Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Slow And Silent Targeted Attacks On The Rise

Targeted, methodical attacks difficult to detect

Jan 08, 2009 | 03:29 PM

By Kelly Jackson Higgins
DarkReading

The most determined cybercriminals don't necessarily work fast when they breach a network, and their infiltration is often silent and undetectable. But it's this brand of "low and slow" targeted attack that can also be the most deadly, security experts say.

This is a methodical attack, where the attacker covers his tracks as he penetrates the network, sometimes ceasing the attack for days at a time to avoid raising suspicion. It's typically a nearly invisible hack that isn't discovered until it's too late, after the bad guys have made off with valuable data and done serious damage. Security experts say IT and security managers need to be at the ready for these highly targeted attacks, which may be more common than once thought.

"It used to be a 'smash and grab,' where criminals would see what they could get," says Mike Rothman, senior vice president of strategy at eIQnetworks. "Now the criminals we're seeing are a lot more savvy than that and are using time to their advantage. They're not leaving broken windows, broken couches...If they start shuffling through one drawer, they are careful to put everything back."

No one knows for sure just how widespread these attacks are today, but some basic characteristics are present as to how they are executed. The attacker typically initially gains access through a Web application vulnerability, or via a successful spear-phishing attack on an employee. After he gets inside, he may wait a few days or so after this first stage of the attack.

"The path of least resistance is still through the application. Once there, they can compromise" the system, Rothman says. "And then they can turn off logging" to evade detection, he says.

Instead of brute-force attacking a Web server or database with malformed URL requests that could easily be detected, the attacker may send only one or two a week, for example. Once inside, the attacker can create his own account, install Trojans or other malware to steal sensitive data, or do other nefarious things. But he takes each step slowly and quietly, rather than in one fell swoop.

Some recent high-profile attacks were staged similarly, in methodical, multiple steps -- aimed at the attacker gaining a foothold in the network without raising suspicion or sounding any network alarms.

Take the TJX hack. "The TJX incident is a good example of a multistage, low, and slow attack," says Amit Klein, CTO of Trusteer. "The attackers first compromised the wireless LAN, which was poorly encrypted, then eavesdropped on TJX employee logins to collect credentials, then logged in to the main system and created their own accounts, and then tapped into the TJX transactions/databases."

The first clue that TJX's breach wasn't a smash-and-grab job were configuration changes on some of its servers. "Someone compromised it and had been in there for years before people realized it," eIQnetworks' Rothman says.

Rothman says his firm is hearing a lot of stories "from the field" about organizations discovering that they've been victims of these longer-term, stealthy attacks. "We are starting to see these data points add up," he says.

The first phase of the CheckFree hack had the earmarks of a "low and slow" spear-phishing attack on one of its systems administrators, according to Trusteer's Klein. Attackers reportedly stole the credentials of one of CheckFree's system administrators in order to redirect traffic from the MyCheckFree page to their own malicious one. But the subsequent stages of the attack weren't so stealthy, and the bad page was discovered quickly due to the fact that the bad guys didn't bother to mimic the MyCheckFree Web page when they redirected victims to their phony site.

"They weren't very subtle about [the malicious Web page]. It could have been more [powerful] if it had been presented as identical with the CheckFree page," notes Trusteer's Klein. Still, the attackers successfully compromised CheckFree customers.

"The multistage attack compromises the network and finally compromises the customers of the [targeted organization]. And doing so requires not being detected in the first steps of the attack" as the CheckFree attackers successfully did, Klein says.

The next level of these attacks is actually modifying the victim's application to monetize it in some way, notes John Pescatore, vice president and research fellow at Gartner. "So far, it's all been cybercrime for obtaining information and reselling it for identity theft, versus breaking into Amazon.com and adding a dollar to each transaction that's billed and gets sent to [the attacker]," he says. "These kinds of things are where the attacker really becomes a long-time resident and modifies an application. We haven't seen that yet."

Defending against these types of attacks isn't easy -- you can't fight what you can't see. Correlating events requires keeping longer-term logs and data than most organizations typically do. Whitelisting can help flag unauthorized or unusual application activity, experts say, and securing user credentials can protect you from the dangers of spear-phishing attacks.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)