| | June 20228 Network InfrastructureRed Team engagements are exercises where a third-party simulates an attacker to test an organization's controls as authentically as possible. These types of engagements can identify gaps in your controls, processes, or incident response capabilities and are a valuable part of a high functioning security program. One tool used by Red Team engagements is the exploitation of vulnerable systems to further their objective. Recently some Red Teams have begun using Zero Day exploits as part of their testing. A Zero Day is a vulnerability that is exploited before a patch or fix is available. The use of Zero Days in Red Teams or for testing purposes is somewhat controversial, as is the discussion around appropriate vulnerability disclosure practices. Putting those complexities aside, its first worth asking what value is there in defenders seeing and experiencing Zero Day exploits in a Red Team engagement?Intuitively security teams know that some of the most important controls we implement are the least exciting. Network segmentation, asset management, patching cadence, principle of least privilege are all concepts that make up the foundation of our security programs. However, in practice its difficult to stay focused on the basics and always ensure our environments follow these disciplines closely. It's too easy to be drawn to exciting technologies to hunt more complex threats. Expensive and time-consuming implementations of Security Incident Event Managers (SIEM) or Data Loss Prevention technologies pull overworked teams away from the basics. Are these solutions sometimes necessary, absolutely. Do they also compete against maintaining proper basic hardening of our environments, definitely.Red Team engagements are an excellent resource to challenge our assumptions about our environment. They hunt for the controls that were forgotten, the system that was configured insecurely for convenience, or the default credential that didn't get changed. What gets lost in these engagements is that increasingly real attackers are showing a willingness to be patient. Attackers are content to wait for extended periods of time, looking for the right opportunity. They persist in low-risk systems that aren't tracked on risk assessments. Most organizations can't afford a Red Team engagement long enough to simulate this same behavior accurately for their teams to test against. STRENGTHENING ORGANIZATIONS' NETWORK SECURITY By Brenden Smith, CISO, FirstBankIN MY OPINION
<
Page 7 |
Page 9 >