How Hackers Infiltrate Systems

To defend your organisation against complex and simple attacks alike, think like a hacker.​.

The recent hacks and subsequent embarrassing data leaks of the Democrat National Convention and the Clinton Foundation  has demonstrated the high stakes and fragile cybersecurity ecosystem of US political campaigns. As the 2016 Presidentail general election heats up, The Takeaway, a news program produced by WNYC in New York reported that Julian Assange and Wikileaks are preparing to release another batch of hacked data.

Though attacks can be sophisticated, it's likely the DNC attacks were the result of simple spearfishing, a tactic that involves tricking an employee to open or click a link inside an email that appears to be from a trusted source. "[Spearfishing] is a relatively easy trick, and anyone, from the CEO to an entry level employee, can be duped," said Skyport Systems CEO Art Gilliland.

The campaign leaks should serve as a cautionary tale for companies big and small, Gilliland said. Many businesses, he explained, are as vulnerable as the DNC and should learn from this summer's hack attacks. "In building an effective program to protect the enterprise, companies should consider the reality of the adversary marketplace." Meaning, hackers often behave like rational actors within traditional markets.

To defend your company against complex and simple attacks alike, Gilliland said, think like a hacker. "[Kill chain] is taken from military parlance. The attack lifecycle enumerates the steps that an attacker follows to steal or damage a target asset inside a company." Although much more sophisticated attack lifecycles exist, he said, the basic kill chain process is easy to understand.

  • Think like an attacker and focus on adversary disruption.
  • Most attacks follow these steps, Gilliland said:
  • Recon - The attacker researches, profiles, and tests the environment and its people.
  • Infiltrate - Breaks in and takes positions inside the organization.
  • Discover - Uses the internal position to understand more about the environment and the surrounding systems.
  • Capture - Works to take control of the asset, typically information, that is valuable.
  • Exfiltrate - Moves the asset out, or in some cases damages the asset.
  • Monetize - Sells or uses the asset to make money or gain advantage.
  • Create identity-based perimeters for cloud services

As more organizations consume services or infrastructure from SaaS and cloud providers, the need for a different model of security becomes important. The challenge isn't that they don't deliver security, the challenge often is that they don't deliver all of the security that an organization requires. Create what Gartner calls the Cloud Access Broker. These are gateways that implement policies on the interactions between users and the cloud.

Develop individual trust zones in the cloud

The most promising new architectural approach is in the creation of individual security perimeters around every workload that runs in the data center. This approach is often referred to as micro-segmentation and represents the separation of the network trust zones into units of a single zone of trust for each application or workload.

Encrypt sensitive data

Broad use of encryption can help ensure that the data that is stolen is useless. Find technologies that can encrypt data without breaking applications. Approaches like tokenization and format preserving encryption can help to protect without breaking the existing environment. Finally, start with the stuff that really matters and work from there. It is not necessary to encrypt everything all at once. Start small, reduce risk, and move on.

"The hardest part of cybersecurity is that many of the tools used by adversaries are also used by the good guys," Gilliland said. The best way to improve defensive posture is to focus more on adversary disruption tactics and less on technical architecture. "If the adversary is profit motivated, they will likely just move on. Remember that old adage: If you are in a group chased by a bear you don't need to be faster than the bear, you only need to be faster than the others with you," he said.

TechRepublic

 

« Mass Surveillance: Cuba Filters Text Messages
Effective Drone Defence & Control »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

High Technology Crime Investigation Association (HTCIA)

High Technology Crime Investigation Association (HTCIA)

HTCIA was formed to provide education and collaboration to our global members for the prevention and investigation of high tech crimes.

Endace

Endace

Endace is a leader in network visibility, network recording and packet capture solutions for security, network and application performance monitoring.

Ergon Informatik

Ergon Informatik

Ergon Informatik AG is Switzerland's leading provider of customised software solutions and software products including fraud detection and the Airlock web security suite.

Sylint

Sylint

Sylint is an internationally recognized cyber security and digital data forensics firm with extensive experience discretely addressing some of today’s biggest cyber breaches.

Partners in Regulatory Compliance (PIRC)

Partners in Regulatory Compliance (PIRC)

Partners in Regulatory Compliance provides an array of cybersecurity services including cybersecurity policy management, risk assessments and regulatory compliance consulting.

Octiga

Octiga

Octiga is an office 365 cloud security provider. It offers Office 365 monitoring, incident response and recovery tools.

Dashlane

Dashlane

Dashlane puts all your passwords, payments, and personal info in one place that only you control. So you can use them instantly. Securely. Exactly when you need them.

Cardonet

Cardonet

Cardonet is an IT Support and IT Services business offering end-to-end IT services, 24x7 IT Support to IT Consultancy, Managed IT and Cyber Security.

Cyber Security Services

Cyber Security Services

Cyber Security Services is a cyber security consulting firm and security operations center (SOC).

IntegraONE

IntegraONE

IntegraONE is a IT solutions provider offering a full range of networking and technology solutions.

Avetta

Avetta

Avetta One is the industry’s largest Supply Chain Risk Management (SCRM) platform. It enables clients to manage supply chain risks and suppliers to prove the value of their business.

McKinsey & Company

McKinsey & Company

McKinsey & Company is a global management consulting firm. We are trusted advisor to the world's leading businesses, governments, and institutions.

Queen Consulting & Technologies

Queen Consulting & Technologies

Queen Consulting & Technologies specialize in providing IT support, management, and Security to Gov’t Contractors, CPAs, and Nonprofits.

rThreat

rThreat

rThreat is a cloud-based SaaS solution that challenges your cyber defenses using real-world and custom threats in a secure environment, ensuring your readiness for attacks.

DataTrails

DataTrails

DataTrails enables organizations to prove and verify the provenance and authenticity of any data they use in their business operations.

Vonahi Security

Vonahi Security

Vonahi Security is a cybersecurity SaaS company that pioneered automated network penetration testing.