78
Akamai Confidential ©2011 Akamai Powering a Better Internet RISE OF THE CHAOTIC ACTOR: ADAPTING TO THE AGE OF ANONYMOUS Joshua Corman CSA Chicago Chapter Meeting Director of Security Intelligence July 11th, 2012

Corman Anonymous Csa Chicago 20120712

Embed Size (px)

DESCRIPTION

Rise of the Chaotic Actor: Adapting to the Age of Anonymous

Citation preview

Page 1: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

RISE OF THE CHAOTIC ACTOR:

ADAPTING TO THE AGE OF ANONYMOUS

Joshua Corman CSA Chicago Chapter Meeting

Director of Security Intelligence July 11th, 2012

Page 2: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

• Director of Security Intelligence for Akamai Technologies

• Former Research Director, Enterprise Security [The 451 Group]

• Former Principal Security Strategist [IBM ISS]

• Industry:

• Expert Faculty: The Institute for Applied Network Security (IANS)

• 2009 NetworkWorld Top 10 Tech People to Know

• Co-Founder of “Rugged Software” www.ruggedsoftware.org

• BLOG: www.cognitivedissidents.com

• Things I’ve been researching:

• Compliance vs Security

• Disruptive Security for Disruptive Innovations

• Chaotic Actors

• Espionage

• Security Metrics

About Joshua Corman @joshcorman

Page 4: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 5: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Adaptive Persistent Adversaries

Page 6: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

6

Page 7: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 8: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

RSA 2011 PechaKucha Happy Hour http://www.youtube.com/watch?v=JQEBYxp_vKs

20 Slides x 20 Seconds (6 min 40 sec)

Joshua Corman

@joshcorman

Research Director

Enterprise Security

Page 9: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Understanding Anonymous: The Rise of the Chaotic Actor

Director of Security

Intelligence

Akamai Technologies

2011 FlashTalks powered by PechaKucha

Joshua Corman

@joshcorman

Page 10: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

10

Page 11: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

11

Page 12: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Paradox Slide/Deliberate Disinformation

Page 13: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

http://www.csoonline.com/article/682511/the-rise-of-the-chaotic-actor-understanding-anonymous-and-ourselves

Page 14: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

14

Some men just want to see the world burn…

Page 15: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Lots & Lots of Anonymous Sects

15

Page 16: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Your Headline Here (in Title Caps)

16

Page 17: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

You Choose Your Own Level of Involvement

17

Page 18: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Anonymous* Unmasked? [*Alleged]

Page 19: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

You Choose Your Own Level of Involvement

19

Page 20: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

You Choose Your Own Level of Involvement

20

Page 21: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Escalation?

21

Page 22: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Anomalous Anonymous?

22

Page 23: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

False Flags: Adaptive Persistent Adversaries

“Anonymous is God’s gift to the Chinese” – CISO

Page 24: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Cyber-Neo-McCarthyism

I am not now…

…nor have I

ever been…

…a member of

Anonymous.

Page 25: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Building a Better Anonymous…

25

Page 26: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Building a Better Anonymous…

26

Page 27: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

The easy answers

27

Suggested Background

Page 29: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

PANEL: Whoever Fights Monsters…

Page 30: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 31: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 32: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 33: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 34: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 35: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 36: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

1914

Page 37: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

With Great Power?

"When you don't have centralized

leadership, it doesn't matter what

most will do, it matters what one

of them will do," Corman said.

Page 38: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Control and Chaos ”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

Page 39: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Does not one cause the other? ”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

“It’s a Trap” on shirt.woot.com

Page 40: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 41: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 42: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Crossroads

Page 43: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 44: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Chaotic Good

Legislation Watchdog

Chaotic Good

Free

Speech

Chaotic Good

Moral

Outrage

Anonymous Identity/Meme “General Population”

MalSec?

Chaotic Good? or

Evil?

Leave

LulzSec

Chaotic Evil

Page 45: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

“If you believe something…”

Page 46: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 47: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Finger on the Pulse

Page 48: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Back to Anonymous 2020

Page 49: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

The Future of Anonymous

Page 50: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 51: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 52: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

A Modern Pantheon of Adversary Classes

Targets

Credit Card #s Web Properties Intellectual

Property PII / Identity

Cyber Infrastructure

Core Business Processes

Impacts

Reputational Personal Confidentiality Integrity Availability

Motivations

Financial Industrial Military Ideological Political Prestige

Actors

States Competitors Organized

Crime Script

Kiddies Terrorists Hacktivists Insiders Auditors

Page 53: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Skiddie

Prestige/Profit

Confidentially, Reputation

CCN/Fungible

Script Kiddies

Page 54: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Organized Crime

Profit

Confidentially, Reputation

CCN/Fungible

Organized Crime

Page 55: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Espionage: Adaptive Persistent Adversaries

State/Espionage

Industrial/Military

Confidentially, Reputation

Intellectual Property Trade Secrets Infrastructure

Page 56: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Chaotic Hactivist

Ideological and/or LULZ

Availability

Reputation Personal

Web Properties Personal/Family

Exposure

Hactivists Chaotic Actors

Page 57: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Auditor QSA

Profit

Distraction Fines

Credit Card #s

Auditors

Page 58: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Compare and Contrast Threat Actors

QSA Casual

Attacker Chaotic Actor Org Crime

State APT/APA

Asset Focus CCNs CCNs…

Reputation, Dirty Laundry DDoS/Availabi

lity

CCNs Banking

Fungible $

IP, Trade Secrets, National

Security Data

Timeframe Annual Anytime Flash Mobs Continuous Long Cons

Target Stickiness

NA LOW HIGH LOW HIGH

Probability 100% MED ? HIGH ?

“Impact” Annual $ 1 and done Relentless Varies Varies

Page 59: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Attacker Power - HD Moore’s Law

Moore’s Law: Compute power doubles every 18 months

HDMoore’s Law: Casual Attacker Strength grows at the rate of MetaSploit

Page 60: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

HDMoore’s Law

APT/APA

Organized Crime

Anon/Lulz

Casual

QSA

100

90

80

70

60

50

40

30

20

10

x

Su

cce

ss R

ate

(%

)

Defender “SecureOns” 1 2 3 4 5 6 7 8 9 10 11 12

Espionage

Organized Crime

Chaotic Actors

Casual Attacker

Auditor/Assessor

Adversary Classes

http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/

Page 61: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

APT/APA

Organized Crime

Anon/Lulz

Casual

QSA

100

90

80

70

60

50

40

30

20

10

x

Su

cce

ss R

ate

(%

)

Defender “SecureOns”

HDMoore’s Law

1 2 3 4 5 6 7 8 9 10 11 12

Espionage

Organized Crime

Chaotic Actors

Casual Attacker

Auditor/Assessor

Adversary Classes

http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/

HDMoore’s Law (continued)

Page 62: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

APT/APA

Organized Crime

Anon/Lulz

Casual

QSA

100

90

80

70

60

50

40

30

20

10

x

Su

cce

ss R

ate

(%

)

Defender “SecureOns”

HDMoore’s Law

1 2 3 4 5 6 7 8 9 10 11 12

Espionage

Organized Crime

Chaotic Actors

Casual Attacker

Auditor/Assessor

Adversary Classes

http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/

HDMoore’s Law (continued)

Page 63: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

APT/APA

Organized Crime

Anon/Lulz

Casual

QSA

100

90

80

70

60

50

40

30

20

10

x

Su

cce

ss R

ate

(%

)

Defender “SecureOns”

HDMoore’s Law

1 2 3 4 5 6 7 8 9 10 11 12

Espionage

Organized Crime

Chaotic Actors

Casual Attacker

Auditor/Assessor

Adversary Classes

http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/

HDMoore’s Law (continued)

Page 64: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

APT/APA

Organized Crime

Anon/Lulz

Casual

QSA

100

90

80

70

60

50

40

30

20

10

x

Su

cce

ss R

ate

(%

)

Defender “SecureOns”

HDMoore’s Law

1 2 3 4 5 6 7 8 9 10 11 12

Espionage

Organized Crime

Chaotic Actors

Casual Attacker

Auditor/Assessor

Adversary Classes

http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/

HDMoore’s Law (continued)

Page 65: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

APT/APA

Organized Crime

Anon/Lulz

Casual

QSA

100

90

80

70

60

50

40

30

20

10

x

Su

cce

ss R

ate

(%

)

Defender “SecureOns”

HDMoore’s Law

1 2 3 4 5 6 7 8 9 10 11 12

Espionage

Organized Crime

Chaotic Actors

Casual Attacker

Auditor/Assessor

Adversary Classes

http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/

HDMoore’s Law (continued)

Page 66: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

2011: Attacks Density (4Realz DBIR Style)

“Only 55 of the 630 possible events have a value greater than 0…90% of the threat space was not in play at all”

Page 67: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

2012: Attacks Density (4Realz DBIR Style)

“Only 22 of the 315 possible events have a value greater than 0…93.1% of the threat space was not in play at all”

Page 68: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

It’s all about Zombies

Page 69: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Defensible Infrastructure

Survival Guide/Pyramid

www.ruggedsoftware.org

Page 70: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Defensible Infrastructure

Operational Discipline

Survival Guide/Pyramid

Page 71: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Defensible Infrastructure

Operational Discipline

Situational Awareness

Survival Guide/Pyramid

Page 72: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Defensible Infrastructure

Operational Discipline

Situational Awareness

Countermeasures

Survival Guide/Pyramid

Page 73: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

LanCope

BigFix (IBM)

NetWitness (RSA)

Fidelis XPS

HBGary

FireEye

ArcSight (HP)

Defensible Infrastructure

Operational Discipline

Situational Awareness

Countermeasures

A real use case of 'better security' in the face of adaptive

adversarieshttp://www.the451group.com/report_view/report_view.php?entity_id=66991

Case Study: Zombie Killer of the Week

Page 74: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Who are you playing against?

Page 75: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Innovation Opportunities?

Start with a blank slate! Operationalizing the Basics More/Varied “Eyes & Ears” Increased agility Obtain/share adversary centric intel Big Data & A.I. (more than hype) Simulate adversary-driven scenarios

Page 76: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Page 77: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

Thank You & Contact

Mar @ sudux.com

@krypt3ia

“anonymous” contributors

“unspecified” contributors

@attritionorg

@JoshCorman

http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/

Page 78: Corman Anonymous Csa Chicago 20120712

Akamai Confidential ©2011 Akamai Powering a Better Internet

THANK YOU…

Joshua Corman Director of Security Intelligence

http://blog.cognitivedissidents.com/