Showing posts with label #ComptiaSecurityPlus601. Show all posts
Showing posts with label #ComptiaSecurityPlus601. Show all posts

Thursday, 11 May 2023

Enterprise Mobile Security


Introduction

Mobile has become our an additional finger which knows all most of sensitive information. Leading this makes it very much important to secure and especially for enterprise. The mobile device has different composition regular computer, embedded in nature makes it bit more challenging in securing.

Communicating Methods

Communication between from one mobile to another mobile is through electro magnetic waves (zero and one) but the mobile itself does not have the capability to transfer through long distance. Hence mobile devices can communicate using different methods such as Cellular Network - (5G which is the fifth generation of cellular wireless standards providing capabilities beyond 4G), Bluetooth, Wi-Fi, Near field communications and so on. There are various security concerns with this, i.e., Traffic monitoring, Location tracking, Wide access to mobile devices. Let's look into each of these methods.

Cellular Network

  • Cellular network or also known as mobile network, are the main mode of the communications, which connects to and from end nodes through the service provider network.  
  • Each phone communicates with the service provider by radio waves through a local antenna at a cellular base station or cell site. The cellular consists of below components:

Credits: https://www.electroschematics.com/wp-content/uploads/2010/03/Mobile-Communication.png

  • Cellular Layout
    • Mobile network is divided into different geographical areas known as cells. This geographical are is divided hexagonal cells - an antenna coverages a cell with certain frequencies. 
    • Each cell has a transceiver - mobile tower that make a wireless connection to the mobile device and the base station is a land station in the land mobile service below the tower. Both serves the similar purpose to produce network signals to the consumers.
    • Base Station
      • Base stations provide the cell with the network coverage and connects with the tower, which can be used for transmission of voice, data, and other types of content.
      • The base stations are meant to improve the signal frequency and communication between interconnected devices such as computers or smartphones.
    • Tower
      • Tower is where the antennas and electric communications equipments are placed to create a cell or adjacent cells.
      • The cell towers distributes the signals are generated by the base station. 
    • All base stations and towers in a city are connected via a high-speed link or fibre optics to a mobile telephone switching office (MTSO). 
  • Mobile Tower Switching Office
    • Our mobile has not enough signal powers to directly call a caller residing in another city hence it sends signals to a mobile tower. 
    • The mobile tower then sends signals to MTSO. MTSO check our sim data in its database to find the cell in which the phone is present  and send a signal to another city MTSO. Then MTSO sends signals to mobile through the mobile tower.
    • MTSO is normally located in the central cell of a cluster and is generally connected to the Public Switched Telephone Network (PSTN).
  • Public Switched Telephone Network - PSTN
    • A public switched telephone network is a combination of telephone networks used worldwide, including telephone lines, fiber optic cables, switching centers, cellular networks, satellites and cable systems. 
    • PSTN is a century-old worldwide connected telephone network and lets users make landline telephone calls.
  • Common security concerns
    • Traffic monitoring
    • Location tracking
    • DDOS attacks
    • Access fraud
    • Stolen phones
    • Subscription fraud
  • Security measures
    • Network Traffic Monitor and Analysis
    • Encrypted communication
    • Velocity Checking
    • A subscriber usage-pattern database 
    • Customer call analysis 
    • Geographic dispersion checking 
    • Extensive proprietary antifraud algorithms 
  • Below site explains in detail about different fraud and solutions in cellular network
    • https://csrc.nist.gov/csrc/media/publications/conference-paper/1997/10/10/proceedings-of-the-20th-nissc-1997/documents/031.pdf

Wi-Fi 

  • Wi-Fi is the family of wireless network protocols, commonly used for local network access. Wi-Fi stands for Wireless Fidelity.
  • Wi-Fi uses radio frequency.
  • An internet connection shared with multiple devices within certain range via wifi router. This router is connected directly to the internet modem and acts as a hub to broadcast the internet signal to all your Wi-Fi enabled devices.
  • Wifi repeaters, is used to extend the length of the existing network.
  • Common security concerns
    • Data capture: Need to Encrypt data
    • On-path attack: Always Monitor data
    • Denial of service: Monitor unwanted traffic which is calling the frequency interference
  • Security measures
    • Wired Equivalent Privacy (WEP) encryption was designed to protect against casual snooping but it is no longer considered secure. Later WPS - Wi-Fi Protected Setup, WPA - Wi-Fi Protected Access and WAP2 were introduced, which is also not secure now.
    • In 2018, WPA3 was announced as a replacement for WPA2, increasing security and enabling secure authentication on the wireless router. 
    • WPA3-Personal
      • WPA3 with shared key where everyone uses same key
    • WPA3-PSK
      • Using WPA3 session key is derived from PSK using SAE (Simultaneous Authentication of Equals) to provide stronger defences against password guessing.
      • This allows the access provider and station peers to authenticate each other as part of the handshake process while using cryptographic tools to prevent an attacker from performing an offline password cracking scheme.
  • As like Cellular networks, W-Fi internet access has become much more embedded in society. 


Li-Fi

  • Li-Fi stands for Light Fidelity.
  • LiFi technology will allow us to connect to the internet using light from lamps, streetlights or LED televisions. 
  • Li-Fi uses infrared light or via LED to transmit data.
  • In addition to being cheaper, safer and faster than wifi, it does not need a router and just requires to point your mobile or tablet towards a light bulb to surf the web.
  • Common security concerns
    • Jamming
    • Spoofing
    • Data modification
    • Inability to work without light
  • Security measures
    • LiFi technology is widely considered to be generally more secure than WiFi. 
    • Plenty of security features can be embedded in LiFi systems in order to make them more secure as light cannot pass through walls like radio waves and it carries more volume of data at a time.
    • Encryption
    • Monitoring


Bluetooth

  • Bluetooth wireless technology is a short range communications technology intended to replace the cables connecting portable unit and maintaining high levels of security. 
  • Bluetooth uses a spread-spectrum, frequency-hopping, full-duplex signal.
  • An antenna-equipped chip in each device that wants to communicate sends and receives signals at a specific frequency range defined for short-range communication.
  • For Bluetooth devices to communicate, they pair with each other to form a personal area network (PAN), also known as a piconet.
  • This process is done through discovery, with one device making itself discoverable by the other device. 
  • Bluetooth is a common mobile connectivity method because it has low power consumption requirements and a short-range signal. 
  • Point to Point
    • One-to-one connection, conversation between two devices
  • Point to Multi Point
    • One of the most popular communication methods 802.11 wireless.
    • Multipoint doesn’t necessarily mean that you can stream media from two devices at a time.
  • Common security concerns
    • Bluejacking
      • Sending of unsolicited messages to another device via Bluetooth
    • Bluesnarfing
      • Access a bluetooth enabled device to access data from the device.
      • Security has been patched in the latest devices
  • Security measures
    • Update with latest patches
    • Monitoring
    • Encryption


RFID

  • Radio Frequency Identification (RFID) refers to a wireless system comprised of two components: tags and readers. The reader is a device that has one or more antennas that emit radio waves and receive signals back from the RFID tag.
  • Uses radar technology
    • Radio energy is transmitted
    • Bidirectional communication
  • There are two types of RFID tags: active and passive tags. An active tag can broadcast a signal over a larger distance because it contains a power source. A passive tag, on the other hand, isn’t powered but is activated by a signal sent from the reader.
  • Common security concerns
    • Data capture
    • Spook reader
    • Signal jamming
    • Decrypt communication
  • Security measures
    • Cryptography is primary
    • Blocker tags, prevent unauthorized readers
  • Commonly used as geofencing security measure, radio-frequency identification (RFID) to define a geographic perimeter, when the device enters of exits alerts are sent.


NFC

  • Near-field communication (NFC) is a set of standards for contactless communication between devices. NFC chips in mobile devices generate electromagnetic fields. This allows a device to communicate with other devices. 
  • NFC is extension of RFID technology.
  • Near-field communication transmits data through electromagnetic radio fields to enable two devices to communicate with each other. To work, both devices must contain NFC chips, as transactions take place within a very short distance. 
  • NFC-enabled devices must be either physically touching or within a few centimetres of each other for data transfer to occur.
  • NFC began in the payment-card industry and is evolving to include applications in numerous industries worldwide.
  • The NFC standard has three modes of operation: 
    • Peer-to-peer mode: Information shared exchanged between two mobile devices directly.
    • Read/write mode: An active device receives data from a passive device. 
    • Card emulation: The device is used as a contactless credit card. It emulates a payment card or other physical card in card readers, magnetic-stripe readers, and contactless card readers used to make payments directly from your mobile device.
  • Common security concerns
    • Remote capture
    • Frequency jamming
    • On path attack
    • Lost of NFC device control - digital pickpocketing
  • Security measures
    • Encryption
    • Always patch up-to-date
    • Turn-off when not in use 


Mobile Networks

Mobile networking has evolved significantly since the introduction of the first-generation (1G) mobile network in the 1980s. G refers to Generation. Each Generation is defined as a set of telephone network standards, which details the technological implementation of a particular mobile phone system.
Credits: https://www.techindulge.com/technovation/1g-2g-3g-4g-and-5g-wireless-phone-technology-explained-meaning-and-differences/

1G

  • 1G is the first generation of wireless cellular technology. 
  • 1G supports voice only calls.  
  • 1G is analog technology
  • The maximum speed of 1G is 2.4 Kbps.

2G

  • Changed from analogue (1G) to Digital (2G).
  • Ability to send SMS (Short Message Service) and plain text-based messages.
  • GSM and CDMA was introduced during this period.
  • The maximum speed of 2G with General Packet Radio Service (GPRS) is 50 Kbps. The max theoretical speed is 384 Kbps with Enhanced Data Rates for GSM Evolution (EDGE).
  • Before making the major leap from 2G to 3G wireless networks, the lesser-known 2.5G and 2.75G were interim standards that bridged the gap to make data transmission.

3G

  • Enabled web browsing, email, video downloading, picture sharing and so on.
  • The maximum speed of 3G was around 2 Mbps for non-moving devices and 384 Kbps in moving vehicles. 

4G

  • Applications include amended mobile web access, IP telephony, gaming services, high-definition mobile TV, video conferencing, 3D television, and cloud computing. 
  • The max speed of a 4G network when the device is moving is 100 Mbps. The speed is 1 Gbps for low-mobility communication such as when the caller is stationary or walking.

5G

  • 5G promises significantly faster data rates, higher connection density, much lower latency, and energy savings, among other improvements.
  • 5G offers data transfer rates of up to 20 Gbps, it allows users to download ultra-high-definition videos and access the internet at lightning-fast speeds. 
  • Also offers lower latency, better network coverage, and improved call quality.

Wireless Carriers

Wireless carrier means the cellular technology company that provides mobile telecommunication services for a Supported Device.

CMDA

  • CDMA stands for Code Division Multiple Access. 
  • It is handset-specific.
  • CDMA is not very common, and it is available in comparatively fewer carriers and countries. These devices are exclusive to Canada, Japan, and the United States.
  • The CDMA technology does not support any such feature. It cannot transmit voice and data simultaneously.
  • CDMA is faster, provides better security and has comes with built in encryption.

GSM

  • GSM (Global System for Mobile) standard in Finland was launched by AT&T. Every device uses SIM (Subscribers Identity Module) to communicate with the provider network.
  • GSM is highly available and globally used. Over 80% of the entire world’s mobile networks use it.
  • It uses the Time division multiple access (TDMA) and Frequency division multiple access (FDMA).
  • GSM supports the transmission of both voice and data at once.
  • GSM is slower, less secure and no default encryption compared to CDMA.

LTE

  • Long-Term Evolution (LTE) is used for faster data transfer and higher capacity. Different variations of LTE networks exist across carriers that use different frequencies. For example Sprint, T- Mobile, Verizon, and AT&T all have their own bands of LTE.
  • LTE moves large packets of data to an internet protocol system (IPS). Old ways of moving data used Code-division multiple access (CDMA) and the Global System for Mobile Communications (GSM), and those methods moved only small amounts of data.
  • LTE and 4G simply evolved together, with LTE is industry standard that describes the particular type of the forward edge of the fourth generation’s advancement.
  • 4G LTE functionality has two key preconditions: a network that supports the ITU-R (ITU Radiocommunication Sector) standard speeds and a device powerful enough to match and handle the speeds of that network. 
  • GSM and CDMA all switched to LTE as global 4G standard. As CDMA and GSM, are inefficient uses of the airwaves.

SATCOM

  • For users who lack traditional landline or cellular coverage, satellite communication (SATCOM) is an option for mobile device use. 
  • SATCOM uses an artificial satellite for telecommunication that transmits radio signals. 
  • It can cover far more distance and wider areas than most other radio technologies. 
  • Because satellite phones do not rely on phone transmission lines or cellular towers, they function in remote locations. 
  • Most satellite phones have limited connectivity to the Internet, and data rates tend to be slow, but they come with GPS capabilities to indicate the user’s position in real time. 


Mobile Management

  • Mobile Device Management
    • Managing mobile device access and usage in an organization is a security challenge to achieve. 
    • Manage the company owned or user owned mobile devices centrally. 
    • Set policies on apps, camera, data, access and so on.
    • Access control such as force screen locks, multi factor authentication, remote wipe, geofencing will be part of MDM.
  • Mobile Content Management
    • Secure the content present in the mobile device is role of Mobile Content Management - MCM. 
    • Monitoring and restriction on the file sharing, online content viewing and uploading.
    • Centrally manage the data in cloud using solutions such as Microsoft Office 365.
    • Any data which sent or receives from mobile devices should go through DLP - Data Loss Prevention - preventing any sensitive information leakage.
    • Data on the device needs to be encrypted.
    • Restrict and block external or removable drives.
  • Mobile Application Management
    • Not all applications are secure some are malicious, managing mobile apps is quite tough.  
    • Any new application installed should be managed through Mobile Application Management - MAM and only allowed apps could be installed. 
    • Not all the applications dangerous but still are not required for the business, such as games and social media apps - these applications would be denied for installation.
  • Unified Endpoint Management - UEM
    • Evolution of MDM, manages mobile and non mobiles.
    • End users can use different types of devices, and it could be blended together.
    • Applications can be used across different platforms.


Mobile Protection Measures

  • Remote wipe
    • Managed by MDM, removes all the data from the device whenever required usually during theft.
    • Make sure essential data is properly backed up.
  • Geolocation
    • Location tracking system
    • Used during commute, cross border alerts, find phone
  • Geofencing
    • Restrict mobile feature or features when the device is present in particular location.
    • Authenticate and allow login when the device is located in particular area.
  • Screen lock
    • Locking the mobile using PIN, Passcode, Pattern and Biometerics.
    • Auto lock after configured time.
    • Erase data after few invalid entries.
  • Push notification services
    • Information popup service on the screen.
    • Receives notifications even when the phone is idle or using different application.
  • Passwords and Pins and Biometrics
    • Mobile devices can have multi authentication based on the apps used.
    • Password rotation, reset, complexity policy handled through MDM.
  • Context aware authentication
    • Switch to multi level authentication during abnormalities observed or different pattern followed.
    • Example, access through different location, connected to different wifi, paired with bluetooth.
  • Containerization
    • Segment the storage for business use, to avoid data leak.
    • Easy to manage offboarding where the corporate data is deleted retaining the personal data.
  • Full device encryption
    • Encryption ensures even after the theft data is lost but still secure.
    • Managed and keys are rotated through MDM.
  • MicroSD Hardware Security Module - HSM
    • Provides security services - encryption, key generation, key rotation, digital signatures, store keys securely and encrypted.
  • SEAndriod
    • Security Enhancements for Andriod, built using SELinux (Security Enabled Linux).
    • Centralized policy management. 
  • Always have the device patched with the latest security fixes.


Mobile Deployment Models

Enterprise mobile device deployment models would fall in any of the below agreements:

  • BYOD is Bring Your Own Device
    • Employee owns the device
    • Difficult to secure, could be managed by MDM using containterization.
  • COPE is Company Owned/Personally Enabled
    • Company buys the device, used for both professional and personal.
    • Organization has full control on the device, including monitoring.
  • CYOD is Choose Your Own Device
    • Similar to COPE, corporate own device but user's choice of mobile device.
    • Gets tricky in terms of security for certain models.
  • COBO is Company Owned/Business Only
    • Company buys the device and used only officially with restriction.
  • VMI is Virtual Mobile Infrastructure
    • Apps and Data are separated from the mobile device.
    • Data is stored securely centralized, risk is minimized.


Conclusion
Mobile security along with other general security measures will help the enterprise and the individual to be secure.


Credits and References

  • https://www.uscybersecurity.net/wp-content/uploads/2019/02/Mobile-Security.jpg
  • https://whatsag.com/mobile-technology/the-difference-between-a-cell-tower-and-a-base-station.php
  • https://www.youtube.com/watch?v=1JZG9x_VOwA
  • https://www.baeldung.com/cs/mobile-networking-generations
  • https://www.lifewire.com/1g-vs-2g-vs-2-5g-vs-3g-vs-4g-578681
  • https://www.weboost.com/blog/what-is-4g-lte-and-how-does-it-work#:~:text=LTE%20moves%20large%20packets%20of,it%20helps%20streamline%20your%20service.
  • https://www.uctel.co.uk/blog/4g-vs-lte-understanding-the-difference-between-4g-and-lte#:~:text=So%20what%27s%20the%20difference%20between,compared%20to%20the%20fourth%20generation.
  • https://csrc.nist.gov/csrc/media/publications/conference-paper/1997/10/10/proceedings-of-the-20th-nissc-1997/documents/031.pdf
  • https://www.investopedia.com/terms/n/near-field-communication-nfc.asp
  • https://www.youtube.com/watch?v=UOGZbq4t_g8

Thursday, 17 November 2022

Incident Management

 


Introduction

Every organization irrespective how secure they are, there will be incidents occurring either internal or external. Planning for such incidents are vital. We will see life cycle which covers the responsibilities from identification to investigation and to mitigation. 


Incident Response

As a security engineer one might need to face and handle different security issues every day such as malware detection, buffer overflow attack, DDOS attack, data theft, access misuse, disruption, down time, ransom attack and so on.

NIST - National Institute of Security and Technology provides complete security handbook called "NIST Special Publication 800-61 Revision 2" - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf guidelines to handle the incident response lifecycle.

Incident Response Lifecycle

  • Preparation
  • Detection and Analysis
  • Containment, Eradication and Recovery
  • Post Incident Activity 


Incident Response Planning - Preparation

Incident response planning involves in preparation, roles, rules and procedures to tackle incident.
  • Documentation
    • Communication details and protocols
    • Documentation for incident analysis
    • Incident mitigation software
    • Capture the data, including hardware and software to use later as evidence
    • Policies while handling incidents
  • Roles and Responsibilities:
    • Incident Response Team - IRT, Cyber Incident Response Team - CIRT, SME plans and executes how to handle the intrusion. Trained team to handle the incidents for the entire cycle
    • IT security management, precaution and post action measures such as firewalls
    • Compliance officers, planning and communication
    • Technical staff, helps in resolving 
    • Users, awareness and training
    • Vendors, awareness and training
    • Management, strategies
    • Communications team, informing the press or infected parties
    • Legal team, decides when the information needs to be shared
    • CIO - Chief Information Officer, CISO - Chief Information Security Officer, mission, policies and decision making
  • Exercise
    • It is important to ensure effectiveness during an event or identify any deficiencies in the process that should be addressed.
    • Mock runs without impacting production or any system, rehearsal.
    • Functional exercises, run through actual drill as they would perform during actual emergency. 
    • Tabletop exercises as full drill would be time consuming and expensive, these would be in smaller simulated disaster version.
    • Walk through, discuss and test processes, procedure from the tabletop exercise.
    • Simulation, test the simulated event such as phishing attack
  • Training, is critical to be given periodically to each teams based on their roles and responsibilities. Hence each roles and responsibilities needs to be clearing defined.
  • Jump Kit
    • As like first-aid, jump kit is prepared and available for immediate use of an incident.
    • Communication
      • Contact list needs to be update to date and accessible for everyone.
    • Hardware and software for analysis and mitigation
      • Secure storage facility
      • Forensics workstations
      • Portable printer
      • Protocol analyzer
    • Ancillary analysis resources
      • Port lists
      • Network diagrams
      • Application architecture
  • Continuity or Recovery Plans
    • Disaster Recovery Plan
      • To ensure full recovery of operational capacity following the natural disaster.
      • Documentation, planning and periodic tests needs to be done.
    • BCP or COOP - Continuity of operations planning
      • Ensures the continuity of operations by restorations of an organization functions in the shortest time possible, even if the services resume at reduced level during emergency.
      • COOP is similar to BCP but primarily focus on government and public sectors.
    • Based on the incident either of the plan could be considered as part of recovery.
    • Fundamentals of any disaster recovery plan involves backups.
    • Retention Policies
      • Backup of copies
      • Regulatory compliance
      • Operational needs


Attack Frameworks

IRT needs to understand the process of attack, how they are executed, and how to prevent. Having knowledge of these frameworks are crucial.
  • Cyber Kill Chain
    • Lockheed Martin developed to defend its network based on chain of attacks made by the attacker.
    • Cyber kill chain adopts this process in cyber security.
    • The cyber kill chain has steps involved the attacker attacks the system from the beginning to end, as a security engineer one needs to break this chain as early as possible.
    • Lockheed Martin's cyber kill chain attack from the attacker's perspective in general includes below stages:
      • Reconnaissance: Identifying the target
      • Weaponization: Preparing for the attack
      • Delivery: Launching the attack
      • Exploitation: Gaining access from the attack
      • Installation: Establishing persistence
      • Command and Control: Enabling remote control for further manipulation
      • Actions: Achieving the goals
    • In order to defend, we need to understand the attacker's actions.
    • There are different tools and solutions used at each stage, to break the chain before the attack reaches the goal.
  • MITRE ATT&CK
    • MITRE ATT&CK - Adversarial Tactics, Techniques and Common Knowledge Framework was created by MITRE Non Profit Organization in 2013 to document attacker tactics and techniques based on real-world observations.
    • The document continues to evolve providing the organization's incident response team to understand the attackers behaviour and plan ahead to mitigate these attacks.
Credit: https://anomali.cdn.rackfoundry.net/images/uploads/research/mitre-attck-navigator.png
  • Diamond Model of Intrusion Analysis
    • Another similar framework to describe cyber attacks.
    • There are 4 parts giving a comprehensive view for cyber attacks.
      • Adversary
        • Details about the attacker, who, why or purpose of the attack
      • Infrastructure
        • Infected physical or logical systems or data leak details
      • Capability
        • Develop or deploy using the attack tools or techniques
      • Target
        • Affected area, data centre or country or region
    • The model provides flexible framework to analyze the threat as cognitive (understand interrelated logic) and as well as mathematical(improves strategic).
Credit: https://ars.els-cdn.com/content/image/1-s2.0-S0167404822002024-gr20.jpg


Incident Detection

  • Challenge
    • It is difficult to identify an incident has occurred as there is huge volume of data and hard to detect legitimate threats.
    • Incidents are complex extensive knowledge is needed.
  • Precursor
    • Sign that an incident might occur in future
    • Logs or vulnerability scanners giving the heads up incident
    • Network traffic deviate from normal flow
    • Unauthorized host configuration change alerts
  • Indicators
    • Sign of incident has occurred or may be occurring
    • Alarms from anti malware or anti virus software
    • Alerts from intrusion detection/prevention system
    • Exploit announcement
    • Direct contact from the attackers reach for ransom
  • Isolation and Containment
    • Sandboxes, to avoid malware spreading over the network it has brought to isolation run the malware and analyze the results
    • Malware are smart at times they run differently or destruct the running system if they are isolated or unable to connect to other systems in network.
  • Recovery after Incident
    • Removing the malware is important following one of the methods
      • Restore from backups
      • Rebuild from scratch
      • Replace compromised files
      • Disable breached user accounts and create new 
    • Tighten the system, such as 
      • Firewalls
      • Enable Multi Factor Authentication
      • Certificate changes
  • Reconstitution
    • Eradication means removing the element of the incident such as malware.
    • Recovery is restore systems to normally functional operations.
    • Not all the incidents requires eradication, for some only recovery but be good enough, and sometimes bother eradication and recovery needs to work hand in hand.
    • Eradication and recovery should be done in phased approach as recovery may take time and it needs to be efficient.
  • Documentation
    • Lessons learnt from the incident needs to be captured with all the details along with time and to be improved over a period of time.
      • Functional impact of the incident, categorization such high impact or low
      • Information impact of the incident, type of impact on the information, eg: data leak of PII can be classified as data breach
      • Recoverability from the incident
    • Post incident analysis documentation for future prevention.


Investigations

Suspected incident or indicators needs to analysed, first step would be to confirm if it is true positive. Different tools and frameworks are available to determine the scope of the incident. IRT will help the team to prioritize potential issue for deeper analysis or to take next action of incident mitigation.


Identify Vulnerability 

In the given system the vulnerability scanner will scan the entire device or application to check if there are any know vulnerabilities. In general these scanners will scan and match the signatures of existing identified vulnerabilities present in the device or it could warn us with the security controls not in place. 

After discovery we can read about the vulnerability and how to resolve this from different sources available in the internet or the vulnerability scanner itself can provide the details. One of the most popular site to refer is National Vulnerability Database at "https://nvd.nist.gov/vuln".

The scan report includes the issues such as malware found, firewall not configured, old version software found, unencrypted telnet server and much more. The report could produce false positives where it has identified a vulnerability but in reality it is not, which we need to be aware of. Sometimes it can have false negatives, the real issue is missed to report. To avoid such scenarios have the scanner up to date along with the signatures.

Credit: https://docs.gitlab.com/ee/user/application_security/vulnerability_report/img/project_level_vulnerability_report_v14_5.png


SIEM - Security Information and Event Management

SIEM is centralized log system, which will consolidate all the information and logs from different source systems such as operating systems, firewalls, routers, web servers, database servers, application servers and so on, to analyze from single reporting tool.

The logs are parsed and stored in common format, as each system would produce different style logs. As the single reporting system these information will converted and also tagged with different category, such as source system could tagged as linux, linux oracle server, and so on. Further each log entries would categorized as information, warnings, errors or urgent.

As these informations are collected over of a period of time it could be used to see the trends and proactively provide alerts or alarms. Additional reports and intelligence could be fed into these systems. SIEM provides interactive dashboards with charts, graphs, trends which can help investigator explore the data through interactive drilldowns.

Credit: https://www.softwaretestinghelp.com/wp-content/qa/uploads/2019/06/Splunk.png


Logging

Security monitoring process involves in creating and analyzing extensive logs and data. Log files will guide us where to look for the related data. Using these files we can gather information root cause information and plan for the solution. Hence while creating log files we  need to be careful as it takes up system resources - too much logs will be bog down the read operation though necessary information should be logged.

Log Files:
  • Network logs
    • Switch logs
    • Router logs
    • Firewall logs
    • DNS logs
  • Operating system logs
  • Application logs
  • Web application logs
  • Database logs
  • Audit logs
  • System logs
  • Call Manager logs
  • Bandwidth logs
  • Security logs
  • Access logs - requests and connections between systems
Log Management:
  • Syslogs
    • Transferring logs from one device to centralized database usually SIEM is called syslogs in Linux.
    • Logs come with different severity levels - debug, information, warning, error or fatal, we can configure to capture based on the level. Log level warning is good for the production and debug for development environment.
    • Daemons running syslog are:
      • syslog - syslog message includes the facility code and the severity level. A facility code is used to specify the type of system that is logging the message. Messages with different facilities may be handled differently. Eg: 0 - kernel messages, 1 - user messages, 2 - mail messages.
      • rsyslog - Rocket Fast System Log
      • syslog-ng - Logging with filter
      • nxlog - Multi operating system platform log collector
  • Journalctl
    • The journald daemon collects data from all available sources and stores them in a binary format for easy and dynamic manipulation.
    • Journalctl command is used to view, search and filter the logs stored in the binary format.
  • Metadata
    • The data that describes other data sources. Will be useful while performing the incident analysis.
    • Eg: for email we will have standard header storing the sending and destination address, in mobile having the gps locations, etc.
  • Network Activity
    • Netflow
      • Gathers the traffic statistics from all the traffic flow in the entire network.
    • IPFIX
      • IP Flow Information Export, tracks the IP actions in the network
      • IPFIX collects the data packets from across the network, organized by an Exporter which sends the compiled version to the Collector.
      • IPFIX provides the flexibility by customizing the templates, these templates outlines the data the user wants to collect.
      • Serves as industry standard for the export of flow information from network devices.
    • sFlow
      • Sampled Flow, used for monitoring high speed switched networks.
      • Packet sampling in embedded technology is used to monitor network devices such switches, routers, wireless access points.
      • Only the portion of the actual network traffic is captured, yet been found useful in getting the complete network visibility, for defence against security threats.
    • Protocol analyser
      • Able to analyse the traffic at packet level, several tools such as wireshark protocol analyser


Incident Mitigation

In the process of incident mitigation is a critical part of the incident response process. Applying mitigation techniques or controls in order to secure an environment is a key to containment, eradication and recovery phases.

Incident mitigation requires eradication or containment of the malware for securing an endpoint as a precaution. An endpoint could be desktop computer, laptop, smartphone or tablet. As a security team its our responsibility for monitoring all of these different devices.


Approach

Controlling the applications running on the endpoint, creates more secure and stable environment.
  • Allow List
    • Create a list of applications that are approved
    • Allow only the approved applications to run on the endpoint
    • Restrictive approach 
  • Deny List
    • Maintain deny list of applications
    • These list of applications will not be allowed to be executed on the endpoint
    • Anti-virus and anti-malware behaves the same
  • Quarantine
    • Applications suspected to be malicious will not be allowed to run.
    • It will move from that system and place it into a quarantine area, where no applications are allowed to run. This does not mean removing it or cleaning it, just in different area to avoid spread.
    • Later security team can perform additional analysis on the suspected application and this will avoid its spread if proven malignant. 


Criteria

An ability to run or not run an application in an operating system is commonly built into the core functionality of the os. Security team can enable to disable different parameters to allow certain software to run or deny.
  • Application Hash: Execute only if hash of the executable matches on the system.
  • Certificate: Execute only if the digital signature matches.
  • Path: Limit permissions to certain folders, allowing to be executed only from certain folders. Eg: one may run an application with local rights and accessing only those certain folders. Here this cannot extend accessing the folders belongs to root or other users.
  • Network zone: Set a policy that would allow or disallow an application to run based on the zone it is executing from. Eg: an application run in private area but prohibited to be executed in public zone. 


Controls

  • Firewalls
    • Allow or deny application traversing in the network
    • Block using rules such as ip address block or allow, zone wise allow or block
  • MDM - Mobile Device Manager
    • Have rules on the mobile devices that can allow or disallow access.
    • These rules or polices can be configured using MDM and only security administrator can set or unset the policies
  • DLP - Data Loss Prevention
    • DLP identifies and blocks the transfer of any PII - Personally Identifiable Information.
    • Eg: Credit card numbers, social security number, etc if it has been transferred outside will be blocked.
  • Content filter/URL filter
    • Restrict or allow only certain websites.
    • Many of the these URL filters can also be integrated with third party blocklists.
    • Blocklists can be updated constantly allowing real time blocking the malicious sites.
  • Certificates
    • Allow access from only trusted devices
    • Deny the access if it does not have trusted certificate on that device
  • Isolation
    • Isolation is a process where a device or application is moved into an area where it has limited or no access to other resources.
    • It is a key strategy while fighting against malicious software or software thats constantly trying to communicate back to a command and control location.
    • Network Isolation
      • Isolating device to a different network disabling the access to the rest of the network, when suspected malicious or not fully protected.
      • No communication to other devices.
    • Process Isolation
      • When a process running on the device seems to be suspicious, we can disallow any access from that process to the rest of the network.
      • This will limit application execution but allow device management.
  • Containment
    • Run each application in its own sandbox, limiting the interaction with the host operating system and other applications.
    • Here it prevents the spread of malicious software to prevent from jumping outside of that application to infect the local machine or other devices in the network.
  • Segmentation
    • In general extensive security is created between the outside of the network and internal network. But once the malicious software enters inside network it is able to traverse freely without any concern of being blocked.
    • To overcome this network administrators have started to create segmented networks within the network. 
    • Eg: Database is usually placed in a network where it can be accessed only from backend application. And web application servers can be accessed from internet but internally it can only interact with backend applications.
  • SOAR - Security, Orchestration, Automation and Response
    • As there are different and many controls needs to be taken care, it would be challenging and mistakes can occur if done manually.
    • To automate these processes we need SOAR.
    • Using SOAR, an admin can integrate multiple third party tools and have them all work together.
    • Runbooks
      • A runbook holds detailed steps on how to perform particular task
    • Playbooks
      • When a particular event occurs, a set of runbook together performed is called a playbook.


References and Credits

https://gluu.biz/wp-content/uploads/2020/05/incident-management.png
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/sy0-601-comptia-security-plus-course/

Thursday, 10 November 2022

Cloud Cybersecurity Solutions


 

Introduction

Cloud enables elasticity allowing users to dynamically avail resources based on the needs and only pay for what they use. Voila! a great invention for the digital world.

Allowing only authenticated services to scale up or down and ease of ramping up or down with immediate visibility to the authorized admins. The authentication, authorization, firewalls, audit and transaction visibility are crucial steps in cloud security. 

Though we technically own the servers, but as we know mostly we don't have physical control on the servers, leading to additional care. Cloud security it is shared responsibility of the customer and the cloud service provider - CSP. 

Today we shall discuss about cloud infrastructure and some of key elements in towards its security. 


Region and Availability Zones

Uptime and availability are one of the two important aspects of cloud security. Regions are different geographic locations the service providers maintain their infrastructure. For each region there can be more than one Availability Zones - AZ. For example a cloud service provider could support two regions India and Australia, and in each of the regions there could multiple AZs for instance in India two AZs in Mumbai but different parts.

Each of the AZs are self contained and independent. Each having different power providers, separate network confirmations and so on. Making in reliable, if any one AZs downtime will not affect the other AZ.

As user we can take advantage of this, and could configure our application to the nearest region of our users in order to reduce latency. Also load balance either through active/active or active/standby configuration. Providing the flexibility to switch when there is an issue or overload requests, enabling high availability.

Each region cost may different of the services and not all regions would provide all the services. Also while selecting the region the compliance regulations needs to be considered. 


Virtual Private Cloud (VPC)

In a public cloud space we can create a private isolated network known as VPC. It is just like the private cloud having both public and private subnets. The private does not exposing the IP addresses as public address and can be accessible only through restricted means. VPC is essentially at the network layer as a IAAS service. 

An analogy, in a IT parks we have different organizations having different facilities such as parks, auditorium but the work area is private only employees or restricted person can enter. Here private area is similar to VPC, we have major control over it and as well its considered to be secure. Separation is security opportunity, eg the web servers can be accessed from anywhere but the database should be accessed only by the backend application servers.

Multiple subnets could be created in the single VPC, definitely within the range of IP addresses the VPC is created with. The subnet could be either private or public, this draws the line for the servers in these network not to access from public network. 

VPC Gateway endpoints, allows connecting multiple VPCs keeping the data private without using the internet.

Virtual LAN (VLAN) is as like LAN way of partitioning the network as the group of servers connected can access each other without hitting internet. Here the partitioning occurs in the layer two of OSI model.

Virtual Private Network (VPN) uses encryption on top of the public network, making it secure and avoiding man-in-middle attacks.


Firewall

Security groups are acting as a “firewall” on instances. Using security group, we can control both the incoming and outgoing traffic. They are stateful, which means any traffic in is allowed to go out, can go back in. Supports only allow rules, means traffic cannot be explicitly blocked, rather only allow configured traffic in. 


NACLs are acting as a “firewall” at the subnet level. We can associate a single NACL to multiple subnets, but only one NACL can be assigned a subnet.


These stateless as the inbound and outbound rules apply for all traffic. For example, if the output traffic is allowed our request would reach out, but if expect a response, sorry it would need to have the outbound rules specified. Supports all both allow and deny rules for both inbound and outbound traffic. Here we can specify only reference a CIDR range (no hostname). 


Additionally we have services provided by CSPs to protect at different layers of OSI, such as WAF - web application firewall secures at layer 7, Network firewall protects at layer - 4 and so on. This could enhance the security blocking unusual API calls, not allowing or allowing access from certain geographic locations, track and report attempts made to access critical data.


IAM Policies

In cloud access to resources is governed by policies and their permissions centrally with audit enabled by default. Each policy can be attached to the entity, user, user group or a role.  

There are two basic policies either we call it identity based policy or resource based policy. Under identity based policy permissions are given to the user, user group or role. And for the resource based policy these policies define who can access and what activities they are allowed to perform.

Stating access will be granted only when both the policies allow, if either is denied access will not be granted. By default all the access would be denied, explicit allow only grants the access. But if there is explicit deny it will get higher precedence and access will be denied.

Granular access policies can be set such as allow or disallow certain IP addresses, data and time, group, geographic locations, etc. 


Managing Secrets

Applications that use API Keys, encryption keys or credentials should not have it hard coded. Cloud provides services to handle the secrets elegantly. Secrets are encrypted at rest and in transit. 

Secrets management protects and manages the access to the applications and services. IAM policies makes sure one has access to secrets. 


Central Logging

Monitoring and audit is crucial phase of cybersecurity. Cloud provides framework and services to manage and enable monitoring granular level. 

IAM access, policy change, infrastructure changes are some of the common tasks where the logging is default enabled and aggregated in the central location. But these would not be sufficient, cloud provides APIs to write more and customized logs based on the user's requirement.

These centralized logs can be further used for further inspecting and analysis, as well integrate with any SEIM Solution. Intuitive reports could be created from these logs. 


Cloud Access Security Broker (CASB)

Each cloud service provider provides a set of tools enabling the security tools. But there could be gaps or the requirements could not be matched by them. And as the data resides with the cloud service provider maintaining security and adhering security policies becomes important. In such scenarios on premises or third party offerings - CASB come to a rescue, fill in the gaps and compliment cloud security services. This is placed between the cloud consumer and cloud provider.  

CASB provides security software as a service addressing cloud service risks, enforce security policy, threat protection, data security, comply with regulations. This can be implemented as software running either locally or in cloud. CASB operates on four primary characteristics:
  • Visibility: Visibility on the entire processes running on cloud and if it authorized. Validation and avoiding misconfigurations.
  • Compliance: Following organization own or mandated policies, like HIPAA, PCI
  • Threat prevention: Allow only authenticated and authorized users to the granular level, including multi level approvals or multi factor authentication.
  • Data security: Protect and encrypt the sensitive data at rest and in transit. Ensure APIs is secure, where the attackers can exploit the interfaces.

CASB along with next-generation secure-web gateways (SWGs) monitoring and management of web APIs and user/entity behaviour analytics (UEBA) provide the capability to deliver static and dynamic access to the management.  

CASB is evolving into on huge service known as Secure Access Service Edge (SASE) architecture. SASE combines multiple security and networking technologies to provide comprehensive web and cloud security. Security Service Edge (SSE) is the convergence of multiple cloud-based security services as part of a Secure Access Service Edge (SASE) architecture. 


Security Awareness

Structural awareness solutions help manage risk and apply protections to systems and data.

  • Cloud compliance and best practices: Visualization and continual assessment of the environment, including the ability to enforce known good standards
  • Instance and container visibility: Monitoring and protection of containers through their life cycle
  • Virtual private network: Secure access to applications running in a VPC for remote employees
  • Secure data: Encryption and key management solutions to protect data and meet regulatory compliance standards
  • Vulnerability assessment and management: Visibility into the attack surface to discover and resolve security issues
  • Software composition analysis: Management and security for open-source licenses
  • Operational intelligence: Aggregation and correlation for the analysis of data across security, performance, and availability
  • DevSecOps: Automated and continuous process management for continual integration and delivery of secure applications
  • Cyber risk management: Prioritized insight into the threats, vulnerabilities, and impacts of cloud assets
  • Container security: Minimal or hardened operating system that is specifically designed to run containers. Running similar security demand services on a same host, limit the scope of intrusion.
  • Backup: Maintaining backups ensuring availability by following the legal requirements such as holding information for 7 years, data should saved our of country.
  • Permissions: Authentication and authorization at granular level and constant audit to ensure there is no break.

Situational awareness solutions detect security events and are capable of responding, recovering, and helping with continual improvement. 

  • Firewalls and proxies: Provide fine-grained inspection of traffic for potential threats at both the network and application levels
  • Endpoint detection and response: Protect endpoints, including cloud workloads from zero-day and other attacks
  • Intrusion detection systems: Monitor networks and workloads for security events
  • Backup and restoration: Protect data from errors, failures, and accidental deletion
  • Disaster recovery: Provides additional flexibility to quickly recover from a disaster, ensuring that cloud workloads are available
  • Security information and event management: Ingests, correlates, and prioritizes events for deeper visibility into anomalous behavior and threat mitigation
  • Workload isolation: Provides dynamic security control for microservices, containers, and other workloads


References and Credits

https://www.cloudcodes.com/blog/wp-content/uploads/2020/05/cloud-security-for-dummies.png'
https://www.cloudflare.com/en-in/learning/cloud/what-is-a-virtual-private-cloud/
https://www.professormesser.com/security-plus/sy0-601/sy0-601-video/cloud-security-controls/

Scarcity Brings Efficiency: Python RAM Optimization

  In today’s world, with the abundance of RAM available, we rarely think about optimizing our code. But sooner or later, we hit the limits a...