{"id":66836,"date":"2017-11-08T18:12:05","date_gmt":"2017-11-08T10:12:05","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/fbi-more-cyber-attacks-now-blend-in-with-normal-network-behavior\/"},"modified":"2017-11-08T18:12:05","modified_gmt":"2017-11-08T10:12:05","slug":"fbi-more-cyber-attacks-now-blend-in-with-normal-network-behavior","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/fbi-more-cyber-attacks-now-blend-in-with-normal-network-behavior\/","title":{"rendered":"FBI: More Cyber Attacks Now Blend in with Normal Network Behavior"},"content":{"rendered":"<p>Recent trends in malicious cybersecurity activity show that hackers are becoming much more adept at breaching networks using acquired \u201clegitimate\u201d credentials (such as outdated test login accounts to Virtual Private Networks, VPNs) and \u201cblending in\u201d with normal network behavior, according to <strong>FBI<\/strong> Cyber Division Senior Intelligence Analyst Kristen Lane.<\/p>\n<p>Speaking at <em>Via Satellite<\/em>\u2019s Cybersat Summit in Tyson\u2019s Corner, Virginia, Lane told attendees that the agency has identified satellite and aerospace networks as part of a \u201ccritical assets\u201d category that is increasingly being targeted by cyberattacks. The agency has also noticed a shift in how malicious actors behave on infiltrated critical asset networks. \u201cLegitimate credentials, most of which are acquired from a previous hack, are being used to access the network, providing more time for the actor to remain on the network and cover to blend in as normal traffic,\u201d she said. \u201cInstead of quickly moving in and stealing data, these actors will take their time and learn how the network works, steal data and\/or create chaos. They will then sometimes hang on to those legitimate access tools, or, more likely, create and acquire new access credentials that they can use to access the networks at a later time \u2013 all before IT network defenses even realize what\u2019s going on.\u201d<\/p>\n<p>The hacks that produce legitimate credentials are often conducted by hostile nation states, which have gotten into the business of collecting and selling legitimate credentials to criminal actors so that they can use them to steal or sabotage data. The \u201cblending in\u201d behavior is even more prominent on hacked cloud servers with unprotected public access points. \u201cThese new tools that are being developed and sold allow hackers to scan the IP space of a network and identify public vulnerabilities,\u201d said Lane. \u201cThis doesn\u2019t mean that trusted VPN providers aren\u2019t just as vulnerable. In fact, the \u2018blending in\u2019 behavior applies to VPNs in that the malicious actors are reaching out and accessing end-user data from the VPN hub without the end-user even noticing the behavior.\u201d<\/p>\n<p>Malware is still very much a threat, but it, too, is getting more adept at blending in with other software that exists on a network. Some newer malware programs lay dormant until a system triggers an \u201cautomatic back-up\u201d process for photo and document files, which are stolen as they are copied. \u201cHacking tools are becoming a lot less unique and more normalized,\u201d said Lane. \u201cIn fact, the more identifiable malicious programs like ransomware are more commonly being used as distractions. They are often dropped into a network to pull the attention of an IT manager away from the real, underlying threat.\u201d<\/p>\n<p>[contextly_sidebar id=\u201dM2qllQRSl739NEsEqjgnn18y26vgNUYe\u201d]Due to recent geopolitical tensions and news events, cyberattacks receive more media attention now than ever. This means that more information on attacks \u2013 and even vulnerabilities \u2013 is being made available to the public. Hackers are naturally using this to their advantage, said Lane. \u201cWe had one instance where a security leak for a major vendor was made public a week and half before the company was able to patch that leak \u2014 it was just out in the open. In that time, several malicious actors were able to exploit the leak and weaponize the cyberattack to steal and destroy massive amounts of data.\u201d<\/p>\n<p>To combat these vulnerabilities, Lane and her colleagues at the FBI have engaged in an outreach effort to promote near-constant communication between businesses and the cybersecurity specialists at their local FBI field office. Lane emphasizes that Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) should develop strong working relationships with FBI officials, who have already developed protocols for securing and handling all types of data \u2014 from confidential government information to international business transactions. \u201cThe FBI has presence in 72 different countries to handle international incidents and we fully leverage our \u2018Five Eyes\u2019 intelligence alliance with Australia, Canada, New Zealand and the United Kingdom,\u201d said Lane.<\/p>\n<p>The FBI also has a long list of recommendations for satellite and aerospace companies looking to sure up their cyberdefenses internally. \u201cWe\u2019ve seen many breaches that could have been easily prevented by a variety of actions including strategic network segmentation to blocking unnecessary social media activity on the network,\u201d she said. \u201cVulnerabilities are most commonly created when a company or agency fails to deploy consistent network defenses and protocols. When IT managers allow exceptions to the rule, they create inconsistencies in a defense that will almost certainly be exploited. Proper cybersecurity measures are built on discipline, collaboration and communication.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent trends in malicious cybersecurity activity show that hackers are becoming much more adept at breaching networks using acquired \u201clegitimate\u201d credentials (such as outdated test login accounts to Virtual Private Networks, VPNs) and \u201cblending in\u201d with normal network behavior, according to FBI Cyber Division Senior Intelligence Analyst Kristen Lane. Speaking at Via Satellite\u2019s Cybersat Summit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":54777,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-66836","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66836"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=66836"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66836\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/54777"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=66836"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=66836"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=66836"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}