Saturday, November 05, 2016

Cyber influencers on next week's elections?

We blogged last week on activity that we believe may be indications of potential upcoming election tampering. Tonight it was on the news. And while I'm sure they didn't get it from us, we've been watching election activities in Eastern Europe since the last Ukrainian Presidential election. 

We witnessed election tampering (hacking, DDoS, and telephone DoS) in the Ukraine, and then again DDoS in Bulgaria. We're also paying attention to Macedonia and Moldova --not because we had a dog in either fight but because there are massive lessons to be learned from watching the cyber interactions when we have customers who operate in both areas... and we have a global customer base that we believe have interests in the areas, and want to know.

In October (last month), Wapack Labs watched as Montenegro was hit with a DDoS and insurgency preparations as pro-Russian opposition tried to take hold in October 2016 elections.  

***********************

Wapack Labs believes with high confidence that there will be additional election tampering, but analytic rigor dictates that more data be collected.  We have five major elections in the near future where foreign interests may be manifested by some cyber activity – Bulgaria, USA, Macedonia, Moldova, Transnistria and France:

  • 06 November 2016 - Bulgaria. Presidential elections will be held in Bulgaria on 6 November 2016.[1] Bulgaria is a NATO member but has very strong pro-Russian fraction of the population. The incumbent President, Rosen Plevneliev, announced in May 2016 that he would not be running for re-election. Last year Bulgarian Central Election Commission and other governmental institutions were DDoSed as the country held municipal elections.[2] 
  • 08 November 2016 - USA.  Hacking of Democratic organizations, with release of the data, as well as intrusions to the Arizona and Illinois election commissions were mostly attributed to Russian APT hackers. 
  • 11 December 2016 - Macedonia. Early parliamentary elections will be held in Macedonia in on 11 December 2016, having originally been planned for 24 April and later 5 June. The elections were called as part of an agreement brokered by the European Union to end the protests against the government. From 20 October 2015, a transitional government was installed including the two main parties.[3]
  • Leading Moldovian Presidential candidate Igor Dodan
    meets with Putin (2014)
  • 13 November 2016 - Moldova. Second round of presidential elections will take place on 13 November 2016. The Socialist Party leader Igor Dodon, fell just short of the majority needed to secure outright victory and faces a runoff election.[4] Wapack Labs believes that Moscow will radically increase its influence on the ex-Soviet republic. Russia has troops in unrecognized Transnistria and this development might similar to country Georgia where pro-Western government lost land to Russia and then lost its power to more Russia-oriented coalition.
    Soviet-like Transnistria coat of arms
  • 11 December 2016 - Transnistria. Presidential elections, 11 December 2016[5]  Transnistria is part of Moldova, an unrecognized state with Russian military base and strong military influence. 
Moscow is courting both leading presidential candidates but is worried that their fierce rivalry and worsening economic conditions might lead to destabilization of this pro-Russian region.[6]
  • April and May 2017 - France. The next French presidential election is scheduled to be held in April and May 2017.[7] But the first primaries are this month already.  Marine Le Pen who’s National Front was taking Russian funding is predicted to gather between 28% and 30% in the first round, ranking first or second, and so to be qualified for the run-off.[8]
***********************

There's been much in the news about the potential for DDoS next week during the elections. We do not see this as much of a stretch. There are many who'd like to disrupt voting next week, including just about any kid who's got access to a botnet and credentials to the sensors in your thermostats and refrigerators. 

There are however, many geopolitical influencers supporting the idea that there will be cyber activities --Wikileaks is preparing to dump what Assange is calling the most damning dump yet. That's yet to be seen.

In the mean time, get ready folks. You've heard me say it before.. welcome to the new normal.

Have a great weekend!
Jeff



[5] http://vpk-news.ru/articles/33317 [article in Russian]

Sunday, October 30, 2016

Like Beer? Beer + Information Security + Intelligence = AWESOME!

I started a post about how I blew my entire $12.88 marketing budget last month on a rubber stamp
that I used at the ISC2 and ASIS conference in Orlando. That 12.88 rubber stamp got more action than a fox in a hen house.

...but now there's a horse race going on... I challenged my marketing person to come up with way of getting the word out about this nearly one year old offering. We've been publishing, but haven't really advertised it. So...

What's the Readboard? Like the graphic says, we hired a professional journalist to rewrite our more technical and intelligence reports into short format products, 1-2 pages written in a journalistic style. These products can be used when your boss needs fodder, or you need to explain in human what happened, or... whatever.

Sign on for a free trial by 11/30 and enter your name for a drawing for a Beer of the Month Club raffle --for a year! (That was MY idea. I LOVE beer!).

Scan the Sign-up QR code, or use this link...

https://wapack-labs-exec-read board.dpdcart.com/subscriber/login

Either way, sign up for the free trial, and win some beer!


Saturday, October 29, 2016

The new normal... IoT, Complexity in Networking, Interconnectedness, Point and Click


Several months ago, after installing a Nest thermostat in my home.. my first venture into the world of Internet of Things, I decided to play a joke on my daughter.  

Knowing she was home alone, I remoted into the thermostat from the app my phone and cycled the heat from 50 degrees to nearly 80. She of course had no idea what was going on... well, I thought it was funny.

But this is only one example of how the IoT is going to affect our life. In a recent discussion with a university CISO, it was reported that a foreign student was utilizing a laboratory research microscope to communicate back to his home country.  This utilization of the IoT comms channel was discovered and shut down by the security team, but this example exposes a stark reminder that IoT cyber avenues create serious vulnerabilities to the health of the international network.

Last week it was Dyn. I won't rehash; the story is still pretty fresh on our minds, but this isn't going away folks. You've heard me talk about the 'new normal'. It goes like this:

  • Ransomeware is a normal part of business... and a cost of doing business. The VP of a North American Business unit (in a 325,000 person company) reported to me that he'd been hit personally with ransomware. In another example, it was the CEO of a 300 person aluminum extrusion company.  If you don't have protections in place, be ready to pay. 
  • APT isn't as Advanced as it used to be.  The computing footprint has expanded into cloud offerings, mobiles, and virtualized. At the same time, many of the tools that used be new are now point and click. Uses of previously identified APT infrastructures are showing up in places beyond the defense industrial base, and have become largely pervasive.
  • DDoS is being demonstrated on a regular basis, and can be done through a service provider for hire.  As an example, we reported recently (in Red Sky Alliance) on a Bulgarian company that provides DDoS services for state actors in Nigeria.  It was reported in a Russian forum (yes, we read Russian language forums) that the company, during a sales call demonstrated its DDoS capabilities to the Russian government contractor "Rostec" by attacking and downing the Ukrainian Ministry of Defense sites and the Russian edition of Slan.ru. It is not clear what role Rostec plays with the Russian government, only that there is an effort to coordinate DDoS efforts in Russia, and that an external company was being looked at to provide those services. 
  • And last, the introduction of insecure Internet of Things devices is going to multiple all of these issues exponentially. Heck, it already has. 

Protection of the networks is only going to get harder folks.  I sat on a plane to Nashville with a guy who used to be an executive and engineer at one of the early, large DNS providers.  He knows tech.  He's since started a company and builds networks for real estate management companies --and he's thrown his hands in the air and given up.  In his words, "SSL doesn't protect sh*t, authentication doesn't work, and the costs of continuously layering expensive technologies on top of expensive technologies is getting out of hand." He chooses to encrypt nothing and leave the networks wide open. When a user wants something encrypted, they PGP.  Is this approach best? Who am I to say? It's one way to skin the cat, but it won't protect from Ransomware or DDoS, only confidentiality of data --and will the Realtors know how to use PGP? Probably not. This guy is totally frustrated --and in my opinion, lost; because the landscape has become so complex.

The point is this... there's an exponential increase in technologies required to protect your networks and data; the threat landscape is maturing, growing, and focused on more than just being a nuisance; and the complexity in our computing footprint is offering bad guys an enormous target with millions of ways to access the networks.

The sheer number of IoT devices targeting Dyn last week is only the tip of the iceberg. And the idea that an IoT DDoS taking down Kreb's website are two examples of how toasters and thermostats and refrigerators can and will be used. What happens when these devices aren't just used for DDoS, but proxies and attack relay points, dump points for hiding data, covert communication channels, command and control, and more.  

I'm not here to tell you that the sky's falling. It's not. I'm here to tell you that we need to figure out how to talk, share intelligence and share analytics.... Red Sky Alliance is one of those great places to do this, and it's fed by intelligence from Wapack Labs. Give me a shout or look for me in St. Louis this week. I'll be in town for the NDTA conference. I'd be happy to give you a walkthrough. 

OK folks.. I'm off.

Until next time,
Have a great weekend!
Jeff

Saturday, October 22, 2016

Sécurité - Sécurité - Sécurité


Sécurité is a safety signal used as a preface to announce a navigation safety message. It could be an approaching storm, a navigation light failure, a submerged log in a harbor entrance or military gunnery practice in the area. 

There's a digital transformation the shipping industry,  just as there have been in many others as the internet continues to connect industries and people who've performed even the most manual of jobs and functions.
The principal aim is to integrate all the shipbuilding functions “so they work in harmony and are properly aligned to build complex vessels”, Tim Nichols, marine division marketing director for Siemens’ PLM software, told a round table in Hamburg.
Yesterday we witnessed a global denial of service attack, resulting from a denial of service, apparently targeting Dyn, a Manchester, NH based DNS provider.  The attacks lasted roughly eleven hours and denied popular websites like Spotify, Twitter and others the proper name resolution needed to allow their names to be converted to their actual IP address. For the uninitiated reading my blog, DNS is the Internet's telephone book.  Wapack Labs => 603-606-1246. DNS translates wapacklabs.com into our actual numeric IP address. It allows your computer to remember your speed dial name instead of the actual number.

So why am I talking about maritime at the same time as the massive DDoS attack of yesterday? 

Because just this week, we published a report on a Maritime Internet Service Provider who allowed thousands of shipboard border IP addresses to be resolved outside of their network.  Over the course of the last two years, we've reported on key loggers and bad guys logging into vessel traffic systems, embedded and integration points, terminal operations, security systems, logistics, and shipboard connections. And about six months ago, a maritime CISO reported to us that satellite communications had undergone a denial of service, rendering ship-to-shore communications neutered. The result? Ships couldn't talk to the ports -- they were kept at sea.  While many of us would say "who cares?" --if a ship runs out of fuel it becomes a navigation hazard. Onboard medical issues, ordering of supplies, delivery of supplies, all become tricky, but as importantly, when a ship leaves Port A for Port B, their cargo might be bought and sold several times. In this case, because the ships kept at sea contained cargoes like crude oil, there was a very real chance that hackers were manipulating markets --yes, far fetched, but you just can't make this stuff up.

As well, Wapack Labs has been collecting key logger outputs from roughly 1250 caches of malware outputs. When a user logs onto their email, the key logger captures the user name/password pair, and then sends images of the clipboard to the external repository. We've performed hundreds of thousands of victim notifications from this data, and made it searchable for free through our api (api.wapacklabs.com). 

Here's why I'm concerned.  Massive attacks like yesterday are going to become commonplace. This will become the new normal as the Internet of Things puts autonomous internet-enabled dumb tools in the hands of hackers as new weapons.  On land, we simply wait it out.  Neither Spotify nor Twitter are mission critical, but what if I told you that industrial controls, GPS (navigation at sea), fuel monitoring, and new ships carrying highly dangerous cargos like liquid natural gas and crude are FILLED with these same devices that are creating opportunities of massive attacks like the one we witnessed yesterday.

The picture shown above is a vessel tracking system (marinetracking.com) taken just moments ago (9:15 Saturday morning).  The VTS shows the ports and maritime traffic in southern New England --Connecticut, Cape Cod and the Islands --and even with the crap weather going on in New England right now, you can see, there's a TON of maritime traffic. This view is essentially the air traffic control system of the sea.  Imagine you're the master of one of these at sea vessels and losing confidence in your VTS's ability to show you where other ships are? Or running dry and adrift? Or losing navigation, pumps or communication?

Yesterday's demonstration was just that folks... a demonstration. When this hits the maritime, air, train, and trucking industries who are relying more and more on automation via the internet, non-mission critical internet sites like Spotify and Twitter will quickly become safety at sea, safety in the air, and safety on the road issues. You heard it here first folks. The sky isn't falling just yet, but unless we get a handle on the need to balance security with interconnectedness, you'd better get ready.  As we see more and more autonomous vehicles --cars, ships, airplanes, etc., this scares the hell out of me. This internet was never meant to be secure, and there aren't enough layers of security that can be bolted onto one of these maritime systems that will make them safe --or the people who man them. 

BT

Preparing to head off to the FS-ISAC Summit tomorrow. Nashville here I come. Next week, it's the National Defense Transportation Association where I'll be speaking and sitting a panel on --you guessed it, the intersection of cyber and physical in the maritime and logistics space. 

I look forward to seeing many of you! 

So until next time,
Have a great weekend!
Jeff

Saturday, October 15, 2016

A Stutzman Public Service Announcement - Skin Cancer

Yesterday I had to fly home to have short notice surgery.

In January I noticed what looked like a black pin prick mark on my left shoulder.   By March it'd grown slightly to maybe the size of a ball point pen mark. Over vacation this year, I noticed that it'd grown into what looked like a small mishapen kidney bean.

I'd been to my Primary Care Provider (an awesome Nurse Practitioner) in March; I use the VA in Manchester, NH. She told me she didn't think it would be anything to worry about but if it changed, she'd refer me to dermatology.  At the end of August, I requested that referral.  I'd made an appointment for September.  For whatever reason, that appointment changed to the first week in October.

I underwent a biopsy --the doc numbs the site and within two minutes, the entire procedure is over --and a sample of the black skin from my left shoulder was headed for the lab.

Exactly one week later, while sitting in my office in NH, I received the call -Malignant, and Melanoma... skin cancer... the most aggressive kind.

On Thursday, while on-boarding a new engineer,  I received another call. "We have a surgeon with a cancellation.  We'd like to get you in to perform the extrusion." So I booked SWA to Manchester, headed to the VA, and had the thing removed.

The entire procedure took about an hour, but the melanoma was roughly 6 cm long, shaped like a kidney bean, and fortunately for me, had not yet grown deep enough to pass through the skin. I'd caught it early.  I thought for sure I'd be in and out in 15 minutes... I'd booked a return flight only three hours later.

I thought I was going to end up losing a 'quarter sized' piece of flesh. What I really lost was about five inches long, two inches wide, and about 3/4 of an inch deep --a 5" canoe shaped hunk of meat was taken from my shoulder.  I asked the doc --"when my daughter asks me how many stitches, what do I tell her?" He responded, way to many to count. The incision was deep.  Four layers of 24+ stitches were used to sew me up, before the green caterpillar of thread on the surface.

At this point, the doc says the pathology results will be back in about 10 days, but he fully expects that we caught it early enough, and he's fairly certain it's all gone ...but had I waited, even another month, and it grew through the skin, I'd have been really screwed.

So I'm sitting in my MD apartment with bandages covering a sewn-up 5" straight line incision, not yet writhing in pain but expecting it to come as the pain meds fully wear off.

Here's the deal... I grew up working on a farm down the road, bailing hay and mowing lawns in the summer. I NEVER had a shirt on. I tan quickly, and it's these color-generating cells that like to turn into cancer.  My upper body is covered with spots, but I happened to see this one in the mirror one morning while shaving.

I'm ok now, and didn't write this for sympathy. There are many others who can't simply have a small steak cut out of their skin and move on.  I'm writing this to let you know that for every time you've thought to yourself "I'll never get skin cancer", well,  I had that same thought many times too, until this year when I wore a shirt in the pool on vacation and my friend Chris reminded me that I had health insurance and should make it a point to get checked.

So do me a favor. Spend a few extra minutes in front of the mirror. If you see anything strange, don't screw around. Get checked. If you don't know what it might look like, have a look at Google Images.

As an aside, My VA surgeon went to medical school at Dartmouth and then worked surgery --oncology at Michigan.  If you think you can't get smart docs at the VA, come to Manchester.  These guys are smart, polite, and professional.

OK folks..  I knew you were expecting the Stutzman wit, but I'm hanging out today resting, healing. And I know you hear it a lot, but GET CHECKED.

Stutzman wit again next week ;)

Until then, have a great weekend.
Jeff

Saturday, October 08, 2016

Wapack Labs, VAMC, Southern NH University and Digimind Re-Train Returning Veterans

Press Release - New Boston, New Hampshire, October 10, 2016 - Wapack Labs, Digimind, Southern New Hampshire University and the Veterans Administration Medical Center (VAMC) in Manchester, NH team up to turn returning veterans into qualified cyber professionals.

There are roughly 290,000 currently advertised information security jobs today and while the number of training programs is growing, Wapack Labs believes that not everyone needs a four-year degree to fill the void. So we offer paid internships through Manchester’s VAMC Occupational Therapy office for honorably discharged or medically retired returning veterans, and experiential learning internships for Southern NH University veteran students. We begin their program by teaching them to use Digimind social media tools to spot physical threats in cyberspace.  The vets are taught to be cyber analysts through a series of increasingly more complex cyber skills reinforced through work. The entire program takes approximately a year.

When the veteran interns meet Cyber Analyst requirements, Wapack Labs has several Fortune 500 companies and government organizations who have agreed to interview them for available positions.  Veteran interns used Digimind tools to support the Cleveland Police Department’s efforts before, and during the Republican National Convention, major sponsor’s onsite at the Rio Olympics and the team “Team Jeagar” has authored roughly 150 intelligence reports since inception in May.

Wapack Labs is using Digimind’s services to train cyber analysts with real time sourced data. 

Jeff Stutzman, CEO and a U.S. Navy and Coast Guard veteran stated, “At Wapack Labs, we are proud to help these guys learn cyber skills that will place them in an ever growing industry. The majority of our employees are US Military veterans and National Guard members.  We feel it is of the upmost importance to help our veterans.”

"Digimind is proud to be a part of this effort by Wapack Labs to train and employ veterans. Beyond the clear benefit to the veterans as individuals, the fact that this software is being to used to keep citizens of multiple countries more secure is an additional boon. Digimind hopes to continue to partner with Wapack Labs, contribute to this program, and be a part of similar programs in the future." said Paul Vivant, CEO of Digimind.

The common sense approach and wide array of metrics regarding social media collection offered by Digimind has proven very valuable to Wapack Lab’s collection mission. Digimind was instrumental in Wapack Lab’s support of law enforcement collection efforts during the 2016 Republican National Convention in Cleveland OH.  Following the RNC, Digimind services were used in a collection program in support of the 2016 Summer Olympics in Rio de Janeiro, Brazil.  Training new analysts using Digimind’s “Influencer” metrics has helped Wapack Lab’s interns identify social media individuals in active support of event security planning and with targeting potential bad actors and their attacks against Wapack Labs clients.

About Wapack Labs: Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC, and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber. Wapack Labs' engineers, researchers, and analysts design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information, using deep analysis techniques and visualization. Information derived from these tools and techniques serve as the foundation of Wapack Labs' information reporting to the cyber-security teams of its customers and industry partners located around the world.

About Digimind: Digimind is the global social media monitoring and competitive intelligence company that provides businesses with unrivaled insights into their true standing in the market. Digimind's proven intelligence technology has provided Fortune 500 brands around the world with critical information for their business for more than 17 years. Profitable since its founding, Digimind has a 92 percent customer retention rate and serves its clients out of its offices in North America, Europe, Asia and Africa. For more information, please visit Digimind at www.digimind.com

For questions or comments regarding this news release, please contact Jim McKee, CFO at 314-422-8185 or jmckee@wapacklabs.com. 

BT

Wonder why we do this? VA Occupational Transition assistance is an amazing service. These guys really bend over backwards to help our vets. They are awesome!  However, they can only provide work in positions not related in any way to patient care --the vets are patents. What's that leave?  Food service, facilities, landscaping, etc.  Great jobs?  No, but for those who need it, it's something. And while some may enjoy food service, others have other interests.

I want to train the next generation of cyber professional.... So we figured, let's take them on ourselves... these guys know a threat when the see it, know how to write (for the most part), are eager to learn, have our work ethic. and honestly, I can be a bit of an HR nightmare.. these guys don't flinch at some of my salty language. 

We take as many as we can... we have three from the VA with one more coming, and four of them on internship from Southern NH University (the vets get three college credits toward their degree for working with us).  We take on as many as we can afford. 

Below is one job description for a returning vet who needs Occupational Transition assistance... I think we can do better.


1. SCOPE AND OBJECTIVES:   TSES will perform the following duties including, but not limited to: 

Tasks:

  • Clean and sanitize work areas, equipment, utensils, dishes, or silverware
  • Store food in designated containers and storage areas to prevent spoilage.
  • Prepare a variety of foods, such as meats, vegetables, or deserts, according to customers’ orders or supervisors’ instructions, following approved procedures.
  • Take and record temperature of food and food storage areas, such as refrigerators and freezers.
  • Wash, peel, and cut various foods, such as fruits and vegetables, to prepare for cooking or serving.
  • Attend staff and training sessions as appropriate.

Work Context:

  • Spend Time Standing: 97%
  • Contact with Others: 66%
  • Physical Proximity: 67% 
  • Indoors, Environmentally Controlled
  • Responsible for Others’ Health and Safety: 48%

Knowledge:

  • Food Production: Knowledge of techniques for proper cooking, handling, and storage techniques
  • English Language: Knowledge of the structure and content of the English language including the meaning and spelling of words, rules of composition, and grammar. 
TSES will provide as necessary:  

  • TSES workers to assist facility personnel.  Workers are available, seven days per week.  A copy of the time and attendance sheets will be provided to Facility Service Administrative Officer for documentation.
Wapack Labs offers paid and unpaid internships to vets and former Police/First Responders. Today, our junior cyber analysts include two Marines --one heavy equipment mechanic; the other, counterintelligence; one newly discharged Army sniper, one Navy Aviation Structural Mechanic, one police officer from St. Petersburg, FL. We've had one Marine LAR complete the program, recently had an Army MP leave the program, being replaced on Monday by another.  We start our program roughly every 10 weeks and internal training begins with classes in OPSEC and 'Operating Safely in Cyberspace', and progress gradually through roughly 30 modules including lessons in writing for intelligence, GEOPOL, cyber threats, scripting, TCP/IP, malware analysis, and more.

Southern NH University and Digimind were kind enough to pitch in.  Interested in pitching in?  Sponsoring a vet?  Call me or shoot me a note.  The investment is small but the payoff is amazing.

Until next time,
Have a great weekend!
Jeff