Sunday, January 28, 2018

Backup. It is not for prevention, it is for recovery.

Moments after I have finished teaching an introductory course on cybersecurity and protection I came across an article about US hospital administrators who preferred, after Cyber Ransomware attack,  to pay the money (over $ 50,000) than using backups to restore back its IT capabilities. I tend to believe that they tested the possibility of recovery by returning from backups, Paying the ransom seems to face the quickest solution for a life-saving organization to get back to normal.

I took advantage of the article just published in time for a final quiz… I have then published to my students some questions for a paper to be written on that subject. Beyond the usual questions of "What is Ransomware, how can I prevent it, how can I recover from such a cyber incident?"

I was interested in knowing what my students were thinking, so I asked, "How would you work if you were the cyber managers in the organization?" You could see who read the article diligently and who looked at it. The answers ranged from the scale of "I would never pay a ransom" to an in-depth analysis of the dilemmas of the hospital's director of security and risk management.

Of course, I also asked how it is possible to prevent a situation in which similar infertility will re-enter the hospital network. The report states that the infection was done by using RDP after scanning open ports and performing "guessing passwords" and therefore I expected (and was not disappointed in most cases) to see that reference is made to canceling the use of RDP or changing the default port; Strengthening passwords; Use IDS / IPS technology to identify and block port scanning and guessing passwords from a remote station.


One thing bothered me by reading most of the answers and after cross-referencing the bibliographic sources. From there, there are those who attribute to data backup processes part of the prevention process and not the beginning of the rehabilitation process.

The article that started it is here. If you have got hat Ransomware, you can try the fighting it here


Tuesday, September 5, 2017

Malicious Authorized User

An interesting article that I have just read is talking about vulnerabilities in MongoDB. I'm not that savvy in the DB arena, but I know one or two things in patching systems. The bottom line of that article saying that "Organizations should have a documented patch management process, should scan for vulnerabilities and configuration mishaps, and discover and classify sensitive data and systems so they can properly lock them down."

I agree with that statement. As I have just learned that companies pay a great effort to have their production segments of network well protected, hardened and patched to the latest revision (once Microsoft provided security patch for XP, they are all safe…), however within their enterprise network, it is a different issue. IT pays attention to the servers but ignore the workstations. A few days back, a SOC that I work with found that some 30% of an organization's workstations are using outdated software that their vulnerabilities were well documented into CVEs two to three years back.  Did this report meant something to the IT, not a bit, as they are relying on their peripheral cyber barriers to protect them? 



They probably never heard from the "malicious authorized user" the inner threat that can cause much more damage, allowing the payload to be safely found the right exploit to breed itself to the entire network.  

Credits:
Image source ipa.go.jp (here)
The article that triggered this post (here)

Sunday, May 14, 2017

Hackers don't make mistakes. It is all part of the plan!

Hackers that uses tools allegedly stolen from the NSA and uses it set a 
ransomware do not make mistakes. 
The fact that one have noticed that WannaCry ransomware had a turnoff switch, I assume that it was deliberately planned like that. Waiting to see if and when someone will reverse engineer the code to find it.  Why? I can just guess that they wanted to see how fast one will "catch" them, or better, to understand how they need to react to make it more sophisticated.  
So they did. I have learned today that WannaCry 2.0 is out there without the kill switch, so it is on the loose again.
According to officials that ransomware has affected some 75000 PCs in just 24hrs, that is 22,500,000$ reasons why to try and improve it. You got it right, the profit potential after 24 hours were twenty-two million US dollars (paid with untraceable Bitcoin). How many paid? No one knows...   
when it will end? for sure the epidemic infection will be reduced once IT organizations will patch and block the SMB protocol in their networks, as it carried this virus.
x