Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/9/2015
10:30 AM
Connect Directly
Facebook
Twitter
LinkedIn
RSS
E-Mail vvv
0%
100%

Solving the Right Problem: Stop Adversaries, Not Just Their Tools

A malware-centric strategy is mere child's play against today's sophisticated adversaries. Here's why.

Most organizations today focus on protecting their networks against malware, exploits, malicious websites, and unpatched vulnerabilities. Unfortunately, there is a fundamental flaw with this approach: a malware-centric defense approach will leave you vulnerable to attacks that don’t leverage malware.

In fact, malware is responsible for only 40 percent of breaches and external attackers are increasingly leveraging malware-free intrusion approaches in order to blend in and fly under the radar by assuming insider credentials within victim organizations. The nature of the game now is persistence and gaining long-term access to the enterprise. The chances of ultimate discovery and effective remediation diminish greatly when no external binaries are brought into the environment and no unusual outbound C2 traffic is taking place.

Let me illustrate that with a real-world example.

A few months ago, CrowdStrike Services was hired by a large defense contractor that had been struggling for months to remediate an intrusion from a sophisticated Chinese-affiliated actor. The adversary kept coming back and the client could not identify the point of entry, despite having numerous host and network forensics, whitelisting, as well as Indicator of Compromise (IOC)-scanning malware detection tools.

They brought us in with the explicit mission of identifying the C2 channels the adversary was using to get back inside the environment. In the end, it turned out that the question they were posing -- identification of the C2 servers -- was the wrong one. Once the services team deployed our next-generation endpoint technology across their servers and desktops to profile and identify all adversary activity, we determined that the adversary had compromised their two-factor authentication system, stolen the seed values and was coming in with through the VPN system using legitimate credentials and generated two-factor token values. There were no C2 server IOCs to locate and once the adversary was inside the network, they were able to move around using legitimate credentials and windows system administration tools, without actual use of malware.

This critical gap between current enterprise defense strategy and the evolution in adversary tactics is responsible for a growing number of successful intrusions, as well as the fact that a typical breach remains undiscovered for over 200 days. In response, organizations now need to adapt their strategy and augment their malware-detection and IOC scanning tools with solutions that can hunt for, identify and stop adversary activity even when no malware is present.

This new approach also requires a move from an indicators of compromise to an indicators of attack (IOA) detection strategy. An IOA-based detection system can look for adversary intentions and effects, such as whether they are stealing credentials, moving laterally, executing processes and maintaining persistence, as opposed to only trying to locate known indicators of malware. This is no longer a promising emerging approach but a necessary and critical building block for effective cyber defense.

[Learn more about what motivates hackers from Dmitri during his conference session, Understanding Your Attackers, on Wednesday, April 29, at Interop Las Vegas.]

Dmitri Alperovitch is the Co-Founder and CTO of CrowdStrike Inc., leading its intelligence, research and engineering teams. A renowned computer security researcher, he is a thought-leader on cybersecurity policies and state tradecraft. Prior to founding CrowdStrike, Dmitri ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15564
PUBLISHED: 2020-07-07
An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by a guest to register a shared region with the hypervisor. The region will be map...
CVE-2020-15565
PUBLISHED: 2020-07-07
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require flushing of both TLBs....
CVE-2020-15566
PUBLISHED: 2020-07-07
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a host OS crash because of incorrect error handling in event-channel port allocation. The allocation of an event-channel port may fail for multiple reasons: (1) port is already in use, (2) the memory allocation failed, o...
CVE-2020-15567
PUBLISHED: 2020-07-07
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-atomic bitfield writes...
CVE-2020-15563
PUBLISHED: 2020-07-07
An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM g...