4.1
Hardening targets
- no system is secure with default configurations
mobile device manager (MDM)
- manages mobile devices and harden
- centralize management
- set policies on apps, data, camera, etc.
Securing Wireless and Mobile
Site surverys
- Determine existing wireless landscape
- Identify access poitns
- work around existing frequencies
- heat maps identify wireless signal strengths
Wireless survey tools
- show signal coverage
- interference
Bring your own device (BYOD)
- Employee owns the device
- needs to meet company’s requirements
- Difficult to secure
Securing Wireless Networks
WPA2 PSK problem
- brute-force problem
- Listen to the four-way handshake
- derive the PSK hash without the handshake
- Capture the hash
- Attacker can brute force the Pre-Shared Key (PSK)
WPA3 and GCMP
- Wifi Protected Access 3 (WPA3)
- GCMP block cipher mode is stronger than WPA2
- Changes the PSK authentication process
- mutual authentication
- creates a shared session key
- Simultaneous Authentication of Equals (SAE)
- everyone uses a different session key, even with the same PSK
Pre-Shared Key (PSK)
- The shared Wi-Fi password
- everyone uses the same 256-bit kley
In corporate environments (WPA-3 Enterprise)
- we use 802.1X allows everyone to have separate credentials
AAA framework
- Identification is usually your username
- AAA triad
Remote Authentication Dial-In User Service (RADIUS)
- One of the more common AAA protocols
- centralizes authentication for users
- RADIUS services are available for almost any operating system.
Application Security
Secure coding concepts
- input validation
- normalization, fix any data with improper input
- test with fuzzing
- secure cookies
- can have secure attribute set which only sends it over HTTPs
- Static Application Security Testing (SAST)
- checks for buffer overflows, etc.
- can’t find everything (e.g insecure cryptography)
- Code signing
- integrity and who wrote the code
- uses a CA
- Sandboxing
- applications cannot access unrelated resources
4.2
Asset Management
Assginment
- Associate a person with an asset
- useful for tracking
- Classification
- Hardware (capital expenditure = can depreciate)
- Software (operating expenditure)
Physical destruction that destroys drives
- 3rd parties are often used and provide a certificate of destruction
data retention
- backup your data
4.3
Vulnerability scanning
Usually minimally invasive (e.g. port scan)
- should be tested from the outside and inside
Fuzzing
- looking for the application to act out of the ordinary given a random input
- fuzzing engines and framework are very time and processor resource heavvy
Package monitoring
- Some applications are distributed in a package
- Confirm legitimacy
Threat intelligence
Research the threats and threacts actors
Open-source intelligence (OSINT)
- publicly available sources
- government data
3rd party intellignece
- someone else compiles threat info
- threat intelligence services (analytics, correlation)
Cyber Threat Alliance (CTA)
- information sharing organization
- members upload specifically formatted threat intelligence
- CTA scores each submission and validates
- other members can extract validated data
Dark web intelligence
- hacking groups and services
Penetration Testing
Simulate an attack Try to exploit the vulnerabilities
Rules of Engagement
- formal list of rules that defines purpose and scope
- type of testing and schedule (what hours, internal/external)
Exploiting vulnerabilities
- try to break into the system
- can cause Denial of Service
Process
- Initial exploitation
- Lateral movement
- Persistence
- The pivot
- Gain access to systems that would normally not be accessible, use a system as a proxy
Analyzing Vulnerabilties
False positives
- vulnerability is identified but doesn’t exist
Common Vulnerability Scoring System (CVSS)
- enhanced feed sharing and automation
Common Vulnerabilities and Exposures (CVE)
- vulns can be cross-referenced online
Exposure Factors
- percentages that signifies loss of value or business activity if the vulnerability is exploited.
Environmental variables
- what type of env is associated with this vulnerability?
Risk tolerance
- amount of risk acceptable to an organization
- it’s impractical to remove all risk
Vulnerability Remediation
Patching
- most common mitigation
- scheduled vulnerability patch notices
- unscheduled patches
- e.g. zero day
Insurance
- Cybersecurity Insurance coverage
- lost revenue
- data recovery costs
- money lost to phishing
- privcacy lawsuit costs
Compensating controls (e.g. disable the problematic service, revoke access to the application)
Security Monitoring
24/7 Monitory all entry points
Log aggregation
- SIEM (Security Information and Event Manager)
- consolidate many logs to a central database (servers, firewalls)
Security Tools
Security Content Automation Protocol (SCAP)
- many different tools can identify the same vulnerability
- allows tool to identify and acts on the same criteria via SCAP
- can automate the detection and removal of vulnerabilities
Benchmarks
- Apply security best-practices to everything
Agents can usually provide more details
- always monitoring
agentless runs without a formal install
- performs the check then dissapears
Data Loss Prevention (DLP)
- stop the data before the attackers get it
- more than one single appliance
Simple Network Management Protocol (SNMP)
- A protocol used to monitor and manage network devices (routers, switches, servers, printers, etc.).
- The device exposes management data through a structured “database” called a Management Information Base (MIB)
- A MIB is basically a catalog of variables (metrics and settings) that SNMP can read (and sometimes write).
Netflow
- Gather traffic statistics from all traffic flows
- Has a probe and collector that watches network communication and the summary records
Firewalls
Appliance that sits in-line network and filters can run other services
- encrypt traffic
- VPN
most firewalls are layer 3 devices (routers)
Web Filtering
Content filtering
- control traffic based on data within the content (e.g. URL filtering, …)
can be agent based can also proxy based that sits between the users and the external network
OS security
Active Directory
- A database of everything on the network
- Manages authentication
- Centralized Access Control
Group Policy
- Manage the computers or users with group policies
Security-Enhanced Linux (SELinux)
- Security patches for the linux kernel
- Adds Mandatory Access Control (MAC)
- Limits application access
Email Security
It’s easy to spoof an email
Mail Gateway
- evaluates the source of inbound email messages
- blocks it at the gateway before it reaches the user
- usually in screened subnet (network segment that sits between an external firewall and internal firewall so nothing reaches the LAN)
Sender Policy Framework (SPF)
- which servers authorized send emails for a domain
- added to DNS TXT records
Domain Keys Identified Mail (DKIM)
- A mail server digitally signs all outgoing mail
- the public key is in the DKIM DNS TXT record
- the signature is validated by the receiving mail servers
Domain-Based Message Authentication, Reporting, and Conformance (DMARC)
- extension of SPF and DKIM
- The domain owner decides what receiving email servers should do with emails not validating using SPF and DKIM
- compliance reports are sent to the email admin
Monitoring Data
File Integrity Monitoring (FIM)
- Some filed change some files should NEVER change
- we should monitor if important OS files change
- Windows - SFC (System File Checker)
- Linux - Tripwire
Endpoint Security
Endpoint is the user’s access
Edge vs access control
- Edge is where the inside of the netowork meets the outside
- access control limit access to data, inside or out
posture assessment
- via persistent agents
- permanently installed on system
- dissolvable agents
- no installation is required
- agentless NAC
- integrated with AD
- checks made during login and logoff
If failed posture assessment, quarantine the network
Endpoint detection and response (EDR)
- extend signature functionality of antivirus to behavioral analysis, machine learning…
- response can be automated
Extended Detection and Response (XDR)
- evolution of EDR
- more than a single agent that interprets data from multiple sources/systems
- includes user behavior analytics
Identity and Access Management (IAM)
- give right permissions to the right people and the right time
- access control
- authentication and authorization
- identity governance
- starts with provisioning user accounts and ends with de-provisioning
- identify proofing
- verify the user is who they are
Single sign-on (SSO)
- provide credentials one time and gain access to all the resources
- usually limited by time
Lightweight Directory Access Protocol (LDAP)
- Protocol for reading and writing over an IP network
- used to query and update an X.500 directory (used in Windows AD, Apple OpenDirectory)
X.500 Directory Information Tree
- hierarchical structure
- container objects
Security Assertion Markup Language (SAML)
- open standard for authentication and authorization
- authenticate through a 3rd party to gain access
- no designed for mobile apps
Oauth
- Determines what resources a user will be able to access = authorization
- not an authentication protocol
Federation
- provide network access to others
- authenticate and authorize between the two organizations
- e.g. login with your facebook credentials
Access Controls
policy enforcement of authorization
Least privilege
- rights and permissions should be set to the bare minimum
Mandatory Access Control (MAC)
- the operating system limits the operation on an object
- every object gets a label
Discretionary Access Control (DAC)
- as the owner, you control who has access
- used in most operating systems
- each individual users must create the appropriate access
Role-based access control (RBAC)
- administrators provide access based on the role of the user
Rule-based access control
- access is determine through system-enforced rules
Attribute-based access control (ABAC)
- access may be based on many different criteria
- combine and evaluate multiple parameters
- resource information, IP address, time of day, …
Password Security
Make your password strong
- password age and expiration
- password complexity (length)
- password managers
Just-in-time permissions
- grand admin access for a limited time
- principle of least privilege
- accounts are temporary
4.8
Incident Response
NIST SP800-61
- incident response lifecycle
Digital Forensics
Legal hold
- technique to preserve relevant information
- custodians are instructed to preserve data
- separate repository for the electronically stored information (ESI)
Chain of custody
- hashes and digital sigs to maintain integrity of data
- Acquisition
- Reporting (document how data was acquired)
- Preservation (how the data is going to be stored)
- E-discovery (work together with digital forensics to provide it for court data)