31
UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore [email protected]

UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore [email protected]. Who am I? •Head of the Research

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

UNLEASH THE INFECTION MONKEY: A MODERN

ALTERNATIVE TO PEN TESTS

Ofri Ziv, GuardiCore

[email protected]

Page 2: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Who am I?

• Head of the Research Group at GuardiCore• Security research

• Development of data analysis algorithms

• Msc in Computer Science

• Over 11 years of cyber security research experience

• Data center security company

• www.guardicore.com

Page 3: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research
Page 4: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Netflix Chaos Monkey

Page 5: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

How do you test a network’s security resiliency, continuously?

Page 6: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Current Approaches

Page 7: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Here’s a network…

Page 8: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Vulnerability Scanning

Coverage

Frequency

Simulate an attacker

Page 9: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Pen te$ting

Coverage

Frequency

Simulate an attacker

Page 10: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

The Monkey Way

Page 11: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

The Monkey Way

Coverage

Frequency

Simulate an attacker

Page 12: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Monkey Benefits

1. Resiliency Testing- Simulates a real attacker- Propagate in-depth

2. Scale- “Pen Tester” in every VLAN- Full coverage

3. Automated tool- Continuous execution- Easy to use

Page 13: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Pick a random machine and see where the Monkey ends up…

• Start at a random location

• Find all propagation paths

• Continuous pen testing

Page 14: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Components

Self propagation tool

C&C server

Integrates with orchestration

Page 15: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Self Propagation

Page 16: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Monkey Scans

• Fingerprinting

• ICMP

• Open ports

Page 17: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Monkey Attacks

• OS dependent

• SSH

• WMI/SMB/RDP

• CVEs

Page 18: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Monkey Tunnels

• Reach internal networks

• Tunnel through the Monkey chain

Page 19: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Monkey leverages orchestration data

Page 20: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Case Study

• Details:• Production network

• 176 machines (Linux / Windows)

• Dozens of separate networks

Page 21: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

3 machines were breached

Page 22: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

45 minutes later…

Page 23: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

There’s always a way in…

Page 24: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Eventually…

Page 25: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

• 111 out of 176 machines were breached

• Over 30 tunnels were used to reach internal networks

Page 26: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Live Demo

Page 27: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

WIIFY

• Predict attacks by thinking like a hacker

• Mitigate threats before actual compromise

• Continuously validate network resiliency

Page 28: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Other Primates

• Metasploit

• Netflix’s Simian Army

• SafeBreach (startup)

Page 29: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Black Hat Sound Bytes

• Download the monkey at https://www.guardicore.com/infectionmonkey/

• Use the Infection Monkey to continuously test your network

• Contribute code and share techniques and ideas at https://github.com/guardicore/monkey

Page 30: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Q&A

[email protected]

https://www.guardicore.com/infectionmonkey/

Page 31: UNLEASH THE INFECTION MONKEY: A MODERN …...UNLEASH THE INFECTION MONKEY: A MODERN ALTERNATIVE TO PEN TESTS Ofri Ziv, GuardiCore ofri@guardicore.com. Who am I? •Head of the Research

Just Remember…

“What the monkey chooses to do with the technology is not necessarily an indictment of the technology itself.”