The threat from ransomware continues to be an unfortunate daily reality for technologists and security professionals. But, before we talk about “doom and gloom” we should recognize how far the industry has come. I would argue in the not too distant past, most companies were susceptible to what we would consider a relatively unsophisticated ransomware attack. Open Email -> Malware -> Network spread -> Ransomware ->
Gracias a los avances, sobre todo en el ámbito de los dispositivos finales, a la implantación del teletrabajo desde cualquier lugar y a los principios de «confianza cero», el sector ha logrado avances significativos en la protección frente a este tipo de ataques.
Still, every week we see new articles on successful ransomware attacks. Many ransomware report trackers actually show an uptick in 2023. For instance Black Fog’s The State of Ransomware report shows an 8% uptick year over year. In addition, we see actors starting to target data storage outside of what traditionally is attacked, such as cloud storage and cloud databases.
“”If we truly have made advances against ransomware, why the increase in successful attacks?“”
Todo es cuestión de prioridades
In analyzing these successful attacks, I’ve identified two primary categories where the system breaks down, allowing malicious actors to succeed in ransom style attacks.
- Lack of investment in an information security program. At the surface this seems obvious, and it is. You pay for what you get. Organizations with big-budget security teams suffer fewer ransomware attacks (with exception discussed in the next category).It’s easy to put on your curmudgeon hat and say “Well people just need to take this more seriously, and spend more on security!” The reality is most attacks we see in the news resulting from a lack of investment are against public services. Many of these organizations are simply not financially equipped to invest in the staff, time, and “cutting edge” technologies that can stop attacks. I’m going to end the thought there as it’s a different blog on politics, public policy, and unification. Public spending is not a topic that can be glazed over. But, the next category we as an industry can tackle more easily.
- We have on blinders. I understand this is a big statement, but when the topic is approached correctly, I often hear vigorous agreement that this is the case.
Cuando digo que tenemos las anteojeras puestas, me refiero a que no estamos analizando a fondo el modelo de riesgo del ransomware. Estamos demasiado centrados en cómo han tenido éxito los ataques más habituales como para detectar dónde tenemos lagunas en nuestros programas de seguridad. Nos centramos en la protección de los terminales, los servidores y las tecnologías tradicionales de almacenamiento de datos (SAN, NAS, etc.) y, en consecuencia, logramos proteger esos activos frente a los ataques.
“At the end of day, a threat actor who wishes to hold data for ransom only has to accomplish one task: deny availability of critical business data.“
Many companies are more focused on controls for preventing attacks than implementing a holistic strategy to protect availability. In other words, don’t focus only on the ransomware attack, focus on a more general availability protection strategy inclusive of “data encryption for impact” (ATT&CK ID T1486).
For example, many ransomware playbooks are focused on the idea that an actor could execute a binary payload and encrypt data. But the same effect could be achieved, given sufficient access, by simply swapping encryption keys on a critical database. The degree of difficulty for an attacker to pull this off varies wildly, but for many organizations it is a valid attack path. Don’t be too quick to point out that native DB backups, multi-versioning etc. can solve this. It’s not wrong by any means, but the reality is that due to performance impacts on large databases, these controls are often disabled and you may or may not be informed. In addition, management of these protection methods are often done from the same privileged credentials as normal admin activity, which are the credentials targeted by threat actors.
Okay…. but what does that mean…
All in all, it means you should revisit your ransomware playbook and consider making a top-level availability playbook if you don’t have one already (If you do, revisit it with a ransom lens). This should be a cross-functional effort. The security team should take a first pass, then sit down with data owners, infrastructure teams, and DR/BC teams to brainstorm on the most realistic protection and recovery methods. Many protection and recovery methods come with a performance trade off. Security can not ignore this reality, and IT can’t ignore security in favor of performance. There is no one size fits all answer.
Lo siguiente puede servir como punto de partida orientativo sobre qué aspectos hay que tener en cuenta en esta iniciativa:
- Conocer todos los almacenes de datos críticos para el negocio, entre los que se incluyen:
- “Private” managed data stores, NAS SAN
- Dispositivos de los empleados
- Databases (both on-prem, traditional cloud abstraction, and as-a-service
- Almacenamiento en la nube
- Elabora una lista de tácticas, técnicas y procedimientos que puedan utilizarse para afectar a la disponibilidad de tus almacenes de datos críticos y asóyalos al marco MITRE ATT&CK. (https://attack.mitre.org/tactics/TA0040/)
- Ej. 1: Cifrado masivo de dispositivos finales
- Ejemplo 2: Robo y eliminación de almacenes de datos críticos (en la nube y en las instalaciones)
- Asignar las tácticas a las fuentes de datos y clasificarlas según la probabilidad de que se produzcan.
- Establecer prioridades en función del riesgo jurídico, operativo y estratégico
- Evaluar los controles y los procesos
- Identificar oportunidades para implementar controles de prevención, detección, respuesta y Recovery por fuente de datos.
- Identificar las deficiencias
- Crear nuevos procesos y controles
- Actualiza tu manual de respuesta ante ataques de ransomware con métodos de respuesta para todas las técnicas, basándote en tus procedimientos de respuesta y Recovery del paso 4.
- Llevar a cabo simultáneamente un ejercicio de simulación (TTX) y un ejercicio de recuperación ante desastres (DR).
- This is a real challenge. Combining the two to perform a “open book” TTX with some random injects will really show how the teams work under the pressure of a real ransomware incident.
Resumen
Threat actors keep evolving to stay relevant and protect their income. Although we have gotten pretty good at protecting against traditional ransomware threats as an industry, every organization likely has a few blind spots.
- Ransomware attacks keep succeeding.
- As we get better at stopping traditional attacks, threat actors change their tactics to maintain success
- Threat actors are targeting data stores such as DBs and cloud storage
- Actualiza tu manual de respuesta con opciones de detección, prevención, respuesta y Recovery para la recuperación de la disponibilidad no tradicional.
- Implementa soluciones de copia de seguridad inmutables y de alto rendimiento para bases de datos y activos en la nube.
Cómo ayuda Clumio
Clumio focuses on helping customers build resilience into their cloud applications and data. When it comes to ransomware, recovery is a key backstop to maintaining your business application availability. With Clumio’s backup options for databases like Amazon RDS, MS-SQL on EC2, and DynamoDB as well as Amazon S3, EC2, EBS, and Microsoft 365, you can create performant recovery strategies to make both infrastructure and security teams happy.