Attacks/Breaches
Guest Blog // Selected Security Content Provided By Sophos
What's This?
6/4/2014
04:05 PM
Maxim Weinstein
Maxim Weinstein
Security Insights
100%
0%

Back To Basics

By failing to execute on basic security, we're making the attacker's job too easy.

About half of American adults have had data stolen via a breach in the past year, according to a recent study. It would be easy to look at that statistic and the who's who of brands that have been breached -- Target, eBay, Adobe, Nieman Marcus -- and conclude that attackers have gotten so sophisticated that we have no chance to protect our own organizations from a similar fate. The truth, though, is that many of these high-profile attacks have succeeded, not because of their sophistication, but because we continue failing to execute on basic security.

Consider the Adobe breach, which leaked 38 million records and some of the company's source code. It's been alleged, though not officially confirmed, that the point of entry was a public-facing web server that was lacking available patches. The leaked account records were not properly protected with a strong one-way hash algorithm designed for passwords. (Instead, they were encrypted with 3DES, a symmetric encryption algorithm not built for the purpose.) That the attackers could get from a public-facing web server to the company's confidential source code repository implies that the network was not properly segmented, nor access properly controlled and monitored between segments.

Speaking of network segmentation, some of the big retail breaches at Target and elsewhere were aided by point of sale (POS) systems sharing the VLAN with other systems that didn't require the same level of security. If the networks had been segmented, firewall rules could have restricted attempts to exfiltrate stolen data. And, when the average enterprise sees 10,000 security alerts per day, keeping sensitive systems separate make it easier to prioritize alerts like the one Target famously failed to act upon.

Other noteworthy breaches in recent years can be chalked up to dropping the ball on encrypting laptop hard drives or flash drives, restricting and monitoring access to management tools, and protecting encryption keys.

I'm not suggesting that getting security right is easy. I am suggesting that it's time to get back to basics. The latest APT-detecting threat intelligence gizmo with "innovative" technology isn't going to help you if your existing firewall is configured like Swiss cheese and your customer data is being toted around unencrypted on the VP's laptop.

A great place to start is the SANS Critical Security Controls list. The list is prioritized, so you can start at the top and work your way down, making sure you're covering your bases at each step. Call on your vendors to help, as well. They should have best-practices documents available to help you configure their tools for optimum effectiveness. And if you've seen threats slipping by, be sure to report them to the vendors, so they can improve their products and/or guide you in improving your use of the products.

A focus on doing the basics really well doesn't guarantee protection against every threat, but it certainly reduces your exposure to both opportunistic threats and targeted attacks. And if something does slip by, it's a lot easier to explain an attack that took advantage of an obscure vulnerability than one that should have been stopped by standard operating procedures.

Thanks to my colleague Chet Wisnewski, host of the Chet Chat podcast, for the presentation that inspired this post.

Maxim Weinstein, CISSP, is a technologist and educator with a passion for information security. He works in product marketing at Sophos, where he specializes in server protection solutions. He is also a board member and former executive director of StopBadware. Maxim lives ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
chny07
0%
100%
chny07,
User Rank: Apprentice
6/14/2014 | 4:45:59 AM
amazing
Thanks for the great article. i really appreciate it. it will be a great guide for my en ucuz iphone fiyatları thesis
ecowper
100%
0%
ecowper,
User Rank: Apprentice
6/12/2014 | 1:33:55 PM
Basics is the key
The more we analyze the breaches, the more it becomes clear that some really basic things aren't happening well, in general. And I do mean very basic. Network segmentation, user privilege and access management, end point security controls staying set at "factory default", etc. 

Doing security basics better would mitigate much of the impact of the initial entry point into the network. 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0547
Published: 2015-07-04
The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.

CVE-2015-0548
Published: 2015-07-04
The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.

CVE-2015-0551
Published: 2015-07-04
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P2...

CVE-2015-1966
Published: 2015-07-04
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafte...

CVE-2015-4196
Published: 2015-07-04
Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report