RSA SecurID attack details unveiled – they should have known better
blogs.gartner.com
blogs.gartner.com
(Knowing the details of how RSA got spearphished is interesting, I suppose, but it leaves out the really important bits.)
It is also important to note that just as stealth fighters
evade radar instead of defeating it, APTs do not “defeat”
security products.
Haha. You keep telling yourself that bucko.>Threat – means that there is a level of coordinated human involvement in the attack, rather than a mindless and automated piece of code. The operators have a specific objective and are skilled, motivated, organized and well funded.
Seems odd to specify "mindless and automated piece of code". Does this mean Stuxnet wasn't a "Threat"? I'd say it fit all those requirements - specific goal, wide-ranging tech use, and everyone saw it coming but nobody managed to stop it.
It's wikipedia with all the associated baggage. I'd guess what they meant to draw a distinction from was the automated bots/worms out there that just rattle the windows of hundreds of thousands of sites with for known vulnerabilities. Then they install something relatively innocuous like an ad for scareware AV similar to the current huge SQLi attack.
Anatomy of an Attack
Skip to the appendix if you don't want to read irrelevant comparisons to U-Boats and stealth aircraft.
Even there, the details are light. They got spearphished with excel files with flash payloads (CVE-2011-0609). Those installed "Poison Ivy" (some remote admin a la vnc/rdp). They spread out from those points attacking other accounts/computers/servers. They looked around for interesting things, put it in passworded RARs and FTPed them out to other compromised (non-RSA) servers (apparently "Good[DOT]mincesur[DOT]com | up82673[DOT]hopto[DOT]org | www[DOT]cz88[DOT]net").
There is very little useful information in their breakdown. Everything they mention is standard fair, certainly not something special to "Advanced Persistent Threats". The flash vuln (with excel files) has been known for weeks. There is no discussion of what the attackers actually managed to get their hands on.
Of course they could also know something pretty significant that they're not telling. What was taken and how tough it was to get at internally could be a flag. If there was a really significant or telling element to the attack it may well be that they've been asked not to reveal it. Not that I'd bet on that side of the line.
But no, it was email attachments (EDIT: granted, with an Excel 0-day). Email attachments???!! Says a lot about the effectiveness of security awareness training. Fear the APT.
https://www.adobe.com/support/security/advisories/apsa11-01....
While there is definitely something to be said for what you're saying about "omg, email attack" the other side of the coin is that spearphishing is the most popular/common attack vector because it works.
I don't think she understands what eating your dogfood means.
As they were using a network observer which wasn't as sophisticated as other tools they make and sell.
> The irony though with RSA is that they don’t eat their own dog food.
> In other words, they relied on yesterday’s best of breed tools to
> prevent and detect the attack. They gave a lot of credit to NetWitness
> for helping them find the attack in real time but they obviously weren’t
> able to stop the attack in real time, which means the signals and
> scores weren’t high enough to cause a person to shut down the attack
> in real time.
>
> RSA sells its own fraud detection systems based on user and account
> profiling which use statistical Beysian models, and rules, to
> spot abnormal behavior and intervene in real time to re-authenticate
> users and verify the authenticity of suspect access, behavior, or
> transactions. (RSA appears in the leaders quadrant of Gartner’s 2010
> Web Fraud Detection Magic Quadrant). They should have applied these
> techniques to their own internal systems. They need to stay innovative
> and apply the lessons learned from serving their clients to their own
> internal enterprise systems.Having a fully scriptable, ubiquitous environment like Flash installed systemwide just increases your attack vectors. I'm not blaming Adobe here as much as recognizing that 0-day vulnerabilities will always exist.
Microsoft office aside (if you need to use, it's going to be installed), perhaps there will now be pressure to remove and ban Flash from work environments.
Domains used in the attack included:
www .usgoodluck .com
obama .servehttp .com
prc .dynamiclink .ddns .us
http://krebsonsecurity.com/2011/03/domains-used-in-rsa-attac...