Wednesday, July 8, 2015

The OPM Mega-Hack

In perhaps one of the most prolific hacks in American history, anywhere from 4 to 18 million current and former federal employees had their personal information stolen a few weeks ago.  The data was being stored in a vast database run by the Office of Personnel Management (OPM).  Based on early identification of the methodology used to obtain the data, law enforcement officials attribute the intrusion to the same Chinese hackers that attacked Anthem Insurance earlier this year.  According to U.S. officials, “the breach, which was revealed Thursday and affected current and former federal workers from nearly every government agency, could be the biggest ever of the government's computer networks” (Liptak, Schleifer, & Sciutto, 2015).  Cybersecurity professionals believe the goal behind the attack was to build a database of federal employees with the intent of fostering future “insider” attacks.  Within the OPM database was security clearance information including which federal employees claimed family and friends living in China.  Experts theorize that this information could eventually be used to blackmail U.S. citizens with high-level security clearances to leverage classified information.  Weeks later, it appears the federal government is no closer to discovering how the massive breach occurred or at least has not been entirely forthcoming about the details.  “The cybersecurity experts added that some government agencies have not been following the government's own best practices for cybersecurity, such as updating operating systems with latest protections” (Liptak, Schleifer, & Sciutto, 2015).

And while the Chinese government neither confirms nor denies its involvement in the breach (surprise), this incident falls squarely into everything the cyber community knows about China’s modus operandi.  In 2014 the computer security firm Mandiant released a ground breaking report detailing a lengthy and sophisticated hacking campaign by a unit within China’s Peoples Liberation Army.  The report entitled APT1 (Advanced Persistent Threat 1) detailed three years of observation into a Chinese military unit’s cyber activities based in mainland China.  Mandiant’s findings were alarming in the complexity and persistence of the Chinese government’s development of their offense cyber capabilities.




In the end, the OPM hack although extraordinarily massive in its scope is just another example in China’s pattern of using offensive hacking to further their long-term geopolitical agenda.

References
Liptak, K., Schleifer, T., & Sciutto, J. (2015). China might be building vast database of federal worker info, expert says. CNN. Retrieved from http://www.cnn.com/2015/06/04/politics/federal-agency-hacked-personnel-management/


Mandiant. (2014). 2014 Threat Report. Retrieved from https://dl.mandiant.com/EE/library/WP_M-Trends2014_140409.pdf

Wednesday, June 3, 2015

2015 IRS Hack

It appears the Russians hacked us…again.  In true Soviet fashion, their government of course denies any official involvement.  The report from Congress last week is that cyberattackers acquired taxpayer information from approximately 100,000 Americans.  This time it was courtesy of the IRS’ “Get Transcript” tool (Reisinger, 2015).  Ignoring the fact that this revelation comes on the heels of other recent Russian intrusions against the White House and State Department, the most interesting part of this story isn’t the “who” but the “how.”  Employing previously acquired PII such as names, addresses, and social security numbers, hackers used a weakly defended internet based tool to make off with an estimated $50 million in tax refunds.  That’s right; we did this to ourselves…again.

The IRS has an online database of American taxpayer information called “Get Transcript.”  Hackers conducted targeted attacks against this system to the tune of 200,000 attempts in order to successfully acquire 100,000 fraudulent tax refunds.  Although the IRS claims this to be a sophisticated attack against their systems, there appears to be a number of amateurish steps cyber professionals should have picked up on.  According to Reisinger (2015), the 200,000 attempts were made from “questionable email domains with more than 100,000 of those attempts successfully clearing authentication hurdles."  This begs the question “how” did this attack succeed.  Apparently every year the Treasury Inspector General for Tax Administration audits the IRS to assess its security systems.  “As of March this year, a list of 44 upgrades suggested to the organization remained uncompleted—ten of which are now three years old. They included security patches to close loopholes that could be exploited” (Condliffe, 2015).  Shortly after the disclosure, the current Treasury Inspector General J. Russell George told Congress that “it would have been much more difficult if they had implemented all of the recommendations we made.”  Although insiders claim a lack of funds is to fault for the security lapses, testimony given before Congress seems to contradict this assertion. 

Whatever the reason for the lapse, the ultimate moral of the story is we are our own worst enemy when it comes to cybersecurity.  FISMA is a 2002 congressional requirement and yet it is still not being implemented in the federal government correctly.  It would seem that IT auditing and compliance related careers should and will be the first line of defense against ourselves…and the Russians of course.

References
Condliffe, J. (2015). IRS failed to update security systems making recent hack more likely. Gizmodo. Retrieved from http://gizmodo.com/irs-failed-to-update-security-systems-making-recent-hac-1708659493


Reisinger, D. (2015). Russian hackers behind $50 million IRS scheme, report says. CNET. Retrieved from http://www.cnet.com/news/russian-hackers-behind-50-million-irs-hack-report-says/

Friday, May 22, 2015

Public and Private Cyber Collaboration

With an increasing number of cyberattacks directed against the United States, the need for a national comprehensive cybersecurity policy is critical.  The extent of this effort has been the creation of guidance by the federal government often without Congressional approval or private sector mandates.  Given the fact that most of America’s critical infrastructure is in the hands of private entities, this must change.  Corporations have largely pushed back against any cybersecurity mandates and without official legislation, the “relationship between businesses and the government has been mostly all carrot and no stick” (Ravindranath, 2015).

As a result of this correlation, the federal government has become increasingly proficient at utilizing the carrot.  This comes in the form of government entities such as the National Cybersecurity Center of Excellence; an organization with the lofty goal of working with businesses to improve their cybersecurity posture, often by helping them find commercially available technology.  Similarly, the Commerce Department’s National Institute of Standards and Technology (NIST) has spent the last few years churning out reams of policy papers advising best practices for virtually every area of information technology.  These policies are increasingly seen as seminal works in the field of computer security with their guidance being implemented by a growing number of private organizations alongside their public counterparts. 

One of NIST’s most comprehensive and widely utilized guides, is 800-53 (Security and Privacy Controls for Federal Information Systems and Organizations).  In this 500 page publication, the Commerce Department’s regulatory agency details a framework for designing an organizational cyber policy. 


The publication goes further by discussing 17 security control categories and then detailing over 250 individual security controls that organizations should objectively consider implementing. 


All of this adds up to an impressive body of work that no one outside the federal government is required to abide by.  It would appear however that some private entities see the benefit in adopting a standard set of cybersecurity principles. 

“Last week, Department of Homeland Security’s cybersecurity and communications office’s chief technology officer, Peter Fonash, said businesses need to be able to exchange up-to-the-minute threat information with the government for instance.  Dodson said her team is working to hand over some projects to the private sector.  For instance, NIST’s Center for Excellence jump-started the Identity Management Ecosystem Steering Group, which aims to combat fraudulent online identities, beginning in 2012.  Today, the group is made up of commercial companies, including Microsoft and IBM.  That group is meant to serve as a forum in which members can discuss and implement better ways to conduct and verify online credentials and transactions” (Ravindranath, 2015).

References
NIST. (2013). Security and Privacy Controls for Federal Information Systems and Organizations. Retrieved from http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

Ravindranath, M. (2015). Nextgov. NIST official: Businesses need to take more responsibility for cybersecurity. Retrieved from http://www.nextgov.com/cybersecurity/2015/05/nist-official-businesses-need-take-responsibility-their-own-cybersecurity/113332/



Tuesday, April 28, 2015

Putin Hacks America...again

In early April, the White House announced that Russian hackers had penetrated the White House through a seemingly innocuous email account.  Their target was the "Executive Office of the President" network; an unclassified yet highly sensitive system that processes among other things, President Obama’s emails, schedule and policy notes.  The attack bears the same hallmarks of a similar intrusion last year at the State Department.  Based on the level of sophistication, U.S. officials believe the Russian government is the culprit (Sales, 2015).  If this incident wasn’t serious enough, a couple weeks after the White House disclosure, officials were forced to admit that Russian hackers had also accessed an unclassified Pentagon network in early 2015.  The breach which was only recently declassified illustrated another sophisticated cyberattack against the U.S. government most likely perpetrated by Moscow (Crawford, 2015).  These attacks targeted the same weak link in the cybersecurity chain: Us.

Much like the Sony Pictures attack, officials believe the White House incident was perpetrated through a successful spear-phishing campaign.  For the uninitiated, this type of attack entails the detailed targeting of a high-level official with a malware laden email.  Often times, the official mistakenly opens an infected attachment and the rest is history.  This type of attack is so successfully employed that Wired believes 91% of hacking attacks begin with a phishing email (Sales, 2015).  The Pentagon attack on the other hand appears to be a little less straight-forward.  Understanding that the Department of Defense has only recently declassified portions of the incident, it is unclear how exactly hackers gained access to a highly-guarded yet unclassified Pentagon network.  Initial reports point to an unpatched vulnerability, which indirectly leads us back to inadequate human involvement in the security chain.  Given the fact that the Office of the National Counterintelligence Executive has labeled Russia “a national long-term strategic threat to the United States,” it would seem to be a foregone conclusion that we as security professionals need to increase our training and awareness (Cilluffo & Cardash, 2015). 


References
Cilluffo, F. J. & Cardash, S. L. (2015). How to stop Putin hacking the White House. Newsweek. Retrieved from http://www.newsweek.com/how-stop-putin-hacking-white-house-321857

Crawford, J. (2015). Russians hacked Pentagon network, Carter says. CNN. Retrieved from http://www.cnn.com/2015/04/23/politics/russian-hackers-pentagon-network/


Sales, F. (2015). White House hack: By way of Russia with help from spear fishing. Tech Target. Retrieved from http://searchcio.techtarget.com/news/4500244197/White-House-hack-By-way-of-Russia-with-help-from-spear-phishing

Wednesday, March 25, 2015

Canada's Cyber Offensive

In yet another bombshell released from Edward Snowden’s cache of top secret documents, it turns out Canada has an ambitious and surprisingly advanced offensive cyber capability.  This revelation comes on the heels of an upcoming vote to authorize new powers for the nation’s cyber agencies.  Among the documents published was a confidential presentation by Canada’s intelligence agency Communications Security Establishment (CSE) in 2011.  The CSE, which is Canada’s version of the NSA outlines how by 2015, it “will seek the authority to conduct a wide spectrum of effects operations in support of our mandates” (False flags & cyber wars, 2015).  This authority comes in the form of the C-51 bill which is currently being pushed through the Canadian parliament by the nation’s conservative party.  The legislation has been proposed as a way to combat terrorism, but skeptics view this as another attack on personal privacy.  As a result, filibusters by opposition leaders and public demonstrations have been staged to oppose the bill.  Snowden’s leaked presentation details 32 techniques able to be employed by the CSE in both the defense and offensive arenas.  Some of the more notable weapons in the Canadian cyber-arsenal include:

Malware. The CSE has reportedly been building malware to bring down the networks of rival organizations. The malware was developed by the NSA as part of its QUANTUM hacking project. In fact, the NSA and the CSE have been collaborating for quite a while, gaining access and exploiting computer network targets in the Middle East, North Africa, Europe, and Mexico, say the documents. 

Deceiving attacks. The CSE used what are called “deception techniques” to attack networks while making it seem like they came from other organizations.  For instance, it directed victims to a fake site, then potentially used that site to “siphon classified information about computer networks.”  Additionally, the report says Canada launched attacks to block website traffic, redirect money transfers, and even delete emails.

Social engineering. The country also used a variety of social engineering methods to destroy other organizations' reputations.  Tactics included faking online poll results, posting fake Facebook messages, and even diffusing “negative information about targets online to damage their reputation.”

Network targeting. Lastly, the report indicates Canada's cyber-toolkit targeted specific networks to either garner foreign intelligence or inflict network damage.  Targets may have been aimed at "electricity, transportation or banking systems” (Weissman, 2015).

According to the leaked files, these capabilities have potentially already been employed against the Brazilian mining and energy ministry.  Leaked NSA documents in 2013 detail alleged CSE attacks against cellphones using specially crafted malware entitled WARRIORPRIDE.  Similarly, Canada is known to employ a government sponsored botnet to anonymously attack international targets.  These facts have prompted accusations of industrial espionage by at least one foreign nation against Canada and the United States (False flags & cyber wars, 2015).  As a security professional this level of public outrage is understandable but not new.  What I find more interesting about Snowden’s revelation is the level to which the Canadian government has risen in the field of attacks and espionage in the cyber realm.  I guess it shouldn’t come as a surprise that an advanced nation in the 21st century employs these tactics.  For whatever reason though, seeing overly polite Canada do it has been a real eye-opener.

References
False flags & cyber wars: New Snowden leaks reveal Canada spy agency’s deception toolbox. (2015). RT.com. Retrieved from http://rt.com/news/243397-canada-cyber-spying-snowden/

Weissman, C. G. (2015). Here’s how Canada tapped into computers and phones around the world. Business Insider. Retrieved from http://www.businessinsider.com/canada-tapped-into-computers-and-phones-around-the-world-2015-3


Tuesday, February 10, 2015

Mark Burnett and the Ethics of Hacking

In 2015, a security consultant named Mark Burnett published 10 million passwords along with their corresponding usernames.  His rationale was that doing so is necessary to ensure the continued access to hacking-related information. Until recently, cybersecurity researchers have only been given access to passwords without usernames, which Burnett argues provides a serious detriment to the field of computer security.  Passwords are ubiquitous in the IT industry and only through an examination of how individuals choose them can researchers craft better countermeasures against hackers.  Or so the rationale goes.

The major problem with Burnett’s justification is the illegality of what he did.  Given the recent five-year sentence handed down to Anonymous hacker Barrett Brown for a similar activity, it is understandable why Burnett might question his future as a free man.  To help clarify Burnett’s position as well as that of the federal government, it is critical to establish a few key points in what I can only imagine is an upcoming criminal case.  The passwords in question appear to have been collected from other notable hacks leaked online.  Advertised as a security consultant, Burnett argues that he collected this data with the white-hat hacker intent of helping to strengthen the concept of passwords for the collective good.  That being said, many researchers shy away from publishing passwords with their corresponding usernames because these pieces of data combined create an authentication feature.

In the case of Anonymous’ Barrett Brown, his five year sentence was predicated upon the fact that he trafficked in stolen goods (aka, the passwords) similar to Mark Burnett.  It should be noted however that this charge was later dropped with the government opting to go after Brown for his association with Anonymous.  Additionally, the Obama administration has proposed changes to the Computer Fraud and Abuse Act which would further outlaw the “publication of links to public password dumps even if the person making the link had no intent to defraud” (Goodin, 2015).

According to Burnett, these recent developments in the field of cybersecurity law has forced researchers and journalists alike to stop reporting on hacks entirely for fear of federal retribution.  If posting links to publicly available hacked data lands you in prison, then why would you take the risk?  According to Burnett,

“Including usernames alongside passwords could help advance what's known about passwords in important ways. Researchers, for instance, could use the data to determine how often users include all or part of their usernames in their passwords. Besides citing the benefit to researchers, Burnett also defended the move by noting that most of the leaked passwords were "dead," meaning they had been changed already, and that all of the data was already available online.”


References
Goodin, D. (2015). Fearing an FBI raid, researcher publishes 10 million passwords/usernames. ArsTechnica. Retrieved from http://arstechnica.com/security/2015/02/fearing-an-fbi-raid-researcher-publishes-10-million-passwordsusernames/




Tuesday, December 23, 2014

North Korea-The Newest Cyber Threat in Town

Certainly by now, the world has heard about the infamous cyberattack against Sony purportedly carried out by North Korea.  Although numerous denials have been given, the attack appears to have been perpetrated by a despotic regime in retaliation for the simple act of making a satirical movie.  I’ll let the ridiculousness of that statement sink in for a minute.  Now onto the practical matter at hand; how can the world’s most isolated nation pull off such a technologically advanced attack?  To put this in perspective, consider the following.  If you do a web search for “North Korea at night”, you can plainly see the lack of electricity or at least visible lighting as compared to its southern neighbor.  I remember standing on the DMZ looking into North Korea.  The normally wooded area was clear cut by the residents and soldiers not to provide a defensive line of sight, but for a fuel source....because there was nothing else.  Despite these limitations, North Korea actually has a fairly well developed cyber warfare capability. 

According to a 2014 report published by Hewlett-Packard researchers North Korea is seriously committed to the cyber aspect of their national defense.  The hermit kingdom’s Unit 121 is considered to be one of the world’s premier cyber organizations, third in size only behind the United States and Russia.  South Korea estimates this team is comprised of anywhere between 3000 and 6000 staff.  According to the HP report, some of the more notable hacks North Korea has managed to pull off include:

(2004) Gained access to 33 of 80 South Korean military wireless communication networks. 

(2004) Hacked into the US State Department, US Defense Department, and South Korean defense networks during discussions over nuclear missile testing.

(2007)  Tested a logic bomb which led to the UN ban of certain pieces of hardware to North Korea.

(2009)  DarkSeoul DDoS targeted South Korean and U.S. government, media outlets, and financial websites.

(2011) North Korea disrupted South Korean GPS signals, attempted a DDoS attack against Incheon airport and Nonghyup bank.

(2013)  DarkSeoul DDoS attacked South Korean government’s DNS server and South Korean financial institutions. (Osborne, 2014)

The Sony attack however appears to be the metaphorical straw.  Shortly after the hack and Sony’s subsequent decision to pull “The Interview” from release, North Korea’s limited access to the Internet was cut off for approximately 10 hours.  It is unknown whether this was a deliberate cyberattack against the regime or simply technical difficulties with the nation’s four official networks (Robertson & Strohm. 2014).  Researchers point out however that this occurrence is definitely out of the norm.  And while the U.S. State Department won’t comment on the reports, there appears to be no lack of likely actors willing to target the regime.  Anonymous made headlines in 2013 for its #OpNorthKorea campaign which targeted various North Korean websites.  In the end, the Sony hack illustrates the larger issue at hand; the next battlefield will undoubtedly occur in cyberspace.

References
HP Security Research. (2014). Profiling an enigma: The mystery of North Korea’s cyber threat landscape. Retrieved from http://h30499.www3.hp.com/hpeb/attachments/hpeb/off-by-on-software-security-blog/388/2/HPSR%20SecurityBriefing_Episode16_NorthKorea.pdf

Osborne, C. (2014). North Korea cyber warfare capabilities exposed. ZD Net. Retrieved from http://www.zdnet.com/article/north-korea-cyber-warfare-capabilities-exposed/

Robertson, J. & Strohm, C. (2014). North Korean internet access restored after hours long outage. Bloomberg. Retrieved from http://www.bloomberg.com/news/2014-12-22/north-korea-undergoing-internet-outage-network-researcher-says.html