Saturday, April 06, 2013

Red Sky Weekly: “woshihaoren” (我是好人)

“woshihaoren” (我是好人)

I LMAO'd last night when one of the members told me this story, so I had to pass it along. I'm going to clean up his language a bit. I'm crusty, and he's crusty, and the story was conveyed over a beer and cigar at local watering hole. I know some of the color might be lost, but here goes anyway...
This guy (I'll call him Jack), is the CISO of a company that does about a billion per year in sales, and although I won't tell you what the company makes, I'll say they're a high tech.

Jack has a problem. APT actors basically live in their network. Heck, they come to work nightly when Jack isn't there, stick around for an eight hour shift, and log in and out as they need to capture new information. It's bad. Jack is good.. very good.. but has a small team and although they work very hard to keep actors out, sometimes it just doesn't work out that way.
So one day, Jack gets pissed. He knows the actors use a tool to capture passwords from machines and when they do, they have free reign to do what they want. Worse yet, they capture credentials all the way back to last reboot. So Jack --a really pissed Jack, knows someone is going to read his (what should be private) password. So Jack changes his password, leaving a message for his attacker. You won't be able to translate this in Google, and for those of you who know me, I don't usually pull these punches, but in writing, on a blog, I'm doing my best.
The CISO's taunting new password:

Limp [insert sailor slang for 'Male Sexual Organ'] [insert ‘Racial Slur’]

The password, after the next ‘shift’ (24 hours later) was changed to:

“woshihaoren” (我是好人) --Spaced out Wo Shi Hao Ren means "I am a good person."

So this tells me two things. First, yes, someone is living in the networks and not afraid to interact directly with this (incredibly technical) CISO and his team, and second, OPSEC isn't always a concern --especially when they know they've got you and have free range of movement in your networks.

This isn't the first time I've heard about attackers living in a network, and I'm sure it won't be the last. This guy has been sharing some of the best intel on attackers that I’ve ever seen. While it’s true he’s got a real mess, it’s also true that he knows how to capture data, record actions, and repel when he does find them. Unfortunately he can’t be cloned (yet), and can’t work 24/7, but without a doubt, Jack is one of the best and he isn’t afraid to show others what he’s got going on, or help them with their own problems.
This is what Red Sky is about --neighbors helping neighbors.

BT BT
Now some really cool stuff. We published two reporta --a Fusion Report (FR13-009), and our version of an Intelligence Information Report, an Intel Analysis Report (IAR13-004).
FR13-009: This week we released FR13-009, our 9th in-depth fusion report this year. FR13-009 is an analysis of our "APT1". Granted its not the Mandiant "APT1", but it's number one our list. As always, our report included roughly 15 pages of analysis, including detailed analysis of a widely used remote access trojan and its infrastructure. The report include several pages of indicators, and gave members two new Yara rules and a snort signature to drop into their defenses.

IAR13-004 is an unfinished intel report summarizing yet another VPN service linked to hackers. This paper was provided for situational awareness in an effort to provide Red Sky Alliance with the ability to monitor and warn against future threats and provide data to compare with past intrusion analysis.

Our first Intern graduates to employment! Our first intern is now employed with one of the best companies going. Bruno got hired as a Regional Intelligence Analyst with a global payment processing company in Wilmington, DE. He started on the first of April and so far, so good. I've been told by the CISO of another member company that he'll take as many of our interns as we can give him (they’d made an offer too). In fact, I've got a good Marine coming off active duty that I'm probably going to refer to him soon, but for now, Bruno had some really nice things to say about his experience with Red Sky. Bruno peer reviewed in the top 10% of our membership, rated by folks in a group of mature infosec teams dealing with some of the hardest problems. If you’re a student, want to learn to be an analyst, and think you can contribute and rank out in peer reviews, drop us a note.

That’s it for now!
Have a great week!
Jeff

Friday, March 29, 2013

Red Sky Weekly - 3/29/13


Wapack Labs setup is nearing completion. There’s a bit of painting left to do, but we’re ready to open the doors on Monday. Wapack has already had a couple of folks walk through the doors, including the Data Security Partner for one of the largest law firms in New Hampshire, and a mom who wanted to know if we could restore pictures from a broken disk. We won’t be doing any criminal work yet, but have solid processes and capabilities in host and network based forensic analysis, cellular/mobiles/Pads and malware analysis. I’ll be in Tokyo, but Rick will be in the lab with the team. So if you’re local to the Manchester Historic Mills area, we’re in the Waumbec Mills (250 Commercial St., Suite 2013) right next to the UNH campus.  

SecureWorld Boston: On top of getting payment systems set up, building furniture, and buying trash cans (I think I have swiper's elbow.. and I can't tell you the workouts I've endured just running my Amex through so many times!), I spent two days at SecureWorld Boston. I had probably two dozen people come up and tell me they’d heard of Red Sky Alliance! Our friend Al Koch, from Norman was there with a former coworker of mine from my days at DC3, as were Red Sky's friends from Solutionary. This was my first SecureWorld, but it won’t be my last. I enjoyed reconnecting at a local level. Boston is a blast, and the security community is on fire. I’ll be giving a threat presentation at the next ISC2 Boston Chapter meeting on May 9th, and have begun reconnecting through ISSA and Boston Infragard. It’s funny. I participated in these groups years ago, and now I’m running into many of the same folks that I knew from then. I ran into two old coworkers from my PwC days (they're not kids anymore!), several folks from the local FBI office, and I've got a half dozen new companies that want to talk about joining Red Sky!

STIX! We had the long-overdue opportunity to reconnect with Mitre this week. We’ve been wanting to do a bit more with STIX but hadn’t really had the resources to do it. Mitre has been doing a lot of work in development of STIX, and was gracious enough to offer assistance in “STIX-ifying” Red Sky. This will be welcome addition, as some of the members already started heading that way. We’ll remain on Kill Chain, but we promised Richard and Tom at DHS that we’d work to support STIX, so we’ll do our part.  

New Members: We sent membership kits out to two new incoming members --one Federal Agency and a new large enterprise mid-west Chemical Sector company. Our second year renewals have started to roll in, and so far so good. No drops!

Analytics: This weekend we will be releasing our 8th fusion report for 2013. FR13-008 will be our second infrastructure focused report and will detail two related subnets that have been linked to a wide range of APT activity; and we been working hard developing our third Intel Analysis Report to assist one of our members with a bit of tailored reporting. We had a question asked. It was interesting, and pulling the thread lead to some interesting observations. I hope the community likes the reporting!

Easter Egg: This is to see who's paying attention! The Easter Bunny has a special treat for you! WhoisRecon is coming soon from Wapack Labs Want to be an early adopter user?  Want to get on the pre-release list? Just send the Easter Bunny a note and ask.


It’s been a great week!
...off to Tokyo!
Jeff

Saturday, March 23, 2013

Announcing Wapack Labs!

I sat on a panel this week in Manhattan --a group of bankers, all very good at what they do. At the end of the panel, we were asked for one closing remark. I always offer the same bit... "We're learning to fight submarines." The intent is to say that (and you've read this before in my blog).. during WWI, we lost a ton of ships to German U-Boats. But by WWII, we not only got better at detecting them, but we had our own and fought back! The Air Force and Army guys could probably come up with their own analogy, but in my way of thinking, APT is just the new threat. We (the royal we) will learn how to better cope as we move up the learning curve.

During my drive back from NYC to New England, however, I came up with a new analogy... 

Think about this:

Imagine you, going to your office on Monday morning. Probably (I hope), you work in a nice building with lots of windows, new furniture.. comfortable, right?

What if that building was owned and controlled by your closest (and most aggressive) competitor? 

Cameras in the building are set to capture screens and documents. Every time you do work,  someone (a competitor) is looking over your shoulder, feverishly scribbling notes. The onlooker videotapes keystrokes, credentials, financials, work habits, documents, customer lists, etc. Now imagine that you've got only a small team of security guys,  unable to keep them out. They stand at the main entrance and do their best to block the competitors from entering. They stand in front of each desk and in every hallway, but alas, they look like everyone else... nice haircuts, good suit, shined shoes. Heck, their credentials work!... Security can't always spot them. They just keep finding ways into the building... You get the picture, right? 

How would you feel? Would you do anything differently? You'd probably be upset, guarded, feel like you've lost a bit of privacy, maybe afraid for your company's future?

What would you think if I told you this is exactly what happens when you are victimized during a targeted attack. If the attack is successful, most unprepared companies quickly lose control over their networks. That receptionist in the front office really thought those kittens were cute. She must have watched that video a hundred times when nobody was looking. She'd received it from someone else in the company via email. It must be OK, right? Immediately following her first click, a bug launches. Keystroke loggers are used to capture credentials. Remote access trojans (RATs) are installed and start phoning home. Once the attacker gets the call, he begins to capture documents and other work product. Various 'credential rich' sources are harvested for employee directories, and interesting employees are monitored routinely.  Those systems that are critical to the operation are rendered useless because of all of the bandwidth being used by the attacker. You've got only a small team of security guys (if any), often times they can't keep these guys out. Security monitors at the main entrance, the pipes leading to every computer, and every individual computer, but alas, the intruders look like everyone else. Heck, their credentials work!... Security can't always spot them. They just keep finding ways into the networks... 

Getting the picture? This is probably the most accurate analogy that I've come up with to describe what's happening in computing today.. and it's not just big companies. It's not just in the US. Every company I talk to today has 'virus' problems. Most believe that their  firewall will keep the networks safe. Even some of the biggest companies are blind to current happenings, but this is a global problem and it's getting worse. Every company in the supply chain of a larger is a target, and I'd say with high confidence, compromised and don't know it.

Who's at risk?


Are you a law firm, financial institution, OEM manufacturer (especially transportation - auto, air), chemical (pharma, oil & gas) company or IT
  • Have you ever noticed your network connection slowing and didn't know why?
  • Has your IT team found malware or viruses that have no, or very few results in VirusTotal or other online research sites?
  • Have your nighttime computer routines failed or timed out (this may be an indicator of nighttime activity on your networks).
So what to do about it? Where do you find out what to do about it?

Join Red Sky Alliance today. If you're a private company, and need to know more about what's happening on your networks, or want to compare notes on technical analysis and intelligence with other really smart people in real time, Red Sky Alliance is for you.

Are you a smaller company? Federal civilian government agency? State? Local? Join Red Sky's Beadwindow Portal. Beadwindow offers the same level of service as Red Sky, but with slightly different views on who may participate at a lower price point, and best of all? Everything is UNCLASSIFIED! There's no need to find a SIPRNET (or worse) to download information from NTOC. Your folks don't need security clearances to access our Beadwindow Portal. And when you call, ask about Sequester pricing! Beadwindow costs WAAAYYY less than a week of White House tours!

Just need help analyzing data? Need forensic services? Don't want to build your own team? Or maybe you just need someone to take some of the more routine forensic work off the shoulders of your already taxed Infosec guys.... Check out Wapack Labs! Wapack Labs is our newest addition to the Red Sky lineup. Wapack Labs is furnished, staffed, and set up. It'll open in the Historic Mills along the river in Manchester, NH on the first of April. Wapack Labs will initially handle non-criminal computer forensics, analysis and R&D projects. In fact, we've even had our first customer! A woman walked in on Thursday while we were setting up our furniture. She'd seen the 'coming soon' sign on our door and she wanted to know if we could recover her baby pictures and videos from a crashed 1Tb external drive... and you know what?  When you like to bootstrap (and we do!), mom's money is green, too!  It'll pay for the coffee pot and new Wii U (lab guys apparently, LOVE killing zombies).

Have a great week!
Jeff


Wapack Labs Contact info:

250 Commercial St., Suite 2013
Manchester, NH 03101 
(603) 606-1246  
dkirmes@wapacklabs.com
 


 



Friday, March 15, 2013

Threat Day Tampa! And thoughts about community…


I love my job! No, I’m not gloating that I've been able to spend time in the warmth of Florida, knowing its frigid cold back home in Maine! I seriously love my job.  I wonder how many people in the InfoSec space can say that. An official count tells me not many!  

Every quarter, Red Sky hosts a day-long briefing with our members. “Threat Day” is central in establishing lasting relationships between the members. These events, also establishes trust and fosters a sense of community.

We heard how an incident response team discovered a targeted attack and their smart, timely actions to thwart it, given a dossier on the cultural and political motivations of state sponsored ATP, and the creation of new tools that sifts through big APT indicators quickly and efficiently.

It was a very successful event and we are already looking forward to the next one!

A side topic of discussion this week was the observation that communities and information sharing environments are starting to pop up quickly.  These sharing environments are becoming prevalent because there’s real need to share data and solution providers have figured out that brand loyalty is as much human connection as it is providing a solution to a problem.

As the large InfoSec companies monetize the information sharing concept, I can’t help but think of some of the thoughts Red Sky’s lead analyst recently shared with me, which I think are spot on.  It is his conclusion that sharing communities fall into two categories – ad hoc or constructed.  Each of these community models has their pros and cons but before submitting your indicators, I ask you to consider the following.

The ad hoc community is the simplest to establish and are a result of necessity rather than by choice.  They may be loosely regulated and unstructured and sometimes lacking finished conclusions but these communities are fast moving, quick to respond, and provide a diversity of ideas, particularly deep technical evidence.  If you’re looking for a quick infusion of information, this may be the perfect community for you.

The constructed community is one which participation is purposeful.  Generally, membership is by request or invite only and governed strong bylaws. However, rigid rules and over governance can inhibit and even discourage sharing of information. On the upside, constructed communities reduce static, unnecessary and redundant information. When information is shared, its high fidelity, and you’re less likely to take a “wait-and-see” approach.

Red Sky is taking what is best from both community models and bringing them together in a single environment.  The strength of our community is equal to the strength of the relationships and trust between members. This is why we emphasize the value of our quarterly meetings!  This week’s Threat Day in Tampa is a reaffirmation of this belief. We work hard to bring smart people together, give them the tools to do their job efficiently, and provide them a content rich environment to share information, you can accomplish great things! 

In the future, when asked to join a group to share your information, ask yourself which type of community you’re being asked to  join, what do you expect to get in return for your information, and do you trust those on the receiving end?

If you’re interested in our Threat Day’s or want to join the conversation, email me directly at rgamache@redskyalliance.org

Saturday, March 09, 2013

House is on Fire. Call 911? Do I have a choice?

If you were awakened in the middle of the night by the smell of smoke, would you call 911? Do you have a choice?

I’ve been talking and working with several organizations lately who for whatever reason, chose not to call 911. Worse, some (most all) either don’t have smoke detectors or the batteries have died, they don’t get tested annually, and aren’t even wired to a place that will let them be heard when they go off in the middle of the night.

So, what happens when there’s a fire and the owner is awakened by the smell of smoke? Maybe he’ll grab a fire extinguisher or buckets of water. Within a short time, the fire grows. Grab the garden hose!.... the whole time, as the neighborhood gathers to watch his house burn to the ground, little by little, he forbids the neighbors from calling the fire department.

Get the picture? We’re not talking about smoke. We’re not talking about fire at all. We’re talking about the stubbornness of IT directors and CIOs with emotional connections to the idea that whatever happens in the networks that they built; whatever happens, they can fix it. Let’s think...

  • The fire smoldering deep in their networks is largely undetectable by their current smoke detectors. Those things were installed years ago, and even though they auto-update, they might detect the old stuff, but can’t detect the new.
  • The team is all fairly new, and while they know tools exist on the network, they have no idea how to use them.
  • “The IT guy has been with the us for years. He’s never let us down before. We’ll cut him some slack.. just a few more months.”

Sound familiar?

So here’s the thing. In the last 30 days I’ve talked with at least three companies in this exact situation. One has started submitting information to Red Sky without actually joining. Another has a CSO and an IT director, but the IT guy doesn’t trust the CSO and thinks he can do it on his own. The third isn’t a corporation... but I could write a series of posts on government information security!

So let me pose a couple of thought questions...

Should IT security fall under the CSO when IT has no security organization? What responsibility is held by the CSO when no Infosec organization exists? If not the CSO, then who? In many of the companies I talk to, they have a CSO who’s responsible for physical security. The CSOs usually have no IT experience, but is the only security guy in the many of the companies. So what is their responsibility? If not the CSO, then who?

At what point do you call for help? Who do you call? FBI? Police? Consultant? When IT spends months playing ‘whack-a-mole’, when should IT be required to get outside assistance? How much of the budget should be allowed to be spent before IT is required to blow the whistle? When that occurs, who should they call?

Last, what role does the board play? When IT is unable to stop the intrusions, how much time/money should be spent before senior management reports to shareholders?  When a company refuses to ask for help, how much time (money) should be spent before liabilities fall to the board and senior management for not acting sooner? Is there a liability to the board for not notifying shareholders and requiring management to seek assistance?

BREAK BREAK

I haven’t done a Red Sky update in a couple of weeks. We have a lot going on...

  • This week we’re gearing up for our 5th quarterly threat day (in Tampa). We are really looking forward to a first time face-to-face with several members and to further building out the trust relationship which is so important in our space.
  • Two new Fusion Reports were released to our community. The latest introduced a new threat group to our list of tracked adversaries and provided detailed analysis on the leveraged protocol as well as mitigation recommendations. The second report provided additional analysis and attribution on a recent highly-publicized compromise.
  • We’ve added a new member to Beadwindow. Our newest member is a state level organization for higher education. We really like working with the city, state and local governments!
  • Last, we’ve just taken possession of the space in the Manchester mills. The new company (a Red Sky Alliance company; this one incorporated in NH) is called Wapack Labs, and we’re bootstrapping this one with contract security intelligence work, a bit of R&D, and some research.

I’m looking forward to talking with more of you in the future. We’re giving two more threat briefs, I’ll be presenting heading for Dallas this week, speaking at a McKinsey event in New Jersey and then headed for New York for another panel discussion with the financial community. We’re busy and doing great!

Enough for now.
Have a great week!
Jeff