Wednesday, March 25, 2015

Baseline – Not the Dubstep You’re Looking For…



Disclaimer: I have no real world ISC/SCADA system or security experience, I’m just a guy that takes in information and thinks about a better ways to do things.

We've all heard about taking a “baseline” of your network environment so you have some way to gauge and detect any anomalous behavior on your systems to, hopefully, help catch any type of malicious activity before it gets out of control, or in the very least, have a good idea of where to start when performing IR if there is a network breach. And, like most of us that already work in well-established networks, we know how difficult and time consuming a task this would be. But in a well-designed ICS production environment, this might be a bit less traumatic experience than one might think.

First of all, if a production ICS network is properly segregated (as it should be) the traffic flowing over the network is really not that complex because the protocols used aren't that complex. Modbus, DNP3 and most of the other ICS protocols out there operate on very small frame sizes and command lists compared to other network protocols, so while there may be a lot of traffic flowing back and forth between a controller and a device, the commands being sent are known and can generally be predicated based on their configuration and what action the system is designed to perform. In other words, you’re not going to see your Smart-Meter or valve controller performing Google searches or streaming YouTube videos unless something has gone terribly wrong! (Yes, that was a terribly joke).

This being the case, an ICS production environment is ripe for baselining even if it’s already up and running (which most are). So this is the first step in beginning to secure an ICS production network and there really isn't any reason why this should not be happening right now in all major and even minor critical infrastructure environments. We all know this isn't the case, but it should be the case none the less. If critical infrastructure company can get over this first, daunting hurdle, keeping this baseline up to date can actually become relatively easy in the future. Let me explain…

Once the major baseline is established and the network engineers know what normal traffic looks like and what might be abnormal, it becomes much easier to tune inline controls to recognize and flag real warning signs that something maybe amiss in their systems. And at this point, maintaining this baseline can become very easy if the proper deployment controls are put into place when the engineers either have to replace a controller or deploy a new system.

I am sure (or hopeful, however you want to look at it) that when a new ICS controller is replaced due to failure or through a system upgrade, or anytime a new piece of equipment is going to be introduced into the system, extensive testing occurs to make sure the new device is function properly before being deployed into the production environment. This is only logical and makes perfect sense, but this is also the time to not only make sure the operation and control of the system is well established, but also the perfect time to baseline the new system’s network traffic as it’s being run through all normal  conditional testing. By imposing this new deployment protocol you can capture all of the communications of the system in its purest form and have a perfect baseline of what to expect its typical traffic to look like; from normal operational commands, to fault conditions, to extreme fail-safe actuation or any anomalous traffic that might indicate that someone is trying or has breached the network.

This can be helpful in any kind of network, but ICS/SCADA networks can greatly leverage this kind of process with more precision than any other network environment I can imagine, to great benefit not only to the company, but to the environment and to the consumers of the products produced by critical infrastructure companies.

</my_two_cents>

Discuss…


Saturday, March 14, 2015

Of Cats and Security



So I was listening to Paul’s Security Weekly (@securityweekly) podcast last Thursday night when one of their guests, one Michael Santarcangelo (@catalyst), used the phrase, “Risk Catnip”. I almost fell on the floor laughing, as he weaved that phrase into his thought without any hesitation. It surprised everyone on the show and we all got a great laugh out of it.

The next day, since I loved that phrase so much, I decided to re-Tweet his phrase along with some other phrases ending with “catnip”. One of those phrases was “Threat Catnip”. A follower of mine by the name of @PeterGanzevles (Hacktic) replied with about the best response I believe I ever heard, he coined the term “Threatnip”, which got me thinking… (I know, I know, keep your jokes to yourself).


 Embedded image permalink


“Threatnip”, as it turns out, is actually a real thing and it’s used all the time as a lure to get executives to buy into Threat Intelligence products like reports, dashboards, blinky boxes and consultations. And much like catnip, once the prey has pounced on the lure and plays around a bit, the thrill is gone along with a considerable amount of money that could have been put to better use. Now I’m not saying that there is no use for Threat Intelligence, in fact, quite the opposite is true, but there has to be more than just the “Threat” part, because, as “Intelligence” implies, it must serve as a function of a continuous cycle of security posture improvement.

The morale of this short story is this: don’t be a “Threatnip” peddler, be a total solutions provider!


Here are some people that are much wiser than I on this subject:

Edward McCabe (@edwardmccabe):

John Berger

Rafal Los (@Wh1t3Rabbit)



Saturday, January 17, 2015

3NCRYP7ION is NOT a Crime!

3ncryp7ion is NOT a Crime!

Editors Note: In the first posting of the article, in my rush to get a blog post up I did not do my research thoroughly and I falsely attributed some statements to the French PM.  I have since edited this post, removing those incorrect statements and providing a link as a reference.  

This project came to light because of the recent terrorist attacks in France; a sad day indeed for the people of France, the families of those slain and for freedom of expression. The response by the people of France and the world was an amazing thing to witness, peoples of every nation banding together in solidarity to stand up against those that would attempt to quell freedom of expression, but then, some equally horrifying happened. Just days after the events and the rallies and marches, some European leaders, namely British PM David Cameron came out and floated some ideas for new laws that would weaken or eventually cripple encryption!  What the Verge called a "European Patriot Act". What irony there was in that statement and the follow up by other countries struggle to fight terrorism, support freedom of expression, but staunch privacy rights!

This did not sit well with me and many others in our community so I decided to do something about it, raise awareness and some money to help defend and educate people about not only encryption, but about privacy rights in general. So I created a shirt. Yeah, I know how it all sounds, but what better way to show your support and hopefully, get others to think about exactly how serious this issue is to everyone, even if they don't know why encryption is so important. If even one person asks you about your shirt and what it means, you'll have the opportunity to educate someone that might otherwise never have even bothered to think about this issue.

To order your shirt(s), go here -> 3ncryp7ion is NOT a Crime!

100% of the proceeds will go to somegreat charities, namely, Hackers for Charities and the EFF.
Hackers for Charities is doing great work in Africa to not only educate people in the use of computers, but also providing training for people who want to gain employment in the field. They also help provide internet access to remote villages and people that otherwise might not ever have that opportunity.
The EFF (Electronic Frontier Foundation) does a lot of work on behalf of computer users and the general public world wide by raising awareness of the various laws that are written involving computers and their communications and monitoring,

Please check out the charities here and when ordering, please specify which charity you would like to receive your money. (all un-allocated funds will be split between the two charities equally)

Hackers for Charities

EFF

Thanks to everyone for your support and encouragement in this project. It means a lot to me and I can see that it means a lot to many of you as well! I would also encourage other, more well-known bloggers out there to take up this cause and help raise awareness of the madness that is being proposed the help keep us "SAFE"

NOTE: For anyone ordering shirts that require international shipping, the shirt site does NOT support this, but I do and I will make that happen. just click on the Contact link on the site and send me an email with your order request and I will get back to you with the details.

Wednesday, January 14, 2015

Wi Fight?

So, we have TV shows and movies coming out that show “hackers” doing magical things with computers and we have the added hype from the MSM that shake in fear when a Twitter account gets hacked (really just pwned because of bad passwords, etc.) or when a gaming network has been taken offline using tools, that, well, anyone can use even if they only have basic computer skills and the money to rent a botnet.

And the result of such ignorance and misinformation? Changes to current laws that can practically make anyone in information security a criminal under the right circumstances. I’m not going to delve into that aspect, as Robert Graham has already addressed these issues in a great blog post today. Please read this, if you have not already: http://blog.erratasec.com/2015/01/obams-war-on-hackers.html#.VLcCZyvF9ps

As I perused the proposed changes to the current laws, I noticed something that really stuck out to me, the recurrence of this and similar phrases; “…or facilitate the commission of…” said crime. This line got me thinking, what do I possess that could be classified under that statement? Well, I have a TP-LINK WiFi adapter that can be initialized in promiscuous mode that can sniff WiFi traffic and using some simple programs actually capture this traffic. I also have a WiFi Pineapple that can accomplish the same tasks and a great deal more!

Do these devices make me a criminal? Does watching You Tube videos on how to best leverage these devices (on a perfectly and still legal pentest) make me a criminal? Sure, there is no “intent” here, but the equipment and knowledge can “facilitate”. And this is just hardware, not the software distros that are out there that make these tools even more effective, like Kali Linux, Pentoo, Pwnie Express, just to list a few.

Another, passive, but “facilitating” concept that is frequently used, even by hobbyist in the field, is wardriving, using programs like WiGLE that log and map SSID’s of a range of devices, even providing GPS locations of said devices. Will possession, let alone use, of such applications now be criminal offenses?

The answer, as it stands today, is most likely none of these devices and techniques will be “technically” illegal if the laws are changed, just because of the sheer volume of what’s already out there and the amount of people using them, but, as Jack Daniel said earlier today, “it depends on the aspirations of the prosecutor” on where these lines are drawn.

But, as we all well know, once this Pandora’s Box is opened, it’s going to be damn hard to shut and the talented people who do great research and help protect the public from people and organizations that are truly scary, will eventually become targets, for any number of reasons that some ambitious prosecutor can conjure.

NOTE: Consider this… A great and award winning journalist, and a person that a great many people in information security admire and trust as an authoritative source when it comes to data breaches, namely Brian Krebs, could easily be a prime target under these new laws. Just let that sink in for a moment.

ACTION: Take action, write your local federal legislators, try to engage them in a dialogue and inform them of what our community is really about, educate anyone and everyone you can, encourage discourse on the matter before it’s too late.

SUPPORT:
All the journalist and bloggers out there that have the courage to report and speak out about the truth of things.
Support groups that, on their own time, are fighting the good fight every day, like:

#MalwareMustDie
#WeAreTheCavalry
#WeAreTheArtillery


And other groups and individuals, for they are the militia of the internet as we know it!

Wednesday, January 7, 2015

(I)nternet (C)onnected (S)tuff


So yeah, there was a Target thing, a Home Depot thing, a J.P. Morgan thing and even a Sony thing. Was it bad, yeah, sorta, if you consider that some of our largest corporations were owned in a solid manner and, in some instances, it took months to even discover the breaches. But ironically, the most discussed incursion is the Sony hack, which in retrospect, is really nothing since it’s just an entertainment company (this statement, in no way minimizes the affect this incident had on the innocent employees and their personal information that was leaked). And yet with all the press this Sony debacle is getting these days, especially when the FBI is firmly sticking to “it was North Korea that pulled it off”, people seem to have lost sight of a major area of concern for our nation’s security and that is our ICS and SCADA infrastructure. 

We always hear about the IoT (Internet of Things) and how it will be a hackers paradise, being able to make toasters and refrigerators do all sorts of dastardly deeds, but there is another IoT that concerns me more than all of the other attack vectors combined, and that is our critical infrastructure, which, according to many experts is ripe for the picking. And if there are real nation-state actors out there that want to hurt us (and I believe there are), then they won’t be popping Target, Sony or Cuisinart, they’ll be targeting the systems that we rely on every day.

Just writing what I have so far I feel like I’ve already rehashed a lot of what has been reported for months on end, but I also feel that the truth needs to be repeated so everyone understands just how important these issues really are to our country’s very existence. Most of you work in private sector positions, fighting the good fight to keep our PII safe, and this is needed very much these days, but there is also a great need for the same kind of tenacity in the ICS/SCADA world. And, if you think it tough to evoke change in your particular organization, just think about how hard that same task is in the even larger world of the major utilities like power, nuclear, transportation, oil and gas, because when things go wrong in these areas, people can die and no cyber-insurance policy will ever be able to cover that adequately.

To be honest, I have no experience at all in any kind of ICS or SCADA environment (and very little real experience in the general infosec field), but I can say that if an event on the level of the Sony incident would have happened to one of our critical infrastructure assets, then the United States would be in a very vulnerable state at this moment.

Even though the Sony story is important in a great many aspects, there are bigger fish to fry out there and we’re deathly close to being in that frying pan. So if we really want to be concerned about the “nation-state” actors, we should be more concerned with our critical infrastructure and not so much with the breach of a Japanese based entertainment company.


REVISIONS:

1. As a general note, all governmental agencies need to cooperate with our critical infrastructure firms BEFORE the $hit hits the fan, not after the fact.

2. Disclaimer: To the authors knowledge, at no time were any squirrels harmed during the writing and revising of this post. however, we do not know if they reciprocated in kind. 


Note: A very special thank you to @chrissistrunk for his insight on this piece. Wanna know more about ICS, then he’s your man! 

Saturday, December 27, 2014

Doing the Un-Walk!



Well even after all the brouhaha about the FBI report coming out and (sorta) proclaiming that North Korea was responsible for the Sony Entertainment compromise, which most of the infosec community thought was bullshit from the start, they seem to be walking this back now. This is not surprising considering the evidence that has been presented to the contrary by many respected researchers in the field. On the other hand, a great many people do find this surprising, now why is this, which is the real question…

The real reason why this is surprising to so many people is many fold. First, most of us find it easy to think of North Korea as the “bad guy” just because of their past and current social and political status in the world. No one would ever argue that North Korea is not a bastion of anything other than the suppression and cruelty towards their own people and anyone they could potentially force their will upon (which sadly is only their own people). Second, as of late, they have been flexing what weak muscles they have towards Japan (hiding under the skirt of China since there is no love lost there) with missile tests and the like. And third, well, we all like bad guys being bad guys, it’s just so much simpler when the people we think are bad are, well, acting badly.

This is the perfect formula for a nice tight story, with backup that most people don’t understand, nor really care to for that matter, other than the word of our government, which, ironically, most people don’t trust to begin with! Strange bedfellows indeed! But a great formula for deceiving the masses through the attribution of ignorance. And I do not blame the masses for this, I blame the government (and most of the media) for this, as they are the ones that are attempting to take advantage of people that don’t know any better. Most people don’t know, nor should be expected to know how “sophisticated” cyber-attacks occur, after all, we pay experts to take care of this, right? I’m not trying to go all conspiracy theory on this breach, but the foundation is perfect for laying the blame wherever it’s convenient, especially considering the lack of understanding by most normal folks in society.

Fortunately, we have a lot of very talented and well-meaning people out there that know enough about attacks like this and have the balls to speak out about the research they have done on their own, without any compensation other than wanting to know the truth of the matter. The consensus, even before the FBI even floated their weak hypothesis, was that this attack never originated from North Korea. And now, through this pressure of wanting the “facts” revealed, the FBI is walking back their initial position that this was the work of the North Koreans, which even North Korea denied (which should tell you a great deal, since, as crazy as they are, would take credit for anything if it made them look good).

But enough of that for now…

So some might say it might have been Sony to help push their movie and whatever else. That’s just really crazy talk considering the money they spent on making the movie, not to mention the huge liability their responsible for at the moment, cyber-insurance notwithstanding. So the Sony Entertainment Corporation is out of the running, other than the fact that they obviously have some major security issues that were never addressed.

So who actually breached Sony and why? Well that is the real question isn't it? We can all speculate, from people with an informed perspective or people just being couch quarterbacks, but so far, no one has actually identified a person(s) or group that has left a traceable path of evidence. One group has claimed responsibility for the breach and despite all their threats, other than some data leaks, hasn't produced anything other than smack talk.

So I’ll just leave this out there for everyone to think about, especially since I know I am talking to a limited and intelligent audience; Sony is being hush-hush about this, which is to be expected, the Incidence Response firm will be shackled by NDA’s so no information will come from them and the government has now been discredited from their initial proposition by people that actually know what they’re talking about. But you know the FBI has talented people too, so that might just mean that they are hiding something, which is not unusual, but for what reason? And that is the real question isn't it?


Throughout this whole debacle there is one conclusion can definitely be drawn from all of this though and that is, attribution is now a weapon

Friday, December 19, 2014

Fully Bullshitical Intelligentsia

First off, I will declare that I am in no way an expert in any of the areas of expertise in which I’m going to make comments about. That said, I’m not a moron either and I truly disdain being treated as such, as should any person that relies on their governments intelligence agencies that are bound by law to be truthful to their people unless there is a damn good reason to withhold such information. I fully believe that there are times when certain “lettered” agencies can’t and shouldn't reveal what is truly going on during certain operations, but I don’t believe that the hacking of an entertainment company qualifies as one of those instances.

So, before today there was much speculation as to who the actual perpetrators of the Sony attack were and their reasons behind such a brutal assault against an entertainment company. Sure, the idea of North Korea was being floated about, but generally not in the circles of people that are truly in the “know” about this kind of attack. And yet today, our own FBI took it upon themselves to announce that the attack was in fact the work of hackers from North Korea, never mind that the whole supposed reason behind this attack was the premise of a two-bit movie about a meaningless country’s dictator.

Making any sense so far?

No?

That’s what I thought.

Some very intelligent, yet independent people have taken upon themselves to analyze the malware that was used in this attack and almost every one of them to a tee have concluded that either this was absolutely not the work of the North Koreans, or, in the least have cast considerable doubt to this claim. Yet, the FBI’s proclamation about their findings has been swallowed hook line and sinker but all of the media outlets reporting about this major breach.

So let’s all take a step back from this and see who has something to gain from their claims; the independent researchers who took their own time to investigate the actually, albeit minimal, evidence provided, or the big government agencies that have full access to all of the data, yet have to report to someone “above their pay grade”. Politics can be a bitch no matter your political leanings, but the 1’s and 0’s never lie, if you drill down deep enough. But never forget that any data can be made to appear to be something other than what it truly is. And from what I have seen so far, the independent researchers have offered up quite a bit more technical detail that any of the “three lettered” agencies have. And if these fine people can show their good scientific methods and their conclusions, it’s really not a national security matter, it’s just a matter of truth over narrative.

So, for honesty's sake, let’s lay all the cards on the table and see who has the winning hand.

P.S.

And to anyone who wants to wave the banner of national security, if someone wanted to truly hit us hard, they could cripple our critical infrastructure, rendering us vulnerable to a variety of attacks, but I doubt they would test these attacks on an entertainment company or because of a movie, so calm that shit down. Not that this issue isn’t a real threat that needs to be addressed, just that the events aren’t related, in my unprofessional opinion.