Attacks/Breaches
Guest Blog // Selected Security Content Provided By Sophos
What's This?
6/4/2014
04:05 PM
Maxim Weinstein
Maxim Weinstein
Security Insights
100%
0%

Back To Basics

By failing to execute on basic security, we're making the attacker's job too easy.

About half of American adults have had data stolen via a breach in the past year, according to a recent study. It would be easy to look at that statistic and the who's who of brands that have been breached -- Target, eBay, Adobe, Nieman Marcus -- and conclude that attackers have gotten so sophisticated that we have no chance to protect our own organizations from a similar fate. The truth, though, is that many of these high-profile attacks have succeeded, not because of their sophistication, but because we continue failing to execute on basic security.

Consider the Adobe breach, which leaked 38 million records and some of the company's source code. It's been alleged, though not officially confirmed, that the point of entry was a public-facing web server that was lacking available patches. The leaked account records were not properly protected with a strong one-way hash algorithm designed for passwords. (Instead, they were encrypted with 3DES, a symmetric encryption algorithm not built for the purpose.) That the attackers could get from a public-facing web server to the company's confidential source code repository implies that the network was not properly segmented, nor access properly controlled and monitored between segments.

Speaking of network segmentation, some of the big retail breaches at Target and elsewhere were aided by point of sale (POS) systems sharing the VLAN with other systems that didn't require the same level of security. If the networks had been segmented, firewall rules could have restricted attempts to exfiltrate stolen data. And, when the average enterprise sees 10,000 security alerts per day, keeping sensitive systems separate make it easier to prioritize alerts like the one Target famously failed to act upon.

Other noteworthy breaches in recent years can be chalked up to dropping the ball on encrypting laptop hard drives or flash drives, restricting and monitoring access to management tools, and protecting encryption keys.

I'm not suggesting that getting security right is easy. I am suggesting that it's time to get back to basics. The latest APT-detecting threat intelligence gizmo with "innovative" technology isn't going to help you if your existing firewall is configured like Swiss cheese and your customer data is being toted around unencrypted on the VP's laptop.

A great place to start is the SANS Critical Security Controls list. The list is prioritized, so you can start at the top and work your way down, making sure you're covering your bases at each step. Call on your vendors to help, as well. They should have best-practices documents available to help you configure their tools for optimum effectiveness. And if you've seen threats slipping by, be sure to report them to the vendors, so they can improve their products and/or guide you in improving your use of the products.

A focus on doing the basics really well doesn't guarantee protection against every threat, but it certainly reduces your exposure to both opportunistic threats and targeted attacks. And if something does slip by, it's a lot easier to explain an attack that took advantage of an obscure vulnerability than one that should have been stopped by standard operating procedures.

Thanks to my colleague Chet Wisnewski, host of the Chet Chat podcast, for the presentation that inspired this post.

Maxim Weinstein, CISSP, is a technologist and educator with a passion for information security. He works in product marketing at Sophos, where he specializes in server protection solutions. He is also a board member and former executive director of StopBadware. Maxim lives ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
chny07
0%
100%
chny07,
User Rank: Apprentice
6/14/2014 | 4:45:59 AM
amazing
Thanks for the great article. i really appreciate it. it will be a great guide for my en ucuz iphone fiyatları thesis
ecowper
100%
0%
ecowper,
User Rank: Apprentice
6/12/2014 | 1:33:55 PM
Basics is the key
The more we analyze the breaches, the more it becomes clear that some really basic things aren't happening well, in general. And I do mean very basic. Network segmentation, user privilege and access management, end point security controls staying set at "factory default", etc. 

Doing security basics better would mitigate much of the impact of the initial entry point into the network. 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?