Showing posts with label security news. Show all posts
Showing posts with label security news. Show all posts

Friday, October 26, 2007

Marketers should strategize for data loss prevention.

As data loss continues to grow, prevention is a serious issue for companies, according to a new report by e-mail services firm Ironport Systems Inc.

In a new report titled “Data Loss Prevention Best Practices, Managing Sensitive Data in the Enterprise,” IronPort Systems, a business unit of Cisco, delineates best practices that companies can use to prevent leaks and to be compliant.

“We are seeing more and more complications in being compliant with data loss prevention,” said Tom Gillis, SVP of marketing at IronPort Systems. “We focus on data in motion, or data that is transferred over the Internet and came up with a set of best practices for companies to follow to make sure that their information is not being stolen.”

Whether it’s e-mail, instant messaging, a Web site form or a file transfer, electronic communications that are unmonitored have the potential for confidential information to be stolen. To address these issues, Ironport created a best practices checklist to help marketers deal with these systems.

The first step towards solving the data loss problem is to develop an understanding and inventory of the types of sensitive data that exist within the organization and what policies are needed to control and enforce how that data can be shared.

Secondly, the report urges marketers to focus on all areas of data loss prevention starting with the most vulnerable areas.

In addition, the report encourages marketers to use data loss prevention software that tracks policy violations and includes multi-protocol monitoring and prevention, content-level analysis of all major file and attachment types, selective blocking and/or quarantining of messages and automatic enforcement of corporate encryption policies. This software should be unobtrusive, so that consumers need not concern themselves with any extra steps.

Finally, according to the report, a data loss prevention platform should include detailed reports of all suspected violations. Administrators and policy officers should have the ability to receive reports outlining detected violations including information such as the message sender, contents, attachments, intended recipients and information about the violating content.

Monday, October 22, 2007

BotNet - one day in the life.

A bot network tends to fluctuate such that the number of members of the network wax and wane over time. I base this understanding on my regular observation of modern botnets and the observations of my peers (please see pg. 41 of ISTR Volume X). In the past, IRC protocol-based botnets fell victim to an “Achilles Heel” situation if the single central server being used to control the network was taken down, because the network without a controller would fall apart.

The miscreants that choose to build and control these bot networks began to develop innovative methods that could bolster their reliability. With this goal, Fast-flux DNS tactics were employed to provide redundancy so that these networks were more difficult to take down. Trojan.Peacomm (also known as “Storm Worm”) employed the Overnet protocol – a robust, decentralized, peer-to-peer network that is based on the Kademlia algorithm.

However, all of these advancements in bot network technology still do not make the network bulletproof. These advancements do not protect the botnet from bot losses that occur because the bot-infected computer is taken offline or the infection is detected by antivirus and cleaned. There is little question that Trojan.Peacomm is a sophisticated peer-to-peer bot network that is difficult to disable completely, but it cannot be immune to property fluctuations. Perhaps this is why some of the static numbers for the Peacomm network size are so difficult to digest. According to MessageLabs there are 2 million bots. (They are quoted as reporting that at 2 million bots, it is operating only at 10% capacity, implying that the true size is 20 million bots. This article also goes on to report observations of 50 million Peacomm bots.) A botnet of 20 million bots was also reported on zdnet.com. Are these metrics based on active bot infected computers? Or, on a cumulative total that was observed since Peacomm was first detected?

Personally, I believe in applying Occam’s Razor when estimating the size of a given botnet. It is better to assume nothing about the current size of the network and instead gauge the network size based only on the number of active bots that can be observed for a period of time where the network size is least likely to fluctuate. According to the recently published Symantec Internet Security Threat Report (pg. 47), "The average lifespan of a bot-infected computer during the first six months of 2007 was four days, up from three days in the second half of 2006." This means that an accurate metric for a given bot network, if all of the bots join the network at exactly the same time, at very best can remain accurate for only four days. In reality the bot network will constantly fluctuate, so metrics for longer periods should at least be graphed at points over time to represent this fluctuation.

The "snapshot" approach, where activity is observed only for a reasonable period of time, should deliver a more accurate picture of the known and verifiable state of the botnet at that point in time, but only at that point. It will likely be a partial image, but it is based on accurate and verifiable activity. If many of these “snapshots” are taken, it might provide a more accurate impression of the bot network when graphed. For a dynamic network that can radically change in size from week to week, estimating the size of that network based on a cumulative number generated based on observed IPs over a long period of time might yield an inaccurate perception of the studied network.

Other researchers are reporting lower metrics for Peacomm network size than the 20 million nodes figure. For example, Secure Science Corp report an average of just over 53,000 active Peacomm bots at 7:00 a.m. ET, October 1, 2007. Secure Science Corp used the “snapshot” approach to graph metrics for the Peacomm network over the period of a week, and the undulating metric is fascinating.

Microsoft’s anti-malware team also reported lower metrics. In a recent blog they discuss that Peacomm ranks in only third for the total malware cleaned by the Microsoft anti-malware team. They also report a component of Peacomm was detected on 274,372 computers as of September 18, 2007, at 2:00 p.m. PDT.

Symantec’s DeepSight Threat Analyst Team decided to use this "snapshot" approach in order to gather a geographical picture of a 24-hour period of Peacomm spam activity. Based on spam messages that were captured over a 24-hour period by Symantec antispam sensors on August 18 and September 18, 2007, we observed 4,375 unique Peacomm IPs for August 18; 2,131 of these IPs were acting as Peacomm SMTP servers and 2,244 IPs were acting as Peacomm HTTP servers (these are the servers that serve exploits and Peacomm binaries to innocent victims, as well as Peacomm propagation spam). Contrast that with 6,081 unique IPs for September 18, 2007, with 3,408 SMTP IPs and 2,673 HTTP IPs. Given those two sample sets, only 1,610 IPs intersect. So, for just a month’s time-span we observed a respectable fluctuation in Peacomm IP metrics, reinforcing the understanding that the Peacomm network is consistently in a state of fluctuation.

This Peacomm snapshot was mapped based on the geo-location of the involved IP addresses and an interesting image developed. It seemed that English-speaking countries were most affected by the Peacomm activity. Based on conjecture, this could be because the majority of Peacomm spam is delivered in the English language, but this has not been verified and other factors are definitely involved. (Note: That the markers on the below map represent groups of IP addresses that are related geographically.)

I am sure that the debate about the Peacomm network size will rage on for some time, but I feel that we have to maintain some degree of sensibility before hysteria-inducing claims, such as “Storm worm more powerful than top supercomputers” can be proclaimed. Given the nature of Peacomm, an exact size metric is difficult to derive, although it is important that this is known. Peacomm presents an interesting enigma with regards to the size of the network. On one hand, many researchers (including myself) agree that it is indeed a large network given the sophistication of Peacomm. On the other hand the Peacomm network is impacted by daily bot losses as computers are disinfected or taken offline. My initial research suggests that the network is smaller than some think, leading me to believe that, at least currently, the Peacomm network size is closer to the more conservative estimates that are being published.

Thursday, October 18, 2007

6 hot items on the hacker's holiday shopping list

Here, according to Jackson and Schipka, are some the items likely to be in high demand by hackers shopping in this underground marketplace this coming holiday season:

1. Build A Storm Botnet: This new and uniquely crafted malware tool has been designed with the really high-end hacker in mind and is likely to be one of the hottest items this season, according to Jackson. For prices starting at $100,000, spammers and other malicious attackers can now buy their very own Storm botnet, complete with fast flux DNS and hosting capabilities. Making it possible is a smart new 40-byte encryption feature supported on the latest Storm variants that hackers can basically use to segment compromised machines into their own little Storm botnets.

"Think of this as an FAO Schwarz kind of item," Jackson says. "Rather than leasing a botnet service and paying bot by bot for a good e-mail run or iFrame blast, you can pay for it all at once and have your own little Storm botnet ," Jackson said. The people who would buy such services are those who have already made their loot using leased services and are looking to start owning infrastructure, he said.

2. Rent-A-Bot services: Who needs to buy a botnet when you can lease a perfectly good one by the hour at a fraction of the price? Available in abundance this season, such botnet services are designed to let average spammers deliver a gazillion copies of their malware without them having to invest in the infrastructure needed to do so, Schipka said. For as little as $100 to $200 per hour, spammers can get access to a fully functional botnet capable of delivering the finest image spam and body part enhancement ads to millions at the click of a button, he said.

And such rent-a-bots aren't just for spammers anymore, Jackson said. What makes these versatile services so broadly appealing to bad guys is that they can be easily adapted to deliver the malware of choice or to launch distributed denial of service (DDOS) attacks against extortion targets. One example is the BlackEnergy botnet, which can be used to launch DDOS attacks against specific targets for about $80 per hour, according to Jackson. For those not willing to spend even that much, low-cost options starting at $10 per hour for one million bots are readily available for conveniently distributing smaller spam loads and malware.

All an enterprising hacker needs to take advantage of such services is a plan, Schipka said. "You would need to figure out your business model and draw up a business plan," he said. "If you were renting a bot for three hours at a $100 per hour to deliver spam it means you need to make more than that to benefit from the use of the service." If it's some other sort of malware being seeded via a botnet -- such as a keylogger or Trojan -- the cost of purchasing the code would have to be included as well, Schipka he said. "...They'd need to be looking for a botnet with the highest quality and the lowest amount of money."

3. Ye Olde Malware tools: Do-it-yourself enthusiasts have a wider range than ever before of malware tools, including Trojans, zero-day exploits, rootkits, spyware programs and keyloggers, according to Jackson and Schipka. For around $3,000 to $3,500, serious shoppers can find sophisticated polymorphic malware capable of delivering all sorts of nasty code on vulnerable computers while constantly morphing to evade detection. Variants can be purchased separately for less than $10 on average to about $20 a piece. In some cases, variants can be delivered at the rate of one new variant every 59 minutes, or precisely one minute less than the hourly cycles many anti-virus vendors use to push out new virus signatures, said Schipka.

Likely to be in high-demand are customized Trojan programs specifically designed to steal identity and patient data from systems belonging to health care providers, Jackson said. Current black-market rates for this kind of ID information, which is typically used to defraud health insurers, is about $200 per patient profile.

In the stocking stuffer class are tools such as the Webattacker malware creation kits, exploits from sites such as WabiSabiLabi and numerous one-click phishing kits available from groups such as the Russian Business Network, Jackson said.

4. Data providers: These consumer-friendly service providers are targeted at intrepid entrepreneurs looking to use someone else's identity and financial information for their own gain. As an industry niche that's been around longer than many others, data providers today cater to a wide-ranging audience with disparate needs. Some specialized services offer identity information, complete with driver's license photos, passport scans, credit card numbers, e-mail and street addresses -- all for as little as $5 a pop, according to Schipka. At the higher end, health-care related identity data or information belonging to high-level corporate executives can go for nearly $200 per victim. And then there are services that let individuals buy stolen credit card data at between 2% to 4% of the credit balance left on the cards, Schipka said.

5. Drop services: These specialized services have been developed expressly for the harried online shopper who purchases items online -- especially high-ticket electronics gadgets -- with stolen credit cards but has no place to send them. Drop services can provide thieves with convenient and reliable addresses to mail stolen goods in the country from where the online purchase is made, Schipka said. "Sometimes, these are people who know they are receiving stolen goods," he said. "Sometimes, they just sort of receive these parcels and either send them somewhere else or make them available in person" to pre-specified locations. People in the latter category don't often know they are handling stolen goods and are hired via phony work-at-home advertisements that promise to pay them specific amounts of money for simply receiving and forwarding goods, he said. Drop services typically get the stolen goods for about 30% or less of the retail value of the product, he said.

6. Escrow, anyone? Forget all those quaint notions about honor among thieves. In the online underground, it's more often about scammers looking to scam other scammers, Schipka said. That's where referrals and escrow services can play a key role, he said. For fees ranging from about 2% to 4% of the total transaction, service providers will act as a "trusted" intermediary between a seller and buyer of malware and other illegal services. Such services can hold purchase money in escrow until a buyer has had a chance to see whether the goods or services are okay and performing as billed. And sellers are assured they get paid for delivering what they promised, Schipka said.