{"id":10782,"date":"2016-08-17T10:51:00","date_gmt":"2016-08-17T10:51:00","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=10782"},"modified":"2016-08-17T10:51:00","modified_gmt":"2016-08-17T10:51:00","slug":"ensuring-your-data-is-not-taken-hostage","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2016\/08\/17\/ensuring-your-data-is-not-taken-hostage\/","title":{"rendered":"Ensuring your data is not taken hostage"},"content":{"rendered":"<p class=\"p1\"><span class=\"s1\">After slowing slightly in mid-2015, ransomware has overall regained its rapid growth rate. According to a report,\u00a0total ransomware grew 116% year-over-year for the period ending March 31. Total ransomware rose 26% from Q4 2015 to Q1 2016 as lucrative returns continued to draw relatively low-skilled criminals. An\u00a0analysis of the CryptoWall V3 ransomware hinted at the financial scale of such campaigns. The researchers linked just one campaign\u2019s operations to $325 million in victims\u2019 ransom payments, writes\u00a0<em>Raj Samani, VP &amp; CTO, EMEA, Intel Security.<\/em><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">This spurt in Ransomware attacks can be attributed to three key reasons. The first driver is the syndication of the activity into ransom as a service with offers of revenue sharing to operatives facing the target recipients. The second driver is the development of polymorphism in ransomware generating a unique threat signature for each attack. And the third driver is the increasing sophistication within the malware, widening the scope of damages.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">With Middle East organisations becoming a target for Ransomware attacks, it is incumbent on the C-suite to take action and ensure that their data and organisations are not held ransom.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Remediation strategies for each stage<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Ransomware attacks occur in five stages \u2013 distribution, infection, communication, encryption and demand. So it is only logical that there should be prevention and remediation strategies for each of these stages.<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Distribution stage<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Build a \u201chuman firewall\u201d:<\/i><\/span><span class=\"s1\"> The biggest threat is users who let the ransomware on their endpoints. People are the weakest link. Organizations need to make sure that all employees from the CEO down, understand both how ransomware works as well as the ramifications of an attack<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Stop ransomware before the endpoint:<\/i><\/span><span class=\"s1\"> The most-proactive method of protecting a network from ransomware attack (other than the human firewall) is to keep ransomware from reaching the endpoint in the first place. Consider a web-filtering technology<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Apply all current operating system and application patches:<\/i><\/span><span class=\"s1\"> Many ransomware strategies take advantage of vulnerabilities in the operating system or in applications to infect an endpoint. Having the latest operating system and application versions and patches will reduce the attack surface to a minimum<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Spam filtering and web gateway filtering:<\/i><\/span><span class=\"s1\"> Again, the ideal approach is to keep ransomware off the network and the endpoint. Spam filtering and web gateway filtering are great ways to stop ransomware that tries to reach the endpoint through malicious IPs, URLs, and email spam<b>\u00a0<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Allow only whitelisted items to execute:<\/i><\/span><span class=\"s1\"> Use an \u201capplication control\u201d method that offers centrally administered whitelisting to block unauthorized executables on servers, corporate desktops, and fixed-function devices, thus dramatically reducing the attack surface for most ransomware<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Limit privileges for unknown processes:<\/i><\/span><span class=\"s1\"> This can be done easily by writing rules for host intrusion prevention systems or access protection rules<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Infection stage\u00a0<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Don\u2019t turn on macros unless you know what\u2019s happening:<\/i><\/span><span class=\"s1\"> In general, do not enable macros in documents received via email. Notice that Microsoft Office turns off auto-execution of macros for Office documents by default. Office macros are a popular way for ransomware to infect your machine, so if a document \u201casks\u201d you to enable macros, don\u2019t do it<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Make yourself \u201cweaker\u201d when working:<\/i><\/span><span class=\"s1\"> Don\u2019t give yourself more login power than you need. If you allow yourself administrator rights during normal usage, consider restricting this. Surfing the web, opening applications and documents, and generally doing a lot of work while logged in with administrative rights is very dangerous. If you get hit with malware while you have fewer rights, you will reduce your risk because malware will also execute with fewer rights, which will reduce the threat\u2019s attack surface<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Use access protection rules on software installs:<\/i><\/span><span class=\"s1\"> Write access control rules against targeted file extensions that deny writes by unapproved applications. This complements host intrusion prevention systems rules with a similar strategy<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Use sandboxing for suspicious processes:<\/i><\/span><span class=\"s1\"> If a process is flagged as suspicious (due to low age and prevalence, for example), that process should be sent to a security sandboxing appliance for further study<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Block \u201cunapproved\u201d processes from changing files:<\/i><\/span><span class=\"s1\"> Block these by writing rules for host intrusion prevention systems or access protection<b>\u00a0<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Communication stage<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Firewall rules can block known malicious domains:<\/i><\/span><span class=\"s1\"> Writing rules to block malicious domains is a standard capability of network firewalls<\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Proxy\/gateway scanner signatures for known traffic:<\/i><\/span><span class=\"s1\"> For those with proxy and gateway appliances, these technologies can be configured to scan for known ransomware control server traffic and block it. Most ransomware cannot continue operations if it cannot retrieve the public encryption key needed for asymmetric encryption<b>\u00a0<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Encryption stage<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Back-up and restore files locally:<\/i><\/span><span class=\"s1\"> By creating a storage volume and running archival differential-based file backups to that storage volume, remediation is as easy as removing the ransomware, going back in time with the backup to a point before the ransomware affected the files, and restoring all the affected files. This can be done today by network administrators who could either use external storage volumes with a good archival backup utility or partition a local drive and run the backup utility against that<b>\u00a0<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Limit shared file activities:<\/i><\/span><span class=\"s1\"> Many ransomware variants will look for access to files on storage other than the boot volume\u2014such as file servers, additional volumes, etc.\u2014and will encrypt everything they can find to inflict maximum damage. Consider limiting operations allowed on shared volumes<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\"><b>Ransom demand stage\u00a0<\/b><\/span><\/p>\n<p class=\"p1\"><span class=\"s3\"><i>Restore from backup, keep a recent backup offsite and \u201cair gapped\u201d:<\/i><\/span><span class=\"s1\"> Store a set of multiple, complete backups and assume an attack. An \u201cair-gapped\u201d backup is not connected to the computer or the network anywhere. (For an individual this could mean back up to an external hard drive. When the backup is done, unplug the drive and keep it in a drawer, away from any computers. That way ransomware cannot detect the backup and damage it.) Consider using a \u201cbare metal backup\u201d utility, which not only backs up your user files, but also lets you erase all storage volumes (in case the machine is stolen) and get you back to a usable state with all your applications and data restored<\/span><\/p>\n<p class=\"p1\"><span class=\"s1\">Ensuring your organisation\u2019s precious data is not ripe for the taking is a daunting task, especially with the steady rise of ransomware as an attack vector. By adopting a planned approach involving both end users and IT administrators, and implementing integrated security solutions that protect, detect and correct, businesses in the region can avoid the unplanned downtimes and losses associated with such malware attacks.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>After slowing slightly in mid-2015, ransomware has overall regained its rapid growth rate. According to a report,\u00a0total ransomware grew 116% year-over-year for the period ending March 31. Total ransomware rose 26% from Q4 2015 to Q1 2016 as lucrative returns continued to draw relatively low-skilled criminals. An\u00a0analysis of the CryptoWall V3 ransomware hinted at the [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":10794,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6],"tags":[906,1350,1043,10],"class_list":["post-10782","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights","tag-encryption","tag-intel-security","tag-ransomware","tag-security-2"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/10782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=10782"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/10782\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/10794"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=10782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=10782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=10782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}