
Guide to Security
This is a guide to security.
Check out Audible on Amazon and listen to the newest books!
Understanding the Attack Surface
When discussing the concept of an attack surface, it is important to recognize that this term encompasses the totality of all nodes, users, devices, and entry points within a software environment, network environment, and business environment. In essence, the attack surface represents every possible vulnerability that could be exploited within a network. To develop a clearer understanding of the attack surface, it is beneficial to visualize its components and how they interact with one another.
There are numerous methods by which individuals can access company network information today, beginning with internal servers and workstations, which have been longstanding elements of organizational infrastructure. However, additional vectors—a term that refers to the pathways through which attacks can occur—have emerged, each one expanding the size and scope of the attack surface. These vectors include remote workers and remote offices, applications and data stored in the cloud, and the various devices that employees use in the course of business, such as phones and tablets. Each new attack vector introduces both a risk and a challenge, requiring IT administrators to ensure that these vectors are properly secured in order to protect the network.
Attack vectors can be organized into numerous categories, but for the sake of clarity, they can be consolidated into four general categories. The first category is software. Software is an absolute necessity for accomplishing work, but its risk lies in the fact that there is an almost unlimited number of vendors creating an almost unlimited number of applications. While companies have learned over the years to restrict what users can and cannot install inside a company's firewall, circumstances have become considerably more complicated over the past decade.
The network itself is, of course, an attack vector. It is the means by which hackers and unauthorized users attempt to gain access to information secured behind the firewall. Mobile devices represent a relatively new threat because, while administrators can define with relative ease what software users can and cannot install on company-owned equipment, it becomes significantly more difficult to control what applications are installed on phones and tablets when those devices are personal devices that employees use to connect to the company network.
The physical attack vector, for the sake of simplification, represents every door, server room, wireless router, network access point, and internal computer connected to a company network.
Attacks generally manifest in two forms. The first is passive, in which a hacker monitors a network's activity and scans for vulnerabilities on that network. Because the attacker is merely observing and not actively attempting to penetrate the network, it is not always obvious that they are present. The purpose of this kind of attack is to reconnaissance the network and its activity, often with the intent of developing an attack plan.
Active attacks, on the other hand, go further, with hackers actually gaining access to and perhaps modifying information, either by burrowing in through a vulnerability or attack vector, or by intercepting information that comes out of and goes out to the network.
The attack surface has become a significant problem for organizations because it has been growing for some time due to advances in technology. Twenty years ago, organizations had servers, workstations, and internal network access points, and that constituted the entirety of the attack surface. Today, there are numerous new kinds of entry points, such as wireless routers, and new kinds of devices that connect to an organizational network, such as tablets and phones.
In addition to these developments, there are more sophisticated hacking tools available. Toolkits can actually be purchased on the dark web, making it relatively easier for individuals who are not hardcore hackers to launch attacks. There are also new kinds of exploits—the tricks and methods used by hackers to gain access. Then there is BYOD, or bring your own device. Many companies have realized that it is nearly impossible to prevent people from bringing their personal phones and tablets to work.
In fact, many organizations have recognized an opportunity to provide those devices with connectivity for two basic reasons. First, because it saves money—though that assertion is open to debate—the basic idea being that the company does not have to provide employees with a work phone. Second, it can enhance productivity because employees are not tethered to their desks. However, as discussed, personal devices have greatly increased the attack surface, especially when employees do not pay close attention to the applications they are installing.
Network Hardening
In network hardening, multiple techniques are utilized to ensure that the network is as secure as possible, minimizing the risk associated with all entry points. This is a multitiered procedure that employs techniques such as strong password policies, ensuring that software is secured, patching software vulnerabilities, securing network ports, utilizing intrusion prevention systems, implementing strong malware detection software and hardware, addressing stale and outdated accounts, and reducing the amount of unnecessary software and services. Essentially, network hardening involves reinforcing the network's defenses by mitigating common attack vectors and maintaining active defenses against attacks.
Some of the common vulnerabilities in a network that are targeted for network hardening include open network ports. Network ports are used for communication within a network, both internally inside the network and externally out to the internet. For example, when a web browser is used to surf the web, it uses port 80 or port 443, the latter being for secure encrypted connections.
Different kinds of software use different ports, and many of them are for legitimate uses. Then there is old or discontinued software. This represents a sizable challenge for network administrators because there is sometimes a need for old legacy software, and organizations often move slowly to update to newer software, operating systems being a prime example. The problem is compounded when hundreds or thousands of systems in an organizational network are involved. The same applies to unpatched software. There was a time not long ago when organizations waited for the next release of an application or operating system, which could take months or even longer.
Now, depending on the vendor, software updates are released on a weekly basis for a couple of reasons. First, bandwidth allows for it, but more importantly, software development is not perfect. When vendors detect new vulnerabilities or security risks, they want to get patches out to their installed base as soon as possible. However, there must also be a procedure to ensure that new software patches do not break functionality.
Recently, a major software developer pushed out an update to its operating system, and within a matter of days, some frustrated users reported that the update had deleted their personal files. That is an extreme example, but it did happen, and organizations often want to test an update to ensure that it will not disrupt employees in their work activities. Another common vulnerability is Wi-Fi routers.
Wi-Fi has been in useful existence for approximately twenty years. Add to that the sheer number of wireless devices that people bring to work, and the result is a headache for administrators. Not only that, but many organizations offer guest Wi-Fi for visitors to their business. This represents a major attack vector that needs to be part of the network hardening process.
Generally, there must be two basic roles in the network hardening process. The first is the administrators, the people who actually perform the hardening. They identify security vulnerabilities in a number of ways, ranging from the very obvious, such as locking down unused network ports and installing firewalls and malware detectors, to more active and aggressive forms of network hardening. One of those methods is penetration testing, or pen testing for short. Pen tests are simulations of hacking attacks in which IT professionals actively attempt to break into a network to identify security gaps and lock them down.
On the other hand, IT administrators sometimes overlook another group as a way of helping to secure a network: the users. Some administrators may regard users as the problem, but users are on the frontline. They are in the trenches every day, conducting reconnaissance, so to speak. They are a valuable resource because, if properly trained to recognize potential security gaps, they can advise an administrator when they detect a problem. This kind of advocacy is important, but not all organizations recognize the importance of keeping their employees informed and helping them realize that they have a vested interest in protecting the network as well.
Other issues surrounding network hardening merit attention, specifically some of the things that good network administrators want to stay on top of and that employees need to be aware of.
The first is something called zero-day vulnerabilities, or simply zero-day. This refers to a phenomenon in which a security vulnerability exists, but the people who need to know about that potential exploit—the software developers, the security personnel, and the administrators—are not aware of it. This is when the clock starts ticking, hence zero-day. When a hacker becomes aware of the vulnerability, they could walk right in, so to speak, because there was a vulnerability there and no one knew about it.
Virus definitions are updated constantly because of things like zero-day exploits, in which security companies recognize a new virus or a potential vulnerability and release updates to close the gaps. Antivirus software definitions need to be updated regularly for this very reason.
Software bloat is another consideration. Many individuals have purchased a new computer or phone and found all sorts of software on it that they did not request. It could be a free trial of antivirus software, or a free trial of some sort of marketplace. Software bloat is a phenomenon that can represent a real network hardening problem because network administrators do not want to deal with all sorts of software they did not ask for. Such software can bog down the system, and most people do not have the time to assess each application to ensure that it does not pose a security risk. Software bloat is a genuine concern.
Poor password policy is a headache for everyone. People dislike having difficult-to-remember passwords, and they dislike having to remember yet another password. However, there is a good reason for strong password policies. Long gone is the time when a password consisting of five or six numbers could be expected to keep an account safe from things like brute force attacks, which use shared CPU power to repeatedly try passwords until the correct password has been found.
Finally, the attack surface and the sheer volume of new attack vectors represent a significant issue for security administrators. Where there used to be one device for every employee—a desktop or a laptop computer—there are now two, three, or four devices for every employee, with each one connecting to the organizational network. This kind of exponential growth in the number of possible attack points makes network hardening even more difficult and more important in the present moment.
Demilitarized Zone
In networking, a demilitarized zone (DMZ) is a logical space or gap between the entry point to a network—the firewall and the outside world—and the network itself. The purpose is to provide a barrier between the outside world and an organization's sensitive information.
A basic graphic helps explain what a DMZ is and how it works. On the left side is the outside world, the internet, including a phone to represent external devices, even if they are physically present in the building. Then there is the cloud and a laptop to represent remote users. Just to the right of that group is the firewall, the guardian of the network. It is necessary to get through that firewall in order to access a company's network. On the far right is the internal network, the LAN, with servers and workstations that are physically plugged into the network. There is a firewall just to the left of that as well, and the space in the middle is the DMZ. Within the DMZ are the Wi-Fi routers and servers.
In a typical example, one server is for email and one is for a web server. File folders with arrows show the flow of traffic in two directions. This area in the middle provides access for users, who could be company personnel working remotely, suppliers, or customers. They have access to certain resources. Customers, for example, would not be able to access the mail server, but they might be able to access the website located in the DMZ.
However, all the sensitive information, the important material for an organization, is secured behind the second firewall, the one on the right. There is no specific rule that states what can and cannot be placed in the DMZ. More often than not, it is a matter of common sense. It is simply a matter of deciding what and how much to place in the DMZ, because while it is still secured by a firewall, it is directly accessed by the outside world, that is, the internet. A DMZ is also known as a perimeter network because it provides a sort of perimeter.
Generally speaking, DMZs can be physical or logical, meaning that a DMZ can be cordoned off to a separate physical location, or the perimeter can be set up on the same servers. Essentially, it is a barrier that makes it more difficult for attackers to gain access to sensitive information. It separates the untrusted (the internet) from the trusted (the internal network, the LAN).
Another way of looking at DMZs is as follows. The internet is, rightly, untrusted, but it is also necessary to do business in the modern world. Organizations need to be able to access the internet and to give others access via the internet. On the other hand, the internal network is a trusted place where all important information is stored. Sometimes it needs to be accessed from the outside, by employees who travel, for example.
Organizations need to be able to provide those employees with access to what they require in order to do their jobs. The DMZ acts as a space in the middle that can satisfy that need without putting the network on the right at risk from the network on the left. As mentioned, it is up to whoever designs the DMZ to determine what kind of access is provided.
Generally, website access and email access are provided. FTP, File Transfer Protocol, is usually a common service on a DMZ. Database access might be provided, and services like VoIP, Voice Over IP, could be placed on a DMZ.
Threats vs. Vulnerabilities vs. Risks
There is a distinction between threats, vulnerabilities, and risks that every stakeholder needs to understand in order to appreciate why it is so important to protect an organization's information from outside risks. A helpful diagram can pare down the terms. There are really two elements to be concerned with: threats and vulnerabilities. Where they intersect is where the third element, risk, lies. Understanding that relationship on an organizational scale will help create a culture of risk prevention.
Threats are the potential sources of danger, the things that network administrators worry about every day. Vulnerabilities, on the other hand, are the potential things that can be exploited—the security holes that need to be identified and closed. Risk is the asset that can be lost or compromised if A, the threat, leverages B, the vulnerability, to get to that asset.
Threats come in many forms. They can be intentional, such as a hacker attempting to find a way into a network. They can also be unintentional, such as an employee doing something that causes harm, for example, failing to lock a computer at the end of the day. Threats can also come in the form of natural disasters, such as earthquakes, hurricanes, and thunderstorms. They could be the result of force majeure, things that occur either through some sort of error or at random, such as power outages.
Some examples of vulnerabilities include security policies, which are valuable to have but only as good as the policy itself. Security infrastructure could pose an opening for hackers if it has not been properly established, the old example of a backdoor being a case in point, whether intentional or unintentional.
The backup policy is crucial for disaster planning. If data is not backed up on a regular basis, there is a vulnerability, because lost information is costly. Whether an organization has a disaster plan is another consideration. Has every contingency been thought through? Organizations must be ready for everything.
Then there is the question of how to deal with former employees, whether they left voluntarily or involuntarily. How does an organization go through and scrub the footprint that they left behind? That could include security codes, passes, email accounts, network access accounts, and so on. All of this leads to risk, the result of threats multiplied by vulnerabilities.
Risk requires thorough assessment and planning. Every company understands risk, or at least it should, but how well an organization understands and deals with risk often comes down to planning and teams. In the event of a disaster, intentional or otherwise, does every person in the organization know how to react, or will they be hobbled, sitting and waiting for someone to tell them how to react?
That, in no small part, comes down to policy. If it has not been written down in a clear and unambiguous manner, there may be a problem. Related to that is the fact that things change, particularly in the technology world. A policy is not and should never be a document that is signed off on and then placed in a cabinet to collect dust. It is a living, breathing document that needs to be revised on an ongoing basis.
Security Threats
The top four security threats to organizations today are malware, social engineering, unpatched software, and BYOD along with its younger sibling, IoT (the Internet of Things).
Malware is a catch-all term that, upon closer examination, means much more. It refers to software designed to do harmful things, in some cases to compromise systems and steal information. However, malware is also used to cause mayhem and wreak damage. It is always at the top of the list because malware grows and becomes more dangerous as hackers learn new tricks.
Social engineering is used by hackers to build relationships with people on the inside or to take advantage of a situation where people are involved. Sometimes it is employees who unwittingly give up information. Sometimes it is methods that hackers use to take advantage of a situation. There is a methodology to it as well. Dumpster diving is when a hacker goes through an organization's trash to find information that may help gain access to a network. Shoulder surfing is when someone looking over a shoulder might glean a password or account name. Social engineering can become quite sophisticated, perhaps taking months or longer.
Software that goes unpatched represents a real threat. Zero-day exploits appear, and the clock begins to tick. Someone identifies a flaw in a piece of software, for example, and while that flaw remains unpatched, it is a threat. In the case of many organizations, they have a working system and do not want to disturb it, so they may stay with Windows 7 or a piece of software that is three generations old.
BYOD and IoT are relatively new. Bring your own device has only been with us for about ten or fifteen years. These represent a risk because these devices can connect wirelessly to an organization's network, and security for mobile devices is not always as robust as needed. People bring their own devices, and companies allow them to connect because it is convenient. It may be cost-effective, and it may make employees more efficient because they do not have to be tethered to their desks to get work done. However, these devices could pose a real headache when they contain questionable software or, even worse, actual malware.
The Internet of Things is even newer, with devices that did not previously connect now having connectivity. Televisions and other electronic devices, refrigerators even. While there is a convenience factor to these devices, the thousands of vendors who manufacture them do not always or equally spend a great deal of time thinking about security. This poses a threat to organizations that use them.
Attacks
Employees often have limited information about the attacks that can cripple a company or put it at great financial risk. People are generally aware of some of the buzzwords, such as virus, but they do not intuitively understand how they are packaged and delivered. This presents a risk for companies that do not properly train their personnel in what to look for.
Virus, Trojan, and Worm are terms that most people have heard. These three are the unholy triad of malware. Generally, they are small programs that can attach themselves to legitimate programs. Sometimes they are standalone processes that have been installed when a user clicks something they should not have. Some malware, like worms, are designed to spread themselves across a computer network. Whatever their methodology, their purpose is always for malicious reasons. They could be used to spy quietly without the user being aware of them. They can lock files and systems, encrypting them so a user cannot gain access. They can cause mayhem, destroying files or entire file systems, and they can spread themselves exponentially to widen the damage.
Another common kind of attack—and the word attack is used loosely because these are not necessarily actively enacted—are clickjacking and URL spoofing. Clickjacking is a method used to hijack clicks, thus the name, on websites. It takes advantage of vulnerabilities on a webpage to trick users into clicking invisible links. URL spoofing creates what appears to be a legitimate page from a legitimate company, except that it is not legitimate. Someone has gone to great lengths to duplicate a bank's website, for example, and then tricks users into going there, or perhaps through a URL that looks like, but is not exactly, the spelling of the bank's URL.
Why do hackers use clickjacking and URL spoofing? There are several possible reasons. They could want to earn money off advertising. In the case of clickjacking, if a user clicks on something that is actually an advertisement, the hacker gets the money. That is the best-case scenario. Often these methods are used to steal information or even infect the system.
IP spoofing is another common kind of attack. In IP spoofing, an attacker hides their actual IP address and tricks another system into thinking that the IP address is a trusted one. Why use IP spoofing? It can trick another system into accepting it as trusted. Internal network IP addresses, for example, have a certain numerical format, and firewalls are trained to allow addresses using that format. If an attacker can trick a system by claiming to be part of the network, they can begin to cause mayhem.
Phishing and spear phishing are common methods of fishing for information about a potential target, thus the name, except with a P-H at the beginning instead of an F. Commonly, this is done through email, but it has been used in social engineering and has spread to SMS and other kinds of messaging systems now that they are more prevalent. Spear phishing is a more sophisticated and therefore more dangerous form of phishing. It is more targeted, often using personal information about the recipient, calling them by name, and sending them a message as if it were from a known and trusted sender. Both kinds of phishing are used to get information about a target. That could range from someone pretending to be from IT looking to confirm a password to obtaining information about account information and more. These are very dangerous types of attacks.
Brute force attacks sound scary because they can be. In a brute force attack, a computer applies processing power to a problem to attack it. In a brute force attack, a computer keeps trying a password over and over again, guessing until the computer gets it right. This has become more of a problem because, in the past, computers simply were not fast enough to have the processing power to process all the conceivable combinations. However, computers have become exponentially more powerful, which is why there is greater emphasis on password complexity.
The man-in-the-middle attack is where a hacker sits between two parties, for example, two people sharing an email conversation. The man-in-the-middle attack could be used passively to gain sensitive information, such as information about a client, a company, or account information. It can even be used actively to modify the information being transmitted. For example, the hacker receives the email, modifies the information in it, and then sends it along to the intended recipient.
Keyloggers are small pieces of malware that capture keyboard input. Their purpose is obvious. Someone can intercept account information, passwords, and other sensitive information because every keystroke is silently captured and transferred.
Everyone knows spam, and no one appreciates it. However, many people do not understand why much of the spam that is received can be dangerous. Often it is nonsensical and obvious in the scam it represents, but it can and does come in many forms, through emails, telephone, and messaging systems.
Spam can be dangerous in all kinds of ways. The obvious examples, such as the prince looking to get money out of the country, are familiar to most people. However, spammers have become more sophisticated, often tricking people into clicking links, opening attachments, and similar actions. Spam can also herald other things. For example, it can bog down servers as the buildup to an attack happening elsewhere. Spam can be quite insidious, and everyone in an organization needs to be spam literate.
Physical Security
The physical footprint of an organization is large, spanning a great deal of area, particularly for a company that has physical locations in different geographical areas. It includes buildings, rooms inside those buildings, warehouses, and other ancillary locations. However, it goes deeper. It includes any tangible thing that can be read or removed, such as printed documents, calendars, rolodexes, and printed reports. It can also include any computer, connected device, access point, either wired or wireless, and servers.
Why worry about physical security when there are locks and security guards? First, locks can be broken if they are used at all. People tend to trust a visitor, especially if they do not know that someone wandering down the hallway is a visitor. One method of social engineering is to enter a secure building close behind someone working there. The employee swipes their security pass, and the hacker enters along with them. This has happened. The hacker can then wander around the building looking for exploits. As long as they are acting as though they belong there, it is rare that an employee would confront them.
Locks are effective when they are used. A few years ago, a colleague discussed the time they wandered into an empty office in their building. No one was occupying the office, and it was unlocked. However, on the floor was a wireless router plugged into an Ethernet port, thus plugged into the network. The problem was that the company had a policy of securing the locations where wireless routers were located, keeping them in locked cabinets. The colleague unplugged the router and logged a security incident, because it was quite possible that someone had wandered into the empty office and plugged into the company network.
Another consideration is passes and security badges. Does the company have a policy to expire them? Passwords are usually set to expire, so these keys should be treated similarly. Because these systems are all digital now, it is less of a problem. However, for a small company with a rudimentary legacy system, if someone retires or is terminated, their access should immediately be terminated, and these cards should be treated as another attack vector.
Social Engineering
In some very real ways, social engineering is as dangerous as, or in some cases more dangerous than, online hacking. It is often overlooked as a topic for staff training. Because every personality is different, different people are more susceptible to the often sophisticated tactics used by would-be attackers. There are common social engineering techniques used by hackers. By recognizing them, individuals can reduce the risk of falling under the spell of a social engineering campaign.
The first is dumpster diving, a term that refers to rummaging through an organization's trash. It is not a new idea, and when companies do not properly dispose of potentially sensitive information, it could very well end up in a dumpster and ultimately in the hands of a hacker.
Tailgating is the act of following an authorized person into a secure place. If an attacker is smooth enough, they can pretend to be an employee with the person in front of them, using that person's credentials to enter a secure space.
Phishing is the act of trying to get information from someone by pretending to be someone else. It might seem like a bank or some other authority calling or emailing for more information.
Pretexting is similar to phishing but slightly different, because the hacker pretends to be a legitimate person who needs specific information. One common tactic is to call an employee pretending to be from technical support. People are surprisingly trusting if they believe they are speaking with a legitimate person, and in this way hackers can gain valuable information.
Also similar is quid pro quo, where a hacker tries to find someone in an organization who has a real need. For example, calling successive numbers pretending to be tech support. Eventually, they will come across someone who has an actual technical problem. By establishing this connection, the hacker hopes that the person on the other end of the line will be more trusting and give up information. These are only a portion of the various social engineering techniques used by hackers.
Social engineering is effective because people are more trusting when the interaction is out of context with what they are told to look for. Everyone knows they should not open an attachment or click a link from an untrusted source, or at least they should. However, put the connection out of context with something as seemingly innocent as talking to tech support on the phone, and they may open right up. A stranger is not necessarily a stranger when they are standing in one's living room. While that is not always the case, people tend to open up a bit more when they are in a familiar setting.
Corporate Security Policy
A security policy is not a nice-to-have; it is a must-have. The legal and financial ramifications of a major security event can have a lasting impact. Organizations need to be proactive, not just anticipating the worst but understanding what the worst looks like should it happen. Having a policy means adhering to it, doing what it says. The problem is often that people may not even read it.
New hires, for example, when they are onboarded, may receive guidance on the policy. They are asked to sign a document indicating that they read it. However, that is not a substitute for actually reading and understanding it. It is difficult to keep everyone informed when the policy evolves. The policy may very well evolve, but that is a challenge that must be overcome.
Do not cut corners with the policy. It is there to protect the organization. The moment someone asks for a favor—"I know we are not supposed to have this software, but could you install it for me anyway?"—they have missed the entire point of the need for a policy.
There are some hard and fast facts about a corporate security policy. Every employee must read and sign it. It can be made part of the onboarding process for new hires, and perhaps it is not enough to tell them to read it; explain why they need to know this information. What they receive does not have to be in depth, not the nitty-gritty details. They do not need to know what goes on behind the scenes in IT in the event of a catastrophic power failure. However, they do need to know how it affects them and what they can do to mitigate the risk. They certainly need to be aware of compliance issues.
Countries and geographic regions have adopted new legislation in the information age, and everyone was affected when the EU's GDPR regulations went into effect in May of 2018. In many cases, especially when dealing with private information, organizations are legally bound to protect that information at their own peril. However, that is an organization-wide responsibility. It is not enough that the compliance officer understands the liability risks. The people who handle the information have to be aware of it. A security policy must be monitored and audited on a frequent basis to ensure that it is doing its job.
Password Protection
The ten worst passwords used by people in 2018 are well known, and even a novice hacker could crack them without breaking a sweat. It is reminiscent of Hollywood, where someone is trying to break into a computer, and after three tries they are in because the user's birth date was the password. Given the opportunity, most people would choose something simple because it makes life easier.
However, modern CPU speed has made brute force attacks even more concerning. There was a time twenty years ago when choosing eight characters of randomized numbers was probably safe from the average attacker. That is no longer the case. Social engineering, particularly phishing, is a real threat. The sophistication of hackers cannot be ignored, and making passwords easy to remember only elevates the risk.
People struggle because they are no longer in a single-password world. Because of password complexity, passwords are not easy to remember. It is a challenge, and that is why employees push back on complex passwords. However, the cost of a breach can be disastrous.
Then there is what is commonly called sticky note syndrome. Many people have walked into an office and spied a yellow sticky note pinned to the monitor, not with just one password, but often with multiple passwords. That is a significant security violation, and IT administrators understand this. A password policy must incorporate strong language and strong follow-through on the physical storage of passwords.
Users do not necessarily care about security; they believe it is IT's job. Their job is to get work done, and they want things uncomplicated. They want to be unencumbered, and that is understandable. However, that does not change the need for a strong password policy without any loopholes. No exceptions, because every exception puts the company at greater risk.