Showing posts with label threats. Show all posts
Showing posts with label threats. Show all posts

Monday, July 22, 2019

Digital Transformation Makes the Case for Log Retention in Cloud SIEMs

As organizations pursue their digital transformation dreams, they’ll migrate from on-premises SIEM to cloud-based SIEM. In the process of doing so, CISOs are taking a closer look at their previous security incident and event log retention policies, and revisiting past assumptions and processes.

For organizations needing to maintain a smorgasbord of industry compliance and regulatory requirements, overall event log retention will range from one year through to seven. Many organizations find that a minimum of one year meets most mandated requirements but err on the side of retaining between three to four years – depending on what their legal counsel advises.

With public cloud, data retention spans many different options, services, and price points. Backups, blob storage, “hot” access, “cold” access, etc. – there are endless ways to store and access security events and logs. With cloud storage dropping in price year-on-year, it’s cheap and easy to just store everything forever – assuming there’s no rush or requirement to inspect the stored data. But hot data, more expensive than the cold option, gives defenders the quick access they need for real-time threat hunting. Keeping data hot for SIEM use is inevitably one of the more expensive data storage options. A balance needs to be struck between having instant access to SIEM for queries and active threat hunting, and long-term regulatory-driven storage of event and log data. Can an optimal storage balance be achieved?


Widely available public threat reports for the last couple of years provide a “mean-time” to breach discovery ranging from 190 to 220 days and a breach containment window of between 60 to 100 days. Therefore, keeping 220 days of security event logs “hot” and available in a cloud SIEM would statistically only help with identifying half of an organization’s breaches. Obviously, a higher retention period makes sense – especially for organizations with less mature or less established security operations capabilities.

However, a sizable majority of SIEM-discoverable threats and correlated events are detectable in a much shorter timeframe – and rapidly detecting these breaches naturally makes it considerably more difficult for an adversary to maintain long-time persistence. For example, automatically piecing together the kill chain for an email phishing attack that led to a malware installation, that phoned home to a malicious C&C, which had then brute-forced the administrative access to a high value server is almost trivial for cloud SIEM (assuming appropriate logging was enabled). Nowadays, such a scenario (or permutation of that scenario) likely accounts for near half of all enterprise network breaches.

My advice to organizations new to cloud SIEM is to begin with a rolling window of one year’s worth of event logs while measuring both the frequency of breaches and time to mitigate. All older event logs can be stored using cheaper cloud storage options and needn’t be immediately available for threat hunting.

Depending on the security operations teams’ capacity for mitigating the events raised by cloud SIEM, it may be financially beneficial to reduce the rolling window if the team is overwhelmed with unresolvable events. I’d be hesitant to reduce that rolling window. Instead, I would recommend CISOs with under-resourced teams find and engage a managed security services provider to fill that skills gap.

A question then arises as to the value of retaining multiple years of event logs. Is multi-year log retainment purely a compliance tick-box?

While day-to-day cloud SIEM operations may focus on a one-year rolling window, it can be beneficial to organize a twice-annual threat hunt against several years of event logs using the latest available threat intelligence and indicator of compromise (IoC) information as seeds for investigation. These periodic events have two objectives: reduce your average monthly cloud SIEM operating costs (by temporarily loading and unloading the historic data) and allow teams to change mode and “deep dive” into a broader set of data while looking for “low and slow” compromises. If an older breach is detected, incrementally older event logs could be included in the quest to uncover the origin point of an intruder’s penetration or full spectrum of records accessed.

Caution over infinite event log retention may be warranted, however. If the breached organization only has a couple years of logs, versus being able to trace breach inception to, say, four years earlier, their public disclosure to customers may sound worse to some ears (including regulators). For example, disclosing “we can confirm customers over the last two years are affected” is a weaker disclosure than “customers since July 4th 2015 are affected”. Finding the sweet-spot in log retention needs to be a board-level decision.

Having moved to cloud SIEM, CISOs also need to decide what logs should be included and what log settings should be used.

Ideally, all event logs should be passed to the cloud SIEM. That is because the AI and log analytics systems powering threat detection and automated response thrive on data. Additionally, inclusion of logs from the broadest spectrum of enterprise devices and applications will help reduce detection times and remove potential false positives, which increase overall confidence in the system’s recommendations.

Most applications and networked appliances allow for different levels of logging, including scaling from error messages to alerts and error messages through to errors, warnings, status messages, and debugging information. In general, the greater the detail in the event logs, the greater the value they bring to cloud SIEM. In this way, upgrading from “normal” to “verbose” log settings can offer several threat response advantages – particularly when it comes to handling misconfigurations and criticality determination.

The symbiotic development of cloud SIEM and cloud AI innovation continues at an astounding pace. While cloud SIEM may be new for most organizations, its ability to harness the innate capabilities of public cloud are transforming security operations. Not only are threats being uncovered quicker and responses managed more efficiently, but continual advancements in the core AI makes the technology more valuable while costs of operating SIEM and storing data in the cloud continue to drop. This makes it possible for companies to make pragmatic use of the intelligent cloud by operating on a one-year window of hot data while getting value out of older data, stored cold, on twice a year threat hunts.

-- Gunter Ollmann

First Published: SecurityWeek - July 22, 2019

Sunday, November 25, 2012

Persistent Threat Detection (on a Budget)


If there’s one simple – high impact – thing you could do to quickly check whether your network has been taken over by a criminal entity, or uncover whether some nefarious character is rummaging through your organizations most sensitive intellectual property out of business hours, what would it be? In a nutshell, I’d look to my DNS logs.

It’s staggering to me how few security teams have gotten wise to regularly interrogating the logs from their recursive DNS servers. In many ways DNS logging can be considered sprinkling flour on the floor to track the footsteps of the culprit who’s been raiding the family fridge. Each step leaves a visible impression of where and how the intruder navigated the kitchen, and their shoe size.

Whenever an electronic intruder employs their tools to navigate your network, tries to connect back to their command and control server, or attempts to automatically update the malicious binaries they've installed upon the system they have control over (or wish to control), those victim devices tend to repeatedly resolve the domain names that that attacker is operating from. Therefore, armed with a list of known bad domain names and/or IP addresses, it’s a trivial task to mine the DNS logs and identify any successful intrusions.

Depending upon how authoritative your “blacklist” of criminal domains is, and how picky you are about the IP destinations that the domain names are resolving to, you can rapidly spot those nefarious shoe impressions in the flour.

One word of caution though, this isn’t a comprehensive technique for detecting persistent threats operating within your network – but it is one of the simplest! It also has the highest impact – particularly if you’re operating on a shoestring budget.

An obvious limitation of DNS log mining is the depth and accuracy of the blacklist you’re matching DNS events to – so you’ll want to ensure that the list you’re using covers the types and classes of threats you’re most interested in detecting. While there are plenty of free blacklists out there, the vast majority of them deal with spam, phishing and drive-by hosts… so you’ll want to invest some time shopping around a little.

Here are a few tips to using DNS as a means of detecting persistent threats (advanced or otherwise):

  • Turn DNS logging on! Seriously, do it now… you can read the rest of this blog after you've turned it on.
  • Select a bunch of relevant blacklists that contain malicious domains associated with the threats (and criminal actors) you’re most interested in.
  • Create a list of IP address ranges for countries, companies or regions that computer systems within your organization shouldn’t be communicating with, and use this as a second-pass filter for spotting other unwanted or likely malicious traffic.
  • Scrape your DNS logs frequently – ideally at least once per week.
  • If you’re worried about a handful of specific threats (e.g. a criminal operator or state that is likely targeting your organization), scrape your DNS logs for relevant domain names hourly – and alert upon their discovery.
  • Even if you’re only scraping you’re DNS logs weekly, don’t throw them away after you’re done. Try to keep your DNS logs for multiple years at least. (Note: DNS logs compress to almost nothing – so they’re not going to take up much space).
  • Consider scraping all the older logs (going back up to 5 years) once a month or so. New domains will be added to the blacklists you’re using over time, and new intelligence can shed new insight in to past intrusions. It’ll also help to establish when the intruder first compromised your network when you do find one.
  • If your DNS server allows it, turn on logging of “failed” lookups – i.e. NX domain requests. While these events won’t help in your blacklist lookups, they will help identify malware families that make use of domain generation algorithms (DGA) as well as “broken” applications within your network that need some tuning in finding their legitimate destinations.
  • DNS log scraping can be conveniently done off-line through simple batch script processing. So the impact on the team responsible for securing the corporate infrastructure is minimal after a nominal development investment.

If you’re not happy with the quality of the blacklist you’ll be able to bring to bear in uncovering the persistent threats likely already operating within your environment, or if it would be helpful to do a “one-off” check of your DNS logs and to help build the internal business case for investing in a more permanent detection solution, let me know.

Wednesday, December 8, 2010

Threat Landscape in 2011

OK, so it's that time of the year again and all the security folks are out making predictions. And, as usual, I have a number of inbound calls for me to pump out the same. Not necessarily "the same" predictions though - since why would marketing and PR teams want to pimp "the same" predictions as everyone else... that'll never get mentioned in the press... ideally a few predictions about how the world will come to an end and preferably in a way that no one has though of before. You know the sort of prediction I mean - "By the end of 2011, cyber criminals will have full control of the electronic systems that control sewer pipes in the US and will be extorting cities for millions of dollars - or else they flood the city and cause massive deaths from typhoid and plague."

Cynicism in the run up to Christmas? Bah-humbug :-)

Anyway, despite all that, "predictions" can be pretty useful - but only if they're (mostly) correct and can be actionable. So, with that in mind, I've posted some "expectations" (rather than predictions) for 2011. I think it's important to understand the trends behind certain predictions. A prediction that comes from no where, with no context, and with no qualification is about as helpful as a TSA officer.

Here are the 2011 predictions (aka expectations) I posted on the Damballa blog:
  1. The cyber-crime ecosystem will continue to add new specialist niches that straddle the traditional black and white markets for both the tools they produce and information they harvest. The resulting gray-markets will broaden the laundering services they already offer for identities and reputation.
  2. Commercial developers of malware will continue to diversify their business models and there will be a steady increase in the number of authors that transition from “just building” the malware construction kits to running and operating their own commercial botnet services.
  3. The production of “proof-of-concept” malware, hitherto limited to boutique penetration testing companies, will become more mainstream as businesses that produce mechanical and industrial goods find a greater need to account for threats that target their physical products or production facilities.
  4. 4. Reputation will be an increasingly important factor in why an organization (or the resources of that organization) will be targeted for exploitation. As IP and DNS reputation systems mature and are more widely adopted, organized cyber-criminals will be more cognizant of the reputation of the systems they compromise and seek to leverage that reputation in their evasion strategies.
  5. The pace at which botnet operators update and reissue the malware agents on their victims’ computers will continue to increase. In an effort to avoid dynamic analysis and detection technologies deployed at the perimeter of enterprise networks or operating within the clouds of anti-virus service providers, criminal operators will find themselves rolling out new updates every few hours (which isn’t a problem for them).
  6. Malware authors will continue to tinker with new methods of botnet control that abuse commercial web services such as social networks sites, micro-blogging sites, free file hosting services and paste bins – but will find them increasingly ineffective as a reliable method of command and control as the pace in which takedown operations by security vendors increases.
  7. The requirement for malware to operate for longer periods of time in a stealthy manner upon the victim’s computer will become ever more important for cyber-criminals. As such, more flexible command and control discovery techniques – such as dynamic domain generation algorithms – will become more popular in an effort to thwart blacklisting technologies. As the criminals mature their information laundering processes, the advantage of long-term host compromises will be evident in their monetary gains.
  8. The rapidity in which compromised systems are bought, sold and traded amongst cyber-criminals will increase. As more criminals conduct their business within the federated ecosystem, there will be more opportunity for exchanging access to victim computers and greater degrees of specialization.
  9. Botnet operators who employ web-based command and control portals will enhance their security of both the portal application and the data stolen from their botnet victims. Encryption of the data uploaded to the data drop sites will increase and utilize asymmetric cryptography in order to evade security researchers who reverse engineer the malware samples.
  10. The requirement for “live” and dynamic control of victims will increase as botnet operators hone new ways of automatically controlling or scripting repeated fraud actions. Older botnets will continue their batch-oriented commands for noisy attacks, but the malware agents and their command and control systems will grow more flexible even if they aren’t used.

Sunday, July 5, 2009

Making Money with Your Own Stealthy Botnet - Part III

So, how can you use a stealthy botnet and milk your victims for all their worth with the least likelihood of being detected? I've already discussed the vectors of modifying advertising in real-time and pay-per-installs, but what happens if you get more personal?

Sure, we've seen lots of FUD about identity theft and the roll botnets play propagating that threat. The problem with a lot of these "legacy" attacks is that they get noticed pretty quick and, more importantly, banks and financial institutes have become much better at automatically detecting the money-transfer part of the fraud/theft. Bot-masters embarking down this fraud path have little imagination or grasp of the value of all the other information they could be potentially tapping on each victim host.

If I had a botnet of 50,000 victims and was contemplating a life of crime, an interesting and stealthy route to make money could lie in household profiling.

3. Household Profiling
Consider for a moment the value of an identity. For the last five years the financial/tradeable value of an "identity" has been on the decrease. For example, an "identity" (consisting of name, address, phone number, birth-date, credit card number, card expiry, CCV code and Social Security Number) can be picked up for as little as $0.20 in batches of a thousand, but can rise to as much as $100 if it also includes the victims online banking credentials.

The problem though is that as soon as the accounts are tapped, the probability of the victim knowing, getting new credit cards, changing online banking details AND having the transaction voided, is practically guaranteed - and there is a high likelihood that the victim will hunt out bot agents on their host - not to mention being hunted down by law enforcement.

So, instead of focusing on this "short gain" fraud, why not embrace the long term - building up a complete profile of the user/family. Most of this concept could be categorized as "spyware", but there could be some tweaks to make it more profitable to the botnet operator.

Lets look some of the information that I think could be extracted from a family PC infected with a botnet agent capable of keylogging, screen-grabbing, man-in-the-browser, file scanning and encrypted C&C (which is basically every bot agent out there today...):
  1. Household Financial. Does the family have money to spend, and how do they manage their money? Every time a family member logs in to their online banking portal or receives an email, you could grab financial information such as:
    * Houshold monthly income
    * Total cash savings
    * Monthly spending patterns
    * Long-term savings and retirement plans
    * Stock-holdings and investment profile
  2. Bill Payments. Who supplies the household and how much are they spending? Monitoring online portals and scanning emails (or even VoIP traffic) it would be possible to uncover marketable profile information such as:
    * How much are they spending on utility bills?
    * Which stores do they regularly visit, what do they actually buy, and how much do they spend?
    * Are they up on their payments or behind?
    * Are they and the family in good health? Are they planning/saving for a major operation?
  3. Web Profiling. That holy grail proposed throughout the 1990's of building up a full profile of the family my monitoring their network traffic? Well it's all possible - but this time not inhibited by bothersome laws. Saleable information such as the following could be extracted:
    * Which sites do they visit, and how long to they spend on them?
    * What are they searching for or likely to purchase shortly?
    * What do their children and grand-parents do? How old are they?
  4. Contact Extraction. By scanning through mailboxes (both locally stored and webmail) along with social networks, gaming and other portals, the bot agent could extract detailed contact information - which in turn can be used for profiling (or infecting) friends.
  5. Affiliations. The monitoring of web traffic and emails will likely also reveal less tangible affiliation information such as religion and social groups.
Now, imagine you can automatically extract, group and sort this information from 50,000 hosts (which for the sake of arguments could encompass maybe 40,000 family units and a total of 100,000 personal identities) - how would you make money from it?

Several methods spring to mind:
  • Gray-channel marketing portals. Much of this personal information can be "washed" through the gray-market and be absorbed through a second-tier of marketing channels. While each record subset of information probably doesn't have much value by itself - probably only $0.50-2.00 per record and maybe $1-5 per family - it does have the advantage of being sold to multiple institutions as well as being offered as a "subscription" service. With that in mind, you'd probably be looking at earning something like $200+ per year (less expenses).
  • Targeted Profiled Sales. I've been told many times that it costs somewhere between $50-$200 to attract a new customer and entice them to move to a new utility/service provider. It would be relatively easy to provide profiles of households based upon existing utilities (and what their monthly bills are - along with history of payments) and sell them to competitors. I wouldn't be surprised if you could make $10-20 per "package" - and could net something in the region of $20k per month - by selling that info to commission-based utility sales reps. Sure, that's probably illegal and wouldn't be condoned by the Utility companies themselves, but I suspect quota-based sales would be a reliable vector. With that in mind, perhaps chopping out the middle-man and getting a job as the Utility sales rep directly may be more financially viable.
  • Just-in-time-sales. With sufficient effort, you could probably automate the identification of impending sales events. For example, the lease on the family car has just ended and they're now browsing the web for a 4-door convertible - or perhaps the family are just about to begin planning their summer/winter vacations. Extracting this information, passing it to a local dealer and taking a slice of the eventual sale price would be simple enough. It's probably not high value, but it is low risk.
  • Bulk Contact Sales. If all else fails, there's an existing market for email addresses and other bulk contact details. This type of info is trivial extract and its source can be easily obfuscated. However, even with 50,000 bots (potentially yielding 1-2m contacts), you're probably only going to make a few thousand dollars per year.
All in all, I think you could maintain a healthy revenue stream from simple household profiling with a relatively low threshold of being detected (and subsequently being thrown in jail). Out of all the botnet revenue models discussed thus far this one would probably be most preferable... so far...

Friday, June 26, 2009

Making Money with Your Own Stealthy Botnet - Part I

Over the last month or so I've had quite a few conversations with friends and former colleagues concerning what are the "cool" things you could do with your very own private botnet. Most of these conversations stem from them wanting to learn more about what I'm now doing - having joined Damballa a little while ago - and some of the nasty things criminals are doing with their botnets... which often deteriorates in to a "if I had a big botnet I'd..." type of discussion.

So, several ideas have been thrown around and I figured it would make an interesting series of blogs.

If I had a botnet...
"If I had a botnet..." is an interesting way of thinking about how criminal use of botnet may evolve over the next few years. While the news is full of stories and stats about monster botnets being built up and the volume of spam they're capable of pumping out, those are actually the boring ones (from a threat perspective) - and probably the least efficient use of a botnet. If your intent is to make money from a botnet, then using it for spam is effectively chump-change.

So, "if I had a botnet... how would I make real money from it?" - that's the killer question, and the one I'm going to explore.

1. The Custom Advertiser
Lets assume that I have a medium-sized botnet of some 50,000 victim hosts - most of which are home PC's on local DSL networks. Since acquiring (or reacquiring) those victims is a raw cost to me, anything I do with my botnet needs to be subtle and go undetected for as long as possible.

The users of the bot-infected computer, like most of the Internet-browsing planet, are constantly surfing sites plastered with advertising. Since my bot-agent is running on their host and is capable of both hooking the TCP/IP stack (i.e. man-in-the-middle) and operating within the browser (i.e. man-in-the-browser), I can intercept, view and edit any Web content before it gets rendered within the browser.

Since advertising seems to be a profitable route, why not replace those ads with ads of my own choosing? It's simple to do - in fact it's damned-near trivial. It's not even a new idea - some major ISP's around the world have toyed with doing similar things in the past (if not actually doing it today).

Armed with this capability to replace advertising (such as anything from ad.doubleclick.net etc.) a handful of business opportunities suddenly appear:
  1. Strike up a deal with a particular organization and offer to plaster their ads on to every page 50,000 people view for an entire day.
  2. Modify the code surrounding the legitimate advertisement such that if the user click on it they'll be taken to a different site. This could even be keyword based - for example, any legitimate ads for drugs and health care products get redirected to Canada Online Pharmacy. Think in terms of Phorm for ad replacement.
  3. Replace the advertising with my own ads that are actually just redirects/proxies to ads being served from sites I already control. That way I'm serving legitimate ads, but any click-throughs are being associated with my Web site rather than the site the user was actually on.
  4. Screw around with a company I don't like. Since most managed online advertising campaigns are supposed to be targeted against a specific audience - and they pay through the nose for each click-through. I could plaster their advertising everywhere such that they exhaust their daily online budget really fast and miss their target audience.
I'm sure the list of opportunities could go on and on, but lets look at the feasibility of these replacement scams for making money.
  1. I think it would be a struggle to entice a legitimate/mainstream company to use my advertising services, so I'd be stuck selling to some company comfortable operating in the gray areas of the Internet. This means I'm not going to be able to attract top dollar for the advertising - so maybe I can only charge $2-5k per day. I'm also going to have to be careful of serving up too much of the same advertising to the same people and having them suspect something isn't quite right with their PC and asking questions that could reveal what I'm up to.
  2. I'd likely have to deal with the same kinds of gray companies as for (1), but I could probably make more money. I'd be expecting the same daily rate of return on the advertisement placements (e.g. $2-5k), but I could probably also get a cut of any subsequent sales (e.g. like the way pharma-scam franchises currently work).
  3. This could potentially yield me the most money. It'll be a little unpredictable, and I'd have to be careful not to be detected by the real advertising company (e.g. Google has some pretty sophisticated means for spotting click-fraud, and might catch this vector - but I could do some other magic such as modifying the victims REFERER fields to fake the source of their click). The advantage with this is that I could set it up all online and never actually have to speak with anyone... and I'd get cheques in the mail each month.
  4. I don't think I'd actually make any money out of this unless I approached a competitor to the business being targeted. I might be able to get a few hundred dollars a day, but I'd end up having to explain how the scam works to them - which would shorten the viable life of the scam.
What do you think? Are there some better money-making business opportunities focused around replacing advertising inside the Web browser?

Look out for the next installment of Making Money with Your Own Stealthy Botnet...

Saturday, May 23, 2009

If you can't protect it, you'd better be able to detect it!

The security trend over the last half-decade has been towards "protection" and we've seen technologies such as IDS morph in to IPS and network sniffing evolve in to DLP.

What I find amusing/worrying is that this laser focus on protection means that organizations have increasingly dropped the ball where it comes to threats that currently have no protection solution on the market. Basically, an attitude of "if I can't protect against it, then I don't want to know about it" has become prevalent within the security industry.

So, on that note, I found it refreshing to read the brief story over at Dark Reading How To Protect Your Organization From Malicious Insiders by Michael Davis. It's been a long standing mantra of mine that "If you can't protect it, you'd better be able to detect it!"

The 'Insider Threat' is one of the more insidious threats facing corporates today (especially in economic turmoil) and there really are so many ways for a knowledgeable employee to screw things up if they wanted to. I've had to do a mix of forensics and internal pentests within these areas in the past and it's always a potential playground of carnage.

But it's a little distressing to me that with the global sales push on DLP solutions many organizations have essentially thrown away their common sense. What I've observed is that enterprises that were initially deeply concerned about the potential of insider threat jumped heavily on to the DLP bandwagon and see this class of security technology as a way of over coming the threat. Then once they've deployed the DLP solution it's as if a mental box is ticked - "insider threat = solved" - and they move on to their next priority.

The problem is that DLP sucks as a protection system against the real insider threat and its rollout within an enterprise can be a substantial distraction to security & audit teams responsible for tracking the threat. Add to that the fact the executive support for further insider threat protection strategies quickly wanes after DLP has been rolled out -- "DLP = job done".

DLP will help identify (and block) many clear-text data leakage routes from an enterprise, however it'll do nothing against an insider that backdoors a server or Easter-eggs a DB to self destruct in a couple of weeks time - yet the mindset is that an investment has been made in DLP, and that since these kinds of insider threats can't be "protected" against, it's a problem too tough to solve (even though it may have been "solved" previously to the DLP solution - but that budget has now been used up - and DLP is supposed to reduce costs).

What ever happened to "detection"? As far as the insider threat goes, if you can't protect against it, you'd damn-well better ensure you can detect it. Failing that, I hope you're budgeting enough for post-attack disaster recovery and forensics.

Think of it this way. Say you're running a public library. You can bag check everyone that leaves the library to make sure they aren't stealing your books - and that's a wise precaution. But that doesn't mean you should skimp on the smoke detectors. The threat is "book loss" but there are clear differences between protection and detection strategies.

Saturday, April 18, 2009

The Fine Art of Attack Prediction

Internet security is gradually evolving from an art in to a science - particularly the evaluation of vulnerabilities in terms of threat impact and business risk (to which I think that CVSS has played a significant role in galvanizing the major software vendors). That said, one security realm still firmly entrenched as an art is "threat prediction".

The way I see it, "Threat Modeling" is quite a bit different from "Threat Prediction". While the former focuses on using existing threat information to model trends and evaluate risk profiles (often incorporating measurement systems such as CVSS), the later tends to assume longer timescales and deals with factors or industry trends that can not be reasonably precomputed and modeled.

Threat prediction typically requires the crystal ball to be rolled out and, depending upon the diviner, can be a little hit or miss at the best of times. However, I've found that threat predictions tend to become more accurate if you assume a few things first:
  1. If the bad-guys can make money from exploiting it, then you bet that they'll try.
  2. The more sophisticated the technology, the more vulnerable it is to primitive attack.
  3. The lowest hanging fruit are the first to fall.
There's also a fine line to be walked between keeping it real and flooding the airwaves with FUD (which the industry is only too keen to keep on perpetuating), and I often find myself wishing some security commentators would bear those three assumptions above before launching a press release.

Common Sense Threat Prediction
Threats are evolving at an increasing pace, but in most areas it's not too hard to predict a few years in to the future. While many "new" threats appear original at first glance, if you study your Internet security history you'll soon be able to draw parallels with past and present threats. In fact, the more you understand the mechanisms that shaped past threats, the better you'll be able to predict how new ones will evolve.

For example, look at how protection against password guessing as evolved...
  • [Whitehat] Force the user to supply a password in order to login - thereby stopping the blackhat from logging in with just the UserID.
  • [Blackhat] Passwords can be guessed, automatically cycle through popular passwords to find the right one for the UserID and gain entry to the system.
  • [Whitehat] Implement an account lockout procedure consisting of a maximum failed guess threshold (e.g. three failed password attempts and the account becomes inactive).
  • [Blackhat] Abuse the threshold procedure to lockout lots of users accounts and construct a denial of service attack - seeking to make money via extortion.
  • [Whitehat] Setup a proceedure to automatically 'unlock' locked accounts after a few minutes or hours - thereby negating the DoS threat and inconvenience to the end user.
  • [Blackhat] Implement horizontal guessing of passwords. Armed with a long list of known UserID's, try the same password against each UserID before trying a different password - thereby making use of automated account unlocking without adversely hindering the guessing process.
  • [Whitehat] Implement CAPTCHA's to stop the blackhat from using automated tools to pass the Turing test and guessing the USERID password.
  • [Blackhat] Socially engineer or recruit other Internet users to answer the CAPTCHA's and include the results in to the automated password guessing tool. [more discussion on these techniques can be found here and here].
A thing to bear in mind with the example above is that the overall "password battle" between blackhats and whitehats evolved throughout a decade - with the most rapid change occuring within the first couple of years (note that CAPTCHA's have only been popular as an anti-automation technique for 2-4 years, and it's only in the last year that we've seen the criminal blackhats recruit and pay Internet employees to break CAPTCHA's).

It's probably also worth pointing out that particular Internet threats and attack techniques never actually disappear, and it's not uncommon for the same threat to reappear several years later in a slightly different guise because of some new implementation of an old (and vulnerable) technology. I wrote a whitepaper on the topic a couple of years ago - Old Threats Never Die.

With all that in mind, It's also worth pointing out that threat prediction is getting easier. While the technologies are getting more and more sophisticated (and integrated), if you keep the thought "how would I make money from exploiting it?" at the forefront of your mind, you'll probably be reasonably good at predicting what the bad-guys will do

Friday, April 17, 2009

Password Revisitied

I've been hearing a lot about HTTP-based brute-forcing of Web email accounts lately - in particular the use of automated tools - and there are few interesting aspects here that I think commentators are missing.

Firstly, the easiest (and fastest) way to brute-force a webmail account is to not use HTTP. Ignoring the major free-mail services (e.g. gmail, yahoo mail, hotmail, etc.), many people rely upon ISP-provided webmail services for their every-day mail access. What you will find is that these ISP-provided webmail services come bundled with the ability to host your own personal Web site - as part of the service. And, you've probably already guessed it, you use your email address and it's password to access via FTP or WebDAV. Therefore, brute-forcing via FTP/WebDAV is possible - in fact it's not only possible, it's also much faster and more efficient (in many cases, FTP won't lock out the account after too many password guess failures).

Another aspect for consideration is the fact that in most cases today you don't actually need to brute-force the password, instead you can focus on a much smaller subset of probabilities via the "forgotten your password" interfaces. While an account password may be 8 characters long and contain numbers, uppercase characters and extended characters, the password recovery may be as simple as guessing a favorite color or pet's name. Even security aware geeks fall for this - and I wonder how many passwords can be recovered by answering the "your favorite movie?" recovery question with "Star Wars"? - too many I bet.

So, what happens after all that? What if you want to "recover" a webmail account (yours or someone elses)? Hire an expert of course...

Password Recovery Services

If you have regular access to the Internet, the odds are pretty high that you’re also making use of the email services from one of the popular free Webmail providers. In fact, most people I know have multiple personal accounts on several of the most common platforms (e.g. gmail.com, hotmail.com, yahoo.com, etc.).

Unfortunately, remembering the passwords for these accounts can be troublesome – particularly if you don’t use an account regularly or (more commonly nowadays) if you’ve been using some application’s “remember my account/password” functionality.

What happens when you’ve forgotten the password (or never knew it to begin with)? If contacting the email provider and answering the “forgotten password” questions hasn’t worked, there are several ways to gain access to the password.

If it’s been “remembered” by the Web browser or “saved” by the email client (e.g. Microsoft Outlook) there are several installable tools freely available to help recover the password. Most of the tools are very small and effectively do a little registry or memory hooking to “see behind” the *** asterisks, and present the password back to you. Meanwhile, others perform a little crypto magic and decode the stored password from somewhere else on the host.

I’ve used these tools many times in the past – both personally (e.g. recovering passwords for DSL modem dialup's when trying to migrate to a replacement PC) and professionally (having gained control of a remote host during penetration testing and needed to recover other user-level passwords for deeper penetration) – but you have to be pretty careful. Today, more often than not, you’ll find many of these “free” tools come bundled with spyware and keyloggers built in.

Someone Else’s Account

OK, but what if you’re in need of hacking in to someone else’s free Internet email account? What about if you don’t want the owner of the account to know you’re interested in getting their password and gaining access to their account? Well, in this age of hacking-as-a-service, you’d be right in guessing that it’s pretty easy to engage on-demand “password recovery” hacking services.

But why would someone want to use these hacking services? Funnily enough, the hacking-as-a-service web sites themselves will give you plenty of excuses why you’d want to engage their services in breaking in to personal email accounts…

  • Online Infidelity (Cheating Spouses)
  • Identifying Cyber Stalkers
  • Internet Security Audit
  • Background Search
  • Online Fraud Investigations
  • Employee Data Theft
  • Cyber harassment
  • Internet Surveillance
  • Password Recovery
  • Identity Theft
  • EBay (Online Auction) Fraud
  • Child Predators and Pornography

I think most people have a fair amount of personal information in their free webmail accounts. With the webmail providers continuously increasing their free storage capabilities (and making it very difficult to actually “delete” any emails), most users probably have several years of stored emails – emails likely containing order confirmation details, photo’s of loved ones, banking and personal account details, address details, etc. – all of which has a value to an identity thief and can be sold through any number of channels.

But it can go further than that. It must be hard for some employers not to engage these services themselves. How many times have you seen farewell emails go around the corporate email system with the leaving employee saying that they can be contacted at such-and-such webmail address? What if that farewell was from a manager or executive who was off to work for a competitor, or launch a start-up organization, and the likelihood of other employees following them was high? If the (former) employer could inspect that webmail account every so often they could probably figure out who was about to jump ship and maybe take preventative action.

Is it Legal?

Depending upon which country you happen to be living in, maybe – but more than likely “probably not”. You’d have to check with your own legal team (I’m not a legal expert), but the services being provided sound pretty-much like criminal hacking to me. At the very least they’re going to breach the terms and conditions of the webmail provider.

You’ll also find that many of the hacking-as-a-service providers will have their own “terms and conditions” and disclaimers for self preservation. By way of example, here’s a snippet from one such site:

"Use of Sites Services
We don't have any partnership or alliance with Yahoo, Hotmail, AOL, Rediffmail. If you lost your password from these sites you have to first contact the corresponding authority. We are recovering passwords using some of our softwares, brute forcing and dictionary attacks. We will not responsible for any damage occur in the email id you supplied.
We will not crack passwords of another persons. If you are contacting us to crack another users password, that will be 100% with your own risk. Password hacking of another persons account is illegal. So all legal and government actions relating to the case is against you only.”

Service Levels and Reassurances

Competition in the password hacking business is fierce, and you’ll find no shortage of suppliers. At the moment the market is fragmented, with many smaller hacking-as-a-service providers specializing in a handful of local country-specific webmail providers. For example, a quick search will reveal dozens of specialist Russian and Czech sites focusing on popular .ru webmail services – such as Mail.ru (list.ru, bk.ru, inbox.ru) and Pochta.ru ( fromru.com, front.ru, hotbox.ru, hotmail.ru, land.ru, mail15.com, mail333.com, newmail.ru, nightmail.ru, nm.ru, pisem.net, pochtamt.ru, pop3.ru, rbcmail.ru, smtp.ru).

I’ve also come across a lot of portals that “specialize” in hacking any email account as long as it doesn’t belong to a .gov or .edu domain (which is interesting in its own right). But I’ve also stumbled across a few that cater exclusively to .gov and .edu mail services - so none are "safe".

That said, you’ll also find the competition has driven some of the larger international service providers to present polished commercial facades that promote the quality and professionalization of their services, with many offering money-back guarantees should they fail to retrieve the password of the account you’re interested in.

While most search engines will quickly uncover stacks of service providers, you’ll also come across lots of hacker forum postings promoting their services – each offering their own unique reassurances of their service. For example, with the help of an online translator:

To start probably need to reassure potential customers:
A) We are not advances.
[i.e. they do not need advanced payment]
B) We are carrying out transactions through the guarantors of the forum in which you find this announcement.
C) We provide daily report on the work done.
D) We are not physically stronger orders.
E) We maintain our established time frame.
F) We are polite and attentive, what you want.
About rules, see no need to write, because each order individually discussed with the client.

How much does it cost?

Whether you’re dealing with the hacking-as-a-service providers Web portal, or directly with the password recovery purveyor, “100” appears to be a popular figure for a single email account. That “100” may be in US dollars, Web-money WMZ, or some other form of currency, and can be paid using any of the usual online payment systems.

In the majority of cases, the providers do not require advanced payment, and the process of engaging a service provider is pretty easy. For example, the Crackpal service (pictured above) lists five easy steps to the password recovery of your targeted webmail account:

  1. Email the target id to crackpal@crackpal.com or click to order password
  2. After Successful Crack we will send you the proofs
  3. Verify proofs and if you are well satisfied then you can reply back
  4. We will send the Detailed Payment information after getting reply
  5. After payment confirmation we will send the original password

Interestingly enough, while several payment options are available, it looks like they will only accept direct bank deposits from Malaysia, Singapore, the Philippines and India – which likely hints at their operational location.

Password recovery prices tend to increase once you move from popular webmail accounts to other email accounts. For example, hirehackers.net charges a lofty $200 per retrieval session for POP3 email account passwords…

…and you’ll also uncover plenty of scam artists operating in this field.

Behind the Scenes

There’s actually not a lot going on behind the scenes in the attacks. As you’d expect, in almost all cases the hacking of the targeted email accounts are done through standard automated guessing techniques (e.g. dictionary attacks and brute-forcing) using commonly available tools and scripts.

What you will find though is that some degree of specialization has been necessary by the hacking-as-a-service providers due to CAPTCHA use. The smaller providers appear to be making use of tuned auto-CAPTCHA-breaking scripts, while the other “general” providers are more than likely employing human CAPTCHA breakers (you can find out more details of these CAPCHA breaking trends in an earlier blog entry on Mechanical Turks).

This approach is not necessarily guaranteed to retrieve all passwords – especially if it is a long and complex password (i.e. a “good” password). And it’s often for this reason that the providers won’t charge in advance (most common with fixed price recovery schemes). I suspect that each provider has decided upon a “maximum effort” level (or duration) that they’re will to expend in earning their 100 whatever-monetary-units.

But, as you’d expect, there are also a handful of hacking-as-a-service providers that charge based upon a sliding-scale of effort involved. You’ll often see such portal sites including details of how many IP addresses or botnet agents they will be using in their password recovery efforts – and you can sometimes select how much effort (as in time and agents) you’re willing to pay for.

Protection

How do you protect against someone employing these services to hack in to your webmail account? Unfortunately, there is very little you can do beyond the obvious.

  1. Use a webmail provider that is known to have good anti-bruteforce protection (e.g. check out the details of how they handle account lockout processes and alerting).
  2. Use a “good” password. There are plenty of guides on selecting appropriate passwords, but in general make it long and unpredictable. But beware – some webmail services don’t actually allow users to select passwords that would meet the “good” criteria (such as artificially restricting password length to 10 characters). If you’re currently relying on one such webmail provider, I’d recommend changing to another one that does – there’s no shortage of free webmail providers out there.
  3. Don’t keep your entire email history online if at all possible. Delete regularly – especially personal information!

If you’re like me and don’t really use free webmail services that much, but find you need something like them for handling all those bothersome web sites that require an email address so they can send you a confirmation email with a URL to download or access they thing you were actually interested in, then I’d recommend disposable webmail services such as dodgeit.com (or dodgit.com).

These types of email service allow you to specify any email address you want within that domain (e.g. brochuresfromhell@dodgeit.com), and then access that “account” anytime without requiring a password. Obviously, they’re no good if you’re expecting any personal information to be received – and most don’t allow you to send emails either.

Friday, April 3, 2009

"Unnamed", unloved, "invisible" and unprotected...

So, whats an "unnamed" threat, and how well are you protected against it?

Given the industry reliance upon reactive signature systems, an "unnamed" threat is something you genuinely need to be scared of.

Then there's those "invisible" threats too. How about them?

Dealing with those pesky "unnamed" threats are covered within the Damballa blog I wrote this afternoon.

Monday, March 2, 2009

Searching for a Phishing Spot

Phishing is one of those threats that have been around since the dark ages of the Internet and has never really gone away. It's constantly on everyone's lips, and most people know someone who's fallen victim to the scam somewhere along the line. I think that, as a threat, Phishing is on the decline (from the perspective of uncontrollable escalation like some other threats) but will likely never go away as long as we continue with Internet 1.0.

From the criminal phishing perspective, a critical component to the scam is the hosting of the counterfeit Web site. While I'd say that most security professionals have a good feel for the percentage and frequency of Web sites that are compromised and end up hosting the phishing content, I'd never really encountered any public analysis of the compromise vector and what the percentages were beyond a finger in the air.

Today I came across a very interesting paper Evil Searching: Compromise and Recompromise of Internet Hosts for Phishing, by security researchers Tyler Moore and Richard Clayton, which actually quantifies whats been going on.

Of particular interest to me was their analysis of the use of search engines by the criminals to find the vulnerable Web servers, and how repeated compromise of these vulnerable Web servers (for the purpose of Phishing) can be analyzed.

It's a very interesting paper, and I'd recommend those of you looking to protect your sites from Phishers take the time out to read through it.

Personally, I think the best defense against the Search vector is what we've been saying for decades (and has appeared in every single pentest report I can ever remember writing) - watch out for information leakage, and change/obfuscate all service banners! Yes, I know that that's not going to work in all cases, but it's a damn good place to start!

You should probably also check out the paper I wrote several years back related to Passive Information Gathering.

Monday, January 26, 2009

Attack Coordination Using Social Networking Sites

With little doubt, the fastest growing and most influential Web 2.0 technology has been that of the Social Networking site. Sure, the concepts have been around for quite some time - harking back to the first dial-up BBS' of the 1980's - but the growth of sites like Facebook and MySpace is unheralded. The amount of time people now spend "Social Networking" has even overtaken the quest for porn (see the BBC's "Porn putting on its Sunday best").

Now, if you combine the facilities of social networking sites to coordinate large groups of people incensed by another group with tools that enable members to "donate some of their computers bandwidth", you can quickly develop massive "opt-in" DDoS systems.

The first component - the groups of incensed and motivated members - are already out there. Just look at the Facebook groups that sprung up backing either Israel or Hamas in the most recent conflict, or older groups such as the animal cruelty activists like "Stop Huntingdon Life Sciences Animal Cruelty".

The future of Social Network initiated/coordinated DDoS attacks is just around the corner (if it hasn't already happened in less-than-newsworthy cases already). Welcome to the birth of SDoS - Social network Denial of Service.

I posted a longer blog on the topic, along with the tools available to activist and social conscience groups - and some future threat motivations up on the IBM Frequency-X Web site.

Take a gander at "Social Network Denial of Service (SDoS)?" for more thoughts and analysis.