Happy New Year and welcome to the first episode ever of Security Weekly News.
It's another year of malware, exploits, and fun here on the Security Weekly Network. Ransomware, TikTok, World War III, & in the Expert Commentary, we welcome Jason Wood of Paladin Security, to talk about Iranian Cyber Threats: Practical Advice for Security Professionals!
Visit https://www.securityweekly.com/swn for all the latest episodes!
To learn more about our sponsors visit: The Security Weekly Sponsor's Page
In case you hadn’t heard yet, the United States killed Iranian General Qasem Soleimani last Friday. Since then it seems like everyone is freaking out over what Iran’s response will be. I think my favorite headline came from The Express in the UK. “World War 3: Is World War 3 official? Will WW3 happen and will the UK get involved?” To tell you how good their research on the topic was, they said the attack occurred in Iran in the first paragraph, then later say it happened near the Baghdad airport. Even without that level of hysteria, people are concerned as to what Iran’s move is going to be. In our field, folks are worried about cyberattacks from Iran. So let’s talk about preparation for attacks against our systems, regardless of whether Iran did it or not.
In the show notes, I’ve linked to an article by Rick Holland on the Digital Shadows blog. Rick’s analysis is focused on threat modeling in particular, while my point of view is focused more on day to day security operations. He makes the point that this is “not the time ZOMG CYBER IRAN” and I agree with him. Yes, the tension between the US and Iran is at a very high level. Yes, the Iranians are quite busy conducting offensive operations and they are now very angry. At the same time, what really changed for most of us between January 2nd and January 3rd. The answer is not a lot.
Our networks are still plugged into this hostile environment called the internet and they are being attacked by people of varying skill levels. This has been ongoing for years. We should have fairly comprehensive defenses in place already for the type of actions that Iran may take against our organizations. For example, a quick look at APT33 or Refined Kitten’s techniques include things like spear phishing, brute force attacks, and distributed denial of service. There have already been some web defacements in response to General Soleimani’s death. None of these are new and they aren’t limited to Iranian attackers only. You can include the Chinese, Russians, Americans, and nearly everyone else to the list of countries or groups using them.
There’s really nothing new that you need to implement that you should not have in place already. If you don’t have defenses for this stuff in place, then you have bigger problems. In times of greater tension you may decide to be more attentive on your monitoring. For some organizations, that may mean performing hunts in their networks for signs of similar attacks being employed. This is what I would hope to see organizations in financial, defense, government, and critical infrastructure doing. They should already have robust defenses and, due to their threat profile, should be on a higher state of alert. For other organizations, they may be responding to emailed alerts from defenses more closely. And finally, I hope that some organizations decide they need to take a look at their security logs for the first time in months.
So what can you do? Honestly, stay focused on the operational basics. That means making sure patches are being deployed in a timely manner, that unexpected services aren’t hanging out on the internet, and that you’ve changed default passwords to something other than “admin” or “password”. Preferably something really long and not easily guessed. Check to make sure your back up system is working as expected and do a test restore to make sure the process works. Make sure that those who are responsible for security monitoring are paying attention and are not asleep at the keyboard.
One point that Mr. Holland makes in his blog post did stand out is that we need to make sure our threat model includes being “collateral damage” in an attack intended for someone else, but it spreads in unexpected ways. He cites the example of Maersk and NotPetya. Maersk was not the intended victim for NotPetya, but it got caught up in it and was seriously damaged. This could happen to anyone of us. The defenses against this fall into the operational basics again.
Finally, I’d add one more point to the current panic sweeping the twitters. Make sure we keep some perspective on what is going on. We are going to continue to have political and military strife in the world. We can’t lose our cool when another conflict occurs between nations or other groups. If you feel unprepared to respond to an incident in your organization, then that’s a sign that you’ve got some work to do. Otherwise, stay attentive and be ready to respond, regardless of who may be attacking you. After all, that’s what we are paid to do in this field.
|[caption id="attachment_210" align="alignleft" width="120"] Doug White - Professor[/caption]||[caption id="attachment_210" align="alignleft" width="120"] Jason Wood - Founder; Primary Consultant[/caption]|