Stamus Networks’ Éric Leblond on Cybercriminals Compromising Threat Intel
Stamus Networks CTO Eric Leblond describes how cybercriminals are now compromising threat intelligence feeds to make it harder than ever to detect cyberattacks.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Eric Levo, who's CTO for stainless networks, and we're talking about how threat intelligence feeds are now an attack vector that we need to think about.
I mean, normally we would just accept everything that comes over there and hopefully we're using that intelligence to th toward attacks, but looks like the bad guys are paying attention to that as well. Eric, welcome to the show. Hello.
Hello everyone. I'm really happy to be with you today to talk to you about what we did recently discover at, uh, stemless Networks, uh, with regards to, um, the fact that strategy tensions can be in fact used, uh, as an offensive tool. So how is that accomplished exactly, because most people would just implicitly trust that feed.
So what do we need to pay attention to here? So what did happen is that there, there has been a switch between, uh, in the model, uh, years ago, uh, 10 years ago when the tools have been designed. The strategy intelligence were just mostly coming from the vendor that did develop the tool.
Um, by tool I'm talking about, uh, nutrition detection system, a malware analysis platform, um, or some, or any other platform that is, can inject data that are defining threats or things that can be put on. And because of this model where the vendor was in fact, uh, providing the code that executes the detection arm of the threat, um, uh, method, the method to detect the threats we had in fact, um, kind of a regular trust. Like you just have one single vendor.
But what did happen in the last 10 years is that, um, people did start to share things. So now you can strategy that come from multiple sources, um, because they come from multiple sources. It's, you exactly have the same issue as you have with, um, an application that is developed where people are using different module to put everything together.
So we have exactly the same issue. So instead of having basically one trust to give to somebody we trust, uh, now multiple people, and in some case we even have some real sharing platform that are in, in production. For instance, I don't know if you know, malware information sharing platform, but is at least in Europe, something really common, uh, where people, uh, build community on start to share threat intelligence that a at a big scale.
And because of that, your threat intelligence can come from a lot of different organization, um, because of that, that you can have potentially, uh, bad things coming, um, into the system. So you will ask me why bad. So one thing is simple, like, uh, you have a system that detect dominant name on you, an alert as soon as you have a domain name showing up.
com to have a list of domain that trigger an alert, that's a simple effect. You are going to have the storm of event coming to your system, and if you don't have control measure in place, you will have, uh, a full disc in your databases restoring the event or stuff like this. Are they injecting misinformation therefore into the feed to disrupt our business operations?
And how sophisticated is all this getting? Will they throw malware in their feed? So I I, I don't think it's, I I have no proof and we have seen no proof as ish networks, but it has been used.
But we wanted to raise, uh, the concern that the design of, uh, management of threat intel need to be taken into account. Because the Google example was a sim is a simple one, but is kind of trivial. You, you get a white list, you know where to remove from the threat intel.
But in some cases, and we have seen with Sirta that we're using, you know, product and where we're contribu and we also big contributor to, and we have seen that, uh, some of the feature add different settings, but we are not correct that could potentially allow a threat intelligence to act on the system itself. So on the inte detection system in this case. And because of that, you have potentially something that is, so we did work with, uh, with OASF, uh, that is behind, uh, the development of we fixed the issue together.
Uh, but in fact, the real problem is that the design of these tools has been done without taking into consideration that now strategy just can come from, from everywhere. So what are we supposed to do about this? I mean, is is somebody vetting these feeds on our behalf or are we supposed to do that and we have to dedicate resources for this?
How do I manage this process? So in fact, you need to know the tools you are using on pre filter, the strategy engines you pass to the system. So in the example of, uh, a really way they used domain that it injected in one strategy engines, you should have put in place some, uh, filtering in, in front of the system before sending that to the detection.
And if it's about, uh, uh, um, something like sirta, the other problem is that you have some feature that are really specific in sirta in the whole language. You have more from I think 100 or 200 keywords or just one or two. So something that you can do in your tools, this is that we do in the product we have at STEM networks.
We filter out from untrusted sources the potentially dangerous, uh, keywords to be sure that we have nothing that can reach the system and trigger problem on, on our, on our appear. What is the motivation for the bad guys for doing this? I mean, are can they monetize this as uh, somebody's gonna pay them To do this?
So, so, and um, so one of the thing that you can do is that, uh, so one of the potential impact that we have seen, at least in the case of sata, uh, is a denial of service. So you can modify the system, make the the probe, uh, useless or, or almost shut it down. You can remove any file.
com example, it's a bit the same. You are shutting down the database. You cannot store the event anymore.
So because you are, you cannot store the event anymore, it just means that you can then do your attack and will not be not, uh, you will not be seen by the attack, by the people in charge of a defense of a network because the, the system is all not operational for because it has been brought down or because the database is true. So essentially they're trying to blind us before they launch the more serious attack in the isolate a particular website or whatever else they may be up to because they know that we're overly dependent upon these threat feeds. Is that the idea?
Yeah, but that's exactly the idea. Yes, indeed. Just make people blind before you attack.
Is this something that your average cyber criminal syndicate can do? Or is this a nation state level kind of approach to launching something In, in fact, if you are looking at the regular way threat intel are coming, like you have one or two big vendor of threat intel that you are using in your system, and then in this case you mean that you need to target the vendor itself. So that can be complicated.
I bet that most of these people have a good, uh, level of security versus in the system and all we define the Strat intel. But at the same times, uh, if you have really share, uh, something people that are sharing or using public sources to, uh, ingest the Strat intel, in this case, you have less control. So you can ingest, you only have multiple sources where, uh, that you can correct or then already you can do modification.
So it's like usual. So you just need one simple unprotected source that can get into your community of, uh, sharing on send the data that can trigger the problem. Am I supposed to therefore constantly monitor my threat intelligence?
Um, is there, am I supposed to dedicate somebody to that task or is there some way to automate this so I can understand what's going on and maybe not dedicate resources that frankly I don't have? Yeah, so, so in, in most cases what you can do is check, uh, to put a simple check in place in place, sorry to see that in fact, what you have, uh, ingested is correct with regard to the boundary you can define before. So it's more about just defining a policy and then applying this policy, but it should be automated.
You don't wanna spend hours looking at million of domains, million of threat intelligence to finally, uh, see that, uh, some of them are potentially ous you want to filter out mm-Hmm. And for that you need to know the software that are going to inges this threat intel or this detection methods on doing that. You will be able to know what to limit.
It seems like the bad guys have infinite resources and they have the time and money to go tweak our threat intelligence systems. Are the attacks just getting to a level of sophistication that we as mere mortals cannot keep pace with? So do we need to rely more on machines?
Well, that's a good question. Sorry. So yeah, I, I, I just, I don't really know because, uh, you need to automate things because you cannot deal with the amount of data that is coming.
Uh, but also you need to have a clear audit of, uh, of a system you are using to know their limit, to know where they're weak, to know where they can suffer, and then implement in front of them method to protect them, uh, to, so for example, the, um, open source tools has been audited by the French authority for, to give it, uh, a common certification. And the strategy intelligence were outside of the scope. So the, the, the fact that the tool itself was put was protected himself from the potential bad threat intelligence was not part of, of a risk metrics that has been used.
And I think that this need to change. We're not in a world where one vendor use threat intelligence for one software ID design, but we're in a tool where you have threat intelligence on multiple vendors, where you ingest the threat intelligence and that makes a big difference. What are people doing with this intelligence?
And I asked the question 'cause obviously it helps me to better defend my environment, but we also know a lot more about the bad guys than we used to know. Are we getting more aggressive about responding to them? And are you seeing maybe countries coordinating responses?
I mean, you know, we have a lot of insight and intelligence. I'm just unclear how much we're acting on it. I think it depends on the level where you apply the certain intelligence, if you apply the certain intelligence for your organization or for a country, is completely different.
Completely different. And depends also if your motivation, if you just want to detect early sign of a behavior that is potentially harmful for your organization, uh, then you just need to ingest the s some, um, act on trigger incident response if she, you see something like somebody going to a strange website, somebody using some method on a file that are strange or stuff like this, which are part of a threat intelligence definition, but are a bit broad in my case. And, uh, use that to define yourself.
Uh, but if you are a country or, um, police forces, uh, that, that is really fun. Has the nature of the game changed? And I'm asking the question because I think we have a, in some areas a quaint notion that we can detect threats and respond and we'll do that over the course of days and weeks.
And I wonder if this game has moved now to seconds and minutes because by the time we detect something, the havoc has already been wreaked. So, um, is the whole cybersecurity job function moved into this kind of real time intelligence motion? I would say it's, it's, uh, it's two sided, yes, it is going faster.
So you need to act, uh, faster on, the faster you can, the, the faster you can fix things and prevent things, the better you predicted you will be. That's one thing. And yes, indeed it go really faster.
People are, the attacker are well organized and they have methodology and they can be really fast. And, but it also depends of what type of attack you are you are seeing. Uh, for instance, we have seen a lot of increase of attack on, uh, border devices like getaways, VPN controller and stuff like this, where in this case people just install themselves or install, install themself and sit on the network waiting to act maybe later.
But when doing that, they also communicate outside. So you can still detect then with certain intel once the first people in the community will see what type of network communication we are doing. If we're taking, I mean in my, in my, in my case, um, network detection or on response like what we do at service networks.
All right folks. Well, you heard it here. We all know you can't defend what you can't see, but the bad guys have figured out that as well and are going to some effort now to make sure that we don't see them at all in the first place.
Hey Eric, thanks for being on the show. Bye. You have a good day everyone.
Bye-Bye. And back to you guys in the studio.