Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/15/2015
11:00 AM
Danelle Au
Danelle Au
Commentary
Connect Directly
Facebook
Twitter
LinkedIn
RSS
E-Mail vvv
50%
50%

To Better Defend Yourself, Think Like A Hacker

As attacks become more sophisticated and attackers more determined, organizations need to adopt an offensive approach to security that gets inside the head of the hacker.

One of the seminal movies that all cybersecurity professionals should watch is of course War Games. It features a young hacker, played by Matthew Broderick, who almost starts a nuclear war when he starts playing war games with a central military computer.

While the premise itself seems improbable, the concept of playing war games isn’t new. The many arms of government do it. Large corporations do it. This concept has also made its way into the cybersecurity world—cyber war games to test one’s security infrastructure. In a red team and blue team engagement, the red team attacks and the blue team defends to validate readiness. In the cybersecurity world, war games can range from table top exercises to actual live exercises where attack scenarios are simulated. 

To date, most of the cyber war exercises have been deployed by governments to test both public and private sector infrastructures, or large corporations with the time and resources to support them. But as attacks become more sophisticated and automated, and attackers more greedy, the need for all organizations to at some level understand and experience the mind and method of hackers is becoming more urgent.

The mindset of an attacker

The fundamental premise behind this is simple. To better defend yourself, you need to put yourself in the mindset of an attacker. It’s about learning from the hackers and understanding their behavior -- and understanding how your own actions (or inaction) affects the outcome. Most importantly, it is about proactively executing real breach scenarios on your network to find holes before an attacker does, and understanding what vulnerabilities are most pressing for you.

This mindset makes sense. After all, we spend more than $70B in cybersecurity, yet we continue to be breached. The latest Mandiant report states that organizations take almost 205 days to discover breaches in their network -- only a marginal improvement from the year before. No surprise, the latest PWC Global State of Information Security report shows that we’re seeing more security incidents in 2015 than last year: 38% more security incidents were detected in 2015 than 2014 and the theft of “hard” intellectual property increased 56%.

It doesn’t feel like we’re winning, does it? One reason is the current reactive approach to cybersecurity – if and when a new threat is exposed, a new security solution is deployed. Each of these point products requires a unique management system and configurations that needs to be optimized. Complexity impacts security.

The biggest challenge for CISOs today is not waiting for a vendor to offer a solution to their problem; it’s prioritizing their efforts (amidst a talent shortage), understanding which of their security systems are working as expected, and knowing what their cybersecurity risks are at any one point in time. How does a CISO answer the board-level question of “Are we secure”? The answer is combining current approaches with an offensive security approach that adopts the mindset of the hacker.

But first, there are specific characteristics of the hacker that we need to understand:

  • Persistence and patience. We know hackers are persistent and relentless. They spend time getting to know the organizational structure and the network; they will actively investigate the best way to infiltrate an organization. Whether they are motivated by money or another cause, they’ve evolved from the equivalent of the cyber purse-snatcher to the great cyber heist. 
  • Breach methods. Malware today has become much more sophisticated, it can exhibit specific behaviors based on user activity, and is sophisticated enough to lie latent when necessary to bypass security solutions. Yet, what we find are the majority of breach methods are limited, and are being replicated across organizations. According to the Verizon Data Breach Investigations Report, 92% of cyber attacks in the past 10 years can be linked to just nine basic attack patterns. Of these, most companies have to face only between two and four.
  • Asset- and objective-oriented. Every action performed by an attacker may look like a singular incident, but is actually a phased progression toward their objective. Hackers will adjust their methods based on success and failures; they also tend to reuse tools and infrastructure. The ability to look at the entire cohesive view of what an adversary is doing (the complete attack kill chain), and their techniques is critical to not only to detect today’s attack but understand their modus operandi for future attacks. 

Cyber war games of the future

When we look at these characteristics, it’s clear we need automation to more effectively (and continuously) execute war games -- with an emphasis on the word “war.” So many security strategies and solutions today are focused on individual battles. You can win some, but not all, and in cybersecurity, one loss can cost you the war.

At the same time, breach methods must be supported by a human element that understands and can analyze patterns, tactics, and procedures. In a kill chain model, breaking one step thwarts the adversary; proper analysis and understanding of how attackers are behaving and their techniques can only be performed by skilled security professionals.

In other words, the cyberwar games of the future will be played by machines powered by humans.  It is the combination of human plus platform/machine that will tip the advantage towards the defenders. Just like Amazon’s Chaos Monkeys in the cloud world where failures occur to force systems to be more resilient, we need to proactively execute breaches in our environment to find holes -- before an attacker does. 

Danelle is vice president of strategy at SafeBreach. She has more than 15 years of experience bringing new technologies to market. Prior to SafeBreach, Danelle led strategy and marketing at Adallom, a cloud security company acquired by Microsoft. She was also responsible for ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jeromeo1969
100%
0%
jeromeo1969,
User Rank: Apprentice
2/9/2017 | 2:15:52 PM
Excellent!
The days of being reactive are over! In addition to thinking like a hacker, Red Teams should be testing environments on a near constant basis. As we know environments change, and a once secure environment is only one mis-configuration away from being breached. New vulnerabilities are discovered all the time, and if you wait six months between penetration tests the bad guys will find your vulnerabilities before you do. An endless cycle of training and testing are the only way to stay secure!
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Jim, stop pretending you're drowning in tickets."
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3571
PUBLISHED: 2019-07-16
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
CVE-2019-6160
PUBLISHED: 2019-07-16
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
CVE-2019-9700
PUBLISHED: 2019-07-16
Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the source of network traffic.
CVE-2019-12990
PUBLISHED: 2019-07-16
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
CVE-2019-12991
PUBLISHED: 2019-07-16
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).