Cyber Security Predictions for 2017

2016 was a big year in the annals of Cyber Security, and 2017 promises to eclipse it.

Creating an Enterprise Data Strategy

An introduction to the process of developing comprehensive strategies for enterprise data manangement and exploitation.

A Framework for Evolutionary Artificial Thought

Let’s start at the beginning – what does this or any such “Framework” buy us?

The Innovation Dilemma

What things actually promote or discourage innovation? We'll examine a few in this post...

Digitial Transformation, Defined

Digitial Transformation is a hot topic in IT and big money maker for consultants - but what does it really mean?.

Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Saturday, December 31, 2016

What We Just Learned about Grizzly Steppe

The Obama administration announced yesterday that sanctions were being placed on Russia in retaliation for the 2016 Election Hacking scandal. Shortly after that announcement, a Joint Analysis Report (JAR) was released providing a description of the nature of the Cyber attacks. It's still not clear if this report (released to scribd.com) is the complete intelligence report that the President had requested some weeks back or one perhaps one of several. What is clear however, is that the level of detail is perhaps more granular than expected, but the scope seems to be narrower than it could have been.
Architectural representation of the Election Hacks from FBI Report: JAR-16-20296

So what did we learn from the document? Here are a few highlights:
  • We have a relatively straightforward diagrammatic view of how the attacks occurred (I've placed an example of this in the post image)
  • We've been given a glimpse into the nature of the Russian Intelligence Service (RIS), but a limited one. Approximately two dozen names are listed as being associated with the RIS, but it's not clear if all these are indeed separate groups (and no explanation is given about any of it). There are some very Bond-like spynames in the group like CrouchingYeti, Fancy Bear and Gray Cloud but that in itself isn't very illuminating.
  • We are shown some detail regarding the identity of the exploit. Unfortunately, this is not provided in a context that might be well-understood outside of the Intelligence Community or a small cadre of Cyber security experts. The exploit information is supposed to clinch the identification of the groups in question and maybe it does, however it certainly seems as though part of the story is missing.
  • Fully half of the document is dedicated to describing various Cyber risk factors and mitigating actions in some detail. While this is good information, it is terribly generic and it seems a though it has been used to inflate the size of the report somewhat - perhaps at the expense of the main point for releasing it.
While I don't wish too sound too critical here, I think it might be worthwhile for the folks working on this analysis to consider creating another draft. First, I'd like to address why I think that's necessary and then I'll delve into what ought to be revised or added in the next version of the report.
The reason why we need to get this right should be obvious, but I'll state it again anyway. The report represents the foundation for both the claims that the attack occurred as well as for the sanctions that will follow. This may or may not represent a form of Cyber-warfare (both the attack and the response - I've outlined that topic in more depth here). In any case, it is a serious matter and the sanctions probably represent the most severe actions we've taken against Russia since the end of the Cold War. Thus the foundation needs to be as a strong as possible. Obviously, there are national security issues at play with this topic, however in some situations, more information can be better than less. The information missing from the current version of the report includes the following:
  • Detail on the other organizations which were hit in the attack - there is an implication of a much wider attack, but no specifics.
  • An explanation of the context - the goals of the attack and how the stolen information was utilized. Also, there needs to be an explanation of the process of exploit identification for those who aren't already familiar with it.
  • A discussion of how the US can help safeguard election processes and systems. This is somewhat covered by the best practice portion of the report, but that seems to also be saying that all such mitigation for thwarting future attacks is entirely up to each potential target which isn't altogether satisfying. We should be having stronger a dialog on how critical processes can be protected by the groups we thought we there to perform that task. For example, who if anyone, will take the lead on auditing voting systems in every state?
The current Grizzly Steppe report seems to have give us the bare minimum. We need more than that if we wish to learn from this experience and keep it from happening again. Let's give it another try...
copyright 2016, Stephen Lahanas

Friday, December 16, 2016

The 5 Principles of Cyber Warfare

This week we got a partial glimpse into the types of action that the United States might consider to be acts of Cyber Warfare. I had written about this topic 2 weeks ago in regards to Voting Integrity in the face of Russian cyber attacks, but the story has escalated since then – culminating this week in direct accusations against the Russian government. The CIA and even President Obama have directly implicated Putin as being personally involved with the deliberate aim of swaying the 2016 election. In a year of big stories, this may have been the most far reaching in its implications. One of those implications, which has already been alluded to by many in Washington, is that this act may in fact represent a form of Cyber Warfare.

So, what exactly does Cyber Warfare mean and how does it differ – if at all – from Cyber Terrorism? That’s a tough question, one that I’ve not seen answered clearly before. Cyber Terrorism can come from nation states, such as China, North Korea, Iran and so forth, but one might expect that actions perpetrated by nation-states are less like terrorism per se and more like warfare. It is worthwhile at this point to step back into the not too distant past and bring up a similar question that also still applies here – what’s the difference between a “Cold” and a “Hot” war? The Cold War, as you might remember, involved a whole host activities from espionage to proxy wars. The Hot or real war between the super-powers never occurred and it didn’t happen primarily because of the concept of Mutual Assured Destruction through use of our nuclear arsenals. In that case, the distinction between the terms also involved both the nature of the participants as well as the types of activities involved which is similar to the current question.
None of this really helps though to clear up the confusion regarding what is or what isn’t Cyber Warfare. Here are a few reasons why:
  • Cyber Warfare can be both covert and overt – depending on the nature and intent of the attacks as well on the determination as to whether they should be publicized in any way.
  • Cyber Warfare could be conducted by both Nation States and Terrorist organizations. The key distinction here though would be that we wouldn’t necessarily classify acts committed by smaller unknown groups or even individuals as Cyber Warfare. In those instances, the term Cyber Terrorism might be more applicable. However, it is also clear that in Cyber Warfare, as in traditional warfare, non-nation state organizations can and have conducted offensive operations.
  • Cyber Warfare can be a standalone or blended activity (e.g. coordinated with other traditional war-fighting activities). It’s conceivable that an entire conflict could be fought solely within the Cyber Domain. Cyber “Domain” here refers to the notion that Cyber represents one of several potential war-fighting domains such as Land, Sea, Air and Space. The US military formally acknowledged Cyber as such a domain with its creation of US Cyber Command several years ago. Of course the reality of this statement is more complicated than it sounds as Cyber also infiltrates all other warfare domains through the technology implied by it – it is cross-cutting domain and even if an attack were completely limited to Cyber actions it is highly likely that physical capabilities (such war-fighting assets as ships, planes etc.) might be impacted.
  • Cyber Warfare can be directed at the Government or the Industrial Base or both. We can’t say for example, that all attacks against businesses must be considered Terrorism per se – the intent is what’s important. If the intent of an attack is to cripple the country that’s been targeted, then a Cyber attack like that is no different in principle from the types of bombing raids we conducted against Germany in WW2 in order to cripple its industrial base. Today though, the sectors that are perhaps more vulnerable might be Energy and Finance as opposed to Manufacturing. The results might be the same though if the goal is hobble an economy or otherwise disrupt a nation state.
Now, we are ready to consider what the distinctions between Cyber Warfare and Cyber Terrorism really are. They would likely involve the following considerations:
  1. Cyber Warfare must necessarily consist of a sustained campaign of Cyber activities, designed to disrupt any mission critical functions of an enemy at a national level. This doesn’t mean the activities have to occur in many places to effect a national impact, it merely has to be designed to impact an opponent that way (and would also likely encompass more than one attack or incident).
  2. Cyber warfare must necessarily occur between substantial Cyber combatants. The nature of what constitutes a ‘substantial’ combatant lies in what resources they have to bring to bear in any given conflict. A well-established terrorist or rebel group may have the money and personnel to manage sustained attacks. However smaller groups with few resources may only be able to sustain limited operations or a single attack. While there is always the possibility that an individual or a small group might be able to do harm at the national level, it is unlikely that they could sustain this over months or years and it would be more akin to one-off terrorism than warfare in the context of sustained operations and likely outcomes.
  3. Cyber warfare, in general, involves more specific objectives in contrast to Terrorism which is often random in nature and may only be focused on making a statement rather than effecting some desired outcome.
By these definitions, I’d have to say that the Russian hacking of the DNC computers and related activities designed to impact the 2016 election falls under the category of Cyber Warfare rather than Terrorism. And this begs the question, why does all of this matter and why do we need more specific definitions? The bottom line is, that if we don’t have a clear idea of what represents acts of Cyber warfare (either covert or overt), it’s highly likely we won’t be able measure our response properly. Deciding how to respond is obviously a very big deal – as any such decisions could quickly escalate from the Cyber domain into all the others. Perhaps our government does have all of this worked out, and maybe it’s just too secret for any of us to know about. However, from our vantage point now it’s all bit fuzzy. When the President says “we will retaliate in a manner and time of our own choosing” we basically don’t have a clue to what that really means.
Rather than spend a lot of time speculating as to what our response might be, we can instead highlight some principles that may apply to any such situation. The following principles represent a potential framework that might be used to help deal with Cyber warfare as it continues to evolve.
  1. Proactive Awareness – In order to survive or win any Cyber conflict, the nation needs to know when in fact it is under attack. Some attacks are more obvious than others and as the recent election shows, our response can be slow or too late to avoid impacts. Proactive Cyber Awareness is not about hacking into everyone’s cell phones, but rather it is about being able to identify unusual behavior in key systems and sectors across the country (or wherever our interests may be). This means we need more selective and actionable intelligence then we seem to be getting now.
  2. Measured Response – This has been mentioned in the news, but as I noted it’s not been explained by anyone (at least publicly) yet. For this to actually work, someone needs to define the measured responses up front rather than assessing each event as if it were the first time it had been considered. The landscape is fairly complicated so this involves a lot of work and some automation. However, it shouldn’t fully automatic any more than our current traditional war-fighting capabilities are – the human in the loop must always be present.
  3. Defined Escalation Approach – This is a process and it ought to be built atop the measured responses defined previously, the idea being that whenever or wherever Cyber activities begin crossing over to other areas there needs to be another level of safeguards built in to avoid any type of cascading escalation that could lead to something like a nuclear conflict.
  4. Maintain a Consistent Policy - In theory, our management of Cyber war shouldn’t be unique in each potential scenario – there ought to be a consistent expectation as to what will happen if enemies launch attacks against the US. This is a key point in the recent debate over Russia as the situation has also become embroiled in US political differences, confusing the matter. While there will always need to be specific considerations given to certain situations, we should never give an indication to any opponent that Cyber attacks may be permitted without any response coming from the US. This would be an extremely dangerous precedent and helps to explain why the President and CIA made statements this week to the effect that election interference would not go unpunished. Better late than never and like all of warfare, if we're in the game we should build policy around what's necessary to win - as opposed to settling for mere survival. There may such as a thing as a Cyber Maginot Line...
  5. Continuous Innovation – This may be the most important point, given the stark reality that it is easier and more cost effective to mount a Cyber attack than it is to defend against one. Despite the billions spent each year in the US across government and the private sectors, Cyber Security breaches and attacks have only become more prevalent and severe. More focus needs to be given to pushing the envelope on innovation to help reduce the current advantages enjoyed by our Cyber opponents. Today, much if not the majority of innovation has come from the attackers and we’ve been playing catch-up. As in every other realm of warfare, the side with the greatest technological advantage tends to win.
It’s anyone’s guess as to whether the current Russian hacking crisis will boil over into something more, but one thing is certain, the age of Cyber Warfare has most definitely dawned.

Copyright 2016, Stephen Lahanas

Friday, October 26, 2012

Cyber Security & Threat Management

Threat Management is still a relatively new concept; there is no industry standard definition for it. In fact, the few people who are talking about it right now tend to view it from at least two very different perspectives – one a product focused approach to unifying perimeter security tools and two, a practice-focused management paradigm. As it evolves, Threat Management will eventually encompass both of those perspectives and will likely become perhaps the single most important element within any given Cyber Security solution.

The reason why it will become so critical is that Threat Management allows us for the first time to build upon a complex conceptual framework with a variety of analytical tools which will automate an ever-growing percentage of Cyber Security tasks. Without this framework it would remain difficult or nearly impossible to manage Cyber Security in a proactive and coordinated manner. For the purposes of this discussion let’s define Threat Management as:
“The conceptual and technical framework dedicated to discovering, defining and managing threats to operational security and mission assurance. Threat Management is software & hardware agnostic and can apply as an integrated IT practice in any functional domain. The goal of Threat Management is not merely to ensure that immediate (local domain) threats are mitigated but that threats are also managed in the context of communities of interdependent or inter-related entities. Threat Management depends upon top-down, bottom-up and lateral participation or guidance to build knowledge frameworks which can then be used to define security policy and solution mitigation.”
So, what is a “Threat” given this construct? A Threat is “any event, vulnerability or behavior (or combination thereof) that either poses a danger to the operational mission or if combined with other events, vulnerabilities or behavior could constitute a threat to the operational mission.”


The first step towards identifying threats is to define what threats actually represent

In that last sentence we begin to see the systems implications of what we’re talking about. The goals here are two-fold; one – block a threat before it is manifested or two – stop a threat in motion that wasn’t blocked in time to preserve operational capability. The other key consideration here is that we’re viewing this practice as evolutionary – it learns as it goes and learns from the community which uses it.

Threat Management and Semantic Technology
Much of what we’re describing with Threat Management already occurs in some fashion; however that is not consistent from one enterprise to another and in fact much of it is handled using manual processes with little ability to correlate or manage various aspects of the problem in a unified approach. To unify Threat Management we need a mechanism which allows us to characterize all aspects of Threats and to correlate that information from information collected from the full spectrum of security related software or hardware appliances. 

Threat Management as we’re describing it here is wholly dependent on a Semantic Knowledge layer and data exchange architecture. This allows us to:
  • Provide non-proprietary data exchange approaches (for security-related data capture and analysis).
  • Characterize complex or aggregated data “patterns” in utilizing ontologies or RDF-based databases or related tools.
  • Provide a knowledge sharing framework for the community of defenders and security experts who analyze existing or predict future threats.
  • Build policies based upon Threat Activity and Threat Prediction – policies that can also be captured, manifested and distributed using Semantic technology.
  • Drive dynamic reconfiguration of H/W and S/W infrastructure in response to policy definition and distribution.
While there are Security vendors that have made incredible progress in being to integrate some of these capabilities in the context of their proprietary tools, this approach ultimately will fail without the Semantic layer for one simple reason – the entire world is never going to standardize on one security tool. However, the Semantic Layer for Threat Management can extend to encompass any infrastructure or combination of security tools.



Copyright 2012, Semantech Inc. All Rights Reserved

Wednesday, October 24, 2012

Data Driven Cyber Security

Data without meaning has no value. Data that is interpreted too late to respond to a situation has only forensic value. For too many years, computer network security and information assurance practices have focused solely on forensic capabilities. Semantics is the science of applying meaning – to symbols, to language, to data and to events. If meaning can be mastered, it can then be portrayed effectively in analytical displays. The combination of Semantic definition of the Cyber landscape with innovative analytic engines provides us for the first time with the ability to link multiple communities together in a proactive unified Cyber response, in real-time.



Data is the glue that binds together our ability to perceive and mitigate Cyber Threats.

A Comprehensive Cyber Security Methodology requires Cyber Semantics & Analytic solution components - those components include the following core capabilities:
  • (Attack) Pattern Definition – The beginning of the Semantic foundation is the collection and / or predictive definition and provision (or definition) of attack patterns. 
  • Dynamic Threat Correlation – Attack elements are correlated against patterns in real-time to help determine both the threat level as well as potential actions. This becomes a pattern matching exercise; and more importantly, one that occurs across multiple partner organizations. 
  • Dynamic Incident / Event Collection – Provides the ability to collect and synthesize attack data as attacks are occurring (for use both in immediate remediation as well as later analysis and reconfiguration)
  • Cyber COP – COP stands for ‘Common Operating Picture.’ The ability to build this atop a Semantic foundation allows for dynamic and community views as well as comprehensive activity aggregation.
  • Cyber Enterprise Architecture (EA) – Enterprise Architecture is the blueprint for infrastructure environments as well as the software and analytics which are housed in those infrastructures. Our Cyber EA approach is built using the same focus on Semantics – allowing for coordination from the ground up.
  • Mission Intelligence or Reporting / Cyber Health Dashboards – One thing that has become abundantly clear over the past decade is that Cyber Security is a time sensitive activity and that traditional security analytics are painfully slow.  In order to get ahead of the curve – there must be automated alerts and warnings built into our Cyber oversight mechanisms. This Cyber Health Dashboard can exist within or separate from a Common Operating Picture. The Cyber Health Dashboard allows individual security managers to catch activity real-time and then coordinate within their larger communities through collaboration to reduce the impact of the attacks. 


Copyright 2012, Semantech Inc. All rights Reserved 

Tuesday, October 23, 2012

The Cyber Security Challenge

Over the next several weeks we're going to introduce a number of concepts relating to Cyber Security. We'll begin today by explaining some of the things wrong with how security is often viewed today...

Network defense and management for the past two decades has focused primarily upon reactionary responses to security breaches or “exploits.” Determining whether an attack has occurred is a forensic rather than a proactive activity.

Continuation of a reactive defense paradigm allows our adversaries to enjoy a more or less permanent offensive advantage and leaves us vulnerable to novel attacks not previously experienced and accommodated within our current defensive structures. In other words, Situation Awareness without predictive and dynamic responsive capabilities will continue to leave us relatively unprepared for the scenarios we are likely to face in the near future. 




Cyber Security must be an integrated discipline in order to work...

Another facet of the problem relates to the nature of Network Defense and attack as a collaborative activity. Network attack is and already has been collaborative in nature for more than a decade; however most network defense implementations are still highly segmented. This also provides a significant advantage in information sharing and freedom of action to Cyber adversaries.

This becomes particularly important when we consider the relative complexity required to support federated defensive collaboration as opposed to the relative simplicity required to mount a coordinated, distributed attack. The natural advantage again resides with our adversaries. This advantage is both technical and economic in nature, which is why Cyber attack represents perhaps the lowest cost option for asymmetric operations (i.e. the relation of the cost of organizing an attack versus the potential cost of damage inflicted).

Over the past decade, Computer and Network defense has consisted of ever-increasing levels of perimeter controls and sensors as well as identification and sharing of specific exploit “signatures.” The exploits represent specific attacks at the OS, application or network level and their signatures are derived from incident histories. While this represented a major breakthrough when it was first introduced nearly a decade ago, the incident focused perspective of network defense may now be hurting us more than helping us prepare for current and future scenarios by obscuring a larger invisible threat.

An analogy helps to place the issue in context – “while an army has specific capabilities relating to its various weapon systems, training and logistics support elements; ultimately it is an intricate combination of all factors that eventually become synthesized into specific tactics and strategies.”

Incidents or exploits detected in network attacks are but individual elements within an arsenal of Cyber-weapons or capabilities and by themselves are not as meaningful as the manner in which they may be employed or orchestrated. Incidents are in fact part of larger “Event Patterns” which may in turn be part of Cyber tactics and strategies.


Copyright 2012, Semantech Inc. All rights Reserved