Black Hat USA 2014: The Ultimate Cybersecurity Event

Black Hat USA is about to return for its 17th year in Las Vegas, NV. The show will bring together the brightest minds in the world of cybersecurity for a six-day period where learning, networking, and skill-building top the activity list. FireEye will be there in full force.

Here is what you need to know:

  • Be on the Look Out: FireEye and Mandiant will have a presence at the conference in booths 411 and 246, respectively. You’ll be able to watch live demos, attend presentations, and get the latest updates on our full platform of technologies and services.
  • Jump into the Trenches: Join FireEye CTO Dave Merkel on Thursday, August 7 from 1-2PM for his insightful presentation “Lessons from the Trenches: Advanced Techniques for Dealing with Advanced Attacks” which will review the latest approaches attackers are using to compromise organizations and, more importantly, what the most innovative security teams are doing to stay ahead. Mr. Merkel will be drawing on data and anecdotes from hundreds of organizations, and will outline how leading security teams have reorganized, re-architected and realigned their security strategies.
  • Take a Practical View: Visit the FireEye booth (411) for ongoing presentations with a focus on various case studies that can be applied to everyday activities. Presentations will be interactive and include audience responses.
  • View Live Demonstrations: FireEye will have eight demo stations networked to live products and solutions to recreate real and recognizable environments.
  • Come out and Party: Join the FireEye crew for an event co-sponsored by Rapid7 on Wednesday, August 6 at XS Nightclub in Wynn/Encore. Register for the party here!
  • M After Dark: There is nothing quite like Mandiant’s “M After Dark” party, which will take place on August 5, from 7-9PM at the Eye Candy Sound Lounge at Mandalay Bay. Click here for registration information.

We hope to see you in Las Vegas the week of August 2 through August 7. If you are unable to attend, check back on the blog for insights from the conference.

 

Security as a Differentiator: Investis Partners With FireEye Managed Defense to Offer Its Clients the Very Best in Cybersecurity

This is a contributed post from Alex Booth, COO, Investis

As a provider of digital corporate communication services to many of the world’s leading companies, information security is of critical importance to us here at Investis. In order to be the world’s safest platform for managing digital communications and hosting corporate sites, we wanted the strongest security partner in the business. As COO of Investis, this was a critical decision which is why I wanted to share the reasons we chose FireEye Managed Defense. To give you the short version, though, the choice was easy - the long version of which you can see in the video below or get a synopsis of in this post…

We are an ISO 27001 certified company and a member of CISP, the UK government’s cybersecurity information partnership. We believe you can never take security too seriously, especially in a digital landscape with increasingly sophisticated cybercrime. With that in mind, we wanted the most advanced solution to protect our environment and clients, and FireEye was the perfect partner to help us safeguard against advanced threats.

FireEye is the cybersecurity partner of choice for many of the US’s largest firms and its subsidiary, Mandiant, was selected by the UK Government Communications Headquarters (GCHQ) as one of four vendors certified to respond to cybersecurity attacks targeting the UK’s national infrastructure.

As a result of an on-site assessment by Mandiant consultants, we chose to augment our security team with the FireEye Managed Defense service.

We are looking forward to working with the great team over at FireEye to ensure we offer our clients the very best in cybersecurity.

Economics of Security Part II: Qualifying the Economic Return From Cybersecurity Solutions

In part one of this series, my colleague, Bryce Boland, CTO, APAC touched on aligning a security program with the value-areas of a business. To be successful in this endeavor, you must calculate the return on investment (ROI) that a robust security program will offer. In part two, I will offer recommendations to achieving this.

The economics of security is an interesting challenge. I polled some contacts and discovered that, as much as we focus on reducing the capex on software and hardware, the majority of costs are actually opex. Therefore if we want to drive efficiencies in security, we should look at the usability (i.e. the time and costs required to achieve the desired outcome) of the tools as much as what they actually do.

Cybersecurity is a multi-dimensional problem, so whilst we consider efficiencies we must look at them in the context of outcomes and value. Our value question in cybersecurity has two factors: (1) are we able to leverage the most efficient path to obtain the solution and (2) being able prioritize on events/incidents that have the greatest business impact.

Simple event/incident response process

The rudimentary processes behind cyber have been around for years and are well documented in various standards. There’s a catalyst event that drives us to understand the problem, so we can qualify and prioritize if and when we need to respond – i.e. solve the problem.

Screen Shot 2014-07-02 at 10.41.08 PM

Are we increasing or decreasing efficiencies?

In recent years many have suggested the logic that “big data” can help us make smart decisions. Yet there is danger that this can create a spiral effect that has the potential to cripple us. By adding more content, we increase the cycles required to understand, qualify and respond. There is also a key question around the quality of that data. Take for example all the events we aggregate into a SIEM tool today, how many of those are truly worth taking action on?

How do we measure success and value?

If we are to evaluate the economic value cyber security solutions bring we need to look less at what they do and instead more how they do it. We need to understand the quality of the information they provide, both in terms of business impact and conversion to action, as well as the operational cycles required to achieve this; which are the cost & time multipliers.

As our technology world complexity continues, the operational aspect as a multiplier can only increase. Today I hear more companies asking for partnerships to solve problems rather than products; they see the time and skills challenge in solving the problem as prohibitive. If we are to succeed today, we need outcome focused solutions; that is they are efficient in providing actionable responses that are business oriented in their focus and/or services that reduce the operation costs associated with time to action. So how do we evaluate this in our buying criteria?

There have been many ROI tools that try to qualify the potential value that come from security investments. However if we are to align to business goals, we must drill into the process behind event correlation/validation – the heart of security – for business impact assessment and response actions.

Qualifying economic value from event/incident management

The framework below aims to give you a reference point to start to map out the economics of your security program.

Given solving this problem is entirely dependent on each individual organization; we must be able to qualify what makes our businesses profitable and how technology enables this. The model does not include metrics in each part of the incident lifecycle but does highlight some of the common key success metrics.

To make economic judgments, you need to assess the following:

  1. What is the ratio between events received and action taken?
  2. What is the efficacy level in the events & incidents you identify (i.e. the real cyber attack event to false positive ratio)?
  3. How many cycles do you iterate through to get from an event(s) to an action; is it timely and cost efficient? (Can you rank the processes/tools you leverage today in terms of man-hours and skills required to get to to action?)
  4. Do you align, prioritize and qualify events against against business goals and impact (How many cycles does this take)?
  5. Make the assessment using the framework & success criteria below to evaluate the key time and cost multipliers in your event/incident security process, so you can validate the economic value that comes from the processes and tools you leverage today, to see which are effective and which are not?
Measures of effectiveness of event/incident management

Measures of effectiveness of event/incident management

In conducting the evaluation process above (and visually outlined above), there is a defined process for tying operational expenditures with investments for securing the processes that generate business value. By analyzing the actions taken to conduct security operations and the, ideally, efficiencies in doing so, security leaders will be able to provide a full picture of their impact on the business. Ultimately, this changes the security conversations from just security to business practices overall.

Economics of Security Part I: Translating Information Security Risks to Business Risk

In this two-part series, my colleague, Greg Day, VP & CTO EMEA and I will focus on making the business case for security solutions that will protect your organization.

One of the many challenges IT Security professionals face is translating the security risks of technologies into the business risks they pose to the company. This translation is critical to building buy-in from your business to fund security initiatives and ensure your projects are funded properly relative to the myriad other things your business is pursuing with its money.

But where should you start? I’ve found that the best place to start is by looking at the processes in the business that generates value. These are the parts of the business that a results-oriented manager will want to protect from threat. By describing security risks in terms of how critical business processes – and their subsequent value generation – could be disrupted, your concern will resonate better with management. Consider the total business value that process generates today – is it 15 percent of the business or 85 percent? Give it a dollar figure. Given your assessment of the likely threat actors and security risks, how much of that value could be destroyed? This is a simple measure of the possible direct or immediate loss that could be experienced – something management are often measured and rewarded on.

Next you can look at knock-on impacts – this too helps speak to the management incentives. If the security risk manifests and creates a specific and significant business impact, would the market, regulators or customers notice? Would the stock price of the company drop as a result? Most business leaders will have a significant and direct interest in market valuation as their remuneration is often closely linked to the company’s stock market performance. Similarly, ask what is the business impact if a security failure leads to a loss of customers, of transaction volume, or increased regulatory scrutiny? Could you face a class action suit?

Sometimes the link between the business value generated and the technology underpinning it is a little hazy, but any modern business process that creates value will leverage and create data. It might be your customer data, the “secret sauce” of your products, a manufacturing capability that ensures your product has the best quality, the output from your R&D team, or perhaps it’s the plans for your next new business. Whatever this data is, and how you depend on it in your business, ensuring it is protected from threats is the difference between success and failure for many companies. Often this data is what the attacker is after. From a business perspective, the reliance on this data to operate the business effectively is how you connect the security risk to the business risk.

What are the most important assets and data in your business that create real value? This is very specific to every business. Think like an attacker: if you were to attack your business, what information would you steal, and why? What could you monetize, use to gain economic advantage, or gain market share? You can assess the value of that asset to your company in terms of potential losses from the dependent business processes, and the value of that asset to an attacker. Then determine how much you should invest to protect against the risks from cybersecurity threats. By going through the process of understanding how data and IT assets are part of the value creation in your business, you actually create the story to help understand the business risk, because you construct the discussion starting from the business process first.

Sometimes the most valuable thing you have is access to your customers. If your customers are large companies, this might make you a springboard to attack a smaller company – and likewise for a larger company your greatest security risks could be exposure to the less security aware vendors in your operations and supply chain. Make sure to consider these scenarios when talking to your business. As larger organizations consider the risks in their supply chain, they will increasingly consider security requirements in MSAs and demand not just compliance but demonstrable security capabilities in their business partners. It is a logical extension of risk management thinking to consider the broader supply chain risks as part of overall business risk management, and this will drive many smaller businesses to invest in improved security capabilities.

More than half the organizations we surveyed do not regularly assess their information security investments in terms of their value relative to the business process they protect. My recommendation is to re-evaluate your investment plan annually, and ensure that your continued security investments are relevant to the threats your business faces. You might also consider using a risk framework like ISO27005 as a tool to help you manage this in a consistent way, to prioritize risks and corresponding investments.

To summarize: understand how and where your business makes its money, illustrate the dependency on technology and data, then explain security risks in terms of the business impact.

In the second part of this series, Greg will discuss how to measure the economic value of your cybersecurity solutions.

Cybersecurity in Heterogeneous Environments: A Podcast with Tom Hankins of Pacific Northwest National Laboratory

As technology continues to evolve and become more cutting edge, it may not initially be as secure as it needs to be. When you consider more heterogeneous environments with multiple operating systems, applications, and considerable open source development, a robust cybersecurity initiative becomes a must.

I recently had the opportunity to sit down with Tom Hankins, Cybersecurity Operations Manager at Pacific Northwest National Laboratory, a part of the Department of Energy (DoE), to discuss the cybersecurity challenges faced by national laboratories, and how to effectively deal with them.

To listen to the podcast in full, click here.

In an increasingly hostile cyber environment, Hankins believes that making the case to senior management to take the cybersecurity plunge shouldn’t be all too difficult: “it’s only hard if you don’t get yourself out of your little cyber cage and present your case. You have to write these things down. You have to come up with a marketing plan, and you have to execute it.” Hankins continued, “the typical pushback is that we’re going to interrupt the business. And while you will be somewhat service interrupting - that does happen - you also need to address how you’re going to get that job done with minimal impact and how the impact of losing integrity, losing availability, losing confidentiality is a much larger problem.”

Tom will present his approach to dealing with these challenges at the Gartner Security & Risk Management Summit, June 23-26 in Washington, DC.

CRN’s “Women of the Channel” Highlights Growing Role in Cybersecurity

In a male dominated industry like cybersecurity, it is not often that women are recognized for their contributions to the field. However, as the industry grows and more women step forward into the field and offer themselves as role models, we hope to see a shift in our industry. FireEye has seen this shift start to happen within our own company with five females at the executive level and eight VPs; and we’re thrilled that this recognition goes beyond our own corporate culture.

This year, CRN announced its Women of the Channel project, which recognized 340 female executives for their accomplishments over the past year, as well as the long-term impact that their work is having on the channel and technology sector. It is a special recognition of those female channel executives who have risen in the ranks of their organizations.

CRN editors were also tasked with selecting 100 executives from that very list for special recognition as “The Power 100: The Most Powerful Women in the Channel,” which honors those who have earned a special distinction, one based on an exemplary record of success, as well as a high level of influence in the channel.

FireEye’s own Kristi Houssiere has been recognized as one of the year’s most influential women in business, and has also been recognized as one of this year’s “Power 100.” She has made a significant impact on the FireEye team and has played a tremendous role in delivering cybersecurity solutions as well as marketing our message and brand with and through the channel.

Kristi Houssiere serves as FireEye’s senior director of global partner marketing, and is responsible for the company’s marketing initiatives and strategies for all indirect routes to market, including alliance and distribution partners. In 2014, she helped advocate and expand FireEye’s highly successful global partner program, “FUEL,” which has reached over 700 partners worldwide. It also continues to drive more than 90 percent of FireEye sales through channel partners.

Robert Faletra, CEO of the Channel Company, had some encouraging words to say about the honorees: “It is our privilege to acknowledge the exceptional achievements of the women in this year’s Power 100.” He continued, “We are committed to raising the visibility of the contributions of women in the channel, and we applaud the far-reaching influence of these executives who are defining today’s channel and helping to shape its future.”

When asked to give advice for young women looking to succeed in the workplace, Kristi stated, “Work to build a solid foundation in selling, as it is essential to any successful career. Ask questions, get involved, listen and create trust with your partners, customers and work teams.”

We are honored to have Kristi at FireEye and hope that her example will lead other women to take hold of the cybersecurity industry.

Introduction to Strategic Thought

I plan to address strategic thought as applied to digital security in a series of posts. Here I would like to briefly introduce the concept and offer a simple example.

Joint Publication 1 (JP-1), Doctrine for the Armed Forces of the United States, helps illuminate the strategic approach to digital security. JP-1 defines three levels of warfare: strategic, operational and tactical. Above the strategic level one can place the overall goal of the digital security program, as one might place the overall goal of a military or political endeavor. Below the tactical level one can similarly place tools or technology – the weapons one might employ when conducting tactical maneuvers. Taken as a whole, the five levels appear as shown in Figure 1.

Figure 1. Five Levels of Strategic Security

Figure 1. Five Levels of Strategic Security

Using a strategic security framework enables a digital defender to build a more effective and durable program. A strategic security system doesn’t start with tools and tactics; instead, it begins by setting one or more overall mission goals. The strategy-minded chief information security officer (CISO) obtains executive buy-in to those goals, which works at a level understood by technicians and non-technicians alike. Next the CISO develops strategies to implement those goals, organizes and runs campaigns and operations to support the strategies, helps his or her team use tactics to realize the campaigns and operations, and procures tools and technology to equip the team.

Figure 2 shows an example of one strategic security approach to minimize loss due to intrusions, using a strategy of rapid detection, response, and containment, along with network security monitoring-inspired operations/campaigns, tactics and tools.

Figure 2. Five Levels of Strategic Security Example

Figure 2. Five Levels of Strategic Security Example

Most security professionals – and by association policymakers and leaders taking advice from those practitioners and engineers – fixate on the tools, and to a lesser degree, the tactics of the digital security problem. Goals, strategies and campaigns aren’t usually a consideration because technicians, administrators, programmers and the like spend their time working with tools. The extent of their tactical involvement is thinking about creative ways to use their tools. The communities that tend to think in terms of goals, strategies and campaigns – think tanks, policy analysts and so on – have traditionally not engaged with the technicians to bring the entire strategic security approach to bear on modern challenges.

As shown in Figure 2, “detecting intruders” is actually shorthand for a rich strategic security program – one whose goal is minimizing loss through a strategy of rapid incident detection, response and containment. Security teams run operations to match threat intelligence against security event data and hunt for novel intruders as needed. They tactically collect, analyze, escalate and resolve incidents and the related data using tools suited for those functions.

It is crucial, however, that the ultimate goals and strategy remained linked with the tools at the bottom of the process. If that chain decouples, the outcome could be disastrous, where technical reality makes strategic theory obsolete. For example, a program built on monitoring the network will fail if all network traffic is encrypted. The tools at the bottom of the process will not be able to “see” the contents of network traffic and will be less effective when trying to identify suspicious and malicious activity. In this dysfunctional case, the tools’ inability to deliver required data to the personnel conducting tactical endeavors and operational campaigns will prevent the program goal from being achieved.

In future posts, I will elaborate on these concepts to demonstrate how they improve enterprise security.

Note: This post is adapted from a research paper by the author, published through The Brookings Institution as Strategy, Not Speed: What Today’s Digital Defenders Must Learn From Cybersecurity’s Early Thinkers.

FireEye Announces the General Availability of Network Threat Prevention Platform with IPS

Today we announced the FireEye Network Threat Prevention Platform with IPS will be available to customers worldwide starting June 2, 2014. This product is available as an add-on license to the FireEye Network Threat Prevention Platform (NX series) appliances, giving customers a holistic view of multi-vector attacks that goes well beyond what conventional intrusion prevention system (IPS) tools offer. The Network Threat Prevention Platform with IPS uses FireEye’s patented Multi-Vector Virtual Execution (MVX) engine technology to better protect systems from known and unknown threats while reining in false-positives. With this new addition, security teams now get compliance and true security in a single box.

Network Threat Prevention Platform with IPS has been in beta for the past several months, including with The Italian Ministry of Foreign Affairs, who had this to say about the new platform add-on:

“We have chosen the FireEye Network Threat Prevention Platform with IPS because it is a solution that allows us to combine advanced threat protection with compliance-driven security needs. We will be able to provide our security team greater visibility into network threats and more effective data to act on by significantly reducing false-positives and -negatives.”

We also heard two interesting anecdotes from other beta customers illustrating how the combination of the FireEye MVX engine with IPS greatly reduces the overhead on security:

  • A large university experienced 732 events per day which we were able to validate and confirm down to 32 being true positives.
  • One large health care provider experienced 1,400 events per day that we then pared down to just 40 as being true positives.

How does Network Threat Prevention Platform with IPS work? When network traffic triggers a signature-based alert, the MVX engine evaluates the traffic in a “real world” environment to confirm whether the threat is real, greatly improving the signal-to-noise ratio. In addition to passing a true alert directly to the alert management system, as traditional IPS does, the MVX engine inspects the corresponding network traffic within instrumented, virtual-machine environments. The MVX engine evaluates activity across the multiple avenues used in advanced attacks. That analysis is integrated with host-based detection and other components of the broader FireEye platform.

For more information on the FireEye Network Threat Prevention Platform with IPS, visit: https://www.fireeyesolution.com/products-and-solutions/network-threat-prevention-platform.html

DoJ Indicts Chinese Military Hackers: First Impressions

Today, the US Department of Justice (DoJ) took actions previously unseen in the world of computer security. The press release announcing the activity noted the following:

“A grand jury in the Western District of Pennsylvania (WDPA) indicted five Chinese military hackers for computer hacking, economic espionage and other offenses directed at six American victims in the U.S. nuclear power, metals and solar products industries.”

The accompanying indictment begins with the following excerpt:

“From at least in or about 2006 up to and including at least in our about April 2014, members of the People’s Liberation Army (“PLA”), the military of the People’s Republic of China (“China”), conspired together and with each other to hack into the computers of commercial entities in the Western District of Pennsylvania and elsewhere in the United States.”

These two sentences are packed with meaning for anyone who has been working to counter the Chinese digital threat, either within, or on behalf of, victim organizations. First, the indictment zeroes in on the military aspect of the threat. DoJ isn’t talking about nebulous “Chinese hackers,” perhaps working as contractors for hire. These are PLA troops, some of whom are pictured in the indictment wearing their uniforms. Second, these sentences confirm the temporal span of the activity, roughly an eight year period. This is a sustained, persistent, resourced campaign. Third, they emphasize economic espionage against commercial American targets, not targets in the US military or intelligence communities. The US government has always been clear that it will not tolerate Chinese hacking to financially and scientifically accelerate Chinese economic growth.

For those of us who worked on exposing this threat over the years, the indictment contains many other relevant details. We read that the five defendants “worked together and with others known and unknown to the Grand Jury for the PLA’s General Staff, Third Department (“3PLA”), a signals intelligence component of the PLA, in a Unit known by the Military Unit Code Designator 61398 (“Unit 61398”), and in the vicinity of 208 Datong Road, Pudong District, Shanghai, China.” This is exactly the same unit, designation, and location identified in the 2013 Mandiant report, APT1: Exposing One of China’s Cyber Espionage Units. This statement is the first open, unclassified, official confirmation of the core attribution element in the Mandiant report. It shows that APT1 aka United 61398 aka the Second Bureau of the Third Department of the General Staff Directorate of the PLA is a threat to US economic and security interests.

There are many other aspects of the indictment that I find fascinating, but in the interest of time I will mention one other. Paragraph four states the following:

“During the period relevant to this Indictment, Chinese firms hired the same PLA Unit where the defendants worked to provide information technology services. For example, one SOE involved in trade litigation against some of the American victims mentioned herein hired the Unit, and one of the co-conspirators charged herein, to build a ‘secret’ database to hold corporate ‘intelligence.’”

This is a remarkable statement, because it may answer one of the burning questions those of us analyzing the problem have often asked: how does stolen Western data pass from the Chinese military to the Chinese private sector? According to the indictment, a State Owned Enterprise (SOE) simply hires Unit 61398 to provide IT services, and the military hackers leave the “intelligence” behind in a “database” for the benefit of the SOE.

As the story develops over the coming days, I will keep an eye on it and report back as newsworthy items appear.

Live from Infosecurity Europe 2014: Cybersecurity Experts Come Together

Infosecurity Europe 2014 was the place to be for any major player in the world of cybersecurity, and live from the show floor; the FireEye Blog team had a front seat to some exciting conversations. Paul Dwyer, director at FireEye, had the opportunity to sit down with a number of influencers and ask questions that were on all of our minds.

In this first podcast in the series, Amar Singh, senior analyst at KuppingerCole, and founder of ARK Advisors discusses the threat of malware, and also touches on the subject of industrial espionage. Click here to listen to the full podcast. Bruce Hallas, founder and curator of The Analogies Project, a not-for-profit venture designed to help the information security community communicate and engage more effectively with stakeholders, joined Paul in our next podcast. Hallas discussed the significance of generational cybersecurity, and outlined the key behaviors and security working practices of generations Y and Z. Click here to listen to the full discussion.

First Base Technologies CEO Pete Wood also sat down with us for a chat, and shared his thoughts on how an information security function evolves to become business-led. Mr. Wood was also asked about the current business security model, and whether cybersecurity should be considered a Board Level issue. Click here to listen.

Finally, FireEye Director of Technology Strategy EMEA, Jason Steer had the chance to speak with Brian Honan from BH Consulting about the recent Internet Explorer (IE) browser vulnerability, as well as the importance of separating networks into different segments. Listen to the full podcast here.

Did you attend Infosecurity Europe 2014? Chime in and let us know what you thought of the event and the topics discussed. Leave us a comment below.