For Top Cyber Threats, Look in the Mirror

Craigslist.org Founder Hypes Government Transformation

By G C Network | July 29, 2009

Craig Newmark, best known for being the founder of the Craigslist website, is working hard to get the word out on Gov2.0. Last week in FedScoop, he really laid out…

Maria Spinola: An Essential Guide to Cloud Computing

By G C Network | July 27, 2009

Maria Spinola, a Strategic IT Marketing and Innovation Adviser and editor at www.Cloudviews.org, has recently published An “Essential Guide to Possibilities and Risk of Cloud Computing“. Her very pragmatic approach…

US Interior Department IT Infrastructure Vision

By G C Network | July 22, 2009

Tim Quinn, Chief Infrastructure Officer, US Department of Interior, sees IP convergence as a key part of DoI’s future IT infrastructure. During the Federal News Radio Executive Forum, he also…

DHS Acting CIO Margie Graves on Current DHS Challenges

By G C Network | July 20, 2009

During the Federal News Radio Executive Forum, Department of Homeland Security (DHS), Acting CIO, Margie Graves provides a unique insight on the department. In her remarks, she described the challenges…

DHS EAGLE & First Source Digital Guide Launched

By G C Network | July 17, 2009

The Enterprise Acquisition Gateway for Leading Edge Solutions (EAGLE) is a multiple-award indefinite delivery/indefinite quantity (IDIQ) contract vehicle, specifically designed as the preferred source of information technology (IT) services for…

Looking Forward To GovIT Expo!

By G C Network | July 14, 2009

I am humbled and more than pleased to serve as the Technical Chair of SYS-CON’s 1st Annual Government IT Conference & Expo. To highlight the importance of this conference, I…

Publishing Synergy: Blog, Twitter and Ulitzer

By G C Network | July 13, 2009

Have you ever been given the task of building and executing an aggressive customer outreach program? Well I received my assignment about a year ago and trust me; the budget…

Input: Cloud Computing, Security to Drive US Gov’t IT Spending

By G C Network | July 12, 2009

According to a PC World article, cloud computing and cybersecurity will be the high-growth areas for government IT spending over the next few years. The analysis and consulting firm Input…

GovIT Expo 2009

By G C Network | July 11, 2009

I’m happy to announce my appointment by SYS-CON to be the Technical Chair of the 1st Annual Government IT Conference & Expo. This event is a 1-day deep dive into…

NCOIC To Help FAA on NextGen

By G C Network | July 7, 2009

Today, the U.S. Federal Aviation Administration (FAA) and the Network Centric Operations Industry Consortium (NCOIC™) announced an agreement to work together to advance the Enterprise Architecture of NextGen, FAA’s national…

A recent report by Praetorian, a cybersecurity company headquartered in Austin, TX, focused on threats that resulted in data compromise or access to sensitive information. Based on a review of 100 separate internal penetration test engagements the study identified the five most prevalent threats to corporate data.  The amazing thing about these weaknesses is that the top four are all based on utilizing stolen credentials and the last one helps an attacker be more effective in using those stolen credentials.  In other words, the enemy is right there in the mirror!  The study spanned 75 unique organizations and only focused on security weaknesses that were used to obtain a full network compromise.

Where are your pain points?

The most prevalent threat is something we’ve all heard of before – Weak Domain User Passwords.  Since most corporate environments use Microsoft’s Active Directory to manage employee accounts and access, it needs some improvements in order to fully address complex passwords. Since Active Directory only requires passwords to be a specific length and contain specific character sets so addressing this weakness will require the use of third-party software.

The next most common corporate threat is Broadcast Name Resolution Poisoning.  Using this vector, an attacker responds to broadcast requests (i.e. LLMNR, NetBIOS, MDNS, etc) by providing its own IP.  When this is done, the credentials of a user accessing network resources can be instead transmitted to the attacker’s system.
The next big no-no is when system administrators all use the same Local Admin password. If an attacker is able to compromise the LM/NT hash representation of the password, then the attacker can use the hash to authenticate and execute commands on other systems that have the same password.  Using the hash, an attacker doesn’t need the actual password at all!
Microsoft Windows operating systems have another embedded password weakness.  Believe it or not, the operating system stores domain credentials in cleartext within memory of the Local Security Authority Subsystem Service (LSASS) process.  Although this weakness requires an attacker to have Local Admin or SYSTEM-level access, it ranks high on the threat list.
This last threat enhances all of the other – Insufficient Network Access Controls. Many organizations don’t restrict network access based on business requirements.  This will enable unfettered attacker mobility after only a single system on the internal network has been compromised.
These threat vectors, last updated by Praetorian in June 2016, were evaluated as part of a complete corporate network compromise kill chain.  They also highlight the importance of understanding the cybersecurity threat.  Although the mirror is a good place to start improving on network security, you must also work to identify all your organization’s security pain points.  With that knowledge you can more effectively enhance your team’s defenses and eventually evolve towards a better understanding of your security threat environment.
If you are serious about protecting your data, download the full report and read about the effective strategies your company can use to protect itself.  If you are a CISO or corporate executives, IBM also provides some excellent information on how to secure the C-suite.  They also provide an interactive toolthat can help better analyze your threats, protect your users and save your data from these and many other security challenges.

This post was brought to you by IBM Global Technology Services. For more content like this, visit Point B and Beyond.

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2016)

Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network