sans critical security controls summit london 2013

70
Presenting a Hard Target To Attackers Wolfgang Kandek CTO, Qualys Inc SANS Critical Security Controls 2013 London, May 1, 2013

Upload: wolfgang-kandek

Post on 27-Nov-2014

430 views

Category:

Documents


1 download

DESCRIPTION

Present a hard Target to Attackers

TRANSCRIPT

Page 1: SANS Critical Security Controls Summit London 2013

Presenting a Hard Target To Attackers

Wolfgang KandekCTO, Qualys Inc

SANS Critical Security Controls 2013

London, May 1, 2013

Page 2: SANS Critical Security Controls Summit London 2013
Page 3: SANS Critical Security Controls Summit London 2013
Page 4: SANS Critical Security Controls Summit London 2013

Defense

Page 5: SANS Critical Security Controls Summit London 2013

Threat Intelligence

Page 6: SANS Critical Security Controls Summit London 2013

Public Threat Intelligence

Page 7: SANS Critical Security Controls Summit London 2013

2012 – Data breaches in the news

Page 8: SANS Critical Security Controls Summit London 2013

2012 – Data breaches in the news

Page 9: SANS Critical Security Controls Summit London 2013

2012 – Data breaches in the news

Page 10: SANS Critical Security Controls Summit London 2013

2013 – started in a similar way

Page 11: SANS Critical Security Controls Summit London 2013

2013 – started in a similar way

Page 12: SANS Critical Security Controls Summit London 2013

2013 – started in a similar way

Page 13: SANS Critical Security Controls Summit London 2013

2013 – started in a similar way

Page 14: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 15: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 16: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 17: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 18: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 19: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 20: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 21: SANS Critical Security Controls Summit London 2013

Industry Reports

Page 22: SANS Critical Security Controls Summit London 2013

Traditional Tools Are Failing

Page 23: SANS Critical Security Controls Summit London 2013

Attacker CompetenceIs Rising

Page 24: SANS Critical Security Controls Summit London 2013

Attacker CompetenceIs Rising

Page 25: SANS Critical Security Controls Summit London 2013
Page 26: SANS Critical Security Controls Summit London 2013
Page 27: SANS Critical Security Controls Summit London 2013
Page 28: SANS Critical Security Controls Summit London 2013

78 %

Page 29: SANS Critical Security Controls Summit London 2013

• Open System Administration Channels

• Default and Weak Passwords

• End-user has Administrator Privileges

• Outdated Software Versions

• Non-hardened Configurations

=> Flaws in System Administration

VZ DBIR Background Info

Page 30: SANS Critical Security Controls Summit London 2013

“We were getting owned through our users that were running IE with

admin privileges”

Page 31: SANS Critical Security Controls Summit London 2013
Page 32: SANS Critical Security Controls Summit London 2013
Page 33: SANS Critical Security Controls Summit London 2013
Page 34: SANS Critical Security Controls Summit London 2013
Page 35: SANS Critical Security Controls Summit London 2013
Page 36: SANS Critical Security Controls Summit London 2013
Page 37: SANS Critical Security Controls Summit London 2013

90 %

Page 38: SANS Critical Security Controls Summit London 2013
Page 39: SANS Critical Security Controls Summit London 2013

39

Page 40: SANS Critical Security Controls Summit London 2013
Page 41: SANS Critical Security Controls Summit London 2013
Page 42: SANS Critical Security Controls Summit London 2013
Page 43: SANS Critical Security Controls Summit London 2013
Page 44: SANS Critical Security Controls Summit London 2013
Page 45: SANS Critical Security Controls Summit London 2013
Page 46: SANS Critical Security Controls Summit London 2013

85 %

Page 47: SANS Critical Security Controls Summit London 2013

85 %of past incidents prevented

Page 48: SANS Critical Security Controls Summit London 2013

• About 5000 seats

• Data Breach

• 6 month security project

• Fully Patched in 2 weeks

• Admin rights controlled

• Whitelisting

• No Additional Software purchased

• No Enduser Impact

DIISRTEDepartment of Industry, Innovation, Science, Research and Tertiary Education

Page 49: SANS Critical Security Controls Summit London 2013

20 %

Page 50: SANS Critical Security Controls Summit London 2013

20 %327 malwares

Page 51: SANS Critical Security Controls Summit London 2013

20 %327 malwares

262 bypassed AV

Page 52: SANS Critical Security Controls Summit London 2013

20 %327 malwares

262 bypassed AV

Page 53: SANS Critical Security Controls Summit London 2013

Implementation

Page 54: SANS Critical Security Controls Summit London 2013

Implementation

Page 55: SANS Critical Security Controls Summit London 2013

Score: Use a letter grade system

Page 56: SANS Critical Security Controls Summit London 2013

Score: Use a letter grade system

Page 57: SANS Critical Security Controls Summit London 2013

Score: Use a letter grade systemor other mechanisms

Page 58: SANS Critical Security Controls Summit London 2013

Score: Use a letter grade system

Page 59: SANS Critical Security Controls Summit London 2013

Results

Page 60: SANS Critical Security Controls Summit London 2013

Opportunistic Attackers

Page 61: SANS Critical Security Controls Summit London 2013

Opportunistic Attackers

Page 62: SANS Critical Security Controls Summit London 2013

Targeted Attackers

Page 63: SANS Critical Security Controls Summit London 2013

Targeted AttackersDisrupt, Slow Down

Page 64: SANS Critical Security Controls Summit London 2013

Targeted AttackersDisrupt, Slow Down,

Raise Cost, Force Mistakes

Page 65: SANS Critical Security Controls Summit London 2013

Information

Page 66: SANS Critical Security Controls Summit London 2013

US DoS, DIISIRTE,NASA, DHHS-CMS,GS, OfficeMax…

Page 67: SANS Critical Security Controls Summit London 2013
Page 68: SANS Critical Security Controls Summit London 2013
Page 69: SANS Critical Security Controls Summit London 2013

• Microsoft Security Intelligence Report v14

• Verizon Data Breach Investigation Report

• Kaspersky Lab – Evaluating the Threat Level of Software Vulnerabilities

• Symantec – Empirical Study of Zero-day attacks

• Mandiant Intelligence Center APT1

• South Carolina Data Breach Incident Report

• FireEye Advanced Threat Report

References

Page 70: SANS Critical Security Controls Summit London 2013

Thank You

Wolfgang [email protected]

@wkandekhttp://laws.qualys.com