Sunday, October 23, 2016

Managing the Kill Chain

Discussion for EA874 Topic 5 > Enterprise Security Architecture
Post # 2

Enterprise security architects today have their hands full as they are tasked to develop security programs that will reduce their organization's attack surface and be able to rapidly respond to contain cyberattacks with security management solutions that enables total network visibility, and analytics which provide actionable security intelligence.  Security architects need to be familiar with the growing set of technology solutions that can combine firewall and network device data with vulnerability and threat intelligence, which enables effective security decisions for rapid response to bring threat management processes under control.

Securing the network against cyberattacks is not a straightforward task with clear-cut solutions. While it is true that enterprise security is currently being hardened with better programs and technologies, we see and hear alarming stories of more powerful and persistent attacks being developed by threat actors. Even more alarming are the data breach incidents that happened to those organizations who we easily perceive as highly advanced technology practitioners.

On September 22, 2016, Yahoo publicly disclosed a data breach on their systems that happened late 2014. Hackers stole information associated with at least 500 million Yahoo! user accounts, and is said to be the largest discovered in the history of the Internet. Specific details of material taken include names, email addresses, telephone numbers, encrypted or unencrypted security questions and answers, dates of birth, and encrypted passwords.  Yahoo alleged in its statement that the breach was carried out by "state-sponsored" hackers.

There is an alarming growth of such cyberattacks:

In June 2015, The Office of Personnel Management of the U.S. government suffered a data breach in which the records of 4 million current and former federal employees of the United States were hacked and stolen.

In September 2014, Home Depot suffered a data breach of 56 million credit card numbers.
In October 2014, Staples suffered a data breach of 1.16 million customer payment cards

In late November to early December 2013, Target Corporation announced that data from around 70 million credit and debit cards was stolen.

In October 2013, Adobe Systems revealed that their corporate data base was hacked and some 130 million user records were stolen. According to Adobe, "For more than a year, Adobe’s authentication system has cryptographically hashed customer passwords using the SHA-256 algorithm, including salting the passwords and iterating the hash more than 1,000 times. This system was not the subject of the attack we publicly disclosed on October 3, 2013. The authentication system involved in the attack was a backup system and was designated to be decommissioned. The system involved in the attack used Triple DES encryption to protect all password information stored.

The list is growing longer each month.

Many of these sophisticated cyber security attacks are generally attributed to groups classified as APT's or Advanced Persistent Threats, and are normally composed of organized syndicates or even state-sponsored actors.





























Image source: https://en.wikipedia.org/wiki/Advanced_persistent_threat

The attacks are sometimes described using the so-called "Kill Chain" model as a method to describe and analyze intrusions on a computer network. The model has it's share of critics, pointing out that the scope of recent intrusions extends far beyond that of the Cyber Kill Chain model. Nonetheless, I think the model can be useful for understanding an approach for developing defense or pre-emptive action against threats.

The following is a brief description of its seven steps.

Step 1: Reconnaissance. The attacker gathers information on the target before the actual attack starts. He can do it by looking for publicly available information on the Internet.

Step 2: Weaponization. The attacker uses an exploit and creates a malicious payload to send to the victim. This step happens at the attacker side, without contact with the victim.

Step 3: Delivery. The attacker sends the malicious payload to the victim by email or other means, which represents one of many intrusion methods the attacker can use.

Step 4: Exploitation. The actual execution of the exploit, which is, again, relevant only when the attacker uses an exploit.

Step 5: Installation. Installing malware on the infected computer is relevant only if the attacker used malware as part of the attack, and even when there is malware involved, the installation is a point in time within a much more elaborate attack process that takes months to operate.

Step 6: Command and control. The attacker creates a command and control channel in order to continue to operate his internal assets remotely. This step is relatively generic and relevant throughout the attack, not only when malware is installed.

Step 7: Action on objectives. The attacker performs the steps to achieve his actual goals inside the victim’s network. This is the elaborate active attack process that takes months, and thousands of small steps, in order to achieve.


In the case of the Target breach of 2013, an analysis using the kill chain model provides facility for deconstructing the attack.





















Image source: http://www.darkreading.com/attacks-breaches/leveraging-the-kill-chain-for-awesome/a/d-id/1317810


/

No comments:

Post a Comment