Kategorie: Uncategorized

  • Schatten-IT als Bedarfsindikator für das IT-Lösungsportfolio

    Informationstechnologie, die ein Nutzer sich selbst beschafft und ohne Wissen der IT-Verantwortlichen im Kontext seiner beruflichen IT-Infrastruktur nutzt, wird umgangssprachlich gerne als Schatten-IT bezeichnet. Die Bandbreite dieser Schatten-IT reicht vom privaten Email-Account, der genutzt wird, um vertrauliche Daten zur wochenendlichen Bearbeitung auf den heimischen Rechner zu transferieren, über das Tablet mit dem sich die Sitzungsmitschriften doch einfacher erstellen lassen und die dann über das private Cloud-Konto wieder auf den Organisationsrechner wandern, bis hin zum privaten online Chat- und Collaborationaccount mit dem das berufliche Zusammenwirken und der Informationsaustausch über das private Smartphone organisiert werden. Gemeinsam ist diesen Lösungen, dass es sich bei Ihnen fast immer um Cloud-Lösungen handelt, die das gemeinsame Agieren von Nutzern über öffentlich zugängliche Internet-Server realisieren. Diese Schatten-IT wird im Allgemeinen bereits als gefährlich angesehen, denn durch Ihre Nutzung entstehen Abhängigkeiten von unkontrolliert aufgesetzten IT-Lösungen und deren Protagonisten, es werden bestehende Sicherheitsmechanismen außer Kraft gesetzt und es besteht das erhöhte Risiko des unautorisierten Datenabflusses. Besondere Gefahren entstehen, wenn Schatten-IT sich im Umfeld besonders schützenswerter Informationen etabliert hat, denn in diesen hat der Abfluss schützenswerter Informationen besonders schwere Auswirkungen.  Des Weiteren ist diese Schatten-IT auch zugleich das bevorzugte Ziel des vom State-Actor betriebenen Hackings und ist damit besonderen Belastungen ausgesetzt.

    Trotzdem ist es durchaus bekannt, dass sich gerade im Umfeld der Collaboration und Communication eine Kommunikationskultur etabliert hat, in der sich die spontane Gruppenbildung und der Austausch von Lageinformationen – bis hin zum abfotografierten Bildschirm – als organisationsübergreifende Führungsmittel etabliert haben. Dabei agieren die Protagonisten jedoch nicht im Umfeld fehlender Richtlinien oder fehlender Aufklärung vielmehr ist es eine persönliche Abwägung des operativen Vorteils gegen den Regelverstoß, die den Nutzer dazu bringen, bewusst die Richtlinien der Organisation zu verletzen.

    Das Kernproblem ist somit nicht der Regelverstoß des Nutzers, sondern die mangelnde Akzeptanz einer bestehenden oder das Fehlen einer von Nutzer als (Überlebens)notwendig eingeschätzten Lösung. Der Nutzer weist somit die IT-Organisation mit der Nutzung der Schatten-IT also auf eine Fähigkeitslücke in der Gestaltung des IT-Lösungsportfolios hin und stellt somit einen deutlichen Handlungsindikator zum Start eines Digitalisierungsprojektes dar.

    Zur Deckung der Fähigkeitslücke im IT-Portfolio ist es also notwendig dem Anwender Lösungen zur Verfügung zu stellen, die diesen DIgitalisierungsbedarf erfüllen und die die Sicherheits- und Architekturanforderungen der Organisation zumindest teilweise erfüllen.  Eine Nichterfüllung des Digitalisierungsbedarfes ist keine Option, denn dies würde den Nutzer weiter in die Schatten-IT treiben und weitere, größere Sicherheitsrisiken entstehen lassen.  Somit steht die IT-Organisation vor der Herausforderung Lösungen auszuwählen und zu implementieren, die aus Sicht der eigenen Organisation unzureichende Systemeigenschaften besitzen. Um diese Herausforderung zu bewältigen, bieten sich die folgenden Handlungsstrategien an.

    Grundsätzliche werden Schatten-IT Lösungen im seltensten Fall auf der privaten IT-Infrastruktur eines Nutzers betrieben, sondern nutzen kommerzielle Dienste. Somit können die Ersatzlösungen in der Regel als Cloudlösung implementiert werden. Dazu können drei Varianten unterschieden werden: die Implementierung in einer abgeschlossenen Umgebung der Organisation – einer „On Premise Cloud“, die Implementierung in einer abgeschlossenen Mandanten-Umgebung eines kommerziellen Cloudanbieters, einer „Private Cloud“ oder es wird die Implementierung eines ausgewählten Anbieters genutzt, eine „Public Cloud“. Die Ablösung einer Schatten-IT erfordert also in jedem Fall die Implementierung einer Multi-Cloud- oder Hybrid-Cloud-Strategie. In der Folge erfordert dies ebenfalls die Implementierung einer Cloud-Security-Strategie um zumindest die wesentlichen Sicherheitsrisiken einer Cloud-Nutzung zu mitigieren.

    Als wesentliche exemplarische Risiken in der Betrachtung einer Cloud-Security Strategie sind folgende Risiken zu nennen:

    • Der Informationsabfluss an den Cloudprovider
    • Der Informationsabfluss an andere Cloudnutzer
    • Informationsverlust auf der Übertragungsstrecke
    • Die Penetration der eigenen IT über die Cloudlösung
    • Die Manipulation von Informationen in der Cloud
    • Der ungewünschte Ausfall der Cloudlösung

    Werden diese Risiken im Kontext der verschiedenen Nutzungsszenarien „On Premise Cloud“, „Private Cloud“ und „Public Cloud“ betrachtet und hinsichtlich der bekannten exemplarischen Sicherheitstechnologien zur Mitigation der Risiken analysiert ergibt sich die folgende Handlungsmatrix. Diese kann als Vorlage für eine individuell zu gestaltende Cloud-Security-Architektur dienen und sowohl in den betrachtenden Risiken, als auch in der Auswahl der umzusetzenden Maßnahmen erweitert und angepasst werden.

     On Premise CloudPrivate CloudPublic Cloud
    Informationsabfluss an Cloudprovidern/aCiR, SLASLA
    Informationsabfluss an CloudnutzerMFAMFA, CMONMFA, SLA
    Informationsverlust auf der ÜbertragungsstreckeVPN, E2EE2E, VPN, DLPE2E, DLP
    Penetration aus der Cloudn/aMonitoring, IPSMonitoring, IPS, SLA
    Informationsmanipulationn/aVPNVPN
    VerfügbarkeitDDoS SchutzSLA, DDoSSLA

    n/a: Risiko nicht relevant
    CiR: Crypto in Rest – Verschlüsselung von Spreicherdaten
    CMON: Cloud Monitoring – Überwachung von Cloudanwendungen
    DDoS Schutz: Distributed Denial of Service Schutz
    DLP: Data Loss Prevention
    IPS: Intrusion Protection Systems
    SLA: Service Level Agreement Verhandlung
    VPN: Virtual Private Networks
    E2E: Ende zu Ende Verschlüsselung
    MFA: Multi Faktor Authentifizierung
    Monitoring: Überwachung der lokalen Systeme auf atypisches Verhalten

    Im Allgemeinen ist die Implementierung einer Lösung in der „On Premise Cloud“ ist zu bevorzugen, da die Cloudverantwortung in der Hoheit der eigenen IT-Organisation liegt und die restlichen Risiken gut mitigieren oder nicht relevant sind. Im Gegensatz hierzu sind bei der Public Cloud viele Risiken schlecht mitigierbar und müssen über vertragliche Vereinbarungen oder Zertifizierungsanforderungen die hier übergreifend unter dem Stichpunkt SLA zusammengefasst werden, geregelt werden. Die „Private Cloud“ als Zwischenlösung stellt hier eine flexiblere Umgebung dar um individuelle Sicherheitskonfigurationen in Kooperation mit einem Cloudanbieter zu realisieren.

    Zusammenfassung

    Grundsätzlich ist anzustreben Schatten-IT im Rahmen von Digitalisierungsprojekten durch kontrollierte Lösungen zu ersetzen, auch wenn diese den Sicherheits- und Architekturvorgaben der eigenen Organisation nur bedingt genügen. Die dadurch entstehende hybride Cloudnutzung kann und muss durch Sicherheitstechnologie im Rahmen einer Sicherheitsarchitektur abgesichert werden. In dieser kommen sowohl technologische als auch organisatorische Maßnahmen zum Tragen.

  • Fitbit, OSIN + Cyber Security

    Many of you have noticed the press about defense locations being detected by analyzing the sport patterns military people release on fitness portals like Fitbit, Strava, Polar, and others. Searching for these patterns in areas where there is no sport activity o a regular base like Mali, Iraq, Afghanistan, Syria, Lybia and others shows not only where military bases are located but also details about daily routines ans behaviors.

    This shows how easy it is in a todays world to collect information from public sources, an intelligence tactic which is known in the field as Open Source Intelligence or OSINT. And OSINT plays also a role in the Cybersecurity Perimeter.

    OSINT is used by attackers to collect informations about potential victims of social engineering attacks. Because the more you know about somebody, the easier it is to build the trust to force these victims into actions or the release of confidential informations.

    OSINT is used by attackers to collect information about targeted organisations and their systems. These informations coming from different sources: 404 error web pages which reveal informations about OS, software & release levels, in depth analysis of email headers, public whois information, document informations in published pdfs and more. These informations help significantly to identify the most promising attack vectors and to reduce work and frustration for the attacker.

    OSINT is used by attackers to collect informations about vulnerabilities of systems and successfull realised attacks. These informations will help to build an individual attack, mostly a combination of specialised social engineering and individual malware.

    Check your enterprise:

    A very simple check to see how exposed your organisation is to OSINT: Enter the following text into a google search box:

    „Company Confidential“ filetype:pdf site:yourOrganisation.com

    YourOrganisation.com should be replaced by the domainname of your organization. This query uses google to search all pdfs (filetype:pdf) which contains a typical confidentiality string and limits the results to those of your organizations domain. You will be astonished, I bet.

    What can you do agains OSINT?

    In fact, there nothing what can be done to prevent attackers from using OSINT to gather informations. The counter OSINT strategies are:

    • Limit the amount of unnecessary technical information published into the internet.

    All information which will be shown or distributed should be as frugal as possible. This does not refer to content, but to error messages, status informations, document informations, source code comments in webpages and more. This is not an technical issue, thats simply a configuration and awareness task. In addition an onion- or segmentation-based approach to data security decreases the risk of accidentially exposed information.

    • Reduce the effects malware and social engineering attacks are creating in your systems infrastructure.

    Most malware is calling back to Command & Control server, loading additional software or getting information about what to do. Intercepting this chain reduces the damage malware can create and identifies compromised systems.

    • Setup an infrastructure which allows you to detect atypical information flows and specialized attacks.

    Seeing whats happening in your network, identifying anormal user behavior is a key to identify penetrated systems and malicious users to start appropriate countermeasures.

    • Make the IT-Infrastructure flexible to isolate compromised subsystems and to respond to attacks individually.

    Compromised systems need to be isolated as soon as possible to prevent further penetration of the IT-Infrastructure. An automated environment increases the reaction speed and ensures the minimation of the attack surface,

    These four countermeasures are working independently but – as in every systems engineering approach – integration enables savings. These savings include implementation cost (by reduced planning), operational cost (by reduced training and effort) as well as total cost of ownership (by optimized license models). They also increase security by minimized friction between subsystems and faster and error-reduced communication between system components.

    Please feel free to comment!

    P.S. This Video shows an example, how simple OSINT can be used to prepare an individual ransomware attack…

  • Cyber Immunology

    Designing a Cyber Security system is a complex task. Designing systems is not easy and designing security systems is even more difficult.

    Security design is thought typically around 4 axes: Security against technical failure, Security against human failure, Security against natural hazards and Security against intended misbehavior. While the first three elements are typical defined as a Safety approach, defining security against intended misbehavior is a little more difficult. The reason for that is, that safety mostly deals with systems and subsystems refusing operation by different reasons and the whole system needs to be passively move into a fail-safe status. Security against intended misbehavior is the opposite. It includes an active component which manipulates the system to create a state of maximum damage or intended misbehavior. Security against these principles cannot be achieved by relying on passive fallback mechanisms.

    So the question is: How does a generic system look like, which protect systems against the unknown treats of intended misbehavior.

    The General Protection System

    As a pragmatic approach for defining a role model for the general protection system a technical model can be build upon the biological model of the human immunology model. This model incorporates the protection against unknown threats – in general viruses, bacterias, and parasites, it works in a high availability mode, it is self-learning and it is built with more than 400 millions of years of evolutionary design improvement. The challenge is the transformation of a biological model into a technical approach.

    The biological model can be structured into 3 natural and 1 artificial area: A unspecific detection and prevention capability, an individual defense capability, a self-learning memory capability and an artificial stimulation and knowledge exchange capability.

    The unspecific detection and prevention capability is generally based on Macrophages, detecting alien intruders with an sophisticated friend-foe detection, killing most of them and triggering the foe-specific generation of killer cells, T-Helper cells and B-Cells and cytotoxic T-Cells. This part of the immune system can be compared with the hardening of an IT-System, following the different standards and the addition of an Intrusion Detection System (IDS) and a Security Incident and Event Monitoring System (SIEMS).

    The cytotoxic T-Cell as an exemplary defense capability which reacts against the attack can be compared with the Computer Emergency Response Team (CERT), highly specialist IT-Security and Forensic specialists, asked for fighting against a cyber attack.

    The generation of attack-specific cytotoxic T-Cells is memorized by the T-Memory cells, providing a a self-learning memory capability of the immune system. This capability can be compared with a lessons learned process, which updates the technical prevention and detection capabilities of the IT-Security system by implementing a Security Change Management Process.

    This natural immune system is stimulated by human intervention to increase the effectiveness by active and passive vaccination – stimulating the immune system with weakened threats to trigger an immune reaction (active vaccination) or supporting the memory of the individuals immune system by providing artificial or foreign Antibodies (passive vaccination). These artificial stimulation and knowledge exchange capability are realized in the technical world by stimulation and testing the IT-Security infrastructure by intrusion testing (active vaccination) or updating the prevention and detection capabilities of the system based on the information of external security bulletins.

    In summary this approach generates a Cyber Immunology Blueprint based on 7 Key Capabilities.

    The Cyber Immunology Blueprint

    These seven key capabilities can be seen of the seven work-packages of a Cyber Immunology Implementation.

    The hardening & prevention work-package is typical the initial start. Here the critical assets, the security targets, the access control rules and the initial system protection mechanisms and rules are defined, which act as the first line of defense. But as there is not total protection system in real life, the whole system needs to be monitored by an independent supervising authority which detects system malbehavior and identifies possible attack. The implementation of this authority is managed in the Intrusion Detection work-package. This authority also acts as a sensor to the Security Incident and Event Monitoring System which creates the Cyber Security Situational Awareness Picture. To do so, it links the security status of a technical system with the key business processes and the security target definition of an organization. In case of a severe event this system triggers the Security Incident Response, an emergency activity which analyses the incident in depth and defines countermeasures and updates for the Hardening and Prevention work-package. The operational implementation of these countermeasures is managed with a Security Change Management system which should follow the ITIL principles and is mostly based on a dynamic hardware & software inventory. Security Information Exchange and Penetration testing are two work-packages which actively stimulate the whole Cyber Security Blueprint, to prevent the system from becoming static and outdated. The Penetration Testing work-package fulfills the active part of the stimulation while Security and Threat Information Exchange ensures the stimulation by external knowledge.

    The depth of implementation for these work-packages can be different, according to the individual needs of an organization. Mostly an implementation of this blueprint follows a spiral approach, implementing simple methods first but in all work-packages, followed by more sophisticated subsystems while the whole Cyber Security System matures and evolves.

    Summary

    Following the experience of nature, a Cyber Immunology System can be modeled by implementing the seven key work-packages of the Cyber Security Blueprint. This system ensures a dynamic, active defence as well as an improved first line of protection for the unknown threat. An individual spiral implementation strategy reduces the amount of resources needed for the setup.

  • remotestarterkit.com

    You can see a set of tools. Or you can see the core processes of online collaboration. Or you can see the best practices of user experience & GUI design

    http://www.remotestarterkit.com

  • Maritime Cyber Security

    Cyber attack hit maritime infrastructures: https://lnkd.in/d6EHGhq
    Not that maritime infrastructures are the center of the attack, but the article shows how the domino principle hits the whole business process chain.

    Screenshot von lnkd.in