Attacks/Breaches
Guest Blog // Selected Security Content Provided By Sophos
What's This?
6/4/2014
04:05 PM
Maxim Weinstein
Maxim Weinstein
Security Insights
100%
0%

Back To Basics

By failing to execute on basic security, we're making the attacker's job too easy.

About half of American adults have had data stolen via a breach in the past year, according to a recent study. It would be easy to look at that statistic and the who's who of brands that have been breached -- Target, eBay, Adobe, Nieman Marcus -- and conclude that attackers have gotten so sophisticated that we have no chance to protect our own organizations from a similar fate. The truth, though, is that many of these high-profile attacks have succeeded, not because of their sophistication, but because we continue failing to execute on basic security.

Consider the Adobe breach, which leaked 38 million records and some of the company's source code. It's been alleged, though not officially confirmed, that the point of entry was a public-facing web server that was lacking available patches. The leaked account records were not properly protected with a strong one-way hash algorithm designed for passwords. (Instead, they were encrypted with 3DES, a symmetric encryption algorithm not built for the purpose.) That the attackers could get from a public-facing web server to the company's confidential source code repository implies that the network was not properly segmented, nor access properly controlled and monitored between segments.

Speaking of network segmentation, some of the big retail breaches at Target and elsewhere were aided by point of sale (POS) systems sharing the VLAN with other systems that didn't require the same level of security. If the networks had been segmented, firewall rules could have restricted attempts to exfiltrate stolen data. And, when the average enterprise sees 10,000 security alerts per day, keeping sensitive systems separate make it easier to prioritize alerts like the one Target famously failed to act upon.

Other noteworthy breaches in recent years can be chalked up to dropping the ball on encrypting laptop hard drives or flash drives, restricting and monitoring access to management tools, and protecting encryption keys.

I'm not suggesting that getting security right is easy. I am suggesting that it's time to get back to basics. The latest APT-detecting threat intelligence gizmo with "innovative" technology isn't going to help you if your existing firewall is configured like Swiss cheese and your customer data is being toted around unencrypted on the VP's laptop.

A great place to start is the SANS Critical Security Controls list. The list is prioritized, so you can start at the top and work your way down, making sure you're covering your bases at each step. Call on your vendors to help, as well. They should have best-practices documents available to help you configure their tools for optimum effectiveness. And if you've seen threats slipping by, be sure to report them to the vendors, so they can improve their products and/or guide you in improving your use of the products.

A focus on doing the basics really well doesn't guarantee protection against every threat, but it certainly reduces your exposure to both opportunistic threats and targeted attacks. And if something does slip by, it's a lot easier to explain an attack that took advantage of an obscure vulnerability than one that should have been stopped by standard operating procedures.

Thanks to my colleague Chet Wisnewski, host of the Chet Chat podcast, for the presentation that inspired this post.

Maxim Weinstein, CISSP, is a technologist and educator with a passion for information security. He works in product marketing at Sophos, where he specializes in server protection solutions. He is also a board member and former executive director of StopBadware. Maxim lives ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
chny07
0%
100%
chny07,
User Rank: Apprentice
6/14/2014 | 4:45:59 AM
amazing
Thanks for the great article. i really appreciate it. it will be a great guide for my en ucuz iphone fiyatları thesis
ecowper
100%
0%
ecowper,
User Rank: Apprentice
6/12/2014 | 1:33:55 PM
Basics is the key
The more we analyze the breaches, the more it becomes clear that some really basic things aren't happening well, in general. And I do mean very basic. Network segmentation, user privilege and access management, end point security controls staying set at "factory default", etc. 

Doing security basics better would mitigate much of the impact of the initial entry point into the network. 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-4403
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.ph...

CVE-2012-2930
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers...

CVE-2012-2932
Published: 2015-04-24
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the (1) selitems[] parameter in a copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/...

CVE-2012-5451
Published: 2015-04-24
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.

CVE-2015-0297
Published: 2015-04-24
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methos via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.