The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label EMC. Tampilkan semua postingan
Tampilkan postingan dengan label EMC. Tampilkan semua postingan

Selasa, 25 September 2012

Faulty Attribution Analysis by RSA's VOHO Report Negates Its Findings

RSA's First Watch Research and Intelligence Team just released its VOHO report (.pdf) with the declaration that China was responsible (aka "APT"). Their attribution analysis was summarized in two paragraphs:
RSA FirstWatch research has revealed an exploit and compromise campaign with connections over the past 8 months.  The collected data suggests that this attack was orchestrated and carried out by threat actors commonly referred to in the industry as “APT”:
  1. Use of the “xKungFoo” script kit for victim redirection
  2. Use of attack methodology that matches motives seen in past APT attacks – most notably such as those seen in the Aurora and GhostNet campaigns
  3. Use of the “gh0st” remote access tool (RAT) in this and previous campaigns
  4. Use of command and control infrastructure in the Hong Kong area in this and previous campaigns
  5. Gross impact and on almost 900 unique organizations 
  6. Targets of Interest and Opportunity being geographically disperse in addition to industrial & vertical diverse with a heavy concentration in the following areas:
    • International finance & banking
    • Technology
    • Government – municipal, state, federal and international 
    • Utilities & energy
    • Educational 
    • Defense Industrial Base (DIB)
    • Corporate Enterprise
The possibility exists that this was intentional misdirection on the part of the attackers in
regards to their origin
(emphasis added). However, the RSA FirstWatch team believes the data supports our analysis and this is further evidence of APT intrusion into United States government and corporate assets.
Of those two paragraphs, only one sentence was dedicated to alternative analysis (the one in italics). While it may seem like I'm picking on RSA, they aren't the only InfoSec company that performs lazy, biased analysis. Every company that has issued a report which included a section on attribution has failed to assess the alternatives in a non-biased, rigorous manner (.pdf). RSA's VOHO report can serve as an example of what I mean. Readers are encouraged to look for these types of analytic errors in other InfoSec reports as well.

Use of "xKungFoo script"
The authors referenced the work of researcher Mila at Contagio Dump. While it's true that the xKungFoo script is written in Chinese, that doesn't mean that Chinese hackers were responsible, nor does it mean that a person of Chinese descent wrote it. I personally know Russian, American, and Indian engineers who speak and write Chinese fluently. More importantly, as Mia pointed out in the same blog post footnoted by RSA's researchers, the xKungFoo script is widely available for anyone to use so even if it was originally created by a Chinese hacker, it doesn't mean that it was used by Chinese hackers in all instances.

Use of Attack Methodology that Matches Motives Seen in Past APT Attacks
- Watering Hole Specifics
The authors acknowledge that "the idea of using a target’s interests and likely access points is not a new method of attack" but that its scale is notable. The authors go on to note the array of websites that were used as lures:
  • Related to Boston, MA
  • Related to political activism
  • Related to Washington DC Metro area
  • Related to the Defense Industrial Base
  • Related to Education
There's nothing in this grouping which would attribute this attack to any one State or non-State actor.
Additionally, the authors wrote that "one of the main sources of infection for these campaigns were sites that support the cause of democratic process in non-permissive environments, or the communication of information related to free speech. " That's way too broad an assessment to come to any conclusion on attribution. In fact, this entire section of the report doesn't include a single piece of evidence that would uniquely identify an attacker.

Use of GhostRAT
Under the reports' Attack Methodology section, it refers to the use of Ghost RAT, a widely available Remote Access Tool which anyone can use. The fact that it was used in an attack against the Dalai Lama in 2008 (GhostNet) doesn't mean that all of the later attacks which used this tool originated with the same group. In fact, even the GhostNet researchers refrained from attributing this attack to China's government.

Use of Hong Kong ISPs
The geolocation of command and control servers is probably the weakest evidence that one can give when assigning attribution, especially when the suspected attacker is China - the world's most popular cyber villan.

Targets of Interest
The targets of interest mentioned by the authors are too broad to be attributed to any one nation state. In fact, the targets of interest combined with the use of widely available malware and Hong Kong-based C&C servers makes it more likely that this was the work of an Eastern European hacker crew who was casting a wide net for data that it could sell to interested third parties.

SUMMARY
Intelligence is a two-part process: collection and analysis. RSA and its peers, by virtue of their widespread customer base, do a very good job with the collection of data but they fail in performing rigorous analysis. Further, because RSA is a vendor in the business of gaining market share, it's good business today to blame China. I know from experience that many corporations, government and DOD organizations are more eager to buy cyber threat data that claims to focus on the PRC than any other nation state. When the cyber security industry issues PRC-centric reports like this one without performing any alternative analysis of the collected data, and when the readership of these reports are government and corporate officials without the depth of knowledge to critically analyze what they're reading (i.e., when they trust the report's authors to do the thinking for them), we wind up being in the position that we're in today - easily fooled into looking in one direction when we have an entire threat landscape left un-attended. We got into that position because InfoSec vendors have been left alone to define the threat landscape based upon their product offerings. In other words, vendors only tell customers to worry about the threats that their products can protect them from and they only tell them to worry about the actors that they can identify (or think that they can identify). This has resulted in a security awareness clusterfuck of epic proportions. For more information on how the threat landscape should be defined (versus how it's being defined by security vendors), see my paper "Intelligence Preparation of the Information and Communications Environment".
Add to Cart View detail

Jumat, 10 Juni 2011

EMC's Anti-Security Culture: Business First, Security Second

(Updated with additional copy and links - 1920 EST 10 Jun 2011): NetWitness' Chief Security Officer Eddie Schwartz has apparently become the first CSO that EMC's RSA Security division has ever had, which I thought was pretty amazing for a world leader in security technology. In the course of looking into who holds the position at RSA's parent company, EMC, I ran across an EMC Leadership and Innovation article written by former EMC CSO Roland Cloutier that expressed a corporate philosophy which, in my opinion, contributed to the success of the RSA attack earlier this year:
Security must be a business enabler 
Cloutier is adamant that security must be deployed in the service of business goals, enabling the innovation and responsiveness that create competitive advantage. "As security practitioners, our aim is to create an environment for our executives, engineers, and sales folks to build, deliver, and service the absolute best technologies without any impedance or concern about security in our environment," he says. "We want them to understand that security is not a business inhibitor."
One of the recommendations that Cloutier makes in order to keep security from becoming a "business inhibitor" is contained in a special EMC 2009 report "Top Global Security Officers Reveal Strategies for Driving Business Advantage in an Economic Crisis" when he apparently shrunk EMC's security department by 25% in order to create more "efficiency":
"In a tough economy, it's tempting for enterprises to rein in business innovation," said RSA President Art Coviello. "However, strategic initiatives that enable revenue growth and operational transformation are more critical than ever. Security practitioners can help business leaders safely pursue the most lucrative business opportunities by understanding the risk picture and identifying the right trade-offs. At the same time, security teams must find ways to squeeze the most out of every dollar. For example, EMC's Chief Security Officer and council member Roland Cloutier recently freed 25% of EMC's monitoring and response operational resources and achieved a four-fold improvement in alert performance by consolidating device, application and technology monitoring into a centralized SIEM solution."
 EMC's commitment to automation as a "sound" security practice continued right up to February 2011 with the release of their latest RSA security paper "Mobilizing Intelligent Security Operations for Advanced Persistent Threats" (.pdf). No wonder the marketing buzzword "APT" showed up in Art Coviello and Uri Rivner's statements about the March attack. The entire EMC technology and security leadership just finished writing a white paper on it! Here's one of the authors' three recommendations for defending against an APT attack:
3. Focus on developing capabilities that enable the analysis of security information in real time and the automatic adaptation of IT-based defenses. Automation will be essential in minimizing reaction times to attacks: the faster organizations can adapt and stay ahead of the attack, the less time the APT has to cause damage. 
The common theme underscoring all three reports is that in EMC's view automation as an efficiency measure AND a security necessity. It may be a necessity for enabling profitability in a down economy but automated defenses are counter-intuitive for any company that wants to protect its crown jewels from a dedicated and well-funded adversary. Here's why:

An automated solution will never stop a customized attack because the attack was designed to circumvent it!

I'm giving the keynote speech at Basis Technology's Government Users Conference next week on the lack of Cloud security and how Cloud services are becoming sophisticated attackers' preferred targets. Finding economies of scale works for an adversary. It almost never works for the defender. This is a lesson that EMC should have learned by now - the hard way.
Add to Cart View detail

Selasa, 31 Mei 2011

An Open Source Analysis Of The Lockheed Martin Network Breach

From RSA website
On Saturday 21 May 2011, multiple U.S. defense contractors [2] had their networks attacked by hackers who, in the case of Lockheed Martin, used duplicates of RSA's SecurID tokens to gain access to Lockheed's internal network. Of the possible defense contractors mentioned by Reuters (Boeing, Raytheon, General Dynamics, Northrup Grumman, Lockheed Martin) only Lockheed Martin has made public statements about the attack once LM employees began leaking information about the breach to tech blogger Robert X. Cringely on Wednesday May 25th [3].

Here's what is known about the attack so far:
  1. On Saturday night, May 21, 2011 [2], Lockheed Martin's  (NYSE:LMT) network was breached by attackers who created duplicates to EMC Corp's (NYSE:EMC) RSA SecurID tokens [1]
  2. Late Sunday night, May 22, Lockheed shut down all remote access to its intranet for at least one week, possibly longer [3], [4].
  3. On Wednesday, May 25, Lockheed announced that all employees would have to reset their passwords; that all SecurID tokens would be replaced with new ones; and added an additional password requirement for remote logins [3], [4].
Lockheed's official press release [6] about the attack contains contradictory language that calls into question how accurate its own assessments are:
BETHESDA, Md, May 28th, 2011 -- On Saturday, May 21, Lockheed Martin detected a significant and tenacious attack on its information systems network. The company’s information security team detected the attack almost immediately, and took aggressive actions to protect all systems and data. As a result of the swift and deliberate actions taken to protect the network and increase IT security, our systems remain secure; no customer, program or employee personal data has been compromised.
The word tenacious means "not easily dispelled" and "persisting in existence". An attack cannot be "swiftly" dealt with and "persistent" at the same time. Further "almost immediately" doesn't reconcile with the timeline provided by the above publicly available data, which implies that the attackers had up to 24 hrs of access to Lockheed's network before VPN access was shut off. Finally, while Lockheed claimed that no customer, program, or employee data had been compromised, it was significant enough for President Obama to receive a personal briefing on it, and for DHS and DOD (and presumably NSA) to offer their assistance on Lockheed's investigation [2], [4], [5].

Lockheed had slightly over two months from the time that EMC notified them and other RSA SecurID customers about their breach. At that time, at least one prime defense contractor (not Lockheed Martin) made the decision to stop using RSA SecurIDs for its senior staff and found a completely different vendor to supply their security tokens (7). Based upon their remediation actions for this breach, Lockheed Martin's senior executives chose to do very little about the compromised SecurID token technology in spite of many warnings issued by security specialists about the potential aftereffects of the RSA attack . Of particular note is the warning issued by ICANN's Whitfield Diffie, a crytographic expert who told John Markoff of the New York Times that "a worst case scenario would be that the intruder could produce cards that duplicate the ones supplied by RSA, making it possible to gain access to corporate networks and computer systems"[8]. Apparently that's precisely what happened [1].

Lockheed Martin has a history of significant cybersecurity breaches dating back to Titan Rain in 2003 [9], and the F-35 Joint Strike Fighter program in 2009 [10]. It has never publicly acknowledged the F-35 breach and it landed on the wrong side of the Sandia National Labs lawsuit (LM manages the lab) when a jury awarded a multi-million verdict to Shawn Carpenter for wrongful termination. By some ironic twist of fate, Shawn's employer NetWitness was just acquired by EMC corporation shortly after its SecurID breach and a month or so before Lockheed's.

Clearly, the extent of the RSA SecurID breach was worse than EMC reported to the public, to the Securities and Exchange Commission, and to its customers; at least the ones that I've spoken to. EMC is still refusing to acknowledge its role in this attack [11]. It'll be interesting to see if EMC is sued by Lockheed Martin or any of the other defense contractors for not providing accurate information on the extent of their SecurID compromise and/or fined by the SEC for same, even if Lockheed management couldn't read the tea leaves for themselves.

REFERENCES:
[1] Reuters 27 May 2011: "Exclusive: Hackers breached US Defense Contractors": http://www.reuters.com/article/2011/05/27/us-usa-defense-hackers-idUSTRE74Q6VY20110527
[2] NYTimes 29 May 2011: "Lockheed Strengthens Network Security After Hacker Attack"
http://www.nytimes.com/2011/05/30/business/30hack.html?_r=1&partner=rss&emc=rss
[3] I, Cringely blog 25 May 2011: "InsecurID: No More Secrets?" http://www.cringely.com/2011/05/insecureid-no-more-secrets/
[4] Reuters 29 May 2011: "Lockheed says frequent cyber target from around the world" http://www.reuters.com/article/2011/05/29/us-usa-defense-hackers-idUSTRE74Q6VY20110529
[5] MSNBC (Reuters) 28 May 2011: "Lockheed Thwarts Cyber Attack": http://www.msnbc.msn.com/id/43199200/ns/technology_and_science-security/t/lockheed-martin-says-it-thwarted-tenacious-cyber-attack/
[6] Lockheed.com 28 May 2011: "Lockheed Martin Customer, Program And Employee Data Secure": http://www.lockheedmartin.com/news/press_releases/2011/0528hq-secuirty.html
[7] SANS Newsbites, Vol. XIII, issue 24 (editorial comment by Alan Paller): http://www.sans.org/newsletters/newsbites/newsbites.php?vol=13&issue=24&rss=Y
[8] NY Times, 17 March 2011: "SecureID Company Suffers A Breach Of Data Security": http://www.nytimes.com/2011/03/18/technology/18secure.html?_r=1
[9] Time.com, 29 August 2005: "The invasion of the Chinese cyberspies": http://www.time.com/time/magazine/article/0,9171,1098961,00.html
[10] WSJ.com, 21 April 2009: "Computer Spies Breach Fighter Jet Project":
http://online.wsj.com/article/SB124027491029837401.html
[11] NY Times, 29 May 2011: "Lockheed Strengthens Network Security After Hacker Attack": http://www.nytimes.com/2011/05/30/business/30hack.html?_r=2&partner=rss&emc=rss

RELATED POSTS:
EMC and Google Lawyers Walked Into A Bar ...
What The RSA and NASDAQ Directors Desk Attacks Have In Common
Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID