Ransomware, AppSec & DNS – Tony Lauro, Akamai
Tony Lauro, Akamai Director of Security Technology & Strategy, sits down with Mitch Ashley to discuss three new in-depth reports Akamai first published at RSA Conference. These in-depth reports focus on three of the most critical areas of web security: ransomware, web applications and APIs and DNS traffic. The reports are authored by Akamai’s team of cybersecurity experts.
Transcript
This is texturing TV. The great pleasure being joined by Tony Lauro Tony is director of security technology and strategy at Akamai. Tony welcome could be talking with you.
Thank you Mitch. Good to be here. Hey, we're gonna talk about three interesting topics from your rsa's topic discussion talk Etc.
But first would you introduce yourself just a little bit about you and what you do at my yeah, so, you know director of security strategy and technology and what that means basically is, you know, I'm working with Akamai see so Community analyst community and really aligning what Akamai does and what we build from a technology perspective making sure that that fits in alignment with the needs of the community, right? So we're we're always trying to solve kind of the next big great problem on the internet and obviously security is is a major undertaking and that's one of the the main priorities of my mission so It's it's a lot of fun. It is one of the constants of our jobs right couldn't get away with get away from it if we wanted to so tell us a little bit about your talk and you're kind of build it around three three topics relevant within the security area for you and your work.
Yeah, so so at RSA conference Akamai released three major threat reports one was on DNS related traffic insights. We have a massive recursive DNS inspection platform that we operate and kind of tying into that a little bit is a ransomware threat report as well. So what's happening inside of the network?
You know, what are the threats targeting? How are they getting in? You know, what's the the threat vectors there?
And then also a web application and API report really looking at you know, as far as what comes from the web what's attacking our client base doing an analysis around that significant changes and some interesting findings as well? Excellent. I'm sad.
I didn't get to hear your talk. I had to talk on API security myself. I could maybe I could have used that report back.
I'll get you next time now. And it's one of the great things about Akama. I love the data that you produce because you obviously see so much traffic and you share with us.
What's happening? Well, what are those do you want to dive into you want to talk about ransomware you want to talk about I'd love to talk about EPA security. We can talk about any up that you want.
Yeah. Let's start off with API security. It's it's a great passion of mine, you know prior to the pandemic.
I spoke at tour Con in San Diego and that talk was actually titled. Apis are not just developers mullet, but how you're getting owned and the whole mullet analogy kind of came to me. I was like, you know apis this very clean concise language to you know, to operate, you know, small requests typically coming from mobile devices is kind of where we see the most popular but on the front end, it's all very clean, but on the back end it talks it branches it out and spreads out and talks to all the other application infrastructure that you have, you know internally, right?
So therefore I call the the mullet and I had a reference to the Kentucky waterfall and Mississippi next room, all these great moment analogies, but what's interesting about about apis is, you know, if you look at Google Trends and for as far as search results for things like Soap and some of the other aging Technologies versus open apis, you know microservices Etc. You'll see a sharp increase starting in 2007 and surprisingly enough maybe not surprisingly the release of the iPhone kind of ushered in this new age of apis, right? There's an app for that everything has has this application front end now and a lot of what we're seeing in terms of exploitation are attackers following those trends.
A while back. We released a report on. On credential abuse and those you know, four out of five times are attacking Mobile apis on the API, you know endpoints for mobile for the mobile services because they're not as regularly protected.
They're not the inspection doesn't take place the same way Etc. But what we noticed in in the past, you know, 12 18 months. We saw just in 2022 alone.
We've seen nine billion attacks already and this is this is huge. Right. So these numbers obviously continue to grow this it's obviously grown sense RSA, but one of the interesting thing is we saw that application attacks were up 300% year over year.
Um, and again, you you would imagine, you know, there's all these, you know, move to the cloud initiatives, you know, everything has a digital transformation rapper around it, which is is pushing, you know, more of these things, you know into the available tax surface for for attackers. So not only do we see three hundred percent increase in application attacks, but local final inclusion specifically. Yeah, obviously, you know, the the OS top 10, we typically have SQL injection maybe cross-state scripting maybe command injection and then maybe a lot of fun and RFI remote file inclusion and local file inclusion, but sequel injection has been the top maybe next exercise for quite some time with us a long time.
We've seen him. Yeah, it's been I mean I'm talking decades, right? So it was very surprising for us to see that lfi.
Now makes up the most frequently attacked attack Vector on the on our platform 400% increase year over year. And and this is you know, this is kind of surprising. So you look at maybe the commoditization maybe a new tool that has commoditized lfi attacks.
Obviously a significant number of this has to do with spring for shell and lock for Jay. But that was quite surprising for us to to see that I mean you mentioned of course mobile is a big factor, right? So I'm talking all apis to the back end, but I think even the pandemic and the move to the cloud.
Every application is talking apis to everything and people ask me. Why is this such a big deal? I said Do you ever accept, you know do that thing where it says connect your Google account or your Facebook accounts something else and give it an okay.
Yeah. That's an authorization authentication step. But what has it talk to them?
Well, that's all apis all that stuff list. It's gonna share about you and share your data with this other s***. Those are all apis.
That's just you one person doing one thing. So you imagine all of our application Cloud native and you know, micro Services type AppSec and you know, the world is apis too fast services to everything. It's so I am I'm not surprised at all that kind of an increase and I would I would guess it's Gonna Keep, you know growing, you know more hockey stick than it maybe.
Yes. Absolutely. Well the funny thing too.
Is that a lot of what what we're seeing here. Is that the Even orchestration of cloud environments takes place via apis these days right apis that we work. Yeah.
And so we saw 38% of these attacks. We're going to the Commerce vertical which might make sense, right? You know Commerce is is basically where you know, all the all the fun stuff is happening in terms of you know, new innovation and you've got all these eyeballs being brought to these Pages via marketing campaigns Etc.
And to me it's probably not surprising that this is one of the most attack verticals but the technology vertical has also seen the most growth over all of them in in 2022 so far. So, you know between technology and commerce, you know, we're gonna see some interesting things by the end of the year. I'm sure absolutely yeah with same follow Money, right we'll get through also does of course, right?
They're right there. Well, we could take the whole conversation and dive into this, but I want to hear some more about the ransomware as a service. Tell some more.
Yeah, I mean obviously Conti made a bunch of news. This was a a ransomware game ransomware is a service is not necessarily new but we're seeing a lot of innovation in terms of how the attackers are again making it easier for others to carry out campaigns. Um, so during the start of the pandemic, we released some reports that talked about just a shift in some tactics in terms of maybe fishing or targeted attacks that were using, you know, covid vaccination as a lure anytime there's ransomware or or fishing campaigns.
You're gonna see this follow popular popular Trends, right? I did a talk one time in Chicago for government sector and I said raise your hand if you got an email that said your Amazon delivery is delayed how many of you would potentially click on that email and like 60% of them was like, yeah. I do have an Amazon delivery almost everybody does it you know ever so often so that is the lure has been very popular.
But what's interesting is that 60% of the successful contacts. We're carried out on us face. So this goes to show that you know where the money is a lot of the most popular brands many of them most popular brands originate in the US and therefore their headquartered here as well.
But 30% of successful attached from Conti. Also, I've heard in the EU. So, you know a little little bit of a balancer and the rest was kind of come angle amongst other organizations, but I think what was interesting specifically about who is being targeted is that there seems to be this maybe kind of a Goldilocks range of businesses worth 10 to 250 million dollars.
And why that's interesting. You know, you look at you know, small to medium business is because hey they don't have they might have the money to pay Ransom, but they certainly don't want to negle the negatively affect their brand. They don't have the same legal teams Etc.
So we're security teams, you know, they're always secure like an Enterprise but oftentimes they don't have the full infrastructure and complemented people to do that. Absolutely. I I have a friend that owns a nationwide construction business and he's like, yeah, I'm kind of the it and security guy for the company.
I was like You should probably get hiring. Someone pretty quick some extra help. Yeah, absolutely, right?
Yeah. Okay good. Well, let's let's turn our attention to the DNS attacks.
Side of this third third leg of the stool that you talked about. Yeah. Yeah, so obviously DNS is super important on the internet, right you want to know how to get anywhere if DNS wasn't wasn't available.
But what's also interesting is from a threat perspective. If you start to look at the idea of using recursive DNS to inspect traffic, right? Normally, when you anything you do on your computer, it makes a request out to the internet via DNS to find that service that's normally seen as benign traffic which I think is kind of interesting obviously over the years have been some organizations that have kind of focused in on this but we've been doing this for quite some time.
Now, we see and analyze about seven trillion genetic requests a day, which is a obviously pretty large number and that customer base is always growing but what we're trying to analyze is are these requests going to some place that we've seen before is it previously been Associated to malicious now, Payload downloads or fishing campaign sites Etc. And then apply that that information to a response right? Maybe you get a friendly feel well page.
Maybe you get a redirection something to that effect. And this is allowed us really to get some some interesting insights on you know, fishing attacks botnets how they operate. In fact one scary stat that that I was quite surprised about One out of every 10 devices monitored communicated at least once to a malware or ransomware or fishing or command and control domain now that seems it seems like a broad spread but that also really indicates that you know, just from a threat perspective.
There's always something going on at least at 10% chance within your environment than something malicious might be taking place, right? That was my DNA DNS attack monitor going off there might. Yeah alert alert in a way.
It's almost like looking at the twist training on, you know, whatever social media platform or Google or you can look at DNS and traffic and start to see some Trends in terms of what kind of attacks what type of traffic where it's going where it's Absolutely. Yeah, you know that what's interesting is you know out of the fishing traffic most of the victims were were targeted by abuse campaigns that either mimic technology amounted to about 31% of the fishing campaigns or mimicked financial brands at 32% of the of the campaigns that we saw. So when you look at that, it's like listen, you're either going to you know, maybe a social media site and how easy would it be for me to interject a man in the middle fake login page sure.
It might send the the requests on on your behalf, but it's going to you know, stipend off those credentials. And of course this is happening from a banking perspective. That could be pretty bad as well.
We saw a lot of interesting findings, too and we start to look at how Fishing and maybe lure pages and things like that work when bypassing MFA technology that kind of that kind of attack, you know, the attacks on Twitter last year. We're kind of a good indication of the fact that it's not impossible and maybe a little bit more difficult, but with a blend of you know, a fishing or a mimic side man in the middle site, you know poor technology when it comes to you know, how your cryptographically connecting your MFA components and a little bit of social engineering, you know, this stuff can can take place a lot more easily than we think. It's it's not a hundred percent.
That's for sure. Yeah, it can be compromised. Well, this is fantastic.
I wish I could as I mentioned could have gone to your talk, but it sounds like it can at least get the paper or all three papers. So if you'll leave behind some URLs I make sure we include that in our description and give everybody a chance to to download this reports and super fascinating Tony. Well, I appreciate you coming by you should come back again and we'll we'll take you any of those three topics and we can spend lots of time my pleasure.
Yeah, I you know, I done research a lot of these different areas. It's it's really passion of mine and luckily I get to do it for a job as well. So it works out for me.
Yeah, don't work a day in your life when you work at your passion, right? Well, maybe you do work. All right.
Yeah, something like that. Well Tony Tony Lauro from Akamai. Yeah.
Appreciate you stopping in with us today. And as I said, you're always welcome back come back anytime. Thank you very much.
My pleasure. Have a good one. You bet.