the CYBER5

the CYBER5

By Nisos, Inc.BusinessTechnology
Download on the App Store

the CYBER5 episodes

  • Holistic Uses of PDNS and BGP Data to Address Intelligence Needs in the Private Sector

    In episode 70 of The Cyber5, we are joined by Open Source Context Director of Operations, Donald McCarthy.

    We discuss external telemetry available to the private sector, focusing on passive domain name systems or passive DNS, and Border Gateway Protocol or BGP. These data sets are critical for threat intelligence teams, as they often provide crucial information on attacker infrastructure for the SOC. Still, they also help solve problems and provide context on a much broader scale.

    Three Key Takeaways:

    1) What is Passive DNS and how is it collected?

    To simplify, passive DNS is a way of storing DNS resolution data so that security teams can reference past DNS record values to uncover potential security incidents or discover malicious infrastructures. Passive DNS is the historical phone book of the internet. Practitioners can collect it by:

    1. Collecting on the resolver: Have access and enable logging on the resolver, often termed “T-ing the Resolver.” The client-side of the DNS is called a DNS resolver. A resolver is responsible for initiating and sequencing the queries that ultimately leads to a full resolution (translation) of the resource sought, e.g., translation of a domain name into an IP address. DNS resolvers classify data using various query methods, such as recursive, non-recursive, and iterative. 
    2. Listening on the wire: DNS is port 53 UDP unencrypted, and many security teams put a sensor like Bro, Onion, Snort, or Suricata that can collect and then parse the data.

    2) What is Border Gateway Protocol (BGP)? 

    1. BGP is designed to exchange routing and reachability information between autonomous systems on the Internet and is often complementary to passive DNS.
    2. If PDNS is the historical phone book of the internet, Border Gateway Protocol (BGP) is the postal service of the Internet. BGP is the protocol that makes the Internet work by enabling data routing. For example, when a user in Thailand loads a website with origin servers in Brazil, BGP is the protocol that allows that communication to happen quickly and efficiently, usually through autonomous systems (ASes). ASes typically belong to Internet service providers (ISPs) or other large organizations, such as tech companies, universities, government agencies, and scientific institutions. Much of this information can be commercially collected and available. 

    3) Use Cases for PDNS and BGP in the SOC:

    1. Identifying attacker or botnet infrastructure.
    2. Identifying all internet-facing infrastructure in business use.
    3. Identifying tactics, techniques, and procedures of attackers.

    4) Use Cases for PDNS and BGP outside of the SOC:

    1. Verify internet-facing applications and infrastructure for merger, acquisition, and compromise items for M&A.
    2. Verify internet-facing applications, infrastructure, and compromise for suppliers. 
    3. Review staging infrastructure of competitors to scan product launches. 
    4. Investigate threatening emails to executives.
    5. Investigate disinformation websites and infrastructure.

    5) Enrichment is King and Does Not Need to Be Resource Intensive

    If security teams are not engaging with the business to solve problems that risk revenue generation, data sets like PDNS or BGP do not matter.  For example, if an organization does not control DNS at their borders, they will lose a lot of visibility to reduce risk and potentially give away proprietary information.

    40 min
  • Future of XDR, SIEM, SOAR, and Threat Intelligence

    In episode 69 of The Cyber5, we are joined by Lima Charlie’s CEO, Maxime Lamothe-Brassard. 

    We discuss the future of what's known in the security industry as XDR, which is essentially an enrichment of endpoint detection response products. 

    Three Key Takeaways:

    1) What is XDR?  Depends who you ask.

    XDR is not another tool, but merely an extension of Endpoint Detection and Response (EDR) products. Gartner expects 50% of mid-market buyers to adopt XDR strategies by 2027. For context, in around 2010, cybersecurity vendors started driving stronger antivirus solutions for endpoint computers and servers, called Endpoint Detection and Response (EDR). The antivirus was only catching malware with a known signature and not able to detect more malicious lateral movements that are common in today's attacks. 

    Every EDR platform has its own unique set of capabilities. However, some common capabilities include the monitoring of endpoints in both online and offline mode, responding to threats in real-time, increasing visibility and transparency of user data, detecting stored events with malicious malware injections, and creating blacklists and white lists in integration with other technologies. 

    Now that EDR solutions are firmly within the market, they need to be integrated with other tools, including threat intelligence, to be effective at scale for the enterprise. These massive integrations needed at scale, especially with the cloud, are what is starting to be defined as XDR. 

    2) What are the key integrations to EDR products to form an XDR strategy?

    a. Identity Access Management: Gives visibility to who is accessing what applications and websites in the enterprise.

    b. Threat Intelligence: Information and artifacts from attacker infrastructure, previous compromises, and behavior that can be identified outside of firewalls. 

    c. Cloud and SaaS Logging: Any application in the cloud produces a log for access and use.

    3) XDR does not have to be expensive or manpower-intensive for SMB.

    a. Cloud, SaaS, and Identity Access Management produce logs that can be integrated into easy solutions that do not need to be complex products, particularly for SMB. 

    b. Enablement should be the critical aspect of XDR rather than more expensive tooling. 

    c. Easy, automatable solutions to apply security controls are the critical way forward for medium and large enterprises.

    32 min
  • Enterprise Stakeholder Management and the Use of Threat Intelligence

    In episode 68 of The Cyber5, we are joined by Executive Director and Head of Global Threat Intelligence for Morgan Stanley, Valentina Soria. 

     

    We discuss leading a large-scale threat intelligence program in the financial institution space and how to make intelligence absorbable by multiple consumers. We also talk about how intelligence teams can build processes and technology at scale to increase investment costs to criminals. Finally, we touch on large enterprises being a value-add to small and medium-sized businesses.

     

    Two Key Takeaways:

     

    1) Intelligence is Valued Differently By Different Stakeholders 

    1. Tactical, operational, and strategic intelligence gains can fill many gaps in business, inside and outside the security operations function.
    2. Good intelligence analysis should make business stakeholders rethink their assumptions about risk and address realities regarding specific scenarios around the state of the organization’s risk posture.

    2) Begin with the SOC, then Spread Across All Business Sectors 

    1. Cyber threat intelligence is a journey and it takes time to realize a return on investment. Find coverage gaps that complement existing controls that have current metrics leveraged against them and leverage them.
    2. User Metrics to help, such as: 
      1. For SOC/CIRT Teams: The number of incidents and issues remediated,  quantity of vulnerabilities patched, and most importantly, enumerate or outline the loss that could have occurred from those exploited vulnerabilities.
      2. For Outside the SOC: Inform the business of any type of risk through tactical, strategic, and operational intelligence. 
    28 min
  • Value of Securing Containers in the Technology Supply Chain with Security Practitioner Julie Tsai

    Topic: Value of Securing Containers in the Technology Supply Chain

    In episode 67 of The Cyber5, we are joined by senior security practitioner Julie Tsai. 

    We discuss security and intelligence in modern-day technology platforms, concentrating on how to secure the impact that container and cloud environments have on the technology supply chain. Compliance and intelligence play a critical role in the application and development of supply chain risk. Specifically, when developers perform code commits and updates, we discuss the criticality of intelligence and compliance to ensure code is truthful, accurate, and complete. 

     

    Three Key Takeaways:

     

    1) Containers and Virtualization Images Offer Repeatability But Also Potential for Compromise at Scale

    Containers give software developers the potential to establish an assembly line of repeatable, secure patterns because they are operating system agnostic. However, the upstream effort to harden the container and set the right images or configurations needs to be correct from the beginning. Simultaneously, mistakes can lead to a compromised container or host OS level that might impact the container. 

    Container configurations have a shared kernel with modular application containers and services on top. Therefore, security practitioners must be mindful of anything that can break out of that container. Furthermore, if there is a host OS-level hardening, they must ensure kernel-level memory doesn't compromise and impact all the dependent layers.

    2)  Supply Chain Risk with Containers

    Supply chain risk in technology is challenging because developers generally borrow code from other developers, and they don’t check libraries and dependencies for security issues. In addition, contractual agreements aren’t capturing all the supply chain pipeline nuances. It’s hard enough to know what’s happening inside an enterprise network, let alone understand the provenance and the chain of custody. 

    Security issues can get injected into the end product when not following a strict process concerning container changes. “Defense in Depth” is a classic security principle that matters in securing containers such as application and configuration management. In addition, other aspects like source control, commit trail, and fingerprinting different kinds of artifacts are all checksums to ensure the correct update of code.

    3) Threat Intelligence Fundamentals with Container Security

    A threat intelligence program needs to start by aligning with the business with the most prevalent threats. A banking site will have different threats than e-commerce, gaming, or crypt-currency exchange. Therefore, a threat intelligence program needs to be modular enough to scale to many types of threats as the business grows. 

    More tactically related to containers, developers can’t be tearing down containers as little work would get done if a malicious actor scans a container environment. However, if a threat intelligence team notices a regularity or repeatability with the scan attempts followed by authentication attempts to the environment, those types of intelligence alerts are fruitful. 

    Intelligence programs show clear value on highly attacked industries (manufacturing, health care, retail, finance). The challenge is if you put blinders on and think there isn’t a way to be attacked other than regular threat intelligence blogs. 

    28 min
  • Building a Security Team to the Business And Using Intelligence to Inform the Proper Risk Strategy with H&R Block CISO Josh Brown

    In episode 66 of The Cyber5, we are joined by H&R Block Chief Information Security Officer (CISO) Josh Brown.  

    In this episode we discuss the importance in  building an informed security team that can collect intelligence and proper risk strategy. We have a frank conversation about what the business of security means and how to develop a team that understands multiple business lines so a security team is anchoring their security strategy to how the company is driving revenue. We talk through how to do this at scale within the intelligence discipline that touches many lines of risk, not just cybersecurity.

     

    Three Key Takeaways:

     

    1) Security Informs the Business to Make Risk-Based Decisions

    Security professionals must have a deep understanding of how the business functions to understand how to develop a proper risk-based approach. Security is a risk management function that puts up guardrails so the business avoids bad decisions and loses money. Intelligence is critical for gaining a 360-degree review: fraud and user segment of the network. Threat intelligence must be relevant to the specific business, not the industry overall. If there is a threat to a bank, that likely has nothing to do with a tax filing service.  

    2)  Actionable Intelligence That Reduces Business Risk

    The industry has not secured an  intelligence solution. Intelligence is an enrichment function, not the first line of the truth of what to prioritize. Fraud and other specific business-specific data that result in business loss are equally important to be funneled into traditional cybersecurity tools. Further, threat feeds and information must be bi-directional so even competitors and businesses in the same location can understand when incidents are taking place. The threats that most companies face are not those that are regularly marketed such as Advanced Persistent Threats. The cybersecurity industry does a poor job at providing the likelihood of a certain advanced attack. Business email compromises, account takeovers, and fraud are still the most prevalent style attacks, even to those businesses that can afford sophisticated security technology. 

    3) Actionable Intelligence That Gives Visibility into Supply Chain Risk

    “The perimeter” is no longer relevant like it used to be. With work from home, the perimeter is just as much identity access management (IAM) as it is about IP space. On third-party supply chain risk, currently, enterprises implement score card tooling as an audit function so when a software vulnerability is released, an enterprise can quickly query what suppliers use that library or dependency. Further, the supply chain is equally about business interruption (DDoS) as much as it is about suppliers that hold critical data. Major enterprises also care about the vendor’s vendors if compromised depending on the criticality of the data (fourth-party supply chain risk). Since the United States does not even have a standard breach notification law, it’s going to be very challenging to share intelligence bi-directionally let alone get developers to uniformly submit secure technology code.

    38 min
  • Brand and Reputation Intelligence: Open Source Intelligence That Drives Revenue Generation But Protects the Brand with Vizsense's Jon Iadonisi
    In episode 65 of The Cyber5, we are joined by Jon Iadonisi, CEO and Co-Founder of VizSense. Many people think of open-source intelligence (OSINT) as identifying and mitigating threats for the security team. In this episode, we explore how OSINT is used to drive revenue. We talk about the role social media and OSINT play in marketing campaigns, particularly around brand awareness, brand reputation, go-to-market (GTM) strategy, and overall revenue generation. We also discuss what marketing and security teams can learn from OSINT intelligence tradecraft, particularly when there are threats to the brand's reputation. Four Key Takeaways:

    1) Even in Marketing, Context and Insights Provide Intelligence, Not Data

    Raw data is not intelligence; rather, intelligence is a refined product where context is provided around information and data. Similar to the national security and enterprise security world, where adversaries are trying to commit crimes and espionage, businesses want to attract people to their brand. Open-source and social media information are powerful data points when analyzed, providing critical intelligence on what consumers and businesses want to buy. Every human being is now a signal no different from radio intercepts during Pearl Harbor. 

    2)  The Role of OSINT in Driving Revenue for the Brand; Quantitative and Qualitative Metrics

    In the security world, attribution to a particular organization is necessary to continue to receive fundraising, whether it’s a hacking group or a terrorist organization. In the marketing world, brand intelligence is a crucial piece in the following three elements to influence a person:

    1. Persuasive content
    2. Delivered from a credible voice
    3. Network or audience with a high engagement rate

    Open-source intelligence can be mined in a way that provides insights stronger than traditional marketing focus groups. While celebrities attract attention, people are likely to follow people like themselves, aka micro-influencers.  

    Quantitatively, numbers increasing in revenue, sharing, engagements are critical metrics. Qualitatively, marketing teams can mine social media data to determine what people are thinking about a particular product, but also to understand how the products are performing, and then design and build future products. The crowd will tell a brand what they want and they don't have yet, and you can use that data to build future products.

    3) Where Marketing Meets Security: Threats to Brand Reputation

    Security teams should work with marketing teams daily to protect the brand. In today’s threats to brands, the human dimension of what people say online is of equal credibility if not more important than technical signals that show a company has suffered a breach, particularly regarding misinformation and disinformation. The human dimension is converging with a technical dimension, and a true holistic hybrid model is needed for enterprise security and intelligence teams. An example of reputation threats that happen in business every day:

    1. Smear campaigns using disinformation and misinformation from competitors introduce uncertainty into a brand’s ecosystem.

     

    4) Where Security Meets Marketing: Privacy Taken Seriously That Enhances the Brand

    On the flip side, marketing teams should look for ways to promote the security of their products as business differentiators. Marketing teams should also consult with the security teams to understand all the different data lakes that are available in social media, dark web, and open source to ensure they can collect on the proper type of sentiment where brands are being discussed.

    33 min
  • Building an Intelligence Program to Protect Executives with Okta Senior Intelligence Analyst John Marshall

    In episode 64 of The Cyber5, we are again joined by John Marshall, Senior Intelligence Analyst at Okta. 

    We discuss building a threat intelligence program to protect executives, particularly on nuances of being a “solution-side security company”. We discuss a risk-based approach for protecting executives and the data that's important to aggregate and analyze. We also talk about success metrics for intelligence analysis when building an executive protection program.

     

    Three Key Takeaways:

     

    • Plans, Actions, and Milestones

     

    Regardless of industry, connecting with your executive team on a personal level to establish trust is the first step in any executive protection program. Communicating plans, actions, and milestones are critical. Within these three segments, intelligence requirements should be tiered into 3 groups - strategic, operational, and tactical. 

     

    • Strategic: Security of the people, security of places, and security of the brand
    • Operational: Methodologies and means a security team is going to use to monitor for threats to the brand. Specifically, collecting intel on current events, private investigation, travel tracking for executives, and company-wide messaging system to track employees
    • Tactical: Day-to-day implementation of integrating the strategic and operational methodologies

    2)  Distinguishing Between Targets of Opportunity and Targets of Attack

    Typical items to review when protecting executives:

    • Weather that’s going to impede movement
    • Social media activity that reveals plans for protests or riots near a location of interest
    • Natural disasters 
    • Geo-political events

    The primary mechanisms to protect against targets of opportunity:

    • Background checks
    • Social media monitoring, includes OSINT monitoring and analysis 

    When mechanisms to flesh out targets of opportunity appear to escalate, where they become a target of the attack, often private sector security teams lack an action arm to dispel that threat and have to rely on law enforcement for investigations. 

    Intelligence analysis and determination of facts should be pursued on any threat so that security teams can effectively request law enforcement intervention - equipped with more information that will allow faster response. 

    3) Articulating Success Metrics 

    Pinpointing the right event is the most critical of success criteria. Executing the intelligence cycle of planning, collecting, exploiting, analyzing, and disseminating information that an executive can use to answer a “so what?” is still a nuanced concept for many private sector organizations. 

    Documenting “wins” and “losses” are equally critical. Security is a risk management function that exists to keep the workforce safe and doing their jobs. 

    Whether it's getting an executive out of a traffic jam or informing a team of a hurricane happening during a conference that mitigates injury, these should be documented for value-based metrics. 

    23 min
  • Defining Metrics for Attribution in Cyber Threat Intelligence and Investigations

    In episode 63 of The Cyber5, we are again joined by Sean O’Connor, Head of Global Cyber Threat Intelligence for Equinix. 

    We discuss attribution in the cyber threat intelligence and investigation space, and what the private sector can learn from public sector intelligence programs. We also discuss different levels of attribution, the outcomes, and the disruption campaigns that are needed to make an impact on cybercriminals around the world. We define the impact of attribution with different stakeholders throughout the business and how the intelligence discipline will likely evolve over the next five to 10 years.

     

    Five Key Takeaways:

     

     

    • Lessons For Private Sector Intelligence Teams from Public Sector National Security Apparatus (Intelligence Life Cycle, MITRE ATT&CK, Cyber Kill Chain)

     

     

    Many cybersecurity best practices and frameworks originate from the US public sector:

    • Intelligence life cycle: Defining priorities and communicating intelligence to stakeholders
    • Lockheed Martin Cyber Kill Chain: Defining broad malicious actions in IT networks
    • MITRE ATT&CK Framework: Identifying more specific malicious movements in IT networks
    • Structured analytical techniques by CIA analysts, such as Richard Kerr. 

    2)  Attribution is Critical in Cybersecurity to Warrant an Action

    Attribution to cyber threat actors by industry is still important as a starting point to derive appropriate controls for the SOC and the CERT within a large organization. How these threats pose a risk of monetary loss are important elements of context when providing these threats to business executives. Here are two typical starting points:

    • Review phishing telemetry for common TTPs and create rule-based detections based on phishing infrastructure used by actors. 
    • External threat landscape assessment for TTPs resulting in targeted threat hunts for most notorious ransomware gangs. Creating custom detections is typically the outcome until the appropriate disruptions can be put in place. 

    3) Disruption Campaigns Happen with Successful Information Sharing

    Successful disruption campaigns come from non-public information sharing between vendors, enterprises, and public sector institutions like CISA or the FBI. They typically do not originate from marketing blog posts. 

    4) Threat Intelligence is a Service-Based Role that Goes Beyond the SOC

    Success in cybersecurity (SOC and CERT) is keeping security incidents limited to “events” and ensuring they do not escalate into breaches. This occurs from multiple stakeholders having the proper visibility to ensure network telemetry is complete, accurate, and truthful. However, due to the services nature of intelligence work, it goes beyond just the SOC. 

    5) Threat Intelligence Should be a Floating Team to the Business

    Threat intelligence should be a floating team that can operate outside of the SOC and is an asset to the overall business, not just limited to combating cyber threats. Often executives want intelligence on mergers and acquisitions and market entry in a given geopolitical area, and threat analysis needs to be tailored to different customers. A Chief Intelligence Officer may be more widely accepted in the future as the needs of the business expand and diversify.

    32 min
  • Introduction to Cryptocurrency Investigations

    In episode 62 of The Cyber5, we are again joined by Charles Finfrock, CEO and Founder of Black Hand Solutions. Charles was previously the Senior Manager of Insider Threat and Investigations at Tesla and prior to that, he worked as an Operations Officer for the Central Intelligence Agency. 

    We discuss the generalities of cryptocurrency and go into the tactics, techniques, and procedures for conducting cryptocurrency investigations. We also discuss some case studies and what proper outcomes look like for making it more expensive for the adversaries to conduct their operations in this generally unregulated world.

    Three Key Takeaways:

     

    • Generalities, Functionalities, and Value of Bitcoin and Cryptocurrency

     

    In its simplest form, Cryptocurrency is digital coins or money (Bitcoin and Ethereum being the most popular). It is not run or governed by a central authority, but by a mathematical algorithm that verifies the transactions, controls the supply of the certain coin, and runs on the blockchain.

    Blockchain, as it pertains to Cryptocurrency, is a ledger that verifies what has been sent and received from an account. It is pseudo-anonymous, it is not anonymous - which is why criminals have been leveraging it so aggressively. 

    When Bitcoin is transacted, the amount sent and received are recorded on the Bitcoin ledger (Blockchain) and associated with a Cryptocurrency wallet address. Criminals think they can hide their identities as a result of not needing a formally validated identity through a central authority. 

    Since Cryptocurrency is not controlled by a central government no one can modify the supply of the particular cryptocurrency. It derives value in the same way the US dollar used to derive value from gold - scarcity. The argument for Bitcoin's value is similar to that of gold—a commodity that shares characteristics with the Cryptocurrency. The cryptocurrency is limited to a quantity of 21 million. Bitcoin's value is a function of this scarcity.

    2) Conducting Cryptocurrency Investigations - Decreasing Return on Investment to Criminals

    When criminals first started using Cryptocurrency in 2012 it was because they thought they could hide their identity. At the time, tools were not available to law enforcement to unmask and attribute actions to persons. That has changed. 

    The two kinds of investigations that clients engage in are reactive and proactive. Reactive are when scams have already been perpetrated against their brand. Proactive are when security teams engage with actors to derive the scam before a significant amount of loss occurs.

    Legal and technical methods can be deployed to “burn down the infrastructure” to decrease the return on investment for online criminals. Oftentimes an outcome can be to contact a centralized bank or Cryptocurrency exchange (i.e. Coinbase) that is linked to the Cryptocurrency as a means to “cash out” the criminal proceeds, report the fraud, and disrupt the activity, thus increasing the costs to the criminals. 

    3) Provenance and Repudiation To Understand Truth, Accuracy, and Completeness

    As with any online crime investigation, investigative techniques identify stylometric attributes of the criminal infrastructure that reveal the provenance of data by the malicious actor. The end provides authorities the ability to repudiate this scheme in the future.

    Often what we look for are lapses in operational security by the threat actors, which include but are not limited to the following:

    • An actor registered a domain and failed to enable private registration before correcting their mistake.
    • An actor forgot to use their VPN or proxy to connect to their C2 infrastructure and revealed their source IP range.
    • An actor reused certificates on different infrastructure or failed to properly encrypt their C2 traffic.

     

    Going a step further, we pivot from technical analysis to open source intelligence (OSINT) to add valuable context to the nature of the threat an organization faces. By exposing network infrastructure and drawing associations using threat information and other technology-enabled OSINT connections, we can determine the motivation and sophistication of the threat. We assess characteristics such as: 

    • Content, stylometric attributes, and similarities between criminal persona accounts and true-name accounts.
    • Re-use of content in a spearphish that was similar to content existing elsewhere, such as blog or social media posts.
    • Re-use of usernames or email addresses to register a malicious domain or subscribe to a third-party file server or virtual private server.
    • Photographs that provide traceable location details such as landmarks or geographical attributes.
    • Screenshots, files, or photos used by the actor that leave vital forensic clues revealing real identity or location. 
    • Details ascertained through direct engagement with the threat actor.
    30 min
  • Combating Account Takeovers and Fraudulent Websites at Scale for SMB

    In episode 61 of The Cyber5, we are joined by Josh Shaul, CEO of Allure Security. 

    We discuss cybersecurity and account takeovers. We focus on the lifecycle of an account takeover , how to permanently solve it, and how to show a clear return on investment to small business owners. We also talk about how to impede attackers by making their efforts more costly and difficult. 

    Four Key Takeaways:

     

    1) Account Takeovers 

     

    An account takeover is a form of identity theft and fraud, where a malicious third party successfully gains access to a user's account credentials. Previously targeted at large enterprises, these attacks are now targeting SMBs.  

    2) Disrupting the Return on Investment Against an Attacker 

    By Automating defenses and rapidly removing fake websites, attackers are faced with increased cost and less success.  

    3) Too Much marketing Focus on APTs 

    A lot of cybersecurity products and technology focus on advanced persistent threats (APTs) and ignore the  threats that matter. Organizations can best protect themselves by mapping technology to the threats that are actually targeting them. 

    4) Intelligence Must be Actionable

    Making intelligence actionable is necessary for proper security regardless of an organization’s size. For many organizations, this is most easily achieved through managed services providers that provide people, process, and technology that is otherwise not attainable for small enterprises. 

    39 min

About the CYBER5

From the publisher's feed

The CYBER5 is hosted by Landon Winkelvoss, Co-Founder at Nisos, and features cybersecurity and investigations industry leaders' thoughts and answers to five questions on one topic on actionable…