Stories from the Security Operations Center

23
STORIES FROM THE SECURITY OPERATIONS CENTER (S.O.C.) Paul Fletcher Cyber Security Evangelist, Alert Logic

Transcript of Stories from the Security Operations Center

Page 1: Stories from the Security Operations Center

STORIES FROM THE SECURITY OPERATIONS CENTER (S.O.C.)

Paul Fletcher

Cyber Security Evangelist, Alert Logic

Page 2: Stories from the Security Operations Center

Complexity of defending web applications and workloads

Web App

AttacksOWASP

Top 10

Platform /

Library

Attacks

System /

Network

Attacks

Page 3: Stories from the Security Operations Center

Network Topology

Page 4: Stories from the Security Operations Center

Popular Web Application Attacks

Source: blog.sucuri.net

Page 5: Stories from the Security Operations Center

Recent SQL Injection Vulnerabilities

Page 6: Stories from the Security Operations Center

Today’s Attacks Have Several Stages

Page 7: Stories from the Security Operations Center

Initial Attack:

Word Press

XMLRPC Attack

Page 8: Stories from the Security Operations Center

Initial Attack: Word Press XMLRPC Attack

Athletic Apparel Shop Brick & Mortar and e-commerce

Application stack Custom code written in XML

Word Press content management system

MySQL database

Detection method Intrusion Detection System (IDS)

Log collection and analysis

Web Application Firewall (WAF)

Page 9: Stories from the Security Operations Center

Word Press XMLRPC Attack

Page 10: Stories from the Security Operations Center

Word Press XMLRPC Attack

Page 11: Stories from the Security Operations Center

Word Press XMLRPC Attack

Page 12: Stories from the Security Operations Center

Mitigating WP XMLRPC Attacks

Page 13: Stories from the Security Operations Center

Mitigating WP XMLRPC Attacks

Page 14: Stories from the Security Operations Center

Mitigating WP XMLRPC Attacks

Page 15: Stories from the Security Operations Center

Exfiltration:

SQL Injection

Page 16: Stories from the Security Operations Center

Exfiltration: SQL Injection Attack

Page 17: Stories from the Security Operations Center

SQL Injection Attack

Page 18: Stories from the Security Operations Center

SQL Injection Attack

Page 19: Stories from the Security Operations Center

What do you see?

Attack:

Response:

Page 20: Stories from the Security Operations Center

SQL Injection Attack

Page 21: Stories from the Security Operations Center

Impact of Web App Attacks – Key Takeaways

• Web Apps are becoming more prevalent in organizations

- Use of open source versus traditional applications

• Web App attacks are “gateway” attacks

- Yahoo breach started with a Word Press hack

- 9,000 C&C servers compromised by Word Press hack

- Shadow IT

• Early Stage Detection

- Prevents our customers from dealing with large scale breaches

Page 22: Stories from the Security Operations Center

How Alert Logic Detects Threats

Page 23: Stories from the Security Operations Center

Thank You.