Focusing on Enablers to Prevent Security Breaches – Ben Smith, NetWitness
NetWitness Field CTO Ben Smith explains why cybersecurity teams need to focus more on enablers rather than indicators of compromise to prevent security breaches.
Transcript
This is texturong TV. Hey guys. Thanks for the throw.
We're here with Ben Smith. Who's the field CTO for net witness? And we're talking about the state of cybersecurity and the degree to which may be where you are responsible for some of these things that happen out there because well arguably we may be enabling another folks.
So Ben I'm gonna let you explain that but It's not always popular. It's a kind of blame the victim per se but exactly who is responsible for the current state of cybersecurity. And what should we own up to?
Well that that is it that is a great topic for a three-hour conversation Mike so strap in get ready, but we'll give you the abbreviated version today. My first of all net witness myself. We're very happy to have this opportunity to interact with you and your extended audience.
We don't like to talk about blame when it comes to cyber attacks or breaches. That's for The Regulators. That's for shareholders.
That's for the press to kind of store it out afterwards and in the world of threat detection response, which is really net Witnesses sweet spot and has been for more than 25 years. A very common tool to use while you're diagnosing what has happened or maybe more seriously, what is happening inside? Your environment is reliance on these these iocs these indicators of compromise.
If I see this IP address somewhere in my environment if I see this protocol that I'm not expecting to see in my environment and that's great and really kind of core and and fundamental and also Mike it's probably good to point out here that simply knowing about ioc's doesn't necessarily mean that you have the Staffing or the expertise to to leverage those iocs to hopefully put out the fire. It's in your environment. I like to think of iocs as something that is is useful but it's kind of like a post-operative report of what was found in the environment think about a medical report for example, and I think we can probably both agree.
It would probably better be better just not to have to do the operation at all. So when we think about indicators of compromise, those are sources of information that are useful that can help let's let's maybe Loop all the way back to your first question could could help assign blame or maybe throw a spotlight on a weakness. We like to kind of think about it maybe a step a step earlier in the process and how we talk about that here at net witnesses around this concept called enablers of compromise, and we've deliberately phrased it that way we're trying to reach that same group or that same target audience who's very familiar with iocs enablers of compromise is something that we have certainly not heard focused on in the industry and the short definition of that and I will give you the floor back Mike the short definition of an enabler of compromises.
It's really about good security hygiene. So when we think about blame and maybe more holistically when we think about the breaches or the attacks that we're seeing in the news today, it's not at all uncommon. Weeks months sometimes years after that incident to be able to piece the puzzle pieces together whether you are the victim or whether you are a reporter or whether you're someone else trying to figure out what happened to put those puzzle pieces back together and to say oh, yeah this one thing and it's rarely just one thing.
Maybe it's one or two or three things. Maybe there was poor security hygiene in the environment. So when we talk about enablers of compromise, that's really what we're talking about at netwitness.
We're talking about poor security hygiene poor operational practices that are in place at my organization, maybe your organization as well. And the risk is we just don't know that those processes those procedures are in place until it's too late. So many years ago.
I talked about Bella and he asked me question about something and I said, you know, well, here's what we know and then I asked him I said, you know. us and everybody and his brother publishes tons of information about how to deal with this issue and I'm kind of surprised that you're encountering this thing because it's very well documented and he looked at me and he just said Son It's kind of hard that think about fire prevention when you're holding on to a hose for dear life. So how do we kind of shift over to this more proactive mindset that you just described because so much of what we are doing in cybersecurity is reactive these days.
Yeah, a lot of it's reactive and sometimes that's operational reactivity. Sometimes that's regulatory reactivity. You've talked to a bunch of folks.
I know I've talked to a bunch of folks who who are trying to solve this problem and they start that conversation by saying I'm going to apply this technology maybe this Sim security information event management a log management capability to try and give me that visibility into my environment whether you're trying to solve the problem that I'm putting in front of you today the enablers of compromise and identifying them or any other problem and at least from my perspective. I don't disagree that having a Sam in place is important. There are a lot of regulations out there that mandate that especially if you're working as you well know in certain industries, however, I am of the very strong belief that true visibility doesn't start with logs.
It starts with the network. The network is the one single source of Truth. What's happening inside your operational environment logs tend to be a very good trailing indicator to say something happened.
We logged this at some point in the past. It's very hard to lie. When you're looking at the network traffic and being able to reassemble that Network traffic to see what is happening.
So this is a very long answer Mike to your to your question better visibility would be the short version of that. But sometimes when I start this conversation with friends and colleagues and customers, they immediately default to thinking oh, this is a conversation about a Sam. We actually believe in that witness that everything starts with network visibility.
And yes having logs is important having endpoint data is important in a perfect world. You've got something that takes a look at all three of those different data planes, but if you have budget if you have brain power if you have Personnel for just one of those three, the network doesn't lie and the network is a great place to look for these Anglers of compromise these poor operational practices. I'll give you a quick example.
One of those practices would be using plain text passwords. That's not necessarily something that's going to be captured in a log entry a log entry might show that a person or a process logged successfully into this account inside this application or this system. It's not going to give you any visibility into how that password was entered on the network.
It's very easy almost trivial you could say to find and see and then hopefully act upon a plain text password maybe that plain text password is being passed by human being it's not at all unusual mic that those plain text passwords are stored within batch files within many operational environments. If you're from the Linux side of the house, maybe that's a Cron job on the window side. It's a batch file at some point in the past.
Somebody probably decided that they needed admin access or they needed a very specific set of Controls and they hard coded them into the process and it's these types of embedded passwords. That might not be visible. If you have something like a data loss prevention platform that's looking at the files that are sitting on disk may not actually be visible until they're actually leveraged or used on the network.
So that is one of the examples that we think that Network level visibility you might call that Network detection and response that's really the place to start this conversation. Are there patterns in enablers of compromise that people should be seeing or finding more readily because it seems like you know, we worry about how sophisticated the Cyber criminals are becoming but it also looks like basically they're just leveraging the same vulnerabilities in the same issues over and over again and they're not really having a trial all that hard. So is it just that we're not aware of these patterns and or we just don't see it.
I I think maybe the the biggest hill around that question that you've just posed Mike is your absolutely right A lot of these attacks in my estimation. Well over 50% well over 75% are doing exactly as you've described they are using try and true techniques or more to the point their daisy chaining techniques together. So they've got a simple exploit and a simple exploit and a simple exploit and maybe those three have not been used together maybe your systems.
Maybe you're tooling isn't tuned to look for those things in combination with one another. So there's a lot of noise in the environment. And as you know, Mike a lot of companies really struggle, they try and approach this from a maybe a vulnerability management or a patch management perspective not a line of business that we're in but certainly something that we talk about frequently because it is an effective tool one of many inside of your threat detection response toolbox, but a lot of organiz Conditions that I consult with might get hung up around we've got a patch a hundred percent of our infrastructure and that bypasses maybe the most important question when it comes to enablers of compromise.
You don't know how vulnerable you may be as it relates to a single application or a single server or single service until you have figured out what is that criticality of that item if it's a finance server, maybe I call that a tier one piece of equipment a tier 1 process in my environment versus something that is important but not quite as important that might be a tier two or a tier three. It's the identify your crown jewels concept and once you've identified those crown jewels, if I wrap it back around to patch management Microsoft for years has been preaching a very useful model they've used internally inside their own it teams instead of trying to get to that 100% patched Nirvana, which I'm here to tell you nobody gets to instead after you have done the asset criticality list of all of the devices and the systems in your environment. Try to get to 50% Microsoft calls this the half-life goal try to get to 50% patched and you don't stop at 51% You don't stop at 55% But maybe you're a little more accepting that once you have identified those most critical Assets in your environment.
They're probably going to be hopefully they're going to be in that top 50% and then they're inevitably even in a very mature environments. They're going to be assets that have not been patched. So that is one great example right of having visibility into your environment.
We think when you're looking in the network detection response space the smarter you are about your assets your information and your systems being able to help your analysts, right those level one analysts that might be on the front lines that are trying to put out that fire while it's happening. To be able to very quickly see okay. I see it.
This is happening. And this is happening. And this is the big light bulb moment.
This is a tier 1 asset. So I need to treat this with a different sense of urgency a different priority. Maybe I have a different run book that directs me down a different path because this is a particularly facet in my environment a regular quote unquote regular fishing attack might have one run book but a phishing attack that's been directed at my CFO something that would be pretty obvious with that Network visibility.
We talked about that might require a different longer more expedited. However, many different steps you want that all boils down to asset criticality folks that I have heard from me before Mike have heard me talk about the the Dirty Little Secret in the world of information security and that is just about every problem that you and I are talking about today ultimately boils down to an asset management problem and that wraps back around to the vulnerability assessments the patch management talk track that I just had for you it's hard. There is no easy button, but for the the Hanging fruit at least from my perspective is if you haven't stack ranked the Assets in your environment.
If you don't know where your critical data is, you're already well behind the eight ball and much more likely to fail when that breach occurs. Do you think part of the problem is also how we're structured? I mean we hear about the millions of jobs in the cybersecurity space that are going unfulfilled but also seems like we don't lean enough on the it teams and the application development teams to go address some of these issues for us and not everything has to be done specifically by security operations team and maybe they should just be focused on that policies, but the procedure should be executed elsewhere.
Yeah, there's there's the I maybe the broader argument there Mike and I'll I'll pull on my lawyer suit and answer a slightly different question, which is where security really should live in the organization whether it is a function that rolls up to us. So whether it is a function that rolls up maybe into a CIO. Most successful organizations that I have spoken with are the ones that regardless of where that Security Group lives.
That security group has managed to walk across the bridge of being able to translate with the it folks that you just mentioned to translate with the operational teams to try and figure out hey, if we the security team have brought you this concern we have been empowered to bring this to you and we have an expectation that you're going to do X if we bring you a user account that we believe has been compromised through maybe Network visibility or we see that in conjunction with logs or endpoint. Maybe the security team wink wink should have the expectation that the it owner or the operational owner of that system. It's going to take action maybe temporarily disabled those credentials in even less mature environments Mike.
The good news. Is that step that I just described that requires good relationships. And this is a people comment as opposed to a technology comment.
Even that scenario that I just described. That's also something that can be automated. If you're trying to de-provision of user who you believe might be a threat to an environment, if you have a an orchestration an automation capability that you have either built or you've acquired that you're using inside your security operations center.
That's a step that can be fully automated. It can be part of that run book that I just described so maybe to a little more directly address your question and then I'll give you the floor back Mike. This is a p people challenge.
I think much more than a technology challenge. Everyone working in technology has his or her own fifthum security folks with good reason or very proud of the work that they do. It folks with very good reasons are very proud of the work that they do as are the Ops folks as is the risk management team as is the legal team Etc organizations that do the best job recovering from breaches and talking to the public about what happened.
Those are the organizations that have already figured out how to build those lines of Communication and I will be even a little more Stark here Mike lines of trust between security and it lines of trust between security and operations. This is a great Target a lot of organizations struggle with it. I have worked in many organizations as an employee myself.
but if you can solve that one problem make it easier for these two groups to work with one another delineate who is an owner delineate what the expectations are those the organizations that stand the best chance of a full and positive recovery from a breach How smart ultimately can all of this get from an automation perspective I mean in my dream scenario there would be a danger Will Robinson memo that comes around from the machine and it says there are three indicators of compromise coming and here are the things that enabled that and you should take action and you know, it can it get that simple something. It can get that simple and there's technology and solutions out there today that get you almost to that point Mike, but the the breakpoint in that conversation with a lot of organizations is there's a distinction between whether you want to characterize it as correlation or analytics or big data or AI or machine learning or choose your favorite acronym automation. We'll just call that bucket automation.
There's a difference between automating the steps to either recognize or resolve an incident and then there is the other half of that bucket which is around basically cutting the humans directly out of that decision Loot and that's a very dangerous step that is a much more mature step and one that I certainly do not recommend even for mature organizations at least to start deprovisioning a user the example that I gave you before maybe for something in relation to that lower importance asset, maybe a tier two Or tier 3 asset. Maybe I have a run book that says if this user is touching this tier 2 asset and I have reason to believe Mike just like you said there are these three iocs. Maybe there's an enabler of compromise that we have sourced and presented as well to that analyst.
I want to go ahead and automatically deprovision that user from that system. However, if that user as opposed to that system, that user is a tier one user. Maybe it's not my cfo's laptop.
Maybe it's my CFO. Maybe I have a different run book. So the power of these run books is to build in different logical decision chains.
And yes, absolutely a good orchestration automation capability. Today is capable Mike of collecting those iocs bringing them together maybe correlating them like you said and then come into you maybe with the preliminary analysis to say hey, these three things have happened two of these three things are associated with very specific threat actors that are out there. This is a part of the conversation where the miter attack framework really kind of enters in.
It's a fantastic available to everybody framework that we at netwitness highly encouraged folks to consume and Leverage. And once you know that something is out there once you know more importantly Mike something might be happening on your network because you have the visibility into that Network traffic. Yes, an orchestration automation solution can almost get you to that capability, but I'll just emphasize my both for you and your audience the place to stop and pause that conversation is now that I've automated most if not all of the diagnosis of what may be happening.
Should I then automate the remediation and that's a question that's worth asking that's another cultural question those different groups. We just talked about the security team may say yes, let's automate it all the way to the end the operational team which may have a different set of Glass on maybe different priorities may say well there may be a risk to that and maybe it's okay if we put a temporary maybe you can even call it a circuit breaker in that run book. We want to human being or maybe a team of humans to take a look at that.
It depends. Everything depends on how important is that asset that has been breached and if you haven't gone through the hard work to figure out what that asset criticality is, if you haven't leveraged your tooling to take that hard work to say, here's my list of Tier 1 assets. I don't want my Tier 1 analyst Mike to think about gosh.
Okay. Here's an IP address. Where is that IP address located?
What department does it belong to I want to have a capability just to be told immediately. Here's the IP address. But by the way, this is the finance server.
And by the way, this is on the second floor of your corporate headquarters in this specific geography present that technical information in a human readable format. We think that's a powerful means to diagnose and and fix bad stuff maybe happening in your environment. All right, folks, you're heard it here.
If you're addicted to some sort of dysfunctional cybersecurity Behavior. First thing you do is get rid of the enablers. Hey, and thanks for being on the show.
It's my pleasure Mike. Thank you. All right back to you guys in the studio.