Wednesday, September 14, 2016

This 7-Step Cybersecurity Kill-Chain Will Stop Your Enemy Cold!

Are You Concerned About a Potential Backdoor?  

Better still…. Are You Ready to Do Something About It?

Take Action

This 7-Step Cybersecurity Kill-Chain Will Stop Your Enemy Cold!  (But Not Before Gathering the Highly Prized Intelligence you want)

Intelli-Flex partner US ProTech has Mastered the Cybersecurity Kill Chain framework 1st developed with the DOD and in preparation for the CyberSecurity Summit, we wanted to share this information.  It’s part of a process they have termed the “Intelligence Driven Defense model” for the identification and prevention of cybersecurity intrusion activity. The model identifies what 7-steps the adversaries must complete in order to achieve their objective and more importantly how and when to kill their presence.

We are going to run this in this series of 4 blog posts, that will provide you the critical info needed to take action against the greatest threat of our time – Hackers using APT’s.

Today, let’s discuss steps three and four in the process of seven:

1. RECONNAISSANCE
a. Harvesting email addresses, conference information, etc.
b. The first step of any APT attack is to select a target.

2. WEAPONIZATION
a. Coupling exploit with backdoor into deliverable payload
b. Next, attackers will re-engineer some core malware to suit their purposes using sophisticated techniques.

3. DELIVERY 
a. The three most prevalent delivery vectors for weaponized payloads by APT actors, as observed by the US ProTech Computer Incident Response Team (USPT-CIRT) for the years 2005-215, are email attachments, websites, and removable media such as a USB stick.

The transmission and delivery of weaponized bundles to the victim’s targeted environment is the objective but these efforts arrive with some digital fingerprinting.  This stage represents the first and most important opportunity for defenders to block an operation; however, doing so defeats certain key capabilities and other highly prized data.  At this stage we measure of effectiveness of the fractional intrusion attempts that are blocked at the delivery point.

4. EXPLOITATION
a. At this stage exploiting a vulnerability to execute code on victim’s system command channel for remote manipulation of victim is the objective.

Here traditional hardening measures add resiliency, but custom defense capabilities are necessary to stop zero-day exploits at this stage.  After the weapon is delivered to victim host, exploitation triggers intruders’ code. Most often, exploitation targets an application or operating system vulnerability, but it could also more simply exploit the users themselves or leverage an operating system feature that auto-executes code.  In recent years this has become an area of expertise in the hacking community which is often demonstrated at events such as Blackhat, Defcon and the like.

900,833,392+ Records Breached During 5,063 Reported Data Breaches**Explanation about this total

Coming Soon:
5. INSTALLATION  
6. Real-Life Example “IsSpace Backdoor”
7. COMMAND & CONTROL
8. ACTIONS ON OBJECTIVES 

CONTACT US for a demonstration

REGISTER TODAY for the Inland Southern California Cybersecurity Summit (#ISCCS)

Guest Blogger - Jonathan Goetsch, Speaker and Panelist at ISCCS

Jonathan Goetsch is the CEO of US ProTech, Inc., a highly recognized Cybersecurity services company that has been established since 1999 serving thousands of clients.  Based in Las Vegas, NV with operations in California, Texas and Belgium, US ProTech’s Cyber-Expertise serves mid-market to large enterprise business and Governmental agencies in six countries.  As an Offensive-Side Red-Team Cyber Penetration Testing Team, US ProTech specializes in cybersecurity processes that are approved by the U.S. Government, validated by the U.S. Department of Commerce to exceed US Military Standards under NIST (National Institute of Standards and Technology) and accommodates SCAP (Security Content Automation Protocol).  Jonathan’s work in the Cybersecurity community spans the past 20+ years and he’s regularly recognized by the media and his peers for exceptional industry insight, contributions to the community and has been named to The Top 20 List as Global Providers of Cyber Security Services each of the past two years.

Wednesday, August 31, 2016

900,833,392+ Records Breached During 5,063 Reported Data Breaches*

Are You Concerned About a Potential Backdoor?  

Better still…. Are You Ready to Do Something About It?

Take Action

This 7-Step Cybersecurity Kill-Chain Will Stop Your Enemy Cold!  (But Not Before Gathering the Highly Prized Intelligence you want)

Intelli-Flex partner US ProTech has Mastered the Cybersecurity Kill Chain framework 1st developed with the DOD and in preparation for the CyberSecurity Summit, we wanted to share this information.  It’s part of a process they have termed the “Intelligence Driven Defense model” for the identification and prevention of cybersecurity intrusion activity. The model identifies what 7-steps the adversaries must complete in order to achieve their objective and more importantly how and when to kill their presence.

We are going to run this in this series of 4 blog posts, that will provide you the critical info needed to take action against the greatest threat of our time – Hackers using APT’s.

Today, let’s discuss the first two steps in the process of seven:



1. RECONNAISSANCE
a. Harvesting email addresses, conference information, etc.
b. The first step of any APT attack is to select a target.

Depending on the motive(s) of the APT actor, the victim could be any company or person with information the attacker(s) sees as valuable. Attackers “fingerprint” the target to create a blueprint of IT systems, organizational structure, relationships, or affiliations and search for vulnerabilities—both technical and human— to exploit and breach the network. As large organizations tend to invest in multiple layers of security, this step could take weeks, even months. However, the more knowledge the APT actor acquires on its target, the higher the success rate of breaching the network.



2. WEAPONIZATION
a. Coupling exploit with backdoor into deliverable payload
b. Next, attackers will re-engineer some core malware to suit their purposes using sophisticated techniques.
Depending on the needs and abilities of the attacker, the malware may exploit previously unknown vulnerabilities, aka “zero-day” exploits, or some combination of vulnerabilities, to quietly defeat a network’s defenses. By re-engineering the malware, attackers reduce the likelihood of detection by traditional security solutions. This process often involves embedding specially crafted malware into an otherwise benign or legitimate document, such as a press release or contract document, or hosting the malware on a compromised domain.

*Explanation about this total

Coming Soon:
3. DELIVERY 
4. EXPLOITATION 
5. INSTALLATION  
6. Real-Life Example “IsSpace Backdoor”
7. COMMAND & CONTROL
8. ACTIONS ON OBJECTIVES 

CONTACT US for a demonstration

REGISTER TODAY for the Inland Southern California Cybersecurity Summit (#ISCCS)

Guest Blogger - Jonathan Goetsch, Speaker and Panelist at ISCCS

Jonathan Goetsch is the CEO of US ProTech, Inc., a highly recognized Cybersecurity services company that has been established since 1999 serving thousands of clients.  Based in Las Vegas, NV with operations in California, Texas and Belgium, US ProTech’s Cyber-Expertise serves mid-market to large enterprise business and Governmental agencies in six countries.  As an Offensive-Side Red-Team Cyber Penetration Testing Team, US ProTech specializes in cybersecurity processes that are approved by the U.S. Government, validated by the U.S. Department of Commerce to exceed US Military Standards under NIST (National Institute of Standards and Technology) and accommodates SCAP (Security Content Automation Protocol).  Jonathan’s work in the Cybersecurity community spans the past 20+ years and he’s regularly recognized by the media and his peers for exceptional industry insight, contributions to the community and has been named to The Top 20 List as Global Providers of Cyber Security Services each of the past two years.

Monday, June 27, 2016

SD-WAN – a.k.a. A Three Stranded Cord Is Not Easily Broken

Many of us have heard the adage: "A Three Stranded Cord is Not Easily Broken."  Inherently, we understand that this is true. We see this in demonstrated for example when we purchase rope: lots of strings intertwined.  Over the years as the cords weaken, one may break but the rope still holds.  With this basic explanation, you now understand SD-WAN.  


Now let me explain a little further.

Whenever a new technology solution arrives on the scene it takes a while before its widespread adoption. Part of the reason is that new terms are created and blended with our existing vocabulary creating confusion. SD-WAN is a new technology born out of a recognition that one of the major expenses for many organizations is their bandwidth.  Over the years numerous technologies have been introduced to reduce these cost:
  • MUXes
  • Voice over Frame-Relay
  • VoIP
  • WAN Optimizers

Just to name a few.  

The carriers have also been trying to stretch and maximize their investments. For most of us the network has become a utility.  We expect an always on network and use it constantly. Just look around, the proliferation of hand held mobile devices with a plethora of applications that allow non-stop communication, entertainment, and access to information (Maps, Google, Starbucks) has created a demand for bandwidth that is frankly challenging to meet.  Each of the respective carriers is adding bandwidth daily.  I work with a number of them and Time Warner, AT&T and others are laying fiber all over metropolitan areas.  Private companies have cropped up that lay and sell both dark and lit fiber. 

We also see that the cellular companies are adding and upgrading cell sites and working to partner with other cellular companies to exchange bandwidth. The appetite for bandwidth is so high that 3rd party companies are building cell sites and selling or renting them to the highest bidder. 

Enough said, back to SD-WAN.

This demand for higher amounts bandwidth is a challenge for most, if not all, organizations. Every CIO is faced with the need to increase the amount of bandwidth, while trying to maintain costs. IT Budgets are consistently flat¹ and 80% of the IT budget is spent just maintaining the status quo. The reality of today is that the network IS a utility and if it goes down, most organizations come to a grinding halt. “All the while, of course, the IT department is expected to deliver value for money by minimizing capital expenditure and operational costs wherever possible.” ²  My focus is SDN over SPB, and while I seek to build secure, resilient, "always on" infrastructures that are easy to manage and deploy, eventually we have to leave the premise and traverse the WAN. Whenever I have to extend my network fabric over the WAN I am faced with the reality that the single MPLS pipe they pay for becomes my single point of failure. It doesn’t matter that my SDN network built on SPB has sub-second failover, if that WAN link is the only link, my network is down. Those virtual servers and applications are cutoff from the users. I now bring in my carriers and help the customers to create a more resilient WAN. 

Enter in SD WAN.   

Talari and other companies have developed technologies and algorithms that allow the bonding together of multiple lower costs links from different carriers into a single, higher aggregate bandwidth pipe, that has higher availability and throughput than a traditional more expensive MPLS network. In addition, because we have spread the bandwidth over different medium (cable, fiber, G4, etc), and different companies, the failure of any one link does not bring the network down and is therefore more resilient. So, the adage:  A three stranded cord… applies. 

There are a number of organizations that are offering SD-WAN³, and there are a number of great white papers available⁴ for those of you that would like to get a better understanding of what, how, who, etc.  Most traditional router/WAN Optimize vendors have begun to develop products in this area, so make sure, when investigating them to do your research. I work with a number of carriers and they are starting to include this as part of their service. They provide multiple connections over different technologies and incorporate the SD-WAN service as a bundle. I suspect that this trend will become common place. It seems like a win-win to me. As with most technologies today, there are hosted and premise offerings and many include firewalls, etc.  Make sure if you opt for a hosted solution, that behind the scenes, they are not creating a single point of failure. As always: Caveat Emptor a.k.a. get references. 

Good luck.

Wednesday, April 20, 2016

Shhh… It's a secret! Third Party Maintenance

Ever find out about something new only to find out that it wasn't really new at all? Not only that, but that many before you had made the discovery and were already reaping the benefits.   That's fine, as Alexander Pope said:  "Be not the 1st by which a new thing is tried, nor the last to lay the old aside."  So, rather than lamenting over what cannot be reclaimed, I have come to embrace that I am now blessed with the ability to take advantage of it and can't wait to share the news with others, who like me were previously in the dark.

For years I had been working with customers and encouraging them to make sure to keep their equipment warrantied by the manufacturer.  Advising them "Don't go on the tightrope without a net."  The risks to the business were too critical. 

Fast forward to today.  80% of our customers IT budgets are spent to maintain status quo and a large portion of this it tied to vendor maintenance.  That leaves only 20% of their budgets available to bring on new applications that enable the organizations to take advantage of the technologies and services I offer.  Technologies and services that can bring about transformation of their businesses.   In trying to solve this conundrum for our customers and help them to recognize the benefits of revitalizing their organizations through improved communications services, I stumbled upon Third Party Maintenance (TPM).  These TPM Services offer lower cost technical support for the key vendor offerings.  I am talking substantially reduced rates with easier administration because they are provided through a single source.   So we have centralized contract and support administration.  Yes, Virginia there is a Santa Claus!  The same technical support for products and applications, hardware replacement, patching, etc.  So how is it that I never knew about this?  Well reality is that the Vendors are never going to share this information, they count on maintenance dollars.  Many sell hardware just to get the maintenance.  So, and unless you were among the select group of companies using these services by these exclusive organizations, you didn't realize it.  Recently however, Gartner, Forrester and IDC² all published articles on the topic and so the secret is out.  Savings can be achieved in a number of key areas:

1.       Lower Hardware Replacement costs
2.       Reduced TAC (Technical Assistance Centers) - Live help
3.       Eliminated Software Support costs
4.       Extended refresh cycles on hardware and software

This is really good news for all of us.  These saving can be used to accomplish a number of key initiatives such as funding for: 

1.       Outsourcing IT to a managed service  - allowing exiting staff to refocus on core competencies and project completion
2.       New technology introduction (SPB/SDN) that will enable faster, non-disruptive new application introduction
3.       New applications that improve business processes and revitalize communications
4.       Additional staffing, enabling project completion

Now, "any change, even for the better is always accompanied by drawbacks and discomforts¹".
For example: 

Quality Concerns:  Some will be will be fearful that they will not get the same levels and quality of service.   This was my initial concern, but having investigated this a bit, and seeing organizations such as Walt Disney, I was put at ease.  Disney does NOT accept lower quality service, I suspect that it is actually better.
 
Vendor Resistance:  Guaranteed, you will hear resistance and pushback from the Vendors.  No doubt, your Cisco Rep is NOT going to be happy to see you cut off SmartNet (Smart for them, expensive for you).   Maybe a few less Box Tickets to your favorite sporting events.

Refresh Policies:  You may also need to redo some long engrained policies around hardware refresh.   But Gartner/Forrester/IDC are all saying the same thing:  Why replace equipment that is performing the exact same function it was when purchased and that is still working, has an MTBF (Mean Time Before Failure) of 15+ Years?²

So, consider a change that will allow you to be the hero to the team, because you will be able to say yes to some of the projects on hold for budget, and can help your organization begin its transformation.

¹ Arnold Bennett
² Challenging the Status Quo on Maintenance Contracts and Refresh Cycles to Lower Costs

Wednesday, April 6, 2016

What Exactly is the Internet of Things?

Internet of Things/Internet of Anything/BYOT (Bring Your Own Thing)?  Pick one.  They all work.

I apologize in advance for the excessive use of alphabet soup acronyms, it is the way of the industry.  If you don't know what they are, Wikipedia is a good start.

What exactly is the Internet of Things?  It is a world where IP addresses are applied to non-traditional network devices that allows them to be controlled by network management (Software Define Networking/SDN).  It is kind of humorous, but a perfect example is seen in YouTube videos that people post.  Videos of them watching their pets on their PC's/Smart Phones, doing the oddest things while they are away via IP cameras installed in their homes.

All this is done is being transmitted over the Internet.  Your turn. You think of something you'd like to do.  How about being able to check your groceries in when placing them into your refrigerator or freezer, track the contents and create recipes based on what you have on hand?

Yes, you could correlate what you have in your cupboards to recipes on the Internet, even tie them to your diet preferences (Gluten Free, Dairy Free, Low Fat, Low Carb, and Weight Watchers) and voila!  You now have a meal based on what you have on hand, or even, create a shopping list based on what you have used.  No longer do you need to call some to check to see if you need milk, etc.  You just login to your home and check to see if there is milk in your refrigerator.

Far-fetched?  Not really.  The capabilities exist today.  The concept of tying your devices to  a network (home or office) and the Internet and then doing a Mashup¹ to combine the information with other information available on the Internet to create useful usable knowledge from information.

Another example is aligned with the PoE+ standards.  PoE+ (Power over Ethernet)  The updated IEEE 802.3at-2009[7] PoE standard also known as PoE+ ² that allows devices that are not traditionally considered network devices (lights, HVAC [*Heating/Ventilation/Air Conditioning], water heaters, refrigeration, and other devices) to be IP enabled and thus monitored and controlled by standard network protocols (Ethernet/IP(Internet Protocol)/SNMP (Simple Network Management Protocol)).

Beyond this there is the draft-unbehagen-11dp-spb-00, dated December 31, 2014, that speaks to an extension of the RFC 6329³ to allow Auto Attachment of devices to an SPB (Shortest Path Bridged Network 802.1aq)⁴ network using the LLDP (Link Layer Discovery Protocol- 802.1AB)⁵.  This means that dumb devices, like unto Wireless Access Points (APs), Cameras, LED Lighting, etc. could be provisioned to use the existing protocols as defined by the IEEE Institute of Electrical and Electronics Engineers) to attach to a network and securely connect to the appropriate services.

What it means to businesses?  A worker or person (perhaps your Grandmother) that knows nothing about networking can connect these devices to an Ethernet port and it will auto-provision.

I promise you I am not purposely intending to confuse you by using all these acronyms.  

Once connected to the network these devices can be remotely monitored and controlled by a person or persons that is authorized to do the provisioning.  It is all there, pre-built and it makes complete sense.  Every day, new devices are being added to the list of IP/Internet enabled devices can connect to an Ethernet PoE+ switch, get power and automatically join the network and be securely managed.

Over the next few years, you can expect to hear about smart buildings that have very low power consumption (PoE+) partly due to the use of lighting products that are comprised of LEDs that require minimal power and phones and devices that connect to the Ethernet switches to get power an allow control.   These smart buildings will be able to be fully automated via software to meet the needs of the tenants, while maximizing the efficiency and customizing the facilities to meet the specific needs of the occupants.   I am looking forward to the day when every office has its own climate control.

Ordinarily, my immediate concern would be for security, but thanks to SPB (802.1aq & RFC 6329) these networks can be stealth networks (read that as invisible) and therefore inaccessible to malevolent probing entities.  The Access Control will be defined in Software Profiles (SDN -Software Defined Networks).  So, the access to the network and control will be restricted to those users on approved devices, having the proper security profiles.   No hijacking of the network, no ransoms.

Tomorrow is a whole new world, and with the IOT and BYOT (Bring Your Own Thing) you will find happier employers and employees.  No longer will a bright, talented worker arrive at an organization only to receive two year old technology.  Instead, they will bring their computing device of choice (MAC, Android, Windows, and Linux) to the job and it will attach to the network with a profile that grants it access to only those records that are necessary to perform their duties.

The companies will no longer have to concern themselves with the capital and operational expenditures for PCs, Phones, Tablets, etc.  Each user will bring their own (they may need to provide some monitors and/or universal docking stations).  Cabling will be minimized, also reducing costs.  As WiFi matures and we move into 802.11ac Phase 2, speeds and densities will be sufficient to untether our users and allow them to work….where ever:  Where ever they are, on whatever device they choose, using whatever mode they prefer (Text/IM, Voice, Video, Immersive Collaboration).

So, let your imagination go and imagine what Thing you will attach.

The IoT Playbook for Wireless LAN

References:  
¹ "A mashup, in web development, is a web page, or web application, that uses content from more than one source to create a single new service displayed in a single graphical interface. 

From <https://en.wikipedia.org/wiki/Mashup_(web_application_hybrid)> "
² PoE plus, provides up to 25.5 W of power.[8] The 2009 standard prohibits a powered device from using all four pairs for power.[9]

From <https://en.wikipedia.org/wiki/Power_over_Ethernet> 
³ RFC 6329 - An IETF Standards Track defining the extensions to the IS-IS standards for Shortest Path Bridging 802.1aq using SPBM (MAC-in-MAC 802.1ah) and SPBV (Virtual LANs).
⁴SPB (Shortest Path Bridged Network 802.1aq) - IETF Standard that defines shortest path forwarding in a mesh Ethernet network using multiple equal cost paths.
⁵LLDP Link Layer Discovery Protocol, an IEEE Standard for LAN/MAN Media Access Control Connectivity Discovery

From <https://en.wikipedia.org/wiki/Institute_of_Electrical_and_Electronics_Engineers> 

⁶SDN is an evolving standard based on both Open Flow/Open Stack that allows centralized control to network access.  Specific deployment options vary from Vendor to Vendor.  SDN is championed by numerous organizations including ONF (Open Networking Foundation), IEEE, Avaya, HP, Sun, etc.

Thursday, March 31, 2016

To the Future Employees of Information Technology

This week, I had the honor of addressing the graduating class of 2016 at ITT Technical Institute. Many students received degrees in IT, business, computer science, electrical and industrial engineering, drafting and design, project management, network systems administration IS and Cybersecurity.

That their program includes Cybersecurity got me excited. As we all know, ransomware attacks have become more and more prevalent. Emerging technologies such as SDN and SPB are designed to negate this danger for networks. The solutions are available TODAY and these graduates will be the ones to protect their future employer’s networks from hackers and cyber stalkers.

I spoke to these future employees about why it’s a great time to enter into the industry. I shared that when certain pivotal technology is introduced, it becomes an enabler of a whole new era of possibilities, pointing out that nearly two-thirds of the jobs that will exist in the future – jobs that these graduates will eventually occupy - haven't even been named. Some good examples:  Graphic Artist?  CAD Engineer?  Web Developer?  Who heard of them 20 years ago?  The evolution of these technologies bring about improvements and widespread adoption and availability to the general population.  Whole new industries are born with endless possibilities and exciting careers!


We live in a time that this evolution is propelling us forward at a rate that previously only existed in science fiction and the movies.  This new generation of IT focused students will be part of this transformation, if they chose to. I hope they do.

Friday, March 25, 2016

Magic Quadrant Leader Mitel Looking To Go Bigger

A Mitel/Polycom merger would certainly be advantageous to both organizations.  Mitel has a solid Voice/UC footprint and history.  They recently have made a number of noteworthy acquisitions (PrairieFyre/Oaisys/Aastra/Mavenir) and partnerships (Vidyo/LiveOps) that they have been able to capitalize on.  This track record is evidence of a company with a good grasp of the industry and trends.  With the acquisition of Aastra, Mitel has a large hosted footprint and the ability to provide a hybrid solution to meet the real-time communications needs of an increasingly mobile and dispersed workforce will ensure they are invited to the table. 

The Mitel/Polycom blend would bring both organizations into a key position for hosted, mobile and IP endpoints.  In addition, with the widespread acceptance and expectation of immersive UC that allows anywhere collaboration across diverse endpoints, the merger would make them a de facto leader in this space. 

This is certainly something to keep an eye on.  Shoretel, are you sure you don’t want to be acquired?