As the fallout from the SolarWinds hack continues to unfold, Microsoft this week said attackers stole source code for three of its products (but didn’t hack any customers’ information), and an ExtraHop investigation found a 150% increase in suspicious network activity that went largely ignored during the peak of the attack.
Additionally, the top White House cybersecurity official said the alleged Russian hackers compromised at least 100 companies, and President Joe Biden plans to soon take executive action in response to the attack.
While the breach wasn’t discovered until December 2020, threat researchers believe that Russian hackers inserted malware into SolarWinds’ Orion software update that was pushed to about 18,000 customers beginning last March, and then remained in organizations’ environments for months without being detected.
ExtraHop Outlines SolarWinds Lessons LearnedNetwork detection and response vendor ExtraHop investigated the methods that attackers used to evade detection before FireEye ultimately discovered the SolarWinds Sunburst exploit in early December.
ExtraHop threat researchers found that between late March 2020 and early October 2020, detections of probable malicious activity increased by about 150%. This included lateral movement, privilege escalation, and command and control beaconing, which allowed the hackers to evade more traditional detection methods like endpoint detection and response (EDR) and antivirus. In fact, attackers disabled a long list of endpoint and other security products, and if they couldn’t disable the tool, the malware simply moved on to other systems.
But, as the report notes, “the network can’t be disabled. Every single person, technology, device, and malicious actor interacts with the network — whether on premises or in the cloud.”
ExtraHop Head of Product Ted Driggs likens the attack to stealing money. “If somebody walks into a bank and waves a gun around, it’s pretty obvious that something illegal is happening,” he said. “But if I am trying to steal money, the more subtle way to do it is to make a series a moves where no single move would raise eyebrows. And only when you look at the whole chain does it become clear that something is really wrong.”
This, he added, is where network detection and response becomes an extremely valuable tool. While an endpoint product can provide an in-depth look at something really bad happening on one particular device, the security team can’t understand the full scope of the attack without a more comprehensive view across the entire environment.
“So, because we gather all the data needed to build those behavioral profiles and to do these investigations, we were able to provide a script to our customers that goes back and looks at evidence for these particular indicators are compromised in their environment from that historical record,” Driggs said. As part of the new report, ExtraHop released an expanded list of more than 1,700 Sunburst indicators of compromise that it observed across affected environments protected by its Reveal(x) product.
Cross-Silo Detection and ResponseAnd while extended detection and response (XDR) is a newer technology compared to network detection and response, this too provides a valuable tool to prevent SolarWinds-type attacks in the future, Driggs added.
XDR is about sharing threat context and enforcement across domains. It does this by pulling telemetry from across endpoints and the network and then correlating it into a centralized platform for analysis and incident response. It combines elements of security information and event management (SIEM), security orchestration, automation, and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA). Several security vendors including Cisco, Fortinet, Palo Alto Networks, VMware, McAfee, RSA, CrowdStrike, and Trend Micro have all rolled out XDR products and strategies in recent months.
“Individual customer organizations don’t have the exposure to enough attacks needed to build and tune their own cross-silo detection system, so it’s really exciting to see new vendors and new products from large vendors taking on that silo erosion,” Driggs said. “What all security vendors can do is to continue to be committed to making their data available in programmatic and open formats such that building across silos is as easy as possible.”
To this end, ExtraHop uses APIs “with a specific goal of making it dead easy to integrate into your SEIM, SOAR, XDR, case management, whatever platforms you have,” he continued. “And we are working on deeper integrations with specific partners that will further drive that turnkey silo erosion.”
Microsoft Concludes SolarWinds InvestigationMeanwhile, Microsoft this week said it completed its own internal investigation into the SolarWinds hack. After initially disclosing the breach in December, Microsoft on New Year’s Eve admitted that the hackers also accessed its internal source code. This week, Microsoft said it found no evidence that the hackers stole any customer data. It did, however, disclose that the attackers used the SolarWinds update to download some source code for Microsoft Azure, Intune, and Exchange.
“The search terms used by the actor indicate the expected focus on attempting to find secrets,” the security team said in Microsoft’s final SolarWinds investigation update. “Our development policy prohibits secrets in code and we run automated tools to verify compliance … We have confirmed that the repositories complied and did not contain any live, production credentials.”
In a separate blog post published this week about SolarWinds lessons learned, Vasu Jakkal, Microsoft’s corporate VP for security, compliance, and identity, says organizations need to implement a zero-trust architecture and defense-in-depth security strategy to guard against future threats.
A zero-trust approach assigns rules and policies to workloads, endpoints, virtual machines, or network connections, and then only allows necessary actions and connections in a workload or application while anything else gets blocked.
“Zero Trust is a proactive mindset,” Jakkal wrote. “When every employee at a company assumes attackers are going to land at some point, they model threats and implement mitigations to ensure that any potential exploit can’t expand.”
Biden’s Response to SolarWindsMeanwhile the Biden administration’s investigation into one of the worst breaches in U.S. history continues on Capitol Hill. Deputy National Security Adviser Anne Neuberger, who is leading the government’s response to SolarWinds, on Wednesday told reporters that the investigation will likely take “several months.” The alleged Russian hackers specifically targeted at least nine federal agencies and compromised at least 100 private-sector companies, Neuberger said. This is the most specific information the federal government has released to date about the scope of the breach.
However, the final tally of affected organizations will likely be higher considering 18,000 downloaded the malicious software update, she added. “So the scale of potential access far exceeded the number of known compromises,” Neuberger said. “Many of the private sector compromises are technology companies, including networks of companies whose products could be used to launch additional intrusions.”
The federal government is also investigating how gaps in its security posture allowed the attack to happen, and Biden will address these in a forthcoming executive action, Neuberger said. “We’re also working on close to about a dozen things,” she said, “that will be part of an upcoming executive action to address the gaps we’ve identified in our review of this incident.”
Comments