what a bank iso should know about forensics - indiana bankers a bank iso should know... ·...

24
What a Bank ISO Should Know About Forensics

Upload: others

Post on 03-Sep-2019

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

WhataBankISOShouldKnowAboutForensics

Page 2: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

DisclaimerMutualRiskAdvisorsisnotendorsingoraffiliatedwithanyofthecompanieslistedinthefollowingslides.

Doyourownduediligence&riskassessmentsontheproductsandlinksmentioned.

Page 3: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

OwenLaChat

SVP&ManagingDirector– MutualRiskAdvisors,Inc.

VP&ISO– MutualBank,Inc.$1.4BCommunityBank– 31 locationsinIN&MI.Nasdaq:MFSF

Former:• CyberSecurityTechnicalTeamLeader• InformationSystemsSecurityAuditor• Detective

Page 4: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

WheretoFocusResources?

o Policies&Procedureso RiskAssessmentso VendorManagemento Phishingo System&NetworkMonitoringo Logs/SIEMo IncidentResponse/Forensics

Page 5: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

Policies&Procedures

oArethefoundationalpiecesofagoodinformationsecurityprogram.o Shouldoutlineandmemorializeyourexpectations.o Shouldbeviewed,approved,andfollowedfromthetopdown.oOfteneitherspendtoomuchornotenoughtimedevelopingandtuning.

Page 6: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

RiskAssessments

o Isthepersoncompletingtheriskassessmentsqualifiedtoassessrisk?oAretheyfocusingonthelargestrisksandquantifyingcorrectly?oDothemitigatingcontrolsactuallymitigate?

Page 7: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

VendorManagement

o Vendorscanbealargerisktotheenvironment.oDovendorsfollowyourinfosecpolicies/procedureswhendealingwithyourdata?

o Logs?o Knowyourvendors,whattheydo,howtheydoit,theirweaknesses,etc.Duediligence.

o Testyourtechnicalvendorsregularly.o “Trust,butverify.”

Page 8: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

Phishing

oHowmanybreachesoccur.o Fairlydifficulttoconsistentlykickinthefrontdoorofthenetwork.o It’snecessarytoexaminesamplesforintelligencefromnewattackmethods.

o “ButIhaveaspamfilterandemployeesrarelyreportanyphishingemails.”

Page 9: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

NetworkMonitoring

o Knowyournetworkmapsandroutes.o Internal/externalsensors.

o DoIneedIDS/IPSsensorsontheinsideandoutside?o Externalsensors– “That’swhatafirewallisfor..”

o 24/7monitoring&internaloversight.oWhattrafficisitmissing?

o TLS/SSL?o HTTPwithanencryptedpayload…o IsTLS/SSLmalwaredataextractioncommon?

o Geolocation.o Fullpacketcaptureisanecessity.

Page 10: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

NetworkMonitoring- TrafficAnalysis

oMolocho Fullpacketcapture.ohttp://molo.ch/

oNetworkMineroNetworkanalysistool&offlinePCAPreassemblytool.ohttp://www.netresec.com/?page=Networkminer

oWiresharkohttps://www.wireshark.org

Page 11: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

NetworkMonitoring- IDS/IPS

o SecurityOnionohttps://securityonion.net/

o Snort/Suricataohttps://www.snort.org/ https://suricata-ids.org/

oOSSECohttp://ossec.github.io/downloads.html

o Broohttps://www.bro.org/

Page 12: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

SystemMonitoring

o Knowyourvulnerabilities.oAssesspatchlevels.oDeviceinventories.

o Applicationsinstalled,versionnumbers,OS,runningservices,etc.oKnowwhereyourdeprecatedappliances/softwarereside.oAttackermindset.

Page 13: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

Logs/SIEM

oWhat’sbeinglogged?oAreyouloggingtherightthingsandforenoughtime?oDoyouhavealogcollection/aggregationsystem?oAreyoucapturingWindowsEventLogs,Syslog,netflow,pcap,etc.

oAutomatedalertingbasedonpredefinedthresholds.oUsergetslockedout,VPNs,attemptedsoftwareinstalls,RDP,accountscreated/deleted,andmanymore.

Page 14: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

LogSolutions

o ELK(ElasticSearch,LogStash,Kibana)ohttps://www.elastic.co/webinars/introduction-elk-stack

o Solarwinds LEMohttp://www.solarwinds.com/log-event-manager

o Splunkohttps://www.splunk.com/

Page 15: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

IncidentResponse/Forensics

oWhoownsresponseactivities?o ITvsIS.Who’sincharge?oNewFFIECguidancefocusingmoreonISactivities.o LargeamountofcontrolplacedinISforhistorically“IT”duties.

o In-houseresources.oHowoftencanyouleverage?oCertificationso Training

oOutsourced– Forensicretainers.

Page 16: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

HostBasedForensics(Media)

o ForensicToolkitohttp://www.accessdata.com

o EnCase Forensicohttps://www.guidancesoftware.com/encase-forensic

o InternetEvidenceFinderohttps://www.magnetforensics.com/

oHashcatohttps://hashcat.net/hashcat/

Page 17: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

HostBasedForensics(Imaging&Memory)

o RAMCaptureUtilitiesoMagnetRamCapture

o https://www.magnetforensics.com/magnet-ief/o FTKImager

o http://www.accessdata.com

o RAMParsingUtilitiesoVolatility

o http://www.volatilityfoundation.org/

Page 18: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

TrackingNetworkAnomalies

Page 19: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

PhishingAttempt– Documentw/Macros

Page 20: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

IDSAlert– EXEdownloadedoverHTTP

Page 21: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

FullPacketCapture

Page 22: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

LogSystemAlert

Page 23: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

HostBasedForensicEventConfirmation

Page 24: What a Bank ISO Should Know About Forensics - Indiana Bankers a Bank ISO Should Know... · Disclaimer Mutual Risk Advisors is not endorsing or affiliated with any of the companies

Questions?

[email protected]