Privileged Identities

Privileged Identities

Learning what is at the core of online attacks

Over the last year, we have witnessed a series of staggering data breaches affecting some of the world’s leading businesses— with each breach seemingly worse than the last in terms of financial and reputational damage.

Following intrusions into Target, JP Morgan, Sony Pictures and others, many people are asking “has it reached the point where no system is ever fully protected from hackers?”

The unfortunate answer to this question is that if an intruder wants into your network—they will get in—no matter how many perimeter defenses you build around your IT infrastructure. It is vital for IT departments to anticipate that their systems will be breached, and their most sensitive data could be stolen and made public.

Therefore, the real question that corporate executives should be asking themselves is: what can be done to minimize the damage of a cyberattack on my organization?

The Keys to Your IT Kingdom, Privileged Identities

The lesson from the recent Sony Pictures hack is that organizations that do not have a security solution which can limit damage internally are taking remarkable risks and acting extraordinarily naive about the advanced capabilities of today’s cyber attackers.

That’s because one of the most common ways for cybercriminals to gain access to systems is through unsecured privileged accounts. Privileged accounts provide the access needed to view and extract critical data, alter system configuration settings, and run programs on just about every hardware and software asset in the enterprise.

Almost every account on the network has some level of privilege associated with it and can potentially be exploited by a hacker. For example, business applications and computer services store and use privileged identities to authenticate with databases, middleware, and other application tiers when requesting sensitive information and computing resources.

In fact, there are so many privileged accounts in large enterprises that many organizations don’t even know where all of their privileged accounts reside—or who has access to them.

Unlike personal login credentials, privileged identities are not typically linked to any one individual and are often shared among multiple IT administrators with credentials that are rarely—if ever—changed.

The Privileged Account Attack Vector

Cyber attackers need privileged access to carry out their illicit plans—whether it’s to install malware or key loggers, steal or corrupt data, or disable hardware. That’s why privileged account credentials are in such high demand by hackers. In fact, research conducted by Mandiant revealed that 100 percent of the data breaches they investigated involved stolen credentials.

A destructive data breach can begin with the compromise of just one privileged account. Criminal hackers and malicious insiders can exploit an unsecured privileged account to gain the persistent administrative access they need to anonymously extract sensitive data.

As stated previously, if attackers want to get into your environment, they will— and there’s really no way to prevent it short of creating an “air gap” to isolate your most critical systems from the rest of your network. Conventional perimeter security tools that most organizations rely on, like firewalls, react too late to defend against new advanced persistent threats and zero day attacks.

So, the issue is not whether attackers will penetrate your perimeter, but what will happen once they’re in. The first thing they will do is look for ways to expand their access. Usually remote access kits, routers and key loggers are installed. The intruder’s goal is to extract the credentials that will give them lateral motion throughout the network.

To accomplish this, attackers look for SSH keys, passwords, certificates, Kerberos tickets and hashes of domain administrators on compromised machines. Often, hackers will quietly monitor and record activity on the systems, and then use this information to expand their control of the IT environment.

This is the classic “land and expand” attack, and the entire activity can be completed in about 15 minutes. It doesn’t take long because most of these attacks use automated hacking tools.

Next Generation Adaptive Privilege Management

Given the fact that your adversaries are using highly advanced automated tools to attack, shouldn’t you match their efforts with your own automated security solutions?

Adaptive privilege management is an automated cyber defense solution that proactively secures privileged accounts in response to a stimulus. For example, an organization’s logger, SIEM, or trouble ticket system reports an anomaly. Then, the adaptive privilege management solution uses that information to look up the address—say, in LDAP or a configuration management database (CMDB)—to determine what is being targeted.

If the organization under attack has a hundred sets of systems, the adaptive privilege management solution might have a hundred password change jobs in place to manage those credentials. Based on the outside stimulus, the solution can call PowerShell or another web service with the appropriate password change job and begin immediate remediation.

Adaptive privilege management works in conjunction with detect-and-respond software to react to notifications that those products produce, and immediately change the credentials on systems under attack. Every time the intrusion detection system spots a new event, the credentials are changed again.

The goal is to block intruders by responding with new credentials as soon as any logins are compromised. Essentially, when hackers harvest a credential, the solution deploys new credentials—effectively minimizing lateral motion inside the environment, even in zero day attack scenarios.

The basic idea is continuous detection and remediation. Adaptive privilege management automatically discovers privileged accounts throughout the enterprise, brings those accounts under management, and audits access to them.

Remember, if you can’t find the privileged accounts on your network, you can’t secure them. But just because you may not know where all of your privileged accounts reside, that doesn’t mean the bad guys can’t locate these powerful accounts—and leverage them to execute their cyberattacks.

The reality of today’s cyber security landscape is that attackers can breach your network regardless of your countermeasures. Fortunately, with adaptive privilege management you can remediate security threats faster than cyber attackers can exploit them.

This article originally appeared in the August 2015 issue of Security Today.

Featured

  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Survey: Only 13 Percent of Research Institutions Are Prepared for AI

    A new survey commissioned by SHI International and Dell Technologies underscores the transformative potential of artificial intelligence (AI) while exposing significant gaps in preparedness at many research institutions. Read Now

  • Survey: 70 Percent of Organizations Have Established Dedicated SaaS Security Teams

    Seventy percent of organizations have prioritized investment in SaaS security, establishing dedicated SaaS security teams, despite economic uncertainty and workforce reductions. This was a key finding in the fourth Annual SaaS Security Survey Report: 2025 CISO Plans and Priorities released today by the Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

  • Mobile Applications Are Empowering Security Personnel

    From real-time surveillance and access control management to remote monitoring and communications, a new generation of mobile applications is empowering security personnel to protect people and places. Mobile applications for physical security systems are emerging as indispensable tools to enhance safety. They also offer many features that are reshaping how modern security professionals approach their work. Read Now

Featured Cybersecurity

Webinars

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation. 3