News: 1700040608

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ransomware more efficient than ever, and baddies are still after your logs

(2023/11/15)


Organizations are still failing to implement adequate logging measures, increasing the difficulty faced by defenders and incident responders to identify the cause of infosec attacks.

In 42 percent of incident response (IR) cases analyzed by Sophos, organizations didn't have the requisite telemetry logs needed to properly analyze an event.

The security company reckons that in 82 percent of these cases, cybercriminals were at fault after disabling or wiping telemetry and logging capabilities. The primary goals of attackers when wiping logs include evading detection, identification, and attribution, and maintaining access within a system.

[1]

In nearly a quarter of cases, organizations experiencing a security incident didn't have appropriate logging available for [2]incident responders to start with.

[3]

[4]

"This was due to a variety of factors, including insufficient retention, re-imaging, or lack of configuration," Sophos says in its latest [5]report . "In an investigation, not only would this mean the data would be unavailable for examination, but the defenders would have to spend time figuring out why it wasn't available."

When organizations lack adequate logging measures, it's often due to resource constraints, and limited IT and data capabilities generally, Peter Mackenzie, director incident response at Sophos, told The Register .

[6]

These entities are often small to medium-sized businesses and those that aren't in IT-focused sectors, he added. The absence of logs can also indicate possible efforts from the organization to cover up the attack.

"Time is critical when responding to an active threat; the time between spotting the initial access event and full threat mitigation should be as short as possible," John Shier, Sophos field CTO, says in the report.

"The farther along in the attack chain an attacker makes it, the bigger the headache for responders. Missing telemetry only adds time to remediations that most organizations can't afford. This is why complete and accurate logging is essential, but we're seeing that, all too frequently, organizations don't have the data they need."

[7]

Logging is widely seen in the security industry as a necessity for businesses that aim to build a strong security posture and an incident response plan that enables fast recovery from attacks.

In cases of security breaches, logs allow incident responders to see where and when it all started, how the attacker was able to get in, where their IP address points to, what user account executed a specific task, and more.

"Logs provide crucial insights into network and system activities, aiding in the detection, investigation, and understanding of security incidents," says Mackenzie in the report.

[8]Impatient LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land

[9]Ransomwared health insurer wasn't using antivirus software

[10]MGM Resorts attackers hit personal data jackpot, but house lost $100M

[11]BYOD should stand for bring your own disaster, according to Microsoft ransomware data

[12]Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts

"Logs provide crucial insights into network and system activities, aiding in the detection, investigation, and understanding of security incidents."

They are also a hugely valuable resource for defenders and those whose roles are outside of or adjacent to cybersecurity too. They can help investigate performance issues, determine which systems can access certain resources, and provide alerts for events such as storage disks approaching full capacity, for example.

Organizations that look for ways to prevent logs from being wiped should implement strict access controls and ensure regular backups are made and stored securely, Shier told The Reg .

Having SIEM systems up and running for real-time monitoring and implementing immutable logs are also good ideas.

Sophos said there's little excuse for organizations to not have a logging system in place, especially given that as of September this year, [13]Microsoft made logging free for customers even on its basic licenses.

Away from Microsoft, the US' Cybersecurity and Infrastructure Security Agency (CISA) took over the reins of Logging Made Easy, a free and open [14]SIEM solution for organizations that lack logging capabilities.

Originally pioneered by the UK's National Cyber Security Agency (NCSC) but retired by GCHQ's cyber arm in April, CISA now runs the project and makes it free for all via [15]GitHub .

"LME's self-install design uses free, publicly available software to drive performance and transparency," said CISA last month.

"But being free and open does not mean it's unprotected. LME is tested, secure, and reliable. It is also backed by a legacy of high performance, exemplified by its prior iteration's positive reception under NCSC oversight."

Ransomware is speedier than ever

Logs can be especially useful when investigating ransomware, being able to reveal what systems have and haven't been accessed by an account the logs can show is compromised.

Sophos' data backs up that of Secureworks in October which revealed [16]ransomware attacker dwell times are now measured in hours rather than days.

Ransomware attacks that take longer than five days are now considered 'slow attacks', Sophos' report says, with 62 percent of all incidents falling into this realm.

The other 38 percent are considered 'fast' and take place in fewer than five days. In some instances of supply chain attacks, Sophos' fire fighters saw ransomware deployments within six hours of each other.

According to Secureworks, the typical time between an attacker making the initial intrusion into an organization and deploying ransomware has [17]fallen to 24 hours . In ten percent of cases, ransomware was deployed within five hours.

In the Sohpos report, Shier says attackers are unlikely to change their tactics until they stop working entirely. This should be welcome news for defenders because despite the decrease in time to compromise, without attacker innovation it means defensive strategies don't need to change drastically.

"The key is increasing friction whenever possible – if you make the attackers' job harder, then you can add valuable time to respond, stretching out each stage of an attack," he says.

"For example, in the case of a ransomware attack, if you have more friction, then you can delay the time until exfiltration; exfiltration often occurs just before detection and is often the costliest part of the attack.

"We saw this happen in two incidents of Cuba ransomware. One company (Company A) had continuous monitoring in place with MDR, so we were able to spot the malicious activity and halt the attack within hours to prevent any data from being stolen.

"Another company (Company B) didn't have this friction; they didn't spot the attack until a few weeks after initial access and after Cuba had already successfully exfiltrated 75GB of sensitive data. They then called in our IR team, and a month later, they were still trying to get back to business as usual." ®

Get our [18]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZVSk1daGJxtK7n5JmbNu2gAAAJM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2022/10/03/ibm_incident_reponder_survey/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVSk1daGJxtK7n5JmbNu2gAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVSk1daGJxtK7n5JmbNu2gAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://news.sophos.com/en-us/2023/11/14/active-adversary-for-security-practitioners/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZVSk1daGJxtK7n5JmbNu2gAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZVSk1daGJxtK7n5JmbNu2gAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/11/10/lockbit_leaks_boeing_files/

[9] https://www.theregister.com/2023/10/11/philhealth_ransomware_no_antivirus/

[10] https://www.theregister.com/2023/10/06/mgm_resorts_cyberattack_cost/

[11] https://www.theregister.com/2023/10/05/microsoft_byod_ransomware/

[12] https://www.theregister.com/2023/10/05/lorenz_ransomware_group_leaks_details/

[13] https://www.theregister.com/2023/07/20/under_cisa_spressures_collaboration_microsoft/

[14] https://www.theregister.com/2018/10/08/siem_uba_ueba_explained/

[15] https://github.com/cisagov/LME/

[16] https://www.theregister.com/2023/10/10/ransomware_attacks_register_record_speeds/

[17] https://www.theregister.com/2023/10/10/ransomware_attacks_register_record_speeds/

[18] https://whitepapers.theregister.com/



Most of what I really need to know about how to live, and what to do,
and how to be, I learned in kindergarten. Wisdom was not at the top of the
graduate school mountain but there in the sandbox at nursery school.
These are the things I learned: Share everything. Play fair. Don't
hit people. Put things back where you found them. Clean up your own mess.
Don't take things that aren't yours. Say you're sorry when you hurt someone.
Wash your hands before you eat. Flush. Warm cookies and cold milk are good
for you. Live a balanced life. Learn some and think some and draw and paint
and sing and dance and play and work some every day.
Take a nap every afternoon. When you go out into the world, watch for
traffic, hold hands, and stick together. Be aware of wonder. Remember the
little seed in the plastic cup. The roots go down and the plant goes up and
nobody really knows how or why, but we are all like that. Goldfish and
hamsters and white mice and even the little seed in the plastic cup -- they all
die. So do we.
And then remember the book about Dick and Jane and the first word you
learned, the biggest word of all: LOOK. Everything you need to know is in
there somewhere. The Golden Rule and love and basic sanitation. Ecology and
politics and sane living.
Think of what a better world it would be if we all -- the whole world
-- had cookies and milk about 3 o'clock every afternoon and then lay down with
our blankets for a nap. Or if we had a basic policy in our nation and other
nations to always put things back where we found them and cleaned up our own
messes. And it is still true, no matter how old you are, when you go out into
the world it is best to hold hands and stick together.
-- Robert Fulghum, "All I ever really needed to know I learned
in kindergarten"