Arizona State University Chapter 11 Cyber Attacks Questions Response Evaluate the National disaster recovery effectiveness based on case studies from the text or recent news stories and make recommendations for improvements based on your research. 500 words, APA required Cyber Attacks
“Dr. Amoroso’s fifth book Cyber Attacks: Protecting National Infrastructure outlines the challenges of protecting our nation’s infrastructure from cyber attack using security techniques
established to protect much smaller and less complex environments. He proposes a brand
new type of national infrastructure protection methodology and outlines a strategy presented
as a series of ten basic design and operations principles ranging from deception to response.
The bulk of the text covers each of these principles in technical detail. While several of these
principles would be daunting to implement and practice they provide the first clear and concise framework for discussion of this critical challenge. This text is thought-provoking and
should be a ‘must read’ for anyone concerned with cybersecurity in the private or government
sector.”
—Clayton W. Naeve, Ph.D.,
Senior Vice President and Chief Information Officer,
Endowed Chair in Bioinformatics,
St. Jude Children’s Research Hospital,
Memphis, TN
“Dr. Ed Amoroso reveals in plain English the threats and weaknesses of our critical infrastructure balanced against practices that reduce the exposures. This is an excellent guide
to the understanding of the cyber-scape that the security professional navigates. The book
takes complex concepts of security and simplifies it into coherent and simple to understand
concepts.”
—Arnold Felberbaum,
Chief IT Security & Compliance Officer,
Reed Elsevier
“The national infrastructure, which is now vital to communication, commerce and entertainment in everyday life, is highly vulnerable to malicious attacks and terrorist threats. Today, it
is possible for botnets to penetrate millions of computers around the world in few minutes,
and to attack the valuable national infrastructure.
“As the New York Times reported, the growing number of threats by botnets suggests that
this cyber security issue has become a serious problem, and we are losing the war against
these attacks.
“While computer security technologies will be useful for network systems, the reality
tells us that this conventional approach is not effective enough for the complex, large-scale
national infrastructure.
“Not only does the author provide comprehensive methodologies based on 25 years of experience in cyber security at AT&T, but he also suggests ‘security through obscurity,’ which
attempts to use secrecy to provide security.”
—Byeong Gi Lee,
President, IEEE Communications Society, and
Commissioner of the Korea Communications Commission (KCC)
Cyber Attacks
Protecting National
Infrastructure
Edward G. Amoroso
AMSTERDAM • BOSTON • HEIDELBERG • LONDON
NEW YORK • OXFORD • PARIS • SAN DIEGO
SAN FRANCISCO • SINGAPORE • SYDNEY • TOKYO
Butterworth-Heinemann is an imprint of Elsevier
Acquiring Editor: Pam Chester
Development Editor: Gregory Chalson
Project Manager: Paul Gottehrer
Designer: Alisa Andreola
Butterworth-Heinemann is an imprint of Elsevier
30 Corporate Drive, Suite 400, Burlington, MA 01803, USA
© 2011 Elsevier Inc. All rights reserved
No part of this publication may be reproduced or transmitted in any form or by any means, electronic
or mechanical, including photocopying, recording, or any information storage and retrieval system,
without permission in writing from the publisher. Details on how to seek permission, further
information about the Publisher’s permissions policies and our arrangements with organizations such
as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our
website: www.elsevier.com/permissions.
This book and the individual contributions contained in it are protected under copyright by the
Publisher (other than as may be noted herein).
Notices
Knowledge and best practice in this field are constantly changing. As new research and experience
broaden our understanding, changes in research methods or professional practices, may become necessary.
Practitioners and researchers must always rely on their own experience and knowledge in evaluating
and using any information or methods described herein. In using such information or methods they should be
mindful of their own safety and the safety of others, including parties for whom they have a professional
responsibility.
To the fullest extent of the law, neither the Publisher nor the authors, contributors, or editors, assume
any liability for any injury and/or damage to persons or property as a matter of products liability,
negligence or otherwise, or from any use or operation of any methods, products, instructions, or
ideas contained in the material herein.
Library of Congress Cataloging-in-Publication Data
Amoroso, Edward G.
Cyber attacks : protecting national infrastructure / Edward Amoroso.
p. cm.
Includes index.
ISBN 978-0-12-384917-5
1. Cyberterrorism—United States—Prevention. 2. Computer security—United States. 3. National
security—United States. I. Title.
HV6773.2.A47 2011
363.325⬘90046780973—dc22
2010040626
British Library Cataloguing-in-Publication Data
A catalogue record for this book is available from the British Library.
Printed in the United States of America
10 11 12 13 14 10 9 8 7 6 5 4 3 2 1
For information on all BH publications visit our website at www.elsevierdirect.com/security
CONTENTS
CONTENTS
Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ix
Acknowledgment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xi
Chapter 1 Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
National Cyber Threats, Vulnerabilities, and Attacks . . . . . . . . . . . . . . . . 4
Botnet Threat . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
National Cyber Security Methodology Components . . . . . . . . . . . . . . . 9
Deception . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
Separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Diversity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Consistency . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Depth . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Discretion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Collection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Correlation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Awareness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Response . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Implementing the Principles Nationally . . . . . . . . . . . . . . . . . . . . . . . . 28
Chapter 2 Deception . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31
Scanning Stage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Deliberately Open Ports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Discovery Stage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Deceptive Documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Exploitation Stage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Procurement Tricks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Exposing Stage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Interfaces Between Humans and Computers . . . . . . . . . . . . . . . . . . . .
National Deception Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
35
37
39
41
42
45
46
47
49
v
vi
CONTENTS
Chapter 3 Separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51
What Is Separation? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Functional Separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Infrastructure Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
DDOS Filtering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
SCADA Separation Architecture . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Physical Separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Insider Separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Asset Separation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Multilevel Security (MLS) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
53
55
57
60
62
63
65
68
70
Chapter 4 Diversity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Diversity and Worm Propagation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Desktop Computer System Diversity . . . . . . . . . . . . . . . . . . . . . . . . . . .
Diversity Paradox of Cloud Computing . . . . . . . . . . . . . . . . . . . . . . . . .
Network Technology Diversity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Physical Diversity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Diversity Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
75
77
80
82
85
87
Chapter 5 Commonality. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 89
Meaningful Best Practices for Infrastructure Protection. . . . . . . . . . . . 92
Locally Relevant and Appropriate Security Policy . . . . . . . . . . . . . . . . 95
Culture of Security Protection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 97
Infrastructure Simplification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
Certification and Education . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
Career Path and Reward Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105
Responsible Past Security Practice . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
National Commonality Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107
Chapter 6 Depth . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109
Effectiveness of Depth. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111
Layered Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .115
Layered E-Mail Virus and Spam Protection . . . . . . . . . . . . . . . . . . . . . . 119
CONTENTS
Layered Access Controls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Layered Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Layered Intrusion Detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Program of Depth . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
vii
120
122
124
126
Chapter 7 Discretion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129
Trusted Computing Base . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Security Through Obscurity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Information Sharing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Information Reconnaissance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Obscurity Layers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Organizational Compartments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Discretion Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
130
133
135
137
139
141
143
Chapter 8 Collection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
Collecting Network Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Collecting System Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Security Information and Event Management . . . . . . . . . . . . . . . . . .
Large-Scale Trending . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Tracking a Worm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Collection Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
148
150
154
156
159
161
Chapter 9 Correlation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 163
Conventional Security Correlation Methods . . . . . . . . . . . . . . . . . . . .
Quality and Reliability Issues in Data Correlation . . . . . . . . . . . . . . . .
Correlating Data to Detect a Worm. . . . . . . . . . . . . . . . . . . . . . . . . . . .
Correlating Data to Detect a Botnet . . . . . . . . . . . . . . . . . . . . . . . . . . .
Large-Scale Correlation Process. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Correlation Program. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
167
169
170
172
174
176
Chapter 10 Awareness . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
Detecting Infrastructure Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183
Managing Vulnerability Information . . . . . . . . . . . . . . . . . . . . . . . . . . 184
viii
CONTENTS
Cyber Security Intelligence Reports . . . . . . . . . . . . . . . . . . . . . . . . . . .
Risk Management Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Security Operations Centers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Awareness Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
186
188
190
192
Chapter 11 Response. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193
Pre- Versus Post-Attack Response . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Indications and Warning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Incident Response Teams . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Forensic Analysis . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Law Enforcement Issues . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Disaster Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
National Response Program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
195
197
198
201
203
204
206
Appendix Sample National Infrastructure Protection
Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 207
Sample Deception Requirements (Chapter 2) . . . . . . . . . . . . . . . . . . . 208
Sample Separation Requirements (Chapter 3) . . . . . . . . . . . . . . . . . . 209
Sample Diversity Requirements (Chapter 4) . . . . . . . . . . . . . . . . . . . . .211
Sample Commonality Requirements (Chapter 5) . . . . . . . . . . . . . . . . 212
Sample Depth Requirements (Chapter 6) . . . . . . . . . . . . . . . . . . . . . . 213
Sample Discretion Requirements (Chapter 7) . . . . . . . . . . . . . . . . . . . 214
Sample Collection Requirements (Chapter 8) . . . . . . . . . . . . . . . . . . . 214
Sample Correlation Requirements (Chapter 9) . . . . . . . . . . . . . . . . . . 215
Sample Awareness Requirements (Chapter 10) . . . . . . . . . . . . . . . . . 216
Sample Response Requirements (Chapter 11) . . . . . . . . . . . . . . . . . . 216
Index . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 219
PREFACE
PREFACE
Man did not enter into society to become worse than he was before,
nor to have fewer rights than he had before, but to have those
rights better secured.
Thomas Paine in Common Sense
Before you invest any of your time with this book, please take a
moment and look over the following points. They outline my
basic philosophy of national infrastructure security. I think that
your reaction to these points will give you a pretty good idea of
what your reaction will be to the book.
1. Citizens of free nations cannot hope to express or enjoy
their freedoms if basic security protections are not provided.
Security does not suppress freedom—it makes freedom
possible.
2. In virtually every modern nation, computers and networks
power critical infrastructure elements. As a result, cyber
attackers can use computers and networks to damage or ruin
the infrastructures that citizens rely on.
3. Security protections, such as those in security books, were
designed for small-scale environments such as enterprise
computing environments. These protections do not extrapolate to the protection of massively complex infrastructure.
4. Effective national cyber protections will be driven largely by
cooperation and coordination between commercial, industrial, and government organizations. Thus, organizational
management issues will be as important to national defense
as technical issues.
5. Security is a process of risk reduction, not risk removal.
Therefore, concrete steps can and should be taken to
reduce, but not remove, the risk of cyber attack to national
infrastructure.
6. The current risk of catastrophic cyber attack to national infrastructure must be viewed as extremely high, by any realistic
measure. Taking little or no action to reduce this risk would be
a foolish national decision.
The chapters of this book are organized around ten basic
principles that will reduce the risk of cyber attack to national
infrastructure in a substantive manner. They are driven by
ix
x
PREFACE
experiences gained managing the security of one of the largest,
most complex infrastructures in the world, by years of learning
from various commercial and government organizations, and by
years of interaction with students and academic researchers in
the security field. They are also driven by personal experiences
dealing with a wide range of successful and unsuccessful cyber
attacks, including ones directed at infrastructure of considerable
value. The implementation of the ten principles in this book will
require national resolve and changes to the way computing and
networking elements are designed, built, and operated in the
context of national infrastructure. My hope is that the suggestions offered in these pages will make this process easier.
ACKNOWLEDGMENT
ACKNOWLEDGMENT
The cyber security experts in the AT&T Chief Security Office, my
colleagues across AT&T Labs and the AT&T Chief Technology
Office, my colleagues across the entire AT&T business, and my
graduate and undergraduate students in the Computer Science
Department at the Stevens Institute of Technology, have had
a profound impact on my thinking and on the contents of this
book. In addition, many prominent enterprise customers of
AT&T with whom I’ve had the pleasure of serving, especially
those in the United States Federal Government, have been great
influencers in the preparation of this material.
I’d also like to extend a great thanks to my wife Lee, daughter Stephanie (17), son Matthew (15), and daughter Alicia (9) for
their collective patience with my busy schedule.
Edward G. Amoroso
…
Purchase answer to see full
attachment
Consider the following information, and answer the question below. China and England are international trade…
The CPA is involved in many aspects of accounting and business. Let's discuss some other…
For your initial post, share your earliest memory of a laser. Compare and contrast your…
2. The Ajax Co. just decided to save $1,500 a month for the next five…
How to make an insertion sort to sort an array of c strings using the…
Assume the following Keynesian income-expenditure two-sector model: AD = Cp + Ip Cp = Co…