Weekly Intelligence Summary: 2012-01-27

Dave Kennedy
January 27th, 2012

In terms of risk to Verizon Security customers, the most significant developments this week revolve around governance issues in Europe. Data protection, privacy and anti-piracy laws, regulations and agreements are in flux and regardless of the final outcomes, the changes themselves are costly. Predictably, Anonymous finds only fault with these developments, thus attacks and threats of attacks are among this week’s intel collections. The RISK Team had to dip into our reserves of skepticism in the face of reports of railway hacking in the the northwestern US. Early reports have an aroma similar to hacked water pumps.  Symantec pcAnywhere needs to be updated, but we assess calls to disrupt operations are hype. On the other hand, Trend Micro’s report of malware exploiting a vulnerability from a January Microsoft security bulletin reflects an in the wild risk. So far, that risk has very limited scope.

Considering Vulnerability Disclosure in the Realm of SCADA Systems

admin
January 24th, 2012
Every once in a while, a vulnerability disclosure incident occurs that significantly changes the game. Recently, Digital Bond released vulnerability information in conjunction with exploit code packaged in Metasploit for 6 different SCADA system devices. This time around, the stakes have been raised with much bigger consequences.
 
With consequences this high, it is worth re-evaluating the impact of vulnerability disclosure on risk in the IT environment.
 
First, a brief reminder about how risk works. Even though we can’t measure it with precision, we can do a fairly good job in understanding when it increases or decreases. We do this intuitively every day regardless.
 
Risk is a function of threats, vulnerabilities, and consequences. Threats and vulnerabilities combine to contribute to the likelihood that a breach will occur. Consequences, or impact provide the expected losses if a breach happens. We will not deal with measuring consequences since discovery/disclosure rarely impacts the level itself, so it remains constant for any scenario in this model.
 
Threat levels increases whenever the attacker costs are reduced or the benefits are increased. Attacker costs can be reduced by providing more information about specific vulnerabilities, and go lower still the more information is provided, with weaponization providing the lowest cost to entry (with the exception of actually pointing out targets). Benefits increase with larger promise of fame, fortune, etc.
 
Vulnerability levels increase when the attack surface increases – typically when new software is introduced into an environment or a configuration change is made on existing assets. It is important to note that the act of discovering or disclosing vulnerability information does nothing to increase this level unless the act of addressing the known vulnerability results in the introduction of more new ones, for example deploying a patch that has more vulnerabilities than the ones it intends to fix (possible, but unlikely).
 
The promise of managing vulnerability levels, which is the basket bugfinders have their cards in, is in attempting to reduce the level through the identification of individual vulnerabilities and the application of controls – a configuration change, modified ruleset on intrusion prevention, and most often the application of a patch.
 
In their seminal work on the patch ecosystem, Timing the Application of Security Patches for Optimal Uptime, Beattie et.al. model the patch process. They properly demonstrate that the decision to patch is more complex than the simplistic notion that all patches should be applied immediately. The real decision involves a cost-benefit analysis between the costs to patch (including effort and also potential patch failures) and the costs not to patch (risk of compromise). Given that the large majority of vulnerabilities are never acted upon by attackers in the wild, this is a challenging analysis.
 
With the preliminaries out of the way, we can evaluate the situation at hand. With Digital Bond, et.al. in conjunction with Rapid7 and their Metasploit team, releasing weaponized exploits for several vulnerabilities on several systems, they have artificially increased the threat.
 
Now, the question is whether this increase in threat can be offset by a decrease in vulnerability. Unlike with general-purpose computing, SCADA systems are often configured and left alone for significant periods of time because the operations are highly sensitive. This typically means that organizations are very reluctant to touch the systems. Accordingly, a vulnerability disclosure is highly unlikely to reduce vulnerability by enough to justify the increase in threat.
 
Perhaps more importantly, the consequences are worth discussing. SCADA systems increase the significance of vulnerability disclosure activities simply by introducing critical physical infrastructure into the consequence equation.
 
Ultimately, the release of these weaponized exploits and the corresponding vulnerability information has increased the threat and is likely to have minimal impact on vulnerability level for some time, meaning the risk is increased significantly.
 
Bugfinders do what they do for various reasons. Some are motivated by ego and pride, and even spite. It is worth identifying these people because often these emotions are given higher priority in their decisionmaking than the impact on risk. Therefore, they are willing to increase risk to society simply due to an emotional response because “the vendor was a jerk” or “the deserved it” because they were somehow slighted or ignored. All of us experience situations like these and need to work harder to overcome the spiteful response that demonstrates a lack of professional care.
 
Many researchers, truly the best and brightest technical minds in our profession, have positive intentions and believe their actions are beneficial to society. This is primarily because they are focused on vulnerabilities rather than compromises. They mistakenly believe that reducing the vulnerable state is beneficial because they fail to acknowledge that threat levels more than increase enough to overcome the slight benefit to vulnerability levels. 
 
There are a number of reasons that researchers use to justify their actions. We will ignore the petty ones for now and address the risk-oriented ones.
 
“It is better to know than not to know…”
 
The most common justification for vuln disclosure is the assumption that one needs to know about the vulnerability so it can be mitigated. While it is an attractive thought, the real problem with this idea is that nobody can know about every vulnerability. So, for example, though vulnerabilities that will be disclosed in months and possibly years in the future currently exist in an environment, they are not addressed in any way. While patching vulns often makes people feel like they are being productive, there are just too many to focus only on specific ones. This phenomena, by the way, is well known in psychology as “the certainty effect.”
“We must find the vulnerabilities before the attackers do…”
 
This justification is attractive as well, and can work in some highly constrained environments where the population of vulns is relatively small. Unfortunately the evidence for success for all software is not promising. The problem occurs because there are too many vulnerabilities – whether that be a single IT environment or the entire software universe. A conservative approach to understanding this would be to do the math on likelihood of collisions – which I can’t do, but it is similar to that done in determining the likelihood of a hash collision or to the birthday problem where 365 days is replaced with an estimate of the number of vulnerabilities in your population – that is, number of vulnerabilities that exist whether or not they have been found. The collision rate is clearly not zero, but it isn’t very high, either.
 
“It is the only way to defend ourselves…”
 
Many security pros still believe that identifying specific vulnerabilities and patching them is our best hope in protection, even if it is a hopeless cause. This simply isn’t true. We see that in the evidence – since we know that we can’t find all the vulns before the bad guys, it is inevitable that we find out in other ways – either through behavorial analysis, heuristics, or some other means. It happens a lot less than compromises of known vulnerabilities (for obvious reasons) but it still happens. This is the area where we really need to get better, since we know there are unidentified vulns in our environment currently.
 
“It reduces risk in the long run by making vendors and developers more secure programmers…”
 
This justification is often used but completely unjustified. A simple look at the total number of vulnerabilities found every year shows an increase more often than not, and when it doesn’t people are quick to point out that there are still many more vulns out there that remain undiscovered. Just comparing the amount of new code written every day to the number of vulnerabilities found in the same period is a sobering thought exercise.
 
On the other hand, people make qualitative claims of success in certain contexts and perhaps this is true. In these situations, it is worth considering alternative approaches that might provide the same benefit at lower cost. Presumably, everyone agrees that compromises would occur with or without public vuln disclosure. If this is the case, then breach evidence could provide just as effective, perhaps even more effective, justification for training developers to be more secure. Consider, for example, that perhaps the most publicized success in this area – the Trustworthy Computing initiative at Microsoft – was only initiated after Code Red and Nimda ran wild across the Internet, many thousands of disclosed vulnerabilities after the fact.
 
As a profession, and really a society, we have tolerated and even lauded bugfinding activities without any evidence that it helped. It can be exciting because many of the characters involved have colorful personalities and are clearly among the best and brightest, as mentioned earlier. Risk management is challenging to begin with, so being able to cling to specific data and resolve it makes us feel like we are demonstrating progress. SCADA consequences increase the stakes significantly – into the physical realm. It is time to consider the implications of our actions and respond accordingly.

by Pete Lindstrom

Through the years, the value proposition of vulnerability  discovery and disclosure has been batted about quite a bit in the Information Security field. Every once in a while, a vulnerability disclosure incident occurs that significantly changes the game. Recently, Digital Bond released vulnerability information in conjunction with exploit code packaged in Metasploit for 6 different SCADA system devices. This time around, the stakes have been raised with much higher consequences and the profession needs to step back and evaluate whether conditions supporting discovery and disclosure in the past still exist today. It is worth re-evaluating the impact of vulnerability disclosure on risk in the IT environment.

First, a brief reminder about how risk works. Even though we cannot measure it with precision, we can do a fairly good job in understanding when it increases or decreases. We do this intuitively every day and the basic guidelines are straightforward.

Risk is a function of threats, vulnerabilities, and consequences. Threats and vulnerabilities combine to contribute to the likelihood that a breach will occur. Consequences, or impact describe the possible losses if a breach happens. We will not deal with measuring consequences since discovery/disclosure rarely impacts the level itself, so it remains constant for any scenario in this model. Read the rest of this entry »

Weekly Intelligence Summary: 2012-01-20

Dave Kennedy
January 20th, 2012

The period of tedium in risk intelligence ended last week. An already busy week was capped when Digital Bond announced serious, but non-specific vulnerabilities in six control systems. This happened at their S4 conference under the auspices of creating a “Firesheep moment.” We could interpret that to mean some sort of wake up call to the industry, but happily (for them) it also self-serves to drive business for Digital Bond and attendance at future conferences. In conjunction with Rapid7, PLC exploit modules are being released increasing risk in the short-term for any organizations running those systems. Since these are control systems, this action impacts not just hardware, but potentially the day-to-day lives of people. Persons exhibiting a blunted affect cannot appreciate that they are affecting risk much more significantly than the incrementing vulnerability aspect of risk – unskilled and apathetic attackers will probably add these exploits to their existing attack portfolios, at much lower cost to them. Evidence of long-term benefits of actions like these is specious, given the supply of bugs seems to significantly exceed demand. Ultimately, an artificial increase in risk highlights the inherent conflicts of interest (the only clear winner here is Digital Bond). There are much better, scalable ways to get a point across – and truly reduce risk to control systems - than by jeopardizing infrastructure.

Weekly Intelligence Summary: 2012-01-13

Dave Kennedy
January 13th, 2012

Paraphrasing Lenin: the last couple weeks nothing has happened; in all likelihood, we’ll soon pay for them with a week when decades happen. The significant InfoSec risk data point this week was Microsoft Tuesday with seven bulletins and one Adobe bulletin. In the coming week, Oracle will release a CPU with 78 fixes for vulnerabilities in Oracle, PeopleSoft and Sun Solaris product lines. Wired declared Anonymous to be the net’s immune system. But an analyst is compelled to assess if Anonymous is becoming symptomatic of an autoimmune disease. This week, an entity self-identifying as Anonymous (yes, we get the contradiction) claimed responsibility for attacking IP organizationscontrol systems, a steel company, a site related to an MMORPG and Sony Pictures’ Facebook page. Attackers with affinity to Anonymous have a lengthy history of collateral damage or just plain misses.

Weekly Intelligence Summary: 2012-01-06

Dave Kennedy
January 6th, 2012

0.006 Percent. Technical media headlines exploded Thursday night after Seculert blogged that the Ramnit worm had compromised 45,000 Facebook users. But the headlines don’t read “Six one-thousandths of one percent of Facebook users infected!” One cannot make reasonable intelligence assessments while running around with one’s hair on fire upon seeing the number 45,000 in a headline. Sorry, Seculert, but our assessment is “noted.” The RISK Team regards it as a teaching opportunity. Analysts should avoid the seductive pull big numbers have. One must also assess context to arrive at risk. Readers of this blog are almost certainly (93% ±6%) using at least one risk mitigation measure that excludes them from the 45K; e.g. not being on Facebook to start with. So, in context, their risk is negligible. Noted. Move on to real risks.

Weekly Intelligence Summary: 2011-12-30

Dave Kennedy
January 4th, 2012

Microsoft issued an out-of-cycle security bulletin for four vulnerabilities in ASP.NET. Recall that large scale ASP.NET attacks took place recently (using unrelated vulnerabilities). It’s not too great a leap to give Microsoft a “trust me” and roll the bulletin out in 30 days or less.  Stratfor was compromised and the RISK Team is more concerned about the 2.7 million e-mail messages than the 860K users, 50K e-mail addresses and 68K credit cards.  The Care2 social network was also breached to the tune of 17 million users. The RISK Team extends to our colleagues wishes for a happy and prosperous New Year and for our adversaries to mend their wicked ways in 2012.

Announcing 2012 DBIR Participants

Wade Baker
December 27th, 2011

Ah, the week between Christmas and New Year’s Day: lots of folks out enjoying “use or lose” vacation time, the pace of work a bit slower than normal, significantly fewer emails and other distractions demanding attention. A great time to reflect on the old, anticipate the new, and cross off some long-standing items from the to-do list.

Given the nature of the season, it’s also appropriate to ponder the topic of sharing. Sure, there’s the sharing of time, fellowship, gifts, and food with which we’ve all been involved recently, but as the year draws to a close, many of us on the RISK Team are also thinking about sharing of a different nature – incident sharing.

It’s doubtful that security incidents made the top of anyone’s wish list this year (or any other), but the knowledge gained through studying them and sharing lessons learned is often considered to be a gift worth keeping. Many of you will remember that our effort to study and share incident information with the world is done through the annual Data Breach Investigations Reports (DBIR). Though the publication is still a few months away, we’re very glad to give a foretaste of what our readers can expect early next year.

We’ve continued our efforts to expand the scope and perspective of the DBIR, and the 2012 version should be the biggest ever in many respects. One of the things we’re particularly excited about is that we will have participants representing the Americas, EMEA, and APAC regions. Submitting data and analysis for the 2012 DBIR are:

  • The U.S. Secret Service
  • The Dutch High Tech Crime Unit
  • The Australian Federal Police
  • The Irish Reporting and Information Service
  • The London Metropolitan Police
We’d like to applaud and thank these organizations for their willingness to contribute to the 2012 DBIR and, more importantly, to increasing the collective knowledge of the security community. As we head into our annual DBIR production cycle, we’d like to wish you a happy and secure 2012.

Weekly Intelligence Summary: 2011-12-16

Dave Kennedy
December 19th, 2011

Adobe released updates for Adobe Acrobat and Reader version 9 for a vulnerability reported last week which was being used for targeted attacks. Enterprises that have not migrated to Adobe Reader X should test and deploy this patch within 30 days.  More reports of exploits for a Java vulnerability patched by Oracle in October are showing up in crimeware.  Video game company Square Enix (Final Fantasy, Kingdom Hearts) was the victim of another data breach and as many as 1.8 million accounts were compromised.  Compromised account data included personal registration information but the site didn’t accept credit cards. They reported an earlier compromise in May. Symantec reported the Nitro attackers were still active and were spoofing Symantec to try to trick users to install Trojans.  Microsoft released a lucky thirteen security bulletins, but also called our attention to general improvement across their products.

Weekly Intelligence Summary: 2011-12-09

Dave Kennedy
December 9th, 2011

Adobe announced a previously unreported vulnerability in Adobe Reader and Acrobat, and acknowledged Lockheed Martin and the Defense Security Information Exchange for reporting it. Mila Parkour and Symantec have additional details on targeted attacks exploiting the vulnerability. Defensive systems from AV to IDS have been updated this week to improve detection of related attacks. Your attention is invited to a post by Branden Williams on RSA’s blog and their “Security Practices Critical Checklist;” it is almost certainly the most widely useful risk intelligence collection for this week. To some it may seem like “mom and apple pie,” but if one considers the source — RSA’s experience on their own network and their perspective including their customers – it might be unwise to dismiss it.  Another example of experience and perspective contributing to the credibility of an intelligence collection, RISK Team alumnus Alex Hutton made some pointed observations on risk management on the New School security blog. Microsoft pre-announced fourteen bulletins for Tuesday and if that isn’t sobering enough, read Paul Ducklin’s report on malware on thumb drives. Picking up a lost thumb drive is the antithesis of a “lucky penny.”

Weekly Intelligence Summary: 2011-12-02

Dave Kennedy
December 2nd, 2011

From the same source that informed us that Sergey Brin and Steve Ballmer cooked up a “new and frightening Stuxnet” on Larry Ellison’s barbecue, we now hear about West Milford New Jersey’s  “water plant victim of ‘Terrorism.’”  After the “comedy of errors” at an Illinois water plant, stirred up by Joe Weiss, we had expectations that the irrational hyperbole might be tempered; apparently not. Last month, we learned of targeted attacks on energy and defense companies as well as SCADA systems in Norway. This week, we learned of attacks on Canadian companies related to chemicals and mining.  Kaspersky continues to analyze and share details on Duqu. A year ago we were led to believe Zeus was on the way out but new reports from Brian Krebs and Symantec make it clear it’s a continuing threat.  The most interesting InfoSec intel collection this week was Edward Jay Epstein’s unconfirmed account of Dominique Strauss-Kahn’s day on 2011-05-14. Think InfoSec by Ian Fleming.  It remains to be seen if it will be in the library’s non-fiction section or in fiction next to Brin, Balmer and Ellison’s virus and Weiss’ water pump, but it initially appears to be more interesting to follow.

Weekly Intelligence Summary: 2011-11-25

Dave Kennedy
November 28th, 2011

In the Republic of Korea, Nexon reported a massive data breach affecting as many as 13 million users in the MMORPG MapleStory. The Department of Homeland Security sent a go-team to Springfield, Illinois and determined every significant piece of last week’s report of SCADA hacking was baseless. It remains to be seen if the lemmings that leaped last week to conclude TEOTWAWKI was at hand have learned anything; their leader apparently has not. And finding an objective assessment of Android security lately is simply impossible. Google, unsurprisingly, says, “no problem.”  Juniper, Websense, and Bit9, who all sell something in this space, seem to have other views. The RISK Team does observe developing for Android Market is easier than being accepted by Apple for iOS/iTunes and Apple appears to have more rigorous standards and testing for apps before they’re in iTunes thanGoogle has for Android Market apps. However, intelligence analysis is too clouded by the hype to categorically exalt or damn either.

Weekly Intelligence Summary: 2011-11-18

Dave Kennedy
November 19th, 2011

Wednesday, technical media in the US were busy exercising their jumping to conclusions skills over a bug in Bind DNS software.  Open source intelligence collections reflect about two dozen DNS servers experienced outages due to the bug; no one has reported any malicious traffic. The first lemming stampede was on when every hiccup on the Internet was blamed on: “someone DoSed my Bind server!”  Action: don’t panic. As infrastructure, DNS servers should already be part of patch management systems. Patching Bind servers with “routine” priority is appropriate in the complete absence of threat reports. Thursday, unconfirmed reports of a hacking attack on a water plant in Springfield, Illinois became a media storm. DHS declared, “there is no credible corroborated data,” but the second lemming stampede is on.  Action: do nothing until credible corroborated intel arrives.  The reports might be true, but so far they certainly fail to meet any reasonable criterion for actionable. If only a portion of the lemmings’ energy reported more details on broad attacks on companies in Norway. Or reported on what happened at Valve to Steam users PII?

Quick response to “Thoughts on the 2011 DBIR and APT”

Wade Baker
November 17th, 2011
Over on the New School Security blog [link], Adam Shostack recently wrote
an interesting piece [link] on APTŠbut not the kind you¹re thinking of. He
was referring to ³Authorization Preservation Threats,² and his subject
matter was the 2011 DBIR [link]. The post centered on the plethora of
incidents stemming from exploits/failures related to authentication and
authorization we observed in among the 761 incidents we analyzed this past
year.
In the post, he mentions that he’d like to know the overlap between brute
force attacks and default credentials. Happy to oblige, Adam.
Brute force only: 40 incidents
Default creds only: 97 incidents
Both: 160 incidents
Obviously, there are a lot of incidents that involve both types of
attacks. As Adam writes in his blog “I don¹t want to attack anyone¹s
business here, but if you¹re looking at any super-fancy technology before
you¹ve rolled out AD password policies and also mastered changing your
passwords on the non-AD stuff, you¹re ignoring the Authorization
Preservation Threat.”
That’s pretty good advice if you ask me.

Over on the New School Security blog, Adam Shostack recently wrote an interesting piece on APTs but not the kind you’re thinking of. He was referring to “Authorization Preservation Threats,” and his subject matter was the 2011 DBIR. The post centered on the plethora of incidents stemming from exploits/failures related to authentication and authorization we observed in among the 761 incidents we analyzed this past year.

In the post, he mentions that he’d like to know the overlap between brute force attacks and default credentials. Happy to oblige, Adam.

  • Brute force only: 40 incidents
  • Default creds only: 97 incidents
  • Both: 160 incidents

Obviously, there are a lot of incidents that involve one or both types of attacks. As Adam writes in his blog “I don’t want to attack anyone¹s business here, but if you’re looking at any super-fancy technology before you’ve rolled out AD password policies and also mastered changing your passwords on the non-AD stuff, you’re ignoring the Authorization Preservation Threat.

That’s pretty good advice if you ask me.

Weekly Intelligence Summary: 2011-11-11

Dave Hylender
November 11th, 2011

More than a dozen organizations collaborated to bring about Operation Ghost Click: six arrests and four million bots no longer under criminal control.  Gary Warner at the University of Alabama Birmingham’s posted a very good one-stop summary and he links to other reliable and detailed reports. Cynics may label it Whack-a-mole, but every arrest cements society’s mores and our refusal to accept cyber crime and dispossession of systems by sociopaths.   There’s a full moon and another Adobe Flash and Google Chrome update. Coincidence? We might know in 28 days.  Did Mitsubishi Heavy Industries take data breach management lessons from Sony? Their story get’s worse at every turn; this week’s revelation was nuke plant designs leaked.  And November’s Microsoft Tuesday was this week; Verizon Cybertrust Security customers have the RISK Team’s unflustered recommendations to avoid upsetting plans for the holidays.

Weekly Intelligence Summary: 2011-11-04

Dave Kennedy
November 4th, 2011

We may be entering another bi-polar phase in InfoSec intelligence.  We’ve cycled from last week’s abundance of lame collections to this week’s abundance of useful, but generally not actionable, risk intelligence reports.  Symantec released a report on “Nitro” targeted attacks from China on at least 48 chemical and defense companies in the US, Bangladesh and the UK. Symantec also revised their Duqu report after the Laboratory of Cryptography and System Security in Hungary reported a surprise attack vulnerability via a MS Word file dropped Duqu in a targeted attack. Microsoft issued a related Security Advisory and a “Fix-it” tool. The RISK Team recommends only the most risk-adverse organizations act on it because the threat rate is so low.  Microsoft pre-announced four security bulletins for next week and the Duqu-related vulnerability will probably not be among them. The US government’s National Counterintelligence Executive issued a report that removes doubt as to the countries conducting cyber-espionage against Google and companies in the US energy sector. The US Intelligence Community reported the People’s Republic of China was responsible—31 pages and none of it actionable. Finally, some actionable intel: Qualys provided concise risk mitigation tips to reduce the effectiveness of slow HTTP DoS attacks.  Cheers to them!