Cyberattacks Against Microsoft Active Directory – Kapil Raina, CrowdStrike
Kapil Raina, vice president of zero trust marketing and identity protection evangelist for CrowdStrike, explains how cyberattacks against Microsoft Active Directory (AD) are evolving.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We get the whole Rena who is vice president of zero trust marketing and identity protection evangelists for crowdstrike. That's a mouthful right there. And we're talking about Microsoft active directory and surprisingly a lot of attacks are still aimed at this particular platform, and we're going to jump into there.
Oh, welcome to shop. Thanks. I appreciate you having there.
What's your sense of exactly what's going on here? I know you guys have done some research in this space. Is there's still a lot of Microsoft active directory out there or people targeting that and what should we be worried about?
Yes, so why we're talking about is Microsoft active directory still used by almost 99. % of organizations out there Yeah, especially Enterprise organizations, right and even if they're trying to move away from let's say an on-premise version of active directory to the cloud like for example is already that's a process right you can imagine how many applications users systems you have and all the identities and how this year. They are to move that to the cloud and having it run there and maybe protect it there.
That's a huge project itself. So that's the reason we're still talking about it in terms of you know, why is everyone still using it the other is you know, the world has changed right? We have distributed applications.
You have multi-cloud environments you have now even privileged users like administrators working from home, which we never there before. So this complex it infrastructure environment is created sort of another level of complexity and therefore increasing tax service for adversaries. Then we take Microsoft they need for granted and we don't secure it enough.
I know a lot of people manage their access through it, but it seems like maybe we're not thinking enough about the securing the actual platform. I think a lot of it professionals have done a Admiral's job. You very good job to try and defend active directory.
Right? But there's a couple of challenges one is as you alluded to it's it's been around for a long time. Microsoft has created this as a infrastructure.
That's now embedded almost everywhere it the challenge is you sort of You know. Do you rely on Microsoft that created the infrastructure to protect it and that's been a challenge? Right and we've seen a number of attacks where you know, there's vulnerabilities in the infrastructure of accurate itself.
So not even the attack of a credential. It's actually the attack of active directive domain controllers. So that's definitely one challenge is you know, you you have to think about protecting after directory but maybe not necessarily just from the identity provider itself.
Maybe you should think about doing other things and you know organizations to be fair have been trying to do that. But again, the things we talked about which is the change of how it applications or distributed and used but the other is the modern attacks adversaries have become much more sophisticated, right? So we have all this research.
We pull together the last couple years how you've changed and so modern tax today almost, you know, 80% plus of all breaches involve some kind of identity related technique or threat. It's a lot and because you have sort of connected systems you have to say and Point you have a mobile device. You have a workload your container.
All an attacker has to do is enter any one of those whether it's through the endpoint through like a malware attack or through an identity compromise and then migrate over to maybe where they really want to go. So the attack surface is become much larger. And then finally when we talk about more specifically about digital transformation, we're talking about lots and lots of applications and containers and federal workloads running.
And if you're associating identity with them suddenly you went from let's say a thousand employees and maybe a thousand, you know, 80 accounts plus maybe a few hundred for applications to many many thousand for every organizations. Now, it's not just you know, here is my active director. Here's some credentials.
What are those credentials associated with are they associated with applications or services are they users privilege users? So just even knowing that has become much more complex. So I think to be fair organizations are trying to but you know, it has changed the it provider or the identity provider like Microsoft has had challenges and trying to protect that infrastructure and then finally adversaries.
You got a lot smarter and quicker about attacking identity. What exactly is the challenges with defending identity because we've had you know For Better or Worse username and passwords in various things like that for a while and we're now talking about zero trust approaches to Identity and everybody nods their head, but it's not clear to me that everybody understands exactly what that means. What am I supposed to do?
Because I don't think I can roll out of bed and go buy me some zero trust. So what's involved? Sure, absolutely.
So think of maybe protecting identity in a couple of a couple of approaches one is infrastructure right active directory is a piece of software. It's infrastructure has components called domain controllers. You have to protect that because if an adversary takes over that infrastructure, they own all of the credentials.
So, you know infrastructure attacks include things like, you know, looking at, you know week protocols Legacy protocols that you've enabled looking at, you know access to those systems. Can I for example do a remote desktop protocol as a user to a domain controller which again opens me up from an attack surface point of view as a privilege user? Um, you know, so you have sort of infrastructure protection then the next level is hygiene.
Right do your users are they using compromise passwords? Because then at that point, you know, they're on the dark web and and then adversary can just sort of walk in the front door that way so you're looking at hygiene steps, whether it's looking compromise password things like, you know, for example, we track things like are you know, how many you when a customer comes on to the Falcon platform? You can look at say, you know, how many of my passwords in the Enterprise are stale accounts meaning accounts have been provision that have some privileges but have been used.
Let's say 30 60 90 days, right and that's a high risk because if it's just sitting there and then was monitoring it it can be taken over. So looking at things like that hygiene and then finally you're looking at things like behavioral analytics right real time. So it's not enough just to look in and look theoretically and say, you know, I patch my vulnerabilities that I do all the good password hygiene what's actually being used right now?
We know there's a firm number of attacks that take over legitimate credentials. I have a legitimate credential here crowdstrike, but did an obviously take over my credential and therefore the Privileges that has access to how do I know that right? That's a lot of behavior like, how is how is the credential being used?
Is it deviate from you know anomaly, how's it compared to other people in my my peer group? So a lot of the artificial intelligence Technologies in machine learning is used for that as well. So if you take a look at these three areas, that's how really holistically you can address a lot of these issues.
And that's also what makes it a challenge if you're trying to address them piecemeal or relying on the identity provider along. how long a journey is this because what you just described is the classic people processing platforms kind of conversation that seems to me something that's going to be measured in years or can we accelerate this and Well, if you if you ask me as with my marketing hack I can say can we measured in in 60 minutes or less? Because if you approach it from a platform perspective, right you're able to look at what's happening, you're endpoint.
Let's say your identity layer your Cloud layer. You can create a better attack story. So, you know, if adversaries entering anywhere in your organization if they're trying to compromise in the early steps with let's see doing a lot of movement, which is very common, especially when you talk about identity attacks.
So if you have a platform approach, it's much much easier, right? So in the case of crowdstrike, for example, you deploy a simple sensor everywhere and that information comes into the system. It makes a decision.
You can apply a policy and you can stop attacking detect and stop attacking that way so it's very very straightforward. And so, you know, we were already seeing some some benefits from it, but you know, it is challenge for for a lot of organizations. So for example You know some of the data when you look at it.
You know, we look at things like we mentioned stale passwords. For example, we compromised passwords up privilege users privileged users that have compromise password, which is really really bad, right? But what's interesting for example, and this is sort of internal research that we've been doing and we'll be you know more formally presenting that to to the industry.
But you have something like, you know, if you look at different Industries and different types of problems, the banking for example has interesting enough some of the biggest challenges including things like high risk passwords right passwords that are more likely to be compromised because of the privilege associated with them or we see for example Banking and retail for example have the highest number of compromise passwords passwords that are in their system that are known already on the dark web to be compromised, right? The other thing we've been tracking is still password again, if you look at what happened, let's say a couple years ago some of the solar winds you had a application that most organizations had that had a privileged identity Associated right a privileged account. But that privileged account was given a lot of scope.
Right, it could take over a lot. But that's essentially, you know an account that you don't monitor all the time. The human doesn't right.
And so, you know, you want to be careful about that careful about still passwords almost a quarter of passwords and we didn't tell research we're considered stale accounts meaning accounts that increase the attack surface. We don't know if they're compromise. We don't think we'll be but there's a hard chance of that happening because they're not being monitored for Behavioral or something else.
And so it's much easier when we approach it from a platform perspective to both, you know, kind of deploy these Solutions detect and stop them but more importantly looking at an adversary whether they're intending attacking from the cloud moving like maybe into the Enterprise on-prem or endpoint vice versa. I think that's really important and that's really different day than it was before which is looking at identity holistically in the cloud at the end point for the user for the application which wasn't really concerning like say five years ago. How do we Bridge The Divide between the folks who run a platform like Microsoft ad and the cybersecurity folks because a lot of the it folks who are managing things or in their day-to-day.
They're just trying to keep things up and running as their primary Mission and they don't really have security at the portfolio brain. So, how do we bring these guys together? Well, it's interesting if we go back a few years ago.
You're up to your right. So the Responsibility for active directory and security was not part of the ciso's function. Today the majority of cisos now own securing active directory because again identities such a big partial portion of attacks.
And so therefore now they own that so today ceases have a lot more responsibility and influence in making sure active directory secure. Now for someone who's maintaining the credentials, they're traditional. I didn't access management, right?
They can still do do that on-hinner, right? It depends on the way you deploy the security technology, like for example, in our case, you deploy a simple sensor that they may already be using for example on their endpoint. So they may already be using a sensor.
Let's say from crowdstrike. It's so all you're doing now is looking at different kinds of data. You're just turning on a different capability without having to install or do anything further.
So it is happy, right? The administrator is happy because you're not really adding any load or anything additionally to the system that they haven't seen before and security is happy because now they have insight into one more layer not just endpoint Cloud but also again, Do you think the providers of the platforms should be doing more in regards to security because you kind of alluded to this earlier, but Microsoft's not the only one but the platform provider has a vested interest in the features and the capabilities and sometimes they don't like to talk about the security issues, but maybe security needs to be thought of more as a feature. Yeah, and and to be fair, it's not that these providers don't think about security but it's challenging.
Right if if you're a company that has so many different products and so many different markets and so many many areas. It's hard to be a specialist crowd strikes. So mission right is to stop adversaries.
And so that's all we think about. So the reason we can do it effectively is because we think about security and we learn about adversaries. I mean, that's the one unique values.
We have human intelligence, right all these analysts but also all this data that we process trillions of transactions on our cloud and that gives us a better mechanism to detect threats faster. But when you're a larger company like Microsoft, right they have to do so many things as a company right active security of their infrastructures only portion of it. Their answer really has been you know, don't run active directory on premise move to Azure ad.
Right, which makes sense? Right? So you move your all your credentials to the cloud and then Microsoft can do a better job of helping you protect that but again that process and for many organization that's nearly impossible that that's a challenge the other is you know, what do you do with Legacy systems systems that you know, you might say.
Okay. Well the answer is maybe multi-factor authentication. Well, how does that help when you have a legacy systems?
You can't protect with MFA for example, how do you how do you deal with contractor systems that you can't touch or you know how to do anything or so there when you go outside the Microsoft ecosystem then in customers get stuck. So you really have to think about security multi-cloud multi-vendor and think about a specialist that thinks about adversaries and all the different attacks, but that's what you really need. So to be fair.
Yes, the identity provider should do certain things, but you really need a security specialist to really protect that really you do for everything else in your environment. All right folk share it in here whether it's infrastructure like Microsoft ad users or for that matter an application. You just can't trust anybody these days couple.
Thanks being on the show. Thank you for time right back to you guys and student.