Discussion for EA874 Topic 5 > Enterprise Security
Architecture
Post # 2
Post # 2
Enterprise security architects today have their hands full as
they are tasked to develop security programs that will reduce their
organization's attack surface and be able to rapidly respond to contain
cyberattacks with security management solutions that enables total network
visibility, and analytics which provide actionable security intelligence. Security architects need to be familiar with
the growing set of technology solutions that can combine firewall and network
device data with vulnerability and threat intelligence, which enables effective
security decisions for rapid response to bring threat management processes
under control.
Securing the network against cyberattacks is not a
straightforward task with clear-cut solutions. While it is true that
enterprise security is currently being hardened with better programs and
technologies, we see and hear alarming stories of more powerful and persistent
attacks being developed by threat actors. Even more alarming are the data
breach incidents that happened to those organizations who we easily perceive as
highly advanced technology practitioners.
On September 22, 2016, Yahoo publicly disclosed a data breach on
their systems that happened late 2014. Hackers stole information associated
with at least 500 million Yahoo! user accounts, and is said to be the largest
discovered in the history of the Internet. Specific details of material taken
include names, email addresses, telephone numbers, encrypted or unencrypted
security questions and answers, dates of birth, and encrypted passwords. Yahoo alleged in its statement that the
breach was carried out by "state-sponsored" hackers.
There is an alarming growth of such cyberattacks:
In June 2015, The Office of Personnel Management of the U.S.
government suffered a data breach in which the records of 4 million current and
former federal employees of the United States were hacked and stolen.
In September 2014, Home Depot suffered a data breach of 56
million credit card numbers.
In October 2014, Staples suffered a data breach of 1.16 million
customer payment cards
In late November to early December 2013, Target Corporation
announced that data from around 70 million credit and debit cards was stolen.
In October 2013, Adobe Systems revealed that their corporate
data base was hacked and some 130 million user records were stolen. According
to Adobe, "For more than a year, Adobe’s authentication system has
cryptographically hashed customer passwords using the SHA-256 algorithm,
including salting the passwords and iterating the hash more than 1,000 times.
This system was not the subject of the attack we publicly disclosed on October
3, 2013. The authentication system involved in the attack was a backup system
and was designated to be decommissioned. The system involved in the attack used
Triple DES encryption to protect all password information stored.
The list is growing longer each month.
Many of these sophisticated cyber security attacks are generally
attributed to groups classified as APT's or Advanced Persistent Threats, and
are normally composed of organized syndicates or even state-sponsored actors.
Image source: https://en.wikipedia.org/wiki/Advanced_persistent_threat
The attacks are sometimes described using the so-called
"Kill Chain" model as a method to describe and analyze intrusions on
a computer network. The model has it's share of critics, pointing out that the
scope of recent intrusions extends far beyond that of the Cyber Kill Chain
model. Nonetheless, I think the model can be useful for understanding an approach for
developing defense or pre-emptive action against threats.
The following is a brief description of its seven steps.
Step 1: Reconnaissance. The attacker gathers information on the
target before the actual attack starts. He can do it by looking for publicly
available information on the Internet.
Step 2: Weaponization. The attacker uses an exploit and creates
a malicious payload to send to the victim. This step happens at the attacker
side, without contact with the victim.
Step 3: Delivery. The attacker sends the malicious payload to
the victim by email or other means, which represents one of many intrusion
methods the attacker can use.
Step 4: Exploitation. The actual execution of the exploit, which
is, again, relevant only when the attacker uses an exploit.
Step 5: Installation. Installing malware on the infected
computer is relevant only if the attacker used malware as part of the attack,
and even when there is malware involved, the installation is a point in time
within a much more elaborate attack process that takes months to operate.
Step 6: Command and control. The attacker creates a command and
control channel in order to continue to operate his internal assets remotely.
This step is relatively generic and relevant throughout the attack, not only
when malware is installed.
Step 7: Action on objectives. The attacker performs the steps to
achieve his actual goals inside the victim’s network. This is the elaborate
active attack process that takes months, and thousands of small steps, in order
to achieve.
In the case of the Target breach of 2013, an analysis using the
kill chain model provides facility for deconstructing the attack.
Image source: http://www.darkreading.com/attacks-breaches/leveraging-the-kill-chain-for-awesome/a/d-id/1317810
/
No comments:
Post a Comment