viernes, 19 de diciembre de 2014

[Algunos] Retos de un CISO en el mundo actual

La vida del CISO (Chief Information Security Officer) o responsable de Seguridad de la Información antes de que nos invadieran las siglas anglosajonas, es una vida realmente dura. Entre sus responsabilidades se encuentran prever y proteger a la organización de todos los riesgos que puedan afectar a la seguridad de sus activos de información, detectar y responder de manera adecuada ante los incidentes de seguridad, gestionar la infraestructura de seguridad de su organización, gestionar todo el ciclo de vida de las vulnerabilidades técnicas y garantizar el cumplimiento con las leyes, regulaciones y estándares pertinentes en materia de seguridad de la información.

Pero si todo esto no os parece un reto suficientemente complicado, hay que añadir que el CISO tiene que afrontarlo con presupuestos generalmente muy ajustados o por debajo de lo necesario debido a lo difícil que es predecir el ROI de las inversiones en seguridad. Y no sólo es difícil predecirlo, sino que en muchos casos también es harto complicado medirlo una vez la inversión se ha realizado. Y es que aquí nos encontramos con la llamada ‘paradoja de la seguridad’ y que se da cuando en una organización no se están produciendo incidentes de seguridad. Cuando esto ocurre, la dirección de la empresa puede dudar si la falta de incidentes se debe a la inversión realizada o si seguirían sin tener incidentes aunque redujeran el presupuesto dedicado a seguridad. Y este tipo de dudas, en los tiempos de crisis que vivimos, ya sabemos cómo suelen acabar.

En mi opinión, la mejor manera que tiene un CISO de justificar sus presupuestos es realizar un análisis de riesgos presentando el ROI de la inversión de seguridad en forma de reducción del riesgo. Sin embargo, el resultado de estos análisis de riesgos se debe presentar en el idioma que la dirección entiende: $$. Hay que poner un valor cuantitativo y económico a cada riesgo, justificándolo adecuadamente y teniendo en cuenta el contexto del negocio. Y este es otro punto realmente complicado, ya que en muchas ocasiones el CISO no dispone de la información y el conocimiento del contexto de negocio para poder trasladar correctamente los riesgos de seguridad a impactos económicos para el negocio. Y esto nos lleva a una nueva paradoja del mundo de los CISO; les sobran los datos pero les falta información. Y es que el exceso de datos es otro de los mayores problemas con los que tiene que lidiar un CISO (o su equipo); eventos generados por multitud de dispositivos de seguridad y sistemas, resultados de escaneos de vulnerabilidad y pruebas de penetración, nuevas vulnerabilidades, nuevas amenazas, nuevas técnicas y tecnologías aparecidas en el ámbito de la seguridad de la información, etc...

Ser capaces de lidiar con toda esta cantidad de datos y ser capaces de transformarla en información útil, es uno de los grandes desafíos a los que se enfrentan los departamentos de seguridad de la inforamción. Ser capaces de centralizar, correlacionar y analizar a tiempo la información es un primer paso sin duda importante para ser capaces de convertir los datos en información. Generar alertas que permitan reaccionar a tiempo ante incidentes de seguridad, o análisis de tendencias que permitan detectar anomalías va un paso más allá y permite convertir esa información en inteligencia de seguridad. Pero el auténtico reto para el CISO es dar aún un paso adicional y ser capaz de transformar esa información y esa inteligencia de seguridad en inteligencia de negocio, siendo capaz de relacionar de una manera rápida y acertada esos riesgos e incidentes de seguridad con el impacto real que tenga para el negocio. Es decir, el auténtico desafío que deben encarar ahora los responsables de seguridad de la información es el de ser capaces de reportar en tiempo real a su dirección cual es el riesgo para el negocio que se está derivando de los riesgos de seguridad de la información, de manera que la dirección pueda contar con información actualizada e integral de los riesgos que afectan a su organización, independientemente de su origen (financieros, de seguridad física o de la información, de cumplimiento, de evolución de los mercados, de evolución de la competencia, etc..). Una vez los CISO puedan contar con herramientas que les permitan realizar esa transformación de datos a inteligencia de negocio de una manera eficiente, su vida será un poco más sencilla puesto que la justificación de sus presupuestos caerá por su propio peso. O visto desde la otra perspectiva, la Dirección del negocio contará con la información suficiente a la hora de tomar decisiones sobre qué objetivos concretos de seguridad exigirán al departamento de seguridad de la organización y, por lo tanto, que partida presupuestaria le asignarán para el cumplimiento de esos objetivos.





Así pues, en resumen, un buen CISO debe disponer de un correcto equilibrio entre habilidades técnicas y habilidades de gestión y conocimiento del negocio, teniendo capacidad para lidiar tanto con el personal técnico como con la dirección de la compañía mientras mantiene bajo su paraguas un alcance realmente amplio de responsabilidades en este apasionante mundo de la seguridad de la información dónde lo que ocurre hoy nada tiene que ver con lo que estará pasando el año que viene, o lo que es prácticamente lo mismo, de aquí a dos semanas. J

jueves, 27 de noviembre de 2014

Sistemas Industriales: ¿Parchear o no parchear?


Muchas son las peculiaridades que deben tenerse en cuenta al considerar la seguridad de los sistemas industriales y los sistemas SCADA. Una especialmente relevante  es el parcheo o actualización de los sistemas o del software que éstos soportan. Cuando en una evaluación de la seguridad de este tipo de sistemas se llega a la pregunta: “¿Y cómo realizáis el mantenimiento de los sistemas para solventar las vulnerabilidades conocidas que hayan sido resueltas por el fabricante?” nos podemos encontrar con respuestas de lo más variado. Algunas posibilidades son:
Opción 1: Cara de póker
“- Nosotros no aplicamos parches de seguridad. No es necesario puesto que nuestra red industrial está totalmente aislada y de todas formas, la mayoría de los fabricantes que utilizamos no publican actualizaciones de seguridad. Por otro lado, en ocasiones la actualización del software implica también cambio de hardware, por lo que las restricciones presupuestarias no permiten aplicar dichas actualizaciones.”
Esta respuesta o respuesta similares es bastante común. Y no me parece una estrategia descabellada a seguir la de no aplicar parches de seguridad siempre y cuando se cumplan los siguientes condicionantes:
1.       Se realice un análisis de riesgos para comprender claramente cuáles son las amenazas que nos pueden afectar por el hecho de no parchear nuestros sistemas y qué impacto podrían suponer dichas amenazas en caso de materializarse. Téngase en cuenta que no me refiero a realizar un ejercicio superficial de análisis de riesgos, si no que me refiero a analizar los riesgos en profundidad. Es decir, conocer exactamente qué vulnerabilidades son las que no estoy parcheando, como podrían ser explotadas por un atacante y qué medidas compensatorias al parcheo estoy implementando en mi infraestructura para paliar estos riesgos. A la hora de considerar las amenazas se debe prestar especial atención al perímetro de los sistemas industriales, los puntos de interactuación con las redes tradicionales y los puntos de acceso que son fácilmente accesibles por visitantes o por el público en general.

2.       Una vez realizado dicho análisis de riesgos, se vea que los problemas, costes o dificultades derivados de aplicar los parches sean superiores al riesgo que se mitigaría en caso de parchear.

3.       Que esta decisión sea llevada a cabo de forma informada y consciente por el propietario del riesgo,  es decir, por el responsable del proceso de negocio que sufriría las consecuencias en caso de que estos riesgos se materializaran.
Por otro lado, está claro que hay que presionar a los fabricantes para que implementen procesos de gestión de las vulnerabilidades de sus productos y la calidad de los mismos debería ser un criterio clave en la selección de este tipo de tecnologías para que este problema no se perpetúe en el tiempo.

Opción 2: El hombre tranquilo
“- Pues depende del fabricante, del dispositivo, y del técnico que se encargue de la actualización. No lo tenemos realmente documentado, pero usamos métodos diversos como la descarga directa desde la página web del fabricante de los ficheros de actualización (quien por cierto no publica un hash del fichero para verificarlo tras su descarga, y si lo publica no lo verificamos). A veces, para ganar tiempo incluso lo descargamos desde nuestra propia casa dónde el ancho de banda es mayor que en la oficina. Lo grabamos en nuestro USB y lo conectamos a la red de sistemas industriales que está totalmente aislada de la red de IT. Otras veces, es un partner o el propio fabricante quien viene con su USB o con sus portátiles y se conectan directamente a nuestra red industrial para aplicar las actualizaciones o realizar cualquier otro tipo de intervención.”

En estos casos, como podéis imaginar, el problema radica en que el ‘aislamiento’ deja de ser tal cuando el USB, el portátil o el CD de turno se conecta a nuestra red aislada. Algunas amenazas a las que se exponemos nuestros sistemas con éstas prácticas son:
·         Malware que pueda causar problemas de rendimiento o incluso una denegación de servicio en estos equipos.
·         Malware avanzado capaz incluso de permitir el control remoto o el robo de datos. Aunque a priori esto parece imposible en una red aislada, en la actualidad podemos encontrar numerosas pruebas de concepto sobre cómo se podrían realizar estos ataques sorteando el ‘Air GAP’.
·         Actualizaciones fraudulentas descargadas de internet cuyo funcionamiento será diferente al esperado.
·         Terceros que se conectan a nuestra red utilizando sus propios sistemas que pueden tener un nivel de seguridad inferior al nuestro. Además, si no controlamos qué actividades realizan en nuestros sistemas pueden ser una fuente de amenaza a tener en cuenta. No olvidemos que es muy probable que nuestros partners trabajen también para nuestra competencia directa, por lo que es una fuente de riesgo a tener en cuenta.

Opción 3: El precavido
“En nuestra organización disponemos de procesos documentados y seguros para llevar a cabo la actualización de todos nuestros sistemas industriales. Tenemos diversos sistemas para estar informados de cualquier nueva vulnerabilidad que se descubra que puede afectar a nuestros sistemas. Realizamos un análisis comparativo de los riesgos que supone llevar a cabo la actualización comparándolos con los que supone dejar los sistemas sin parchear, de manera que el propietario del proceso puede establecer el criterio a seguir para tomar la decisión de si se debe parchear y en qué plazo debe hacerse. Una vez decidimos que un parche debe aplicarse, lo obtenemos de una fuente segura verificando su integridad y autenticidad, lo desplegamos en nuestros entornos de prueba para verificar que la actualización no comprometerá la funcionalidad ni la seguridad de los sistemas y, sólo después de esto, y bajo nuestro estricto control y supervisión, la actualización se despliega en producción dentro del plazo establecido por el propietario del proceso.”

Pues si te vienen con estas, poco vas a tener que decir salvo asentir y felicitar al cliente. Sin embargo, hasta el momento no me he encontrado con el caso, aunque no pierdo la esperanza…
En conclusión, los procesos de gestión de vulnerabilidades son un aspecto crítico a considerar en cualquier evaluación de seguridad que se realice, pero especialmente si lo que estamos evaluando son sistemas industriales y/o sistemas SCADA. No actualizar significa acumular vulnerabilidades, mientras que el proceso de actualizar puede ser en sí mismo una amenaza si no se realiza de manera adecuada. Por lo tanto, planificar, documentar y establecer un ciclo de mejora continua sobre los procesos de gestión de vulnerabilidades debería estar en la agenda de cualquier responsable de seguridad que pretenda mejorar la protección de su organización.

49M of GBP or how to be scammed

A few weeks ago I received a linkedin message asking me if I would mind receive and manage 49 millions of GBP. Usually I ignore these emails, or just do a quick look to see what kind of new baits are being used to deceive those who are overconfident or too ambitious. In this case, however, I decided to see how the game evolved since the scammer had taken the effort to create a LinkedIn profile, make connections, wait some time and finally start the campaign to send mail. The initial mail was not particularly elaborate, since only asked if I was interested in working managing and investing the 49 billion pounds, and so, I should send an email to chang09e@gmail.com. Thus, the scammer could continue trading from Gmail once will disable his account of linkedin. As I said, I decided to answer and express my interest in the offer with the intention of seeing what technique was using the cheat. After a few hours I received the following response:

Thanks for your email. I'm Elizabeth Chang. You were contacted on behalf of Terry Wong former personal assistant to the former President of Taiwan Mr. Chen Shui-Bian on private matters. An investment was placed under his care 5 Years ago, He need assistance in investing this funds into good use. So I would want to know if you're willing to assist him if so I would provide you with more details on the matter.
Best regards

Once I responded to this mail requesting additional details about this great opportunity, this is the answer that I received:
Thanks for your response and request for more details. The information contained therein is not to be disclosed due to the sensitive nature. It is for your knowledge only. Mr. Chen Shui-bian is in a difficult predicament with the Taiwan Government because of his role in politics and the ruling government has sworn to ruin him because he sponsored a major party against the ruling government with his Influence.
However, let me give you some basic details.
Firstly, you must know that this transaction consist of changing the rights of the funds in question to your ownership and afterwards transferring same to you for immediate management/investment in long term profit investment.
Secondly, it is imperative that the most valuable criteria to qualify you for this transaction is on the basis that you are practically, financially and technically qualified to handle and manage such an amount of money. That is not negotiable. This is because of the basic requirements and confidentiality agreement I signed with Mr Chen Shui-bian.
This is a brief on the Placement:
Value of funds: £49 MILLION GBP.
Placement open to: INDIVIDUALS/COMPANIES.
Areas of Investment Interest: HEALTH, REAL ESTATE, COAL MINING AND CONSTRUCTION.
Purpose of Funds: LONG TERM INVESTMENT (AT LEAST) 10-15 YEARS
Client's Full Name: MR. CHEN SHUI-BIAN.
I have been directly contacted as a confidential secretary by Mr Chen Shui-bian to recruit a foreign partner under whose identity the funds will be transferred. For your benefit of doubt, the objectives are to change the entire identity of the funds to your ownership as the beneficiary. The funds will be transferred to you ASAP. My duty is to ensure that the beneficiary documents for this transaction is by all means satisfied and within the ambit of local/international laws. I am entirely responsible for the facilitating of the beneficiary documents that will put you in place as the beneficiary of the funds. Thereafter, you will therefore be legally qualified to receive the funds into your business/personal bank account for investment and management purposes only.
Consequently, we may commence without delay once we have been able to secure your trust and partnership. The funds will be ready for transfer to you as soon as we have established a reasonable degree of trust with each other once you have satisfied the basic qualification requirements. Mr Chen Shui-bian demand utmost confidentiality as regards his involvement with the funds in question. If you agree to partner with Mr Chen Shui-Bian, he will compensate you with 20% of the total sum for your role as the beneficiary partner to the funds and the balance 80% will be invested on behalf of my client by you.
Nonetheless, in order to commence the re-direction of the funds to you, we will require that you submit the following information listed below:
Have You In Your Entire Life Handle Funds Worth One Million GBP Before?
What Is Your Annual Turnover?
Will You Be Able To Travel Outside Your Country If Need Be?
Full Names:
Address:
Occupation:
Office Phone No:
Mobile Phone No:
Country:
Scanned copy of your ID either international passport or drivers license.
The above information will enable us to determine your qualification for receivership and subsequent placement of the funds to you. The data will also be used in the drafting and preparation of all the vital paper documentations in your particulars before the funds can be transferred you in liquid cash.
As it stands out, these are the briefs of this proposal. I will be sending you a "Consultant Non-Disclosure Agreement" for you to read carefully and sign as soon as I receive the above information's.
You can ring me on my private telephone number indicated below for comprehensive verbal communication and explanations.
I await your email and response.
After receiving this response I couldn’t avoid thinking, there are people who really can believe all this and take the bait? But of course the answer is yes if you send it to enough people.
The mail uses some very basic tricks like indicate that you can contact by phone at the number listed to give an impression of confidence. But of course, there aren’t any phone number indicated in the mail.
After answering sending dummy data I received the following email in response:
Thanks so much for your email. I would need you to forward this informations to Mr. Terry ( terrysaitakw@gmail.com ) he would provide you with every other information you require to get the funds. Thanks once again.
This was new to me and made no sense. Why should I send the data to a new gmail account? I can think of the following reasons:
  1. There really is more than one person behind the hoax and have divided the task, dealing with the first initial contact and then moving the contact to the ‘second level support to fraud’. It seems unlikely.
  2. Another trick to build confidence in the victim who is perceived to be dealing with an organization. This hypothesis seems the most likely for me.
Anyway, I did the forward to this Mr. Terry and this was his answer:
Now I am certain that you are willing to give the required assistance. Let me reiterate here that I seek an assistance from you that will benefit us immensely that is why I am sending you more information to enable you have an in-depth and total understanding of this transaction before we commence.
I want you to understand that we are only going to deal with each other in this transaction as you already know Mr. Chen Shui-Bian is jail. By this I mean, this transaction is confidential between me and you. This is so because of the present circumstances surrounding the owner of the funds Mr. Chen Shui-Bian. And as such, I expect that we keep every dealing entirely confidential between us.
Find enclosed with this message, a Non-Disclosure Agreement between my humble self and you. You are advice to download, print out read and sign the agreement.
As soon as you send back the signed agreement, I will begin the process of securing the beneficiary documents in your names.
I will be expecting the signed agreement, please send back signed page via email attachment.
Sincerely
After receiving this email I thought I had the chain here. I thought the PDF included a malware and this was the method by which the scammer monetized the campaign. But no, the PDF was clean and simply simulating a real NDA. A new trick to seems a reliable opportunity. So I returned it ' signed ' and this was the next mail I received:
Thanks for the signed agreement, I am glad that we have reached an agreement and this gives me a big sign of confidence in you, I am obliged to give you some useful information's that you alone would be privy to and you alone I insist. I had to reach out to Mr. Chen Shui-bian personally over some issues and get certain facts straight. As you know Mr. Chen Shui-bian and his family are in difficult predicament with the Taiwanese Government. Firstly, you must acknowledge that this transaction is a deal and it has to be treated as such and every information's from you and I must be kept confidential, you must not communicate the origin of this transaction to any third party, I am only trying to assist a friend to relocate his funds valued £49 MILLION from the present location without Taiwanese Government awareness because of his political problem. Secondly, you must understand that the £49 MILLION is NOT directly in my possession; it is currently deposited in the name of an existing legal entity and Mr. Chen Shui-bian cannot directly access the funds because of his present political predicament otherwise the Taiwanese Government will also confiscate the funds and that is why he privately seek your assistance to help him move the funds from the present location for investment in your country. I am assisting him in my own private capacity to help him move the funds from the present location and the Government is not aware of my assistance to him. The £49M in question is presently deposited as a secured vault deposit with a Private security Bank in London, United Kingdom where some top government officials and politicians keep their money while they are in public office for security and confidential reasons. A vault deposit is not like a regular bank account because a regular bank account can be traced and investigated easily and could put my client into serious trouble or even death penalty in Taiwan because it is forbidden for top government officials to hold such bank account. I do not need to emphasize this point. As soon as I secured the beneficiary documents that will empower you to the deposit, I have forward your information to Mr. Chen attorney to draft the necessary beneficiary documents in your favor; I will be sending you copies when they are ready on after i obtain it for your safe keeping. Kindly acknowledge the receipt of this email.
I love the part of “this gives me a big sign of confidence in you”. J
And at least, after answering the mail I received a mail asking me to send money so I could access to the 49 GBP of Mr. Chen.
Thank you for your email, I called the mobile number you provided but I can seem to be able to reach you. I am still battling to get the change of beneficiary from Mr. Chen's lawyer because he is requesting for 5,640 pounds to get the documents and I told you prior to this that you will be responsible for all administrative and lawyer's charges which includes Mr. Chen's lawyer because all eyes and the Government are still monitoring our moves in that regime so please try and understand the situation i am in now and to let you know that Mr. Chen's family are in serious financial predicament so that is why we want to repatriate the fund and use it for a good purpose to generate fund for their well being so let me hear from you regarding the payment for the lawyer so that i can furnish you with the account details. CHINA MERCHANTS BANK (SHENZHEN SUNGANG SUB -BRANCH)SWIFT: CMBCCNBSXXXADD: No 828 international trade bldg , baoanbei road louohu shenzhen china.ACCOUNT NO: 6225 8878 3037 9612NAME: LIANG MING DEBest regards
In conclusion, social engineering methods used in these scams don’t evolve , are still using the Nigerian scam without taken care of the appearance of the emails and based on SPAM (in this case via linkedin) to attract potential victims. But they do not need to invest more efforts in this type of campaign since it still works and with a minimum investment they can win a lot of money from their victims.

viernes, 14 de noviembre de 2014

49 millones de libras o como ser engañado por un chino


Hace algunas semanas recibí un mensaje de Linkedin preguntándome si me importaría recibir y gestionar 49 millones de libras. Generalmente ignoro este tipo de mails, o simplemente les echo una rápida ojeada para ver qué tipo de nuevos cebos están utilizando para engañar a aquellos que son demasiado confiados o demasiado ambiciosos. En este caso, sin embargo, decidí seguir el juego a ver cómo evolucionaba dado que el estafador se había tomado la molestia de crear un perfil de linkedin, establecer conexiones, dejar pasar un tiempo y finalmente iniciar la campaña de envío de mail. El mail inicial no era especialmente elaborado, puesto que únicamente solicitaba que si se estaba interesado en trabajar gestionando e invirtiendo esos 49 millones de libras ajenas, se enviara un mail a chang09e@gmail.com. De esta manera, el estafador podía continuar su actividad desde Gmail una vez linkedin deshabilitara su cuenta ante los previsibles avisos de los usuarios. Como digo, decidí contestar y manifestar mi interés por la oferta con la intención de ver qué técnica estaba usando el estafador. Al cabo de unas horas recibí la siguiente respuesta:

Thanks for your email. I'm Elizabeth Chang. You were contacted on behalf of Terry Wong former personal assistant to the former President of Taiwan Mr. Chen Shui-Bian on private matters. An investment was placed under his care 5 Years ago, He need assistance in investing this funds into good use. So I would want to know if you're willing to assist him if so I would provide you with more details on the matter.

Best regards

Después de que respondiera a este mail solicitando más detalles sobre esta gran oportunidad, la respuesta que recibí fue la siguiente:

Thanks for your response and request for more details.

The information contained therein is not to be disclosed due to the sensitive nature. It is for your knowledge only. Mr. Chen Shui-bian is in a difficult predicament with the Taiwan Government because of his role in politics and the ruling government has sworn to ruin him because he sponsored a major party against the ruling government with his Influence.
However, let me give you some basic details.
Firstly, you must know that this transaction consist of changing the rights of the funds in question to your ownership and afterwards transferring same to you for immediate management/investment in long term profit investment.
Secondly, it is imperative that the most valuable criteria to qualify you for this transaction is on the basis that you are practically, financially and technically qualified to handle and manage such an amount of money. That is not negotiable. This is because of the basic requirements and confidentiality agreement I signed with Mr Chen Shui-bian.

This is a brief on the Placement:

Value of funds: £49 MILLION GBP.

Placement open to: INDIVIDUALS/COMPANIES.

Areas of Investment Interest: HEALTH, REAL ESTATE, COAL MINING AND CONSTRUCTION.

Purpose of Funds: LONG TERM INVESTMENT (AT LEAST) 10-15 YEARS

Client's Full Name: MR. CHEN SHUI-BIAN.

I have been directly contacted as a confidential secretary by Mr Chen Shui-bian to recruit a foreign partner under whose identity the funds will be transferred. For your benefit of doubt, the objectives are to change the entire identity of the funds to your ownership as the beneficiary. The funds will be transferred to you ASAP. My duty is to ensure that the beneficiary documents for this transaction is by all means satisfied and within the ambit of local/international laws. I am entirely responsible for the facilitating of the beneficiary documents that will put you in place as the beneficiary of the funds. Thereafter, you will therefore be legally qualified to receive the funds into your business/personal bank account for investment and management purposes only.
Consequently, we may commence without delay once we have been able to secure your trust and partnership. The funds will be ready for transfer to you as soon as we have established a reasonable degree of trust with each other once you have satisfied the basic qualification requirements. Mr Chen Shui-bian demand utmost confidentiality as regards his involvement with the funds in question. If you agree to partner with Mr Chen Shui-Bian, he will compensate you with 20% of the total sum for your role as the beneficiary partner to the funds and the balance 80% will be invested on behalf of my client by you.
Nonetheless, in order to commence the re-direction of the funds to you, we will require that you submit the following information listed below:

Have You In Your Entire Life Handle Funds Worth One Million GBP Before?

What Is Your Annual Turnover?

Will You Be Able To Travel Outside Your Country If Need Be?

Full Names:

Address:

Occupation:

Office Phone No:

Mobile Phone No:

Country:

Scanned copy of your ID either international passport or drivers license.
The above information will enable us to determine your qualification for receivership and subsequent placement of the funds to you. The data will also be used in the drafting and preparation of all the vital paper documentations in your particulars before the funds can be transferred you in liquid cash.
As it stands out, these are the briefs of this proposal. I will be sending you a "Consultant Non-Disclosure Agreement" for you to read carefully and sign as soon as I receive the above information's.
You can ring me on my private telephone number indicated below for comprehensive verbal communication and explanations.

I await your email and response.

Después de recibir esta respuesta no pude dejar de pensar, ¿pero habrá gente que realmente se pueda creer todo esto y picar el anzuelo? Utiliza algunos trucos muy básicos, como indicar que se puede contactar telefónicamente en el número indicado para dar mayor sensación de confianza, aunque luego no indican ningún número de teléfono.
Después de contestar enviando datos ficticios, recibí como respuesta el siguiente mail:

Thanks so much for your email. I would need you to forward this informations to Mr. Terry ( terrysaitakw@gmail.com ) he would provide you with every other information you require to get the funds. Thanks once again.

Esto sí que era nuevo para mí y no tenía ningún sentido. ¿Por qué hacerme enviar los datos a una nueva cuenta de gmail? Se me ocurren los siguientes motivos:

1.       Realmente hay más de una persona detrás del fraude y tienen divididas las tareas, ocupándose los primeros del contacto inicial y pasando luego el contacto al ‘segundo nivel de soporta al fraude’. Me parece improbable.

2.       Un nuevo truco para generar confianza en la víctima que tiene la percepción de estar tratando con una organización aunque el estafador tras ambas cuentas sea el mismo. Esta hipótesis me parece la más probable.

En cualquier caso, le hice el forward al tal Mr. Terry y esta fue la siguiente respuesta recibida:

Now I am certain that you are willing to give the required assistance. Let me reiterate here that I seek an assistance from you that will benefit us immensely that is why I am sending you more information to enable you have an in-depth and total understanding of this transaction before we commence.

I want you to understand that we are only going to deal with each other in this transaction as you already know Mr. Chen Shui-Bian is jail. By this I mean, this transaction is confidential between me and you. This is so because of the present circumstances surrounding the owner of the funds Mr. Chen Shui-Bian. And as such, I expect that we keep every dealing entirely confidential between us.
Find enclosed with this message, a Non-Disclosure Agreement between my humble self and you. You are advice to download, print out read and sign the agreement.
As soon as you send back the signed agreement, I will begin the process of securing the beneficiary documents in your names.
I will be expecting the signed agreement, please send back signed page via email attachment.

Sincerely
Tras recibir este mail pensé que aquí acababa la cadena. El supuesto PDF incluía un regalo no deseado en forma de malware y éste era el método con el que el estafador monetizaba la campaña. Pero no, resultó que el PDF no tenía ningún malware y simplemente simulaba un NDA. Así que lo devolví ‘firmado’ y este fue el siguiente mail que recibí:
Thanks for the signed agreement, I am glad that we have reached an agreement and this gives me a big sign of confidence in you, I am obliged to give you some useful information's that you alone would be privy to and you alone I insist.

I had to reach out to Mr. Chen Shui-bian personally over some issues and get certain facts straight. As you know Mr. Chen Shui-bian and his family are in difficult predicament with the Taiwanese Government.

Firstly, you must acknowledge that this transaction is a deal and it has to be treated as such and every information's from you and I must be kept confidential, you must not communicate the origin of this transaction to any third party, I am only trying to assist a friend to relocate his funds valued £49 MILLION from the present location without Taiwanese Government awareness because of his political problem.

Secondly, you must understand that the £49 MILLION is NOT directly in my possession; it is currently deposited in the name of an existing legal entity and Mr. Chen Shui-bian cannot directly access the funds because of his present political predicament otherwise the Taiwanese Government will also confiscate the funds and that is why he privately seek your assistance to help him move the funds from the present location for investment in your country. I am assisting him in my own private capacity to help him move the funds from the present location and the Government is not aware of my assistance to him.

The £49M in question is presently deposited as a secured vault deposit with a Private security Bank in London, United Kingdom where some top government officials and politicians keep their money while they are in public office for security and confidential reasons. A vault deposit is not like a regular bank account because a regular bank account can be traced and investigated easily and could put my client into serious trouble or even death penalty in Taiwan because it is forbidden for top government officials to hold such bank account. I do not need to emphasize this point.

As soon as I secured the beneficiary documents that will empower you to the deposit, I have forward your information to Mr. Chen attorney to draft the necessary beneficiary documents in your favor; I will be sending you copies when they are ready on after i obtain it for your safe keeping.

Kindly acknowledge the receipt of this email.

Me encanta lo de “this gives me a big sign of confidence in you”. J

Y por fin, tras contestar a este mail recibí el mail pidiéndome que ingresara cierto dinero para que pudieran poner a mi nombre los fondos de Mr. Chen:

Thank you for your email, I called the mobile number you provided but I can seem to be able to reach you. I am still battling to get the change of beneficiary from Mr. Chen's lawyer because he is requesting for 5,640 pounds to get the documents and I told you prior to this that you will be responsible for all administrative and lawyer's charges which includes Mr. Chen's lawyer because all eyes and the Government are still monitoring our moves in that regime so please try and understand the situation i am in now and to let you know that Mr. Chen's family are in serious financial predicament so that is why we want to repatriate the fund and use it for a good purpose to generate fund for their well being so let me hear from you regarding the payment for the lawyer so that i can furnish you with the account details.

CHINA MERCHANTS BANK (SHENZHEN SUNGANG SUB -BRANCH)

SWIFT: CMBCCNBSXXX

ADD: No 828 international trade bldg , baoanbei road louohu shenzhen china.

ACCOUNT NO: 6225 8878 3037 9612

NAME: LIANG MING DE

Best regards

En conclusión, los métodos de ingeniería social utilizados en este tipo de estafas no evolucionan, se sigue utilizando el timo nigeriano sin cuidar en exceso las formas de los mails y basándose en el SPAM (en este caso via linkedin) para captar víctimas potenciales. Pero es que no necesitan invertir más esfuerzos en este tipo de campañas. Para los estafadores, una inversión mínima es suficiente, de manera que con que 1 única víctima pique (y pican...) ya obtienen un excelente retorno de la inversión.

domingo, 7 de septiembre de 2014

Segundo factor de autenticación en Linkedin


A mediados de agosto, al dejar mi trabajo en Caja de Ingenieros y por lo tanto abandonar mi número de teléfono móvil, me encontré con que el número al que enviaba mi segundo factor de autenticación había desaparecido. Sin embargo, pensé que no pasaba nada, puesto que en cuanto tuviera disponible mi número suizo no tendría más que actualizar el número de teléfono en linkedin, gmail y los otros servicios online que tienen el doble factor de autenticación.

Sin embargo, coincidiendo con la misma fecha, actualicé mi versión de ubuntu de la 12.04 a la 14.04 sin pensar para nada en el tema del doble factor. Y, efectivamente, me quedé sin acceso a mis servicios online, ya que los servicios web no reconocían mi PC como un equipo autorizado, y aunque me mandaran el código de acceso a mi teléfono móvil yo ya no era capaz de recibirlo.

Con Gmail, no fue un problema, puesto que permite tener configurado un segundo número de teléfono móvil en el que recibir el código, así que pude acceder y cambiar la configuración del acceso con segundo factor. También te dan la opción de tener impresos códigos de emergencias de un sólo, por lo que las alternativas de cara a recuperar el acceso son mayores.

Sin embargo, linkedin no permite configurar un teléfono alternativo, por lo que no tenía ningún medio de acceder a mi cuenta. Tras enviar un mail a su dirección de soporte preguntándoles cómo podía conseguir recuperar mi acceso, me solicitaron que les enviara por mail una imagen de mi DNI o mi pasaporte. Una vez enviado, deshabilitaron el segundo factor inmediatamente, por lo que pude recuperar mi cuenta sin problema.

A raíz del incidente, me planteé si se podría aprovechar este procedimiento que tiene linkedin para permitir que los usuarios que sean tan torpes como yo y que pierdan tanto su móvil como los equipos autorizados a acceder a la cuenta, para conseguir acceso a una cuenta sin necesidad de disponer del segundo factor de autenticación. Y en efecto, se podría llegar a acceder, ya que el procedimiento es vulnerable (no se trata de una vulnerabilidad técnica en este caso, sino procedimental). Así pues, el segundo factor de autenticación en Linkedin puede ser saltado bajo determinadas circunstancias. Veamos como:

Todo lo que necesita el atacante es conocer el nombre de usuario y contraseña de la víctima y hacer uso de Gimp, photoshop u otra herramienta de edición digital para enviar un DNI falsificado al equipo de soporte de Linkedin. Al fin y al cabo, lo único que se tiene que modificar es la foto, que podría obtener directamente del perfil público de la víctima o de cualquier red social, la fecha de nacimiento y el nombre y apellidos. El número, la dirección y otros datos del carné se pueden dejar incorrectos puesto que no son conocidos por Linkedin y por tanto no pueden cotejarlos. Es posible que el personal de linkedin también compruebe que el mail desde el que el usuario está solicitando la resolución del problema coincida con el que tiene informado el usuario, por lo que el atacante deberá falsear la dirección de remitente al enviar el mail.

Aunque el ataque tiene un alcance muy limitado y puede ser fácilmente detectado por la víctima al recibir mails inesperados del soporte de Linkedin, si el atacante ha conseguido comprometer también el correo de la víctima, por ejemplo porque use la misma contraseña y no lo tenga protegido con doble factor, el ataque podría perpetrarse de una forma mucho más limpia y efectiva.

En cualquier caso, siempre se deberían seguir las siguientes recomendaciones de seguridad en el uso de las cuentas on line:

  • Protege siempre tu móvil con código o contraseña. De lo contrario, si alguien te lo roba o lo pierdes, tendrán acceso directo a tu correo electrónico y a tus perfiles digitales.
  • Intenta no reutilizar la misma contraseña en diversos servicios online para evitar que el compromiso de una credencial resulte en el compromiso de todos tus servicios online.
  • Siempre que sea posible, evita que el acceso a Linkedin u otros servicios online se haga desde el mismo móvil en el que recibes el segundo factor de autenticación. En caso de que el terminal esté infectado por un malware, es posible que el atacante sea capaz de obtener tanto las credenciales de acceso como el código de segundo factor.
  • No almacenes en tu correo imágenes de tu pasaporte, DNI, etc... Como ves, pueden ser utilizadas para conseguir acceso a tus servicios online sin disponer del segundo factor de autenticación.

¿Aún no me sigues en twitter? @omarbenjumea

domingo, 3 de agosto de 2014

Example of Risk Analysis Methodology


Introduction
The objective of this post is explain a risk analysis methodology that I used in the past successfully in different kind of clients. It is similar to other standard methodologies like the Spanish Magerit or ISO31000 but it has some particularities that permits make simply but robust analysis.

In first place let's to introduce the fictitious scenario that we will use as example to develop this risk analysis methodology.

The company Moreculture INC, is an on-line bookshop. It is dedicated only to shop physical books via its web page. It don't has book stock since it buy the books directly to a vendor after each purchase.

Moreculture's CEO is aware that information security is basic for his business, so he decided to make a risk analysis to know what risk affects his business and what he needs to do to avoid them.

Threats Catalog
First thing to do is prepare the catalog of threats to consider in our analysis. What I normally do is simplify an exhaustive threat catalog as Magerit's catalog ignoring these threats that are not relevant for our business or process to analyze. Also, I normally group some similar threats with the objective of do the analysis as simple as possible.

Work with a large catalog multiply the effort and the time required to finish the risk analysis. My recommendation is don't use more than 10 threats in the analysis.

In our example case, we will consider just this 6 threats:
  • Natural Disasters
  • Users errors
  • Programming errors
  • Administration errors
  • Malware
  • Intentional attack

If we group threats to simplify the analysis, is important guarantee that all the threats categories that really could affect the business information are included in our catalog to do a rigorous analysis and don't underestimate relevant risks. In addition, to elaborate the catalog, we should consider the internal and external context where the organization operates. For example, threats as fraud, theft or industrial disaster could or not apply depending of the organization.

Following with our example, now that we have our threats catalog defined, let's to assess the standard probability value for each threat. This value will be the probability that we will consider by default, but could be modify for each asset depending of its vulnerabilities. For evaluate the probability (and the rest of variables in the analysis) I will use a scale of 5 values. Depending on the detailed that we want for our risk analysis we could user just 3 values or use a model with a broader scale (7, 10 or even more values):
    5- Extremely probable
    4- Very probable
    3- Probable
    2- Unlikely
    1- Negligible probability
Thus, our catalog of threats will be as follows (in brackets the dimension or dimensions that can affect the threat):
  • Natural Disaster (Availability): 1
  • Users Errors (Confidentiality, Integrity, Availability): 4
  • Programming errors (Confidentiality, Integrity, Availability): 3
  • Administration errors (Confidentiality, Integrity, Availability): 3
  • Malware (Confidentiality, Integrity, Availability): 5
  • Intentional attacks (Confidentiality, Integrity, Availability): 4

Process Map
Now that we have our threat catalog defined, let's to develop our BIA (Business Impact Analysis). For do it, if we haven't one yet, we will need a map of our business process.
To simplify the example, we suppose that our company has just this process, but any real company will have much more process, specially support process. We will identify also the applications that are supporting each of the process:

  • Selling book to client Process:
    • Web Application of book selling.
    • Enterprise mail for contact with clients and doubts resolution.
    • Billing application.
  • Process of book purchase to the wholesaler:
    • Web Application of book selling. (the app send a command directly to wholesaler using the corporate mail server)
    • Mail Server
  • Process of book delivery to the client:
    • Web Application of book selling. (the app send a command to the courier for pick up the book and deliver it to the client).
    • Mail Server

BIA (Business Impact Analysis)
The first thing that we will do for elaborate our BIA is assess the impact that we could have if the confidentiality, integrity or availability of the information related with our business processes would be compromise. We will do this evaluation in different areas.

Some examples of possible areas are:
  • Financial
  • Legislative / regulatory
  • Operating
  • Environmental
  • Damage to persons
  • Damage to company image or loss of customer confidence
  • Etc..

In our example, as some areas don't apply (environmental, people damage, ..) we will just assess next areas:


Financial
Legislative /regulatory
Very Low
Less than 500€
-
Low
Between 500€ and 2500€
-
Medium
Between 2500 and 7500€
Subpoena
High
Between 7500 y 20000€
Fine or penalty
Very High
More than 20000€
License revocation

Let's analyze the impact for each business process:

If we analyze the sales process's confidentiality we can see that a compromise will have a Very High impact because the app process personal data of clients and the Data Privacy law fines in its lower range could get 40.000€. In legislative impact we will be in High level because we could get a data privacy fine or penalty.

We will do the same kind of analysis for Integrity and Availability dimensions (in availability case we will assess the impact if the process isn't available for 1 hour, 1 day or 1 week):

Sales Process
Financial
Legislative
Confidentiality
Very High (5)
High (4)
Integrity
Very High (5)
High (4)
Availability
1 hour
Very Low (1)
-
1 day
Low (2)
-
1 week
Medium (3)
-

Lastly, for each dimension we select the biggest impact between the assessed categories. Our BIA will be like this:


Confidentiality
Integrity
Availability



1 hour
1 day
1 week
Sales
5
5
1
2
3
Purchases
1
5
0
0
1
Delivery
5
5
0
0
2


Acceptable level of risk
With the BIA prepared we are ready to establish which is the acceptable level of risk for our company. I mean, where are we going to set the line that separates acceptable risks for those requiring urgent actions for resolution. The company sets that don't want to take risks that exceed 7,500 € or likely would pose fines or penalties and, of course, the revocation of his license to sell books online. So, the acceptable level of risk for Moreculture Inc, is don't tolerate risks with a value of 4 or 5.

Inventory of Assets and Map of Dependencies

Now, with the BIA prepared and the tolerate level of risk defined, we need an inventory of assets and the dependencies map before to start the risks evaluation process.

This will be our Assets inventory (simplifying, because we don't consider people or locations as assets in this example):

Applications:
  • Sales Web Application (APP_Sales)
  • Corporate mail (App_Mail)
  • Billing Application (App_Billing)

Data Bases:
  • Data base of clients (DB_clients) (SQL Server)
  • Data base with books master (DB_Maestro)(SQL Server)
  • Data base with the history of operations (DB_Operations)(SQL Server)

Systems:
  • System A (Linux + Apache)
  • System B (Windows XP)
  • System C (Windows 2008 Server)

All the applications are executed in System A, System B supports the e-mail server and System C runs the SQL Server with the three data bases.

The dependencies map will be as follow:

SALES process -> App_Sales -> System A
-> DB_Clients -> System C
-> DB_Master -> System C
-> App_Mail -> System B
-> App_Billing -> System A
-> DB_Clients -> System C

  PURCHASINGprocess -> App_Sales -> System A
-> DB_Master -> System C
-> App_Mail -> System B
DELIVERY process -> App_Sales -> System A
-> DB_Clients -> System C
-> DB_Operations -> System C
-> App_Mail -> System B
-> App_Billing -> System A
-> BD_clientes -> System C

Now we will make inherit assets inherit the impact classification under the dependency map. The result of impacts that we obtain will be as follow:



Confidentiality
Integrity
Availability



1 hour
1 day
1 week
Sales
5
5
1
2
3
Purchasing
1
5
0
0
1
Delivery
5
5
0
0
2
APP_Sales
5
5
1
2
3
APP_Mail
5
5
1
2
3
APP_Billing
5
5
1
2
3
BD_Clients
5
5
1
2
3
BD_Master
5
5
1
2
3
BD_Operations
5
5
0
0
2
System A
5
5
1
2
3
System B
5
5
1
2
3
System C
5
5
1
2
3

Next step is take each asset of our inventory (or typology of asset if we want simplify) and analyze if are or not vulnerable to each of the threats identified in our catalog.


Applications
Data Bases
Systems
Natural disasters
Not Vulnerable
Not Vulnerable
Vulnerable
Users errors
Vulnerable
Not Vulnerable
Not Vulnerable
Programmers errors
Vulnerable
Not Vulnerable
Not Vulnerable
Administration errors
Not Vulnerable
Vulnerable
Vulnerable
Malware
Not Vulnerable
Not Vulnerable
Vulnerable
Intentional attacks
Vulnerable
Vulnerable
Vulnerable

Let us now calculate the intrinsic risk for the assets of our inventory, ie the risk regardless of the security controls that exist to reduce the impact or likelihood of risk. To avoid too lengthen this post, we will make the example of a single asset: system A.

To calculate the risk we will use the following matrix as a function of impact and likelihood. This is a fully customizable array given depending on the type of business that is being analyzed, since in certain sectors, it may make sense to give more weight to the impact that to the likelihood in order to consider possible 'black swans'.



Impact


5
4
3
2
1
Likelihood
5
5
5
4
3
2
4
5
4
4
3
2
3
4
4
3
3
2
2
3
3
3
2
1
1
2
2
2
1
1


Let us see the inherent risk of our 'System A':

System A – Inherit Risk
Impact
Likelihood
Inherent Risk
Natural disasters
Availability: 2
1
1
Users errors
Not Vulnerable
Programmers errors
Not Vulnerable
Administration errors
Confidentiality: 5
3
4
Integrity: 5
Availability: 2
Natural disasters
Confidentiality: 5
5
5
Integrity: 5
Availability: 2
Intended attacks
Confidentiality: 5
4
5
Integrity: 5
Availability: 2

Thus, we see that the risk inherent in our system is Very High (5). Let's see what controls have implemented the system to find out what is the actual risk:

  • Daily updated anti-virus signature update. (significantly reduces the likelihood of the threat of malware).
  • Hosted on internal network separate from the DMZ and the Internet via well-managed firewalls. (reduces the chance of malicious attacks).
  • The company performs an annual scan of vulnerabilities, and although in the latter showed vulnerabilities, the most critical are already corrected. (as is annual, we decided not to further lower the likelihood of malware or malicious attacks. If the process was at least quarterly correcting vulnerabilities in short time, could further reduce the likelihood of these threats).
  • The organization has a solid management process changes that reduce the likelihood of administration errors and their impact, since there is always a process for reverse the changes.

So, the effective risk of System A is:


System A – Effective Risk
Impact
Likelihood
Inherent Risk
Effective Risk
Natural Disasters
Availability: 2
1
1
1
Administration errors
Confidentiality: 4
2
4
3
Integrity: 4
Availability: 2
Malware
Confidentiality: 5
3
5
4
Integrity: 5
Availability: 2
Intended attacks
Confidentiality: 5
3
5
4


Risk Treatment Plan

Now that we have the risks map (inherent and effective) for all assets of our organization, we can elaborate the Risk Treatment Plan. With this objective, we determine actions to do with those risks that exceed the threshold of acceptable risk.

For each one of these risks, we have the next alternatives:
  • Avoid: Stop making the activity giving rise to the risk. For example, turn off the A system and disconnect it from the network.
  • Assume: Assume that you can not do anything to mitigate this risk. This strategy may be valid when the asset is about to be discharged or when the alternatives to reduce its level of risk are excessively expensive and could even exceed the potential cost of the risk occurring.
  • Transfer: Sometimes there are risks that can be transferred to third parties by hiring insurance or outsourcing of certain services.
  • Mitigate: In most cases this will be the optimal strategy. Is to establish or improve asset security controls to reduce risks to acceptable levels, either by reducing the likelihood of threats or reduce the impact these would have if they materialize.

In our example, we have two risks to treat:


System A
Impact
Likelihood
Inherent Risk
Effective Risk
Malware
Confidentiality: 5
3
5
4
Integrity: 5
Availability: 2
Intent Attacks
Confidentiality: 5
3
5
4

And the associated treatment plan could be the next one:

  • Increment frequency of vulnerability scans over the system scanning it in a monthly basis.
  • Solve the detected vulnerabilities on the system in 2 or less months.
  • Hardening the server disabling or unistalling all the unnecessary services.

Ideally, when setting the risk treatment plan will prioritize actions based on the risk to help mitigate and, where possible, be grouped in transversal projects to mitigate the risks of all types of assets rather to address them individually in each case.

After analyzing the impact these measures will have on the risks, we can establish the residual risk level, that is the risk that will remain effective once implemented the measures described:

System A – Residual Risk
Impact
Likelihood
Effective Risk
Residual Risk
Natural Disasters
Availability: 2
1
1
1
Administration Errors
Confidentiality: 4
2
3
3
Integrity: 4
Availability: 2
Malware
Confidentiality: 5
2
4
3
Integrity: 5
Availability: 2
Intended Attacks
Confidentiality: 5
2
4
3


I hope you enjoy and find useful this post. If you find any error or you wish propose any improvement, please, don't hesitate to propose it in a comment.

Twitter: @omarbenjumea
http://about.me/omarbenjumea