Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer...

50
Risk Mitigation for SpamBot Infections Copyright © 2016, CyberGreen Dec 2016

Transcript of Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer...

Page 1: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Risk Mitigation for SpamBot Infections

Copyright©2016,CyberGreen Dec2016

Page 2: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Agenda

1. Introduction2. AboutSpamBot Infections3. Mitigationrecommendationsforspamandother

botnetinfections4. Makingthecaseforimplementingmitigationsand

securingemailservices

2 Copyright©2016,CyberGreen Dec2016

Page 3: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Introduction

WhencyberinfrastructureisinsecurethereisarisktotheglobalInternetcommunitySecuringallend-usercomputingdevicesiscriticaltobusinessproductivity,butoftenoverlooked• Devicesnotproperlysecuredareeasilycompromised,

thencontrolledbythirdpartiesaspartofa“botnet”• Whenbotnetssendspamandviruses,itcan

representarisknotjusttotheorganizationthatownsthosedevices,buttothebroaderInternetcommunity

3 Copyright©2016,CyberGreen Dec2016

Page 4: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

About CyberGreen

• Globalnon-profitandcollaborativeorganizationfocusedonhelpingimprovethehealthofglobalCyberEcosystem

• WorkingtoprovidereliablemetricsandmitigationbestpracticeinformationtoCyberSecurityIncidentResponseTeams(CSIRTs),networkoperators,andpolicymakers

• Mission:helpCSIRTsandothersfocusremediationeffortsonthemostimportantriskso Helpunderstandwhereimprovementscanbemadeo Howwecanachieveamoresustainable,secure,and

resilientcyberecosystem

4 Copyright©2016,CyberGreen Dec2016

Page 5: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Copyright (c) 2016, CyberGreen

Thesematerialsaredistributedunderthefollowinglicense:Permissiontouse,copy,modify,and/ordistributethesematerialsforanypurposewithorwithoutfeeisherebygranted,providedthattheabovecopyrightnoticeandthispermissionnoticeappearinallcopies.THEMATERIALISPROVIDED"ASIS"ANDTHEAUTHORDISCLAIMSALLWARRANTIESWITHREGARDTOTHISMATERIALINCLUDINGALLIMPLIEDWARRANTIESOFMERCHANTABILITYANDFITNESS.INNOEVENTSHALLTHEAUTHORBELIABLEFORANYSPECIAL,DIRECT,INDIRECT,ORCONSEQUENTIALDAMAGESORANYDAMAGESWHATSOEVERRESULTINGFROMLOSSOFUSE,DATAORPROFITS,WHETHERINANACTIONOFCONTRACT,NEGLIGENCEOROTHERTORTIOUSACTION,ARISINGOUTOFORINCONNECTIONWITHTHEUSEORPERFORMANCEOFTHISMATERIAL.

5 Copyright©2016,CyberGreen Dec2016

Page 6: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

About Spambot Infections

6 Copyright©2016,CyberGreen Dec2016

Page 7: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

What is a Botnet?

AbotnetisacollectionofcomputerswhichinteracttoaccomplishsomedistributedactivityontheInternetBotnetsaretypicallycompromiseddevicesthatareunderthecontrolofanunauthorizedandanonymousperson,oftencalledabotnetherderOwnersofcompromiseddevicesgenerallyhavenoideasomeoneelsecontrolstheirdevice

7 Copyright©2016,CyberGreen Dec2016

Page 8: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Spambotnetssendspamandmalware,deliveringamaliciouspayloadeitherthroughafileattachedtospammessagesorbyembeddingalinktoaninfectedwebsiteCriminalsusebothtraditionalemail,instantmessages(IMS)andtextmessagesintheirspamcampaignsAcompanywithmanycompromiseddevicesthatarepartofspambotnetshasa“spambot infection”

Spam Botnet Infections

8 Copyright©2016,CyberGreen Dec2016

Page 9: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

The spambot cycle

9 Copyright©2016,CyberGreen Dec2016

Page 10: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Risks posed by spambots

Acompromisedmachineinabotnetmayhaveothermalwareinstalled,spreadmalwaretoothermachinesinyournetworkortoothertargetsoutsideyournetwork• Adversariesgetfurtherinsideyour

network• Servicedegradation,interruption

orfailure• Usercredentialsorothersensitive

dataexposedBotnetscanaffectWindows,MacandLinuxoperatingsystems,aswellasmobiledevices10 Copyright©2016,CyberGreen Dec2016

Page 11: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Spambots in Distributed Denial of Service (DDoS) attacks

InDDoSattacks,theattackerabusestensofthousandsofspambot devicestocreatelargefloodsoftrafficwiththegoalofexhaustingthevictim'sbandwidthDDoSattacksalsoabusetheUserDatagramProtocol(UDP)traffic,usingprotocolssuchasDNSallowspoofingofsenderIPaddresses• UDPrespondstorequests

withoutvalidationofsenderidentity,i.e.IPaddress

• UDPtrafficcanbespoofed(i.e.haveamisleadingapparentsourceIPaddress):attackercanhidetrueidentity

11 Copyright©2016,CyberGreen Dec2016

Page 12: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

12 Copyright©2016,CyberGreen Dec2016

Real life botnet infection

Ahospital[1] hadabotnetinfectionsosevere,activityfrominfectedmachinesinterruptedthehospitalscomputernetworkwithimpactsincluding:• Doorstooperatingroomswouldnotopen• Pagerswereinterrupted• Computersintheintensive

careunitwereshutdown

[1]http://www.eweek.com/c/a/Security/DOJ-Indicts-Hacker-for-Hospital-Botnet-Attack(accessed9/16)

Page 13: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Real spambot in DDoS attack

In2009,[2] anInternetServiceProviderwasonthereceivingendofa25Gb/sDDoSattack(DNSamplificationandreflection),whichpeakedat30Gb/sinaggregate• Overonemillionspambotnetinfecteddevices

wereusedinthisattack,whichtotallyfloodedthevictim’snetworkandtookthemoffline,therebydisruptingtheirbusiness

[2]http://www.team-cymru.org/Open-Resolver-Challenge.html (accessed9/16)

13 Copyright©2016,CyberGreen Dec2016

Page 14: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

14 Copyright©2016,CyberGreen Dec2016

Potential impacts from spambotinfections

Productivity• Sendingspamandvirusesconsumesprocessingpowerand

bandwidthoninfectedhosts,causingpoorperformance• Inlargeinfections,spambotnetscanconsumeenough

bandwidththatservicesaredisruptedforlegitimateusers,aparticularconcernfor:

— Seasonaloperations,e.g.onlineretailerswheremostsaleshappenbetweenThanksgivingandNewYears

— Timesensitiveoperations,e.g.healthcare,collegeswithlimitedonlineregistrationperiodsoronlinewageringonsportingevents,etc.

Page 15: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Other potential spambot infection impacts

Brand• Lossofreputationwithcustomersandpartners• Becomingknownasa“spammagnet”inglobalcommunityTechnical• Networkservicesinterrupted• “Blacklist”andisolationofinfectednetworkbynetwork

providersfromtherestofInternetaspartoftheInternetcommunity’sefforttostopemailspamming

15 Copyright©2016,CyberGreen Dec2016

Page 16: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Mitigate risks from spambot infections

16 Copyright©2016,CyberGreen Dec2016

Page 17: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

17 Copyright©2016,CyberGreen Dec2016

Mitigation options vary by environment

NotallmitigationbestpracticesareappropriateforallenvironmentsCyberGreenprovidesinformationrelevanttofourbasicenvironmentalprofilesLookfortheseiconstofindmitigationsforyourenvironment

1.

2.

3.

4.

Page 18: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

18 Copyright©2016,CyberGreen Dec2016

Find out if your network is already infected with botnets

ShadowserverwillprovideanynetworkwithdailyreportsonthebotnetinfectionsseenforaspecificIPv4orIPv6addressblock:http://www.shadowserver.org/wiki/pmwiki.php/Involve/GetReportsOnYourNetwork

Note:ShadowserverscanswillonlyhitIPspacethatisnotfirewalledandtheydonotclaim100%accuracyintheirCommand&Controldownloads,sotheremaybefalsepositivesinShadowserverIRCintelligence

Page 19: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Is your IP address part of a blacklist?

IdentifyyourIPv4orIPv6addressbyvisitingthesewebsites:• http://ipv4.whatismyv6.com/• http://ipv6.whatismyv6.com/

CheckthoseIPsathttp://multirbl.valli.org/• OrclickonindividualIPaddresslinksthatappear

onthesite

19 Copyright©2016,CyberGreen Dec2016

Page 20: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

20 Copyright©2016,CyberGreen Dec2016

Stay alert for new or increasing infections

Acompletelistofalltechniquesisbeyondthescopeofthisdocument• Shadowserver hasacomprehensivelistoftoolsand

techniquestomonitoryournetworkanddetectbotnets

https://www.shadowserver.org/wiki/pmwiki.php/Information/BotnetDetection

Page 21: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

21 Copyright©2016,CyberGreen Dec2016

Mitigation: Notify users and clean up infected machines on your network

Allorganizations,includingISPs,needtocleanupinfectedhostsUse“nukeandpave”tobesurethedeviceissecure:1. Reformatorreinstallsystemfromscratchusingoriginalmedia2. Ensurethatoperatingsystempatchesareapplied3. Ensureadequatehostprotections(anti-virusandhostfirewall)are

installedandconfiguredwithupdatedsignatures/definitions4. Restoreuserfilesandapplicationsfromcleanbackupsororiginalmedia.

Besuretopatch*all*installedapplicationsDoeachstepBEFOREconnectingthehosttotheInternetIfyoudon’talreadyhavethissoftwareavailablelocallyonyournetwork,youshouldconnecttotheInternetviaahardwarefirewalled-connectiontodownloadsoftwareand/orupdates

Page 22: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

ISPs: Communicate with customers

CommunicatewithcustomersaboutwhatyouaredoingandWHY,usingthesenotificationmethods• Email• Phonecalls• In-browsernotificationssuchas

“walledgardens”(i.e.notifycustomer“youraccountistemporarilysuspendeddueto…”)

Activelyeducatecustomersaboutthethreats,theirresponsibilityascomputerowners,andmeasurestakenbyISPtoreducerisks

22 Copyright©2016,CyberGreen Dec2016

Page 23: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

23 Copyright©2016,CyberGreen Dec2016

Mitigation: Practice basic computer hygiene

PracticingbasiccomputerhygieneisessentialtoreducingtheriskofallmalwareinfectionsItalsoenablesyoutorecoverquicklywhenacomputerdoesbecomeinfectedBasiccomputerhygieneprotectsagainstmanydifferenttypesofmalwareusedtocreatetoday’sbotnets

Page 24: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

24 Copyright©2016,CyberGreen Dec2016

Computer hygiene: Backups

Regular,completebackupsofalldevicesanddataareessentialMultiplegenerationsofbackupsshouldberetained:• Ifmostrecentbackupis

nogood,apriorversionexists

• Minimizesamountofdatathatmaybelost

Page 25: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

25 Copyright©2016,CyberGreen Dec2016

Computer hygiene: Host-based firewall

Modernoperatingsystemscomewithabasichost-basedfirewallthatshouldbeturnedonBEFOREthecomputerisconnectedtotheInternet,particularlyifthereisnoseparatefirewallatthepointofconnectiontotheInternetStand-alonefirewallapplicationsfromreputablefirewallvendors:• http://www.pcmag.com/article2/0,2817,2487059,00.asp

• http://www.techradar.com/news/software/applications/the-best-free-firewall-software-of-2015-stop-malware-before-it-gets-you-1284587

• http://www.techradar.com/news/software/applications/7-of-the-best-linux-firewalls-697177

Page 26: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

26 Copyright©2016,CyberGreen Dec2016

Computer hygiene: Anti-virus

Ifyoudon’talreadyhaveanti-virus(AV)software,orifyoubelieveacomputerisinfectedbutyourcurrentAVdoesnotdetectavirus,findanAVhere:• http://www.pcmag.com/article2/0,2817,2388652,00.asp• http://www.techradar.com/news/software/applications/be

st-free-antivirus-1321277

DONOTrunMORETHANONEanti-virusatatimeIfyouwanttotryrunningmultipleproducts,downloadone,runit,uninstallit,downloadthenext,runit,uninstallit,etc.

Page 27: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

27 Copyright©2016,CyberGreen Dec2016

Computer hygiene: Images with secure configurations

BuildOperatingSystemimageswithsecureconfigurations,i.e.withanti-virusandfirewallsalreadyinstalled• Greatlyreducestimeneededtocompletelyrebuild

acomputerfromatrustedsource• Oftentheonlywaytoensureallmalwareis

eliminatedonadeviceandthatitisabletoprotectitselffromre-infection

Page 28: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

28 Copyright©2016,CyberGreen Dec2016

Computer hygiene: Protect mobile devices

MobiledevicesmaybeinfectedandusedasSpambots,particularlyiftheyconnecttoinsecurelyconfiguredwirelessnetworks(Wi-Fi)MobiledevicesmayalsosendSMStextmessagesthroughcellularnetworkstoothermobiledevicesorPremiumSMSnumbers• Highvolumeusagemayresult

inadditionalcharges• PremiumSMSnumbersalways

resultinadditionalcharges

Page 29: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

29 Copyright©2016,CyberGreen Dec2016

Computer hygiene: Protect mobile devices

MitigationsformobilesimilartoPCs:• Alwayskeepdeviceoperatingsystemandinstalled

applicationsup-to-date• Don'tdownloadorinstallsoftwarefromnon-approved

sources• BeawareofflashscammessageswithfakeAVorother

contentthatdirectsyoutoafakestorewithfakeAVorothermalicioussoftware

• AskcellprovidertoblockallPremiumSMSmessagestomobiledevice

Page 30: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

30 Copyright©2016,CyberGreen Dec2016

Mitigation: Implement email authentication with SPF and DKIM

SenderPolicyFramework(SPF)andDomainKeysIdentifiedMail(DKIM)emailauthenticationprotocolsthatmakeitharderforspammersandcybercriminalstospoofwhereanemailcomesfrom

Domainswithemailauthenticationarelessattractivetophishers

• Lesslikelytobeblacklistedbyspamfilters

• Ensureslegitimateemailfromthatdomainisdelivered

Page 31: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

31 Copyright©2016,CyberGreen Dec2016

Mitigation: Implement email authentication with SPF

SPFallowsdomainownerstospecifywhichmailserversareusedtosendemailfromthatdomain

• Providesamechanismtoallowreceivingmailexchangerstocheckthatincomingmailfromadomaincomesfromahostauthorizedbythatdomain'sadministrators

SPFspecifications,configurationanddeploymentinformation:https://tools.ietf.org/html/rfc7208

http://www.openspf.org/Project_Overview

https://www.digitalocean.com/community/tutorials/how-to-use-an-spf-record-to-prevent-spoofing-improve-e-mail-reliability

Page 32: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

32 Copyright©2016,CyberGreen Dec2016

Mitigation: Implement email authentication with DKIM

DKIMallowsmessagestobetransmittedinawaythatcanbeverifiedthroughcryptographicauthenticationbymailboxprovider• EmailproviderswhovalidateDKIMsignaturescanuse

informationaboutsignertolimitspam,spoofing,andphishing

• DKIMcanensuremessagesnotmodifiedortamperedwithintransit

DKIMspecifications,configurationanddeploymentdetails:https://tools.ietf.org/html/rfc6376http://dkim.org/

Page 33: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

33 Copyright©2016,CyberGreen Dec2016

Mitigation: Implement secure configuration of email services

TheMessagingAnti-AbuseWorkingGroup(MAAWG)recommendationstoimplementasecureconfigurationofemailservicesfocuson:• LockingdownaccesstoSMTPport25• RequiringauthenticationforemailasprovidedinInternet

EngineeringTaskForce(IETF)RFC2254• Useemailsubmissionservicesonport587asdescribedin

IATFRFCRecommendationsavailableat:https://www.m3aawg.org/sites/default/files/document/MAAWG_Port25rec0511.pdf

Page 34: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

34 Copyright©2016,CyberGreen Dec2016

Additional configurations for ISPs

Blockemailportsatthecustomer’smodem,i.e.blockoutboundport25topreventdirect-to-mxspamBlockoutboundport25fromresidentialuserstoanymailserverotherthantheISP’s;thisforcesspambotstouseISP-ownedmailserversPerformoutboundspamfilteringandbotdetectiononISPmailservers- thiscanbeparticularlyeffectiveinconjunctionwiththepriorblockingtactics

Page 35: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

35 Copyright©2016,CyberGreen Dec2016

Other mitigations for ISPs

Ifblockingportsisn’tpossible,ensurethatrecipientscandistinguishresidentialIPaddressesfromcommercialonesAssignreverseDNStoresidentialIPsthatmarksthemassuch,andpublishthenamingconventionProactivelyprovideresidentialCIDRblockliststoblocklist providerssuchastheSpamhaus PolicyBlockList(PBL)athttps://www.spamhaus.org/pbl/RatelimitUDPfragments

Page 36: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

36 Copyright©2016,CyberGreen Dec2016

Mitigation: Implement RFC 7489 DMARC

IETFRFC7489,“Domain-basedMessageAuthentication,Reporting,andConformance(DMARC)

DMARCdesignedtohelpcombatspamandphishingbyenablingemailsendersandreceiverstodeterminewhetherornotagivenmessageislegitimatelyfromthesender,andwhattodoifitisn’tBuildsonwidelydeployedDKIMandSPFvalidationsystems:ifmessagesatisfieschecksitissentthroughtorecipient,otherwiseit’squarantinedorrejected

Page 37: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

37 Copyright©2016,CyberGreen Dec2016

DMARC

DMARCissupportedbyallfourmajoremailproviders:Google,Microsoft,YahooandAOL.IthasalsobeenimplementedbyserviceslikeFacebook,PayPal,AmazonandTwitter.MoreinformationaboutDMARCisavailableat:• https://dmarc.org/• https://dmarc.org/overview/• https://dmarcguide.globalcyberalliance.org• https://tools.ietf.org/html/rfc7489

Page 38: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

38 Copyright©2016,CyberGreen Dec2016

Verify your fix

Afterimplementingyourmitigationmeasures,monitoryourinfrastructuretopreventre-occurrencebysubscribingtofreereportsfromShadowserver:https://www.shadowserver.org/wiki/pmwiki.php/Involve/GetReportsOnYourNetwork

Page 39: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Additional resources about spambots

• CheckyourlocalCERTandyourAVvendorannouncementsforidentifiedmalwareinfection

• https://www.shadowserver.org/wiki/pmwiki.php/Information/Botnets

• http://www.senki.org/sp-security/monitoring-network-malware-spam-botnet-infections/

• https://www.spamhaus.org/

39 Copyright©2016,CyberGreen Dec2016

Page 40: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Making the case for implementing mitigations for spam botnet infections

40 Copyright©2016,CyberGreen Dec2016

Page 41: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

41 Copyright©2016,CyberGreen Dec2016

Making the case for mitigations

HelpeveryoneunderstandthelevelofeffortneededtoimprovecyberhealthintheircommunityWhyshouldyouimplementthemitigationsinyourenvironment?1. ItistherightthingtodoasagoodInternetneighbor2. Yourorganizationmaybenexttobe

attackedLet’sjointogetherandstopbadguysfromwinning!

Page 42: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

42 Copyright©2016,CyberGreen Dec2016

Changing risk landscape

Increasedneedtodemonstrate“duecare”• Obtainingcyberinsurance• Complyingwithriskframeworkstowinbusinesswith

local/nationalgovernmentsandlargecorporationsIfwe(you!)don’tdoabetterjobofsecuringourowninfrastructureandreducingcyberrisk,governmentregulationmayforceadditionalmandatesand/orpenalties

Page 43: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

43 Copyright©2016,CyberGreen Dec2016

Anticipated organizational benefits

Increasedproductivity• FewerserviceinterruptionsandfailuresImprovednetworkperformance• Existingnetworkmorereliableandresilient,with

greatercapacityImprovedbrandreputation• Technicalreliabilityand

securityasellingpointtocustomers

Page 44: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

44 Copyright©2016,CyberGreen Dec2016

More anticipated benefits

Decreasedbudgetuncertainty• FewerunanticipatedusagecostsforIT• Budgetcanbeusedasplanned,e.g.upgrading

technicalcapability/capacity,personnel,etc.Systemadminsmayspendlesstimespenttryingtodealwithunexpectedproblems• Mayimprovetheirproductivityand

reduceunexpectedovertime

Page 45: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Benefits for ISPs and Email Providers

IdentifythepartyresponsibleforsubmittedmessagesReducedcostsforabusehelpdesk,customersupport,andnetworkoperationscentersImproveddeliverabilityforlegitimateemailmessages,duetoreducedriskofbeingblacklistedNewabilities:• Enforceacceptableusepolicies,termsofserviceforemail

submission• Monitorandlimittransmissionrates,percustomerand/orin

aggregate• Offerpremiumtiersofservicetocustomerswithbusiness

needtooperateemailserverswithdirectaccesstoport2545 Copyright©2016,CyberGreen Dec2016

Page 46: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

46 Copyright©2016,CyberGreen Dec2016

What do you need to implement these mitigations?

Commandsandconfigurationdetailsformostimportantmitigationsarepublicallyavailable• Noadditionalsoftwaremustbepurchased• Implementingmitigationsdoesnotrequireanyspecial

knowledge,skills,orabilities

Note:AllmitigationsshouldbecarefullyreviewedinlightofyourspecificbusinessrequirementsandinfrastructureenvironmentbeforeproceedingAllorganizationalchangemanagementprocesses,includingtesting,shouldbefollowed

Page 47: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

47 Copyright©2016,CyberGreen Dec2016

How long will mitigations take?

CleanrestoreofahostmaytakeanhourortwowhensecureOSimagesreadilyavailableforautomaticrebuild• Doesnotincludetimetoinstallorrestoreuser

applicationsanddata,assumingdatawasbackedupManualinstallationfrommediawilltakeseveralhoursperhostISPsandlargeentitiescanautomateadministrationofchangesviaconfigurationmanagementsystemswithtaskexecution(Salt,Ansible)

Page 48: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

48 Copyright©2016,CyberGreen Dec2016

TechnicalteamsmayneedseveraldaystoweekstoplanandexecuteeachindividualcomponentofthesecureconfigurationforemailservicesrecommendedbyMAAWGortoimplementDMARC

Bonus:withnorealmaintenance,therecurringcostiseffectivelyzero!

How long will it take?

Page 49: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Acknowledgement

49 Copyright©2016,CyberGreen Dec2016

CyberGreenwouldliketothanktheexpertswhomadethecreationofthisdocumentpossible:

Writtenby:- LaurinBuchanan,AppliedVisions,Inc.– SecureDecisionsDivision

ContributedandReviewedby:- MattCarothers,CoxCommunications- Baiba Kaskina,CERT.LV- MotoKawasaki,JPCERT/CC- ArtManion,CERT/CC- Yoshinobu Matsuzaki,IIJ- JoeStSauver,Farsight Security- DavidWatson,ShadowServer Foundation

Disclaimer:CyberGreenbelievesthisguidanceandtheadvicefromourexpertsshouldbeofbenefittoanyonemitigatingariskconditions,butitisnotadvicespecifictoanyreaderornetwork.Ultimately,eachreaderisresponsibleforimplementinghisorherownnetwork remediationstrategyandweassumenoresponsibilityorliabilitytherefore.

Page 50: Risk Mitigation for SpamBotInfections Bot Infectio… · Mitigation: Practice basic computer hygiene Practicing basic computer hygiene is essential to reducing the risk of all malware

Formoreinformationaboutriskmitigationbestpractices

pleasecontact:[email protected]

50 Copyright©2016,CyberGreen Dec2016