targeted attacks: analysis and investigation · – web-based attacks increased 30% – 5,291 new...

56
Targeted Attacks: Analysis and Investigation Building Trust in the Information Age Summer School on Computer Security & Privacy 16th of September 2014 Dr. Marco Balduzzi

Upload: others

Post on 26-Jun-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Targeted Attacks: Analysis and Investigation

Building Trust in the Information AgeSummer School on Computer Security & Privacy

16th of September 2014Dr. Marco Balduzzi

Page 2: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Course Outline

● Who am I and research in the industry● Target Attacks & Success Stories● Investigative Approach● Pseudo-Automated Approach● Discussion● Questions

Slides available @ Slides available @ iseclab.org/people/embyteiseclab.org/people/embyte

Page 3: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Who is Marco Balduzzi (embyte)

Page 4: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

BERGAMO

Page 5: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 6: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 7: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 8: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 9: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 10: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 11: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

MUNICH

Page 12: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 13: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 14: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

NICE

Page 15: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 16: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 17: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Back in the '80s – My First PC

Page 18: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Back in the '90s

Page 19: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 20: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

$ whoamiembyte

Page 21: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 22: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 23: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 24: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 25: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 26: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

1

Page 27: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 28: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 29: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 30: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

● 2010– AsiaCCS 2010

– DIMVA 2010

– RAID 2010

– TWDT 2010

● 2011– NDSS 2011 (2 papers)

– LEET 2011

– DIMVA 2011

● 2012– SAC 2012

– Schloss Dagstuhl 2012

● 2013– PST 2013 (2 papers)

● 2014– ACSAC 2014

– ISC 2014

● HackMeeting (HackIT)– 2003, 2004, 2014

● LinuxDay– 2003, 2004, 2005

● 2004– Security Date, Webb.it, MOCA, SatExpo

● OWASP– AppSec Research EU 2010, 2011, 2013– BeNeLux 2010, 2011– Italy 2013, 2014

● BlackHat– EU 2011, USA 2012, ASIA 2014– WebCast 2011 & 2012

● HITB (Hack In The Box)– KUL 2011, EU 2012, EU 2014

● Latin America– Security Zone Colombia 2011, 2012– 8.8 Chile 2011, 2012

● Others– MOHP 2007– Swiss Cyber Storm 2011– Etc...

Page 31: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Topics of Interest

● Real problems● Web and Browser Security● Vulnerability Code Analysis ● Botnets Detection (Network Security)● Cybercrime Investigation and Research● Privacy and Threats in Social Networks, and New

Technologies● Malware and Intrusion Detection Systems

Page 32: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

*Real* Topics of Interest

Page 33: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social
Page 34: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

So, what am I doing now?

Senior Research Scientist

Page 35: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

FTR Mission

Forward Looking

Statement for Executives

● Forward-Looking Threat Research● Considered the “elite” research team within

Trend Micro

Page 36: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

International Coverage

Page 37: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Honeypots Research

● Yes, we love data ;-)● Web Honeypot. Joint-research project with EURECOM

● ICS Honeypot.

Page 38: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Web Research

● Soundsquatting: Uncovering the use of homophones in domain squatting – Joint-research project with KUL. @ISC2014

Page 39: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Scouting the DeepWeb

Page 40: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Marketplaces & exchanged goods

Page 41: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Cybercriminals' infrastructures

●By Path

Page 42: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Technology Research – AIS

● Joint-project with external researcher

Page 43: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Technology Research

Page 44: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

LATIN AMERICA

EUROPE

APAC

NORTH AMERICA

GLOBAL

Page 45: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Operation Ghost Click

● 4 Millions bots, 100 C&C servers (#1 history)

● Steal clicks (replacing ads, hijacking search results)

● Collaboration between FBI, Estonian Police and FTR

● 2-years operation● Vladimir Tsastsin, CEO of

Rove Digital (ISP) ● 6+ years arrested

Page 46: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Hamza Bendelladj (BX1)

● SpyEye co-author (#1 banking trojan)● Algerian in Thailand (XMas)● https://www.youtube.com/watch?v=OAhSW-l0-Xk

Page 47: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Reveton Ransomware

● Locks you out. Demands money to let you back in :)

● http://www.northeastern.edu/securenu/wp-content/uploads/2012/09/multiple_ransomware_warnings.gif

● https://www.youtube.com/watch?v=wBMyaOa4Xnw

Page 48: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

BUT, Are these Targeted Attacks?

NO!

Page 49: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Targeted Attacks (MKT likes APT)

● Internet Security Threat Report:– Spam volume is decreased, but...

– Web-based attacks increased 30%– 5,291 new vulnerabilities discovered in 2012

– The number of phishing pages spoofing social networks increased 125%

● 42% increase in targeted attacks in 2012

Page 50: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Shift

● World dominated by widespread malware that infects indiscriminately, to a more selectively targeted approach

● Just-for-fun era is over?● Espionage, nation-driven, criminal organizations● Specific targets / industries– e.g. civil society organizations, business enterprises,

critical infrastructures, government and military assets

Page 51: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Modus Operandi

● High-selective Reconnaissance● Use of Social Engineering● Emails and IMs as attack-vectors● Malicious PDF, DOC, Flash● Persistence and Lateral Movements● Data Ex-filtration

Page 52: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

2009: Operation Aurora

Page 53: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

Ongoing since 2004 (at the least)

Page 54: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

2010: StuxNet Critical Infrastructures

Page 55: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social

2012-07: Cyberespionage program

Page 56: Targeted Attacks: Analysis and Investigation · – Web-based attacks increased 30% – 5,291 new vulnerabilities discovered in 2012 – The number of phishing pages spoofing social