
Ten Themes from Recent Conferences, Black Hat DC 2008 Wrap-Up and Thoughts from Several Conferences.
His ten themes describing the state of affairs:
- Permanent compromise is the norm, so accept it.
- We can not stop intruders, only raise their costs.
- Anyone of sufficient size and asset value is being targeted.
- Less Enterprise Protection, more Enterprise Defense.
- Less Prevention, more Detection, Response, Disruption.
- Less Vulnerability Management, more System Integrity Analysis.
- Less Totality, more Sampling.
- Less Blacklisting, more Whitelisting.
- Use Infrequency/Rarity to our advantage.
- Use Blue and Red Teams to measure and validate.
- Team Cymru's Internet Malicious Activity Map. (per Class A subnet)
- Oliver Friedrichs from Symantec will release his upcoming book Crimeware, some of which is described in this post.
- Nitesh's statement in Social Engineering Social Networking Services: A LinkedIn Example
- Sinan Eren from Immunity described how his team conducts "information operations:
- Attack the anti-virus/spam filter on the target company's mail transfer agent.
- Hook the AV to grab copies of all email. (Feeling good about that AV scanner now? Hey, it's defense in depth! Add more, you're secure! Not only does it not work 2/3 of the time, it's an avenue to be compromised! Argh.)
- Analyze email to understand the target.
- Inject forged email into ongoing thread between target and customer. Include malicious attachment.
- From target's computer, exploit DNS MSRPC vulnerability in target's PDC.
- Grab hashes, exploit other hosts. Find files of interest.
- Identify special network segmented from current network but accessed via USB drive.
- Modify USBDumper to acquire files when drive is moved from first network to special network.
- All interesting data transferred via Immunity's "PINK" C&C channel.
- Sinan concluded by recommending we invest in human capital, not security products
- Why we bother blocking anything but specific IPs outbound. All we've done by restricting outbound protocols is force everything to be SSL-encrypted HTTPS traffic
Okay, using AV to own the gateway, using social media as intelligence, using outbound ssl as covert channel, the need for user awareness, some of these sound familiar. ;-)
And don't forget to have a look at Richard's blog from time to time!! ;-)
Security4all Blog
Twitter
Slideshare
Facebook
Digg
Flickr



0 comments:
Post a Comment