June 2022| | 9Network InfrastructureZero Day exploits have the potential to help teams test against more realistic attacker behavior in a condensed time frameZero Day exploits have the potential to help teams test against more realistic attacker behavior in a condensed time frame. Testing against these threats forces Blue Teams to defend in a different way. They can't rely on simple detections from their SIEM or other more straightforward means of defending their environment. It forces teams to re-orient and prioritize some of the basic. Do they have their environment instrumented well? Is the network properly segmented, limiting the "blast radius" of any potential compromise event? Blue Teams can still be successful defending against Zero Days, but it requires shifting away from a tool-centric mindset and focusing on best practices. This is a difficult change in thinking in many environments, but fist-hand experience defending against Zero Days can help drive that. The other important reason teams should consider testing against Zero Days, is that it's becoming more and more realistic defenders will see attackers utilizing them. The recent Log4j vulnerability was an excellent example of this. Nation States are also showing increasingly willingness to use these methods publicly and broadly. There are benefits in defenders being comfortable operating in an environment where they must respond to a threat with little to no information, no signatures/detections, and no pre-configured tools to assist. Practicing this type of response with a Red Team in advance helps defenders operate better when faced with a realZero Day threat. A well-prepared Security team should always practice and train as realistically as possible. There is a tendency for defenders to over value their own tools and practices when using lab environments or other training approaches. The "it couldn't happen in my environment" mindset is a risky one, because it discounts misconfigurations, human error, and flawed designs. Zero Day exploits are no exception to the need for teams to train realistically. It is more important than ever that defenders gain first-hand experience combatting these threats. Zero Day exploits are highly effective at testing our assumptions around layers of controls and defense-in-depth. It allows a Red Team to quickly gain a foothold in an environment, where they can only be constrained through good security hygiene. For this reason, I believe there is value in Red Teams utilizing Zero Day exploits to help teams prepare to respond to the more advanced threats the industry is already seeing. I believe the value proposition exists to conduct this type of testing. However, we can't ignore the challenges associated with responsible disclosure. It is not beneficial to gain first-hand experience defending against these threats, while other companies fall victim to real attackers quietly leveraging the same exploit.Regardless of a Red Team's use of Zero Day exploits, real world events will continue to challenge Security teams to defend against more advanced threats. I believe there is value in this testing approach, and as a result its worth trying to find responsible ways to utilize Zero Day exploits as part of Red Team testing. Brenden Smith
<
Page 8 |
Page 10 >