+ All Categories
Home > Documents > So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins,...

So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins,...

Date post: 15-Jul-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
43
Transcript
Page 1: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,
Page 2: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

So who is this Matt guy anyway?

• Corn-fed, Wisconsin small business owner • Information security consultant – previously with

CDW for 15 years • Certifications: CISSP, CISM, CRISC, CHSP, GIAC,

CGEIT, OMG, BBQ, etc. • When I’m not busy being a security geek:

• Gardener • Bee-keeper • Brewer of beer and mead • Chainmailer • Fisherman • Aspiring blacksmith • TH9 in Clash of Clans

Totally Awesome Mullet Award (circa 1987)

Page 3: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Agendamus Maximus

•A very brief history of warfare

•Hackers and threat actors

•Cybercrime examples

•Defensive strategies

•Open dialog

Page 4: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

History of Warfare (dramatically oversimplified)

The human penchant for war, power, and conquest

“We have always been at war with Eastasia.” – George Orwell, 1984

Page 5: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Land

• Fists

• Clubs

• Metal

• Swords and spears

• Armor

• Arrows

• Heavy things

• Mobility

Page 6: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Water

• Row boats

• Sail boats

• Gun boats

• Navy

• Submarines

• Heavy things

• Mobility

Page 7: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Air

• Balloons

• Gliders

• Propellers

• Jets

• Spy planes

• Heavy things

• Mobility

Page 8: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Space

• Rockets

• Satellites and communication

• Space bound animals

• People

• Orbital bases

• Orbital attack/defense platforms

• Heavy things

• Mobility

• Rockets • Satellites • Animals in space! • People • Space stations • Orbital

attack/defense platforms

• Mobility

Page 9: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Data and the Internet

• Telegraph

• Punch cards

• Magnetic media

• DARPA

• AOL and PCs

• A world connected

• Transient data

• Evil hax0rz

• Mobility (???)

Page 10: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

The Rise of The Hackers

• The Terminally Curious • Kids, young adults, adults, misguided motives

• The Maliciously Inclined • Evil h4x0rz, axe-grinders, egoists

• Organized crime • BotNet herders, malware developers, profit-motivated criminals

• Advanced Persistent Threat actors • Vindictive insiders, ethno-nationalists, ideological fanatics, nation states,

rogue corporations and criminal enterprises

Page 11: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

The future is here…

Are you prepared?

Page 12: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

A few quick statistics

Source: http://www.hackmageddon.com/2015/12/11/november-2015-cyber-attacks-statistics/

Page 13: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Attack Techniques

Page 14: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Commonalities in attack scenarios

• Identify target

• Surveillance and reconnaissance

• Penetration

• Co-opt targets

• Conceal and embed

• Conduct operations

• Profit

Page 15: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Understanding the Zero-day Problem

The Internet 010000100110010100100000011100110111010101110010011001

010010000001110100011011110010000001100100011100100110

100101101110011010110010000001111001011011110111010101

110010001000000100111101110110011000010110110001110100

01101001011011100110010100101110

Matches anti-virus signature – apply countermeasures!

Page 16: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Understanding the Zero-day Problem

The Internet 010000100110010100100000011100110111010101110010011001

010010000001110100011011110010000001100100011100100110

100101101110011010110010000001111001011011110111010101

110010001000000100111101110110011000010110110001110100

01101001011011100110010100101110

Anti-virus says: “Nope. Ain’t never seen it… Carry on, Citizen.”

Very limited or no protection offered

Page 17: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Patch Gap and Vulnerability Management

Notice! This little gap represents the zero-day problem

Page 18: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

So… where does it all come from?

Page 19: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Example: Low Orbit Ion Cannon

Page 20: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Example: High Orbit Ion Cannon

Page 21: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Support and Customer Service for Hackers!

Page 22: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Customize it with SpyEye

Page 23: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

But wait, there’s more! Citadel

Page 24: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Anatomy: Common Cybercrime Tactic - Banking Successful Exploitation via Spear phishing

Bot provides Feedback to hax0r

Online Banking User Targeted

Means of authentication compromised Hax0r collects

Banking credentials Hax0r logs into victim’s online banking account

Hax0r moves $$$ to US account

Unsuspecting perp moves money overseas

Page 25: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Two quick riddles…

Q: When do organizations realize that they have made a mistake in security spending?

A: Usually never – they simply miss out on the chance to use some money for other things, but they seldom really investigate how much or why.

Q: How much better is it to do a great job with security than it is to do an average job?

A: Well, we need to adjust the definition of “great” so that it encompasses not overspending, spending irrationally, or spending ineffectively.

Page 26: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

How do we decide what to do?

• Everyone spends on security, but we know our security will never be perfect

• Budgeting for security is problematic

• We must optimize our security spending and resource allocation

• A security assessment is the process of identifying and prioritizing risks and mitigation strategies

• A well-done assessment should give you confidence

Page 27: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Top 5 Security Things You Should Be Doing (but probably aren’t)

• There will always be “something” to do that is not being done

• Commonalities across verticals

• Verify and ask questions

• Form a plan

• Execute

• Validate

• Improvement and vigilance

Page 28: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

#1 Fix Your Passwords

• Develop and enforce password policy

• Foster a security-aware culture • Employ passphrases • Perform periodic password audits • Password isolation • Consider multi-factor

authentication

Page 29: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Sorry, but I’m about to geek out on you…

• No. This is not the Death Star nor is it a lesson in optics

• Blue ovals are hosts, red boxes are credentials

(username/password combination), and yellow spots are the domains (domain controllers, to be specific).

• The “credentials” in this one are local

administrative accounts, so this represents local account trusts for administrative level users (admin on hosts and/or the domain controllers).

• ~1,400 hosts involved in trusts with at least one

other, many with many others, including the domain.

Page 30: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Geeking out… Part 2 • Much simpler, yes? • Blue ovals are hosts, red boxes are credentials

(username/password combination), and yellow spots are the domains (domain controllers, to be specific).

• The “credentials” in this one are local admin

accounts, so this shows local account trusts for admin level users (admin on hosts and/or the domain controllers) EXCEPT that this time, the actual “Administrator” accounts are excluded.

• In other words, it's the same as the previous graph, if

they were to fix just all of the local “Administrator” accounts. Only 129 hosts now involved in local account trust relationships.

• So by fixing the local “Administrator” account on all

their boxes, they can achieve an order of magnitude improvement in # hosts involved.

Note: We’re not even talking about fixing patch-related vulnerabilities yet!

Page 31: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Why is this so bad? Lessons Learned

• A single vulnerability might give an attacker access to a great deal of stuff

• Once that happens, it’s hard to distinguish between logins by legitimate friends vs. logins by adversaries

• It might be pretty hard, even, to determine if Something Bad™ has happened

• It might be relatively easy to gather data about various vulnerabilities, but it’s hard to spot the relationships that govern how deadly they are

Page 32: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Inferences From The Geeky Graphs

There are things you can do to lessen the impact of a new vulnerability being exploited

• Principle of “Least Privilege” and “Inverted Security”

• Reduce sharing of local accounts

• Turn off cached credentials where not needed

• Now we can begin to think in terms of vulnerabilities we don’t yet know about • (recall the zero-day problem?)

• Oh, and patch your stuphs!

Page 33: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

#2 Use a Password Safe

• Get rid of those Excel and Word docs for password storage

• Encrypted storage

• Improve enterprise disaster recovery capabilities

Did I mention…

GET RID OF THOSE EXCEL AND WORD DOCS!

Page 34: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

How’s Your Memory Doing These Days?

• Don’t use spreadsheets or unprotected documents!

• Individual use • Home • Office

• Mobile

• Enterprise use • Complex environments • Privilege use and tracking • Effective management

Page 35: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

#3 Network Egress Filtering

• Egress, or outbound, traffic filtering • Firewalls and VLANs/VACLs

• Block and monitor • Security Incident Event Management (SIEM)

• Identify and isolate highly sensitive and confidential data • Data Loss Prevention (DLP)

Page 36: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Baseline and Behavioral Analysis

Develop baselines

• What does normal behavior look like?

• What does abnormal behavior look like?

Internal monitoring in addition to external

• Develop initial indicators

• Lends itself well to incident response planning and preparedness

Prepare for the worst, hope for the best

Page 37: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

#4 Improve Your Monitoring and Inventory Management

• Start simple

• Establish basic metrics

• Authorized and unauthorized devices

• Centrally manage audit logs

• Focus on relevant issues first

• More automation of alerting

• Trending

Page 38: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

#5 Perform Routine Scanning

• Utilize your updated inventory • SolarWinds

• Identify known weaknesses • NESSUS

• Continuous remediation • ERM

• Update build standards • ITIL

• Improve patching regiment • WSUS/SCCM

Page 39: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Vulnerability-free Planning

• Plan 1: Find out about and fix all flaws in all products • Not likely; vendors keep releasing patches, indicating that they don’t

know them all • “Apollo 8 has 5,600,000 parts and one half million systems,

subsystems, and assemblies. Even if all functioned with 99.9% reliability, we could still expect 5,600 defects.”

• Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974, p. 307)

• Plan 2: Prevent all flaws from being exploitable by anybody • Also problematic; generally this would involve denying all access… • “The only truly secure system is one that is powered off, cast in a block

of concrete and sealed in a lead-lined room with armed guards - and even then I have my doubts.”

• Gene Spafford (quoted in Dewdney, A. K., “Computer Recreations: Of Worms, Viruses and Core War,” Scientific American, March 1989, p. 110)

Page 40: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Set Goals!

• Identify

• What data do you consider to be sensitive or confidential?

• What forms do your critical data take?

• How and where is it being stored?

• Who “owns” the data and who has access to it?

• Monitor

• How is the data being used?

• Where is it being sent?

• How is it being sent/transferred?

Report • Information is primarily useful when it is

consumed (and is consumable) • Access summaries, capacity reports, data life

cycle management, etc. • Understanding of key risks facing the

organization

Improve • Manage technical issues and improve business

processes • Intelligent application of resources to support

remediation efforts

• Knowledge is power!

Page 41: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,
Page 42: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Open Dialog Time!

Introduction: Jeff Grady from Three Pillars Technology

We know you have questions

Page 43: So who is this Matt guy anyway?€¦ · • Jerry Lederer, NASA safety chief (quoted in Collins, Michael. Carrying the Fire: An Astronaut’s Journeys, New York: Random House, 1974,

Special Thanks to:

MEGA Healthcare Conference Organizers

Our Wonderful Sponsors

Kaye Prieve and Wendy Ellwein


Recommended