(isc)2 2016: why targeting is the next big trend in attacks

51

Upload: lance-cottrell

Post on 21-Feb-2017

13 views

Category:

Presentations & Public Speaking


0 download

TRANSCRIPT

Page 1: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 2: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Why Targeting Is the Next Big Trend in Attacks

Lance CottrellChief Scientist

Ntrepid Corporation

2

Page 3: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 4: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

If you got an e-card from your mother on your birthday, with your childhood picture

4

would you open it?

Page 5: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

The Fraction of Companies Which Said:

“Targeting is a concern or inevitable”

Page 6: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Most Companies are TargetsQuocira Study

Page 7: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Targeting Big Fish

Page 8: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

The Email Threat

» Two Realities:• Masterfully crafted spear

phish will catch almost everyone

• People need to click to work

Page 9: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

The Browser is the Biggest ThreatThe Browser is the Biggest Threat

Page 10: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Targeted Attacks

Page 11: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Spear Phishing

Page 12: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Un-targeted Attacks

Page 13: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Targeted

Page 14: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Made you click!

Page 15: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Social Engineering

Page 16: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Not just a Watering Hole

Page 17: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Snipers at the Watering Hole

Page 18: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Do you read news online?

Do you feel at risk?

Page 19: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 20: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Waterbug / Turla

Page 21: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Dark Hotel

Page 22: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 23: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 24: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Stay Below the Radar

Page 25: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 26: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 27: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 28: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Conserves Zero-day Exploits

Page 29: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

More Damaging

Page 30: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

DNC Emails

Page 31: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Stuxnet

Page 32: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Am I a Target?

» Obvious high profile individuals» Access to valuable data» Access to exploitable data» Access to money» Access to networks» Access to people» Obviously weak defenses

Page 33: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Can We Avoid Targeting?

Page 34: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Email is Really Hard

» No organizational domain» No correspondence with org» Work in full alias

Page 35: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

On the Web, Maybe

» Delete cookies» Hide IP address» Scrub persistent trackers» Mask browser fingerprint» Disposable VM with VPN

Page 36: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

What does targeting mean for our

defensive strategy?

“Bummer of a birthmark, Hal.”

Page 37: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

You can’t train your way out of this

Page 38: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

You can’t train your way out of this

You can fool some of the people all of the time

ANDYou can fool all of the people

some of the time

Page 39: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Detection works worst when you

need it most

Page 40: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

We need next generation security

Page 41: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Damage Reduction

Page 42: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 43: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 44: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks
Page 45: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Isolation

Page 46: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Leverage Virtualization

» Enables isolation» Easy remediation and restoration» Keep them small

Page 47: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Recover…whether or not you detect anything

Page 48: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Keep your boxas empty as possible

Page 49: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Remember

Page 50: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

To Do…

Page 51: (ISC)2 2016: Why Targeting is the Next Big Trend in Attacks

Lance CottrellChief Scientist

[email protected]@LanceCottrell