cryptomining - black hat | home · 7/20/2018  · paul ducklin who am i? [email protected] @duckblog...

25
Paul Ducklin Senior Technologist versus CRYPTOMINING What's the difference?

Upload: others

Post on 22-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

Paul Ducklin Senior Technologist

versusCRYPTOMINING

What's the difference?

Page 2: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

Paul Ducklin

Who am I?

[email protected]

@duckblog

nakedsecurity.sophos.com

Page 3: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

performing the zillions of cryptographic calculations you need to earn hot-topic cryptocurrencies

such as Bitcoin, Monero or Ethereum x

“”

CRYPTOMINING

Page 4: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

2016 July-Dec

2017 Jan-June

2017 July-Dec

2018 Jan-June

$0

$20k

$0

$20k

$10k$10k

WHY CRYPTOMINING?

Page 5: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

2016 July-Dec

2017 Jan-June

2017 July-Dec

2018 Jan-June

$0

$20k

$0

$20k

$10k$10k

WHY CRYPTOMINING?

Page 6: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

2016 July-Dec

2017 Jan-June

2017 July-Dec

2018 Jan-June

$0

$20k

$0

$20k

$10k$10k

WHY CRYPTOMINING?

Page 7: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

HOW TO MINE?

Page 8: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

HOW TO MINE?

Page 9: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

HOW TO MINE?

Page 10: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

HOW TO MINE?

Page 11: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

HOW TO MINE?

Or...

Page 13: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

https://nakedsecurity.sophos.com/2018/01/31/what-are-wannamine-attacks-and-how-do-i-avoid-them/

Page 17: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

When you cryptomine without permission (from everyone concerned)

then you are cryptojacking - and in most organisations, you can

assume you don't have permission. x

“”

Page 18: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

DOES ROGUE MINING REALLY MATTER?

$2 of electricity ! A bit of heat 🤷

Some fan noise !

Page 19: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

DOES ROGUE MINING REALLY MATTER?

$2 of electricity ! A bit of heat 🤷

Some fan noise !

😖😡😱 Cryptojacking is the new ransomware!

Page 20: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

DOES ROGUE MINING REALLY MATTER?

1 There's a REPUTATIONAL cost

2 There's a REGULATORY cost

3 There's an OPPORTUNITY cost

4 There's the CUI BONO cost5

Page 21: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

DOES ROGUE MINING REALLY MATTER?

4 Where is all that money going?

Page 22: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

DOES ROGUE MINING REALLY MATTER?

4 Where is all that money going?

💉🔪💣🎯💩⚔

Page 23: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

The 5 Ps

Patch early, patch often

Pick proper passwords

Protect your portals (e.g. RDP)

Pounce on PUAs

Prefer 2FA

Page 24: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations

Sophos Synchronised Security

Page 25: CRYPTOMINING - Black Hat | Home · 7/20/2018  · Paul Ducklin Who am I? duck@sophos.com @duckblog nakedsecurity.sophos.com. performing the zillions of cryptographic calculations