Tuesday, April 2, 2019

Instrumenting OS for Per Process DNS Query Inspection



Background information

Last night at #SANS2019 I attended Jason Fosen’s talk on process hacker and it reminded me of something I forgot to finish several years ago. I’m finalizing and posting now (several years later). This work was originally done on a windows 8 system.
Years ago, really way too long ago, I wrote a post about how to use DNS query logs to create a daily delta report to identify anomalies and novel connections: https://pen-testing.sans.org/blog/2015/07/10/dns-anomaly-analysis-tips-did-you-put-a-new-cover-sheet-on-that-ddd-report/


What's Doing That?
One of the things that I saw during review of the data was a weird DNS request.


Weird unqualified DNS requests. The unqualified version would be followed by the same random string in the search domain of the computer. Usually one or two queries with qualification. Something like biuivlhobb, then biuivlhobb.montance, then biuivlhobb.montance.local, as an example.
I looked into it via some online searches, and it was pretty clearly Google Chrome doing the queries. But, that wasn’t confirmed. So I dug deeper. I started thinking about how I could see inside of a system that a specific process made a DNS query. The OS was handling the query on behalf of a process. So, how could I see which process asked the OS to make that query?
My inquiry lead me to discover that the windows method for making a DNS request is getaddrinfo. The application would use this system call to do the lookup. https://docs.microsoft.com/en-us/windows/desktop/api/ws2tcpip/nf-ws2tcpip-getaddrinfo

So, I lauched process monitor to attempt to review what was actually making the calls.
Process Monitor : https://technet.microsoft.com/en-us/sysinternals/bb896645.aspx






There were two potential files of interest:
               C:\Windows\System32\dnsrslvr.dll
               C:\Windows\System32\dnsapi.dll
              
But, Process Monitor didn't show the details of the actual calls, so looked into APIMonitor:
http://www.rohitab.com/apimonitor

I set the filter to just look at getaddrinfo and related requests in case I missed something.

Killed existing chrome, started again, was able to identify the getaddrinfo requests:


Cool! chrome.dll verified as the source!




Monday, April 1, 2019

Security Operations Class Status


Summary

SANS MGT517 was cancelled and will not return. I will release the material in several ways over the next year: as an online resource (https://soc.montance.com), as an online class, as in person training, and in a project plan book.

Brief Background

I wrote the course that became SANS Management 517 because the two-day course I was a course author of, MGT535 – Managing Incident Response, didn’t seem to fulfill many of the questions that people were asking about. Namely, “How do I interface my incident handling capability to the Security Operations Center?”

Secondarily, there were always questions about the related disciplines of what I eventually called “Self-Assessment Function” within the SOC. How do I use, create, or mature my vulnerability assessment program? How can I convince the IT department to help us by getting a good baseline in place?

Additionally, there was a gap that several people echoed. There were several documents that identified various aspects of Security Operations Centers (SOC), but there was no single reference that said exactly what a SOC was. Carson Zimmerman’s book, and David Nathan’s book were great, but no one had publicly defined capabilities, staffing, the technology involved, and the things that a SOC ingested and what its output was.

What became MGT517 was my attempt to define a reference model around security operations centers (SOC) for organizations to consider. About 500 students attended MGT517 when it was available through SANS. These students were from countries around the world, and from every sector: from manufacturers of goods you use in your home; the companies who make the computers you use; companies who operate the largest cloud infrastructures in the world; companies who build the software that runs most major businesses; security software firms; financial firms; healthcare entities; representatives of governments. Each time I taught the class, there was a chorus of “Thank you.” I can take this back to my organization and say here’s how we should do this. There was a common theme of there not being any other resource or class which covered this topic. There was usually also constructive criticism and valuable insight shared by attendees.

I am disappointed that SANS chose to cancel the class. But what SANS didn’t cancel is my commitment to continue to develop the material. The SOC, and security operations in general is a critical capability for organizations around the world.

I previously mentioned an Analysis of Competing Hypotheses (ACH) write up on why MGT517 was cancelled. It is still underway. It’s going very slowly, but will be published eventually. That matters less than what I’m going to do next, so what follows is that information.

Crowley Motivations

Material Access and Community Value

I want people to see the information I wrote. I think it provides tremendous value because it puts forward a reference model. You’re welcome to disagree with it. In fact, I would say that you must at least consider that the model may not be a good match for your organization.  I’ve tried to envision and account for every possibility. So, the tailoring to your organization is certainly present in such an abstracted and generalized model.

In addition to the security operations class, I am writing a book to provide a project plan for building a SOC. This should provide a very low-cost option for organizations to access the concepts expressed in these various forums and provide a project plan for the organization to build a SOC.

Business Development

I want to work on interesting SOC projects. I’m only a single person, and I won’t have a team of people working for me. Why not? Because I’m not interested in building a company at this time. That takes away from my ability to focus on the subject matter. But that means that I can’t delegate tasks to people and help lots of companies simultaneously.

It means my ability to get involved in projects is very limited if I want to keep my quality level high. My SANS teaching and course development has consumed a large amount of my time for the last three years. I’m taking the time I was exerting for MGT517 course development and shifting it to course development for an online version and an onsite version outside of SANS. I will have time for no more that 3 or 4 contract customers at any given time, if I continue to teach for SANS and try to run a class independently. There’s a risk in attempting to do all of this, as SANS may see this effort as competitive and choose not to ask me to instruct classes. Setting up courses live takes a lot of time and effort, and marketing the classes is a massive uphill battle. Enrollment, payment systems, and onsite logistics are expensive. Life’s a risk.

Actions Planned

Web Resource

I paid a developer to build a website for me to have a forum for SOC discussion by vetted individuals. I haven’t been able to get back to that effort due to so many different things going on. I’ve tried to find an intern to help me to populate content onto the site. If you’re interested in helping me with the initial deployment of material, please let me know. You wouldn’t be writing anything, just populating material into the website. This will be about a 3 month effort. Twitter is the best avenue to start this conversation: @CCrowMontance.

I have a lot of material buried in slide decks that aren’t accessible to people. My intention is to rescue that information from the powerpoints I’ve build and move it to a forum for people to review and for knowledgeable people to have meaningful discussions. My intention is to vet the people who can discuss, but have the discussions be public. I think this is the best way to produce high quality content. Even without community participation, it will be a place where I can share the research and analysis I have done.

Online Class

The easiest way to get access to the material will be an online version available through NetworkDefense.io. The price will be affordable and the material will be adjusted to an online format. Once done, this will run perpetually and will be available on your schedule.

Live Class

This will probably be a three day event, limited to 25 participants. I’ll go to locations that are good options for me and where I think people want the event to run. This will be very much of a DIY effort, and if you’re interested in helping me to run the class or want it as part of your conference, I’ll certainly consider it. Also, private onsite runs are available with a focus on your organization’s specific implementation.

Tentative Scheduled Events & Locations

This list is ambitious, and I suspect several of these classes will not run, but I’ll try to make them all happen.

·        Online: Expected date of initial availability : November 1, 2019
·        December 2-4, 2019 : Washington, DC Area : Security Operations Class – Public Enrollment
·        January 8-10, 2020 : New York City, NY : Security Operations Class – Public Enrollment
·        March, 2020 : Macau or Hong Kong : Security Operations Class – Public Enrollment
·        June, 2020: Europe or Middle East, TBD
·        August, 2020 : Las Vegas : Security Operations Class – Public Enrollment
·        November, 2020: Melbourne, Australia : Security Operations Class – Public Enrollment

I look forward to seeing you there.

Friday, November 30, 2018

Very Good: Not Good Enough

As a follow on to my previous post, I want to address the cancellation of SANS MGT517.

The short story is there will be no additional offering of this course via SANS, and that is a final decision. I will provide training in the Security Operations Center subject matter via some non-SANS vehicle, stay tuned for the exact details around this in 2019.

The class was cancelled because the scores (from the daily feedback forms) were not good enough for SANS. I'm not going to address the relative merit of that decision, but needless to say I'm disappointed. 

Nonetheless, I think the content I wrote for MGT517 is very valuable to the community, and most of the students who have taken the class have expressed their appreciation of the material, and how it has helped them.

That's all I have for now. Next update after the new year.

Sunday, October 7, 2018

File under #Failure: MGT517 cancelled

Personal failure is always tough to acknowledge. MGT517 has been cancelled from any future runs. There are three remaining in 2018, and none scheduled in the future: https://www.sans.org/mgt517

Standby here for my analysis of this situation and what lead to it. I will also include some speculation on next steps. Expected time frame is mid-November.

Sunday, August 5, 2018

2018 Security Operations SOC Summit wrap up


2018 SOC Summit is finished, the MGT517 following it is almost done. I'm enjoying co-teaching it with Carson Zimmerman. It's his first time out, and I've enjoyed hearing his perspectives on the material.

I'll hit the high points from the talks with my favorite take away from each. For the TL;DR, have a few memes from the talks.

You should download the talks from here:
https://cyber-defense.sans.org/resources/summit-archives

Carson:
. Measure not just the breadth of your log collection, but the depth
. Unit test your SIEM rules / use cases
. Track your SIEM use case analyst quality
. Analyst baseball card

Shelly & Brett
. Establish Trust and protect it
. Scribe to collect and report: but everyone is repsonsible for taking notes!

Alissa
. Insight into the state of your potential hires. Go read what they are saying about their prospects.
. Chaos is not for everyone
. Bad apples spread bacteria
. Let Alissa talk to your SOC analysts! Figure out the problems and address them.

SOC Survey
. Hard to collect data, and we don't have a defined data set, but here are the highlights for this year's survey.
. Tune in for the webcasts and download the paper.

CompariSIEM
. tools matter, but making the most of the tool is the path to success

FOOD, not FUD
. Framework of 5 items to provide Factual, Objective, Optimized Data

Sun or Stars
. Challenges are abundant, few organizations are thinking about striving for what's best for the long term

Hacking your SOEL:
. Move the activity to the front of the response activity

All about your Assets:
. Identify tools that contain the information you need, and figure out how to connect those tools together

The Healthy SOC: A Case Study:
. I'm going to ask you next year to come give a presentation about how you moved from where you are today to what you are next year. Will we be impressed? ;)


-=-=-=-=-=- ~Day 2~ -=-=-=-=-=-

What the CISO Really Wants
. Have an in person conversation once a month with no computers, no technology, where you listen to understand

Building the SecOps Use Case:
. Develop the program for building and assessing use cases, starting with business use

Back to Basics: System Integrity
. Integrity Monitoring is important for identifying change

TTP Zero:
. Normalize the data to constrained conecpts to effectively and consistenly deliver the message on security operations

Technical to Managerial positions:
. It's a different skillset, you probably can't be both

Threat Hunting Tour de Force
. Start with ad hoc techniques then migrate them into procedures

Burning Down the Haystack
. operational tasks should be operational, identify pain points and fix them

Most Dangerous Game:
. Assess if you have full coverage using ATT&CK

Monday, April 2, 2018

Metrics, metrics, everywhere and not a lot of thinking

Someone sent me a personal e-mail asking for guidance on metrics, so I thought I would replicate that here publicly.

Also, Carson Zimmerman will keynote at the SOC Summit in New Orleans in August, 2018 with a talk specifically on metrics. Hopefully you can make it to that event. If you can't make it, you can check out that talk afterward via video.

When starting out, I'd pick 3-5 reported metrics and a couple of service level objectives to start. Too many metrics results in diminished clarity on if you're meeting the objectives of the organization.
Metric
. Time to detection
. Method of Detection
. Time to initiate Response
.  Root cause analysis: Level 1,2,3. 
1 is a measure was available, but wasn't applied
2 is a measure was available, we chose through risk acceptance not to apply and it allowed issue to occur
3 is "zero day" - no measure was available
Service Level Objectives
. Initial notification within 1 hour to system owners of affected systems
. Eradication results in final closure, no need to reopen 100% of time


Online resource, look at Veris, which is the data schema behind the Verizon DBIR:

Look at Pescatore's "briefing the board" info:

For a book to read on metrics, the standard reference is Joqaith's Security Metrics:

Also look at the Hubbard / Siersen  "how to measure risk" book. Rich gave a talk last year at the SOC summit, but I don't see the talk posted. 




Sunday, September 17, 2017

File under #failure

Equifax announced a massive breach of tax payer information.

TL;DR : Lock your credit accounts:

https://www.experian.com/freeze/center.html#content-01
https://www.innovis.com/securityFreeze/index
https://www.transunion.com/credit-freeze/place-credit-freeze2
https://www.freeze.equifax.com/Freeze/jsp/SFF_PersonalIDInfo.jsp


Basic recommendation, freeze your credit report. This does two things. First, it protects you. Second, if most US taxpayers freeze their credit it will change the way these companies do business. They're collecting information about you and reselling it to third parties. They'll charge you a fee (credit monitoring) to protect that information. In my opinion it is perverse that they'll only protect your information for a fee. It will be interesting to see how the class action law suits which follow will shape the credit monitoring services.

I'm also interested in how the Internal Revenue Service (IRS) of the United States addresses this. They've been pretending for two decades too long that the social security number is somehow a shared secret. It is not. Time to re-key, IRS. You have suffered a data breach through an irresponsible vendor partner. You've allowed these vendors to leverage your information for far too long. Fix this broken system.