Better late than never, but the first of a series of blogs from me covering my ever cynical view of security predictions has now been posted to the NCC Group website.
Check out https://www.nccgroup.com/en/blog/2015/01/a-cynics-view-of-2015-security-predictions-part-one/ today. And more to come later this week.
I think yo'll enjoy it ;-)
Showing posts with label predictions. Show all posts
Showing posts with label predictions. Show all posts
Tuesday, January 20, 2015
Wednesday, December 8, 2010
Threat Landscape in 2011
OK, so it's that time of the year again and all the security folks are out making predictions. And, as usual, I have a number of inbound calls for me to pump out the same. Not necessarily "the same" predictions though - since why would marketing and PR teams want to pimp "the same" predictions as everyone else... that'll never get mentioned in the press... ideally a few predictions about how the world will come to an end and preferably in a way that no one has though of before. You know the sort of prediction I mean - "By the end of 2011, cyber criminals will have full control of the electronic systems that control sewer pipes in the US and will be extorting cities for millions of dollars - or else they flood the city and cause massive deaths from typhoid and plague."Cynicism in the run up to Christmas? Bah-humbug :-)
Anyway, despite all that, "predictions" can be pretty useful - but only if they're (mostly) correct and can be actionable. So, with that in mind, I've posted some "expectations" (rather than predictions) for 2011. I think it's important to understand the trends behind certain predictions. A prediction that comes from no where, with no context, and with no qualification is about as helpful as a TSA officer.
Here are the 2011 predictions (aka expectations) I posted on the Damballa blog:
- The cyber-crime ecosystem will continue to add new specialist niches that straddle the traditional black and white markets for both the tools they produce and information they harvest. The resulting gray-markets will broaden the laundering services they already offer for identities and reputation.
- Commercial developers of malware will continue to diversify their business models and there will be a steady increase in the number of authors that transition from “just building” the malware construction kits to running and operating their own commercial botnet services.
- The production of “proof-of-concept” malware, hitherto limited to boutique penetration testing companies, will become more mainstream as businesses that produce mechanical and industrial goods find a greater need to account for threats that target their physical products or production facilities.
- 4. Reputation will be an increasingly important factor in why an organization (or the resources of that organization) will be targeted for exploitation. As IP and DNS reputation systems mature and are more widely adopted, organized cyber-criminals will be more cognizant of the reputation of the systems they compromise and seek to leverage that reputation in their evasion strategies.
- The pace at which botnet operators update and reissue the malware agents on their victims’ computers will continue to increase. In an effort to avoid dynamic analysis and detection technologies deployed at the perimeter of enterprise networks or operating within the clouds of anti-virus service providers, criminal operators will find themselves rolling out new updates every few hours (which isn’t a problem for them).
- Malware authors will continue to tinker with new methods of botnet control that abuse commercial web services such as social networks sites, micro-blogging sites, free file hosting services and paste bins – but will find them increasingly ineffective as a reliable method of command and control as the pace in which takedown operations by security vendors increases.
- The requirement for malware to operate for longer periods of time in a stealthy manner upon the victim’s computer will become ever more important for cyber-criminals. As such, more flexible command and control discovery techniques – such as dynamic domain generation algorithms – will become more popular in an effort to thwart blacklisting technologies. As the criminals mature their information laundering processes, the advantage of long-term host compromises will be evident in their monetary gains.
- The rapidity in which compromised systems are bought, sold and traded amongst cyber-criminals will increase. As more criminals conduct their business within the federated ecosystem, there will be more opportunity for exchanging access to victim computers and greater degrees of specialization.
- Botnet operators who employ web-based command and control portals will enhance their security of both the portal application and the data stolen from their botnet victims. Encryption of the data uploaded to the data drop sites will increase and utilize asymmetric cryptography in order to evade security researchers who reverse engineer the malware samples.
- The requirement for “live” and dynamic control of victims will increase as botnet operators hone new ways of automatically controlling or scripting repeated fraud actions. Older botnets will continue their batch-oriented commands for noisy attacks, but the malware agents and their command and control systems will grow more flexible even if they aren’t used.
Friday, June 26, 2009
Making Money with Your Own Stealthy Botnet - Part I
Over the last month or so I've had quite a few conversations with friends and former colleagues concerning what are the "cool" things you could do with your very own private botnet. Most of these conversations stem from them wanting to learn more about what I'm now doing - having joined Damballa a little while ago - and some of the nasty things criminals are doing with their botnets... which often deteriorates in to a "if I had a big botnet I'd..." type of discussion.So, several ideas have been thrown around and I figured it would make an interesting series of blogs.
If I had a botnet...
"If I had a botnet..." is an interesting way of thinking about how criminal use of botnet may evolve over the next few years. While the news is full of stories and stats about monster botnets being built up and the volume of spam they're capable of pumping out, those are actually the boring ones (from a threat perspective) - and probably the least efficient use of a botnet. If your intent is to make money from a botnet, then using it for spam is effectively chump-change.
So, "if I had a botnet... how would I make real money from it?" - that's the killer question, and the one I'm going to explore.
1. The Custom Advertiser
Lets assume that I have a medium-sized botnet of some 50,000 victim hosts - most of which are home PC's on local DSL networks. Since acquiring (or reacquiring) those victims is a raw cost to me, anything I do with my botnet needs to be subtle and go undetected for as long as possible.
The users of the bot-infected computer, like most of the Internet-browsing planet, are constantly surfing sites plastered with advertising. Since my bot-agent is running on their host and is capable of both hooking the TCP/IP stack (i.e. man-in-the-middle) and operating within the browser (i.e. man-in-the-browser), I can intercept, view and edit any Web content before it gets rendered within the browser.
Since advertising seems to be a profitable route, why not replace those ads with ads of my own choosing? It's simple to do - in fact it's damned-near trivial. It's not even a new idea - some major ISP's around the world have toyed with doing similar things in the past (if not actually doing it today).
Armed with this capability to replace advertising (such as anything from ad.doubleclick.net etc.) a handful of business opportunities suddenly appear:
- Strike up a deal with a particular organization and offer to plaster their ads on to every page 50,000 people view for an entire day.
- Modify the code surrounding the legitimate advertisement such that if the user click on it they'll be taken to a different site. This could even be keyword based - for example, any legitimate ads for drugs and health care products get redirected to Canada Online Pharmacy. Think in terms of Phorm for ad replacement.
- Replace the advertising with my own ads that are actually just redirects/proxies to ads being served from sites I already control. That way I'm serving legitimate ads, but any click-throughs are being associated with my Web site rather than the site the user was actually on.
- Screw around with a company I don't like. Since most managed online advertising campaigns are supposed to be targeted against a specific audience - and they pay through the nose for each click-through. I could plaster their advertising everywhere such that they exhaust their daily online budget really fast and miss their target audience.
- I think it would be a struggle to entice a legitimate/mainstream company to use my advertising services, so I'd be stuck selling to some company comfortable operating in the gray areas of the Internet. This means I'm not going to be able to attract top dollar for the advertising - so maybe I can only charge $2-5k per day. I'm also going to have to be careful of serving up too much of the same advertising to the same people and having them suspect something isn't quite right with their PC and asking questions that could reveal what I'm up to.
- I'd likely have to deal with the same kinds of gray companies as for (1), but I could probably make more money. I'd be expecting the same daily rate of return on the advertisement placements (e.g. $2-5k), but I could probably also get a cut of any subsequent sales (e.g. like the way pharma-scam franchises currently work).
- This could potentially yield me the most money. It'll be a little unpredictable, and I'd have to be careful not to be detected by the real advertising company (e.g. Google has some pretty sophisticated means for spotting click-fraud, and might catch this vector - but I could do some other magic such as modifying the victims REFERER fields to fake the source of their click). The advantage with this is that I could set it up all online and never actually have to speak with anyone... and I'd get cheques in the mail each month.
- I don't think I'd actually make any money out of this unless I approached a competitor to the business being targeted. I might be able to get a few hundred dollars a day, but I'd end up having to explain how the scam works to them - which would shorten the viable life of the scam.
Look out for the next installment of Making Money with Your Own Stealthy Botnet...
Saturday, April 18, 2009
The Fine Art of Attack Prediction
Internet security is gradually evolving from an art in to a science - particularly the evaluation of vulnerabilities in terms of threat impact and business risk (to which I think that CVSS has played a significant role in galvanizing the major software vendors). That said, one security realm still firmly entrenched as an art is "threat prediction".The way I see it, "Threat Modeling" is quite a bit different from "Threat Prediction". While the former focuses on using existing threat information to model trends and evaluate risk profiles (often incorporating measurement systems such as CVSS), the later tends to assume longer timescales and deals with factors or industry trends that can not be reasonably precomputed and modeled.
Threat prediction typically requires the crystal ball to be rolled out and, depending upon the diviner, can be a little hit or miss at the best of times. However, I've found that threat predictions tend to become more accurate if you assume a few things first:
- If the bad-guys can make money from exploiting it, then you bet that they'll try.
- The more sophisticated the technology, the more vulnerable it is to primitive attack.
- The lowest hanging fruit are the first to fall.

Common Sense Threat Prediction
Threats are evolving at an increasing pace, but in most areas it's not too hard to predict a few years in to the future. While many "new" threats appear original at first glance, if you study your Internet security history you'll soon be able to draw parallels with past and present threats. In fact, the more you understand the mechanisms that shaped past threats, the better you'll be able to predict how new ones will evolve.
For example, look at how protection against password guessing as evolved...
- [Whitehat] Force the user to supply a password in order to login - thereby stopping the blackhat from logging in with just the UserID.
- [Blackhat] Passwords can be guessed, automatically cycle through popular passwords to find the right one for the UserID and gain entry to the system.
- [Whitehat] Implement an account lockout procedure consisting of a maximum failed guess threshold (e.g. three failed password attempts and the account becomes inactive).
- [Blackhat] Abuse the threshold procedure to lockout lots of users accounts and construct a denial of service attack - seeking to make money via extortion.
- [Whitehat] Setup a proceedure to automatically 'unlock' locked accounts after a few minutes or hours - thereby negating the DoS threat and inconvenience to the end user.
- [Blackhat] Implement horizontal guessing of passwords. Armed with a long list of known UserID's, try the same password against each UserID before trying a different password - thereby making use of automated account unlocking without adversely hindering the guessing process.
- [Whitehat] Implement CAPTCHA's to stop the blackhat from using automated tools to pass the Turing test and guessing the USERID password.
- [Blackhat] Socially engineer or recruit other Internet users to answer the CAPTCHA's and include the results in to the automated password guessing tool. [more discussion on these techniques can be found here and here].
A thing to bear in mind with the example above is that the overall "password battle" between blackhats and whitehats evolved throughout a decade - with the most rapid change occuring within the first couple of years (note that CAPTCHA's have only been popular as an anti-automation technique for 2-4 years, and it's only in the last year that we've seen the criminal blackhats recruit and pay Internet employees to break CAPTCHA's).It's probably also worth pointing out that particular Internet threats and attack techniques never actually disappear, and it's not uncommon for the same threat to reappear several years later in a slightly different guise because of some new implementation of an old (and vulnerable) technology. I wrote a whitepaper on the topic a couple of years ago - Old Threats Never Die.
With all that in mind, It's also worth pointing out that threat prediction is getting easier. While the technologies are getting more and more sophisticated (and integrated), if you keep the thought "how would I make money from exploiting it?" at the forefront of your mind, you'll probably be reasonably good at predicting what the bad-guys will do
Monday, January 5, 2009
Week of (not my) Security Predictions for 2009
For a bit of fun I'm taking a look at the multitude of "2009 Security Predictions" which all the key security vendors and magazines have been pumping out over the last month and picking at them a little.
To make it a little more exciting I'm calling it the "Week of (someone else's) Security Predictions 2009". I've posted the first blog today, and I'll continue throughout the week - short of being hit by a bus or the X-Force blog crashing (again).
You can find the first days entry on Frequency X, where I've picked on Cisco's rather lame and unimaginative predictions (as newbies on the block, I guess they're just playing it safe).
To make it a little more exciting I'm calling it the "Week of (someone else's) Security Predictions 2009". I've posted the first blog today, and I'll continue throughout the week - short of being hit by a bus or the X-Force blog crashing (again).
You can find the first days entry on Frequency X, where I've picked on Cisco's rather lame and unimaginative predictions (as newbies on the block, I guess they're just playing it safe).
Labels:
2009,
Cisco,
Frequency X,
IBM,
ISS,
predictions,
security
Subscribe to:
Posts (Atom)