determining evil from benign in the normally abnormal ... · determining evil from benign in the...

24
Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick 09-07-18

Upload: others

Post on 16-Apr-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

Determining Evil from Benign in the Normally Abnormal World of InfoSec

Rick McElroy, Security Strategist@infosecrick

09-07-18

Page 2: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL2

Know normal.

Find evil.

Page 3: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL3

VISION

A World Safe from Cyber Attacks

Page 4: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL4

NORMAL ABNORMAL

MITRE

ATT&CKTM

Page 5: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL5

"There aren't necessarily clear points of

difference between what's normal and

abnormal. Abnormal behavior may

just be an exaggeration of normalbehavior.”

- Professor David Watson

Page 6: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL6

Levels of Abnormal Process

Memory

System

User

Team

Department

Company

Industry

Country

Global

Page 7: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL7

Evil

Current TableActual Table

Normal Benign

Abnormal Evil

Normal Evil

Abnormal Benign

Frequent GOOD!!

Infrequent BAD!!

(Lawful Good) (Chaotic Good)

(Chaotic Evil) (Lawful Evil)

Page 8: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL8

Page 9: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL9

Evil..or not Evil?

Normal Benign

Abnormal Evil

Normal Evil

Abnormal Benign

Page 10: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL10

Evil..or not Evil?

Normal Benign

Abnormal Evil

Normal Evil

Abnormal Benign

Page 11: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL11

Evil..or not Evil?

Normal Benign

Abnormal Evil

Normal Evil

Abnormal Benign

Page 12: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL12

Evil..or not Evil?

Normal Benign

Abnormal Evil

Normal Evil

Abnormal Benign

Page 13: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL13

Evil..or not Evil?

Normal Benign

Abnormal Evil

Normal Evil

Abnormal Benign

¯\_(ツ)_/¯

Page 14: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL14

Know normal.

Find evil.

Page 15: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL15

Page 16: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL16

Goals of Effort

We want everyone to contribute data back to MITRE

We want to help teach developers to do the right thing

We want to reduce false positives for everyone

We want to save everyone time

Page 17: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL17

Our Commitment Slide

Host NORMINT Slack

Provide good known binaries back to MITRE

Page 18: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL18

Page 19: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL19

Page 20: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL20

“We cannot change the cards

we are dealt, just how we play

the hand.”

― Randy Pausch

Page 21: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL21

Know normal.

Find evil.

Page 22: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL22

Thank [email protected]

@infosecrick

www.CarbonBlack.com

Page 23: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

I © 2018 Carbon Black. All Rights Reserved. I CONFIDENTIAL23

Questions?

Page 24: Determining Evil from Benign in the Normally Abnormal ... · Determining Evil from Benign in the Normally Abnormal World of InfoSec Rick McElroy, Security Strategist @infosecrick

www.CarbonBlack.com