Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/9/2015
10:30 AM
Connect Directly
Facebook
Twitter
LinkedIn
RSS
E-Mail vvv
0%
100%

Solving the Right Problem: Stop Adversaries, Not Just Their Tools

A malware-centric strategy is mere child's play against today's sophisticated adversaries. Here's why.

Most organizations today focus on protecting their networks against malware, exploits, malicious websites, and unpatched vulnerabilities. Unfortunately, there is a fundamental flaw with this approach: a malware-centric defense approach will leave you vulnerable to attacks that don’t leverage malware.

In fact, malware is responsible for only 40 percent of breaches and external attackers are increasingly leveraging malware-free intrusion approaches in order to blend in and fly under the radar by assuming insider credentials within victim organizations. The nature of the game now is persistence and gaining long-term access to the enterprise. The chances of ultimate discovery and effective remediation diminish greatly when no external binaries are brought into the environment and no unusual outbound C2 traffic is taking place.

Let me illustrate that with a real-world example.

A few months ago, CrowdStrike Services was hired by a large defense contractor that had been struggling for months to remediate an intrusion from a sophisticated Chinese-affiliated actor. The adversary kept coming back and the client could not identify the point of entry, despite having numerous host and network forensics, whitelisting, as well as Indicator of Compromise (IOC)-scanning malware detection tools.

They brought us in with the explicit mission of identifying the C2 channels the adversary was using to get back inside the environment. In the end, it turned out that the question they were posing -- identification of the C2 servers -- was the wrong one. Once the services team deployed our next-generation endpoint technology across their servers and desktops to profile and identify all adversary activity, we determined that the adversary had compromised their two-factor authentication system, stolen the seed values and was coming in with through the VPN system using legitimate credentials and generated two-factor token values. There were no C2 server IOCs to locate and once the adversary was inside the network, they were able to move around using legitimate credentials and windows system administration tools, without actual use of malware.

This critical gap between current enterprise defense strategy and the evolution in adversary tactics is responsible for a growing number of successful intrusions, as well as the fact that a typical breach remains undiscovered for over 200 days. In response, organizations now need to adapt their strategy and augment their malware-detection and IOC scanning tools with solutions that can hunt for, identify and stop adversary activity even when no malware is present.

This new approach also requires a move from an indicators of compromise to an indicators of attack (IOA) detection strategy. An IOA-based detection system can look for adversary intentions and effects, such as whether they are stealing credentials, moving laterally, executing processes and maintaining persistence, as opposed to only trying to locate known indicators of malware. This is no longer a promising emerging approach but a necessary and critical building block for effective cyber defense.

[Learn more about what motivates hackers from Dmitri during his conference session, Understanding Your Attackers, on Wednesday, April 29, at Interop Las Vegas.]

Dmitri Alperovitch is the Co-Founder and CTO of CrowdStrike Inc., leading its intelligence, research and engineering teams. A renowned computer security researcher, he is a thought-leader on cybersecurity policies and state tradecraft. Prior to founding CrowdStrike, Dmitri ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19642
PUBLISHED: 2019-12-08
On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareNa...
CVE-2019-19637
PUBLISHED: 2019-12-08
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
CVE-2019-19638
PUBLISHED: 2019-12-08
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
CVE-2019-19635
PUBLISHED: 2019-12-08
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
CVE-2019-19636
PUBLISHED: 2019-12-08
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.