The threat from ransomware continues to be an unfortunate daily reality for technologists and security professionals. But, before we talk about “doom and gloom” we should recognize how far the industry has come. I would argue in the not too distant past, most companies were susceptible to what we would consider a relatively unsophisticated ransomware attack. Open Email -> Malware -> Network spread -> Ransomware ->
Grazie ai progressi registrati soprattutto nel settore degli endpoint, all’adozione del lavoro da qualsiasi luogo e ai principi dello zero trust, il settore ha compiuto notevoli passi avanti nella protezione contro questo tipo di attacchi.
Still, every week we see new articles on successful ransomware attacks. Many ransomware report trackers actually show an uptick in 2023. For instance Black Fog’s The State of Ransomware report shows an 8% uptick year over year. In addition, we see actors starting to target data storage outside of what traditionally is attacked, such as cloud storage and cloud databases.
“”If we truly have made advances against ransomware, why the increase in successful attacks?“”
È tutta una questione di priorità
In analyzing these successful attacks, I’ve identified two primary categories where the system breaks down, allowing malicious actors to succeed in ransom style attacks.
- Lack of investment in an information security program. At the surface this seems obvious, and it is. You pay for what you get. Organizations with big-budget security teams suffer fewer ransomware attacks (with exception discussed in the next category).It’s easy to put on your curmudgeon hat and say “Well people just need to take this more seriously, and spend more on security!” The reality is most attacks we see in the news resulting from a lack of investment are against public services. Many of these organizations are simply not financially equipped to invest in the staff, time, and “cutting edge” technologies that can stop attacks. I’m going to end the thought there as it’s a different blog on politics, public policy, and unification. Public spending is not a topic that can be glazed over. But, the next category we as an industry can tackle more easily.
- We have on blinders. I understand this is a big statement, but when the topic is approached correctly, I often hear vigorous agreement that this is the case.
Quando dico che abbiamo i paraocchi, intendo dire che non stiamo esaminando a fondo il modello di rischio del ransomware. Siamo troppo concentrati su come gli attacchi più comuni abbiano avuto successo per individuare le lacune nei nostri programmi di sicurezza. Ci concentriamo sulla protezione degli endpoint, dei server e delle tecnologie tradizionali di archiviazione dei dati (SAN, NAS ecc.) e, di conseguenza, riusciamo a proteggere tali risorse dagli attacchi.
“At the end of day, a threat actor who wishes to hold data for ransom only has to accomplish one task: deny availability of critical business data.“
Many companies are more focused on controls for preventing attacks than implementing a holistic strategy to protect availability. In other words, don’t focus only on the ransomware attack, focus on a more general availability protection strategy inclusive of “data encryption for impact” (ATT&CK ID T1486.)
For example, many ransomware playbooks are focused on the idea that an actor could execute a binary payload and encrypt data. But the same effect could be achieved, given sufficient access, by simply swapping encryption keys on a critical database. The degree of difficulty for an attacker to pull this off varies wildly, but for many organizations it is a valid attack path. Don’t be too quick to point out that native DB backups, multi-versioning etc. can solve this. It’s not wrong by any means, but the reality is that due to performance impacts on large databases, these controls are often disabled and you may or may not be informed. In addition, management of these protection methods are often done from the same privileged credentials as normal admin activity, which are the credentials targeted by threat actors.
Okay…. but what does that mean…
All in all, it means you should revisit your ransomware playbook and consider making a top-level availability playbook if you don’t have one already (If you do, revisit it with a ransom lens). This should be a cross-functional effort. The security team should take a first pass, then sit down with data owners, infrastructure teams, and DR/BC teams to brainstorm on the most realistic protection and recovery methods. Many protection and recovery methods come with a performance trade off. Security can not ignore this reality, and IT can’t ignore security in favor of performance. There is no one size fits all answer.
Quanto segue può servire come punto di partenza indicativo per orientarsi in questo percorso:
- Comprendere tutte le risorse di archiviazione dei dati aziendali critici, tra cui:
- “Private” managed data stores, NAS SAN
- Dispositivi dei dipendenti
- Databases (both on-prem, traditional cloud abstraction, and as-a-service
- Cloud di archiviazione
- Creare un elenco di tattiche, tecniche e procedure che possono essere utilizzate per compromettere la disponibilità dei propri archivi di dati critici e mapparle al modello MITRE ATT&CK. (https://attack.mitre.org/tactics/TA0040/)
- Esempio 1: Crittografia di massa degli endpoint
- Esempio 2: Furto e cancellazione di archivi di dati critici (nel cloud e in locale)
- Assegnare le tattiche alle fonti di dati e classificarle in base alla probabilità che si verifichino.
- Stabilire le priorità in base al rischio legale, operativo e strategico
- Valutare i controlli e i processi
- Individuare le opportunità di implementare controlli finalizzati alla prevenzione, all’individuazione, alla risposta e a Recovery per ciascuna fonte di dati.
- Individuare le lacune
- Creare nuovi processi e controlli
- Aggiorna il tuo manuale di risposta al ransomware con le modalità di risposta a tutte le tecniche, sulla base delle procedure di risposta e Recovery definite nella fase 4.
- Condurre contemporaneamente un’esercitazione teorica congiunta (TTX) e un’esercitazione di DR.
- This is a real challenge. Combining the two to perform a “open book” TTX with some random injects will really show how the teams work under the pressure of a real ransomware incident.
Sintesi
Threat actors keep evolving to stay relevant and protect their income. Although we have gotten pretty good at protecting against traditional ransomware threats as an industry, every organization likely has a few blind spots.
- Ransomware attacks keep succeeding.
- As we get better at stopping traditional attacks, threat actors change their tactics to maintain success
- Threat actors are targeting data stores such as DBs and cloud storage
- Aggiorna il tuo piano di risposta con opzioni di rilevamento, prevenzione, risposta e Recovery per il ripristino della disponibilità non tradizionale
- Implementa soluzioni di backup immutabili e ad alte prestazioni per database e risorse cloud.
In che modo Clumio può aiutarti
Clumio focuses on helping customers build resilience into their cloud applications and data. When it comes to ransomware, recovery is a key backstop to maintaining your business application availability. With Clumio’s backup options for databases like Amazon RDS, MS-SQL on EC2, and DynamoDB as well as Amazon S3, EC2, EBS, and Microsoft 365, you can create performant recovery strategies to make both infrastructure and security teams happy.