The Art of Attribution: Identifying and Pursuing your Cyber Adversaries
The Art of Attribution in Cybersecurity
Introduction to the Speaker and Topic
- Dimitra Parovic introduces herself as the co-founder and CTO of CrowdStrike, highlighting her extensive background in threat research, including notable investigations into major cyber intrusions.
- The talk focuses on the art of attribution, specifically identifying and pursuing cyber adversaries.
Importance of Understanding Attackers
- Parovic emphasizes that understanding who the attacker is crucial for effective cybersecurity, rather than just focusing on malware or technical indicators.
- She argues that attackers will change their tools over time; thus, organizations must focus on their motivations and capabilities to develop a strategic understanding of threats.
Strategic Threat Assessment
- Organizations should prioritize understanding potential threats based on limited resources and time, similar to how governments assess national security risks.
- Just as nations focus on top-tier threats rather than every possible actor globally, companies should also identify key adversaries relevant to their operations.
Real-world Analogies in Cybersecurity
- Parovic draws parallels between physical security breaches (e.g., break-ins at offices) and cyber intrusions, stressing the importance of knowing who is behind an attack.
- She questions why businesses often overlook the identity of cyber attackers when they would prioritize this information in physical security scenarios.
Disconnect Between Technical Indicators and Business Relevance
- There is a tendency within cybersecurity to focus excessively on technical details rather than providing executives with actionable insights about threat actors.
- Executives often receive reports filled with technical jargon that lack context regarding why specific threats matter for business strategy.
Historical Context and Current Challenges
- Parovic reflects on 30 years of cybersecurity history where reliance has been placed on government entities for threat attribution without sufficient strategic context being provided.
- Despite improvements in sharing indicators by government agencies like the FBI, there remains a gap in conveying why certain threats are critical from a business perspective.
Attribution in Cyberspace: Is It Possible?
The Challenge of Attribution
- The government treats cyber information as highly classified, making it unlikely for them to pursue attribution effectively. This places the responsibility on the industry to fill this gap.
- Common belief states that attribution is impossible due to tactics like proxies and false flag operations; however, successful attribution occurs daily in cyberspace.
- Various entities, including governments, law enforcement, private citizens, and companies have successfully conducted attribution at an individual level.
Case Studies in Attribution
- An example includes identifying a perpetrator involved in the Target breach through mistakes made in operational security (OPSEC).
- Security blogger Brian Krebs uncovered the identity of the Target hacker within two weeks by tracing back to a domain registration mistake linked to his real name.
- CrowdStrike's investigation into "Deep Panda," a Chinese state-affiliated actor targeting technology and financial sectors, illustrates how specific individuals can be identified.
The Attribution Paradox
- The concept of an "attribution paradox" suggests that while defenders must be right 100% of the time, attackers only need one successful operation.
- For effective attribution, investigators need only find one mistake made by attackers who must maintain perfect OPSEC consistently over time.
Mistakes Lead to Identification
- Criminal actors often make identifiable mistakes; for instance, registering domains with real names can lead to their identification years later.
- Even nation-states are not immune from OPSEC errors; recent leaks demonstrate that no entity is perfect at maintaining secrecy.
Patterns of Behavior Among Attackers
- While it's possible for someone to commit a perfect crime once without being caught, repeated attempts increase chances of mistakes leading to capture.
- Investigators can trace patterns and breadcrumbs left behind by attackers across multiple operations which aids in identifying their targets and methods.
Understanding Cyber Threat Actors
Types of Attackers
- Cyber threats come from various sources including nation-states, criminal groups, activists, and terrorists.
- CrowdStrike has developed a common nomenclature for categorizing these actors which helps streamline communication about threats across different organizations.
Focused Research on High-End Threat Groups
- There are approximately 60–70 high-end threat groups globally; while many low-level scammers exist (e.g., Nigerian scammers), they are less relevant for serious organizational protection strategies.
Notable Threat Actors
China
- China is identified as the most prolific cyber threat actor with over 30 tracked groups under the term "PANDA," indicating affiliation with the Chinese government.
Iran
- Iranian cyber operations have evolved significantly since Stuxnet; they now pose risks beyond espionage into disruptive attacks. Current nuclear negotiations may influence future actions.
India
- India has become aggressive in economic espionage through groups like "Viceroy Tiger," targeting various sectors including government and finance.
Russia
- Russia rivals U.S. capabilities in cyberspace. Recent reports indicate Russian efforts extend beyond national security espionage into commercial sectors such as oil and gas.
The Role of Oil and Gas in the Russian Economy
Importance of Energy Exports
- Oil and gas are critical to the Russian economy, serving as its main export. The government prioritizes support for state-owned firms like Gazprom and Rosneft to maintain this advantage.
Cyber Threat Actors: Nation-States vs. Criminal Groups
Sophistication of Cyber Actors
- North Korea is highlighted as a highly capable cyber actor with sophisticated operations. The naming convention for these groups reflects their national identity, such as "bear" for Russia and "panda" for China.
Understanding North Korean Cyber Operations
Characteristics of North Korean Attacks
- North Korea's chosen national animal, Kalima—a mythical flying horse—symbolizes its elusive nature. This group conducts destructive attacks against South Korea and U.S. targets, focusing on both espionage and direct damage.
Tracking Diverse Cyber Threat Groups
Classification of Threat Actors
- Various cyber threat actors are tracked under specific names: Spider for criminal groups and Jackal for hacktivists (e.g., Dead Eye Jackal refers to the Syrian Electronic Army). Consistent nomenclature aids in identifying the nature of these threats over time.
Identifying Cyber Threat Actors
Key Considerations in Attribution
- To understand a cyber actor, it's crucial to analyze their operational window and how their tradecraft evolves over time, indicating their capabilities through changes in tactics or tools used during attacks.
Objectives Behind Cyber Operations
Types of Operations
- Differentiate between types of operations: espionage (less urgent), destructive attacks (high priority), or misinformation campaigns; understanding objectives helps prioritize responses effectively.
Techniques for Attribution
Identifying Unique Characteristics
- Focus on human tool marks within code to identify unique characteristics that can help attribute attacks to specific actors, including build times that may indicate geographical origins based on work hours observed in malware development.
Tradecraft Patterns Among Cyber Actors
Repeated Techniques
- Once an operator is identified, they tend to repeat successful techniques (tradecraft), making it easier to link future activities back to them based on consistent methods used during intrusions.
Predictive Security Through Intelligence
Importance of Knowing Your Adversaries
- Effective predictive security relies on intelligence about potential threats; understanding who the adversaries are and their capabilities is essential for safeguarding organizations against future attacks. Knowledge about various threat actors enhances security measures significantly.