The threat from ransomware continues to be an unfortunate daily reality for technologists and security professionals. But, before we talk about “doom and gloom” we should recognize how far the industry has come. I would argue in the not too distant past, most companies were susceptible to what we would consider a relatively unsophisticated ransomware attack. Open Email -> Malware -> Network spread -> Ransomware ->
Dank der Fortschritte vor allem im Bereich der Endgeräte, der zunehmenden Verbreitung des „Work from Anywhere“-Konzepts und der Zero-Trust-Prinzipien hat die Branche erhebliche Fortschritte beim Schutz vor dieser Art von Angriffen erzielt.
Still, every week we see new articles on successful ransomware attacks. Many ransomware report trackers actually show an uptick in 2023. For instance Black Fog’s The Bericht zur aktuellen Lage bei Ransomware shows an 8% uptick year over year. In addition, we see actors starting to target data storage outside of what traditionally is attacked, such as cloud storage and cloud databases.
„Wenn wir wirklich Fortschritte im Kampf gegen Ransomware erzielt haben, warum nehmen dann die erfolgreichen Angriffe zu?“
Es kommt ganz auf die Prioritäten an
In analyzing these successful attacks, I’ve identified two primary categories where the system breaks down, allowing malicious actors to succeed in ransom style attacks.
- Lack of investment in an information security program. At the surface this seems obvious, and it is. You pay for what you get. Organizations with big-budget security teams suffer fewer ransomware attacks (with exception discussed in the next category).It’s easy to put on your curmudgeon hat and say “Well people just need to take this more seriously, and spend more on security!” The reality is most attacks we see in the news resulting from a lack of investment are against public services. Many of these organizations are simply not financially equipped to invest in the staff, time, and “cutting edge” technologies that can stop attacks. I’m going to end the thought there as it’s a different blog on politics, public policy, and unification. Public spending is not a topic that can be glazed over. But, the next category we as an industry can tackle more easily.
- Wir haben Scheuklappen auf. Mir ist klar, dass das eine gewagte Behauptung ist, aber wenn man das Thema richtig angeht, höre ich oft, dass dies tatsächlich der Fall ist.
Wenn ich sage, wir haben Scheuklappen auf, meine ich damit, dass wir das Risikomodell von Ransomware nicht vollständig durchleuchten. Wir konzentrieren uns zu sehr darauf, wie gängige Angriffe erfolgreich waren, um zu erkennen, wo Lücken in unseren Sicherheitsprogrammen bestehen. Wir legen den Schwerpunkt auf den Schutz von Endgeräten, Servern und herkömmlichen Datenspeichertechnologien (SAN, NAS usw.) und schaffen es dadurch, diese Ressourcen erfolgreich vor Angriffen zu schützen.
„Letztendlich muss ein Angreifer, der Daten gegen Lösegeld zurückhalten will, nur eine einzige Aufgabe erfüllen: die Verfügbarkeit kritischer Geschäftsdaten zu unterbinden.“
Many companies are more focused on controls for preventing attacks than implementing a holistic strategy to protect availability. In other words, don’t focus only on the ransomware attack, focus on a more general availability protection strategy inclusive of “data encryption for impact” (ATT&CK ID T1486) umfasst.
For example, many ransomware playbooks are focused on the idea that an actor could execute a binary payload and encrypt data. But the same effect could be achieved, given sufficient access, by simply swapping encryption keys on a critical database. The degree of difficulty for an attacker to pull this off varies wildly, but for many organizations it is a valid attack path. Don’t be too quick to point out that native DB backups, multi-versioning etc. can solve this. It’s not wrong by any means, but the reality is that due to performance impacts on large databases, these controls are often disabled and you may or may not be informed. In addition, management of these protection methods are often done from the same privileged credentials as normal admin activity, which are the credentials targeted by threat actors.
Okay…. but what does that mean…
All in all, it means you should revisit your ransomware playbook and consider making a top-level availability playbook if you don’t have one already (If you do, revisit it with a ransom lens). This should be a cross-functional effort. The security team should take a first pass, then sit down with data owners, infrastructure teams, and DR/BC teams to brainstorm on the most realistic protection and recovery methods. Many protection and recovery methods come with a performance trade off. Security can not ignore this reality, and IT can’t ignore security in favor of performance. There is no one size fits all answer.
Folgendes kann als grober Anhaltspunkt dafür dienen, worüber man bei diesen Bemühungen nachdenken sollte:
- Verstehen Sie alle wichtigen Geschäftsdatenspeicher, darunter:
- “Private” managed data stores, NAS SAN
- Mitarbeitergeräte
- Databases (both on-prem, traditional cloud abstraction, and as-a-service
- Cloud-Speicher
- Erstellen Sie eine Liste von Taktiken, Techniken und Vorgehensweisen, die dazu genutzt werden können, die Verfügbarkeit Ihrer kritischen Datenspeicher zu beeinträchtigen, und ordnen Sie diese dem MITRE ATT&CK-Modell zu. (https://attack.mitre.org/tactics/TA0040/)
- Beispiel 1: Massenverschlüsselung von Endgeräten
- Beispiel 2: Diebstahl und Löschung kritischer Datenspeicher (Cloud und lokal)
- Ordnen Sie den Datenquellen Taktiken zu und stufen Sie diese nach ihrer Eintrittswahrscheinlichkeit ein.
- Priorisierung anhand rechtlicher, operativer und strategischer Risiken
- Kontrollen und Prozesse bewerten
- Ermitteln Sie nach Datenquelle, wo Möglichkeiten zur Einführung von Kontrollmaßnahmen zur Prävention, Erkennung, Reaktion und Recovery bestehen.
- Lücken ermitteln
- Neue Prozesse und Kontrollmaßnahmen schaffen
- Ergänzen Sie Ihren Leitfaden zur Reaktion auf Ransomware um Maßnahmen für alle Angriffstechniken, die auf Ihren Reaktions- und Recovery-Verfahren aus Schritt 4 basieren.
- Führen Sie gleichzeitig eine gemeinsame Table-Top-Übung (TTX) und eine DR-Übung durch.
- This is a real challenge. Combining the two to perform a “open book” TTX with some random injects will really show how the teams work under the pressure of a real ransomware incident.
Zusammenfassung
Threat actors keep evolving to stay relevant and protect their income. Although we have gotten pretty good at protecting against traditional ransomware threats as an industry, every organization likely has a few blind spots.
- Ransomware attacks keep succeeding.
- As we get better at stopping traditional attacks, threat actors change their tactics to maintain success
- Threat actors are targeting data stores such as DBs and cloud storage
- Ergänzen Sie Ihr Reaktionshandbuch um Maßnahmen zur Erkennung, Prävention, Reaktion und Recovery für nicht-traditionelle Verfügbarkeits-Recovery.
- Implementieren Sie unveränderliche und leistungsstarke Backup-Lösungen für Datenbanken und Cloud-Ressourcen.
Wie Clumio hilft
Clumio focuses on helping customers build resilience into their cloud applications and data. When it comes to ransomware, recovery is a key backstop to maintaining your business application availability. With Clumio’s backup options for databases like Amazon RDS, MS-SQL on EC2, and DynamoDB as well as Amazon S3, EC2, EBS, and Microsoft 365, you can create performant recovery strategies to make both infrastructure and security teams happy.