33
AI. READY? GO! Sergej EPP Chief Security Officer, Central Europe

190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

  • Upload
    others

  • View
    7

  • Download
    0

Embed Size (px)

Citation preview

Page 1: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

AI. READY? GO!Sergej EPPChief Security Officer, Central Europe

Page 2: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

CONFCIKER

2 | © 2018, Palo Alto Networks. All Rights Reserved.

2008NOVEMBER

Page 3: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

3 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

NETWORKENGINEERS

HACKERS

Page 4: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

APPENDIX

4 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

SOC

BOTS

Page 5: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

RISK MATRIX - 2019

5 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

§ Connected vehicle(air/rail/car) threats

§ Quantum computing

§ Data exfiltration in the cloud

§ Cyber Hygiene

§ AI voice fraud§ AI phishing§ AI chatbots

§ Firmware implants§ Destructive

threats§ ID mass

blackmailing

§ OT/IoT Threats§ Insider Threat

§ Third Party Threat§ Spyware§ Identity theft

§ Ransomware Virus

§ AI Exploit Fuzzing§ AI Malware Gen.

§ Biometrics loss § CEO Fraud§ Compromised

patch control

§ Crimeware-as-a-service

§ Phishing

§ SupervisoryOversight

§ BYOD threats § Attack obfuscation§ Denial of Service

§ Banking Malware

§ Advancedregulations

§ Cryptojacking

Emerging Unlikely Possible Likely Very Likely

Acute

Severe

High

Medium

Low

Page 6: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

6 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

ROBOTS

Page 7: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

7 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

DETECTION

PREVENTION

RESPONSE

§ Burden to triage§ Costs of false negative

§ Enforcement§ Feedback Loop

SECURITY LIFECYCLE

Cons

tant

ly ch

angi

ng e

nviro

nmen

t

§ Interability of alerts§ Often EDR limited§ Highly time-intensive

Page 8: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

8 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.4RECOMMENDATIONS

Page 9: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

9 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

„I will fix your detection problems“- AI

Page 10: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

OUTPUT DATA

INTRODUCTION INTO MACHINE LEARNING

10 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

INPUT DATA

PROGRAM

PROGRAMINPUT DATA

OUTPUT DATA

Machine Learning

Traditional Programming

Referece: Prof. Domingos

Page 11: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

11 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

Page 12: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

12 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

Page 13: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

13 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

4. Run Red Team Exercises

5. Cross-organizational telemetry

3. Use Honeypots

2. Review incidents

1. Use public dataset

effe

ctiv

enes

s

HOW TO GET EFFECTIVE TRAINING DATA?

Page 14: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

14 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

BEISPIEL: SPAM

Page 15: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

15 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

IT’S A TEAMSPORT!

Page 16: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

1. CREATE TRUST FOR

CLOUD SECURITY PRODUCTS

16 | © 2018, Palo Alto Networks. All Rights Reserved.

Page 17: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

17 | © 2018, Palo Alto Networks. All Rights Reserved.

INTERABILITY OF ALERTS

Page 18: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

18 | © 2018, Palo Alto Networks. All Rights Reserved.

BLIND SPOTS

Page 19: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

19 | © 2018, Palo Alto Networks. All Rights Reserved.

COMPREHENSIVE ANALYSIS

Page 20: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

2. ESTABLISHRICH DATA VISIBILITY

20 | © 2018, Palo Alto Networks. All Rights Reserved.

Page 21: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

Reconnaissance Weaponizationand Delivery

Exploitation Command and Control

Lateral Movement

Installation Actions onthe Objective

Automated Detection and Prevention

Threat Alerting and Hunting

Focus on this side

Focus on this side

21 | © 2019 Palo Alto Networks. All Rights Reserved.

FOCUS HUMAN EFFORT ON THE RIGHT SIDE OF ATTACK LIFECYCLE

AFAutoFocus

TRTraps

WFWildFire

GPGlobalProtect

APAperture

Cortex XDR

Page 22: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

EXAMPLE: THREAT INTELLIGENCE

Block list

Quarantine list

Alert list

Sandbox

ExploitKits, Scanning IPs

C2 IPs Move to quarantinenetwork

Rebuild device

Analyze device

Signatures

Firewall

Endpoint

Indicators

APT IPs

Notify user

AI:beaconing

SHARING

UserViolation

Page 23: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

3. AUTOMATE YOUR

SECURITY PLAYBOOKS

23 | © 2018, Palo Alto Networks. All Rights Reserved.

Page 24: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

24 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

Page 25: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

25 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

THE HIDDEN COSTS OF POINT PRODUCTS

BUY IT

BUY SOMEBODY TO MANAGE

BUY A POINT PRODUCT INTEL PERSON

BUY SOMEBODY TO TIEIT ALL TOGETHER

ACTUAL COSTS

Page 26: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

IT‘S SURVEY TIME

26 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

100 3050

“HOW MANY SECURITY TOOLS DO YOU USE IN YOUR ORGANIZATION?”

Page 27: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

HYPE CYCLE

Page 28: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

28 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

Page 29: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

29 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

Page 30: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

4. REVIEW YOUR

POINT PRODUCTS

30 | © 2018, Palo Alto Networks. All Rights Reserved.

Page 31: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

LETS GET IT DONE

31 | © 2019, Palo Alto Networks. All Rights Reserved.

MY PLAN FOR CYBERHYGIENE AND FOCUS ON WHAT MATTERS

30 Days

Create inventory for security products and rate them on§ Penetration level across

network, endpoint, cloud§ Prevention maturity§ API maturity§ Crowd intelligence

90 Days

§ Introduce SecDevOps forkey products and validate recommendation from yourinventory

§ Create a plan and share with vendors

270 days

Rationalize security products

Page 32: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

CONFICKER INFECTIONS 2019

32 | © 2019 Palo Alto Networks, Inc. All Rights Reserved.

Page 33: 190312 Sergej Epp AI Ready Go submission...Reconnaissance Weaponization and Delivery Exploitation Command and Control Lateral Movement Installation Actions on the Objective Automated

THANK YOU

Email: [email protected]: @EppSecurity