Alert Actionability In Plain English From a Practitioner

In response to the latest MITRE Engenuity ATT&CK® Evaluation 3McAfee noted five capabilities that are must-haves for Sec Ops and displayed in the evaluation.  This blog will speak to the alert actionability capability which is essential. This critical ability to react in the fastest possible way, as early as possible on the attack chain, while correlating, aggregating and summarizing all subsequent activity while reducing alert fatigue to allow Sec Ops touphold efficient actionability. 

 As a Sec Ops practitioner and former analyst, I can remember the days of painstakingly sifting through countless alerts to determine if any of them could be classified as an incident. It was up to me to decide if the alert were a false positive, false alarm, or something the business should take more seriously… was it something we should wake someone up in the middle of the night over? 

It’s been years since I sat on the front line, triaging the results of millions of dollars in investments installed on 100’s of 1000’s of systems worldwide. Thank goodness, times have changed. But the concept of “Alert Actionability” is still a very real aspect of SOC tooling, and it seeks to address 3 primary factors:  trustworthiness, detail, and reaction capabilities. 

Trustworthiness 

When I say “trustworthiness” I’m referring to a quality of fidelity that has two equal, yet opposing, faces of efficacy: false positives and false negatives. Now, it would be very easy for a SOC solution provider to claim that its product offers 100% visibility if it creates an alert for every process activity and artifact recorded. Sure, its coverage is present, but how actionable is the needle in a stack of needle? As a result, the vendor is likely pressured to fine tune it’s alerting and as such introduces the risk of false negatives, or actual malicious events which go undetected. In the zeal of appealing to useability requirements the false positive curve decreases but the false negative volumes have no choice but to rise. 

Resulting in a graph like this: 

The secret sauce in the vendor’s capabilities lies in its capacity to push the intersection of these as far right as possible: minimize the false positives and maximize true positives while simultaneously attempting to bring false negatives down to zeroThe better a vendor’s product can perform these non-trivial goals, the more likely it is to win your trust as a solution! And the more likely you are to trust the results you see on the dashboard.  

Endpoint Detection and Response (EDR) tools have a unique property in which they offer both telemetry and alerting. This implies that there are two goals for EDR platforms: to include event level (telemetry) visibility with automated detection and to provide alerting capabilities for triggering action and triage. With telemetry, the concept of “falsing” is negated because it’s used in a post-facto context. After the alert is constructed, the telemetry can be correlated with the alert logic to provide supporting details. Simply, for EDR telemetry, the more the better. 

Detail 

As an analyst, I remember how much I loved putting together the pieces to tell a story. Extracting key artifacts from several disparate data sources and correlating hypothesis allowed me to present a compelling case as to the conclusion of the alert’s disposition. And I knew that I needed as much detail as possible to make my case; this is just as true today. The detail needs to be easily accessible, and it’s even better when the platform provides the detail proactively. In cases where such supporting evidence may not be possible in the alerting, an analyst’s expectation is that the platform makes hunting for those details easy; I’d even venture to say, “a delight.”  

Reaction Capabilities 

Many EDR platforms on the market offer reaction capabilities to address the “Response” moniker of the acronym. How flexible those response capabilities are in the platform provides a domain of options to act in response to the alert. For example, its rather evident that once an alert is convicted, the analyst may want to block the process, or remove a file from disk. But these reactions imply that the conviction is monolithic in that the analyst is absolutely sure of her conclusion. What if the conclusion is that we simply need more data? Having a robust reaction library that allows for further investigation with routines like sending a sample to a running sandbox, interacting with a given endpoint to act as an administrator, view system logs, or check the history of network connections all empower the analyst with further investigatory options. But why stop there? Having any fixed set of reactions would be presumptive. Instead, EDR products with a dynamic library and flexible, customizable, and modular reaction platform is key as every single SOC I’ve ever worked with has unique Incident Management and Standard Operating Procedures. 

What’s Next? 

MITRE ENGINUITY™ released results for its 3rd round of ATT&CK® Evaluations in April 2021. The industry is certainly fortunate to receive such 3rd party efficacy testing in the EDR market completely free to consumers. It is incredibly important to add that the ATT&CK Evaluations should be used as a single component of your EDR evaluation program. Efficacy helps determine how fit-for-purpose the product is by answering questions like, “Will it detect a threat when I need it to?” or “Can I find what I need, when I need it?”. But practitioners realize there are also pivotal points that need to be addressed around manageability. Understanding that not alerting on everything is just as important as alerting on the right things. And giving you a plethora of alerting response capabilities helps complete the alert investigation and response actions. McAfee’s MVISION EDR embraces all of these key alert actionability factors and will help displace the manual efforts in your analytics processes. McAfee’s MVISION EDR (soon to evolve to MVISION Extended Detection & Response (XDR)provided insight through detail and reduced alert fatigue during the evaluation providing context and enrichment, resulting in a ratio of 62% analytic detections (non-telemetry detections) out of the 274-total detections. 

Check out other McAfee discussion on MITRE (see resources tab.) 

  

 

 

The post Alert Actionability In Plain English From a Practitioner appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI Employee Indicted Over Illegal Document Removal

FBI Employee Indicted Over Illegal Document Removal

An employee of the Federal Bureau of Investigation (FBI) has been accused of stealing classified information and national security documents from her workplace and keeping them at home. 

Intelligence analyst Kendra Kingsbury of the FBI’s Kansas City Division was charged in a two-count indictment returned under seal by a federal grand jury in Kansas City, Missouri, on Tuesday, May 18.

The federal indictment alleges that 48-year-old Kingsbury took sensitive government material home to her residence in Dodge City for more than a decade.

Kingsbury worked as an intelligence analyst for more than 12 years until she was placed on suspension in December 2017. During her career with the FBI, she held a top-secret security clearance and was assigned to a number of different squads dealing with illegal drug trafficking, violent crime, violent gangs, and counterintelligence. 

It is alleged that Kingsbury improperly removed sensitive government materials – including national defense information and classified documents – from June 2004 to December 15, 2017, and kept them at home. According to the indictment, Kimberly had no need to know most, if not all, of the information contained in those materials.

Kingsbury was charged with two counts of having unauthorized possession of documents relating to national defense. The first count relates to numerous secret documents that describe intelligence sources and methods related to US government efforts to defend America against counterterrorism, counterintelligence and cyber-threats. 

Detailed in those materials are details of open FBI investigations across multiple field offices and documents relating to sensitive human source operations in national security investigations, intelligence gaps regarding hostile foreign intelligence services and terrorist organizations, and the technical capabilities of the FBI against counterintelligence and counterterrorism targets.

Count two refers to Kingsbury’s alleged theft of secret documents that describe intelligence sources and methods related to US government efforts to collect intelligence on terrorist groups. Among these materials is information on al Qaeda members on the African continent, including a suspected associate of Osama bin Laden.

Alan Kohler, Jr., assistant director of the FBI’s Counterintelligence Division, said: “The breadth and depth of classified national security information retained by the defendant for more than a decade is simply astonishing.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybersecurity Lecturer Wins Lloyd’s Science of Risk Prize

Cybersecurity Lecturer Wins Lloyd’s Science of Risk Prize

A lecturer from the University of Plymouth has won a prestigious international prize for her research in maritime cybersecurity.

Dr. Kimberly Tam’s work won her the overall gong and the cybersecurity category in the 2021 Lloyd’s Science of Risk prize. Tam was among six academics announced as award winners by insurance and reinsurance market Lloyd’s of London on May 21.

The Science of Risk prize is awarded to academics and PhD students who further the understanding of risk and insurance through their scientific research. Runner up in the cybersecurity category was Edward Oughton of George Mason University for his stochastic counterfactual risk analysis for the vulnerability assessment of cyber-physical attacks on electricity distribution infrastructure networks.

Tam’s award-winning research focused on a suite of software tools designed to enhance maritime cybersecurity. In conjunction with the University of Plymouth’s Maritime Cyber Threats Research Group, Tam developed a Maritime Cyber Risk Assessment (MaCRA) framework.

“The principles behind the MaCRA framework were first set out in a study published in the WMU Journal of Maritime Affairs in 2019, and co-authored by Dr. Tam and Executive Dean of Science and Engineering, Professor Kevin Jones,” said a spokesperson for the University of Plymouth.

“The paper proposed a dynamic risk assessment model that uniquely takes into account both information technology and operational technology, both of which are prevalent in sectors like transportation and critical national infrastructure.”

Recognizing the value of the software, the Maritime Research and Innovation UK (MarRI-UK) initiative awarded the University a grant to develop it as an industry-ready solution. 

“Receiving the overall 2021 Lloyd’s Science of Risk prize is a big honor. It shows there is real appreciation of the growing threat of cybercrime, and the importance of addressing the challenges it could pose for the globally important maritime sector,” said Tam. 

“My paper looks at ways the physical and cyber worlds affect each other, and how shifting our concept of risk to be more dynamic can be a useful tool moving forward in a more connected world.”

Just over a week ago, Tam’s software won the Cyber Den competition run as part of the UK government’s flagship cybersecurity event, CYBERUK.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Michigan Man Admits Selling UPMC Employee Data

Michigan Man Admits Selling UPMC Employee Data

A hacker from Michigan has admitted to stealing the sensitive data of more than 65,000 University of Pittsburgh Medical Center (UPMC) employees and selling it online.

Federal Emergency Management Agency (FEMA) IT specialist Justin Sean Johnson, known on the dark web by the handles TheDearthStar, Dearthy Star, TDS, and DS, hacked into UPMC’s human resources database in January 2014. Six years later, the 30-year-old resident of Detroit was indicted by a federal grand jury in Pittsburgh and subsequently arrested on charges of conspiracy, wire fraud and aggravated identity theft.

Among the data swiped and sold by Johnson was W-2 information and Personally Identifiable Information (PII) that included Social Security numbers, addresses, names and salary information. Conspirators who bought the data from Johnson via forums filed hundreds of false form 1040 tax returns in 2014 using UPMC employee PII. 

Hundreds of thousands of dollars of false tax refunds claimed in these false 1040 filings were then converted into gift cards for online marketplace Amazon.com. Conspirators used the gift cards to purchase products that were later shipped to Venezuela. 

The lucrative criminal scheme resulted in the loss of approximately $1.7m in false tax return refunds. 

UPMC employees were not the only victims of Johnson’s proclivity for data theft. From 2014 through 2017 he also stole and sold nearly 90,000 additional sets of PII to buyers on dark web forums, which could be used to commit identity theft and bank fraud.

On May 20, Johnson pleaded guilty to counts 1 and 39 of a 43-count indictment before Chief United States District Judge Mark R. Hornak. Johnson will remain in detention while a date is set for his sentencing.

“Unfortunately, through no fault of their own, the people whose identities are stolen in cases like this are often victimized repeatedly,” said Tom Fattorusso, the special agent in charge of IRS–Criminal Investigation at the time of Johnson’s arrest.

“Initially, they have to deal with the stress of knowing their personal information was stolen. Criminals then use the stolen information to file false tax returns, or they sell it to other criminals who use it to file false returns. This causes a hardship for the innocent victims when they try to file their own tax returns. Victims are then left to deal with credit issues caused by the unscrupulous actions of the criminals.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Amex Fined After Sending Over Four Million Spam Emails

Amex Fined After Sending Over Four Million Spam Emails

American Express is the latest big-name brand to receive a fine from the UK’s data protection regulator after spamming millions of customers.

The Information Commissioner’s Office (ICO) fined American Express Services Europe (Amex) £90,000 after it sent over four million marketing emails to customers who did not want them.

The ICO said it began its investigation after complaints from some of those customers, who claimed to have opted out of receiving the missives.

Amex rejected these complaints, saying the emails were about “servicing” rather than marketing, according to the ICO. The content of these messages apparently included how to get the most out of your card, info on the rewards of shopping online with Amex, and how to download the firm’s app.

However, the ICO disagreed, claiming that a little over four million of the 50 million emails sent as part of this campaign were “a deliberate action for financial gain by the organization” — and as such constituted a marketing effort.

In addition, Amex decided not to review its marketing model following the customer complaints.

Andy Curry, the ICO’s head of investigations, argued that Amex is now facing the “reputational consequences” of making the wrong call.

“The emails in question all clearly contained marketing material, as they sought to persuade and encourage customers to use their card to make purchases,” he added.

“Amex’s arguments, which included that customers would be disadvantaged if they weren’t aware of campaigns, and that the emails were a requirement of its Credit Agreements with customers, were groundless.”

Curry encouraged all companies to revisit their procedures and take time out to better understand the differences between service and marketing emails, ensuring their policies are compliant.

Although the ICO is the UK’s regulator for GDPR, this fine was issued under the country’s Privacy and Electronic Communications Regulations 2003, which state that it’s illegal to send marketing emails to people unless they have freely consented.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Air India: Supplier Breach Hit 4.5 Million Passengers

Air India: Supplier Breach Hit 4.5 Million Passengers

Air India has confirmed that 4.5 million passengers have had their personal data exposed in a third-party data breach first disclosed over two months ago.

The incident impacted SITA, an IT provider which claims to serve around 90% of the aviation industry. Attackers compromised servers that operate passenger processing systems for airline clients.

Air India said it first received word of the attack on February 25 this year, but was unable to confirm those affected until SITA informed it on 25 March and 5 April.

“The breach involved personal data registered between August 26 2011 and February 3 2021, with details that included name, date of birth, contact information, passport information, ticket information, Star Alliance and Air India frequent flyer data (but no passwords data were affected) as well as credit card data,” the statement noted.

“However, in respect of this last type of data, CVV/CVC numbers are not held by our data processor.”

Air India claimed that, following the incident, the affected servers were secured, external investigators engaged, credit card issuers were notified and frequent flyer passwords were reset.

“Further, our data processor has ensured that no abnormal activity was observed after securing the compromised servers,” it added.

“While we and our data processor continue to take remedial actions including but not limited to the above, we would also encourage passengers to change passwords wherever applicable to ensure safety of their personal data.”

Finnair, Malaysia Airlines, Japan Airlines and Singapore Airlines were among the other big names affected by the breach.

Although Singapore Airlines said it was not a customer of SITA’s, some of its frequent flyer data was apparently compromised via a fellow Star Alliance member that was.

This isn’t the first data security incident to have affected Air India. Back in 2016 a possible insider attack was detected in which threat actors sought to divert over $23,000 in air miles.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Insurance Giant Reportedly Paid $40 Million Ransom

Insurance Giant Reportedly Paid $40 Million Ransom

One of America’s largest insurers agreed to pay a $40 million ransom after its IT systems were locked down and data stolen by threat actors, according to a report.

CNA Financial paid its attackers in late March, about a fortnight after the incident, two people familiar with the attack told Bloomberg.

A statement shared with the news site refused to comment on the ransom but claimed that the firm had followed all “laws, regulations and published guidance” when handling the matter. This includes the 2020 guidance published by the US Treasury’s Office of Foreign Assets Control (OFAC), it said.

CNA Financial also noted in a security update that it did “not believe that the systems of record, claims systems, or underwriting systems, where the majority of policyholder data — including policy terms and coverage limits — is stored, were impacted.”

The firm was apparently hit by a variant of the Evil Corp-authored Hades ransomware called Phoenix Locker.

The payment could be the largest ever made to a ransomware group — although not all incidents and payment amounts are disclosed given the commercial sensitivities involved.

Attackers tried to extort $50 million from Acer back in March, although it’s unclear whether they were successful or not.

The FBI urges victims not to do so as it encourages more copycat attacks and does not guarantee that the organization’s stolen files will not be monetized in the future, or that it will even receive a working decryption key.

Insurance companies like CNA Financial have been at the center of fierce debate recently over whether the industry should be assisting customers financially who have been struck by ransomware.

Axa has decided to stop reimbursing new policyholders in France for payments to such threat groups, for example.

Insurers may also be a lucrative target if their attackers manage to find client lists, which would provide them with a handy line-up of companies covered by insurance.

The average payment to ransomware groups increased by 43% from Q4 2020 to the first three months of 2021, according to Coveware.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk