Having issues accessing the video above? Watch the video here.
Lessons Learned from 2017 Investigations
If you could go back to the beginning of 2017, what would you improve about your organization's data security? While traveling back in time might not be an option, Dave Ellis, SecurityMetrics' Senior VP of Investigations (GCIH, CISSP, QSA, PFI), gives us his forensic predictions for 2018 to help you strengthen your organization's defense. View this webinar to learn:
- Current data security and breach trends
- 10 tips to avoid a data breach
- 2017 forensic investigation findings
This webinar was hosted on February 28, 2018.
Lessons Learned from 2017 Investigations Transcript
Welcome to today's webinar, lessons learned from twenty seventeen forensic investigations.
We're glad that you're all joining us today, and hopefully, we can answer some questions that you have and and give you some information about our, investigations, in twenty seventeen.
Our presenter today is Dave Ellis.
Dave has led the computer forensic investigations team at SecurityMetrics experience and retired from enforcement and investigations experience and retired from the Oakland Police Department in Oakland, California at the rank of commander.
While serving at the Oakland Police Department, Dave held numerous positions, including commander of the hostage negotiations team.
I threw that one in because it sounds a lot more interesting than the computer geek stuff.
Alright. And he also oversaw the computer forensics team.
Dave studied international relations at Brigham Young University and received a bachelor's degree in criminal justice administration from Columbia College and is a graduate of the FBI National Academy.
Dave has been a featured presenter in North and South America, Europe, and Australia regarding Internet based crimes and has authored several articles regarding current trends in the electronic theft of credit card data.
So we are very lucky to have Dave here presenting with us, and he's gonna have some great information to share with us today.
Just a little bit more about Security Metrics. So, all of us here at Security Metrics, you know, the this organization has been heavily involved in the, PCI data security industry, and and the HIPAA industry as well.
We've been helping organizations comply with mandates, avoid security breaches, and recover from data theft since two thousand.
And just a couple of housekeeping items before I turn the time over to Dave here.
One question we get quite often is will we be sending out the recording of this webinar and the slide deck? And the answer is yes. We will be sending that out to you in the next few days here to the email address that you used to register for the webinar today.
So keep an eye out for that. We'll be sending that out, and we invite you to share that with others at your organization and anyone else you that you think could benefit from this information here today.
One other quick housekeeping item. At the end of the webinar today, we will hold a quick q and a session. So if you have any questions that pop up during the webinar, we invite you to chat those in on your GoToWebinar control panel, and we will get to as many of those questions as we can at the end of the webinar.
We'll stick to the more broad general questions that we think are most applicable to everyone.
And then if there are a few questions that are specific to you, still feel free to chat those in, and we'll have someone reach out to you on an individual basis here, in the next couple of days. So alright. Well, again, we're we're happy to have a a large group here with us today. And at this time, I'm gonna go ahead and turn it over to Dave.
Alright. Thanks, Andrew.
It's pleasure pleasure to be with you this morning and or this afternoon if you're on the East Coast, and thanks for, joining in with us.
On that, on that introduction, you know, you mentioned that, I I was a commander over the hostage negotiations team in Oakland, which, did come into play a few times, probably more so in my home than, than anywhere else. And I'll tell you, I would much rather negotiate a an interrupted bank robbery in progress. That guy's easy. Going home and negotiating, you know, with my wife and five kids, I lost those every time.
But, with respect to my new position, I would I would I remember after getting into forensics on this side of on the corporate side after I retired from the police department, going home kind of talking about, you know, how my day was at work, though not terribly dissimilar from when I was on the police department. I I wouldn't share a lot of those details with the family, but, you know, some some I could. And I remember in specific one time going home and talking about this really creative hack that I had was in the middle of investigating and and how how this hacker was just brilliant. I'm
I'm just going on and on about it. My dad I remember my daughter looks up at me and goes, dad, your old stories were way better than the new ones. So with that, you know, some of the the anecdotes we're gonna, share today probably aren't going to be picked up by, by Hollywood, but, there are some interesting things in there just the same. So sort of the the format we're gonna go through is, we're going to be looking at, the the current trends.
The things that we saw saw last year that were spelling kind of what was happening or changes in the way hackers were doing what they were doing to to get in and steal our information.
Following that, I'll I'll go over ten tips that will hopefully help us, not become one of the statistics.
And on those, all ten of them might not apply to your environments, but I'm pretty certain several of them will. And then I'm gonna finish it off with kind of my my my favorite part of it, which is where I look into the crystal ball and and try to predict, things that we're going to see in the future by these attackers, that we that haven't been, you know, super prevalent just yet. And, you know, with that said, I'm actually going to begin today where I ended last year.
Wanna take a look at the predictions that we made last year and see if, you know, how they came to pass. So last year's presentation talked about the insecure remote access be continuing to plague, and and it certainly has. It's it's been probably the number one slash two most common vulnerability that caused problems for us.
The the large scale POS breaches will decrease, but employees remain at high risk.
The that that certainly has happened.
We have seen annually or or especially toward the latter half of the year, we saw the large scale breaches definitely decline.
Employees in those were the the biggest weak point, and that was where we had employees, you know, opening up phishing emails and things along that line, which are outside of the the ability of a good IT manager to be able to to correct.
So, let's see. Overall number of breaches will temporarily decrease, and that that has also proven true.
What we're seeing is the POS when I say smaller, I mean, it's something short of a level one.
With the advent of EMV, we did see those go down, and and what we expected was the, the ecommerce breaches proportionately increased.
And to kind of put that into perspective, in the payment card investigations, we saw, in twenty sixteen, thirty eight percent of the investigations that we performed, were ecommerce. And in twenty seventeen, that that number went up to fifty six percent.
We also saw a near twofold increase in attacks against health care targets.
According to Malwarebytes, ransomware was the most prolific gainer of the past year. It tripled in number over twenty sixteen, and a full sixty percent of all malware payloads that were installed onto commercial systems in twenty seventeen were ransomware.
Now ransomware has gone through, the same iteration as popular POS malware attacks.
And, you know, if you look back at the the malware attacks against commercial targets, say, you know, go back about ten years.
When we first saw ransomware a couple of years ago, it they they were messy. The the the attackers were going in. Basically, they would encrypt oh, and just a real quick description for anyone who's listening that might not be familiar with ransomware.
That differs from a malware attack, which a malware attack, they go in and they're trying to get something off of your system like HIPAA data or, PII, personally identifiable information, credit card information, some of the the secret sauce of your business, anything that's critical to your business. Ransomware isn't going after that at all. They just wanna go straight to your checkbook. And so they go in and they encrypt, you know, some or all of your systems, and they then offer that, you know, if you pay this ransom, and it's usually in, you know, in the form of Bitcoin, or some cryptocurrency, if you pay it, then we'll go ahead and give you the key to to unlock it. So ransomware kind of went crazy, and, initially, as I was mentioning, it was it was messy. You could tell it was rudimentary. It was in the beginning stages.
It has, certainly evolved. The ransomware attacks that we saw the last half of last year were very sophisticated, leaving, far fewer breadcrumbs for an investigator to follow, than before. And, so let's see here.
Okay. We can move on. I apologize for that that brief delay.
I wanna start with a a sample attack, for example, of and and this is in response to some of the inquiries that we received. They they asked me to go through and talk about just very briefly, an initial attack meeting, how the hacker initially gains access to a system, and and then, you know, what they do with the information and how they're able to commercialize it. So we'll go through this kinda quickly.
Initially, they typically will start with a very, generic Internet scan, And and the vast majority of the small businesses, small health care systems are not individually targeted where the the hacker walks up to his computer, sits down, and says, I'm gonna go after, you know, the ABC hardware company, or I'm gonna go after the x y z health care insurance company or anything like that. They typically, or more typically, will sit down at their computer, and they will launch a port scan of scanning, you know, two hundred and fifty thousand or five hundred thousand IP addresses, you know, a certain range.
And then just imagine, you know, they they go to bed and they wake up in the morning, they pull out their newspaper, and they're having their coffee, and they are perusing the results of their port scans. And what they're looking for specifically is, for example, they see an IP address and port, you know, fifty six thirty one is open or something like that. They're going, oh, hey. They're running remote access software there. Let me see if I can log in, you know, through their, their remote access. And so they're going to now, put in a username, to log in, and they'll put in they'll type in admin or administrator because a lot of systems have that available. It's pretty common.
And now they're only down to, one element to have to break through, and that's the password. And so they will, at that point, do a a brute force attack against the passwords.
And if they're successful, they get in and they, you know, they they've now gained access, and they're gonna start to test what, what they can do, what they can see. And it's often at this point they realize either, yeah. Hey. I'm inside of a b c hardware or x y z HIPAA, you know, in in health care environment, and there's potentially HIPAA data. Or they go, oh, I'm inside, you know, somebody's home network, and I'm looking at at, their photos from the vacation to the Bahamas last year. At this point, if they discover they're in a a commercial environment or some environment that they can exploit, they're going to test, you know, how how far they can get around.
And if they're successful, you know, they gain full access to the system, and then they begin to monitor the activity.
At this point, they may install something like a key logger where they can if the the person who owns that system goes onto their computer and logs into something, they can now capture their their login credentials.
The next step would be they could download malware onto the system that would capture data, or this would be where they would download their or they would encrypt the system if it's a ransomware attack.
And then after that, it's the manner in which they either capture confidential information or they, confidential information or they, you know, or or they contact the owner of the system and levy their, you know, the ransom demands.
So all of that said, that, you know, that very, very high level talking about how how they, you know, get into a system, there are certainly a number of variations.
But at this point, now they're they're going, okay. How can I make money off of this? Well, the the first way is they they can, if it's credit card data, they they can do that use it personally. They can take that those credit card accounts, go online, they can buy TVs, have them shipped to, you know, some some warehouse address or something like that, a very short term environment.
They buy those. They can use them. They can turn around and sell them.
More commonly, they'll they'll use the credit cards to turn around and buy, gift cards or prepaid credit cards, something that instantly turns that that attack into cash for them.
Now the what we're seeing is more common. Now that first scenario would be the individual hackers, but as you might suspect, these hacking organizations go very deep, and it's it's it's the new mafia. It's the new organized crime.
And I I was talking with, a government agent in Europe and as well as one in in the United States on separate conversations, and they both confirmed that organized crime there, that Internet based crimes has risen to the top of their priority. And here in the United States, about seven years ago, income to organized crime from Internet related crimes has exceeded the value than the profits from narcotics trade. So it's it is that big. It's, you know, a multibillion dollar industry worldwide.
And so moreover than the individual who's who's stealing this data and using it for himself, you're seeing that they are going to the, the dark web, and they're selling it. They sell them either individually or they sell them in bulk.
Let's see. This, this screenshot here is of a an offering on the dark web for credit cards that had been captured.
And, you know, if you look at it, it it it breaks it out by area. The first group there is, some cards that are available in the United States, and what they're saying is, you know, where it says one piece doesn't it isn't meaning that they're only selling one card. It's it's it's twenty dollars per card if it's just a standard classic card, twenty five if it's a gold or a platinum, thirty dollars if it's a business signature, you know, corporate card, American Express twenty dollars and then you can go down through the regions Canada, Europe, Asia, Latin America, you know, they all have different prices. If you stroll down there a little ways, you'll see a business signature purchase corporate world card for a hundred and twenty dollars, an infinite card for a hundred and fifty dollars, and then he gives the rules of of the transaction.
So these are these are very, very large organizations hiring extremely talented individuals, to hack in and and and and steal, you know, your and my data and monetize it. Now the the the truly scary part of this, the people that are involved in it, a lot of this money is flowing to terrorism.
And so that that's why you have, you know, the FBI and the Secret Service.
Those the the priorities of the investigations for Internet based crimes is extremely high for them because they know what they're truly fighting is they're they're trying to fight terrorism.
So I'm gonna go through now the the trends of of what we saw last year, as we compile statistics and data from the the investigations that we performed.
And I'm gonna start with just looking at, you know, the the areas where we saw the most common failures and how those failures translated into, you know, an effective method for the the attacker. The first one is firewalls.
In the investigations that we performed, we saw that that about fifty two percent of the, the the cases that we were investigating now this isn't to say fifty two percent of all merchants in the United States have inadequate firewalls. This was fifty two percent of the breached merchants, health care organizations, private parties that we saw had, inadequacies in their firewall configuration.
Either, in some cases, no firewall whatsoever. It was directly connected to the Internet, or more commonly was that, they weren't properly configured.
There were times when I was reviewing firewall logs and, you know, with extremely elaborate firewall rules all through out, and I get to page, you know, nineteen or twenty nine of their firewall logs, and I see an allow any to any.
And what that means is is that was a a default, rule that was present on the firewall is how when they unbox it, it's in any to any environment, which means I will allow any connection from my system to any connection out there, and I will allow any connection out there back into my system. So where I found that in this group of firewall law or firewall rules meant that everything before it was irrelevant.
So, and then outbound rules. Oftentimes, people will will put together a pretty decent set of rules governing what they will allow into their network and they forget to, put anything into the outbound network. Where that is important is that, if, for example, you know, your, your your firewall is trying to protect a system that is processing credit card data, that terminal has some very limited places out out in the world that it needs to communicate with. It needs to communicate with the processor, with the acquiring bank, something like that. And so right yeah. It's important to write a rule that says the only outbound communication I'm going to allow on this terminal is out to the processor for authentication of the transaction. And you can blacklist the entire rest of the world, the rest of the Internet.
Passwords have been a bane, of computer security probably since the invention of the of the password.
We see times when, you know, similar to that firewall rule that didn't get changed from its default setting, oftentimes passwords aren't changed from their default settings either, or people, you know, do something that's that's too simple such as the word password and and whatnot. You know, a couple of years ago, there was a a big Internet breach that resulted in over a billion passwords being lost.
Well, those those passwords weren't lost. They were very cleverly inserted pretty quickly attempting these different passwords.
Now your a system should be set up to, lock itself down if three, incorrect passwords have been entered consecutively, and and that's another portion that we do look for in systems and and we recommend.
At the end of this presentation, one of my predictions is gonna be regarding passwords.
I hope you hang around for that because it it's I I got it listed in the area of things that scare me in the future.
Next, antivirus, very simple that, the the failures here are usually either there's no antivirus or it's expired, it hasn't been updated, or they have it on some systems but not others. The inconsistency there, has been a problem. We we have seen attacks where, you know, they had, like, six or eight devices, you know, in that network segment that got it, breached.
And, excuse me, and, you know, half of them had had up to date antivirus and which picked up on the problem and but there were a couple of endpoints that didn't, and so there was data loss from those endpoints.
Antivirus was a little bit better. We found seventy two percent of the investigations had adequate antivirus running, which, you know, left about, twenty seven and change percent that were not compliant with this. Where this one, makes my list though is because in in about thirty percent of the cases where they had inadequate antivirus, that inadequacy was a direct, contributor to the fact that they were breached, where the others, you know, may or may not have been quite as strong of a factor. The last area, that I wanted to go through on well, actually, I I've got a little another point, but, secure access, this is talking about who your system is allowing to gain information.
It it goes to you know, it it could be a matter of you have a weak authentication password.
Most of the time, this is lack of multi, multifactor authentication.
This has been a a topic for the last several years where, you should not have any, you know, important aspect in an area of your computer that allows you to log in without requiring some secondary level of of authentication, such as, you know, an SMS message to your phone that requires you to enter a a code and that code changes every thirty seconds, something along that line.
Again, as we get at at the end and I I talk about what is in all of our futures with this, we're gonna talk a little bit about this because this is going to become the only, saving factor that we have in in our computers. So I I'm I'm foreshadowing a little bit of doom and gloom at the end, but, but we'll also talk about ways that we can, we can survive through it all. The last couple of points that we saw with some consistency, more than one primary function per server, and this would be a primary function per server, and this would be a case where, you know, if you have a a device that is designed to, take patient information or take, credit cards or something like that, the more you can do to segment that device down and keep it separate from the rest of your environment, the the better off you are and the easier it is for you to provide security for the most critical aspects, the most critical, information pieces in your environment.
So we'll we'll chat a little bit about that more, later. This last one, application security updates, that that one goes back, you know, several years, and it continues to be a problem. And that's where the, you know, you have a payment applications, for example, like Magento.
They had a breach a few years ago and quickly put out a a patch for it.
But for the next two years, we were investigating businesses that had you know, were running the Magento payment application and had been breached because of that vulnerability simply because the owners of the systems failed to update the and apply the security updates and patches that had been provided months and months ahead. So there so we saw so many businesses that didn't need to be breached if they had just had somebody kind of minding the store a little bit better, paying attention to when security updates are are offered.
So with that said, I'm gonna show just a a quick slide on, trends kind of in the in the right direction. These were the the payment card industry specific, trends that were, most commonly found in compliance, protecting the stored data. And and that one goes back to, you know, years before or years earlier. Payment applications were storing customer credit card information.
They they fortunately were we're pretty much past all of that now. All of the the payment applications out there that are commonly in use, don't store, unencrypted cardholder data any longer. We found a few cases which results in the twenty four percent being non compliant where the system would for example, if it threw up an error log in a transaction, it would store that log with unencrypted credit card information in it. There was a few other businesses that that felt they had a business need, to store unencrypted credit card information, but, you know, three quarters of the of them got it right.
And, again, that's three quarters of breached merchants.
So that you know, these these elements show that these were not factors in the reasons why they were breached.
Secure data over open and public networks, that means when the data is in transit, is it encrypted? And, again, most of the the, the systems get that, you know, pretty right.
Restricting access to data, and that's a matter of, you know, the the people in your environment that have access to, customer information, to PII, to HIPAA data, is it is that restricted to just the people who need to have access to that for, their roles and responsibilities at the company, or do you have situations where you have, you know, a VP in the company who says, yeah. I need to have access to it. So we'll we'll get into a little bit more of that later. And last was the physical security. We unlocked door and somebody walks in and has access to, PII or confidential information.
Ninety four percent compliance there. On the, health care side, the FBI reports increased attacks against health care organizations.
These two elements here are are of particular note.
Eighty eight percent of all of the ransomware attacks that, went out out in the US last year were targeting health care organizations.
The the other twelve percent were targeting individuals or, you know, or businesses other businesses. But, so if you're in the health care industry, you can you can see that that they recognize that if they hold hostage the, patient information or or doctor's notes or whatever it can be, you know, they understand that the health care industry has to act immediately.
So that that's why you're the target there.
Eighty nine percent of the studied health care organizations reported having a breach involving the loss of patient data in the past two years, and this was by the Pullman Institute.
And I think they they, their sample was they looked at about five hundred, health care organizations at different levels. And again, practically nine out of ten said that they had experienced some sort of a of a breach.
Staying with health care, looking at, HIPAA requirements, we found in the investigations, that seventy eight percent were compliant, with encrypting patient data.
Fifty five percent were compliant with the firewall rules. And everything I said earlier about, you know, weaknesses in the firewall rules, in the PCI environment were almost identically applicable here in the in the health care industry.
Only a quarter of the health care industries that we looked at, and this was both from surveys that we performed as well as investigations that we performed.
Only a quarter had what we regarded as acceptable remote authentication for access to confidential information.
Just finishing this out, unique login credentials in the HIPAA, two thirds were compliant.
One quarter of those performed penetration tests. We'd certainly like to see that number go up. Penetration tests and and a quick note on penetration tests, they're not all created equal.
If if, you have a choice between having a professional white hat penetration tester go through your system or a an off the shelf, you know, out of the box kind of automated penetration test, you you're probably gonna spend a little bit more, but I highly recommend you go with the professional investigator.
Studies have shown that they are far more competent at finding the the weak spots in your environment, plus they will get into testing, phishing and, you know, other types of of, you know, employee based problems that could lead to you being breached.
Last, we saw about a third of the the companies were providing, employee training on data security and were actually testing their employees on data security.
And we highly recommend that, and we'll get into that a little bit more more as this goes on.
And last, thirty four percent were compliant with training employees on who has to be notified in the event of a breach. That varies state by state, and it varies by industry. So, you know, rather than break it all down, you know, fifty two ways divided by, you know, another four or whatever, you know, be aware of what the reporting mandates are in the state and and industry where you live and work.
Definite increase in attacks against service providers.
Successful attacks against service providers showed, you know, a doubling over the previous year.
Attacks against service providers are especially dangerous because of the potential impact on numerous other businesses.
Two or three service provider investigations immediately come to mind, you know, for me that we we performed last year, in the last quarter of last year. As a matter of fact, in one, a credit card processor suffered a breach, but they self discovered the breach relatively quickly.
In the short period of time that they were exposed, a hundred and fifty of their merchant clients were also breached as a result. Now had they not self discovered that, that hundred and fifty based on the the transaction volume that this processor handled, that hundred and fifty could have easily turned into five hundred other businesses.
In another case, we saw, an application vendor that was breached in. They they this app or this vendor provided a web interface for a specialized type of business, that allowed their online customers to place orders. Well, they suffered a breach that resulted in in the attackers installing malware on the systems of more than four hundred and fifty separate businesses.
So this is a case where you have one entity that gets breached, and as a result, four hundred and fifty unrelated businesses were hacked and and, you know, well over a million, you know, credit cards as a result were stolen.
I'm gonna give one last example of a service provider breach that we investigated last year. And the reason I wanna share this story is that it it's less about, you know, some huge number of affected businesses, but rather about the the right things that they were doing that greatly minimize the potential damage.
In this case, the the client was a a hardware provider, not hardware like hammers, nails, and and that kind of thing, but, you know, p it was a point of sale, terminal hardware provider.
And they had, in in the in the case, an employee's credentials had been stolen, and the attacker then monitored this this service provider, base. And they did that, and they immediately installed malware, capable of capturing customer credit card account data. I believe there were two hundred and fifty or so total businesses that were affected, by this, service provider's portfolio. Portfolio.
But the good news is that ninety five percent of their customers, of these, you know, outside businesses that they provided the hardware for had already employed point to point encryption, p p two p e. And so we went in and we looked at the cases where, the malware had been installed on the systems, that were p two p e protected, and we found that those merchants suffered no data loss whatsoever. In total, out of the two hundred and fifty affected merchants, only a providers, the exponential results of a successful attack against this, service provider, that's what's gonna put of attackers.
Now when I talked earlier about how attackers, you know, oftentimes are you know, typically will start their attack by a an anonymous random search of of IP addresses lurking in IP addresses looking for certain ports or or certain open ports. In the case of service providers or other high value targets, they will actually be targeted, you know, squarely where the guy sits down and says, I'm gonna go after, you know, this processor. I'm gonna go after, you know, this, you know, terminal provider. I'm gonna go after, you know, something like that.
So those are the exceptions, but they are exceptions because they are high value. And as a result, the attackers put a great deal of of effort into their attacks against them and will oftentimes spend months, if not over a year, before they finally are able to breach the system.
Top organizational values. I don't wanna spend a lot of time on this. I mentioned insecure remote access. Employees always concern it is a great concern because you need to make sure that all of your employees are trained on how to handle emails.
Try to try to instill a policy that they're not allowed to, you know, log in to their Gmail accounts and look at their personal emails that might have a link that, you know, that causes problems.
BYOD is bringing the, you know, your own device to work, and this this becomes a a big problem because, for example, you know, I take my laptop home and I log into my home network that doesn't have a, you know, a a tenth of the security, surrounding it, that, you know, our network here at work would have. And so then if I I take that in that laptop and I log in to something and I hit a website, you know, somewhere in China or whatever and inadvertently introduce a or a an exploit onto my computer.
And now I take it back to work, and I log in on the network at work, and now I've got somebody watching my computer. And I then go from that point of entering my credentials to remote into a a client or something like that. So you you kinda see what I'm I'm talking about here? Well, there was a vice president of a level one or, yeah, a level one, company here in the United States, didn't have that quite that vision, and he did exactly what I was talking about right here. Takes his laptop back to work, logs into the corporate network. The the attacker who had been monitoring his activity captured his credentials gets on the corporate network. He's simply monitoring for about six weeks before he finally finds a way to, elevate his he actually created his own set of credentials, elevated his privileges, and then, was able to push out malware to twelve hundred locations.
So it, the the aspect of us bringing in, you know, devices from home, I know it happens. I I know it's a a practicality, but make sure and go talk with your IT managers and and and quiz them on on the defenses against, you know, having a a laptop log in to different insecure environments and then log in to your secure environment.
So with that said, we'll we'll go through the ten tips. I'm gonna go through these very you know, fairly quickly.
We've already talked about some of them. First one, I was just on, you know, the importance of educating, employees.
Ensure that you have policies and procedures that are in place to train your employees to be able to better identify, you know, things like social engineering, spoofing, you know, spoofing in the email, spoofing your domain or someone else's domain. Oftentimes, these, emails are they're spear phishing emails. It comes to you and it looks like it's from somebody else.
We we had a situation on the East Coast where a, a manager, an HR manager received an email that she thought was from the the CEO asking her to send him the, w two information for all of their employees.
It was sadly a spoofed email. And, you know, in those cases, train your people. When they get what looks to be a semi unusual request, pick up the phone and call the guy and say, hey. Did you really are you really asking for this w two information?
So leave that one at that. And, just a kind of another word about phishing, the, you know, we we've all gotten those emails that, like the office talked about. Hey. When the when the son of the deposed prince of Nigeria, you you know, calls and asks for help. You help him. Well, I, you know, I sat back and I wondered, who is falling for these kinds of things? Well, CyberSafe in Canada a couple of years ago did a a study, and they found that out of a hundred and fifty six million phishing emails that go out, sixteen million of those are gonna make it past firewalls and filters and land in somebody's inbox.
Eight million of the of those, about half are gonna be opened, and and ten percent of those, eight hundred thousand embedded links are gonna be clicked on. Well, problem starts right then right then and there. And, you know, beyond that, another eighty thousand immediately fall for the scam and share sensitive information.
The The most telling factor here is this scenario repeats every single day. So, you know, I try to make it a habit when I get an email requesting any type of potentially sensitive information such as from a a bank or a health care service, etcetera, I look up their number on the back of my credit card or my insurance card or whatever and call them using that number, not the phone number that's on the email, and just say, hey. I I received this from you. Is it legitimate?
You know, that that's just one way of doing it. If you can train your employees to do it, that's that's great. I mentioned social engineering. This is where, you know, someone might call into your location and they are with the maintenance crew or public services, the IT tech, telecommunications, the IRS. Well, a hint on the IRS, if they call and they want you to pay your tax bill using a gift card, probably a red flag.
So, again, this this goes back to the the need for training. And the training, just because you train them once on it, don't think they're gonna remember.
Once or twice a year is highly recommended.
Point number two, updates and patches. I I talked about that. I gave the example. The things that you wanna be paying particular attention to is updating your antivirus, your firewall rules, your intrusion detection, your your, file integrity monitoring, and, you know, the things that are, you know, jumping out to say, hey. You know, I the the things that are protecting you.
Develop secure code. This is something more for developers, but they should be, you know, employing NIST NIST recommendations, OWASP testing guides, and I I don't think there's a lot of developers on the phone, so I'll go past that one.
Vulnerability scans and penetration tests.
Vulnerability scans are gonna point you to some of the most obvious or glaring configuration issues, but a penetration test is really gonna give you your money's worth.
Do a penetration test yearly. Make sure it includes social engineering, as as part of the test.
Perform it after any network changes that you might have.
Kind of the the motivation behind this is, the National Vulnerability Database reports that approximately nineteen new vulnerabilities are reported every single day.
And and so the only way to stay on top of that is is that you're constantly testing your system, and the best people to test your systems are not the people who built it. The people who built your system, they know what it's supposed to do, and so they have this halo effect that, yeah, I know what my system's supposed to do. I know the defenses, and they're all doing it. What you need to have is somebody from the outside who comes in and actually puts those defenses to the test.
Configure and review your logs. Now the the reason well, log monitoring, first off, as a PCI requirement, you have to have twelve months worth of logs, and three months need to be readily available. But the purpose the reason I wanted to include log monitoring as one of my top ten ways to avoid data loss is that it's the key to reducing your window of compromise.
Now there's typically four ways you learn about, the fact that you've been breached.
One is, doing an internal review, and I mentioned that that one service provider that caught the breach, within a number of hours, and as a result, were able to limit the damage.
That is the if you have to be breached, the best way to find out about it is your own people are telling you, and that requires that somebody in your organization has eyes on these logs.
The next is a third party notification such as, you know, the FBI. They're out on the dark web. They find information. They buy some of the information, and they trace it back, and they say, oh. And and we had one of these investigations middle of last year where the FBI called a health care provider and said, we just found a big chunk of your database on, on the dark web.
So that was, you know, that that's one way to find out about it. Third party can also notify on credit card information, and sometimes that notification comes just ahead of of the bank or the, issuer card issuer issuing what's called a CPP, which is a common point of purchase, notification that says, hey. The activity that we're seeing on cards is leading us to believe that yours your, you know, business might have been breached. So the CPP is the the next way you might hear about it. The last way that you wanna hear about the fact that you've been breached is, on CNN or, you know, you you read Krebs, Krebs on security, and you open it up and you realize that, yeah, your name's on there. So there's, we've coined a phrase in ours that you don't want Krebs to be your IDS, your intrusion detection system.
So the sooner you can detect, the sooner the the more you're gonna shrink the amount of time that you're losing data, and that gets back to your internal reviews. We're gonna chat just a little bit more about that in a minute. Let's see. I've already covered those.
Oh, actually, no. I do wanna come back to this one for one second.
On on your alerts, you should have somebody in your organization direct role and responsibility to monitor, alerts.
And if your file integrity monitoring, which that's the thing that that you install that says, hey. This file over here changed, and I don't think you wanted it to change. You better have somebody take a look at it. So file integrity monitoring and intrusion detection systems, those alerts should be going to somebody in your organization in real time so that they can act in real time. We performed a a a PCI investigation of a level one merchant, eight hundred locations.
They had file integrity monitoring in place. They actually had a great tool called Carbon Black in place, and it was throwing alerts all over the place for months before somebody finally looked at it. And and if if somebody just would have had the job responsibility to every day look at they would have dramatically cut down to the tune of probably ninety eight percent of the data that was lost. They could have alleviated if they would have taken action on on day one.
So vulnerability risk assessments, this is something where you're gonna review your system for any problems that you might be having, looking out at what's going on, what what are the typical breaches happening in this world, in in this environment, your typical environment.
And, you know, so you're gonna know or you're gonna be learning of existing threats. Try to understand the vulnerabilities that are attacking your system. Going back a little while ago, I mentioned Magento. The only reason I can, you know, mention that by name is it it was pretty widely publicized.
So if you're an IT manager and your payment application happens to be, you know, utilizing Magento, you know, it's something that you're gonna wanna be aware of.
And whether in ecommerce or whatever, try to have somebody in your organization, scanning the available information on the on the Internet to find out what the current risks and vulnerabilities are against you.
Control access, we talked about the importance of of, you know, having remote access.
I I'm gonna reiterate what I said earlier.
Most systems have either admin or administrator as an available username. I I'd get rid of those. Change change that username to something else specific to your environment, and, you know, and that that creates one more thing that the attacker has has to one more hurdle he has to go through before the attacker even gets to your password.
On the multifactor authentication, I I alluded to it earlier. The the additional factors beyond you know? Well, the factors are either something you know, such as a username and a password, something you have, such as getting a a code sent to your phone or a an RSA dongle, something like that, or something you are, biometrics. It's a a fingerprint or other form of of biometrics.
These are only gonna get more important as as time goes on because passwords are getting easier and easier to to get pass. We're we'll chat with that again on one of the last slides.
I'm I mentioned the importance of role based access. Don't don't give, you know, everybody in the executive suite, you know, a hundred percent global access to your environment. They probably don't need it even though their egos might say that they want it.
You know, it's important for the the people who maintain your systems to have that level of access, but everybody else keep keep their level of access within their job, roles and responsibilities.
Number eight is implementing network segmentation.
I, again, alluded to this one a little bit earlier. The importance of this is it's a lot easier to harden the security protocols around a single server or a couple of servers that perform a single function, such as processing credit cards or, you know, you could apply that to, you know, whatever environment that you have. It's so much easier to say that this server with this data on it can only communicate between here and there and firewall it off from, you know, you firewall it off from everything else in your environment.
This this diagram kind of, you know, endeavors to show you that, but, I I can't tell you how often we get into an environment and they have a single perimeter firewall and everything else in their environment is all on essentially the same network segment. And that means that if an attacker gets into one area like an email server, if your network is flatter or not segmented like that, he can then go from the email server to anywhere else he wants. But if an attacker attacks a a segmented system through an email server, he might not be able to then get through the next firewall into where the critical data is residing.
So, hide the sensitive data is number nine. This is you know, a lot of businesses are doing a pretty good job at this.
The example that I gave of the service provider where, of the two hundred and fifty that that were affected, all but eleven had point to point encryption in place. This meant that the attacker goes in, and he can install his malware and even exfiltrate or or pull some of the data out of your system.
But the data was unusable because it was so highly encrypted that, you know, I mean, he he can work for, you know, months and maybe try to decrypt it, but the tools that are in place doing this encryption are are probably such that he's he's gonna end up having a pretty futile effort.
The other thing I wanna say about the hiding the sensitive data is is throw a a plug in for running backups or having backups.
In in ransomware attacks, the the defense against a a ransomware attack and and so first question we'll ask when we go in and and and this company has reported that their system's been encrypted, we'll say, you know, do you have backups? How far do do they go?
We wanna make sure that they have clean backups that predate the time of the of the attack.
And the next issue is a big question. Have you ever tested to see if you can restore your system from your backups?
And that's where kind of the rubber hits the road because we've seen businesses that they say, oh, yeah. We've got great backups. We're not gonna pay the the the ransom.
The the, attacker then destroys the the decryption key.
The business, they they nuke or they wipe their their system, and then they go to restore from these backups. And they find that in a lot of cases, it's not as easy as they thought it was going to be, especially if you're relying on backups that are on tape somewhere.
So the recommendation here is, make sure you have backups. You know, backups should go back a year. Make sure that you are backing up frequently so that you have you you can, you know, point to a time when you can say, yeah. This backup should be clean, and you eliminate the backups that happened after that, and you can restore back to that time. And then practice.
See if you can restore in a test environment from that backup.
It it was a sad experience for some of the merchants to learn that their backups were only minimally useful for them or they were only to able to restore certain, you know, elements of their data.
Number ten is having an incident response plan.
This this is preparing for what may be inevitable, but or preparing for what you don't want to have happen.
Part of that, you know, is so that you can coordinate your response to a security incident. You wanna minimize your impact. You wanna be able to restore your operations as as quickly as possible. I'm gonna go through the next couple.
They're they're just about, the the incident response plan that you you wanna identify any potential risks. You wanna know the equipment that you would need to protect, greatest. What what is the secret sauce? What is the most important thing if to your company if it were lost or stolen in your data environment, and then, you know, you're gonna wanna center your your heaviest protections around that.
Identify and prioritize your assets. That that's what I was just mentioning about right there.
Quantify your asset values and then, you know, prepare your your defenses to best protect those things that are most valuable or would be the hardest to recover.
And then set up policies and procedures.
You know, get a baseline of what the normal activity, is in your company, and then you're you're going to, I build your response, incident response program to be able to return you to that baseline or normal activity as quickly as possible. The other goals are to identify and contain the breach, record information on the breach, notify your and this is your notification path, the defense approach that you're going to take from your IT folks and how you're going to train your employees, set up the response plan. You know, you can go on the Internet and find templates for setting up an incident response plan. You can look back to these notes.
You're gonna need need to sell the plan to your, the c suite in most cases, because it's it's going to be a line item on an expense line item for a company.
And then you're gonna want to train the employees and hold mock incident response, drills.
And in those incident response drills, you're going to look for the gaps in your plan.
Everyone's going to better learn in that drill what their roles are because they're actually gonna have to to role play a few of them. It it will improve the communications between departments, and it will help you discover more efficient methods, perhaps, to to get the word out and to, you know, roll out your fixes or or whatever it might might be. And and the importance is is to practice this while there's nothing at stake.
Now getting into the predictions, you know, I could I I could just about call this, you know, two things that that I think are inevitable and three things that really scare me. So this is just kind of following a curve. The ecommerce breaches are gonna continue to increase as a tax as well as tax against health care.
Again, I mentioned that ecommerce increased last year. It's going to continue to do so. We will probably settle into a rate somewhere in the next year or two where about eighty percent of the investigations in the credit card environment are in the ecommerce space.
What would help this what what would lower the number of ecommerce breaches that we have seen is if a type of tool that could monitor, legitimate activity and separate it from, illegitimate activity in a in a, shopping cart. And, you know, file integrity monitoring kinda does that in in static environments, but it doesn't work in the dynamic environment of a database or a or a shopping cart. So if there were just a tool like that, I think we would start to see a decrease, if in in a a decrease in the, not the attack itself, but the window of vulnerability and the amount of data that is lost. Because instead of being weeks or months before the the breach is discovered, it would be down to an hour or a day or something like that. So, stay tuned on that one. Hopefully, a tool will will come up.
On the next one, smaller merchant breaches, I think, are going to come under greater scrutiny.
Several years ago, virtually all merchant breaches were investigated.
About five years ago, the card brands softened their mandates so as to not overly burden the small merchant, with high costs of a full forensic investigation.
While a breach of a single small merchant doesn't typically expose a large number of credit card accounts, the collective total of several small merchant data breaches does.
So I believe that as we as we see the the number of POS or point point of sale card present breaches decrease, I think you're gonna start to see, an increase for small merchants to take more definitive actions when they're under the suspicion of a data compromise.
Third, this is the first of the ones that that scared me a little bit, and it's coordinated attacks that start with your cell phone.
We had, an attack last year that started with a a cell phone that was breached, and the cell phone led to a personal computer in a home. It led from the personal computer into the home to the, the owner's, business, which happened to be in the health care industry, and then breached, the the breach spread to all of the devices in in that environment. I think you're gonna start seeing a lot more attacks targeted at individuals in addition to being targeted at businesses, and then they're gonna start with the cell phones.
Next is going to be passwords, and I've alluded to this a couple of times. Passwords may not be the security that you're looking for. I I think we're going to see, if not in the next year, in the next coming years, passwords will no longer be considered an element of security whatsoever.
There is technology already present right now that can search and attempt to break password hashes at the tune of somewhere in the vicinity of six hundred billion passes or attempts per second.
That means that they could span every possible combination of keys on a keyboard, you know, up you know, from one to twenty five characters, so spanning every possible password, in the Latin languages in about six days.
That's already here. And as they put more more steam behind it, you know, that six days is gonna turn into six hours, and the amount of resources that it requires to get there is gonna reduce as well. Last one is artificial intelligence.
It's hopefully gonna come in on our side where we can install tools that have AI that detect breaches and adapt, but I think we're going to see AI on the on the dark side where you they install malware that, can self move, self manipulate, self hide as it sees you taking actions on your side. So AI is going to be, both on the dark side and the light side for us, and it's going to make the future of data security very, very interesting. I've gone one minute and twenty seconds over. I apologize that I'm gonna turn it back over to Andrew.
Yeah. Thanks, Dave. It's really fascinating information that that we've discussed today. And we've had quite a few questions come in, and and we'd like to go over just a few of those now in our in our remaining few minutes here. So, the first question here is, is there a risk in downloading an antivirus program off the Internet versus buying a box program from a store?
The risk is is do you know who you're actually downloading it from? A lot of the antivirus is sold by resellers.
And, you know, is that reseller trustworthy?
We I I've seen some antivirus products that, came out of China that actually you know? And and this was actually in the box as well, had malware preinstalled on it. Most of it is is data gathering, data collecting kind of information.
But, actually, if if you go back a little ways, the, when EMV first came out, some of the very first EMV terminals that were shipped to Europe had embedded malware in them. So it's look for the reputable companies. Look for the reputable resellers.
And, you know, if if you identify those two, that's about as best as you can do. But, software versus, you know, getting a a disc or a thumb drive sent to you, they're they're pretty much gonna be about the same as far as the risk level.
Okay. Great.
The next question here is, so you referenced, when when talking about health care data breaches, eighty eight percent of those, ransomware attacks, in in the health care industry.
Is that figure because the health care industry is generally better at reporting data breaches?
You know, I don't think so. I I think that's a matter of of the health care industry being a target rich environment where if they were to go into, you know, some other commercial industries, there might not be the the immediacy attached to having to respond, but they know that in the health care industry, you know, patients' lives are potentially at at at risk here.
They need to get that data back, and they need it now. And and the the attackers less likelihood of them being able to bring professionals in to be able to restore their their systems and all of that.
You know, they can they can go in and get their money faster is what they're looking for.
Okay.
Great. And just a couple more questions here.
So what information should people be keeping in logs as far as backups?
Oh, great great question.
You wanna be backing up, you know, in addition to transactions that that you need for a business purpose, I look at the security side of it. You any logs of anything, that your security system is generating, your antivirus logs, logs that your firewall is throwing out, you know, who's who's trying to to get into the system. If you have an intrusion detection or an intrusion prevention system, which I hope you do, those logs are critical. File integrity monitoring logs are are critical.
So that that's kind of the batch on the security side. Outside of that, you you know, the day to day transaction logs that that you need for, you know, running your business is very important. If if you have those, you know, we can pretty much reconstruct, just about everything that that we would need in in the event of something going wrong. But more importantly, it's gonna give your, your IT manager, your your security manager the information that they need to be looking at to recognize if somebody's hitting your system.
Okay. Great. And you said those logs should go back at least a year?
Yeah. At least a year, you have by requirements, you have to have ninety days worth immediately available to you. You need a a year in some sort of an archive.
Yeah. And then if just throw that last plug out that I gave in a little while ago is is test your logs to see if you can restore your systems.
Well, test your backups to see if you can restore your systems from your backups as well.
Okay.
Awesome.
And then just a a follow-up here to our first question regarding antivirus programs.
Is there an an anti antivirus software that you would recommend?
Oh, gosh. I'm not sure I'm allowed to.
There are some well, I'll I'll throw a number out.
There are there's some very good, freeware. You know, Malwarebytes does does a very, very good job, and and its free version is is pretty robust.
There's a company called ESET. It's e s e t. Has a product called Knob thirty two. It it's it's pretty decent.
And and in the case of those two, I've actually let me back up a little bit. When we perform an investigation, oftentimes, you know, we will be some of the first people in the world to see malware. And so when we when that happens, you know, we send the hashes of these malware, you know, applications out to a lot of the antivirus product makers around the world. You know, your anyway, all of the popular ones that that might come to mind for you.
And we watch the speed at which they they add those to their their databases that they're searching for. And, you know, Malwarebytes and ESET, I've I've seen actually, they respond very, very quickly.
When keyloggers were first a problem, you know, attackers were using commercial keyloggers. And so we were notifying the antivirus company saying, hey. You know, you probably ought to flag if a keylogger is on a system, and at least tell the, you know, the user, hey. Did you install this, or did somebody else install it?
Because if someone else installed it, it it's a problem. A couple of the the big brands were afraid to flag it as malware because they said, hey. This is a commercial product. We're we're gonna get sued.
So, eventually, everybody did kind of put an alert in on on key loggers. But, anyway, those those two, I I I like a lot. A vast mix of very good products.
You know, those are just, you know, three off the top of my head, but there's probably several more. Okay.
Great. Just one last question here, and this question is actually, something that I can answer being in in marketing Security Metrics twenty eighteen predictions white paper forthcoming?
I got a feeling there's going to be a.
Yeah. That that's a great suggestion.
We will definitely have a blog post, that's kind of recapping this webinar that we've had today.
So so that will that will go live in the next, week or two here. So so stay tuned for that blog post.
And in that post, we will definitely summarize the, twenty eighteen forensic predictions.
So so stay tuned for that. And, again, just a reminder, like I said earlier, we have been recording recording this webinar, and we will send you the recording in the slide deck. So keep an eye out for that email.
And, yeah, again, thank you everyone for your attendance today. We've had a great webinar. A lot of great information here from from Dave Ellis, and we thank him as well for sharing his industry knowledge with us. So, thanks everyone for joining us today, and don't hesitate to reach reach out to us directly at events at security metrics dot com if you have any follow-up questions. Thanks everyone, and we'll see you next time.
