Showing posts with label advanced threat persistent. Show all posts
Showing posts with label advanced threat persistent. Show all posts
Wednesday, August 29, 2012
Stop Shamoon before it is too late
Shamoon is striking in the middle east, it is attacking oil and gas companies, one Saudi company was the first, others most probable in the queue and there is a potential for other types of orgnizations to be attacked, it is matter of time.
In this blog i will list actions can be taken,based on the malware analysis done by AV companies, to stop shamoon or at least reduce its impact. However for more details you may browse the following
Shamoon the Wiper - Copycats at Work
Shamoon the Wiper in details
Shamoon, Saudi Aramco, And Targeted Destruction
The Shamoon Attacks
I am listing two plans, short term plan and long term plan which requires budget and time
Short Term (The foundation):
For IT employees
All must be non administrators.
Use Remote Access Server between the IT network and servers at Data Center.
Always use "rus as administrator" and stop login as administrator for day to day support, operations or tasks.
Reset all admins passwords for servers,applications,databases network and security devices.
Never use default passwords or top worst passwords.
No shared accounts or passwords.
For non IT employees and desktop/laptops
Reduce the user privileges if any has an administrator access.
Block the removable storage if no device control in place.
If device control in place, stop all executable file.
Proxy or content filtering
Block the download of executable files, inf, bin, dll, conf and config.
Block access to network related to botnets, C&C and suspicious web servers.
LAN
Use VLANs to segregate network based on floor or department or business unit.
Implement a separate isolated IT management. same applied to mission critical infrastructure.
Remote users using VPN
Allow remote users to access certain resources , stop IP Any Any rules.
Remote offices
Only allow remote offices to access the resources they need, stop IP Any Any rules.
Security monitoring
Install any open source log collection.
Establish daily monitoring and analyzing security logs.
Long term (must be business risk based)
Implement SIEM solution.
Implement device control solution.
Implement two factor authentication solution for servers, network devices and critical infrastructure.
Implement network monitoring and forensics solution.
Implement Malware network analysis solution.
Establish a process to analyze, identify and detect attacks and shall be integrated into a security incident process , NIST computer incident guide can be used.
Establish Cyber Security Intelligence framework.
Time is ticking, they are advanced and using unique techniques, but you can make their attacks fail if proper security controls in place.
Tuesday, August 21, 2012
Build a practical Cyber Security Intelligence- quick thought
Stuxnet, Guass, Flamer, other malicious
codes and unknown malware attacking organizations of all types, some we knew
about and some we do not. But who is the next organization.
Today where threats are more advanced
and ahead of protection technologies and methodologies each organization has to
build some kind of Cyber Security Intelligence capability to stop or at least detect
(in near real time) advanced threats attacking the organization.
Building effective Cyber Security
Intelligence, first organizations must have a working risk management process
and once Cyber Security Intelligence is established then it must be integrated
in the risk management process.
Risk management will help
identifying the Cyber Security Intelligence framework that can meet your
organization business requirements and protect valuable assets.
So what can a Cyber Security Intelligence
framework consists of? The following lists the components of the framework; it
is not a full list but can be used as starting point
1.
Establish
security monitoring, alerting and reporting infrastructure.
2.
Establish
a security analysis procedure.
3.
Establish
non published cyber security information procedure
4.
Follow
up latest security tools
5.
Follow
up latest security news, alerts and analysis
6.
Follow
up linkedin groups either security or groups related to your business
- Information Security and Risk management experts
- Aurora Cyberconflict Research Group
- Information Security Community
- Information Security Network
- ISF - Information Security Forum
- Reverse Engineering and Malware Research
- Malware Analysis
7.
Build
malware analyzing lab
8.
Follow
up underground forums
Of course not the entire list is
required based on your business type and requirements.
Also you may need to have basic
knowledge of other languages such as Arabic, Chinese, Russian, Farsi and Hebrew.
I will keep the list updated and
later will detail how to incorporate all the above components, others and risk
management.
Subscribe to:
Posts (Atom)