Showing posts with label advanced persistent threat. Show all posts
Showing posts with label advanced persistent threat. Show all posts

Tuesday, June 7, 2011

APTs: So What if you ARE a Target?

This blog post continues the discussion from last month, which examined Advanced Persistent Threats, or APTs.  You can find it here.

So if leading technology companies can't stop an APT, what chance do you have against defending against it?  The unfortunate answer is: not much.

An interesting article from DarkReading.com discusses what you should know about detecting a targeted attack, and goes over the methodology an attacker might use to probe a company for weaknesses.  Rightfully so, the article discusses the human vulnerabilities inherent to every company, saying: “Detecting attacks attempting to exploit human assets is often nearly impossible without regular training and awareness. You can't install Snort on your CEO and CFO.”  This is a great point – if your company is specifically targeted by an attacker and your network is secure, the attacker will naturally turn to social engineering, custom malware, or spear phishing in an attempt to gain a foothold.  Some tools can offer limited assistance here, but none surpass user awareness.

To that point, you should make an effort to check out the online tools that your users frequent - Facebook, Gmail, Craigslist, and LinkedIn for example.  These all have good resources that explain how to control privacy of information, as well as tips to avoid scams common to these applications.  These pages can typically be located within a few clicks and are well worth the effort to find.  Make it a point to compile and send these tips to your users on a regular basis.

Your users are, by far, your biggest security liability.  Instituting a sound security policy, coupled with user training, is a must.  Your security policy is your IT security playbook: user-oriented policies, and training about these policies, will act to "harden" your users just as you might harden your network perimeter.

If you don't already have a security policy, check out www.InstantSecurityPolicy.com, which can help you obtain a custom set of security policies in minutes.

Tuesday, May 24, 2011

With the Rise of APTs, Security Policies are More Important Than Ever

Recently, much has been made of a "new" attack known as the Advanced Persistent Threat (APT) due to recent attacks on RSA, Google, Adobe Systems, and others.  APTs are not new, but they can be by far the most damaging attack.  So what can you do to stop them?  First let's go over the basics:

Just What Exactly Is an Advanced Persistent Threat?


An APT is by far the most difficult type of attack to stop.  It combines multiple, sometimes zero-day, vulnerabilities, social engineering, spear phishing, and offline techniques into a long-term and carefully crafted attack.  There is an objective to these attacks – they are not smash-and-grab hits where attackers look for anything of value.  Anyone using an APT is after the “crown jewels” of a company: intellectual property, massive stores of customer or credit card data, classified information, product blueprints, source code, etc.  The attacks move laterally through a network, and can be difficult, if not impossible, to detect.  The attacker will have a long-term horizon, sometimes staying in a network for years, searching for its target. 

The good news, if there is any, is that these attacks are relatively rare.  Due to their complexity and cost, targets of APTs seem to be limited to very large corporations and government entities.  These aren’t the script kiddies of old, but sophisticated criminal or governmentally-funded entities, which is exactly what makes these attacks so devastating.  The only way to combat them is to:
  • Institute tight security controls and good coding practices on your public servers.
  • Perform vulnerability assessments to find systems that may allow code injection.
  • Monitor your network with an IDS and review system logs, tracking down any suspicious entries. 
  • Perhaps most importantly: educate your users on secure web and email practices, through the development and implementation of a solid security policy.

Unfortunately, the new challenge of IT Security involves protecting your network from unpredictable and blended threats that can come from anywhere – not just those that come through the front door.  APTs will likely become more prevalent as the costs and complexity of these attacks decrease with advances in technology.

If you don't already have a security policy, check out www.InstantSecurityPolicy.com, which can help you obtain a custom set of security policies in minutes.  Coming soon: "So What if You Are a Target?"