Showing posts with label Security Analysis. Show all posts
Showing posts with label Security Analysis. Show all posts

Monday, 20 January 2020

Phishing...and a little bit of analysis...

It was a strange email. Not from a name that I recognised. But it praised a post in my music technology blog http://blog.synthesizerwriter.com , mentioned an obscure link from a two year old blog post, and then used this as the hook to entice me into clicking on a link.

The choice of link was interesting. From a blog where just about ALL of the links are about music, technology or music technology, the choice was one about creative writing (OK, so I do slip the occasional left-field link into blog posts...). Having a link to the original blog post itself was interesting and tempting to click on to save time, but I didn't click on it, and instead I went directly to the actual blog post source. <Sound of lots of clicking...> Having reminded myself that I did indeed include an 'off the beaten track' link at the end of the blog post, I then looked at the increasing suspicious email.

So I checked the actual email address, and yep, the name wasn't the same (close, but not the same), plus it was a gmail address, so it was already starting to score quite highly on my 'possible phishing' suspicion counter. The link it so desperately wanted me to click on wasn't quite as ordinary as it appeared, and, like the name at the end of the email, was in a different font size. At this point the suspicion counter was too high and I deleted the email.

Photo by Ujesh Krishnan on Unsplash

Not that long ago, phishing emails tended to routinely use urgency (only 24 hours left, do this now, urgent...) as one of the main ways that they tried to get you to click on the link payload. This email was different, because it was attempting to appeal to my vanity by praising this blog, in the hope that I would then click on the poisoned link payload. Normally this would probably raise it closer in my mind to what is called 'spear-phishing', which is where the email is targeted to an individual, but it didn't seem to be that specific. So my suspicion is that this was just what passes for ordinary routine phishing nowadays, and is consigned to the same virtual waste bin as all of those emails with names of people I know that say that I must open this link because I will love it, or I must see it, etc., and where again the name and the email address don't match... Or reminders about TV licence renewal, or refunds for Tax, or...

I apologise for stating the obvious, but the occasional reminder about

not clicking on links in emails that are even slightly suspicious

is always good, imho. It could save you from all sorts of bad stuff. Just delete suspicious emails.

Security analysis

There is a school of thought that says that anything that analyses phishing emails, even to remind people to be vigilant, is dangerous because it helps the creators of the emails to improve their emails and make them more dangerous. My counter-argument would be that there is a lot of analysis already available on the Interweb (and elsewhere (French for 'She Swears', btw)), and nothing that I have mentioned is new or notable - plus there is always the chance that someone will read this who hadn't ever thought about the dangers of malicious emails!

More broadly, there is an opinion that says that just about everyone has already had most of their details leaked in one data breach or another anyway, and so phishing gradually becomes counter-productive, since it is trying to find the access details for an increasingly rare resource: people whose details haven't been leaked in a breach. It's a bit like the instruction that you get in corporates not to go into work when you have a cold. When no-one in the office has a cold then this makes sense, but when everyone has a particularly virulent cold (or flu, for example) then it becomes a 'lock-out' instruction and can create major problems. If everyone is out with a cold, then who is there to tell people when it is safe to return? Even if there is someone around who might be able to tell people when it is okay to return, that person might get a cold too! Game theory is interesting like that, and phishing emails seem to be following some of the classic paths of 'how processes work'. 

Trigger words like 'everyone' are useful clues in analysis. One hears about high school pupils where allegedly 'everyone' in their class has a pony. Deeper analysis by cautious and/or cash/credit-challenged parents seems to indicate that 'everyone' has an actual numerical value of slightly greater than 1 person...

Another trigger word is 'unique'. Here the numerical value is strictly 1, and no adjectives are allowed, so 'totally unique' has no meaning, and neither does 'completely unique' or any other combination. (Although 'uniquely unique' does appeal to my sense of the ridiculous!) Unique is inherently, intrinsically 'total', 'complete', and any other adjective that advertisers and copy-writers try to insert before it. Of course, every security solution, every cryptographic algorithm, (etc.), and every method of phishing detection has to be unique as well, otherwise it wouldn't be worth advertising, would it?

Using multiple trigger words in a single sentence is usually not a good idea for examination by a security analyst. 'Everyone is unique' now has a minimum numerical value of 1, which implies that everyone else does not need to take a course on philosophy as soon as possible. (Oh, and 'as soon as possible' is another trigger phrase: does it mean 'now, regardless of other tasks'; or does it mean 'later, when time is available and no more urgent tasks are left to do?)

The end-point of analysis is supposed to be good advice. Does this mean that trigger words should be avoided? (Oh, and recursion in analysis can cause problems too...)


If you find my writing helpful, informative or entertaining, then please consider visiting this link:












Sunday, 3 November 2019

Threat Analysis Template Speadsheet - Free

The world out there is complex. All too often, things are made very complicated - sometimes for very good reasons, but sometimes it feels like the twisty little passages are there because some people just like having lots of twisty little passages...

In a probably vain attempt to try to reduce the entropy of the universe, here's a quick and simple attempt to produce something which I have searched for and failed to find on the Interweb: a simple Threat Analysis Template spreadsheet that isn't tied to a vast workflow and methodology where you need ample supplies of commitment, time and resources. Instead, there's a single page with 8 steps, a cut-down ranking system (1-4, where you can usually ignore 1 and 2), and some built-in guidance as to what you need to do at each of the steps, with examples.


This isn't intended as a replacement for Microsoft's excellent SDLC, or ETSI's amazingly detailed TVRA, or the <insert appropriate adjective here> OWASP Application Threat Modelling (ATM) (or any other approach!) - it's a quick and dirty, simple and easy-to-use, 'get you started' starter example intended to at least get you walking along the yellow brick road, with no Toto or other companion required (and stumbling, crawling, or indeed, most other methods of progress-making along a path are all okay as well!). Moving to any more sophisticated methodology ought to be reasonably straight-froward from this initial point, when and if you want to move onwards and upwards.

To use it, you will need to gather relevant experts, make sure that their bosses are not in the room, and display the spreadsheet on a projector or a shared piece of paper (A3 is good!). Then just work from left to right, thinking about the topic. First identify the 'Asset' that you are protecting, and assigning a ranking number (1-4) as appropriate - in this case you are answering the question: how important is the Asset? Then take the highest ranked Assets, and get the experts to think about how someone might steal them, stop them working, break them, get them to do something they weren't meant to do, etc. When the experts come up with a way (and they may well do so!) for something bad to happen to that precious Asset, then assign that a ranking number as well, and look at the ranking numbers: if the Asset is ranked 1 or 2, and the Threat is 1 or 2 (that's a 'low value' Asset and a 'not very worrying' Threat) then you probably don't need to do anything else, but if you get 3s or 4s then you need to move across to the right and start describing what the vulnerability is that makes the Threat viable...  And so on across the spreadsheet columns.

Probably the most important column is the last one, where you assign Actions to people to do something about the Threat(s) that have been identified. The best way to get things to happen is to make sure that people know what they have to do, when they have to have finished, and to know that someone will chase them up about it if they haven't bothered to do anything about it. You may be able to figure out a number of motivational techniques to encourage completion.

Getting the spreadsheet template.


You can get the spreadsheet here. There's a 'download' icon disguised as a tray with an arrow pointing down into it (at the top right hand side of the screen), that you need to click on, and then things will happen with your electronic digital calculating thingy box.

Download the Spreadsheet

Did I mention that the spreadsheet is free?

---

Here's a link to click on if you find my writing informative, useful, or even mildly amusing in places:







NULLCON 12, Berlin, April 2022

Here's the badge that I designed for the NULLCON 2022 Berlin security conference (and highly recommended training!).  The NULLCON 2022 b...