Disrupting Nation-State Hackers
Image credit: Chat GPT (DALL-E 3)
“If you really want to protect your network, you really need to know your network. You have to know the devices, the security technologies, and the things inside it.”
This was the underlying theme of a talk at the Enigma conference in 2016 by Rob Joyce, chief of Tailored Access Operations (TAO), the cyber-warfare intelligence-gathering unit of the NSA, now known as Computer Network Operations (CNO).
I watched this talk last week and gave it time for the information to soak into my brain.
It’s a great talk, and I highly recommend taking the ~30 minutes to check it out here: https://www.usenix.org/conference/enigma2016/conference-program/presentation/joyce
Probably the most sobering point that Rob makes in this presentation is when he goes on to say this:
“So why are we successful? We put the time in to know that network. We put the time in to know it better than the people who designed it and the people who are securing it. And that’s the bottom line.”
That statement really hits hard. It got me thinking…How well did I know the networks that I used to build and secure when I was a senior network engineer? (Which coincidentally, was back in 2016)
I knew them very well; after all, I was building them and making them work the way we intended them to. But still, I feel a sense of anxiety at the thought of a powerful threat actor poking around and prodding every little part of these networks.
Once the design is complete and the network is built and tested, it’s over to the operations team for monitoring, maintenance, and ongoing management.
How well do they know the network? What’s inside it, including open ports, hosted applications, and used devices? It may seem obvious, but do we, as defenders, really take the time to know and understand all these details from the time a network is created to the time it’s no longer needed?
I’m willing to bet that most of us don’t.
Networks are constantly changing over time and unless we're adapting our security posture to keep up and adequately match these changes, there's clear gaps that begin to emerge.
I think one of the hidden reasons for this is because safeguarding, maintaining, and monitoring something you own isn’t as challenging, exciting, and fun as breaking something that’s not yours.
So maybe we need to reframe the game. Doing your job well will make an attacker’s job hell.
Doing the best you can to understand and secure your network/applications will make a would-be attacker’s life hard, and we’d much rather make life tough for someone else than ourselves, right? 😉
All jokes aside, I’ve said it before, study and understand your attack surface like it is a part of you because it is! Master the fundamentals.
Enable MFA [MITRE M1032]
Encrypt your sensitive data [MITRE M1041]
Use antivirus/antimalware software [MITRE M1049]
Patch publicly accessible infrastructure [MITRE M1051]
Segment sensitive networks [MITRE M1030]
Take regular backups [MITRE M1053]
…And please review those access logs. All the breadcrumbs are there. #passthehash
In the best-case scenario – attackers will give up and choose an easier target, and sadly, they will find one. Don’t let that be you. We all know what the worst case is.
Below is a visual mapping I created covering the MITRE ATT&CK tactics that Rob walks through in his presentation.
These tactics are commonly used to attack victim networks. For completeness, I've added the mitigations from MITRE that can disrupt adversaries using these associated tactics, preventing a successful breach.
Attack Path Disruption using MITRE ATT&CK