Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/9/2015
10:30 AM
Connect Directly
Facebook
Twitter
LinkedIn
RSS
E-Mail vvv
0%
100%

Solving the Right Problem: Stop Adversaries, Not Just Their Tools

A malware-centric strategy is mere child's play against today's sophisticated adversaries. Here's why.

Most organizations today focus on protecting their networks against malware, exploits, malicious websites, and unpatched vulnerabilities. Unfortunately, there is a fundamental flaw with this approach: a malware-centric defense approach will leave you vulnerable to attacks that don’t leverage malware.

In fact, malware is responsible for only 40 percent of breaches and external attackers are increasingly leveraging malware-free intrusion approaches in order to blend in and fly under the radar by assuming insider credentials within victim organizations. The nature of the game now is persistence and gaining long-term access to the enterprise. The chances of ultimate discovery and effective remediation diminish greatly when no external binaries are brought into the environment and no unusual outbound C2 traffic is taking place.

Let me illustrate that with a real-world example.

A few months ago, CrowdStrike Services was hired by a large defense contractor that had been struggling for months to remediate an intrusion from a sophisticated Chinese-affiliated actor. The adversary kept coming back and the client could not identify the point of entry, despite having numerous host and network forensics, whitelisting, as well as Indicator of Compromise (IOC)-scanning malware detection tools.

They brought us in with the explicit mission of identifying the C2 channels the adversary was using to get back inside the environment. In the end, it turned out that the question they were posing -- identification of the C2 servers -- was the wrong one. Once the services team deployed our next-generation endpoint technology across their servers and desktops to profile and identify all adversary activity, we determined that the adversary had compromised their two-factor authentication system, stolen the seed values and was coming in with through the VPN system using legitimate credentials and generated two-factor token values. There were no C2 server IOCs to locate and once the adversary was inside the network, they were able to move around using legitimate credentials and windows system administration tools, without actual use of malware.

This critical gap between current enterprise defense strategy and the evolution in adversary tactics is responsible for a growing number of successful intrusions, as well as the fact that a typical breach remains undiscovered for over 200 days. In response, organizations now need to adapt their strategy and augment their malware-detection and IOC scanning tools with solutions that can hunt for, identify and stop adversary activity even when no malware is present.

This new approach also requires a move from an indicators of compromise to an indicators of attack (IOA) detection strategy. An IOA-based detection system can look for adversary intentions and effects, such as whether they are stealing credentials, moving laterally, executing processes and maintaining persistence, as opposed to only trying to locate known indicators of malware. This is no longer a promising emerging approach but a necessary and critical building block for effective cyber defense.

[Learn more about what motivates hackers from Dmitri during his conference session, Understanding Your Attackers, on Wednesday, April 29, at Interop Las Vegas.]

Dmitri Alperovitch is the Co-Founder and CTO of CrowdStrike Inc., leading its intelligence, research and engineering teams. A renowned computer security researcher, he is a thought-leader on cybersecurity policies and state tradecraft. Prior to founding CrowdStrike, Dmitri ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
4 Security Tips as the July 15 Tax-Day Extension Draws Near
Shane Buckley, President & Chief Operating Officer, Gigamon,  7/10/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15105
PUBLISHED: 2020-07-10
Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two-factor authenticati...
CVE-2020-11061
PUBLISHED: 2020-07-10
In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job. Disabling verify jobs mitigates the problem. This issue is also patched in...
CVE-2020-4042
PUBLISHED: 2020-07-10
Bareos before version 19.2.8 and earlier allows a malicious client to communicate with the director without knowledge of the shared secret if the director allows client initiated connection and connects to the client itself. The malicious client can replay the Bareos director's cram-md5 challenge to...
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...