how we collaborate and share - first · how we collaborate and share wim biemolt surfcert –...

71
How we Collaborate and Share Wim Biemolt SURFcert November 14th, 2012 FIRST TC, Kyoto

Upload: others

Post on 24-Sep-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

How we Collaborate and Share

Wim Biemolt

SURFcert – November 14th, 2012

FIRST TC, Kyoto

Page 2: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Oudemirdum

Page 3: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Kyoto?

Page 4: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Collaboration!

Page 5: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SURFnet

Page 6: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Global connectivity

Page 7: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

IPv6

Page 8: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Security

Page 9: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

DNSSEC

http://www.internetsociety.org/deploy360/blog/2012/10/excellent-whitepapertutorial-from-surfnet-on-deploying-dnssec-validating-dns-servers/

Page 10: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SURFcert IDS

Page 11: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Changing threats

Page 12: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SpamPot

Page 13: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Fantastic!

Page 14: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

However …

Page 15: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Packet love

Page 16: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SNMP

Page 17: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Secret

Page 18: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

DNS

Amsterdam Nijmegen Amsterdam

onweer service LAN

Page 19: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

What is happening?

Page 20: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Abuse

Page 21: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Partners in crime

Page 22: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Report the crime

Page 23: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Very useful

Page 24: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Measures

Page 25: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

TMS

Page 26: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SURFcert

Page 27: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Party!

Page 28: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

How?

5 5

Page 29: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

netflow

Page 30: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

AIRT

Page 31: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Incidents

2010 2011 2012

(H1)

Infected 2531 6373 1948

Probe 36 41 9

Spam 2597 1379 360

Content 6 6 6

Abusive 1 19 4

Denial 807 244 106

Vulnerable 1285 997 510

TOTAAL 7263 9059 2943

Page 32: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Good job!

Page 33: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

NAT

Page 34: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Is that everything?

Page 35: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Hlux/Kelihos Botnet

0

500

1000

1500

2000

2500

6/11/201100:00

6/12/201100:00

6/1/201200:00

6/2/201200:00

6/3/201200:00

6/4/201200:00

6/5/201200:00

6/6/201200:00

6/7/201200:00

6/8/201200:00

6/9/201200:00

# unique IP addresses per hour

Page 36: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

IPv4 Heatmap

September 2012 October 2012

Page 37: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Google maps

September 2012 October 2012

Page 38: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Region

2012

Page 39: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Slow decline

Page 40: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Abuse Information Exchange

Page 41: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

2nd Hlux/Kelihos Botnet

Page 42: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Status

Page 43: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Zeus

Page 44: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Busy!

Page 45: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

IP spoofing allowed?

Page 46: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Warning by executable

Page 47: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Favor?

Page 48: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Together strong

Page 49: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SCIRT

Page 50: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Goals

Page 51: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Focus

Software audits Risk management

Juridical questions Virtualization

wifi Malware analysis

IPv6 security Forensics

Honeypot & IDS/IPS Phising

Page 52: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

MoU & TLP

Page 53: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Press

Page 54: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Dorifel

Page 55: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Zeroaccess

Page 56: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Dutch national cooperation (o-IRT-o)

Since 2002

Page 57: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Sinowal

Page 58: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

DNSSEC (again)

Page 59: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

You have them

Page 60: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

We have them

Page 61: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

TF-CSIRT

Page 62: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

CSIRT Training

Page 63: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Trusted Introducer

• Lists teams

• Accredits teams

• Certifies teams

• Trusted security services.

Page 64: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Around the world

Page 65: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

FIRST

Page 66: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

FIRST TC

Page 67: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Share!

Page 68: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Clearing houses

Page 69: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Conclusion

Page 70: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto
Page 71: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

W

Wim.Biemolt[at]surfnet.nl

wimbie

www.surfnet.nl

+31 30 2 305 305

Creative Commons “Attribution” license:

http://creativecommons.org/licenses/by/3.0/