Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
For Real Security, Don't Let Failure Be Your Measure of Success
Oldest First  |  Newest First  |  Threaded View
tdsan
tdsan,
User Rank: Ninja
7/19/2019 | 7:53:18 PM
Excellent point about obtaining visibility
  1. What are the most common successful attack vectors for my type of company and environment?
    • Email, Web, RDP and SSH
  2. How likely would we be to detect such an attack should it occur?
    • Extremely likely, we review logs everyday on external systems, we have SIEM, HIDS, NIDS monitoring essential and non-essential systems, notifications are sent and collected using Logwatch | crontab provides extensive information
  3. Can we make this type of attack harder and more expensive for the hacker?
    • Yes, using Web (NGFW, place in DMZ) and Email (Proofpoint)
    • RDP - use hardening mechanisms provided by DISA Stigs, only allow local subnets
    • SSH - use keys, remove root access, only allow certain ranges of IP to access systems
    • IPv6 - implement IPv6 and move off of IPv4 (most attacks come from IPv4, we have identified that on our AWS and GCP servers), configure VPN ESP/AH AES256 IPSec tunnels
    • Utilize cloud service to monitor servers and access
    • Countries that are not relevant to the business remove access, insert rules to block countries (PaloAlto, SonicWall, Juniper, and others do a good job), but also employ the blocking mechanism on outbound ACLs
    • Encrypt data at rest and in transit, utilize IPSec from IPv6
    • Configure MPLS VPN rd1:1 connections to remote sites, think about IS-IS configuration for remote connections, think about Route Bridges and TRILL, move away from OSPF (no self-healing properties)

This is what I can think about off the top of my head, other items will come.

Todd


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Developing and Testing an Effective Breach Response Plan
Whether or not a data breach is a disaster for the organization depends on the security team's response and that is based on how the team developed a breach response plan beforehand and if it was thoroughly tested. Inside this report, experts share how to: -understand the technical environment, -determine what types of incidents would trigger the plan, -know which stakeholders need to be notified and how to do so, -develop steps to contain the breach, collect evidence, and initiate recovery.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-43668
PUBLISHED: 2022-12-07
Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the file when opening a file with the affected product.
CVE-2022-44606
PUBLISHED: 2022-12-07
OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
CVE-2022-44608
PUBLISHED: 2022-12-07
Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition.
CVE-2022-44620
PUBLISHED: 2022-12-07
Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
CVE-2022-45113
PUBLISHED: 2022-12-07
Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafted URL may allow a remote unauthenticated attacker to set a specially crafted URL to the Reset Password page and conduct a phishing attack. Affected products/ver...