Response to a press article- Ransomware spikes as crooks eye easy cash

On 10-05-2016 fin24Tech reported that Kaspersky Lab detected a 14% increase in ransomware as cybercriminals turned to private users and corporations for easy cash.

The reality with the cyber security world today is best summarised by the quote from the former United States Secretary of Defence, Donald Rumsfeld on 12 February 2002 when he said:

“There are known knowns; there are things we know we know. We also know there are known unknowns, that is to say we know there are some things we do not know. But there are also unknown unknowns – the ones we don’t know we don’t know.”

It must also be recognized, that the fact that we face these risks, does not mean that we should disconnect ourselves from the internet. Ransomware has rapidly evolved from simple locker ransomware, designed to lock the computer and preventing victims from using it, to complex crypto ransomware which encrypts personal files and data (the Holy Grail). As Ansie Vicente once said, extortion groups that use ransomware are less discriminating and will typically deploy this malware opportunistically, choosing targets with poor defences. These attacks need targeted actionable threat intelligence that is in machine-readable format. Predict, Prevent, Detect and Response provide the counter to these malicious attacks.

adaptive-security-architecture

Aleks Gostev, the chief security expert in the Global Research and Analysis Team says that “once the ransomeware gets into the user’s system there is almost no chance of getting rid of it without losing personal data.

For more information, visit:

http://www.fin24.com/Tech/Cyber-Security/ransomware-spikes-as-crooks-eye-easy-cash-20160510

An Interview On Traditional Security/ASA

My organization was reportedly hacked last month and while I was busy reading and writing about adaptive security architecture I managed to interview  our Director: IT Operations who was involved with the whole process of assisting in stabilizing the environment and this is what he had to say:

Q1: What is your level of experience in Information Security?

Answer: My level of experience in Information Security can be regarded as low as I do not deal with the concept of Information Security on a daily basis. My little understanding can be regarded to border of the understanding of preventative and detective way of securing information/systems.

Q2: Which Information Security Concepts/Architectures (if any) do you have experience with?

Answer: I have experience on preventative and detective concepts. My regular duties involve supporting teams that are responsible for application support and maintenance and we often focus on preventative and detective ways of securing information.

Q3: Have you ever had to deal with targeted attacks launched by cybercriminals? What was the success rate in dealing with cyber security attacks?

Answer: Our organization recently had an incident where we were hacked by the “Anonymous group” using the SQL injection method. The passwords that were not encrypted were published in the “Anonymous group” website. This can be attributed to the fact that we have not yet adopted a comprehensive adaptive security architecture and approach. Even our preventative and detective are still operating in silos. After the attack we made efforts to harden the passwords by making them to have a minimum of 8 characters which include capital letters, special characters such as @, &, $ as well as small letters and numbers. We also encrypted passwords but we have not had an incident after that.

Q4: Based on your answer above, do you reckon that traditional security mechanisms still have what it takes to protect organizations from malicious attacks?

Answer: No, I see them as more reactive to the incident and they are not effective. They also do not offer an integrated approach to information security.

Q5: Have you ever heard about the concept of Adaptive Security Architecture?

Answer: Not yet until I read the Gartner report on this concept of Adaptive Security Architecture

Q6: If so, do you think it is the kind of security that you would recommend to your organization?

Answer: Yes. Adaptive Security approach is the kind of security I would recommend to my organization.

Q7: Which security tools or vendors do you know that offer security solutions that have adaptation?

Answer: Not aware of a specific vendor or tools whose solutions offer adaptation.

  • Q8: If not, would you like to hear more about adaptive security architecture?
  • Answer: Yes

 

We are not just building a bigger firewall!

I was fascinated when  I read the content below, that I decided to choose the title that I have put above. This is an interesting perspective from Alan Cohen who somehow provokes some deeper thinking around the purpose or re-purpose as he calls it, about adaptive security.
The issue with this approach is IT winds up retrofitting a new generation of computing capabilities with an older generation of security approaches. How will all the challenges of perimeter, choke-point security disappear when applied to a new, more challenging computing environment? The issue is not about protecting a device or an IP address, but dealing with:
• Workload motion within and across data centres (public and private—the “anywhere” problem) where a vendor’s “network” gear will not run.
• The lack of context about your workload / server captured by the network—the network was never built for that.

• And probably the most insidious problem of them all: taking all of the complexity of traffic steering, IP addresses, and manual intervention and shoving it into a DevOps world designed for continuous delivery and increasingly relying on automation.
The size, complexity, and dynamism of computing should not provoke a corresponding spike in the complexity of managing your security posture. The traditional firewall market—whether it’s delivered through a middle box or a VM—will have the same issue. Or as Gartner has noted, “through 2018, more than 95% of firewall breaches will be caused by firewall misconfigurations, not firewall flaws.”1 The answer is not to build a bigger firewall.

The new model of security: Letting the workload defend itself

Adaptive-Security

Security controls also must be aligned with the resources that you are trying to protect. If your computing resources change, your security must automatically adapt as well: it must automatically understand the computing workload, the environment, and the communications channels. This is best done at the workload level, and must work on each one. This allows the workload to play a role in its own defence, contributing its context—workload, application, environment, and location—into building a dynamic policy that transcends the computing environment.

For more information, visit: https://www.illumio.com/blog/adaptive-security-beyond-the-perimeter

Why Cyber-Security needs to be adaptive

Although the subject sounds expressive, exactly, why cyber-security needs to be adaptive? Perhaps the question should be why shouldn’t cyber security be adaptive? I liken this to a question once asked by a Botany Professor: “To burn or not to burn” while referring to burning the (Biome) or field grass in winter. It is generally believed that burning Biome in winter will enable it to retain its state of the Biome and be prepared for the next seasons. In essence there will be benefits realized further down the line in future.

Advanced Persistent Threats (APT)

Advanced persistent threats or advanced threats as they are sometimes called, are considered to be highly sophisticated and can be very challenging for a complex and diverse network like the Internet of Things (IoT). IT Applications and Infrastructure are moving to the cloud and becoming virtual and this phenomenon has exponentially increased security breach today than it has a few years ago. A few years ago a combination of firewalls, intrusion detection/prevention devices were used to protect the perimeter but today everything has changed, these security mechanisms are no longer enough. This view is also shared by Aman & Snekenes (2015) when they say that the current security solutions, like firewalls, intrusion detection systems (IDS), etc., or even small anti-virus programs are not feasible for this sensory, tiny low-resourced thing-driven network. They say that the main driving technologies in the IoT are considered to be tiny sensory objects.

The advocacy that traditional security is no longer feasible for targeted attacks is also supported by (Jones & Horowitz, 2012) when they say that the rising threat of successful attacks warrants the consideration of a top-down system engineering approach that develops solution strategies regarding cyber security that goes beyond the perimeter model. Like the Biome that retains its state after burning, security needs to retain its status of being security from being attacked and withstand any attack. In essence, companies need to invest in their security and adopt an adaptive security so that they can realize security benefits. Here is an interesting piece of reading: Traditional security is dead — why cognitive-based security will matter.

Security Architecture

Aman & Snekenes (2015) proposed an event driven adaptive security (EDAS) which is autonomous risk-based event-driven adaptive security architecture for IoT. They say that EDAS monitors security changes in the IoT environment, analyzes the associated threats and adapts appropriate and optimized security configurations against the risk faced. I think that this EDAS architecture might be useful to employ in dealing with security in IoT and that it can potentially be capable of handling cyber-security.

EDAS: An Evaluation Prototype for Autonomic Event-Driven Adaptive Security in the Internet of Things

What Academia say about Adaptive Security Architecture

Although information security seems to be a factor more concerning to the practitioners to the extent that many papers including white papers have been written about it, academia have long indicated an interest in the subject matter as well. Many academic papers provide a perspective which is slightly deeper than the practitioner’s view in that the discussion also details the requirements for the design of the adaptive security tools.
In their paper, ‘Enterprise security architecture in business convergence environments” Sangkyun K et al. (2015) says that managements are facing difficult problems and confusions when trying to plan or implement information security systems in business convergence environments. They say that the more adaptive the enterprise firm, the greater its ability to improve its fitness as its market, industry, or technology changes. An article “Why can’t I do that?”: Tracing Adaptive Security Decision by Nhlabatsi et al. (2015), the authors take a look at adaptive systems on cloud whereby they say that users should understand how and why the behaviour of the system changes at runtime. This take of decision making capability by the system is shared by Evesti et al. (2014)in their paper Security Measuring for Self-adaptive Security when they say that self-adaptive security requires means for monitoring a security level and decision making capability to improve the current level.
In short, Evesti et al. (2014), define a self-adaptive security system as having the following capabilities:
1. System is capable to monitor its internal security state and external threat landscape in order to reveal security violations
2. System is capable to react to possible security violations and ongoing attacks by selecting alternative security mechanisms and parameters to keep the system on a secure state or move it back to the secure state.
In this paper by Evesti et al (2014), described two architectural requirements for a measurement based security adaptation as a collection of requirements for security measuring and identification of requirements from self-adaptive security perspective.
The paper, A System-Aware Cyber Security Architecture written by Jones and Harowitz and also published on-line in February 2012, says that the rising threat of successful attacks warrants the consideration of a top-down systems engineering approach that develops solution strategies regarding cyber security that go beyond the perimeter model. The authors advocate the use of a System-Aware Cyber Security that they say it provides the means to hypnotize specific threats in relation to specific application functions.
I have also noted from the article, Comparison of adaptive Information Security Approaches by Evesti & Ovaska, 2013 that in order to achieve a coherent security adaptation approach, the cooperation between autonomous computing, security and software development experts will be needed. As a result of collaboration, approach which is secure, easy to utilise, and contains necessary adaptation aspects in the same time can be achieved.
As mentioned earlier, academic papers extend the focus on in-depth mechanisms required by the adaptive security architecture tools. Although these are being addressed through different connotation, like EDAS (Event-Driven Adaptive Security) and some uses Self-Adaptive Security Architecture, the advocacy is on the continuous autonomic control loop.

EDAS (Event Driven Architecture Security)

Its platform consists of a set of methods and tools that are necessary to continuously monitor and analyze events in a context-aware manner to investigate any potential security threats and associated risks. It is constituted of three layers:

1. Monitoring Agent – It is tasked to remove any redundant events and shapes them into a universal format for risk analysis and adaptation.
2. Risk Analyzer – It investigates potential threats and risks associated with the events using a correlation engine such that false alarms are avoided.
3. Risk Adaptor – It is where adaptation engine selects a mitigation action from a pool of possible actions to reduce the risk impact. The selected action is then sent to the local adaptor process where the new security settings are received and applied.

The effects of the adapted changes are recorded, monitored and analyzed again. All this security monitoring, analysis and adaptation happens in a continuous control loop fashion.

ESAS is described in the article: Aman W, and Snekenes E (2015), EDAS: An Evaluation Prototype for Autonomic Event-Driven Adaptive Security in the Internet of Things, 225-256.

Self-Adaptive Security

It is considered as an adaptive security solution that is able to change and modify the used security mechanisms autonomously at runtime. This solution reference the model called MAPE-K (Monitor, Analyze, Plan and Execute), where K stands for knowledge. This platform concentrates on architecture, knowledge and access control. Architecture for security-adaptation loop is mapped to the MAPE model.

1. Monitor – It collects information that is analyzed to recognize adaptation needs.
2. Analyzer – It analyses the consequences of the changes based on knowledge retrieved from the ontologies at runtime.
3. Plan – This phase creates an adaptation plan for execution.

The four phases, MAPE, constitute an adaptation loop supported by knowledge and the adaptation approach combines solutions from different interoperability levels.
The Self-Adaptive Security is described in the article: Evesti, A., Suomalainen, J and Ovaska, E. (2013). Architecture and Knowledge-Driven Self-Adaptive Security in Smart Space, (2), 34-66.

What I have found from some academic papers is that academia supports the notion of going beyond traditional security mechanisms by advocating the development of architectures and tools that are threat intelligent to deal with sophisticated cyber attacks.

Press Article about Cybersecurity

The Times newspaper of 26 April 2016 reported that widespread internet connectivity has made SA a preferred target under the heading, Beware spear phishing.  A startling revelation was made by the author of this piece of article that South Africa is losing approximately R1-billion a year to cybersecurity. The author reflected that there was proportionate increase in online banking fraud between 2013 and 2015. In my view, this article painted a picture that there is a success rate by those who are launching these targeted attacks. The author even pointed out that SABRIC (South African Banking Risk Information Centre) directs this not only to inadequacy in cyber security education in South Africa but also that “too few businesses and internet users had put in measures to counteract such attacks”.

In reading this article further, it was claimed that this spear phishing targets the executives of blue chip companies, parastatals and banks often using the person’s email address. Apparently “the attack can take the form of an emailed invoice within which malware-malicious software- is hidden. Some companies sometimes inform officials not to open suspicious emails and report such suspicions to the relevant personnel. Do companies really have to leave such emails to reach the executives mailboxes? What if the suspicion is not picked up by any official for that matter?

According to an academic article, Architecture-Based Self-Protecting Software System that was written by (Yuan, E. et al.2013), systems relying solely on perimeter security are often rendered helpless when the perimeter is breached; nor can they effectively deal with threats that originate from inside of the system. The authors of this academic article further relay that they see the pressing need for architectural approaches that monitor and adapt overall system behaviour.  This article also reflects that traditional approaches are labour intensive and require significant manual effort during development and/or at runtime. It is high time that companies ditch the conventional security that is perimeter-centric and adopt an architecture-based self protection approach. An architectural focus enables the approach to assess the overall security posture of the system and to achieve defence depth, as opposed to point solutions that operate at the perimeters.

In terms of costs, the adaptive security architectures are cost effective as compared to traditional security mechanisms. There are different vendors that provide adaptive security solutions in the form of software. These tools are computing systems that can manage themselves by using high-level objectives by administrators. The architecture covers all adaptation phases from monitoring to execution with dynamic access control.  The site, Security vendors team up to detect targeted attacks on networks, reflects the extent to which cybercrime has become a concern to many organizations and also provides an indication of some vendors that are positioned to provide solutions to cyber attacks.

The survey done by Ernest &Young, 2015 Global Information Security Survey revealed that a significant number of companies still need a wake-up call when it comes to their information security.  The survey indicated that of the 1,755 organizations surveyed, 54% of them did not have a role or department that is focused on emerging technology and its impact on IT security. Another revelation made was that 36% of those organizations did not have threat intelligence in place. The message is simply that as cyber criminals find new ways to take advantage of the rapid digitization, companies need to switch to an active and adaptive defence approach that enhances the existing capabilities to achieve greater effectiveness against cyber attacks. It is therefore absolutely necessary for companies to establish self-adaptive security architecture that can integrate and launch corresponding security services according to the security requirements of their organizations. Adaptive security architecture provides for targeted intelligence that is intelligence specific to an organization. This means that through targeted intelligence, organizations would be equipped with contextual awareness in that organization would be in a position to know what username and password had been compromised as well as the malware type.

 

Traditional Security vs Adaptive Security Architecture (ASA)

Security is predominantly practices that are based on policy and standards. Most organizations apply security measures uniformly to manage risk effectively. However, Enterprises depend overly on blocking and prevention mechanisms that are decreasingly effective against advanced attacks. The truth is; today’s security threats are more advanced than traditional security solutions.  As much as there is acknowledgement that there is no silver bullet that will defeat those intent on penetrating your defence, efforts still needs to be made to improve security.

Security threats are generally intent and not an accident; hence hackers launch targeted attacks intentionally, thereby fancying their success. Although the traditional security is to some extent effective by employing the IDS/IPS (intruder detection system/intruder prevention system), its central dogma is that it is focused on preventing threats.  Exactly Why cybersecurity needs to be adaptive, is anyone’s guess as times have changed and today cyber attacks have evolved so much that perimeter -centric security is lagging far behind. Today’s security threats come from inside the firewall, and in the DMZ.

The problem with the traditional security is that a firewall or IPS monitors the communication between devices and tries to spot an attack in the traffic based on having seen such an attack before or by assessing an outside system’s reputation. I think that this is less of an intelligent approach as malware and the places it communicates to mutate rapidly to evade such defences. The other concerning issue is that threats are normally persistent and often unfold in stages that sometimes take weeks or even months. The attackers remotely launch these attacks and shape-shift them to eventually achieve their intended purpose. The traditional security technologies are known to be poorly integrated and are unable to provide adequate protection. What is required is an integrated approach that spans the prediction, prevention, detection and response to advanced threats through an integrated and continuous monitoring system.

Benefits of Adaptive Security Architecture

The Adaptive Security Architecture has the potential to provide organizations with the following benefits:

  • Real-time monitoring and response – teams are enabled to move from after-the-fact analysis logs to real time evaluation of users. This makes dynamic, immediate and potentially autonomous response possible.
  • Filtering and prioritization – By applying advanced analytics and machine learning, organizations can identify some on-going security breaches that they can’t detect by monitoring the system alone
  • Reduce threat amplification – restrict the potential spread of a pandemic in a monoculture
  • Shrink the attack surface – make the target of an attack smaller
  • Decrease attack velocity – slow the rate of attack
  • Reduce remediation time – respond to an attack quickly

Gartner indicated that there are 12 critical capabilities that can be derived by employing ASA. As Gartner says, the end goal should be that the “different capabilities integrate and share information to build a security protection system that is more adaptive and intelligent overall”.

The four elements of adaptive security, Predictive, Prevent, Detect and Respond work as an integrated force.

The following are a summary of what each element’s tasks are:

Predict – Proactively assess exposure to threats; attacks are predicted; there is a continuous change to systems to disclose new vulnerabilities

Prevent – The system is hardened to limit hacker’s ability to reach systems; employ techniques to divert attackers by hiding or obfuscating system interfaces and information; prevent incidents by using threat intelligence from third-party reputation service feeds and integrating it into the network.

Detect – Detect incidents in the shortest time as possible; confirm and prioritize risk by correlating indicators of compromise across different entities; contain incidents by isolating a compromised system or from accessing other systems.

Respond – Investigate or conduct forensics by assessing the full scope of the breach and determining impacted systems; design or change model to prevent new attacks or re-infection of systems; remediate/make a change by automating some responses by using emerging security orchestration systems and policy changes.

Blueliv, in their writing about Adaptive Security Architecture to protect companies from Advanced Attacks , make an interesting remark about the fundamentals of deploying adaptive security model by companies as having the need to “receive targeted actionable threat intelligence that is in a machine readable format”.  They further alluded that adaptive infrastructure is one that is aware of various elements occurring across a wide variety of security inspection capabilities and I see this as auguring well with continuous monitoring and analytics of Gartner’s model. The eventual mode then becomes the response mechanism! Thus, as opposed to traditional security, adaptive security architecture is placed in an apt position to identify and react speedily to attacks.

IBM claimed in their 2015 white paper about Security Threat Protection|End Point Protection |Cybersecurity, to embrace adaptive security architecture mechanism by building their products on an adaptive architecture. They (IBM) say that their Threat Protection System is built on an adaptive architecture that evolves with the changing environment and threats that the business faces. They say that this system integrates with 450 tools from over 100 vendors acting as connective tissue for today’s disjointed cybersecurity infrastructure.

If sophistication of attacks is outpacing your organization’s defences, you need look no further as ASA might just be the answer you are looking for. I will also share what the academic literature says about ASA in the subsequent posts.

What is Adaptive Security Architecture?

It is an information security approach that employs modern tactics and tools to thwart the attack on the network by cybercriminals. It can be considered as a way of “beating the cybercrime masters in their own game”. Thus, organizations should not solely rely on preventative mechanisms as cybercriminals are continuously “upping” their game and not giving up in launching attacks on vulnerable networks. In simpler terms, Adaptive Security Architecture means having flexible security measures in place to be able to protect an organization’s information. This goes beyond the traditional perimeter defence from potential threats.

While the two terms, adaptive and security are somewhat explanatory, some readers might find the term, architecture to be a bit ambiguous in this regard. However, having listened to John Zachman (who is widely regarded as one of the early pioneers of Enterprise Architecture) at a seminar at the University of Pretoria in 2012 about Enterprise Architecture, the description given to architecture in a technology space fits well with the adaptive security architecture concept.

He (John Zachman) described architecture as a set of descriptions of representation e.g. what? (Inventory sets); How? (Process); Where? (Distribution); Who? (Responsibility); When? (Timing cycles); Why? (Motivation/Intention). These will be explained further in the next blogs.

In February 2016, Gartner classified Adaptive Security Architecture (ASA) as part of the new IT Reality Theme that sits along Advanced System Architecture; Mesh App and Service Architecture; and IoT Architecture and Platforms. In a 2016 report by Gartner, Designing Adaptive Security Architecture for Protection from Advanced Attacks, they reflected ASA as having four main elements, Predict, Block/Prevent, Detect and Respond. The report advocates that these four elements should work intelligently together as an integrated, adaptive system to constitute a complete protection for advanced threats. Gartner describes capabilities of ASA in each quadrant represented by Predict, Block/Prevent, Detect and Respond. This will be displayed in later blogs.

Continuous Monitoring and Analytics is at the core of adaptive protection architecture. This is to emphasise that security process should be continuous, and that pervasive monitoring and visibility should be constantly analyzed for indications of compromise.

Sun Microsoft lists the following as the objectives of Adaptive Security Architecture:

  • Reduce threat amplification – it restricts the potential spread of a pandemic in a monoculture.
  • Shrink the attack surface – make the target of an attack smaller
  • Decrease attack velocity – slow the rate of attack
  • Reduce remediation time – respond to an attack quickly
  • Facilitate the availability of data and processing resources – prevent or contain attacks that try to limit resources
  • Promote correctness of data and the reliability of processing resources – respond to attacks intended to compromise data or system integrity.

ASA should actually be part of an organization’s processes. In an article available online by Chris Riley, http://devops.com/2015/05/27/what-is-adaptive-security/, he suggests that adaptive security needs to be able to make decisions and respond within seconds or milliseconds after anomalous behaviour.

In 2008 Sun Microsystems produced a paper, Designing an Adaptive Security Architecture which interestingly outlines the steps to be taken in designing an adaptive security model, (http://www.sun.com/blueprints/online.html)

The next blog will deal with the differences between traditional security and the adaptive security and also highlights the benefits of adaptive security architecture.

Relying on Prevention is Not Enough!

Cyber-attacks are a fact of life for organizations of every size and across every industry. Enterprises are said to be overly dependent on blocking and prevention mechanisms that are decreasingly effective against advanced attacks. There is definitely a new approach needed to tackle the evolution of malware, and Adaptive Security Architecture might just be the answer we are looking for! Join me in foraying into a new realm of enterprise security!