Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

Monday, May 4, 2009

Tunnel Vision

When waging our battles on the security front, most organizations just put all the big guns on the front line. We buy expensive load balancers to prevent D.O.S attacks, state of the art firewalls to prevent penetration, VPN products to secure our backdoors etc. Whenever some major threat comes along, everybody jumps out of bed, and rushes over to plug the hole, but at time like that, we often forget one of the oldest tricks in the burglars book - the diversion (a.k.a "Steaks for the dogs").

Unlike the movies, hacking into a network is not a wham-bam, thank you, ma'am deal. A hacker spends a long time conducting surveillance and gathering intelligence, and when he does move in, it will hardly seem like a commando attack. There won't be alarms ringing or security-doors closing and sealing people off in safe rooms, and no SWAT teams will show up with mega-phones yelling. More often than not, some minor file will be found to be missing or altered several days, weeks or months later, and that will lead to investigation that will show the break in. If you get that dreadful 4 AM phone call, telling you that the Firewall's alerts are all over the place, or that your security center detects multiple attacks, that doesn't mean that someone is actually attacking your firewall.

Just like a commando unit trying to break into an army base will distract the guards with some explosions at the front gate, while trying to sneak in through the back, a computer attacker will most likely try to get the entire security team to focus everything on the very visual notification mechanisms. He will use multiple mechanisms to trigger every possible alert on your security devices, and he will do it at past-midnight so that you and your security team will be tired, angry and less-effective. He will try to get you guys to spend as much time as possible blocking the DOS attack and plugging the holes, while he quietly sneaks in through some back door that's less obvious and less protected. You will find yourself running from server to server, trying to find your hands and feet in gigabytes of logs, and chances are you'll spend days on it. When things quiet down, you might find the actual leak or penetration, but by that time, the attacker will be long-gone.

If this has happened to you, don't be surprised. After all, most information security people are technology gurus, not military-trained commanders, and it's only normal to focus our attention on the most visible threat, just like a driver would focus his attention on the tree he's about to crash into rather than another car that's about to crash into him (that is referred to often as "Tunnel Vision"). However, there is a way to handle this, and that is by preparing properly. Your organizations security policy should have this scenario specifically laid out, and the team needs to be trained not to treat any alert as an alarm. One way is to assign responsibilities to people, and sticking to them. If there is a virus rampant on the network, the backup administrator shouldn't be told to forget about the backups "for now" and help clean up machines. On the contrary! He should continue his work and keep an eye out for anything suspicious or wrong with the procedure. If the firewall appears to be breached, the PC-Technician crew shouldn't be assigned to reviewing logs, but should continue to monitor the user-request queue. Maybe an innocent account lockout request could reveal an account breach that is masked by the pointless firewall attack? Perhaps the virus was unleashed intentionally on the network so that the attacker could have uninterrupted access to the data on the backup server?

Another technique that has worked well for the physical security industry is the emergency level system. A company could create an emergency level scale, and assign specific duties to each. If a file was found to be altered, that would raise the threat level, which would have people deflect some duties and investigate, but wouldn't throw the entire IT group into chaos and mayhem.

Wednesday, January 28, 2009

Bring in the troops

In recent weeks, the Conficker virus has been causing a lot of havoc everywhere – account lockouts, network congestion and a lot of headaches. People running Symantec anti-virus software know the same virus as “Downadup”, and that’s not the 1st time a Virus gets labeled differently by different companies. After all, there’s no single authority that investigates viruses, but that got me thinking – maybe it’s time we had one.

With things as they are now, it takes the anti-virus market some time to react to new viruses. Each AV vendor gets samples from its customers, analyzes them and issues signature updates to its product. Each vendor uses its own methodology to assign a priority, and as a result, some vendors take longer to react. In the Conficker case, for example, Symantec’s product is still unable to remove the infection today, almost 3 months since the virus’s first appearance. Even when an update is issued, it’s usually available only for customers of AV vendors, while users with AV software are stranded (We’ll discuss the stupidity of not having AV software on your computer another time).

When a new type of virus or disease appears in the real world, no one waits for Pfizer or Bayer to classify it and inform the public. In the USA, we have the Department of Health and Human Services and the CDC (Center for Disease Control), as well as other federal agencies like FEMA to help manage outbreaks. Since computer worms and viruses do have an economic impact, which could easily reach disastrous proportions (like in the case of worms such as MS Blaster, Code-Red and Sasser), I feel that this sort of thing should definitely be at-least shared by the governments of the world. A Federal Malware Research Center could bring some order to this wild field, and have the necessary resources to inform the public of new threats and how to manage them.

And another thing, while we're at it...we should stop giving worms "cool" and distinctive names. Maybe if the latest virus was called "The Dumbass 1", virus writers were a little less proud of themselves. Now seriously, a malware's name is not a big deal, but it's sad to say that the press today is still glorifying viruses, thereby encouraging low-self-esteemed jerks to write them. Writing a virus is stupid and detestable, and this message should be delivered clearly whenever the issue is discussed in the media - no discounts or exceptions.

Monday, December 15, 2008

There's no business like the scam business

Just a few days ago, the FTC has finally decided to act against Innovative Marketing, Inc. and ByteHosting Internet Services . These two companies are responsible for many, if not most, technical support calls received by pretty much every company in the world. Their variation of spyware nicknamed "Scareware" sneak in to computers and internet sites, and notify the user that his computer is infected with viruses, urging him to buy an anti-virus from these companies. The "warning" is false mostly, and it is designed and branded to look like a genuine notification from Microsoft or the operating system.

Why did it take the FTC so much time to do something about this menace is beyond me, but the question is this - can the FTC really combat this sort of threat? Despite charging only 40$ for their software, both companies made millions of dollars, and that kind of incentive isn't going to go idle just because of some FTC barking. These companies, just like spammers and other shady or illegal operations have never cowered away from authority. In similar cases, the operators would usually disappear and re-start their operation somewhere else. Sometimes under a new name, and other times in another country. Innovative Marketing already has offices in Ukraine, pretty far from the FTCs grab. In fact, I suspect that there at least a few hundred people reading about this in the media and thinking "Hmmmmm...maybe I should start a business like that?"

The Spam market is a good analogy. We have been fighting spam for years now, and we've tried everything. We've enacted legislation , successfully sued spammers , developed technology to fight it and even raised awareness in the public , but Spam rates haven't decreased significantly. Why? Because as long as there's somebody who will buy it, there will be someone to sell it.

That sounds bleaker than I intended, but are we really going to have to live with these computer annoyances forever? I was never an optimist about human nature, and I'm afraid I can't be one here either. The human race has been battling crime since the dawn of time, and despite some very effective law enforcement and punishment systems, people are still stealing, hurting, killing and more. Bottom line? We shall always rejoice when spammers or other cyber terrorists are taken down, but the hard truth is that this is a fight that's never going to end. Maybe it's time to think of taking out some insurance...