seeing red in your future?

118
Seeing red in your future? Ian Amit Director of Services, IO Active

Upload: iftach-ian-amit

Post on 08-Sep-2014

693 views

Category:

Business


0 download

DESCRIPTION

Derbycon 2013 - Seeing Red in Your Future? This talk is designed to complement the “Fifty Shades of Red” talk tomorrow, and provide context for organizations who either think about engaging in a red team test, or have been doing red teaming and want to see more value out of it. In this talk we’ll cover some of the basic elements of what red teaming is, and specifically how it benefits an organization engaging in such a practice. Red teaming by itself is a high-interaction test. Unlike many other tests (namely penetration testing, compliance engagements, vulnerability assessments and other IT related practices), red team is not limited to the technical scope of the organization’s security infrastructure. As such, it is imperative to be able to extract as much value out of a red team engagement as possible, and see return on that investment in as many different areas of the organization as possible. Based on years of experience in conducting red team tests, training and helping organizations improve their security through red teaming, these insights will be applicable to everyone who is seeing red in their future (and you all should in order to really address security in an organization that has people working in it and not just machines).

TRANSCRIPT

Page 1: Seeing Red In Your Future?

Seeing red in your future?

Ian AmitDirector of Services, IOActive

Page 2: Seeing Red In Your Future?

Hello

Page 3: Seeing Red In Your Future?

whoami?

$ id

uid=501(iamit) gid=20(ioactive) groups=12(hack),33(research),61(dev),79(red_team),80(sexy_defense),81(exil),98(idf),100(dc9723),204(/dev/null)

Page 4: Seeing Red In Your Future?

So, you think you can red team...

Page 5: Seeing Red In Your Future?

As in get your organization a proper red team assessment

Page 6: Seeing Red In Your Future?

First things first.

What is a “Red Team Test”?

Page 7: Seeing Red In Your Future?

!pentest

Page 8: Seeing Red In Your Future?

!social_engineering

Page 9: Seeing Red In Your Future?

“A red team is an independent group that challenges

an organization to improve its effectiveness”

wikipedia

Page 10: Seeing Red In Your Future?

But wait! what about security?

Page 11: Seeing Red In Your Future?

Right... that’s part of the deal...

Security is PART of running an organization!

Page 12: Seeing Red In Your Future?

So how do we go about it?

Page 13: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 14: Seeing Red In Your Future?

Map

Page 15: Seeing Red In Your Future?

Map

CISO CIO

CFO CRO

Compliance

Audit GeneralCounsel

Page 16: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 17: Seeing Red In Your Future?

Identify

Page 18: Seeing Red In Your Future?

Identify

Page 19: Seeing Red In Your Future?

Identify

Page 20: Seeing Red In Your Future?

Identify

Page 21: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 22: Seeing Red In Your Future?

Recruit

Audit

Page 23: Seeing Red In Your Future?

Recruit

Six SigmaSix Sigma

Page 24: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 25: Seeing Red In Your Future?

Target

Page 26: Seeing Red In Your Future?
Page 27: Seeing Red In Your Future?

How do I look from the outside?

Page 28: Seeing Red In Your Future?

How do I look from the outside?

Legal

Page 29: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Page 30: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Procurement

Page 31: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Procurement

Information Sources

Page 32: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Procurement

Information Sources

Supply Chain

Page 33: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Procurement

Information Sources

Supply Chain

Human Resources

Page 34: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Procurement

Information Sources

Supply Chain

Human Resources

Sales

Page 35: Seeing Red In Your Future?

How do I look from the outside?

Legal

Research & Development

Procurement

Information Sources

Supply Chain

Human Resources

Sales

Financials

Page 36: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 37: Seeing Red In Your Future?

Assemble

Page 38: Seeing Red In Your Future?
Page 39: Seeing Red In Your Future?

Skillz!

Page 40: Seeing Red In Your Future?

Electronic Social

Physical

Page 41: Seeing Red In Your Future?

Electronic Social

Physical

Page 42: Seeing Red In Your Future?

Electronic Social

Physical

Page 43: Seeing Red In Your Future?

Electronic Social

Physical

Page 44: Seeing Red In Your Future?

Electronic Social

Physical

Page 45: Seeing Red In Your Future?

Electronic Social

Physical

Page 46: Seeing Red In Your Future?

Electronic Social

Physical

Page 47: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 48: Seeing Red In Your Future?

Scope

Page 49: Seeing Red In Your Future?
Page 50: Seeing Red In Your Future?

Threat model

Page 51: Seeing Red In Your Future?

Threat model

Assets

Page 52: Seeing Red In Your Future?

Threat model

AssetsProcesses

Page 53: Seeing Red In Your Future?

Threat model

AssetsProcesses

Controls

Page 54: Seeing Red In Your Future?

Threat model

AssetsProcesses

Controls

People

Page 55: Seeing Red In Your Future?

Threat model

AssetsProcesses

Controls

People

Technology

Page 56: Seeing Red In Your Future?

Threat model

AssetsProcesses

Controls

People

Technology

Location

Page 57: Seeing Red In Your Future?

Threat model

AssetsProcesses

Controls

People

Technology

Location

Culture

Page 58: Seeing Red In Your Future?

Threat model

AssetsProcesses

Controls

People

Technology

Location

Culture

Adversaries

Page 59: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 60: Seeing Red In Your Future?

Monitor

Page 61: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 62: Seeing Red In Your Future?

Execute

Page 63: Seeing Red In Your Future?

Execute

Page 64: Seeing Red In Your Future?
Page 65: Seeing Red In Your Future?

Can you hear me now?

Yes

Whazzzzzzup?

Whazzzzzzzzzzuuuuuppp?

What are you wearing?

Hello?

Still there?

Page 66: Seeing Red In Your Future?

Stay in control

of the escalation processes...

Page 67: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 68: Seeing Red In Your Future?

Pre-report

Page 69: Seeing Red In Your Future?
Page 70: Seeing Red In Your Future?

IDS

Page 71: Seeing Red In Your Future?

IDS

System Logs

Page 72: Seeing Red In Your Future?

IDS

System Logs

Firewalls

Page 73: Seeing Red In Your Future?

IDS

System Logs

Firewalls

Access controls

Page 74: Seeing Red In Your Future?

IDS

System Logs

Firewalls

Access controls

Call records

Page 75: Seeing Red In Your Future?

IDS

System Logs

Firewalls

Access controls

Call records

Web traffic

Page 76: Seeing Red In Your Future?

IDS

System Logs

Firewalls

Access controls

Call records

Web traffic

DNS

Page 77: Seeing Red In Your Future?

IDS

System Logs

Firewalls

Access controls

Call records

Web traffic

DNS

Social Media

Page 78: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 79: Seeing Red In Your Future?

Gap

Page 80: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

Page 81: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

Page 82: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training

Page 83: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training•Process changes

Page 84: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training•Process changes•Technical controls

Page 85: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training•Process changes•Technical controls•Change management

Page 86: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training•Process changes•Technical controls•Change management•R&D practices

Page 87: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training•Process changes•Technical controls•Change management•R&D practices•3rd party sw security

Page 88: Seeing Red In Your Future?

Example 1: Dumpster Diving Olympics

•Personnel training•Process changes•Technical controls•Change management•R&D practices•3rd party sw security•Physical security routines

Page 89: Seeing Red In Your Future?

Agenda

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 90: Seeing Red In Your Future?

Fix

Page 91: Seeing Red In Your Future?

Example 2: Incident Response from HellProcess:Incident response kicks in on any malware with a signature from the past week, or with a generic/heuristic detection.In meantime, malware (APT!?) is left to run (actually ok...)

Problem:High number of incidents in a short time can create a queue. Queue is predictable if IR analysis consists of C&C traffic as well :-)Queue can be exploited...

Page 92: Seeing Red In Your Future?

Example 3: Eager Sales

Page 93: Seeing Red In Your Future?

Example 3: Eager SalesOrganization is a security contractor (build big guns).

Page 94: Seeing Red In Your Future?

Example 3: Eager SalesOrganization is a security contractor (build big guns).R&D, production, testing, management, sales, all in the same location (HQ).

Page 95: Seeing Red In Your Future?

Example 3: Eager SalesOrganization is a security contractor (build big guns).R&D, production, testing, management, sales, all in the same location (HQ).Sales are global, controlled from HQ.

Page 96: Seeing Red In Your Future?

Example 3: Eager SalesOrganization is a security contractor (build big guns).R&D, production, testing, management, sales, all in the same location (HQ).Sales are global, controlled from HQ.Extreme perimeter security, high-end physical security.

Page 97: Seeing Red In Your Future?

Example 3: Eager SalesOrganization is a security contractor (build big guns).R&D, production, testing, management, sales, all in the same location (HQ).Sales are global, controlled from HQ.Extreme perimeter security, high-end physical security.

Sales... few targeted emails, reverse shell home. Network is done. DA on production machines (mfg.), sales ledgers, major diplomatic incident potential...

Page 98: Seeing Red In Your Future?

Example 3: Eager SalesOrganization is a security contractor (build big guns).R&D, production, testing, management, sales, all in the same location (HQ).Sales are global, controlled from HQ.Extreme perimeter security, high-end physical security.

Sales... few targeted emails, reverse shell home. Network is done. DA on production machines (mfg.), sales ledgers, major diplomatic incident potential...

Process breakdown from physical security (USB drops), through separation of duties, network segmentation, egress data management.

Page 99: Seeing Red In Your Future?

Preparing for a red team (map)Locate business critical assets (identify)Getting buy-in (recruit)Defining goals (target)Finding a team (assemble)Define scenarios and RoE (scope)Establish white/blue team (monitor)Hang on tight (execute)Analyze (pre-report)Identify areas of improvement (gap)Create plan for remediation (fix)

Page 100: Seeing Red In Your Future?

mapidentifyrecruittargetassemblescopemonitorexecutepre-reportgapfix

Page 101: Seeing Red In Your Future?

mapidentifyrecruittargetassemblescopemonitorexecutepre-reportgapfix

Page 102: Seeing Red In Your Future?

mapidentifyrecruittargetassemblescopemonitorexecutepre-reportgapfix

RED TEAM READINESS

Page 103: Seeing Red In Your Future?

This isn’t rocket science

Page 104: Seeing Red In Your Future?

It’s not about who’s got the biggest one...

Page 105: Seeing Red In Your Future?

It’s about challenging an organization to improve its effectiveness

Page 106: Seeing Red In Your Future?

It’s about challenging an organization to improve its effectivenessyourself

Page 107: Seeing Red In Your Future?

It’s about challenging an organization to improve its effectivenessyourselfyour peers

Page 108: Seeing Red In Your Future?

It’s about challenging an organization to improve its effectivenessyourselfyour peersyour assumptions

Page 109: Seeing Red In Your Future?

It’s about challenging an organization to improve its effectivenessyourselfyour peersyour assumptions...

Page 110: Seeing Red In Your Future?

There is no certificate at the end :-(

Page 111: Seeing Red In Your Future?

There is no certificate at the end :-(

no CPEs

Page 112: Seeing Red In Your Future?

There is no certificate at the end :-(

no CPEs

no medals

Page 113: Seeing Red In Your Future?

There is no certificate at the end :-(

no CPEs

no medals

Just hard work :-)

Page 114: Seeing Red In Your Future?

And a better ROI than any other test/engagement the organization has ever gone through before

Page 115: Seeing Red In Your Future?

until the next red team...

Page 116: Seeing Red In Your Future?

Questions? Discussion!

Page 117: Seeing Red In Your Future?

map

ide

nti

fyre

cru

itta

rge

tas

sem

ble

sco

pe

mo

nit

or

exe

cute

pre

-re

po

rtga

pfi

x

Questions? Discussion!