Tuesday, June 14, 2011

APT - Advanced Persistent Threat - What is it?

APT - Advanced Persistent Threat - What is it?

The term was actually coined by the US Air Force in 2006 as a way to communicate with counterparts in the unclassified public world. If the USAF wanted to talk about a certain intrusion or attack with uncleared personnel, they could not use the classified threat name, so they choose APT as a common moniker that could apply to all such situations.

What is important when referring to an APT is that is references a specific threat from specific sources. It is not meant as a catchall description for some vague or unknown cyber-attack.

Heretofore, APT was most frequently applied to specific groups operating in the Asia-Pacific region, but there is considerable discussion as to whether adversaries in Eastern Europe operating using the same tools, tactics, and procedures as traditional APT, should also have the APT label.

In the commercial sector, an IT security professional usually does not make the distinction or really care where the threat is originating from, rather that he or she will take the same defensive actions regardless of the source or nationality of the adversary.

APT entered the common lexicon in early 2010 when Google announced its intellectual property had been the victim of a targeted attack originating from China. Although Google was far from the only victim, the company’s visibility and its high profile public disclosure put a new face on these types of attacks and the lengths attackers would go to gain access to proprietary corporate and military information.

Insofar as a definition, APT means:

Advanced means the adversary can operate in the full spectrum of computer intrusion. They can use the most pedestrian publicly available exploit against a well-known vulnerability, or they can elevate their game to research new vulnerabilities and develop custom exploits, depending on the target’s posture.

Persistent means the adversary is formally tasked to accomplish a mission. They are not opportunistic intruders. Like an intelligence unit, they receive directives and work to satisfy their masters. Persistent does not necessarily mean they need to constantly execute malicious code on victim computers. Rather, they maintain the level of interaction needed to execute their objectives.

Threat means the adversary is not a piece of mindless code. The opposition is a threat because it is organized, funded and motivated. Some people speak of multiple “groups” consisting of dedicated “crews” with various missions.

In brief, APT is an adversary who conducts offensive digital operations (called computer network operations or perhaps computer network exploitation) to support various state-related objectives.

APT is characterized by devotion to maintaining some degree of control of a target’s computer infrastructure, acting persistently to preserve or regain control and access. Unclassified briefings by counter-intelligence and military analysts use the term “aggressive” to emphasize the degree to which APT pursues these objectives against a variety of government, military, and private targets.

IS APT NEW?

When the Google attack entered the public arena, many people wondered if APT was something new. The answer to this question depends on one’s perspective, plus understanding some history. As mentioned earlier, the term APT is approximately 4 years old.

Richard Bejtlich, founder of TaoSecurity and director of incident response for General Electric describes APT activity in terms of offender, defender, means, motive, and opportunity.

He breaks APT targets into four phases:

1) late 1990s — military victims;

2) 2000-2004 — non-military government victims;

3) 2005-2009 — defense industrial base;

4) 2009-present — intellectual property-rich targets and software companies.

He points out that analysts currently assess APT activities as supporting four main goals.

· Political objectives such as maintaining internal stability.

· Economic objectives that rely on stealing intellectual property from victims. Such IP can be cloned and sold, studied and underbid in competitive dealings, or fused with local research to produce new products and services more cheaply than the victims.

· Technical objectives that further their ability to accomplish their mission. These include gaining access to source code for further exploit development, or learning how defenses work in order to better evade or disrupt them. Most worryingly is the thought that intruders could make changes to improve their position and weaken the victim.

· Military objectives that include identifying weaknesses that allow inferior military forces to defeat superior military forces.

WHAT SHOULD DEFENDERS DO TO COUNTER APT?

The most effective counter-APT weapon is a trained and knowledgeable information security analyst. Tools are always helpful, but the best advice is to educate business leaders about the threat so that they support organizational security programs conducted by competent and informed staff.

On a technical level, building visibility in to one’s organization will provide the situational awareness to have a chance to discover and hopefully frustrate APT activities.

Monday, June 13, 2011

The Disconnect Between Security & The Business

Saw an interesting item this morning and decided to re-tweet it as well as include it in my blog. (http://jadedsecurity.net/2011/06/07/the-disconnect-between-security-the-business/) Yes, there is a disconnect between security and “the business” and I believe it is the primary driver for so many successful exploitations. What many businesses don’t yet fully grasp is that security is a business mandate, not an IT function. Security needs to be driven from the top down and not delegated to the “guys down in IT”. As the article says, “The new buzzword of the times is GRC (Governance, Risk, Compliance)…..”. Certainly, IT has an important role, but IT is not the driver. Governance, risk and compliance starts at the top. If businesses really want to reduce information security risk they need to have processes and procedures in place that are driven by governance mandates where risk is assessed and ultimately mitigated by compliance with the processes and procedures. It’s not inexpensive, but it is surely less expensive that a breach and all the associated costs.

Friday, June 10, 2011

The Old 80 - 20 Rule

Attended ISSA-Baltimore chapter's second InfoSec Summit yesterday in Laurel Md. The keynote speaker was Dr. Ron Ross Ron Ross, computer scientist at National Institute of Standards and Technology (NIST). He had an interesting observation that 80 percent of cyber intrusions and exploits can be prevented by "best practices". Best practices might be defined differently depending on who you ask, but at the end of the day it’s the simple stuff - firewalls, good authentication, adherence to processes and policies, patch management, training, etc. Would your business pass the 80 – 20 test? In my experience most don’t, but I can show you how.

Tuesday, February 16, 2010

Chip and PIN: The technology is no

longer secure

Date: February 16th, 2010

Author: Michael Kassner



Chip and PIN transaction systems were thought to be secure. The only way to bypass the technology required a stolen card and knowing the PIN. That is no longer the case.


I first learned about Chip and PIN Security when writing a piece about counterfeit credit/debit cards. The point of the article was to shed light on how cybercriminals steal financial information and ultimately our money. I presented a technology called MagnePrint as one possible solution. Several TechRepublic members mentioned another technology that they thought was better called chip and PIN.

Chip and PIN Security

Chip and PIN systems were created to prevent skimming. Replacing the magnetic strip with an embedded microchip supposedly eliminates that possibility. In fact, many consider chip and PIN security a strong two-factor authentication.

Several members also mentioned that chip and PIN technology is prevalent in Europe and why cybercriminals are more focused on stealing credit/debit card information in the United States. This article goes far enough to say that adoption of Chip and PIN technology in the United States is inevitable for that very reason.

How it works

Customers do not see much difference when using a chipped card. It works like this:

1. At the checkout counter, a customer places his or her card in a Pin Entry Device (PED).

2. The PED accesses the chip on the card.

3. The card is then verified by the financial institution providing the card.

4. Once the card is proven authentic, the customer enters the PIN.

5. The PED verifies that the entered PIN matches the PIN cached on the chip.

6. If it is a match, the transaction goes through.

So, what’s the problem? Quite simply, it’s the cost. The article mentions that:

“The card issuers cite the enormous cost of rolling out chip and PIN technology, estimated to be around $5.5 billion, and they rest safe in the knowledge that it is the merchants in the U.S., and not the card issuers, who are responsible for the financial costs of credit card fraud.”

Not quite perfect

I have been studying chip and PIN technology for awhile now. It obviously makes it more difficult to obtain a person’s financial information. But, it’s not perfect. My first inkling of this came from watching the BBC news report Chip and PIN ‘security risk’.

Basically, the PEN hardware is compromised, allowing the criminal to obtain the card’s financial information and PIN digitally. For whatever reason, the transaction traffic to and from the PEN was not encrypted. Still the PEN has to be physically altered for this attack to work, making it a risky endeavor.

New flaw

The same University of Cambridge research team that uncovered the PEN hardware flaw recently discovered a new problem with chip and PIN technology. Professor Ross Anderson, a member of the team points out the seriousness:

“We think this is one of the biggest flaws that we’ve uncovered - that has ever been uncovered - against payment systems, and I’ve been in this business for 25 years.”

Susan Watts of the BBC, presented a documentary (http://www.bbc.co.uk/blogs/newsnight/susanwatts/2010/02/new_flaws_in_chip_and_pin_syst.html) about the research called New flaws in chip and PIN systems revealed. Unbelievably, a transaction can be completed without knowing the PIN. To explain, let’s step through the attack process:

1. The attacker obtains a stolen credit/debit card.

2. Next, the stolen card is inserted into the attacker’s card reader which is connected to a notebook.

a. Also connected to the notebook, is some hardware that interfaces with a fake card via a cable.

3. The criminal starts the payment process by inserting the fake card into the store’s PEN.

4. The PEN accesses the chip to verify the card’s authenticity.

5. Next, the PEN asks the attacker for the PIN via the display screen.

6. The criminal enters any 4 numbers, it doesn’t matter.

7. The software/hardware developed by the researchers then somehow fools the PEN into believing the correct PIN was entered and a signature authorized the purchase.

If you get a chance, watch the video in the documentary. It shows a simulated transaction and the Cambridge researchers explain how they accomplished the attack. The following illustration and picture depicts the equipment used to implement the attack (courtesy of the University of Cambridge research team): http://www.bbc.co.uk/blogs/newsnight/susanwatts/2010/02/new_flaws_in_chip_and_pin_syst.html

If I understand correctly, the PIN exchange only involves the card’s chip and the PEN. That information was leveraged by the researchers to create a Man-in-the-Middle attack. The research team’s paper Chip and PIN is broken (pdf) mentions:

“A man-in-the-middle device, which can intercept and modify the communications between card and terminal (PEN), can trick the terminal into believing that PIN verification succeeded without actually sending the PIN to the card.

A dummy PIN must be entered, but the attack allows anyone to be accepted. The card will then believe that the terminal did not support PIN verification, and has either skipped cardholder verification or used a signature instead. Because the dummy PIN is never sent to the card, the PIN retry counter is not altered.”

What’s next

One of the reasons I have been following chip and PIN technology, is to see if and when it will be adopted in the United States. I asked Professor Anderson about this and his response was:


“I’ll be talking about EMV (chip and PIN standard) at the Federal Reserve Bank’s conference in New York on April 1st. I’ll be arguing the Fed should insist that the EMV specification be
fixed before they allow its introduction in the United States.

The vendors are keen enough to sell the technology in the USA, where the card payment market is worth billions. If the result is a much improved EMV 5.0, then it will presumably come here to Europe in due course.”

One other area of concern that I found interesting is the transition credit/debit card. If the chip and PIN system gains traction, not every merchant will have the correct PED immediately. According to the researcher team’s report, this opens another attack avenue.

If the chip and PIN card includes a magnetic strip as a fall back method for making purchases, the card can still be cloned and the information may remain valid when that person obtains the official chip and PIN card.

Final thoughts

I am not sure where I read this, but it has a lot of “street cred”:

“The whole purpose behind security is to make it more difficult so thieves will go somewhere else as well as eliminating amateurs. Still no matter what you develop, there’s going to be someone who’s going to find a way around it.”

Michael Kassner has been involved with with IT for over 30 years. Currently a systems administrator for an international corporation and security consultant with MKassner Net. Read his profile or Twitter at MKassnerNet.

Wednesday, September 9, 2009

How secure is your credit card info?

In light of the biggest identity theft case ever prosecuted in America, the spotlight is being turned on just how secure is our credit and debit card information?

........Espousing a completely different view is Jerry Tabeling who is the president of IDP, a company that carries out vulnerability assessments of networks and online business applications."Our information is a lot more secure after all the publicity we have had about attacks," he said."But yes there are still problems that still exist though it is getting safer."These, Mr Tabeling told the BBC, tend to centre around a retailer not doing a good enough job securing its network.
...
Meanwhile Mr Tabeling, an IT security specialist, suggested that all consumers need to play a more proactive part in policing their own transactions and their credit information.

Tuesday, December 30, 2008

Creating a rogue CA certificate

by Alexander Sotirov

We have identified a vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure websites. As a proof of concept we executed a practical attack scenario and successfully created a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate allows us to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol.

Our attack takes advantage of a weakness in the MD5 cryptographic hash function that allows the construction of different messages with the same MD5 hash. This is known as an MD5 "collision". Previous work on MD5 collisions between 2004 and 2007 showed that the use of this hash function in digital signatures can lead to theoretical attack scenarios. Our current work proves that at least one attack scenario can be exploited in practice, thus exposing the security infrastructure of the web to realistic threats.

This successful proof of concept shows that the certificate validation performed by browsers can be subverted and malicious attackers might be able to monitor or tamper with data sent to secure websites. Banking and e-commerce sites are particularly at risk because of the high value of the information secured with HTTPS on those sites. With a rogue CA certificate, attackers would be able to execute practically undetectable phishing attacks against such sites.

The infrastructure of Certification Authorities is meant to prevent exactly this type of attack. Our work shows that known weaknesses in the MD5 hash function can be exploited in realistic attack, due to the fact that even after years of warnings about the lack of security of MD5, some root CAs are still using this broken hash function.

Co-authored by Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Weger

Further details:

Colliding certificates:

This work was presented at the 25th Chaos Communication Congress in Berlin on December 30, 2008.

For press or general inquiries, please contact the team at md5-collisions@phreedom.org