PhreakNIC 15 – Post 07 – Counter Espionage Strategy and Tactics – Nick Levay

Works for the Center for American Progress – 501(c)(3) + 501 (c)(4).  High visibility organization, constant media attention, high profile visitors, lots of research.  Threat rich environment because they influence policy.  Drive-by attacks.  High turnover environment that is also a campus environment.  Use your own software, Tweetdeck, they are their own ISP.  Many projects at one place need different types of networks.

Satellite Essential Project track things in Africa, etc.  Track mass graves, troups, etc.  50 cm imagery.

Threat tracking, hactivists, anonymous.  APT threat.  Intrusion set developed by airforce.  China.  Tools, methods, and tactics to attack.  APT is an actual thing in the end brought about to allow classified people to talk about it.

Advanced:  Do what is necessary to get the job done.  Adjusts tactics based on targets posture.  Public exploits.  Work full spectrum of computer intrusion.

Persistent:  Patient and will not stop pursuing their goal.

Threat:  Not mindless piece of code.  Funded, motivated, multiple ‘groups’ and ‘crews’.

So many different targets:  Google, RSA, Intel, Morgan Stanlet, Lockheed, MS, Adobe, GE, Northrop, Goldman, Juniper.  China….attacking lots/all.  Involved with China??

APT Workday:  Email harvesting Activity @ 6am, after hours, always take lunch.  7 day work week.  Lot of management and people.

Spearphishing most used attack vector.  Crappy ones to good ones.  Gmail, Yahoo, etc, addys.  Monitoring emails allow for knowledge of abbreviations.  Updating contact list a big one.  Attacks on American progress.  Look at this, its a funny cat.

C2:

Lots of different malware.  2x malware, beacon transmits, http, dns.  DNS requests fire once an hour.

DNS, HTML Responds, Image Metadata.

Prevention eventually fails.  Actor trying to get posture.  Authorities will be of little help.

Get top down support.  Realistic expectations, everyone’s responsibility.  Mental preparation:  Be prepared for the worst day of your career.  Be source of calm and reason, never ending struggle, work through your worse case.

Study your opponent, Empathize, Defeat.

Detection, Response, Prevention.  Advanced Information Security == Counter-Intelligence.

Internal Threat Intelligence, classify your data, follow news, study the opponent, track their targets.  Not just organizations but also people.  Where are your users logging in to.

Understand the Kill Chain:  Research your target, weaponize,  deliver it, open(exploitation), Install something, c2(command and control), Extraction (Getting data out).  7 mins to respond.  (http://computer-forensics.sans.org/blog/2009/10/14/security-intelligence-attacking-the-kill-chain/)

Always more then one way to stop attack.  If thing that caught attack failed?  What would have happened?  Job never ends.

Log Management:  Log Rhythm, 1 Labs, RSA, ArchSight, loglogic, nitrosecurity.  3 periods of about 45 mins a day doing hardcore analytical work.  How many people to view these logs….human factor.

Big picture:  How many servers monitoring vs watching what they are doing.

Segmentation is critical:  Servers on one place users on another place, security policies that limits the space at which an attacker can move in an organization.  Segment groups.  Sonicwall, Juniper, Checkpoint, FW’s etc.

Scope the comprimise, find it all…need logging, report.

Admins have their own segmentation.  IT separate network.  These machines can bring the others back.

Egress Traffic Control – Log all traffic – paloalto, ironport, mcafee.  Log downloaded files, man in the middle ssl.  Servers do not need to talk to the internet.

Control naming and lookups:  Log DNS and responses….opendns makes this easy.  Blackhole DNS hostnames.  Only port 53 to your servers.

Update and Vulnerability Management – Applied less then 48hrs.  Bad guys go to patch to exploit within 72hrs.  Own a vulnerability management system:  Rapid 7, qualys, ncircle.  Catch machines not getting updates.

Bit9 – Endpoint monitoring and Enforcement – AV useless, bad guys test against it – banary packing has become a cottage industry.  Application whitelisting is the future.  Track new exes.

Fake posture, advanced honeypots, fake documents and networks.  They know when they are in a honeypot.

nlevay@americanprogress.org

Really likes whitelist.

Leave a Reply

Your email address will not be published. Required fields are marked *