How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert –...

71
How we Collaborate and Share Wim Biemolt SURFcert November 14th, 2012 FIRST TC, Kyoto

Transcript of How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert –...

Page 1: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

How we Collaborate and Share

Wim Biemolt

SURFcert – November 14th, 2012

FIRST TC, Kyoto

Page 2: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Oudemirdum

Page 3: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Kyoto?

Page 4: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Collaboration!

Page 5: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SURFnet

Page 6: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Global connectivity

Page 7: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

IPv6

Page 8: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Security

Page 9: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

DNSSEC

http://www.internetsociety.org/deploy360/blog/2012/10/excellent-whitepapertutorial-from-surfnet-on-deploying-dnssec-validating-dns-servers/

Page 10: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SURFcert IDS

Page 11: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Changing threats

Page 12: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SpamPot

Page 13: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Fantastic!

Page 14: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

However …

Page 15: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Packet love

Page 16: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SNMP

Page 17: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Secret

Page 18: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

DNS

Amsterdam Nijmegen Amsterdam

onweer service LAN

Page 19: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

What is happening?

Page 20: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Abuse

Page 21: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Partners in crime

Page 22: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Report the crime

Page 23: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Very useful

Page 24: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Measures

Page 25: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

TMS

Page 26: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SURFcert

Page 27: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Party!

Page 28: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

How?

5 5

Page 29: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

netflow

Page 30: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

AIRT

Page 31: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Incidents

2010 2011 2012

(H1)

Infected 2531 6373 1948

Probe 36 41 9

Spam 2597 1379 360

Content 6 6 6

Abusive 1 19 4

Denial 807 244 106

Vulnerable 1285 997 510

TOTAAL 7263 9059 2943

Page 32: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Good job!

Page 33: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

NAT

Page 34: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Is that everything?

Page 35: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Hlux/Kelihos Botnet

0

500

1000

1500

2000

2500

6/11/201100:00

6/12/201100:00

6/1/201200:00

6/2/201200:00

6/3/201200:00

6/4/201200:00

6/5/201200:00

6/6/201200:00

6/7/201200:00

6/8/201200:00

6/9/201200:00

# unique IP addresses per hour

Page 36: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

IPv4 Heatmap

September 2012 October 2012

Page 37: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Google maps

September 2012 October 2012

Page 38: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Region

2012

Page 39: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Slow decline

Page 40: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Abuse Information Exchange

Page 41: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

2nd Hlux/Kelihos Botnet

Page 42: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Status

Page 43: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Zeus

Page 44: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Busy!

Page 45: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

IP spoofing allowed?

Page 46: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Warning by executable

Page 47: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Favor?

Page 48: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Together strong

Page 49: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

SCIRT

Page 50: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Goals

Page 51: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Focus

Software audits Risk management

Juridical questions Virtualization

wifi Malware analysis

IPv6 security Forensics

Honeypot & IDS/IPS Phising

Page 52: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

MoU & TLP

Page 53: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Press

Page 54: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Dorifel

Page 55: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Zeroaccess

Page 56: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Dutch national cooperation (o-IRT-o)

Since 2002

Page 57: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Sinowal

Page 58: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

DNSSEC (again)

Page 59: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

You have them

Page 60: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

We have them

Page 61: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

TF-CSIRT

Page 62: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

CSIRT Training

Page 63: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Trusted Introducer

• Lists teams

• Accredits teams

• Certifies teams

• Trusted security services.

Page 64: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Around the world

Page 65: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

FIRST

Page 66: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

FIRST TC

Page 67: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Share!

Page 68: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Clearing houses

Page 69: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

Conclusion

Page 70: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto
Page 71: How we Collaborate and Share - FIRST · How we Collaborate and Share Wim Biemolt SURFcert – November 14th, 2012 FIRST TC, Kyoto

W

Wim.Biemolt[at]surfnet.nl

wimbie

www.surfnet.nl

+31 30 2 305 305

Creative Commons “Attribution” license:

http://creativecommons.org/licenses/by/3.0/