Showing posts with label Threat Analysis. Show all posts
Showing posts with label Threat Analysis. Show all posts

Sunday, March 16, 2014

Information Security Explained in One Simple Diagram

Assets motivate adversaries to exercise threat realized through attack vectors against assets. Controls protect assets and reduce exposure to threat by counteracting attack vectors.


Monday, March 10, 2014

How to Construct a Threat Statement

Scientists begin experiments with a hypothesis. Researchers begin their papers with a thesis statement. It is similarly useful to begin a threat analysis with a threat statement. The threat statement establishes the scope of the threat and guides the analyst in his threat research. Consider this threat statement, “Unauthorized disclosure of sensitive data.” Partially mapping out the scope of this statement, it looks something like this diagram shown below.


This scope of analysis is a bit large. Consider how large it would be for an enterprise with sensitive information spread across hundreds of systems! However, it is not unapproachable. Every journey, however long, begins with a single step. In this case, that step is to define the threat into a series of more narrow threat statements, such as this one, “Unauthorized disclosure of sensitive data through theft or loss of off-site stored data backup tape by outsider.” The map of this statement is much narrower.

This threat statement, unauthorized disclosure of sensitive data through theft of off-site stored data backup tape by outsiders, is narrowly scoped. It identifies the threat agent (outsider); it specifies the assets in question (data backup tapes; and the method through which the threat may be realized (theft and loss). This narrowly scoped threat analysis can be completed quickly and compared with other related threats analyses for decision-making.

Analyzing narrowly defined threats does not preclude solving larger scope threat questions such as the first one stated above, unauthorized disclosure of sensitive data.  The solution is necessary to protect sensitive information assets.  However, the answer to these broad scope threats is the sum of the solutions to the more narrowly scoped threat statements.

A well-bounded threat statement consists of four key elements: the asset category that is the focus of the threat agent’s objective, the end state condition the threat agent seeks to achieve within the context of the asset, the threat agent’s privilege level as it relates to the target, and the compromise approach the agent will use to realize the threat.



Target Asset / Asset Category
The target asset is the focus of the threat agent’s objective.  It is the system or category of systems the adversary seeks to compromise.  By restricting the threat statement to a specific asset or asset category, we establish boundaries for analysis of attack methods and related controls.  While the target may be a specific asset, modeling an asset category allows the analysis to be reused across multiple assets.


Other targets include Internet connection, core router, internal web application, Windows XP operating system, Oracle 10g database, Windows 2003 Server, a specific web application, such as wiremoneynow.abc, Active Directory, or even USB flash drives.

The end state is the condition the threat agent seeks to achieve within the context of the target asset.  It is his goal as it relates to the system he is attacking.  Including the end state in the threat statement narrows the analysis on attack vectors used to achieve the end state. 


Some other end states include application administrator access, network denial of service, unauthorized operating system access, remote system control, physical possession of storage media, and access to internal network communications.

The threat statement should specify the threat agent’s privilege level as it relates to the target system. The types of attack methods available to a threat agent and the complexity and risk exposure of executing the attack methods are partially dependent on the agent and his privilege level as it relates to the target system. For example, physical compromise of a system within a secured data center is easier for an administrator with authorized access to the data center than for an outsider who has no data center access privileges.


Other privilege levels include an outsider with no access to non-public target resources, an insider who has access to the target system owner’s private network or physical facilities but no local area network or physical access to the target system, and a privileged insider who has direct physical or local network access to the target system.

The compromise approach specifies the category of methods the threat agent will use to realize the threat. The compromise approach in our example threat statement is theft of authentication credentials.  This limits the scope of attack methods to those such as horizontal credential guessing, vertical credential guessing, keystroke logging, phishing, social engineering, and network communications intercept through CAM table flooding or ARP spoofing.



Saturday, February 22, 2014

Threat Agent Profile: Irrationals

The majority of system compromises can be traced to a simple principle – the benefits, at least in the short to medium term, outweigh the cost. Broadly, leaving governments aside, benefits can be divided into either financial or psychological. Money is the root of almost all compromises. The targets these hackers will go after are pretty simple to predict; roughly, they’ll go after systems that provide the highest return at the lowest personal risk of incarceration. Attacks motivated by psychology are more difficult. Most of the psych hacks are web site defacements and limited to simple exploits – more in the vandal category we reviewed. Within the psychology category is a subset that is irrational; system compromises that really can’t be explained or predicted, that stand against reason. What systems they will go after and how much resource they’ll dedicate in doing so is anyone’s guess. Here is one:

During a yearlong period beginning March 2001, Gary McKinnon, a British citizen, compromised scores of sensitive U.S. government and military systems, including systems at the Pentagon, Fort Benning, Fort Meade, the Earle Naval Weapons Station; and the Johnson Space Center.  In responding to journalists regarding the case, the U.S. Attorney heading up the prosecution, Paul McNulty said, “Mr. McKinnon is charged with the biggest military hack of all time.”[1] And what was Gary’s stated motive? It was to discover evidence of a UFO cover-up.[2]

The ‘irrationals’ represent a very small portion of the system hacks, but they are out there and they are very bothersome. Perhaps the people that scare us the most are the ones that we can’t explain.

Monday, January 20, 2014

What is Threat Analysis?

Threat analysis is the process of determining the likelihood of harmful things occurring to your assets – who will do what to what systems. This information, coupled with value of each of your systems, forms the basis for making sound security decisions.

A threat is an indication of an impending event that is harmful.[1] Something that is impending and harmful to one entity may not be to another.  A 6.0 magnitude earthquake is harmful.  Whether an earthquake is impending or not is dependent on location.  According to the U.S. Geological Survey there is a 90% probability of a 6.0 or greater magnitude earthquake occurring in the San Francisco Bay region before 2037. There is a 0% probability of a similar magnitude earthquake occurring in Bismarck, North Dakota, during the same period.  Earthquakes are a threat to those who live in San Francisco. Earthquakes are not a threat to those who live in Bismarck. Interestingly, with all the recent hydraulic fracturing in North Dakota, the USGS may have to reassess their Bismarck earthquake assessment.

Just as threat of earthquake varies by geographic location, information security threats vary by entity and by asset. Consider the simple example of the threat of customer account takeover through stolen customer authentication credentials for a bank and a local auto repair shop. The threat is real and pressing for the bank if they have an online banking system, but it doesn’t even apply to a local auto repair shop.  Even for two financial institutions, the threat significance could differ based on factors such as the type of data and the transaction capabilities of their online banking system, the size and profile of their base, and even the geography they serve. For banks, the large institutions often see threat activity years before the small ones do. The threat applicability and significance differs based on the organization and the asset in question.



[1] http://www.merriam-webster.com/dictionary/threat