cyber security emerging threats

42
Page 1 Cyber Security Current Trends & Emerging Threats Michael Saylor | Executive Director Cyber Defense Labs

Post on 14-Sep-2014

622 views

Category:

Technology


6 download

DESCRIPTION

Mike Saylor's Briefing to the Dallas-Fort Worth Chapter

TRANSCRIPT

Page 1: Cyber Security Emerging Threats

Page 1

Cyber SecurityCurrent Trends & Emerging Threats

Michael Saylor | Executive Director

Cyber Defense Labs

Page 2: Cyber Security Emerging Threats

Page 2

Michael (Mike) Saylor, CISM, CISA

•19 years of IT security and Cyber investigations

•Incident Response, Fraud Investigations, Digital Forensics

•Executive Director for Cyber Defense Labs at UT Dallas

•President Emeritus for the North Texas FBI Infragard

•Cyber Crime Committee Member for the North Texas Crime Commission

•CIO for the Texas Credit Union League

•Professor of Cyber Security for Collin College

•B.S. in Information Systems, and Masters Criminal Justice

•Worked with local and federal law enforcement on high profile cases

Page 3: Cyber Security Emerging Threats

Page 3

Recent TrendsIndustry Analysis (2012-2013)

Continuing and Emerging ThreatsContinued Convergence

Drugs, Crime, and Terrorism

Enterprise Best Practices

Page 4: Cyber Security Emerging Threats

Page 4

Recent TrendsRecent TrendsMost attacks in 2013 had both web, and social engineering components, but there was also a dramatic rise in politically motivated DDoS attacks. •Mobile Devices and Mobile Applications•Hacktivism / Cyber Protests (Defacement, DDoS)•Advanced Persistent Threat (APT)•Lures

Social Engineering & Social Media

Search Engine Optimization Poisoning

Spam and Spear Phishing

Page 5: Cyber Security Emerging Threats

Page 5

Mobile DevicesMobile Devices• 6.8 Billion Mobile Subscribers on the

Planet 96% of the population• Mobile Apps increasingly rely on a

Internet browser• AppStores have poor patch

management and Q/A• Mobile anti-malware solutions immature• 51% of users circumvent or disable

device passwords & security controls• Growing number of malicious mobile

applications and mobile exploitation

Page 6: Cyber Security Emerging Threats

Page 6

Mobile DevicesMobile DevicesRecent attacks include:•Mobile based DDoS tools (MDDoS)•Scrapping apps, looking for sensitive data on device. •SMShing – SMS texts asking for bank credentials / PIN, or to call 800 number•Trojan / Malware – PC malware transferred from phones that are charging.

Page 7: Cyber Security Emerging Threats

Page 7

Mobile DevicesMobile Devices

Page 8: Cyber Security Emerging Threats

Page 8

Recent TrendsRecent Trends• Malicious

Android Apps up 580% (28k)

• Location Services?

• Mobile Threats will impact your organization – eventually!

• CEO’s Phone?

Page 9: Cyber Security Emerging Threats

Page 9

MalwareMalware82% of malware sites are hosted on compromised systems55% of data-stealing malware is web-based

Page 10: Cyber Security Emerging Threats

Page 10

• Attacks in Response to Geo-Political issues• Objectives are primarily to disrupt and / or voice the

views of a particular group.– Website defacements

– Denial of Service attacks (US / Israeli Banks / Government, business sites)

– Automated exploit attempts

• The Syrian Electronic Army (SEA), hacked API news and planted a false story about Obama being injured in a bombing attack on the Whitehouse and drove the stock market down over 200 points in a few seconds.

Hacktivism / Cyber ProtestsHacktivism / Cyber Protests

Page 11: Cyber Security Emerging Threats

Page 11

Hacktivism / Cyber ProtestsHacktivism / Cyber Protests

Page 12: Cyber Security Emerging Threats

Page 12

TechniquesTechniques

Page 13: Cyber Security Emerging Threats

Page 13

CountriesCountries

1. China 41 percent (of the world's attack traffic)

2. U.S. 10 percent

3. Turkey 4.7 percent

4. Russia 4.3 percent

5. Taiwan 3.7 percent

6. Brazil 3.3 percent

7. Romania 2.8 percent

8. India 2.3 percent

9. Italy 1.6 percent

10. Hungary 1.4 percent

Top Ten Hacking Countries, by Attack Traffic %

Page 14: Cyber Security Emerging Threats

Page 14

CountriesCountries

Page 15: Cyber Security Emerging Threats

Page 15

Any computer system connected to a communications medium will be compromised given enough time and the appropriate resources. 80% of attacks in 2013 required multi-stage defenses for protection.

APT Attacks use:

-Highly Customized Tools and Intrusion Techniques

-Stealthy, Patient attack methods to reduce detection

-Focus on high value targets (Mil, Pol, Eco, Intel)

-Well funded & staffed, supported by Mil or State Intel

-Organizations are targeted for strategic importance

Advanced Persistent ThreatsAdvanced Persistent Threats

Page 16: Cyber Security Emerging Threats

Page 16

APT Attackers worked with BotNet operators to determine if target systems have already been compromised.

Use of polymorphic code that manifests differently on each system it infects.

Cyber Criminals are becoming Information Brokers as a result of their Industrial Espionage schemes.

APTAPT

Page 17: Cyber Security Emerging Threats

Page 17

APT – Distribution of TargetsAPT – Distribution of Targets

Page 18: Cyber Security Emerging Threats

Page 18

““A Thousand Grains of Sand…”A Thousand Grains of Sand…”The Chinese continue to follow the ancient book, "The Art of War,“ which advises the commission of espionage by "a thousand grains of sand"; meaning obtaining small but innumerable pieces of information by vast numbers of people acting as armies of spies sent against the enemy.

This recruitment usually translates to ethnic, 1st generation Chinese immigrants with cultural and familial ties to China. The Chinese government then reciprocates by helping their part-time spies create or proceed with commercial or business ventures in the United States. This is called guanxi (goowongsee). As a result, the Chinese coordinators do not offer money, and they do not accept walk-in cases, which may turn out to be "dangles" (double agents). Most espionage activities are coordinated by the Ministry of State Security (MSS) or the military intelligence arm of the People's Liberation Army (PLA).

Dave Wise, Espionage Author

Page 19: Cyber Security Emerging Threats

Page 19

• Mandiant’s 2013 report on the Chinese (APT1) attacks on 141 organizations since 2006 (115 were in the U.S.).

• The report presents substantial evidence of Chinese sponsored activities, including photos, forensics, communications, and profiles.

• Soon after Mandiant’s report, the U.S. government publishes a 140 page strategy to combat the theft of U.S. trade secrets

• The U.S. government initially attempted to halt the attacks on U.S. organizations, but soon resorted to asking China to please stop stealing our stuff.

• China’s response to the Mandiant report was that it was “unprofessional” to publish and make such claims.

EspionageEspionage

Page 20: Cyber Security Emerging Threats

Page 20

• According to the U.S. Justice Department, of 20 cases of economic espionage and trade secret criminal cases from January 2009 to January 2013, 16 involved Chinese nationals; i.e. organizations hired foreign nationals to work on national security level projects (DuPont, NASA, Google, Intel, DoD, etc.)

• 63% of impacted organizations learn they were breached from an external source, like law enforcement.

• Organizations are being targeted by more than one attack group, sometimes in succession. In 2012, 38% of targets were attacked again after the original incident was remediated, lodging more than one thousand attempts to regain entry to former victims.

• Feb 2013 report (Akamai) shows that 30% of all observed attacks came from China and 13% originated from within the U.S. March 2013 report (Solutionary) states that the majority of attacks on the U.S. are now originating in the U.S.

EspionageEspionage

Page 21: Cyber Security Emerging Threats

Page 21

EspionageEspionage

Page 22: Cyber Security Emerging Threats

Page 22

EspionageEspionage

Page 23: Cyber Security Emerging Threats

Page 23

• In 2013, Exploit Toolkits cost between $40 and $4k• The Malware that likely compromised Target’s POS

system, cost less than $3,000.• 61% of all malware is based on pre-existing toolkits;

upgrades keep them current and provide additional capabilities (“Value”)

• Toolkits used for Targeted Attacks can create custom Blog entries, emails, IMs, & web site templates to entice targets toward malicious links / content. (Blackhole >100k/day)

Exploit Toolkits & MalwareExploit Toolkits & Malware

Page 24: Cyber Security Emerging Threats

Page 24

• Traditional Attacks were loud, high volume attacks typically stopped by threat monitoring tools

• Today’s sniper attacks use specific exploits to get clear shots at the objective

• The convergence of Social Engineering, Social Profiling, and Geo-Location improve attack success

• Rogue software (anti-virus, registry cleaner, machine speed improvement, backup software, etc)– Increase in MAC Malware (MAC Defender)– +50% attacks on Social Media sites were Malware

Exploit Toolkits & MalwareExploit Toolkits & Malware

Page 25: Cyber Security Emerging Threats

Page 25

Several attacks in 2013 were conducted by luring victims to accept malware or follow a link to an infected site. 4% of all email contained a Malware or a link to and infected site.

There are 6 stages of the attack:

LuresLures

Page 26: Cyber Security Emerging Threats

Page 26

LuresLures

Page 27: Cyber Security Emerging Threats

Page 27

• Typo-Squatting

• Fake Facebook Applications

• Hidden Camera Video Lure

• Celebrity Deaths

• Fake Offers & Gifts

• Browser Plugin Scams

• Fake Profile Creeper

• Blog Spam Attack

Lures – Facebook SpecificLures – Facebook Specific

Page 28: Cyber Security Emerging Threats

Page 28

2013 saw an increase in malware infections as a result of SEP. •Hackers crawling current news headlines, creating related malicious sites and conducting SEP•Google Images – links to source photo•Using web analytics to determine what people are searching for

Search Engine PoisoningSearch Engine Poisoning

Page 29: Cyber Security Emerging Threats

Page 29

Top Social Engineering LuresTop Social Engineering Lures

Page 30: Cyber Security Emerging Threats

Page 30

SPAMSPAM2013 SPAM Results•Spam is at 69% of all global email•Phishing attacks are 1 in every 414 emails •Email that contained a virus were 1 in every 291•Top Industries Attacked: Manufacturing, Financial, Services, Government, Energy•Top Recipients Attacked: R&D, Sales, C-Suite, Shared Mailbox

Page 31: Cyber Security Emerging Threats

Page 31

• 639 Unique Brands were target by Phishing in Q2’13

PhishingPhishing

Page 32: Cyber Security Emerging Threats

Page 32

Emerging ThreatsEmerging Threats

Page 33: Cyber Security Emerging Threats

Page 33

• Mobile Internet will continue to increase as it eventually takes the place of desktop Internet.

• The illegal drug organizations are looking to Cyber Crime to facilitate their business and expand their operations. Your organization could be infiltrated by an insider, socially engineered for identities and social profiles, and potentially held hostage with ransomeware.

• Localized Nation State attacks on U.S. increase

Emerging ThreatsEmerging Threats

Crypto-Locker from Russia is Crypto-Locker from Russia is one of the current Threatsone of the current Threats

Page 34: Cyber Security Emerging Threats

Page 34

Terrorists are expected to continue to expand their technical capabilities which may lead to an increase in cyber crime and cyber terrorism.

•Domestic groups funded by foreign States to conduct US-based attacks

•Cyber crime as a funding vehicle for Terrorism

•Cyber as a facilitator / component for a Terrorist attack (Effects-Based Operations)

Emerging ThreatsEmerging Threats

Page 35: Cyber Security Emerging Threats

Page 35

• Malware embedded at the hardware / chip level of consumer products will continue to increase.

• Targeted Attacks and APT will continue to increase in number and sophistication.

• Sophistication from APT attacks will trickle down to black market malware toolkits.

• Mobile Phone attacks will increase in volume and type• Insider Threat will continue to grow as new technology

is introduced, especially non-company devices• Thwarting attacks will require multi-stage defenses

Emerging ThreatsEmerging Threats

Page 36: Cyber Security Emerging Threats

Page 36

• Attackers are increasingly using outsourced service providers (HR, Procurement, IT, Finance, etc.) as a means to gain access to their victims.

• Attackers are using comprehensive reconnaissance (network, physical, social) to help navigate victims’ organization and networks more effectively (e.g. network infrastructure, system administration guides, etc.)

• The use of “Black Hats for Hire” will grow to support the organizational foot soldiers of Nation State actors.

Ic3Br3ak3r223:“im not an Anon just to be clear on that, im an independent for black market…: im a destroyer i dont build anything i only take it apart…I get payed or they pay again and again”

(Hacked: MIT, Harvard, CIA Web Pages, Israeli Military Emails, Pentagon Emails and Axis Security camera around the world. )

Emerging ThreatsEmerging Threats

Page 37: Cyber Security Emerging Threats

Page 37

Emerging ThreatsEmerging ThreatsNetwork Attacks

Physical SecurityBreach

Social Engineering

MalwareWORMSVirus

Phone CallsPhone Calls

EmailsEmails

Remote UsersRemote Users

WirelessNetworksWirelessNetworks

Client-S

ide

Attack

sClie

nt-Side

Attack

sWirelessHomeNetworks

WirelessHomeNetworks

Cloud Provider / Vendor

Cloud Provider / Vendor

Company DataCompany Data

Worms Virus Malware

Worms Virus Malware

NETWORK PERIMETER

INTERNAL NETWORK

DMZ

CORESYSTEMS

Email

Spam / Phishing / Malware

Internet Use

Web Sites

Web Applications

Mobile Device / Media

Malware Embedded HardwareInsider Threat

Social EngineeringSocial NetworkingNetwork AttacksPhysical BreachMalwarePhishingInsiders

APT

Page 38: Cyber Security Emerging Threats

Page 38

• Growth of the Dark Web / Tor Network– Law Enforcement has little understanding of these “off the

web” networks, how to access them, and the types of activities being conducted there, including:

• CrimeWare• Child Pornography• Trafficking of Drugs, Weapons, Humans• Child Exploitation• Sex Tourism

– Without LE involvement and understanding in these networks, criminal activity will grow and evolve, and outpace legislative and procedural response to these crimes.

Emerging ThreatsEmerging Threats

Page 39: Cyber Security Emerging Threats

Page 39

• Sophistication of “Call-Home” tactics of Malware will continue to grow, including the use of Twitter, DNS, VoIP, and other open communication channels for command and control.

• Recent and emerging Ransomeware and Crimeware receive updates / patches and can be armed with various modules.

• Your Social Media Identity is or soon will be valued greater than your Credit Cards.

Emerging ThreatsEmerging Threats

Page 40: Cyber Security Emerging Threats

Page 40

User Education and Awareness and Education and Awareness

Containment is the new Prevention….Compromise is inevitable

Monitoring Network, Vulnerabilities, and Brand

Anti-Virus, Anti-Malware, Device Control

Encryption (Would have helped Target)

Data Loss Prevention & Monitoring

Removable Media Policy

Mobile Device Policy

Frequent Risk-Based Security Assessments and Updates

Aggressive Patching and Software Polling

Incident Response Procedures

Social Media / Social Networking Policy

Best Practice GuidelinesBest Practice Guidelines

Page 41: Cyber Security Emerging Threats

Page 41

ReferencesReferencesGlobal mobile statistics 2013, mobithinking.com 2013

Mandiant Report – February 2013

Securelist 2013

Hackmageddon 2013

Government Technology 2013

Kaspersky Labs report on Red October 2013

Symantec Intelligence Reports 2013

Bit9 Cyber Security Report 2012

Georgia Tech - Emerging Cyber Threats Report 2012

WebSense Threat Report 2012

TrendLabs – Security in the Age of Mobility 2012

LookOut Mobile Security Report 2012

Breakthrough Silicon Scanning Discovers Backdoor, University of Cambridge 2012

Tiger Trap, David Wise, 2012

TrendMicro, Peter the Great versus Sun Tzu, 2012

Page 42: Cyber Security Emerging Threats

Page 42

Questions?

Mike Saylor | Cyber Defense Labs

[email protected]

972-454-0227

Terry Quan | Cyber Defense Labs

[email protected]

214-563-5235

Questions / Contact InfoQuestions / Contact Info