Showing posts with label Social Engineering Attacks. Show all posts
Showing posts with label Social Engineering Attacks. Show all posts

Sunday, October 30, 2011

Symantec Reports Concerted Attacks on Chemical Companies

A report that will be ‘released’ tomorrow by Symantec (available on their site now) outlines what they are calling the ‘Nitro Attacks’ on information assets of a number of chemical companies. The attacks were (conducted from late-July to mid-September of this year) apparently an attempt to gather “intellectual property such as design documents, formulas, and manufacturing processes [emphasis added]” (pg 1). This may be being done just to gain a competitive advantage (China is mentioned but not accused in the report), but there may be a more control-system security-related reason as well (my opinion not Symantec’s).

With W32.Duqu apparently targeting industrial equipment suppliers (As do apparently the Nitro Attacks; Symantec lists among the target companies those “involved in developing manufacturing infrastructure for the chemical and advanced materials industry) and now someone trying to gain information on chemical processes, one begins to suspect (only a bit of paranoia here) that a combination of the two types of information may allow for targeted attacks on chemical control systems.

A side note to authors Chien and O-Gorman: I like the term ‘manufacturing infrastructure’ much better than ‘industrial industry manufacturers’. Are they both describing similar targets?

While I have long maintained that multiple-random PLC manipulations will suffice for successful attack on a chemical processing system, I must note that for a truly catastrophic attack on a chemical facility, one must understand both the process system/equipment and the methodology of the attack. These two recent attacks on chemical manufacturing related targets makes me think that someone else (with less benign intentions) agrees with me.

In any case, I encourage everyone in the chemical processing industry to read this Symantec report. Not only does it provide an important warning about the targeting of that industry, it also provides a nicely detailed description of how one goes about executing a social engineering attack on a specific industry.

BTW: I was pointed at this publication by a TWEET by @danchodanchev.

Tuesday, August 16, 2011

ICS-CERT Updates Honeywell ScanServer Advisory


Yesterday afternoon the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an update on an advisory that was originally published last April. The revised advisory updates the researcher attribution, vulnerability details, and new mitigation information.

The update identifies Secunia as the ‘security researcher’ that originally identified this vulnerability and provides links to two different Secunia pages about the vulnerability. While this information is important to Secunia (and probably the rest of the security research community) the more important bit of information included in this updated is the Microsoft mitigation measure identified (the availability of an Active X killbit for the control exploited in this vulnerability).

Social Engineering Exploit


Still, the most important thing about this vulnerability, and most vulnerabilities involving ActiveX controls, is that not only does it involve a control system software issue, but it requires the active involvement of someone at the facility. No, not an insider attack, but someone accessing a malicious web site. These web sites are not going to be randomly surfed by the facility employee/contractor; they are going to be drawn to the web site by a social engineering attack.

While the mitigation measures provided by Honeywell and Microsoft for this particular attack will allow facilities to avoid this particular problem, a more important mitigation measure would be to train (and re-train frequently) all employees with control system access on how to identify and avoid social engineering attacks. That would help to prevent exploitation of this vulnerability and a whole host of yet to be identified zero-day vulnerabilities in this and other control systems.

Sunday, August 14, 2011

Social Engineering Attacks and LinkedIn


I’ve mentioned social engineering attacks as a method that attackers may use to get access to relatively secured networks. While many social engineering attacks are bulk type attacks, targeted at anyone in an organization, we have been hearing more and more about targeted attacks. These attacks are targeted at specific people in an organization, control systems engineers or technicians for instance.

The question often arises how do attackers select the targets of the spear phishing attacks? Well one way is through the perusal of social networking sites; particularly the professional sites liked Linkedin.com. In the modern networked society in which we operate it would be a waste of time to recommend that personnel in security sensitive positions for go the use of these sites; too much valuable information is exchanged via this medium.

No, what every security expert that I have heard over the last couple of years say is that everyone should be careful about the information that they share on these sites and who they share it with. Frequently this is easier said than done as the managers of these sites are not really concerned about secondary security issues like providing information that could be used in developing a targeted social engineering attack to gain access to an industrial control system.

I had an interesting bit of information shared with me by a long time reader. It seems that LinkedIn has learned a new marketing trick from Facebook. Linked in describes it this way:

LinkedIn may sometimes pair an advertiser's message with social content from LinkedIn's network in order to make the ad more relevant. When LinkedIn members recommend people and services, follow companies, or take other actions, their name/photo may show up in related ads shown to you. Conversely, when you take these actions on LinkedIn, your name/photo may show up in related ads shown to LinkedIn members. By providing social context, we make it easy for our members to learn about products and services that the LinkedIn network is interacting with.

So if you follow an automation company like Siemens or any of a hundred other vendors your name and picture could show up on one of their LinkedIn ads. Someone interested in attacking one of their installations could follow you back to your profile and learn who you work for. From there most people can guess your corporate email address and you are now a target.

Linked in has provided a way for people to opt out of this program so they are not totally clueless; though it does seem odd that they haven’t publicized this option. Anyway, thanks to one of my cybersecurity readers here is the simple technique for protecting yourself against this source of potential social engineering attack targeting:

• Log into your LinkedIn account;

• In the upper right corner of the screen, select 'Settings' under your name;

• Go to 'Account' on the bottom left side of the screen and select 'Manage Social Advertising' under ‘Privacy Controls’;

• Disable the box which states 'LinkedIn may use my name & photo in social advertising'; and

• Click on ‘Save’

This is a simple enough process. It took me literally seconds to complete. I recommend that if you occupy any type of security sensitive position, you should do the same.
 
/* Use this with templates/template-twocol.html */