long term packet capture in critical infrastructures · long term packet capture in critical...

18
Long Term Packet Capture in Critical Infrastructures Creating a Circle of Goodness for Security Operations

Upload: trinhdien

Post on 19-Apr-2018

229 views

Category:

Documents


4 download

TRANSCRIPT

Page 1: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Long Term Packet Capture in Critical Infrastructures

Creating a Circle of Goodness for Security Operations

Page 2: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Introduction Michael Meason, Manager of Technical Service - Western Farmers Electric Cooperative

Telecommunications Engineering

Network Engineering/Operations/Maintenance

Cyber Security Operations and Critical Infrastructure Protection

Letters

BS in CIS, MS in Telecommunications, CISSP, CSFI-DCOE, NSTISSI 4011 4015, CNSSI 4012 4013 4014 4016

Others

Husband/Father, KG5DQA, Aviation, @SigmetXray

Page 3: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Employer Slide Western Farmers Electric Cooperative

WFEC supplies the electrical needs of more than two-thirds of the

geographical region of Oklahoma, part of New Mexico, as well as small portions of Texas and Kansas

Page 4: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

The Circle of Goodness (C.O.G.)

Page 5: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Industrial Control Systems.. That’s What We do.

This is what we protect, but…..

Lessons learned can be applied to any infrastructure that is critical to your business or operations

Don’t dismiss the methodology as inherent to control systems

Page 6: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Imagine if You Could……..

Go back in time 2-8 weeks when an intrusion event occurs

Set the needle pre-event

DeLorean + Flux Capacitor + 1.21 Gigawatts = Network Data Recorder

Page 7: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Security Value

Reconstruct the Sequence of Events (SOE)

Incident response

Situational Awareness

Packet Analysis

Packet Retention

Protocol Analysis

Operational Malfunctions

Evasion Techniques

Baseline Traffic

IOC Replay

Page 8: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open
Page 9: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Operational Value Identify operational misconfigurations

High frequency low impact operational events

ILO & DRAC (DHCP Request Broadcast)

Other awesome examples

Low frequency high impact events

Monday night outages (sending sys logs for all file opens and closes and old syslog servers)

Page 10: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

The Circle of Goodness (C.O.G.)

Page 11: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Organizational Value

Importance of relationship between SOT and operations (OT/IT)

The NDR is a relationship “enhancer”

Help OT/IT help themselves

Page 12: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

The Circle of Goodness (C.O.G.)

Page 13: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Survey of the Tools: Commercial Network Data Recorders (NDR)

Wildpackets

GigaStor - Network Instruments

Solera DeepSee Blackbox Recorder

Page 14: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Survey of Tools: Open Source

Wireshark

TCPDump

DaemonLogger (Martin Roesch)

Moloch

Page 15: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Commercial -VS- Open Source How is commercial different from TCPDump and Uber Storage?

Color coded results

Easily filtered

Easily searched

Organized by timelines

Forensic search capabilities

Packet analysis capabilities

Page 16: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Commercial -VS- Open Source

Integration of hardware/software

Front end/back end integration challenges

You need ninja level foo

There is however, possibly a down-and-dirty solution

Page 17: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

Not a Silver Bullet

A tool in the belt

Noce Te Ipsum (Literally)

Systems don’t secure systems

Active hunting

Link between controls and reality

Page 18: Long Term Packet Capture in Critical Infrastructures · Long Term Packet Capture in Critical Infrastructures ... Packet Analysis Packet Retention . ... Moloch . Commercial -VS- Open

The Circle of Goodness (C.O.G.)