Saturday, 8 October 2016

Knowing your Enemy Part 4



Hi, welcome to the next instalment of our "Knowing Your Enemy" blog series.

This week we are going to focus on two interlinked threat actors “The Professional” and the “Money Mule” and what type of vulnerabilities these types of threat actors are looking to exploit and how. 

Firstly, let’s look at the “Professional” 

The Real-Deal Black Hat

If a hacker’s hat colour is defined by their intentions, the black hat is straightforward bad and, in most cases, straightforward professional. The black hat is the one responsible for that fake tech support call, that un decryptable ransomware and those harvested banking credentials. The black hat has dedicated all his life to cybercrime, and it’s safe to say that he knows human psychology all too well.

Beyond everything else, nowadays black hats are also businessmen who operate a business model called malware-as-a-service (MaaS), or the outsourcing of cybercrime. The worst part is that thanks to MaaS, now every wannabe is welcome to join cybercrime’s vast family.

Ransomware-as-a-service (RaaS), particularly, is the worst. Even though not everyone operating a RaaS scheme is professional enough to deliver a working and sophisticated encryption, its proliferation demonstrates the enormous income a black hat can generate. According to security firm Trustwave, a black hat could easily make $84,000 a month from an investment of $5,900 for the malware they need.

In 2014, Interpol diminished a crime ring operating the Blackshades malware. The criminals behind it were so sophisticated that they had staff and were handing out salaries! They even had a marketing director.
This is not the first case of a cybercrime gang going fully professional. A real-deal black hat would even hire IT experts for the very same reasons that legal companies do. A black hat’s supply chain also needs optimization and propagation.

So, how do these guys operate and how does traditional penetration testing or IT health check activity usually fail to highlight the threats and vulnerabilities associated with this type of actor.

Unfortunately, a lot of organisations only see security testing as a stepping stone for compliance, mandated and usually unwelcome. A request for a proposal would usually contain a rigid scope of systems and multiple levels of constraint’s and limitations being placed over the assessment, that performing a realistic attack simulation is not possible. 

In reality, the attack vectors could surface from multiple areas including through social engineering and phishing assessments, USB drop’s, physical security, through public facing infrastructure and applications.

Thoroughly testing all of these areas routinely would be extremely expensive and time consuming, Fortunately, STAR and red team methodologies are becoming more and more common in the industry, which allows a client to have a better understanding of the likely threats facing their organisation that a Professional threat actor is likely to attempt to exploit. 

Therefore, allowing a security test team to perform a Penetration test across a sampled subset of a limit number of systems is not going to identify the risks present. 

Thoroughly testing all of these areas routinely would be extremely expensive and time consuming and wouldn’t be feasible for an organisation to bring in a specialist 3rd party testing company to do this or a regular basis. Some organisations are realising this and have started to bring security testing in house and making full and thorough testing part an internal risk management program. 

Although there are issues with this, how do you keep the internal team’s skill on the cutting edge, can you be sure you have the breadth of skills and knowledge in a static team. 

Star and Red Team testing allows a client to have a better understanding of the likely threats facing their organisation that a Professional threat actor is likely to attempt to exploit. 

The method adopts a process of performing a certain level of threat intelligence into the assessment, with the aim of identifying any likely threats facing the organisation and focusing the assessment on exploitation of those vulnerabilities. This can be through any number of attack methodologies and usually involves the use of custom malware or targeted social engineering campaigns. 

The Bank of England, along with CREST, have also developed the CBEST program for the financial services industry, which is essentially a STAR assessment and provides the level of testing required to pragmatically deal with the real risks facing an organisation. 

Looking for a security testing company that performs Red Teaming or STAR assessments is the way forward for external security testing. The traditional testing method is still important, especially for internal systems and annual public facing infrastructure and application assessments, in order to provide the defence in depth approach needed.

In order for the “Professional” to be able to generate an income from his illicit activity, he needs to utilise our second threat actor in this series, “The Money Mule”

The Money Mule
No crime can function without mules, cybercrime included. Mules are the final link of a successful cybercrime operation. They are the ones making the dirty money ready-to-use and untraceable. This is often done via internet payments, money transfers, or online auctions.

Mules are typically motivated by greed or desperation. They often work from home, random Internet cafés, or free WiFi hotspots to hide their activities. They are the ones transforming the profits of Internet-based criminal activity into untraceable cash.

Money mules are recruited across the globe and are crucial to money laundering schemes. In Asia and Australia, they are mostly overseas students, while in Europe, they are usually retirees.
So the end result of any successful attack, one that was driven by financial purposes anyway, would be when a Professional needs to access his illicit gains involving money mules.

There really isn’t anything that can be done from a security testing perspective as this is post compromise activity. 

However, proactively monitoring for potential data leakage and evidence of compromise is a very important part risk management.

There is a strong chance that an attack has been successful against your organisation in some form, but it may not have been apparent to security personnel. This is where threat intelligence is again vital, as monitoring any evidence of exploitation of any organisational entity may only be discovered through in depth analysis of hacker forum’s or dark web resources.

Good internal protective monitoring is also extremely important in order to remain informed of any attacks that either have or are currently taking place. 

Links
CREST

Conclusion
During this blog series, knowing your enemy, we have had a look at the different types of threat actors and the relationship that security testing, as part of a balanced security and risk management program, plays in assisting with protecting against compromise. 

Unfortunately, as with any industry, there are good and there are not so good security testing organisations out there selling services. How is an organisation supposed to know who to turn to in order to provide effective security assurance? 

Fortunately, there are companies that are aligned to providing effective testing services through adopting methodologies, processes and standards set by organisations such as the CESG CHECK scheme (via the Tigerscheme and CREST) and the Bank of England’s CBEST scheme for the financial services industry (CREST), that have these effective and comprehensive testing standards and methodologies in place. 

These companies employ Consultants who are security cleared to a at least SC level and have been assessed and accredited to the highest standards of security testing. They can be trusted in order to ethically replicate the threat actors and provide pragmatic advice and direction on how to protect yourself against the growing threat landscape.

Saturday, 1 October 2016

Knowing Your Enemy Part 3.



Hi, welcome to the next instalment of our "Knowing Your Enemy" blog series.

This week we are going to focus on the “The Insider” and what type of vulnerabilities this type of actor is looking to exploit and how. 

The Privileged Employee, or the Insider Threat
The name speaks for itself. The insider, often an employee with privileged access to sensitive data, may willingly or unwillingly be part of a cybercrime operation.
The insider may compromise the company they work for on purpose through sloppiness or through external influence. Alternatively, they may have been a victim of a scam or blackmail.
This ambiguity of his nature often makes insiders the hardest to foresee and counter. In other words, cyber-defences should start with the insider.

Ok, so this threat actor could be extremely dangerous, as they are already inside the outer security perimeter and able to perform an advanced, persistent threat (APT) to an organisation.
They are usually concerned with data theft, possibly with a monetary gain but usually they are disgruntled employee’s out to cause damage to a system. 

How does traditional IT Health Checks and Penetration testing activity cope with this type of threat, well very poorly and there is too much emphasis placed defining specific systems within the scope of testing, rather than allowing a testing team the ability to diversify throughout the environment.

Internal red-teaming would be one way to allow a more effective type of assessment, although this would be difficult to scope and manage in practice. Allowing an external company, the freedom to choose target’s in a live, production environment can be extremely daunting for any business, as the potential for disruption is high.
A solution that can safely automate the typical attack vectors that would emanate through malware payloads or malicious insider actions would be a fair, cost effective solution to the problem.
So what does this mean in practice.  

Well in order to evaluate the threat posed by a malicious insider, you need to look at the entire environmental eco-system as a whole, this includes the user settings on the end user devices, whether it be a Windows workstation that receives group policy updates, or a mobile device that uses a mobile device management system, it could also be an environment where users can bring their own devices which an organisation has little control over the configuration of. 

Then what about the network layer, what ingress and egress points are there in and out of the network, can a user post sensitive data to website forums or connect to malicious malware infested websites.
Removable media is always a prime target for spreading malware, along with emails and malicious websites, so anti-virus, anti-malware, anti-spam and IDS all need to be tested under the guise of a malicious insider.
Fortunately, the industry is catching up and providing solutions to this type of assessment, whether it be through a customised virtual machine (as provided by red wolf security) or through a malware simulation test kit (as provided by Lucy Phishing server) there are options out there that should be adopted and incorporated into the risk management process.
Links

LUCY Phishing Server - Malware Simulation Test

Insider Threat Testing - Red Wolf Security

Conclusion

Insider threat testing is an essential part of modern security testing. Performing server build reviews, internal network security assessments, firewall rule base reviews etc is all well and good and still has a major part to play in the IT Health Check process.
Although if you are not performing internal Red team assessments, using customised malware on a regular basis (which would be ideal, but extremely expensive and could be problematic on a production environment), then adopting an automated tool kit such as those mentioned in this post, alongside the more traditional assessment methodologies, then you are covering the bases.
Progressive and forward thinking security testing Consultancies are adopting this type of testing within their service offerings and methodologies, which can allow them to perform a more pragmatic approach to risk analysis.  

Saturday, 24 September 2016

Knowing Your Enemy Part 2




In the last blog post, knowing your enemy part 1, we looked at the scale of cybercrime in general and highlighted the types of threat actors that are prevalent and pose a serious risk to organisations.
This week we are going to focus on the “Hacktivist” and what type of vulnerabilities this type of actor is looking to exploit and how. 

The Hacktivist
The hacktivist chooses to target his enemies with data theft, reputational damage, and the defacement of websites and denial-of-service attacks. Hacktivism is a real challenge to international affairs and is a powerful instrument. The very fact that hacktivism is a form of protest it a double-edged knife.
Today’s hacktivists are found all over the world, supporting all sorts of causes. And even though hacktivism attacks are not directly related to money loss, there is often something bigger going on behind website defacement or denial-of-service attacks. Eventually, however, it all leads to money leakage.

So, what steps are we talking to protect ourselves from the “Hacktivist”, does a Quarterly vulnerability scan of our remote, external facing infrastructure and web applications provide the level of assurance needed?
Well, it can help, depending on the process adopted and whether the scanning vendor adopts a thorough vulnerability confirmation process and also performs a level of manual testing.
The problem with automated vulnerability scanners is that they rely on typical system signatures and behaviours and cannot see any business logic or processes like an experienced security expert.
I will provide an example of the tree attack methods to show this in more detail. 

  1. Data Theft and Reputational Damage
Ok so data theft means data storage, which from a web app perspective means some form of injection type of attack against a data store, could be SQL or could be in an XML document (XPATH injection). Do VA scanners pick up these types of threats, yes they do and they are by and large very good at it these days. However, will they pick up an injection vulnerability in an area of the application that is only accessible through completing some form of business logic transaction, will the VA be able to step though these processes. Unlikely, unless you are using a tool that can utilise technologies such as Ghost scripts, but even then, these are going to be static not identify all possible scenarios. A tester would be able to manually walk through the application business logic and identify these issues.
As for reputational damage, will a VA know if the data in the backend data store is encrypted or not, no but a manual tester will be able to verify this. 

  1. Website defacement.
There are many ways to deface a website, including cross site scripting, injections (Code, Command, SQL etc). So most of the leading edge vulnerability scanners will pick up the majority of any input validation issues on the input forms.
But what if for example a contact form has a CAPTCHA in order to be processed, the VA scanner will not know how to complete the capture and would therefore fail to complete and process the form in order to test the thousands of potential malicious strings.
A manual test will be able to process this and perform the manual testing needed in order to confirm if this is an issue or not. Implementing a simple CAPTCHA is a very basic way to prevent automated attacks, but they also prevent the automated attacking tools from working, but that does not remove the threat or mitigate the vulnerability. 

  1. Denial of Service
Ok so most of us still think of a denial of service attack at the packet level (SYN Flood, Smurf, PING of Death and more recently, TOR Hammer). These types of attacks are still prevalent but are being protected at the WAF or Firewall effectively, although simply utilising a BOTNET, and attacker can instruct thousands of end systems to send legitimate requests to a website or system in order to overload it, from disparate locations.
This is where the standard network firewall will fail and most likely so will a WAF (application layer), unless it is specifically configured to look for this type of attack – as the traffic will be by and large legitimate.
This type of testing requires the expert to perform automation testing techniques, to see if the system allows the automation of forms without throttling the traffic, which could if such an attack were to be executed, could overload the system.
Automation testing is unfortunately not included in the OWASP web application testing version 4 Guidelines, which is a manual assessment process that is adopted as standard in the Industry, although it is an area of research being undertaken and adopted by the OWASP.
What about automated VA scanner’s? Well they rely on automation in order to be able to function, so if automation protection was in place, they may not function correctly and could report inaccurate results.
There is also the locking of user accounts, how many Pen-test reports where a brute force attack has succeeded through automation and the recommendation is to add an account lockout after say 15 attempts, well couldn’t an attacker utilise that function and lock out all enumerated users accounts (Usually an easily guessable email address) en-mass.
So adopting an effective brute force prevention that does not cause a DoS to end users is vital, but rarely implemented at the time of writing.  

Links

Conclusion
These are the types of issues that a “Hacktivist” will look to exploit. Unfortunately, the default recommendations from automated VA tools and poorly executed manual testing reports provide, which do not help.
So what’s the answer. Well, for web applications, the method of applying a thorough web application assessment (covering the OWASP testing guide 4 plus more in depth area’s as discussed) at least annually alongside regular VA scan’s throughout the year, as with the PCI DSS, is crucial.
Relying on just either a single annual web application assessment of regular VA scan’s will not provide the level of assurance required, as the annual full assessment will cover the depth needed for the issues discussed and the regular scans will cover of any updated input validation strings and techniques, you need to include both in your risk management strategy to remain protected from the “Hacktivist”