https://blog.knowbe4.com/cyber-criminals-use-domino-effect-chain-attacks-to-leverage-one-compromised-bank-to-infect-the-next?hs_amp=true&__twitter_impression=true
Showing posts with label Cybercrime. Show all posts
Showing posts with label Cybercrime. Show all posts
Monday, March 11, 2019
Wednesday, February 13, 2019
Cyber-Security Analogy, Cont.
Let's get back to the wizard in my analogy, and the challenges of mass production.
One of my classes covered material for the Certified Ethical Hacker (CEH) exam, which deals with penetration testing. For those who don't know, you get hired to try and hack into a business so that business can make themselves more secure. Being a penetration tester uses some of the exact same tools a hacker does, except it's done at the request of the target and comes with more report writing. Or so I hear.
We had some lab assignments to go with the academic material, and had a virtual lab with virtual machines that we tried hacking into. Metasploit is probably one of the best known tools for this, and it can be used by good and bad guys alike. We also dealt with stuff like Poison Ivy, and created some phishing e-mails and the like.
I brought up Metasploit because the software contains exploits for all sorts of vulnerabilities. You just have to figure out what type of system you're targeting select the exploit you want to use, and run it. Then bam! You're in, and can do all sorts of nasty things.
You don't have to know how to create the exploit yourself, you just run the program and let it do the work for you. (You probably want to learn a bit about what a defender would see when you do that, and how to minimize the risk, but that's a lot easier to teach then learning how to code an exploit yourself.)
Thus my original analogy, and comments on how mass producing guns changed things. You've got a 'wizard' that can create a program to exploit a vulnerability, a 'spell' if you will. They can either keep it to themselves or share it with everyone else, giving all potential attackers a 'spell' that will find hidden doors in the wall.
The spells themselves are not necessarily the problem, in that defenders use the exact same spells to test their defenses and brick up doors. The real problem is the wizard, and the system for distributing spells.
And that's about where I'll call this whole series of posts to a halt. I'm not entirely sure what the system is for distributing exploits, other than that you can see the results in Metasploit and other such programs. I've heard that organized crime has an entire system for this, so maybe understanding the Dark Net would help me come up with ideas on how to target that? Or should I just assume dissemination is a given, and ignore that entirely?
And as for the wizard... Hmmm. Targeting them gets into some of the same problems with attribution that I mentioned earlier. Though I suppose you could also try coming up with a program to turn them away from the dark side? I'm not sure how many would be interested in that, though. I don't really have a good profile for what the typical wizard is like, what motivates them to do what they do, etc.
Meh. Whatever. These are just some initial thoughts on the topic, based on what I've learned so far.
One of my classes covered material for the Certified Ethical Hacker (CEH) exam, which deals with penetration testing. For those who don't know, you get hired to try and hack into a business so that business can make themselves more secure. Being a penetration tester uses some of the exact same tools a hacker does, except it's done at the request of the target and comes with more report writing. Or so I hear.
We had some lab assignments to go with the academic material, and had a virtual lab with virtual machines that we tried hacking into. Metasploit is probably one of the best known tools for this, and it can be used by good and bad guys alike. We also dealt with stuff like Poison Ivy, and created some phishing e-mails and the like.
I brought up Metasploit because the software contains exploits for all sorts of vulnerabilities. You just have to figure out what type of system you're targeting select the exploit you want to use, and run it. Then bam! You're in, and can do all sorts of nasty things.
You don't have to know how to create the exploit yourself, you just run the program and let it do the work for you. (You probably want to learn a bit about what a defender would see when you do that, and how to minimize the risk, but that's a lot easier to teach then learning how to code an exploit yourself.)
Thus my original analogy, and comments on how mass producing guns changed things. You've got a 'wizard' that can create a program to exploit a vulnerability, a 'spell' if you will. They can either keep it to themselves or share it with everyone else, giving all potential attackers a 'spell' that will find hidden doors in the wall.
The spells themselves are not necessarily the problem, in that defenders use the exact same spells to test their defenses and brick up doors. The real problem is the wizard, and the system for distributing spells.
And that's about where I'll call this whole series of posts to a halt. I'm not entirely sure what the system is for distributing exploits, other than that you can see the results in Metasploit and other such programs. I've heard that organized crime has an entire system for this, so maybe understanding the Dark Net would help me come up with ideas on how to target that? Or should I just assume dissemination is a given, and ignore that entirely?
And as for the wizard... Hmmm. Targeting them gets into some of the same problems with attribution that I mentioned earlier. Though I suppose you could also try coming up with a program to turn them away from the dark side? I'm not sure how many would be interested in that, though. I don't really have a good profile for what the typical wizard is like, what motivates them to do what they do, etc.
Meh. Whatever. These are just some initial thoughts on the topic, based on what I've learned so far.
Cyber-Security Analogy, Cont.
If you want to change the threat environment, you can also consider ways of reducing the number of attackers. Right now it's really, really, really difficult to hold attackers accountable. It's not just that they can fake their id's, it's also that they may come from or pass through other nations on their way to attack your castle. And we don't necessarily have any sort of agreements with those nations that would allow us to enforce our laws on them.
While I do think we need better international cooperation to hold attackers accountable, there's another issue at work here. How do you identify someone as an attacker in the first place? How do you trace back their identifier to the original person?
Tackling that problem is something I have reservations about, in that it's great to focus on that if you want to catch bad guys, but it also is something that can be used to oppress or suppress good people. Consider what I'd said about wanting to explore the Dark Net, and wanting VPN and whatnot before doing so. My reasoning for all of that?
I want to understand the world on a holistic level... and the darker side is part of that. Can we truly understand economics, for example, without understanding the role shadow economics plays in it? I don't know... I don't think there's any equivalent to GDP for the underground economy. There might be a few studies that explore how money gets laundered and how much of it comes back into the legitimate economy, I dunno. Maybe the underground economy isn't large enough to really impact anything, maybe our economists can make sound decisions without ever considering that side of things... But how would we know if we never even consider the possibility?
It's a bit like how some biologists really love looking into how an ecology handles decay. Would there be horrible ecological consequences if we got rid of nasty critters like mosquitoes and flies? You don't know unless you look into it. (I think I read that we could get rid of mosquitoes with little to no consequences, which would be awesome if true and doable.)
The Dark Net seems like a good place to get a better understanding of the shadows in our world, but I have some serious trepidations about going there. It's like turning over a rock, or spelunking in a cave. I'm not sure what I'll find, I'm not sure what I would do with what I'd find, that sort of thing. But... I do know that before I go spelunking in such dark caverns I'd want to do my darndest to make sure nobody there could ever trace me back to my physical address. So I want a VPN service, might try to use Tor, that sort of thing. (I haven't tried too much to maintain privacy online so far, tbh. I know a lot of computer people who flat out refuse to use Facebook any more, but I still have a lot of friends and family there and haven't completely opted out yet.)
Bringing this back to cybersecurity - any attempt to make it easier to identify people online will also make it easier for abuse to happen. Like authoritarian governments tracking down dissidents, or online mobs doxxing people they don't like.
I have reservations about making it easier to identify people online, but I also know that attribution is especially important if we're dealing with a nation/state threat level and want to deter attacks.
How could Ukraine hold Russia accountable for the 2017 Petya attacks, and prevent any future such attacks from occurring, when Russia denies involvement and calls the accusations "unfounded blanket accusations".
Cyber-Security Analogy, Cont.
My previous analogy was... well, not an exact description of things. For example, a denial of service attack would be more like someone creating a bunch of clones to try to get through the gate. So many are trying to get through that it creates a really long line, and all other (legitimate) traffic gets fed up with the wait and leaves.
And you can also imagine that everyone trying to get through the gate has a unique number, identifying their origin. You can fake the number, of course, but you have to have a number of some sort. The clones might all share the same number (one attacker using one computer to generate a flood of attacks) or they might all have unique numbers (one attacker using a botnet under their control to generate attacks). The gate guards can potentially use that number to identify attackers and clear them out.
But...
That's not really why I created the analogy in the first place. I did it to create a different frame of reference, so I could look at the problem in a different way.
For example, much of cyber-security is focused on handling the daily attacks... figuring out ways of improving security at the gate, or blocking up the not-so-secret doors in the walls, or training people so that they don't throw ropes over the wall to let an attacker in.
Each of those fields has their cat-and-mouse, fast-paced development. Someone finds a new 'secret' door in the wall. If it's an enemy, they may keep it to themselves (a 'zero-day' attack that nobody knows about and can't defend against) or try to share it with everyone. If it's a defender, they may try blocking it up with bricks.
If/when both sides grow aware of it, there's a race between the defender to block it up and the attacker... where an enemy wizard creates a new spell to find the door, and spreads that information to all the people interested in getting into the castle. Does the door get blocked before an attacker gets through? Who knows?
All of that is necessary just to stay on top of things, but it doesn't really change the nature of the game.
Or perhaps it does, in the long run. Maybe. If the defenders can find and secure all the doors faster than new ones are found and exploited.
Maybe, someday, getting into the castle will become so difficult that most of the casual attacks drop off.
It'll probably be a long time before that happens, though.
So, what would change the nature of the game?
From my (very superficial, noobie) awareness, there are a couple of different ideas on how to do handle this.
For example, some people want to just rebuild the castle entirely, making sure that this time there are no secret doors or hidden passageways. (I think this gets into Trusted Computing, as well as the push for more secure software, holding software providers liable for vulnerabilities, and probably some other stuff I don't really know much about).
There are quite a few challenges to this goal, though. Imagine trying to rebuild a castle while you're still living in it and working out of it. Assuming you can make something entirely secure in the first place (there are arguments about that, and I don't have enough experience to have my own opinion on it. I mean, systems are complex and it's possible that we can't secure them entirely... but finding and fixing a security flaw like the infamous buffer overflow doesn't necessarily mean that doing so creates another vulnerability elsewhere, so in theory you should be able to secure it all? Maybe? Let me get back to this when I have a better idea of what I'm talking about.)
For anyone unaware - quite a bit of computer technology is concerned with "backwards compatibility". That way all your old programs and things will still work on the new system. It also, unfortunately, means that technology has all these 'kludges', or remnants of things that were necessary back when computers were built a certain way, but aren't now. Or rather, they're only needed now for backwards compatibility. And early computing was more trusting than we are now, so some security issues are intrinsic to decisions made way back when. If you could redesign everything from scratch, incorporating what we now know, things might possibly be different. But that would require a massive investment in time, energy, and money. There are, apparently, still numerous computers using really ancient software because businesses rely on that software and haven't been able to find an alternative on anything more recent. (Many tech people seem to have stories of someone finding an old system that nobody knows what it's used for any more, powering it off because something that old can't possibly be important any more, and discovering that doing so made it impossible for the business to function any more.)
Anyways. Rebuilding from scratch seems massively complicated, though there's some potential to the idea. Especially if you go with a gradual rollout, so businesses can adjust as their existing systems wear out and they have to buy new ones. (Sort of like the transition from IPV4 to IPV6, though you still have a lot of systems that requires the ability to use both.)
There's also the idea that we could secure the castle if we just held software vendors accountable for their software. That is, the hidden doors in your wall are not necessarily just from what you built. Or Microsoft, or Linux, or Apple. The operating system might have vulnerabilities, but any software you add to your computer can also come with vulnerabilities. So even if your operating system is secure, even if all known doorways are bricked up, if you downloaded and installed something (like an internet browser, or a game, or an application to manage your finances, or anything) that software might also create a hidden door in your castle walls.
And software companies, apparently, are well known for releasing products as quickly as they can... and fine-tuning them after they've gone public. Think of every new Windows operating system, or the time it took for Pokemon Go to smooth out all the bugs. The public acts as the final phase of testing for much of what gets released.
And, well... software is complicated. You can test, and test, and test, and probably won't find everything until you're doing it for real. Like when we changed our warehouse management system at my old company... I tested the heck out of it, but some things didn't become apparent until we were dealing with the number of users and orders we did on a daily basis. It's hard for a test environment to duplicate everything, and some problems are probably inevitable.
But that doesn't seem to be the real problem with this solution. After all, it shouldn't be too hard to have a reasonable standard of what is 'inevitable parts of producing a new product' and what is 'sheer laziness and the desire to make money quick'.
The real problem is that, in our current environment, nobody wants to add regulation that will unduly burden software vendors. Or maybe we don't need regulation, maybe we just need a really big lawsuit holding someone (Adobe, or Microsoft, or Google, or Apple, etc) accountable for the losses a business had when an attacker exploited a vulnerability in their product. Assuming you can, since I think we all tend to pro forma sign one of those Terms of Service that they'll probably use to deny liability for any such thing. Still, if software vendors have to pay a really large fee for any mistakes in their code, they'll probably start spending more money on development and testing for security in their product before releasing something new.
And if the case is big enough, and the vendor penalized enough, everyone else in the industry will take notice and start doing the same.
It may not stop attacks entirely, but it would at least make sure that there were fewer hidden doors to find. Of course, it would probably also slow down the software development process.
So those are just a few possible solutions. There's another way of looking at this, though.
I came up with the analogy I did because I wanted to think about what it meant, this mass distribution of the ability to hack into a target. The 'wizards' creating 'spells' that anyone could use.
Hmmm, before I focus on that I want to talk about something else.
Actually, given how long this is getting Imma gonna stop right here and start a new post.
And you can also imagine that everyone trying to get through the gate has a unique number, identifying their origin. You can fake the number, of course, but you have to have a number of some sort. The clones might all share the same number (one attacker using one computer to generate a flood of attacks) or they might all have unique numbers (one attacker using a botnet under their control to generate attacks). The gate guards can potentially use that number to identify attackers and clear them out.
But...
That's not really why I created the analogy in the first place. I did it to create a different frame of reference, so I could look at the problem in a different way.
For example, much of cyber-security is focused on handling the daily attacks... figuring out ways of improving security at the gate, or blocking up the not-so-secret doors in the walls, or training people so that they don't throw ropes over the wall to let an attacker in.
Each of those fields has their cat-and-mouse, fast-paced development. Someone finds a new 'secret' door in the wall. If it's an enemy, they may keep it to themselves (a 'zero-day' attack that nobody knows about and can't defend against) or try to share it with everyone. If it's a defender, they may try blocking it up with bricks.
If/when both sides grow aware of it, there's a race between the defender to block it up and the attacker... where an enemy wizard creates a new spell to find the door, and spreads that information to all the people interested in getting into the castle. Does the door get blocked before an attacker gets through? Who knows?
All of that is necessary just to stay on top of things, but it doesn't really change the nature of the game.
Or perhaps it does, in the long run. Maybe. If the defenders can find and secure all the doors faster than new ones are found and exploited.
Maybe, someday, getting into the castle will become so difficult that most of the casual attacks drop off.
It'll probably be a long time before that happens, though.
So, what would change the nature of the game?
From my (very superficial, noobie) awareness, there are a couple of different ideas on how to do handle this.
For example, some people want to just rebuild the castle entirely, making sure that this time there are no secret doors or hidden passageways. (I think this gets into Trusted Computing, as well as the push for more secure software, holding software providers liable for vulnerabilities, and probably some other stuff I don't really know much about).
There are quite a few challenges to this goal, though. Imagine trying to rebuild a castle while you're still living in it and working out of it. Assuming you can make something entirely secure in the first place (there are arguments about that, and I don't have enough experience to have my own opinion on it. I mean, systems are complex and it's possible that we can't secure them entirely... but finding and fixing a security flaw like the infamous buffer overflow doesn't necessarily mean that doing so creates another vulnerability elsewhere, so in theory you should be able to secure it all? Maybe? Let me get back to this when I have a better idea of what I'm talking about.)
For anyone unaware - quite a bit of computer technology is concerned with "backwards compatibility". That way all your old programs and things will still work on the new system. It also, unfortunately, means that technology has all these 'kludges', or remnants of things that were necessary back when computers were built a certain way, but aren't now. Or rather, they're only needed now for backwards compatibility. And early computing was more trusting than we are now, so some security issues are intrinsic to decisions made way back when. If you could redesign everything from scratch, incorporating what we now know, things might possibly be different. But that would require a massive investment in time, energy, and money. There are, apparently, still numerous computers using really ancient software because businesses rely on that software and haven't been able to find an alternative on anything more recent. (Many tech people seem to have stories of someone finding an old system that nobody knows what it's used for any more, powering it off because something that old can't possibly be important any more, and discovering that doing so made it impossible for the business to function any more.)
Anyways. Rebuilding from scratch seems massively complicated, though there's some potential to the idea. Especially if you go with a gradual rollout, so businesses can adjust as their existing systems wear out and they have to buy new ones. (Sort of like the transition from IPV4 to IPV6, though you still have a lot of systems that requires the ability to use both.)
There's also the idea that we could secure the castle if we just held software vendors accountable for their software. That is, the hidden doors in your wall are not necessarily just from what you built. Or Microsoft, or Linux, or Apple. The operating system might have vulnerabilities, but any software you add to your computer can also come with vulnerabilities. So even if your operating system is secure, even if all known doorways are bricked up, if you downloaded and installed something (like an internet browser, or a game, or an application to manage your finances, or anything) that software might also create a hidden door in your castle walls.
And software companies, apparently, are well known for releasing products as quickly as they can... and fine-tuning them after they've gone public. Think of every new Windows operating system, or the time it took for Pokemon Go to smooth out all the bugs. The public acts as the final phase of testing for much of what gets released.
And, well... software is complicated. You can test, and test, and test, and probably won't find everything until you're doing it for real. Like when we changed our warehouse management system at my old company... I tested the heck out of it, but some things didn't become apparent until we were dealing with the number of users and orders we did on a daily basis. It's hard for a test environment to duplicate everything, and some problems are probably inevitable.
But that doesn't seem to be the real problem with this solution. After all, it shouldn't be too hard to have a reasonable standard of what is 'inevitable parts of producing a new product' and what is 'sheer laziness and the desire to make money quick'.
The real problem is that, in our current environment, nobody wants to add regulation that will unduly burden software vendors. Or maybe we don't need regulation, maybe we just need a really big lawsuit holding someone (Adobe, or Microsoft, or Google, or Apple, etc) accountable for the losses a business had when an attacker exploited a vulnerability in their product. Assuming you can, since I think we all tend to pro forma sign one of those Terms of Service that they'll probably use to deny liability for any such thing. Still, if software vendors have to pay a really large fee for any mistakes in their code, they'll probably start spending more money on development and testing for security in their product before releasing something new.
And if the case is big enough, and the vendor penalized enough, everyone else in the industry will take notice and start doing the same.
It may not stop attacks entirely, but it would at least make sure that there were fewer hidden doors to find. Of course, it would probably also slow down the software development process.
So those are just a few possible solutions. There's another way of looking at this, though.
I came up with the analogy I did because I wanted to think about what it meant, this mass distribution of the ability to hack into a target. The 'wizards' creating 'spells' that anyone could use.
Hmmm, before I focus on that I want to talk about something else.
Actually, given how long this is getting Imma gonna stop right here and start a new post.
Thursday, May 25, 2017
Cybersecurity and Organized Crime Ramblings
I sometimes consider how viewing a system organically makes a difference. "Organically" may be open to interpretation, so I'll clarify that a little. It means thinking of systems as things that grow and develop (and also can die, evolve, and more). I'm not a biologist, of course, so this may not be accurate...it's more like an explanation for a heuristic of mine.
So, for example, almost two decades ago when one of my political science classes talked about the tendencies of organizations to continue to justify their existence (hence why it's so hard to get rid of various organizations), it resonated with my own inclinations because it's a very organic concept. Organizations grow for various reasons, but they don't want to die so they will try to evolve and/or change their purpose in order to continue to stay in existence. It has some implications for anyone wanting to reduce the size of the government, in that you'll obviously face resistance of some sort...but (again with an organic reference) sometimes a little healthy pruning is good for the organization as a whole. Doing so in and of itself is not good or bad, it depends on how well you know the system and how well you prune without cutting out the critical bits.
I brought that up because it helps explain something I've been considering, w/regards to cybersecurity. It also applies to organized crime.
See - plants and animals are intricate systems where balance is key. Cancers, for example, grow when something happens to the mechanisms that normally keep cell growth under control. (again, not a cancer specialist here. I'm probably oversimplifying this tremendously.)
And aging - well, aging is when cells die faster than they can be replaced. (So businesses, nation-states, and all human-centric organizations can grow as they continue to develop or sustain their 'cells'...and start to die when they lose such things faster than they can be replaced. Of course, it's hard to define what a 'cell' in an organization is...but we still get a sense of when something is growing bigger/dying off.)
So cybercrime and crime in general...well, we'll probably always have some. Stopping it entirely is a pipe dream. But what we can and should stop is letting criminal behavior grow to the point that it interferes with/disrupts everything else. Hence so many comparisons to cancer.
Cybercrime today is dangerously close to metasizing. So many successful attacks are occuring that it encourages interested parties to continue to do so...to a greater and greater degree. It's like, defense isn't just difficult in and of itself...it's difficult because there are just so many attackers out there at the moment.
It's getting to the point where you sort of expect to get hacked, or your identity stolen, or something malicious to occur.
The same thing can happen with organized crime. It's like, sure...most of us enjoy movies like The Godfather or Goodfellas. But that's fiction, and it's entirely different when they organize to steal millions of dollars of nuts. Now you see a very real interference with the economy, with the ability of hard working farmers to make a living, and/or with insurance companies that have to pay for the loss.
That's enough to start with. I'm actually heading to visit some relatives for my birthday, so I've got to finish up packing and hit the road.
So, for example, almost two decades ago when one of my political science classes talked about the tendencies of organizations to continue to justify their existence (hence why it's so hard to get rid of various organizations), it resonated with my own inclinations because it's a very organic concept. Organizations grow for various reasons, but they don't want to die so they will try to evolve and/or change their purpose in order to continue to stay in existence. It has some implications for anyone wanting to reduce the size of the government, in that you'll obviously face resistance of some sort...but (again with an organic reference) sometimes a little healthy pruning is good for the organization as a whole. Doing so in and of itself is not good or bad, it depends on how well you know the system and how well you prune without cutting out the critical bits.
I brought that up because it helps explain something I've been considering, w/regards to cybersecurity. It also applies to organized crime.
See - plants and animals are intricate systems where balance is key. Cancers, for example, grow when something happens to the mechanisms that normally keep cell growth under control. (again, not a cancer specialist here. I'm probably oversimplifying this tremendously.)
And aging - well, aging is when cells die faster than they can be replaced. (So businesses, nation-states, and all human-centric organizations can grow as they continue to develop or sustain their 'cells'...and start to die when they lose such things faster than they can be replaced. Of course, it's hard to define what a 'cell' in an organization is...but we still get a sense of when something is growing bigger/dying off.)
So cybercrime and crime in general...well, we'll probably always have some. Stopping it entirely is a pipe dream. But what we can and should stop is letting criminal behavior grow to the point that it interferes with/disrupts everything else. Hence so many comparisons to cancer.
Cybercrime today is dangerously close to metasizing. So many successful attacks are occuring that it encourages interested parties to continue to do so...to a greater and greater degree. It's like, defense isn't just difficult in and of itself...it's difficult because there are just so many attackers out there at the moment.
It's getting to the point where you sort of expect to get hacked, or your identity stolen, or something malicious to occur.
The same thing can happen with organized crime. It's like, sure...most of us enjoy movies like The Godfather or Goodfellas. But that's fiction, and it's entirely different when they organize to steal millions of dollars of nuts. Now you see a very real interference with the economy, with the ability of hard working farmers to make a living, and/or with insurance companies that have to pay for the loss.
That's enough to start with. I'm actually heading to visit some relatives for my birthday, so I've got to finish up packing and hit the road.
Subscribe to:
Posts (Atom)