Hackers strike defense companies through real-time ad bidding
computerworld.com
computerworld.com
http://www.invincea.com/wp-content/uploads/2014/10/Micro-Tar...
> Most of the attacks featured here were not detected by standard Anti-Virus because the malware hashes constantly change.
> Web proxy blocking updates, even in real time, will not stop new malvertising landing pages that appear and disappear within minutes.
> Intelligence feeds from the premier intelligence providers, based on hostname, IP, URL or domain will not be able to block malicious malvertisers quickly enough.
> ... opting out merely places a blocking cookie in your browser. This means that ad providers will not target or retarget based on cookies. But as shown above, the new targeted advertising is via IP intelligence.
It seems like these are extremely difficult to mitigate without heuristic-based antivirus systems. And even if the bidding engines were to scrape them, malicious ad servers could simply serve benign content to all but the targeted IPs.
That said, it's very possible that patterns would emerge in this type of targeted advertising that could be marked as fraudulent using machine learning (for instance, if a brand new ad server were to suddenly start requesting IP targeting). I'm sure the talented people at the larger ad-exchange-software companies like AppNexus will figure something out - or they already have!
Also, despite Invincea's claims to the contrary, good intelligence feeds and in some cases just proxy domain categorization are often fast enough to catch these for most organizations, at least in cases where the attack isn't specifically targeted at a single organization. This is on top of multiple layers of defense that any decent company should have, many of which could catch numerous indicators (domain patterns, URI paths, Javascript) tied to these exploit kits.
The bidder has to prop up and supply the exploit kits themselves, and most of the time it's Sweet Orange, Nuclear, Rig, or Angler. But these are all "commodity" exploit kits and aren't even remotely custom made like they have been in some APT attacks. APTs may also go the ad bidding route and provide their own handcrafted exploit kits, but they may not want to go through a middleman like this and set up a corporate front.
The only unnerving part is the ability to choose a specific target subnet. If the ad networks or second-tier middlemen of "spreaders" / "distributors" are promising clients exclusive access to a certain group of servers or even an entire ad network for a length of time, and if the client uses a specifically created new domain and maybe even a fresh IP, then that means no one may know about the compromised server/network until it's too late and several people from the targeted organization visit it.
I don't know for sure since Invincea did not investigate more into the human aspect of this, but I suspect for this to be profitable there's probably a lot of "overselling" going on, and the bidders interfacing with the ad networks themselves are serving multiple customers' campaigns (or their own campaigns) on the same servers and ad networks, which makes it more difficult to successfully pull off targeted drivebys or "watering holes" as they will get detected and evicted.
>I'm sure the talented people at the larger ad-exchange-software companies like AppNexus will figure something out - or they already have!
AppNexus has been a major offender here for a long time. They've had numerous incidents of malicious ads over the years. I know because I've seen them myself when investigating malware incidents (e.g. adnxs.com as the Referer in an exploit kit chain). You can also see adnxs.com in Figure 21 of the whitepaper. I certainly hope they start caring more about security and establish a more stringent ad reviewal process.
A recent HN discussion brought up the application virtualization tech Invencia offers, including some of its drawbacks:
The bad actor here is DoubleClick, which is part of Google. Google is famously known for being squishy-soft on advertiser vetting. They had to pay $500,000,000 to the U.S. Department of Justice for knowingly hosting ads for steroids and other drugs. (The FBI caught Google in a sting operation. http://www.wired.com/2013/05/google-pharma-whitaker-sting/ "“I want to be the largest steroids dealer in the US,” Whitaker told the Google rep.")
http://bits.blogs.nytimes.com/2009/09/14/times-site-was-vict...
No. Then you will destroy those companies in the US and everyone will use foreign-run companies not so bound.
Yeah. I think that publishers will look abroad for networks who can pay out.
Really, I think the costs and liabilities of what was proposed would do it all on their own. It would substantially increase costs for advertisers and decrease payouts for publishers. Once an ad network does that, it's going to start bleeding from both ends.
At which point some operation in who-knows-where can do better for everyone.
Ad networks really need to take more responsibility to monitor both landing pages and the ads themselves more carefully. Enabling drive-by malware installs, affiliate fraud, and all other manner of schemes - even unwittingly - is bad for everyone involved.
The OP article was a bit alarmist with the hackers singling out defense contractors. I think the real intent of the hackers/malvertisers is this:
>Invincea recently saw a malvertiser win a bid and delivered a Java exploit. This exploit copied a fully functional version of Chrome into the Java cache directory, and that version of Chrome launched in the background and proceeded to visit websites and click on specific ad banners. It is presumed that these ad banners paid revenue via referral bonuses to the malvertiser. By paying 65 cents to install a background web browser that does nothing but click fraud, the malvertiser is able to reap hundreds if not thousands of dollars in advertising referral income. It is a pretty good return on investment, which in turn allows the malvertiser to fund his micro-targeted malvertising attack campaign.
Just like Email several years ago, there's just too much accessibility and money out there for spammers and malvertisers to not jump to Display.
All of the major problems - spam, HTTP/HTTPS security, speed of protocols - have at least been met with myriad solutions. That we're still relying on Flash, JS and Silverlight, etc. for serving ads is nonsensical. Sandboxed iframes are a nice bandage, but it isn't a solution, particularly because it doesn't cover the most vulnerable anyway.
Someone has to be interested in creating a more secure standard that applies some quality standardization as well as security sandboxing.
It should make us not trust that which should not be trusted.
And that's a good thing.
Most of the things we rely on today aren't fullproof. When it gets to the point that you wouldn't be able to trust your closest friends, you consider this situation better?
You already cannot trust emails or text messages from your closest friends because they are easy to spoof. And it is better when everyone is aware of that, I think.
Whether you can (or cannot) trust your friend wasn't changed by technology, in my opinion. What you generally cannot trust is that info you confidentially told them was not eavesdropped. You never could, but statistically it was good enough. Now, statistically it isn't good enough, and therefore you shouldn't.
Consider this: http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-754.pdf
and this: https://www.techdirt.com/articles/20140224/17054826340/new-s...
it's been done before with the KGB in USSR where your closest friend could also be a tattle-tale for the party, but that's just a tiny bit of what one could achieve with computers these days
Governments and corporations have always engaged in social engineering. Facebook has been extremely successful at getting everyone to spy on themselves and their friends since 2004. MySpace and Friendster were less successful and earlier. The only thing that is new is the rate and scale of success.