<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Attackers will win so what can you do?</title>
    <link>http://blog.clearnetsec.com/articles/2007/08/06/attackers-will-win-so-what-can-you-do</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>Attackers will win so what can you do?</title>
      <description>&lt;p&gt;The cat and mouse game you&amp;rsquo;re playing to protect your  network against the enmity of motivated attackers is perilous.&amp;nbsp; You&amp;rsquo;re going to lose. (more  and more 0day is coming: see &lt;a href="http://taosecurity.blogspot.com/2007/08/black-hat-usa-2007-round-up-part-1.html"&gt;Bejtlich's summary at the bottom of his post for Black Hat Day 1 '07 &lt;/a&gt; or&lt;a href="http://www.immunitysec.com/downloads/0day_IPO.pdf"&gt; Immuntiy Sec's recent presentation which makes a nice point,&lt;/a&gt; &amp;quot;Our time to exploit is shorter than your ability to patch&amp;quot;)&lt;br /&gt;
&lt;img src="http://blog.clearnetsec.com/files/0day.JPG" width="300" height="200" align="right" /&gt;&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;The problem is you have to play if you want to be connected. Playing then is about choosing the best strategy, or the dominant strategy if one exist. I think there is a dominant strategy for securing your network -  &lt;strong&gt;traffic analysis&lt;/strong&gt; &lt;em&gt;(augmented with content &amp;amp; context when available)&lt;/em&gt;. &lt;/p&gt;&lt;br /&gt;
&lt;p&gt;From the &lt;a href="http://en.wikipedia.org/wiki/Game_theory"&gt;game theory&lt;/a&gt; book &lt;a href="http://www.amazon.com/Thinking-Strategically-Competitive-Business-Politics/dp/0393310353"&gt;Thinking Strategically&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;&lt;em&gt;In general, a player  has a &lt;u&gt;dominant strategy&lt;/u&gt; when he has one course of action that  outperforms all others no matter what the other players do.&amp;nbsp; If a player has such a strategy, his decision  becomes very simple: he can choose the dominant strategy without worrying about  the rival&amp;rsquo;s moves.&amp;nbsp; Therefore it is the  first thing one should seek.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Traffic analysis  (augmented with content &amp;amp; context) is the best solution when you want pervasive security (i.e. proactive in identifying all types of normal and anomalous activities and strong incident response support due to having the history of  communications) &lt;img src="http://blog.clearnetsec.com/files/stream.jpg" width="347" height="346" align="right" /&gt;&lt;/p&gt;
&lt;br /&gt;
&lt;p&gt;Let me make the point that I do not think traffic analysis in isolation is the winning strategy, but it is a winner when combined with other data freely available on your network. And because I'm tackling this from a defensive perspective (i.e. you have ownership of the network you're protecting), then I'm assuming you get extra defensive observation muscle - snippets of content and context parceled and sent to you by services like syslog. &lt;/p&gt;
&lt;br /&gt;
&lt;p&gt;To take a step back, wikipedia defines traffic analysis as &lt;em&gt;the process of intercepting and examining messages in  order to deduce information from  patterns in communication. &lt;/em&gt;That means learning what's going on from only analyzing the metadata surrounding communication (e.g. the sender, the receiver, the time and length of messages, etc.). &lt;/p&gt;
&lt;p&gt;It's amazing what  traffic analysis can uncover. Taken from &lt;a href="http://www.amazon.com/Blink-Power-Thinking-Without/dp/0316172324"&gt;Blink&lt;/a&gt;: &lt;/p&gt;
&lt;blockquote&gt;
  &lt;p&gt;The Germans were [in WW II], of course, broadcasting in code, so - at least in the early part of the war - the British couldn't understand &lt;em&gt;what &lt;/em&gt;was being said. But that didn't necessarily matter, because before long, just by listening to the cadence of the transmission, the interceptors began to pick up on the individual fists of the German operators, and by doing so, they knew something nearly as important, which was &lt;em&gt;who&lt;/em&gt; was doing the sending. [..] After they identified the person who was sending the message, the interceptors would the locate their signal. So now they knew something more. They new who was &lt;em&gt;where&lt;/em&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This goes on and is only a glimpse of what can be learned of course. In IT security, then you can imagine it's possible to:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;uniquely identify all users on a network only by observing patterns (e.g. quirks about how a user types on a keyboard, command sequences a user typically executes, patterns on how they peruse Internet and Intranet sites, plus 100s or 1000s of additional ways)&lt;/li&gt;
  &lt;li&gt;to always identify an attacker by observing that nothing the attacker is doing matches any known trusted users' patterns &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;At Blackhat '07, a presentation on traffic analysis had a slide titled &amp;quot;Why do this?&amp;quot;, which speaks to the advantages of traffic analysis (I added stuff between []): &lt;img src="http://blog.clearnetsec.com/files/traffic.JPG" width="400" height="310" align="right" /&gt;&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;crypto [i.e. you can't see the content anyways]&lt;/li&gt;
  &lt;li&gt;too much data, already [i.e. the need to aggregate and summarize] &lt;/li&gt;
  &lt;li&gt;it's easier than analyzing everything &lt;/li&gt;
  &lt;li&gt;it's hard to    &lt;em&gt;evade &lt;/em&gt;[i.e. you'll either catch the attacker or possess the data to reconstruct communication paths] &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Now extending traffic analysis with relevant content and context data (syslog, authentication logs, alerts from point products, etc.) allows for very powerful detection for all types of attacks, likely with much greater precision and breadth of coverage versus doing anything else (or relying on a mix of prevention focused systems). Hence, the reason why I think it is a dominant strategy for &lt;em&gt;pervasive &lt;/em&gt;security. &lt;/p&gt;
&lt;p&gt;There is a major challenge in analyzing all this related information though, which is called the &lt;strong&gt;curse of dimensionality&lt;/strong&gt;. I'll save that one for later. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;

</description>
      <pubDate>Mon, 06 Aug 2007 08:36:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:eabab3c2-4553-4729-ac83-cdcc4c40dec6</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2007/08/06/attackers-will-win-so-what-can-you-do</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>traffic analysis</category>
      <category>0day</category>
    </item>
    <item>
      <title>"Attackers will win so what can you do?" by Tate Hansen</title>
      <description>&lt;p&gt;Yes, I would assume adversaries know that traffic analysis exists, or at least it&#8217;s good we assume they do.  &lt;/p&gt;

&lt;p&gt;So, for argument&#8217;s sake, an attacker trying to evade a &#8220;strong&#8221; traffic analysis system would have to nearly perfectly profile everything he was trying to use subversively.&lt;/p&gt;

&lt;p&gt;If he fails to always covertly communicate throughout a victims&#8217; domain following &#8220;normal&#8221; patterns of activity then he can be exposed.  &lt;/p&gt;

&lt;p&gt;So if the attacker hasn&#8217;t &#8220;learned&#8221; to communicate using the same patterns of frequency, duration, packets sizes, etc., then he can be caught.  &lt;/p&gt;</description>
      <pubDate>Mon, 13 Aug 2007 19:06:49 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:c7db3f77-dc8f-4f6b-805c-808451c4d822</guid>
      <link>http://blog.clearnetsec.com/articles/2007/08/06/attackers-will-win-so-what-can-you-do#comment-44</link>
    </item>
    <item>
      <title>"Attackers will win so what can you do?" by dre</title>
      <description>I&amp;#8217;m not convinced.  Don&amp;#8217;t the adversaries know that traffic analysis exists?  I would assume yes.

There are plenty of tricks at the network layer, and many attacks are going multi-channel now.  Say the adversary uses ncovert or nushu or gray-world.net `cooking with covert channels&amp;#8217;?  Pretend there is a tool out there that implements command and control via the ncovert/nushu concepts but the traffic looks just like the update functionality of the operating system under rootkit control?  What about P2P traffic?  IM traffic?  DNS traffic?

What do you do when attacks vectors utilize man-in-the-browser?  Say an adversary re-writes the Javascript eval function to evade filters so that their malware payload can be whitespace obfuscated?

I tried sniffing whitespace once.  Wait, no - that was WhiteOut(tm).  Same difference; both were completely pointless.</description>
      <pubDate>Fri, 10 Aug 2007 18:59:23 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:e1600773-1438-4208-8c3c-a6d2a188c221</guid>
      <link>http://blog.clearnetsec.com/articles/2007/08/06/attackers-will-win-so-what-can-you-do#comment-43</link>
    </item>
  </channel>
</rss>
