{"id":79,"date":"2011-11-05T15:16:33","date_gmt":"2011-11-05T20:16:33","guid":{"rendered":"http:\/\/www.hackspherelabs.com\/?p=79"},"modified":"2011-11-05T15:24:32","modified_gmt":"2011-11-05T20:24:32","slug":"phreaknic-post-07-counter-espionage-strategy-and-tactics-nick-levay","status":"publish","type":"post","link":"https:\/\/hackspherelabs.com\/blog\/2011\/11\/05\/phreaknic-post-07-counter-espionage-strategy-and-tactics-nick-levay\/","title":{"rendered":"PhreakNIC 15 &#8211; Post 07 &#8211; Counter Espionage Strategy and Tactics &#8211; Nick Levay"},"content":{"rendered":"<p>Works for the Center for American Progress &#8211; 501(c)(3) + 501 (c)(4).\u00a0 High visibility organization, constant media attention, high profile visitors, lots of research.\u00a0 Threat rich environment because they influence policy.\u00a0 Drive-by attacks.\u00a0 High turnover environment that is also a campus environment.\u00a0 Use your own software, Tweetdeck, they are their own ISP.\u00a0 Many projects at one place need different types of networks.<\/p>\n<p>Satellite Essential Project track things in Africa, etc.\u00a0 Track mass graves, troups, etc.\u00a0 50 cm imagery.<\/p>\n<p>Threat tracking, hactivists, anonymous.\u00a0 APT threat.\u00a0 Intrusion set developed by airforce.\u00a0 China.\u00a0 Tools, methods, and tactics to attack.\u00a0 APT is an actual thing in the end brought about to allow classified people to talk about it.<\/p>\n<p>Advanced:\u00a0 Do what is necessary to get the job done.\u00a0 Adjusts tactics based on targets posture.\u00a0 Public exploits.\u00a0 Work full spectrum of computer intrusion.<\/p>\n<p>Persistent:\u00a0 Patient and will not stop pursuing their goal.<\/p>\n<p>Threat:\u00a0 Not mindless piece of code.\u00a0 Funded, motivated, multiple &#8216;groups&#8217; and &#8216;crews&#8217;.<\/p>\n<p>So many different targets:\u00a0 Google, RSA, Intel, Morgan Stanlet, Lockheed, MS, Adobe, GE, Northrop, Goldman, Juniper.\u00a0 China&#8230;.attacking lots\/all.\u00a0 Involved with China??<\/p>\n<p>APT Workday:\u00a0 Email harvesting Activity @ 6am, after hours, always take lunch.\u00a0 7 day work week.\u00a0 Lot of management and people.<\/p>\n<p>Spearphishing most used attack vector.\u00a0 Crappy ones to good ones.\u00a0 Gmail, Yahoo, etc, addys.\u00a0 Monitoring emails allow for knowledge of abbreviations.\u00a0 Updating contact list a big one.\u00a0 Attacks on American progress.\u00a0 Look at this, its a funny cat.<\/p>\n<p>C2:<\/p>\n<p>Lots of different malware.\u00a0 2x malware, beacon transmits, http, dns.\u00a0 DNS requests fire once an hour.<\/p>\n<p>DNS, HTML Responds, Image Metadata.<\/p>\n<p>Prevention eventually fails.\u00a0 Actor trying to get posture.\u00a0 Authorities will be of little help.<\/p>\n<p>Get top down support.\u00a0 Realistic expectations, everyone&#8217;s responsibility.\u00a0 Mental preparation:\u00a0 Be prepared for the worst day of your career.\u00a0 Be source of calm and reason, never ending struggle, work through your worse case.<\/p>\n<p>Study your opponent, Empathize, Defeat.<\/p>\n<p>Detection, Response, Prevention.\u00a0 Advanced Information Security == Counter-Intelligence.<\/p>\n<p>Internal Threat Intelligence, classify your data, follow news, study the opponent, track their targets.\u00a0 Not just organizations but also people.\u00a0 Where are your users logging in to.<\/p>\n<p>Understand the Kill Chain:\u00a0 Research your target, weaponize,\u00a0 deliver it, open(exploitation), Install something, c2(command and control), Extraction (Getting data out).\u00a0 7 mins to respond.\u00a0 (<a href=\"http:\/\/computer-forensics.sans.org\/blog\/2009\/10\/14\/security-intelligence-attacking-the-kill-chain\/\">http:\/\/computer-forensics.sans.org\/blog\/2009\/10\/14\/security-intelligence-attacking-the-kill-chain\/<\/a>)<\/p>\n<p>Always more then one way to stop attack.\u00a0 If thing that caught attack failed?\u00a0 What would have happened?\u00a0 Job never ends.<\/p>\n<p>Log Management:\u00a0 Log Rhythm, 1 Labs, RSA, ArchSight, loglogic, nitrosecurity.\u00a0 3 periods of about 45 mins a day doing hardcore analytical work.\u00a0 How many people to view these logs&#8230;.human factor.<\/p>\n<p>Big picture:\u00a0 How many servers monitoring vs watching what they are doing.<\/p>\n<p>Segmentation is critical:\u00a0 Servers on one place users on another place, security policies that limits the space at which an attacker can move in an organization.\u00a0 Segment groups.\u00a0 Sonicwall, Juniper, Checkpoint, FW&#8217;s etc.<\/p>\n<p>Scope the comprimise, find it all&#8230;need logging, report.<\/p>\n<p>Admins have their own segmentation.\u00a0 IT separate network.\u00a0 These machines can bring the others back.<\/p>\n<p>Egress Traffic Control &#8211; Log all traffic &#8211; paloalto, ironport, mcafee.\u00a0 Log downloaded files, man in the middle ssl.\u00a0 Servers do not need to talk to the internet.<\/p>\n<p>Control naming and lookups:\u00a0 Log DNS and responses&#8230;.opendns makes this easy.\u00a0 Blackhole DNS hostnames.\u00a0 Only port 53 to your servers.<\/p>\n<p>Update and Vulnerability Management &#8211; Applied less then 48hrs.\u00a0 Bad guys go to patch to exploit within 72hrs.\u00a0 Own a vulnerability management system:\u00a0 Rapid 7, qualys, ncircle.\u00a0 Catch machines not getting updates.<\/p>\n<p>Bit9 &#8211; Endpoint monitoring and Enforcement &#8211; AV useless, bad guys test against it &#8211; banary packing has become a cottage industry.\u00a0 Application whitelisting is the future.\u00a0 Track new exes.<\/p>\n<p>Fake posture, advanced honeypots, fake documents and networks.\u00a0 They know when they are in a honeypot.<\/p>\n<p>nlevay@americanprogress.org<\/p>\n<p>Really likes whitelist.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Works for the Center for American Progress &#8211; 501(c)(3) + 501 (c)(4).\u00a0 High visibility organization, constant media attention, high profile visitors, lots of research.\u00a0 Threat rich environment because they influence [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,8,9],"tags":[35,48,41,36,40,38,37,39],"class_list":["post-79","post","type-post","status-publish","format-standard","hentry","category-conferences","category-hacker-conference-notes","category-phreaknic-2","tag-apt","tag-china","tag-command-and-control","tag-defense","tag-kill-chain","tag-logging","tag-network-security","tag-products"],"_links":{"self":[{"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/posts\/79","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/comments?post=79"}],"version-history":[{"count":5,"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/posts\/79\/revisions"}],"predecessor-version":[{"id":88,"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/posts\/79\/revisions\/88"}],"wp:attachment":[{"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/media?parent=79"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/categories?post=79"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hackspherelabs.com\/blog\/wp-json\/wp\/v2\/tags?post=79"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}