• No results found

tt1520imperva pdf

N/A
N/A
Protected

Academic year: 2020

Share "tt1520imperva pdf"

Copied!
49
0
0

Loading.... (view fulltext now)

Full text

(1)

Cyber Vigilantes

(2)

Cyber Security Today

Hacking has become industrialized.

Attack techniques and attack vectors

keep evolving with an ever rapid pace.

Attack tools and platforms keep

evolving.

(3)

Reality Check #1:

Hackers Know the Value

of Data Better Than the

Good Guys

(4)
(5)

Website Access up for Sale

(6)

Website Access up for Sale

(7)

Reality Check #2:

Hackers, By Definition,

Are Early Adopters

(8)

Reality Check #3:

The Good Guys Have

More Vulnerabilities Than

Time, Resourcing Can

Manage

(9)

WhiteHat Security Top Ten—2010

Percentage likelihood of a website having at least one vulnerability sorted by class

(10)

Feeling Overwhelmed?

(11)

A Lesson From Nature

“Natural pesticide carcinogens have been shown to be

present in the following foods: anise, apples, bananas, basil, broccoli, brussel sprouts, cabbage, cantaloupe,

carrots, cauliflower, celery, cinnamon, cloves, cocoa, coffee, comfrey tea, fennel, grapefruit juice, honeydew melon , horseradish, kale, mushrooms, mustard, nutmeg, orange juice, parsley, parsnips, peaches, black pepper, pineapples, radishes, raspberries, tarragon, and turnips.”

- Bruce Ames

(12)

A Lesson From Nature

“Thus, it is probable that almost every plant

product in the supermarket contains natural

carcinogens. The levels of the known natural

carcinogens in the above plants are almost always

much higher than the levels of man-made

pesticides, and many are in the range of thousands

to millions of parts per billion.”

- Bruce Ames

(13)

Studying Hackers

ƒ Why this helps

+ Focus on what hackers want, helping good guys prioritize

+ Technical insight into hacker activity

+ Business trends of hacker activity

+ Future directions of hacker activity

ƒ Eliminate uncertainties

+ Active attack sources

+ Explicit attack vectors

+ Spam content

ƒ Focus on actual threats

ƒ Devise new defenses based on real data

(14)

Approach #1:

Monitoring

Communications

(15)

Method: Hacker Forums

ƒ

Tap into the neighborhood pub

ƒ

Analysis activity

+ Quantitative analysis of topics

+ Qualitative analysis of information being disclosed

+ Follow up on specific interesting issues

(16)

-SQL Injection=Most Popular Topic

(17)
(18)

Example: Mobile (In)Security

Hacker Forum Discussion Analysis: 2010

Hacker interest in mobile has increased. In the last half of the year there were 2383 keywords compared to only 264 on the previous half.

Source: Imperva’s Application Defense Center Research

(19)

-Approach #2:

Knowing Hacker Business

Models

(20)

Example: Rustock

(21)

-Spy Eye vs Zeus

ƒ When installing SpyEye

there is even the “Kill Zeus” capability which if chosen, checks whether there are any installations of the Zeus Trojan, and uninstalls it before

installing SpyEye.

ƒ Towards the end of

October, the bot code

developers of SpyEye and Zeus bots were showing signs of a merger.

(22)

-Approach #3:

Technical Attack Analysis

(23)
(24)
(25)

Automated Attacks

ƒ

Botnets

ƒ

Mass SQL

Injection

attacks

(26)
(27)

Approach #4:

Traffic Analysis Via

Honeypots

(28)

Example: DDoS 2.0

(29)

HTTP Request Caught A ToR Honeypot

+ POST /.dos/function.php HTTP/1.1

+ User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.3)

Gecko/20100409 Gentoo Firefox/3.6.3

+ Parameters

– ip=82.98.255.161&time=100&port=80

(30)

-Scale – Probably Thousands

ƒ Google shows

hundreds

ƒ Probably only

the tip of the iceberg

(31)

-Impact: Who was Brought Down?

ƒ Only saw it launched against one server

+ IP was Dutch hosting provider

ƒ But there is likely more

+ We only see a fraction of the general traffic on our honey pot

+ This is only one implementation of DoS

ƒ Impact?

+ Depends on the hosting web server bandwidth

+ A cable modem user typically has a 384Kbs upstream

+ Web host in data center can have 1Gbps pipe

ƒ 1 server = 3000 bots

(32)

Conclusions

(33)

Conclusions

ƒ Time to get proactive

+ Scan Google for Dorks with respect to your application

– Dorks and tools are available on the net

+ Search Google for Honey Tokens

– Distinguishable credentials or credential sets

– Specific distinguishable character strings

+ Watch out for name popping in the wrong forums…

ƒ Fighting automation

+ CAPTCHA

+ Adaptive authentication

+ Access rate control

+ Click rate control

(34)

Conclusions

ƒ Application Security Meets Proactive Security

+ Quickly identify and block source of recent malicious activity

+ Enhance attack signatures with content from recent attacks

+ Identify sustainable attack platforms

– Anonymous proxies

– TOR relays

– Active bots

+ Identify references from compromised servers

+ Introduce reputation based controls

(35)
(36)

Questions?

(37)

-Lesson #3: Automation

ƒ Attacks are automated

+ Botnets

+ Mass SQL Injection attacks

(38)

Lesson #4: Optimization

ƒ Hackers are looking at ways to optimize

+ Examples:

– Compromise servers rather than PCs (insert pic!)

– Malware distribution

– Direct and indirect value

Take-away:

(39)

Lesson #5: Mobile

ƒ Hackers keep a tab on consumer trends

ƒ Mobile security goes up the stack:

+ Mobile-platform attacks (1st generation threat)

+ Lost devices

+ Applications

(40)

Lesson #5: Mobile

ƒ Hacker Forums – Mobile Discussions

Take-aways:

1.As an organization: Risk assessment with respect

to mobile

(41)

Lesson #6: Remember Old Threats

ƒ Old threats do not die out! (Pic of Karl Marx)

+ Familiar

+ Succeeds

+ Easy to carry out

ƒ Past protections might break when moving forward

+ Examples:

– Boy in the Browser

– HTML phishing

Take-away:

(42)

Summary

ƒ Introduce proactive detection into your security

environment

ƒ Assess what is sensitive data and apply the necessary

controls on that data

ƒ Stop attacks before they even enter your application

ƒ Ensure guards are updated in real-time

ƒ Follow-up on trending attack techniques and models

(43)

Did you feel that the session was

both informative & useful?

 Not  very

 infor

...

 Som

ewha t info

r...

 Very  info

rmati ...

1

37

15

A. Not very informative or useful

(44)

Do you feel you know more about the issues

& challenges posed to your organisation

following this session?

 No

 Som

ewha t

 Yes

(45)

Has the session answered your questions

about the issues & challenges of the

discussion topic?

 No

 Som

ewha t

 Yes

(46)

Did the speakers present the topic well?

 No

 Som

ewha t

 Yes

(47)

Using a scale of 1-5, how would you rate the

session overall?

 Poor  Met

 som

e of

 my

...

 Met  my

 expe

cta. ..

 Good  

 Exce

llent   2 4 1 8 21 6

1. Poor

2. Met some of my expectations

3. Met my expectations

4. Good

(48)

Will you be attending any further sessions in

the Technical Theatre during your visit to

this year’s show?

A. Yes

(49)

Will you be attending any other

presentations in the other theatres during

your visit to the show?

A. Yes

References

Related documents

Oliver Zander, Bundesanstalt für Straßenwesen (BASt); Dirk-Uwe Gehring, Peter Leßmann, BGS Böhme & Gehring GmbH, Germany. 10:10

The IP Communications High-Density Digital Voice/Fax Network Modules are integrated in the Cisco 2600XM, Cisco 2691, 2811, 2821, 2851, Cisco 3700 Series, and Cisco 3800 Series

• Minimum number of codes that avoid the hidden terminal problem Æ Relation cell size – minimum tx range. • In a range of at least 4R there must not be any repeated

In our simplified model, an agent with discretionary control (an e-contract) is viewed by the courts as a controlling agent, and an agent with a rule-driven contract (a d-contract)

Association between selected indicators of AIDS-related household morbidity and mortality and daily hours spent doing different labor activities (farming, non-farm self-employment

Six spikes from two land races from two fields of a farmer in Dagaceri were subjected to molecular analysis using the Amplified fragment length polymorphism (AFLP)

Literature of American History: Exploring Diversity [graduate level] Introduction to Early American History, Colonial Era to the Civil War Introduction to Modern American

Fuel & biomass combustion Initiation and/or promotion of tumor growth Acute Respiratory Infections --- Lung Cancer --- Heart Disease --- Chronic Obstructive