. i.e.: light, sound, NRF, S-link, etc.
  • This is actually the softball that I'll toss into the mix. The idea that hackers will continue to innovate should surprise noone, but the ways that they're doing it are actually, IMO, kind of cool! The idea that RSA keys can be cracked over acoustic readings via wireless takes the idea of MASINT to a whole new level. And the thought that computers can be hacked via the speaker and mic on a system shouldn't probably be surprising, and much more complex to do than to think about, but I have a feeling you'll be seeing computer accessories built/sold to cover the mic and speakers.
Enough negativity for now. There are some positives:

First, you've heard me say this before. Now you'll hear it again.. what's old is new again!
  • Companies are learning to protect their jewels! Find what's important to your company, and wrap moats around it. It doesn't always work, but it's a mandatory first step.
  • Risk based models are (finally) popular! Nearly every CISO I talk to is working on processes to integrate threat intelligence into their operation. Why? Because it helps them assess risk! While they may not know it, Infosec is about assessing risk, and risk is derived through threat intelligence (one source obviously). I see this as a VERY positive sign. The security community is changing to intelligence-driven risk modeling!
Highlights from previous years? I've had a few... some right and some wrong.. here are some of the ones I called out last year:
  • I called for heavy VPN usage for exploitation. This has not only come true, but expanded to VPN over DNS, loading virtualized VPN servers in the enterprise, and rent-a-VPN from dozens of service providers around the world.
  • Growth of cross credential usage. Sadly, users still use one password for many accounts. With token and PKI exploitation growing daily, the ability to credential systems is growing harder and companies, because of costs, complexities, and the lack of understanding stick with what they know --passwords... of course the least secure of all. 
  • Growth of government concern and the need for SOX-like reporting. Whadya know.. the DFAR rule came out this year!
  • BYOD was on the radar, as well as Android exploitation. Both are discussed above. 
I'll close out with this... 2014 is going to bring some amazing challenges. One of the things we've been talking about (a lot) are the most common exploitation vectors, the TTPs associated with them, and targeting associated. If you're interested in having this discussion --prioritizing your work, understanding common attack vectors, etc., or would like a copy of previous years predictions, drop me a note.

...until next year...

From the team at Red Sky Alliance and Wapack Labs,
We wish you all a very happy, prosperous and secure New Year!
Jeff

Saturday, December 21, 2013

Red Sky Weekly (12/21/13): Been there, done that, got the t-shirt!

Been there, done that, got the t-shirt is a saying that ran like water flowing across the bow of any of the many ships I spent time on during my early career. It means what is means. Been there, done that, and when we finished, we passed out t-shirts with the campaign, operation, or team logo on it. Sometimes the t-shirts are made from pride, sometimes their made to help heal. Sometimes their made to show unity.

Target earned their t-shirt this week. Sorry guys. I actually do know what it feels like to work the better part of the 168 available hours in a week fighting the networks. Thankfully, I was never in the global press because of it! Hang in there. And let me know when the shirts come out. I'd like to buy one! Neither Red Sky or the lab are first line incident responders, but we are tracking this closely. While it's not apparent (yet) how this all came to be, it is widely known that starting in 2009 Target went through a massive transformation where iron was replaced by hypervisors, and the companies in the know [1] published case studies (we have approximately a dozen more) discussing Target, their circumstances.

...until September 2009, Target’s POS systems and asset-protection ran on physical servers. By the second quarter of 2012, the company deployed 15,000 virtual guests running on more than 3,600 Hyper-V hosts across the entire store network. This includes 300,000 endpoints for servers, virtual machines, mobile devices, PCs, and POS registers.” This also includes an asset-protection solution. The list of technologies has had more than 25 CVE-rated vulnerabilities posted in only the last two months.

My point is this...

Networks are complex. Complexity causes pain... not sometimes; every time. Sadly, complexity is a necessary evil... and it's getting worse. 

And it's getting worse fast... far faster than builders and defenders can operate. 300,000 heterogeneous endpoints in 1700+ retail locations with 15,000 virtual machines running more than 3600 Hyper-V hosts. Add to this the "cloud" (I really hate that word!) that is the internal Target WAN connecting all the pieces, the external clouds used by the third party IT providers, the payment processors that connect (presumably centrally somewhere), and all of the other variables that go along with such a massive, geographically diverse, a non-IT oriented retail focused company. Add to that the fact that the third parties who run IT don't hold stock in the company and probably have a slightly less vested interest in their fiduciary requirement for managing the networks than they do in generating revenue from their customer... not a poke.. it's a fact of life.

Sorry Target. My best to you guys.  I'm certain there'll be some good lessons learned coming from this.

And "BZ!" to Krebs. Well done! Nice reporting sir!

BT BT

Next week will be the last blog of 2013. It's been a hell of a year.


  • 37 blue chip companies represented in Red Sky Alliance, with another dozen or so in Beadwindow. We wanted to keep it a small, trusted group. So far, so good. 
  • Thousands of running threads produced more than 40,000 high quality, properly primary sourced, non-watered down APT and targeted event IOCS in nearly 200 analysis products published detailing full context of the incidents; plus over 300,000 products collected from open sources, used for pivoting off the 40,000 analyzed by Red Sky and its members.
  • Wapack Labs opened to handle some of the non-information sharing requests. As an example, we recently delivered a country study that will be used by a governmental organization overseas to help them secure their small nation... good stuff, but not necessarily information sharing related.
It's been a hell of a year indeed. 

Ok, until next week, I wish you the very best holiday season possible. Next week will be our 2014 predictions post, so hang in there.. one more to go and it's on to the new year!

Merry Christmas, Happy Holidays!
Jeff






[1] http://www.microsoft.com/casestudies/Case_Study_Detail.aspx?CaseStudyID=4000009407

Saturday, December 14, 2013

Red Sky Weekly (12/14/13): Bridging the gap from user to analyst to protection


We were having lunch yesterday. Nice place. Sitting at the bar, I noticed two guys sitting next to me... phones going, both had laptops open. The one next to me was reading email in Outlook, and the conversation was all business. I thought, what a wonderful spot to grab competitive intelligence, so I fired up a sniffer just to check out the wireless... open.

Maybe presumptuous, but I passed the pair a business card, told them what I did for a living, and offered a very short, very impromptu, very polite cyber safety lesson on using open wireless access points. The restaurant was packed.

The guy next to me responds "My brother works for Symantec. He talks like you do. I know the risks, but just don't care." I was floored. He explained... "I travel a lot. If my banking or credit cards get stolen, the banks pay. I need access and don't want to pay the tethering fee for my phone."

On the other side of the coin we have analysts who want to analyze everything. They want to know where the guy filled up his car before buying a bag of Cheetos that he ate with his left hand. Every detail counts. Situational awareness is a must.

So how is it that we have such a massive disparity between what Joe (Jane?) consumer does at a bar in a nice restaurant, and those of us who'll spend days analyzing data to try and help those who don't care if they're being helped? (The guy told me he does have Lifelock! Wuhoo!)

At the same time...

We run into so many analysts who analyze for the sake of analysis, and frankly, although I know they're working hard, are really smart, and have great gouge... But sometimes make me really tired! How much of that work actually will keep that unsuspecting, unknowing, uncaring guy from losing control of his computer?

So tell me...
  1. How much analysis is enough? Now that you've pulled that malware sample apart, spent three months analyzing it, and spent who knows how much money, what did you get from it? Would you have obtained the same results by running it through a simple sandbox and recording the results... in about a minute? How do we push these results (fast) to the user in the restaurant?
  2. Attribution: We know who you are.... now what? Gonna have somebody killed? Jailed? Probably not. But if we can recognize the 'swing' of an attacker, and we know who he/she/they are, do we really need to prove it every time? 
  3. What exactly do you need to know? Why? How fast? What defines a priority intelligence requirement?  I've heard two people explain it really well... one guy is the newly named CISO of a medium sized DIB company. He defines priority intel requirements as those things that will most likely  hurt him today. Another holds a weekly meeting where teams nominate priority requirements that then get assigned out through a standardized collection process (I like this process very much!). 
  4. Keep it simple, stupid! Last, but certainly not least, besides the readers inside the government beltway, or those who've been named honorary govvies, how many of you can tell me what a Taxonomy is without looking it up on dictionary.com? How many of you also know what taxonomies are available to you in the cyber realm? I'm watching with baited breath to see which one comes out on top, and when it does, we'll use it, but in the mean time, we prefer the Keep It Simple Stupid taxonomy... The guys over at Lockheed came up with Kill Chain a few years ago.. Not really anything new, but they did a great job. We like it, and we use it. Comma separated value text and not a lot of overhead. It allows a broad audience to be able to read, understand, and use the data for maximum protection.. fast.
Intelligence is supposed to help with futures. Are we spending time on the right activities? Can you show a clear line between the number of analytic hours you spend digging through data and reductions in successful attacks, reduced incident response cycle times, faster forensics or more targeted infosec spend?  How do push this down to that guy at the bar? Change his behavior without sacrificing usability and features?

We've found that in Red Sky, one of the value propositions is the simple recognition of not just IOCS (you can get IOCS anywhere these days), but in the context. IOCs without knowing the sources, and confidence in the sources can mean high false positives, and therefore, high labor costs in your incident response and forensic teams. If you could reduce this cost by simply participating in a crowdsourced, high confidence environment where you know the sources, can qualify the quality through peer reviews of those sources, and can get the data in a usable, keep it simple stupid format, well, why wouldn't you do it??

BT BT

It's been an amazing week.

  • We held our 4th quarter threat day this week. The presentations were AMAZING, covering all kinds of topics from proprietary commercial SIGINT operations to case studies to new tools. Thank you to the host, and for all those who travelled to attend. What a great day!  
  • Next, we sent two press releases out this week. We haven't sent one in over a year, and then bang! two in one week! In both cases, we're partnering with some amazing folks:
    • Wapack Labs is stepping into a cyber threat analysis and intelligence role for the FS-ISAC starting at the beginning of the year.
    • Wapack Labs was chosen by CBTS to assist with intelligence requirements for their customers and CBTS joined Red Sky Alliance 
  • We're delivering TIAD this week, with analytic training in a National Level CERT. My guy is traveling as this gets published, and the team is standing by in Manchester to support. 
  • On Monday we're being visited by another ISAC, and Tuesday a group of techies (and their VC) from MIT.
It's coming up on the end of the year. We've got three weeks before our 2014 rate increase, so if you're spending end of year money, and have a need for great threat intelligence next year, or simply want to make your current small team more efficient, call us! We'd love to show you what we do!

Ok all, until next time, 
Have a great weekend!
Jeff





Saturday, December 07, 2013

Red Sky Weekly (12/7/13): Are we entering a Cyber Arms Race?

It's been a crazy busy week. We processed three new Red Sky membership requests this week, updated a fusion report originally published in May, and posted three new pieces of analysis. On top of that, the Lab inked a deal to handle Cyber Threat Analysis and Intelligence for one of the major ISACs. My week wrapped last night with a Christmas party in DC. I'll take today for a breather, then back at it tomorrow.

One of the things that struck me at the party last night, sitting at a table with a bunch of folks like me, who either do work for the government or have worked for the government were two themes that came up over the really nice salmon -one spoken, and one not.

The spoken? "The (cyber) arms race"

The unspoken? "Disintermidiation"

The "arms race" discussion was not the long-term topic of the evening, but definitely one that stuck with me. The idea is that every country in the world today seems to be running hard to build, at minimum, defensive cyber capabilities. Many are also building offensive capabilities --either organic or outsourced. Regardless, the race is on. Red Sky analysts are tracking the growth of these capabilities for our membership. We have a feeling it's going to become important very soon.

Disintermediation? This is one of my favorite words. I first heard this word in a cyber context when Dave Aucsmith took the stage at the AFCEA conference in Colorado last spring. Disintermediation is an economic term that describes 'cutting out the middleman' in a supply chain. In a cyber context, the idea was that in the era of cyber, attackers will attack victims without the assistance of a military, essentially cutting out the middleman. An October Gartner report offered an assumption that "By 2020 25% of global enterprises will engage the services of a "cyberwar mercenary" organization." (Source: How to Select a Security Threat Intelligence Service, 16 October 2013, Rob McMillan, Kelly M. Kavanagh)

So I think a lot about these two ideas (forces?)... an arms race, plus cyber disintermediation. Wow. Imagine the future. Indicators are aligning and I'm not sure any of us are going to like it:

  • Red Sky is busy, as are apparently other threat intelligence organizations. Companies are beginning to understand that intelligence is important stuff. 
  • Several companies have sprung up in the last couple of years who chase 0-days, touting offensive capabilities. 
  • There are countries in the world that seem to not mind being viewed as the location of choice for launching points of these capabilities. Motivations to do so are economic, political, activist, or any number of other reasons.
  • Many countries around the world are posturing for offensive cyber operations, and I believe the number of countries staging these capabilities will grow significantly over the next few years.
  • At the same time, the labor pool is short, meaning outsourcing will become mainstream in the future, potentially laying credence to McMillan's assumption. 
Here's my concern, and one we talked a lot about last night... my concern is that outside of those who've worked with the government over the last few years know why they have cyber pain today. Those who have not, don't. I've heard those in-the-know referred to as the "one percenters" and those not in-the-know as the "99 percenters".  Beyond the one percenters, the messaging doesn't seem to resonate outside of the Washington circles. This is important stuff... not one person connected to the internet by cell, computer, pad, wristwatch, appliance, or what's being called the "Internet of Everything" will be able to sit out the storms that are coming. The ability to reek havoc has outpaced the ability to defend against it and it's only going to get worse as we move through the stratas of criminal, to espionage, to planned and unplanned offensive cyber.

Interestingly enough, cyber is still viewed by many as a weapon in and of itself.. cyber is only a means of carrying out something more. It's cheaper (and carries a hell of a lot less risk) to hack a computer than it is implant humans to steal information or sabotage. Information is pouring onto the the Internet in massive buckets from devices you've probably never thought about before, but those information poured onto the internet by nearly any of these devices offer a smart analyst real information.. or a smart operator a real opportunity.  

So, 
  • People in DC are talking about the idea of a 'cyber arms race'. So whether it's real today or not, because people are talking about it over dinner in DC means it's probably coming.
  • The world is becoming even more wired through "Internet of Everything". Are you going to be ready when the coffee pot in your office break room is used to listen in on conversations or become an attack relay into other machines in your company?
  • Analysts are assuming cyber mercenaries in the very near future. Just like the DC comments, it's in writing. For me, this is the second indicator that people are talking about it... and for every comment, the likelihood of it becoming true grows.
  • And, the unspoken, disintermediation, in a cyber context is very real. 
Yes, we are in an arms race. And yes, the landscape and rules of engagement of warfare in the future are going to change significantly. 

Wow. That was a real buzz kill. 

So what are companies doing about it? Threat Intelligence is one of the hottest topics in cyber today. Knowing, or at least having an idea of what's coming allows the smart, informed CISO to make good risk-based decisions about what to fix today, tomorrow, and at least have a plan for next year and the year after that. These roadmaps will likely change. They always do, but the idea is this.. talk with others. Compare notes. Make an informed decision about where all of this is going, and base, your long term strategy on good data, not noise.

That's where Red Sky Alliance comes in. Tactical intelligence is published routinely.. a couple of times every week. They come in the form of Priority Intelligence Reports and Fusion Reports. Strategic information comes in the form of Intelligence Analysis Reporting and GEOPOL studies of the world's offensive growth curve. 

Not comfortable participating in the portal? Call the lab. We'll do it for you. 

Drop us a note. We'll be happy to show you what we do.

Until next time,
Have a great week!
Jeff