Showing posts with label Matthew Pascucci. Show all posts
Showing posts with label Matthew Pascucci. Show all posts

Tuesday, December 5, 2017

Schools are Under Attack

Many hackers are opportunistic predators and will slide to the lowest common denominator when preying on their next victims. Over the past year we’ve seen hackers direct their attention to the education sector; particularly K-12. It’s always appalling when children are taken advantage of in any manner and having their data stolen, ransomed, or leaked…

The post Schools are Under Attack appeared first on CCSI.

The post Schools are Under Attack appeared first on Security Boulevard.



from Schools are Under Attack

Monday, October 16, 2017

Open Letter to Congressman Tom Graves on the “Active Cyber Defense Certainty Act”

To the Honorable Tom Graves:
In November of 2015 I was invited to the now retired Congressman Steve Israel’s Cyber Consortium to participate with other security professionals in the community to discuss cyber security related issues affecting both our organizations and communities. During this meeting you were invited to speak about your thoughts on cyber security, the issues you’re dealing with in Congress and your approval for the CISA bill. After listening to you describe your concerns over the OPM breach I noticed how seriously you took the issue of cyber security. I didn’t personally agree with some of the stances taken in the room, but you don’t have to agree on everything to initiate progress. I applaud your dedication and attention to cyber security and will continue to be interested in your thoughts; even if we might have differing opinions. With this being said, I have concerns with your latest bill being proposed to Congress: The “Active Cyber Defense Certainty Act”.
Each time I see someone propose reform to the “Computer Fraud and Abuse Act” it peaks my interest. Evolving our laws with the ever-changing cyber industry is both needed and incredibly difficult to accomplish and I appreciate your effort to modernize them. With that in mind, I’m concerned that the newly proposed ACDC bill crosses some boundaries I’d like to bring to your attention.
As you’re most likely aware many of the cyber incidents occurring are being launched from systems that criminals have already compromised and being using as a guise for their attacks. This essentially could end up being an attacker proxied through multiple systems throughout various countries with the face of the attack showing as an innocent bystander. By getting the approval to perform a “hack back” against this entity puts this unknowing victim in the middle of a complicated and intrusive scenario. Not only are they already compromised by a malicious entity, but they’re now being legally attacked by others that have assumed have done them harm. Congressmen Graves, these devices could end up being systems used to assist with our economies growth, hold personal records that could affect the privacy of our citizen’s data or may even be used with aiding our healthcare industry. The collateral damage that could occur from hack backs is unknown and risky. Essentially, if someone determines they were compromised by a system in the United States and they start the process of hacking back the system owners might notice the attack and start the process of hacking them back. This in turn could create a perpetual hacking battle that wasn’t even started by the actors involved. This method will in theory cause disarray all over the internet with a system being unknowingly used as a front by a criminal to start a hacking war between two innocent organizations.
 
To interrupt these systems without oversight is dangerous for us all. In reading through the bill I noticed that these cyber defense techniques should only be used by “qualified defenders with a high degree of confidence of attribution”. From this statement, what qualifications does a defender have to hold before they attempt to hack-back? Also, what constitutes a high level of attribution? Seeing this bill is only focused towards American jurisdiction I personally feel attackers will bypass this threat by using foreign fronts to launch their attacks to get around being “hacked back”. This somewhat limits the bills effectiveness as it’s currently written. By being able to track, launch code or use beaconing technology to assist with attribution of the attack is dangerous to our privacy. I agree that this is an issue, one that needs to be dealt with, but it should be dealt with via the hands of law enforcement directly, not the citizens themselves. I’ve read the requirements where the FBI’s National Cyber Investigative Joint Task Force will first review the incident before the “hack back” can occur and offers a certain level of oversight to the incident, but I don’t think there’s enough. I understand the resource requirements within the FBI are stretched, but leaving this in hands of those affected by the breach allows emotions to get involved. This is one reason why we call the police if there’s a dispute in our local communities. They’re trained, have a third party perspective and attempt not to make it personal. I feel that there will be carelessness on the part of those hacking back and this emotion could lead towards carelessness and neglect that will bring upon greater damage.
Lastly, the technology is always changing and being able to get confident attribution is incredibly difficult. If an attack was seen from a particular public IP address it’s possible that the NAT’d (Network Address Translation) source is shielding multiple other internal addresses. By attacking this address it will give no attribution as to where the data or attacks might actually be sourced. Also, with the fluid environment of cloud based systems a malicious actor can launch an attack from a public CSP (cloud service provider) that would quickly remove attribution as to where the source was occurring. I noticed the language within the bill referencing “types of tools and techniques that defenders can use” to assist with hacking back. Will there be an approved tool and technique listing that the active defenders be required to use that stay within the boundaries of this law? Or will active defenders be able to use the tools of their choice? Depending on the tools and how they’re used they could cause unexpected damage to these systems being “hacked back”. Lastly, there’s mention about removing the stolen data if found and I’m concerned defenders will not be as efficient with this data deletion and could cause major damage to systems hosting other applications or systems legitimately. Deleting this data at times could become an issue with investigations, forensics and might not solve the issue long term. This stolen data is digital and just because it’s deleted in one place doesn’t mean it’s been removed permanently.
Congressman Graves, I respect what you’re doing for our country, but I’m concerned with the methods in place to protect the privacy of the data and systems being actively hacked by defenders. I’m anxious about the overzealous vigilantism that might be implied by defenders looking to defend themselves, their systems or their stolen data. You’re an outside the box thinker and passionate about the protection of our country, I love that, but the methods in place could essentially cause more harm than good as the bill is currently written. I personally implore you to reconsider the actions of having a nation of defenders actively attempting to restore their data from sources that were most likely being used without their consent. The unintended privacy consequences, destruction of systems and even life are too important not to mention. If I could have advise in any way it would be to have our country start focusing on the fundamentals of cyber security before they start writing licenses to hack.
Thank you for your service and your continued efforts to protect our nation from future cyber events.
Sincerely,
Matthew Pascucci

The post Open Letter to Congressman Tom Graves on the “Active Cyber Defense Certainty Act” appeared first on Security Boulevard.



from Open Letter to Congressman Tom Graves on the “Active Cyber Defense Certainty Act”

Monday, September 11, 2017

The Equifax breach – Now what?

By now we’re all probably very aware of the massive Equifax hack that exposed 143 million American's social security numbers, birth dates, addresses and drivers’ licenses. There was also a small subset of credit cards and personal identifying documents released with limited personal information to an uncertain amount of Canadian and UK citizens being accessed as well. According to a statement released by Equifax the breach occurred from mid-May through July 2017. They discovered the breach on July 29th, which means attackers were actively working well over a month, if not more, at exhilarating this treasure trove of data. Equifax also stated that criminals exploited a vulnerability in their web application to gain access to sensitive data as the means of compromising their site

Here are a few of my thoughts on the Equifax breach: https://www.ccsinet.com/blog/equifax-breach-what-now/

Also, here's my bald head on CBS news talking about it: http://newyork.cbslocal.com/2017/09/08/equifax-breach-fallout/amp/




from The Equifax breach – Now what?

Saturday, May 6, 2017

Defeating Ransomware With A Little Help From Your Friends

We all know this so it doesn't have to be said, but I'm going to say it anyway: Ransomware sucks. For anyone who's suffered at the hand of attackers making money by holding your personal or business data hostage, you know just how much it sucks. The is...

from Defeating Ransomware With A Little Help From Your Friends

Tuesday, April 25, 2017

Using Machine Learning and Behavior Analysis to Assist with Threat Detection

Here's a whitepaper I wrote with CCSI describing what machine learning is and how you can use behavior analysis to assist your organization with threat detection. Few things over the past years have changed the way we defend our network like these two. 

Attackers are consistently breaching enterprise networks in attempts to compromise confidential data and the hard truth is they’re not slowing down. Data breaches have almost become common place in today’s news and we’ve seen businesses hit with attacks that cost them millions of dollars in lost revenue, fines and consumer trust. The majority of these organizations already had the traditional security commodities in place (e.g. Logging, firewall, SIEM) and yet was still breached by dedicated attackers. In today’s attack landscape advanced attackers are able to bypass many of these defenses with persistent and dedicated attacks directed towards the organizations user base and vulnerabilities within their security architecture. The unfortunate truth when using only traditional security defenses is that the odds are heavily weighted in the attackers favor. By adding behavioral analysis and machine learning to a business’s cyber defense brings visibility to threats, which are sorely needed in today’s networks.



from Using Machine Learning and Behavior Analysis to Assist with Threat Detection

Thursday, January 26, 2017

Differences Between Azure’s Web and Worker Roles

Here's an article I wrote in response to a question regarding the differences between Azure's web and worker roles. Hopefully, it clears up a few things.http://searchcloudsecurity.techtarget.com/answer/What-is-the-difference-between-web-role-and-worker...

from Differences Between Azure’s Web and Worker Roles

Monday, January 23, 2017

Seven ways to prevent catching malware in 2017

The Internet has changed the world we live in. Accessing data and information as well as communicating with people from far away is nowadays a breeze. However, our curiosity can lead us down very dark virtual alleys that may not seem so dark at first sight. The biggest security risk is usually the user itself. Catching malware is fairly easy, but in general it can be avoided easily too. All we need is a little common sense. 
#1: Update your operating system, browsers, and plugins
Whenever there is an update available for your computer waiting in queue, don’t wait further. Updates to OS, browsers, and plugins are usually released to patch any security vulnerabilities recently found. So while you leave those softwares alone, cybercriminals may find their way in through the vulnerabilities.
#2: Install antivirus or malware software
This should go without saying. However there are many computers, particularly home computers that do not have an antivirus or malware protection installed. This should be a must-have first step when it comes to keeping you computer virus free.
#3: Only open downloads and links that you can trust
This too may seem obvious, but it shouldn’t be stressed enough. In order to keep your computer away from malware, you must not visit dubious sites or download questionable, dodgy or illegal files. This is pretty much a sure way to catch malware. If you aren’t able to avoid these sites, make sure your system is properly protected. If you need assistance evaluating links for their safety, you may use the browser plugin Web of Trust (WOT).
#4: Keep your antivirus updated
Protecting your system with protection software is the first step; maintaining it updated is the second. A free antivirus is better than nothing, but bear in mind that it is not the ideal solution. Microsoft provides a security package “free of charge”. Free in that if you have Windows on your system, you will have access, but only because you paid for your Windows license. Most users are not aware of this program, but it’s actually pretty decent protection.
#5: Turn off HTML in emails
Very often, malware is distributed through email. Malicious emails can contract malware by running scripts automatically when opening an email in HTML view. That is why most email clients per default don’t display HTML content – pictures, etc. Do not change this feature - leave it that way and only allow reliable sources to automatically display HTML content.
#6: Enable click-to-play pluginsOne of the more usual ways that exploit kits (or EKs) are delivered to your system is through malvertising, also known as malicious ads. You don’t even need to click on the ad to become infected. These malicious ads can live on well-known, prestigious websites. Besides maintaining your software patched so that exploit kits won’t do their dirty work, you can block the exploit from ever being delivered simply by enabling click-to-play plugins. Click-to-play plugins will keep Flash or Java from running unless you tell them to (by clicking on the ad). The bulk of malicious ads relies on exploiting these plugins, so by enabling this feature in your browser you will manage to keep the EKs at bay.
#7: Run regular scheduled scans with your antivirus
This one too might seem like a no-brainer, however many of us forget to do this. Set up your antivirus of choice to run at regular intervals. Once or twice a week is preferred, but do not wait much longer between scans. Keep in mind that it’s difficult to use your computer while your antivirus is running. A potential solution is to run the software during night time when you aren’t using it. However, we usually turn off the computers at night. Set your antivirus to run on a specific night and remember to leave your computer on on that day. Make sure it does not go into hibernation mode or shut off automatically.

The author of this article is Sarah Williams, who is a copywriter for Gloc Media, a PPC management agency in London, United Kingdom. You can follow her on Twitter on @SWilliamsLondon, connect with her on LinkedIn and say hi on Google+. She loves books, hiking and the online universe.


from Seven ways to prevent catching malware in 2017

Saturday, January 14, 2017

Snowden Petition Reaches One Million Signatures

The petition to President Obama to declare clemency for Edward Snowden has reached one million signatures. With a few days left in office, President Obama is purportedly preparing a short list of pardons and many are hoping Snowden is on this list...

from Snowden Petition Reaches One Million Signatures

Alexa, are you spying on me?

It wasn't law enforcement. or an oppressive regime, that installed surveillance in our homes, but a population bowing to convenience. With the increase of virtual assistants, like Amazon's Alexa, we're causing self-inflicted privacy wounds from the lik...

from Alexa, are you spying on me?

Saturday, January 7, 2017

Chronicling Ransomware

Check out this excellent resource from "PrivacyPC" on ransomware updates and variants starting from May of 2016. The timeline goes through release dates, updates, ransomware decryption and other related events. This is definitely something worth keepin...

from Chronicling Ransomware

Tuesday, January 3, 2017

What to Expect When Moving to Amazon’s AWS

So your organization has decided to make the move to AWS and they’re thinking about ways to manage the migration with the least amount resistance. Good for you! When moving to AWS there are multiple tasks that need to be completed for a successful migration or new implementation within their cloud offering. There are in-depth checklists, Amazon actually has one of their own and in this article, we’re going to review six areas we think should be considered before your move to Amazon occurs.

Applications and Data

When migrating to the cloud an organization needs to consider the applications they’re currently using and if they’ll function properly in AWS. It’s very possible an organization is using legacy apps that might not function properly up in the cloud. Yes, believe it or not, people still use legacy apps. Understand the needs of these applications and if they’re even able to be installed within AWS. Also, get a firm understanding of the data being stored in the cloud. If this data is sensitive, think PHI or PCI, determine if you have the proper controls implemented to cover both security and compliance. If you don’t have this capability after moving to the cloud, you’ll have to start utilizing security solutions to protect this data, either with the AWS native security resources, or other solutions you have configured as an EC2 instance or within a hybrid install. Examples of these solutions would be a web application firewall, data encryption (rest and transit), logging and security assessments. Amazon offers all these services, but it’s possible the organization already has virtual or hybrid solutions which will fulfill your needs. Lastly, it’s important to determine if you’ll be using a public or private cloud model with your data/applications. This could come into effect if there’s a busy tenant causing resource issues which inadvertently cause your stack/application to have performance degradation.

Billing and Cost

As with anything cost and billing are important. This will almost always be an operational expense and the budgeting of moving to the cloud should be spoken of with finance before considering a move. This being told there are a few items to keep your eyes on with AWS. The first thing to determine is if there are other accounts setup with Amazon that might be active within the organization. With it being as easy as setting up instances with a credit card it’s possible a business is already in the cloud and you don’t even realize it. If this occurs or there’s a need to have multiple accounts created there should be an AWS master account created to link back all the services to the organization. Secondly, create billing alerts that will notify you when configured thresholds have gone over. The last thing you want is a misconfiguration or security issue causing additional dollars without knowing about it upfront. There are many other areas to review with billing, but these are two areas you might want to start off with.

Change Management and Automation

This is a big deal in the world of cloud. When deploying systems in the cloud everyone thinks it will be automation nirvana, but because of this flexibility, change, and config management need even more attention. When dealing with a purely AWS environment it needs to be determined who can build and launch instances within your account. AWS has something called Amazon Machine Image (AMI) which allows the needed information for an instance to be built. These need to be monitored as to not have issues with deploying wrong instances and keeping up with updates. Also, how will an organization deal with system hardening, patching, firewall changes (since security groups need to be understood before making inappropriate security holes). When dealing with additional changes and config management on instances it’s very easy to start VM creep and creating a decommissioning process should be written for cost, operational and security concerns.

Incident Response and Security

This is a topic that can have multiple articles written on it alone, but we’re going to try and cram as much as we can in here now. If you’re using AWS for your entire ecosystem then bringing in their security services is a must. Amazon has published native services that allow the ability to use them for IAM, logging, cloud WAF, MFA, encryption with HSM’s and security assessments. Using these tools is a must if you’re going to go all in with Amazon. Using their tools can assist with security since they have native integration with each tool within the Amazon ecosystem. Last, but not least, incident response in the cloud needs to be reviewed. Performing IR in the cloud is a different animal and you’ll need to determine if your normal procedures, tools and runbooks will fit while performing IR in the cloud. There will be areas you can’t touch, like logs on a system within a multitenant environment, and working with Amazon during this time is essential. Learn what you need to do upfront before you have too late.

Remote Management

Obviously, since the systems aren’t on-premise there needs to be a way to remotely access your instances securely. With this there are a few options that need to be thought out before even creating a single instance in AWS. The access to the console needs to be secured and logged right away. It should also have MFA on it and locked down to a particular range if possible, possibly via VPC. This is the access to your world in the cloud and it needs to be secured. Also, there will be applications that have access to the API’s which essentially could have complete access to the instances in AWS. These need to be protected and configured in a way that this access doesn’t get compromised. It’s a big subject and one that needs to be reviewed in greater detail. Lastly, understanding if you’ll be using federation services to tie back to any on-prem LDAP or other identify instance is a thought that must be understood during the design phase of the cloud implementation.

Disaster Recovery and Resiliency

Reviewing how your new cloud environment is built for disaster and resiliency is another major factor to consider when investing in AWS. Get a feel for the availability zones you’ll be hosting your environment in and where you’d like to fail in case of emergency. It’s possible to fail to availability zones in different countries and if that’s that case you should review the data laws of the country your data will no reside in afterward. For your applications and systems, there should be no single point of failure and all critical apps should have a process to make it resilient. Amazon has multiple load balancing, snapshot and synchronization services that allow a customer to keep their data available at all times.

AWS offering is deep and before investing your money into moving into their architecture a customer should have a firm understanding of both their current architecture, where they’d like to be in the future and what AWS has to offer. The options are vast and planning up front is needed for a successful implementation.


from What to Expect When Moving to Amazon’s AWS

Thursday, December 22, 2016

Post Exploit Visibility

Great article from Efflux Systems discussing post-exploitation, eliminating blind spots and improving security operations via correlation and automation. There's been a lot of talk about this subject lately and they bring a good perspective to the conv...

from Post Exploit Visibility

Wednesday, December 21, 2016

Open Season – Building Syria’s Surveillance State – Privacy International

Once again, here's some great work done by "Privacy International" revealing the Syrian governments repressive surveillance state. The report dives into how they perform surveillance, the middlemen involved and how the Assad regime has used technology ...

from Open Season – Building Syria’s Surveillance State – Privacy International

A Look Back at 2016

Here's an article I contributed to for Tripwire tying up the some of the biggest items of the year. Lots of other really good contributors on here too.

from A Look Back at 2016

Saturday, December 10, 2016

Into the Abyss – What is Upstream Surveillance?

This is infographic made by the ACLU on "Upstream Surveillance". You can read the article in it's entirety here.

from Into the Abyss – What is Upstream Surveillance?

Into the Abyss – What is Upstream Surveillance?

This is infographic made by the ACLU on "Upstream Surveillance". You can read the article in it's entirety here.

from Into the Abyss – What is Upstream Surveillance?

Wednesday, December 7, 2016

CLDAP DDoS Amplification is a Thing

Just about any protocol, if not protected properly, can be abused my attackers. We've see this recently with CLDAP being used in DDoS amplification attacks across the internet. In this article, I explain what DDoS amplification is and why leaving unnee...

from CLDAP DDoS Amplification is a Thing

Tuesday, December 6, 2016

What happens after a malicious link is clicked?

Most security teams are focused on how to stop people from clicking malicious links, which they should be, but I don't see enough thought on what should be done after a link has been clicked. Yes, we need to spend time implementing tools that will help...

from What happens after a malicious link is clicked?

Wednesday, October 26, 2016

The Digital Defenders: Privacy Guide for Kids (Comic)

Check out EDRi's "Digital Defenders guide on privacy". It's a comic directed towards kids about the benefits of privacy and security. It goes into privacy on social media, password security, smartphones and even how to use Signal and Tor all throughout...

from The Digital Defenders: Privacy Guide for Kids (Comic)