Attacks/Breaches
Guest Blog // Selected Security Content Provided By Sophos
What's This?
6/4/2014
04:05 PM
Maxim Weinstein
Maxim Weinstein
Security Insights
Connect Directly
RSS
E-Mail
100%
0%

Back To Basics

By failing to execute on basic security, we're making the attacker's job too easy.

About half of American adults have had data stolen via a breach in the past year, according to a recent study. It would be easy to look at that statistic and the who's who of brands that have been breached -- Target, eBay, Adobe, Nieman Marcus -- and conclude that attackers have gotten so sophisticated that we have no chance to protect our own organizations from a similar fate. The truth, though, is that many of these high-profile attacks have succeeded, not because of their sophistication, but because we continue failing to execute on basic security.

Consider the Adobe breach, which leaked 38 million records and some of the company's source code. It's been alleged, though not officially confirmed, that the point of entry was a public-facing web server that was lacking available patches. The leaked account records were not properly protected with a strong one-way hash algorithm designed for passwords. (Instead, they were encrypted with 3DES, a symmetric encryption algorithm not built for the purpose.) That the attackers could get from a public-facing web server to the company's confidential source code repository implies that the network was not properly segmented, nor access properly controlled and monitored between segments.

Speaking of network segmentation, some of the big retail breaches at Target and elsewhere were aided by point of sale (POS) systems sharing the VLAN with other systems that didn't require the same level of security. If the networks had been segmented, firewall rules could have restricted attempts to exfiltrate stolen data. And, when the average enterprise sees 10,000 security alerts per day, keeping sensitive systems separate make it easier to prioritize alerts like the one Target famously failed to act upon.

Other noteworthy breaches in recent years can be chalked up to dropping the ball on encrypting laptop hard drives or flash drives, restricting and monitoring access to management tools, and protecting encryption keys.

I'm not suggesting that getting security right is easy. I am suggesting that it's time to get back to basics. The latest APT-detecting threat intelligence gizmo with "innovative" technology isn't going to help you if your existing firewall is configured like Swiss cheese and your customer data is being toted around unencrypted on the VP's laptop.

A great place to start is the SANS Critical Security Controls list. The list is prioritized, so you can start at the top and work your way down, making sure you're covering your bases at each step. Call on your vendors to help, as well. They should have best-practices documents available to help you configure their tools for optimum effectiveness. And if you've seen threats slipping by, be sure to report them to the vendors, so they can improve their products and/or guide you in improving your use of the products.

A focus on doing the basics really well doesn't guarantee protection against every threat, but it certainly reduces your exposure to both opportunistic threats and targeted attacks. And if something does slip by, it's a lot easier to explain an attack that took advantage of an obscure vulnerability than one that should have been stopped by standard operating procedures.

Thanks to my colleague Chet Wisnewski, host of the Chet Chat podcast, for the presentation that inspired this post.

Maxim Weinstein, CISSP, is a technologist and educator with a passion for information security. He works in product marketing at Sophos, where he specializes in server protection solutions. He is also a board member and former executive director of StopBadware. Maxim lives ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
chny07
0%
100%
chny07,
User Rank: Apprentice
6/14/2014 | 4:45:59 AM
amazing
Thanks for the great article. i really appreciate it. it will be a great guide for my en ucuz iphone fiyatları thesis
ecowper
100%
0%
ecowper,
User Rank: Apprentice
6/12/2014 | 1:33:55 PM
Basics is the key
The more we analyze the breaches, the more it becomes clear that some really basic things aren't happening well, in general. And I do mean very basic. Network segmentation, user privilege and access management, end point security controls staying set at "factory default", etc. 

Doing security basics better would mitigate much of the impact of the initial entry point into the network. 
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7407
Published: 2014-10-22
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-3675
Published: 2014-10-22
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

CVE-2014-3676
Published: 2014-10-22
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

CVE-2014-3677
Published: 2014-10-22
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

CVE-2014-3828
Published: 2014-10-22
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the session_id...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.