Life notes and ideas from a security pro who lives in the mountains and does a lot of cycling, skiing, dirt biking, writing, coding, and thinking. Twitter @k3strel
Showing posts with label Threat Analysis. Show all posts
Showing posts with label Threat Analysis. Show all posts
Sunday, March 16, 2014
Monday, March 10, 2014
How to Construct a Threat Statement
Scientists begin experiments with a hypothesis. Researchers
begin their papers with a thesis statement. It is similarly useful to begin a
threat analysis with a threat statement. The threat statement establishes the
scope of the threat and guides the analyst in his threat research. Consider
this threat statement, “Unauthorized disclosure of sensitive data.” Partially
mapping out the scope of this statement, it looks something like this diagram
shown below.
This scope of analysis is a bit large. Consider how large it
would be for an enterprise with sensitive information spread across hundreds of
systems! However, it is not unapproachable. Every journey, however long, begins
with a single step. In this case, that step is to define the threat into a
series of more narrow threat statements, such as this one, “Unauthorized
disclosure of sensitive data through theft or loss of off-site stored data
backup tape by outsider.” The map of this statement is much narrower.
This threat statement, unauthorized disclosure of sensitive
data through theft of off-site stored data backup tape by outsiders, is
narrowly scoped. It identifies the threat agent (outsider); it specifies the
assets in question (data backup tapes; and the method through which the threat
may be realized (theft and loss). This narrowly scoped threat analysis can be
completed quickly and compared with other related threats analyses for
decision-making.
Analyzing narrowly defined threats does not preclude solving
larger scope threat questions such as the first one stated above, unauthorized
disclosure of sensitive data. The
solution is necessary to protect sensitive information assets. However, the answer to these broad scope
threats is the sum of the solutions to the more narrowly scoped threat
statements.
A well-bounded threat
statement consists of four key elements: the asset category that is the
focus of the threat agent’s objective, the end state condition the threat agent
seeks to achieve within the context of the asset, the threat agent’s privilege
level as it relates to the target, and the compromise approach the agent will
use to realize the threat.
Target Asset / Asset Category
The target asset is the focus of the threat agent’s
objective. It is the system or category
of systems the adversary seeks to compromise.
By restricting the threat statement to a specific asset or asset category,
we establish boundaries for analysis of attack methods and related controls. While the target may be a specific asset,
modeling an asset category allows the analysis to be reused across multiple
assets.
Other targets include Internet connection, core router,
internal web application, Windows XP operating system, Oracle 10g database,
Windows 2003 Server, a specific web application, such as wiremoneynow.abc,
Active Directory, or even USB flash drives.
The end state is the condition the threat agent seeks to
achieve within the context of the target asset.
It is his goal as it relates to the system he is attacking. Including the end state in the threat
statement narrows the analysis on attack vectors used to achieve the end
state.
Some other end states include application administrator
access, network denial of service, unauthorized operating system access, remote
system control, physical possession of storage media, and access to internal
network communications.
The threat statement should specify the threat agent’s
privilege level as it relates to the target system. The types of attack methods
available to a threat agent and the complexity and risk exposure of executing
the attack methods are partially dependent on the agent and his privilege level
as it relates to the target system. For example, physical compromise of a
system within a secured data center is easier for an administrator with
authorized access to the data center than for an outsider who has no data
center access privileges.
Other privilege levels include an outsider with no access to
non-public target resources, an insider who has access to the target system
owner’s private network or physical facilities but no local area network or
physical access to the target system, and a privileged insider who has direct
physical or local network access to the target system.
The compromise approach specifies the category of methods
the threat agent will use to realize the threat. The compromise approach in our
example threat statement is theft of authentication credentials. This limits the scope of attack methods to
those such as horizontal credential guessing, vertical credential guessing,
keystroke logging, phishing, social engineering, and network communications intercept
through CAM table flooding or ARP spoofing.
Saturday, February 22, 2014
Threat Agent Profile: Irrationals
The
majority of system compromises can be traced to a simple principle – the
benefits, at least in the short to medium term, outweigh the cost. Broadly,
leaving governments aside, benefits can be divided into either financial or
psychological. Money is the root of almost all compromises. The targets these
hackers will go after are pretty simple to predict; roughly, they’ll go after
systems that provide the highest return at the lowest personal risk of
incarceration. Attacks motivated by psychology are more difficult. Most of the
psych hacks are web site defacements and limited to simple exploits – more in
the vandal category we reviewed. Within the psychology category is a subset
that is irrational; system compromises that really can’t be explained or
predicted, that stand against reason. What systems they will go after and how much
resource they’ll dedicate in doing so is anyone’s guess. Here is one:
During a yearlong period
beginning March 2001, Gary McKinnon, a British citizen, compromised scores of
sensitive U.S. government and military systems, including systems at the
Pentagon, Fort Benning, Fort Meade, the Earle Naval Weapons Station; and the
Johnson Space Center. In responding to
journalists regarding the case, the U.S. Attorney heading up the prosecution,
Paul McNulty said, “Mr. McKinnon is charged with the biggest military hack of
all time.”[1] And what was Gary’s stated motive? It was to discover evidence of a UFO
cover-up.[2]
The
‘irrationals’ represent a very small portion of the system hacks, but they are
out there and they are very bothersome. Perhaps the people that scare us the
most are the ones that we can’t explain.
Monday, January 20, 2014
What is Threat Analysis?
Threat analysis is the process of determining the
likelihood of harmful things occurring to your assets – who will do what to
what systems. This information, coupled with value of each of your systems,
forms the basis for making sound security decisions.
A threat is an indication of an impending event that is
harmful.[1] Something that is impending and harmful to one entity may not be to
another. A 6.0 magnitude earthquake is
harmful. Whether an earthquake is
impending or not is dependent on location.
According to the U.S. Geological Survey there is a 90% probability of a
6.0 or greater magnitude earthquake occurring in the San Francisco Bay region
before 2037. There is a 0% probability of a similar magnitude earthquake
occurring in Bismarck, North Dakota, during the same period. Earthquakes are a threat to those who live in
San Francisco. Earthquakes are not a threat to those who live in Bismarck.
Interestingly, with all the recent hydraulic fracturing in North Dakota, the
USGS may have to reassess their Bismarck earthquake assessment.
Subscribe to:
Posts (Atom)



