Perimeter

6/22/2017
10:00 AM
Eric Thomas
Eric Thomas
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

WannaCry? Youre Not Alone: The 5 Stages of Security Grief

As breach after breach hits the news, security professionals cope with the classic experiences of denial, anger, bargaining, depression, and acceptance.

When it comes to securing the enterprise, the attackers have the advantage. Defenders are required to protect against every conceivable threat while the attacker needs only a single attack vector to penetrate a network.

The universe of potential intrusion vectors is vast: faulty authentication mechanisms, gaps in the perimeter network, legacy applications, and, of course, human behavior are just a few examples. Unfortunately, enterprise security teams tend to focus on a handful of information security domains:

  • Authentication
  • Patch management and 0-day threats
  • Malware and endpoint protection
  • Network security

"Network security" has come to be synonymous with "perimeter security." Secure the perimeter, the thinking goes, and everything in the datacenter can operate in an environment of mutual trust. Combined with strong authentication mechanisms, this produces a comfortable, low-maintenance state of affairs. Securing only those systems that face the Internet is a whole lot easier than securing the thousands of servers in the datacenter.

Unfortunately the perimeter is but one attack vector of thousands. As breach after breach hits the news, security professionals have realized that securing the perimeter is not enough. And with that acknowledgment, they are now slowly proceeding through the five stages of security grief.

Denial. In this stage, you, the security pro, believe you can’t be breached. Your DMZ is locked down, your stakeholders comply with your policies, and you’ve bought an intrusion detection system (or three). Your job, then, is pretty easy: keep the firewalls up to date, scan the alerts every morning, quarantine the occasional malware infection, sleep well at night. Other organizations are getting breached. What’s wrong with their security people? They probably don’t have an IDS.

Anger. Slowly, an uncomfortable reality dawns: the average time-to-detection for an enterprise breach is somewhere around four months. New attack vectors emerge as headlines in the news. The perimeter is secure, but your contractors and business partners have access to your network, so you’re only as secure as they are. Your favorite restaurant/ department store /multinational bank gets hacked, and you spend an afternoon updating all your recurring payments with your new credit card number. Meanwhile, the number one malware delivery vector is phishing emails. Still.

Bargaining. In search of answers, you turn to the booming infosec industry. There are so many products. So many! You buy them all. The cost of a breach far outweighs your minimal savings in neglecting to buy the one product that would have prevented that breach. You switch on all the endpoint protection you can find. You log everything; your SIEM bursts with event data. You get thousands of alerts every day. After a while you stop reading them.

Depression. Another breach hits the news. One of your vendors proudly announces their product alerted on the breach, which went undetected for four months as attackers siphoned data out of the fortress. You think about the vendor, with whom you’ve spent ungodly sums. Will they detect your breach? You think about the company that got hacked. Are you better at your job than they are? Is it even possible to be good at this? Is it possible to be good at anything? You resolve to get drunk.

Acceptance. The next morning, your head is pounding. You sit down at your desk and unlock your computer. Suddenly, a thought: it’s no longer about whether you’ll get hacked, and it’s not even about when. You realize there might be attackers roaming your network right now and you wouldn’t know about it for months.

So what comes next?

The worst that can happen, you reason, is you get fired. But when the standard for breach discovery is so low, all you have to do is detect an intrusion faster than the other guy.

You study defense-in-depth. You deploy datacenter-level visibility. You monitor for DNS exfiltration, SSL exfiltration, HTTPS exfiltration. You deploy machine learning for anomaly detection. You audit your partners’ security practices and lock down the partner network. There’s no magic bullet. You ignore the alerts and start hunting for threats.

You haven’t been breached yet, but you find all sorts of problems. Adware is everywhere. Your network segments are too broad, allowing for plenty of lateral movement. Software developers are logging in to production databases using privileged credentials. Your internal firewalls are passing all sorts of traffic. Pretty much anybody can access the storage systems.

Finally, data you can use! One by one, you lock down internal attack vectors. You microsegment your applications and deploy next-generation firewalls within the datacenter. You implement two-factor authentication and continuously monitor compliance. You have three columns of Post-Its on your whiteboard: the security hygiene measures your organization needs, the ones it already has, and the ones you’re monitoring. Gradually, the Post-Its move to the right.

You keep hunting the network for threats. Another breach hits the news: the attackers lurked in the network for three years. You think about the security teams at that company. Are you better at your job than they are?

You accept it: Of course you are.

Black Hat USA returns to the fabulous Mandalay Bay in Las Vegas, Nevada, July 22-27, 2017. Click for information on the conference schedule and to register.

Related Content:

Eric Thomas serves as director of solutions architecture for IT analytics company ExtraHop. Eric leads the professional services team, and draws on over 20 years of experience in IT operations. Before joining ExtraHop, Eric performed a variety of operational roles, most ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
7/19/2017 | 3:50:18 PM
Re: Do the best you can during the countdown to inevitability
At Aon many years ago in Manhattan, a lawyer checked his wireless connects and saw one just across town - turned to the window and said " Wow - Citibank."  With no buildings inbetween, he could see it plain as day.  
EricT981
50%
50%
EricT981,
User Rank: Author
6/26/2017 | 4:04:38 PM
Re: Anger
Totally agree. The JP Morgan Chase breach should have been a wake-up call. I'm sure their security budgets are enormous and I know they employ some very talented people.
EricT981
50%
50%
EricT981,
User Rank: Author
6/26/2017 | 4:03:21 PM
Re: Reality
Thanks! Appreciate the feedback!
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:26:58 PM
Yahoo case
"which went undetected for four months as attackers siphoned data out of the fortress."

Very important. In Yahoo case it was years, unbelievable.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:25:22 PM
Anger
 

"Your favorite restaurant/ department store /multinational bank gets hacked"

This is where we get agree at our shopping store but never link it back to our own situation.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:22:48 PM
Re: Do the best you can during the countdown to inevitability
"detect / mitigate phishing"

That makes sense, it is difficult since in involves the end users behavioral change. Something hard to do.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:21:06 PM
Re: Do the best you can during the countdown to inevitability
"Career Is Soon Over"

I agree. However CISO keep telling the business that there is high risk, unfortunately they do not get enough attention.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:18:48 PM
Reality
Enjoyed reading the article. It reflects the reality on the ground. Most of us do not think we would get hit.
EricT981
50%
50%
EricT981,
User Rank: Author
6/22/2017 | 12:50:46 PM
Re: Do the best you can during the countdown to inevitability
I'd love to see the defenders get to Resolve... unfortunately, as you say, until we find a way to effectively detect / mitigate phishing it's gonna be a long road.
cybersavior
100%
0%
cybersavior,
User Rank: Strategist
6/22/2017 | 12:26:50 PM
Do the best you can during the countdown to inevitability
CISO's know.  They don't call it "Carreer Is Soon Over" for nothing.  It's the hotseat and any ignorant user that gets phished can signal that your time is up.  As you say, there are companies that have been breached and those that will be breached.  Maybe the last stage is Resolve.
1.9 Billion Data Records Exposed in First Half of 2017
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/20/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Jan, check this out! I found an unhackable PC.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.