{"id":23434,"date":"2019-01-08T14:57:37","date_gmt":"2019-01-08T14:57:37","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=23434"},"modified":"2019-01-09T10:24:26","modified_gmt":"2019-01-09T10:24:26","slug":"beyondtrust-cto-on-using-pam-in-post-breach-clean-ups","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/01\/08\/beyondtrust-cto-on-using-pam-in-post-breach-clean-ups\/","title":{"rendered":"BeyondTrust CTO on using PAM in post-breach clean-ups"},"content":{"rendered":"<p><em>While no organisation wants to\u00a0respond\u00a0to a security incident or a breach \u2013 particularly at the start of a new year \u2013 the reality is that preventing a cyberattack from landing is not always possible. Morey Haber, CTO at BeyondTrust, discusses the role of privileged access management (PAM) in a post-breach clean-up.<\/em><\/p>\n<p>No one wants to\u00a0<em>respond<\/em>\u00a0to a security incident or a breach, particularly at the start of a new year. Instead the highest priority should be to stop a cyberthreat\u00a0<em>before\u00a0<\/em>it compromises the organisation. But in reality, preventing a cyberattack from landing is not always possible. The steps for incident or breach identification \u2013 from\u00a0threat hunting\u00a0to searching for explicit Indicators of Compromise (IoC) \u2013 are well established. While the processes will vary from organisation to organisation, malware, compromised accounts, lateral movement, etc. will all need to be addressed as a part of any formal clean-up plan.<\/p>\n<p>If a breach is severe enough (for example, including the compromise of domain controllers), organisations may have no choice other than to reinstall the entire environment from scratch. While that is a worst-case scenario, it does happen. In many cases, businesses may choose to scrub servers as best as possible versus performing a complete reinstall. That is a business decision based on risk, feasibility and cost. It also represents a no-win scenario if the threat is a persistent presence that uses techniques to evade traditional identification measures. If you think that is far-fetched, just look at the history of threats like rootkits,\u00a0Spectre and\u00a0Meltdown\u00a0that prove that there is always a way to attack a technology resource.<\/p>\n<p><strong>Threat actors are after your credentials<\/strong><\/p>\n<p>Regardless of your remediation strategy, you can be assured that, via some fashion or another, threat actors will have access to your credentials. This implies that any clean-up effort\u00a0should not reuse any existing passwords\u00a0or keys. If possible, you should change (rotate) all credentials across every affected or linked resource. This is where\u00a0privileged access management (PAM)\u00a0comes into play. The clean-up or redeployment needs to be protected from password reuse or from a\u00a0threat actor\u00a0regaining a persistent presence due to poor\u00a0credential management,\u00a0as remediation efforts begin.<\/p>\n<p>Password management\u00a0is a core aspect of PAM and includes the automatic onboarding, rotation, session management, reporting, and check-in and check-out of passwords from a password safe. While PAM technology is most prominently used for privileged passwords like administrator, root, service accounts and\u00a0DevOps\u00a0secrets, it can also be used as a\u00a0least privilege solution to remove administrative rights for applications and tasks. This means that end users would no longer have, or need, a secondary administrator account to perform business functions.<\/p>\n<p><strong>PAM\u2019s role in clean-up after a breach<\/strong><\/p>\n<p>With this mind, how does PAM help with security breach clean-up? During a security incident or breach, you first need to investigate and address the following:<\/p>\n<ul>\n<li>Determine which accounts were compromised and used for access and lateral movement<\/li>\n<li>Determine the presence and resources using any linked, compromised accounts. For example, the same account that was compromised on asset X or application Y is also used on assets A, B and C for applications D, E and F so they can all communicate<\/li>\n<li>Identify and purge any illicit or rogue accounts created by the threat actor<\/li>\n<li>Identify, and remove or segment, any shadow IT,\u00a0IoT or other resource that was part of the\u00a0cyberattack chain,\u00a0to protect against future threats<\/li>\n<li>Analyse the accounts that have been compromised and determine the least amount of privileges needed for them to perform their functions. Most users and system accounts do not require full domain or local administrator or root accounts<\/li>\n<li>Analyse how data was used\/accessed by the attacker during the breach. Was any IoC data captured during abuse of the privileged account? If data was captured, did it help identify the threat? If data was not captured, determine what needs to change to monitor future misuse of privileged accounts. This includes privileged account usage as well as session monitoring and keystroke logging, where appropriate.<\/li>\n<\/ul>\n<p>This analysis is not trivial. Tools are needed to discover accounts, identify resources, determine usage patterns and, most importantly, flag any potential abuse. Even if all the log data is sent to a security information and event management (SIEM), it still requires\u00a0correlation or user behaviour analytics\u00a0to answer these questions.<\/p>\n<p>Once you have made the initial investigation, here are the five ways PAM can help after a breach and should be considered an essential component of your clean-up efforts:<\/p>\n<ol>\n<li>After a discovery,\u00a0automatically onboard your privileged accounts\u00a0and enforce unique and complex passwords with\u00a0automatic rotation\u00a0for each. This will help ensure any persistent presence cannot repeatedly leverage compromised accounts.<\/li>\n<li>For any linked accounts, have your PAM solution link and rotate them all together on a periodic schedule; including for service accounts. This will keep the accounts synchronised and potentially isolated from other forms of password reuse.<\/li>\n<li>When applicable, remove unnecessary privileged accounts all the way down to the desktop. This includes any secondary administrator accounts associated with an identity. For any application, command, or task that requires administrative rights, consider a\u00a0least privilege model that elevates the application \u2013 not the user \u2013 to perform privileged management.<\/li>\n<li>Using PAM, look for IoCs that suggest lateral movement, either from commands or rogue user behaviour. This is a critical portion of the cyberattack chain where PAM can help identify whether or not any resources have been compromised.<\/li>\n<li>Application control\u00a0is one of the best defences against malware. This capability includes looking for\u00a0trusted applications that are vulnerable to threats\u00a0by leveraging various forms of reputation-based services. PAM can help here too. Decide on an application\u2019s run-time based on trust and known risks before it is allowed to interact with the user, data, network, and operating system.<\/li>\n<\/ol>\n<p>Privileged access management should not only be considered for new projects and legacy systems to stop privileged attack vectors. It should be considered for forensics and remediation control after an incident or breach. PAM will help stop a threat actor from acting on some of the lowest hanging fruit within your organisation <em>\u2013\u00a0<\/em>poor password and credential management.<\/p>\n<p>As a security best practice, privileged access should always be limited. When a threat actor gains administrator or root credentials, they do have the keys to your kingdom. The goal is stop them from obtaining them and &#8216;re-keying&#8217; the accounts via passwords on a frequent basis, so even if they steal a password, their usage can be limited and monitored for potential abuse.<\/p>\n<p>Therefore, after an incident or breach, this helps ensure that any lingering persistent presence can be mitigated and represents a valuable methodology in the clean-up and sustainment process.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>While no organisation wants to\u00a0respond\u00a0to a security incident or a breach \u2013 particularly at the start of a new year \u2013 the reality is that preventing a cyberattack from landing is not always possible. Morey Haber, CTO at BeyondTrust, discusses the role of privileged access management (PAM) in a post-breach clean-up. No one wants to\u00a0respond\u00a0to [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":23440,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4950,134,4525,5,136,6,36,399],"tags":[393,387,394,291,7836,390,547,1787,4757],"class_list":["post-23434","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analysis","category-blog","category-cats","category-enterprise-security","category-industry-expert","category-insights","category-intelligent-technology","category-more-news","tag-beyondtrust","tag-cyberattack","tag-cyberthreat","tag-devops","tag-indicators-of-compromise","tag-iot","tag-morey-haber","tag-privileged-access-management","tag-security-information-and-event-management"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/23434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=23434"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/23434\/revisions"}],"predecessor-version":[{"id":23448,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/23434\/revisions\/23448"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/23440"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=23434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=23434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=23434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}