Tuesday, March 8, 2016

A technical scheme for "watermarking" intrusions

A Sample Scenario

A commercial security company finds a trojan on one of the servers used by Turkey Point Nuclear Generating Station. While none of the management machinery is compromised (and in fact, is not even computerized), the server is responsible for both holding sensitive information and conducting other sensitive operations and an analysis by a point team deployed from a National Lab indicates that had those operations been compromised, there was a possibility of power loss from Turkey Point, although not a nuclear release.

What our policy-makers do in this event is often dictated by whether they know, for a fact, that the trojan was placed there by a participating nation state following acceptable norms, or if it is potentially the work of a rogue nation or criminal group. Sometimes these situations will matter in the future to the point of "evacuate large cities" versus "clean up and forget about it". Our technical and political protocols as represented in this post are a first-draft attempt to provide an initial, reasonable step, towards a solution.

Some other solutions

One major other idea people want to implement is of course "no go zones" for intrusion. This is harder than it looks. Most important systems are dual use - collecting intelligence about a power plant is indistinguishable from being in a position to DoS it. So we back down to having the norm of "taking all due care" when on a sensitive system. This is nearly impossible to audit or manage. So for this and other reasons not stated here, we recommend instead that a system of "anonymous Red Phones" be set up.

The Value of Multilateral as Opposed to Bilateral Norms

Assuming you have a perfect way to do the watermarking as described below, if you only have two members of the Norms Group, detecting the watermark provides attribution. Therefore having many members in the norms group is ideal.

Likewise, a group-level anonymous "red phone" can allow for back and forth over a contested issue without running into the attribution issue.



Real World Use Cases


This "international incident" related to the war in Ukraine was in fact, nothing of the sort.


A basic background in watermarking


Every watermarking specialist has spent hours looking at this image and can't even see it anymore, just patterns of high and low frequency data.

Steganography and Watermarking are very similar, but watermarking has one clear major difference, especially when used, as most people want to, to fingerprint movie files or images so you can tell which customer you sent them to.

This is the normal conceptual format for watermarking, which is how visually inspectable watermarks work. This works fine as the smart people at BangBus know very well.


But customers hate seeing watermarks all over the place and of course, visual watermarks are subject to tampering and removal using that advanced "crop" tool in Windows Paint (or more sophisticated techniques I won't go into). So what super smart PhD people do is an invisible watermark, using this basic format:


And lots of people do really good mathematical work making watermarks (all of which boils down to hiding information in the hair and feathers of Lena). After several pages of math doing statistical modeling, you can add your watermark to compressed data and remain still basically invisible to the human eye, while still being recoverable after display or just from the compressed data stream itself. You'll note that all schemes like this avoid using EXIF or other tag data parts of the image format because you can't get a PhD by doing the obvious solution. However they have one simple problem, which is they all fail in the exact same way:



This is just how information theory works, and no amount of PhDing can solve it, in my opinion (and hopefully in yours). For this reason, invisible watermarks historically only work when the world does not know you are doing them. We are not so lucky in our goals (dire music goes here).

What are our design goals and constraints

One key thing is that we don't need to watermark software in particular, but intrusions in general. And intrusions are large complex things. Some of them involve exploits, some involve software implants ("Trojans") and some involve hardware implants. Many involve all three and each of those three components has many sub-components all of which we are expecting the skilled intrusion detection team to have access to when they conduct their analysis - but not necessarily immediately.

Significant intrusions get analyzed by teams of experts when they are discovered. But of course, signs of intrusions are being looked for by automated systems all the time. Our goal is to create a system that is detectable by a team of experts, but not by an automated system. An extremely robust system will be detectable just from an incident response report, without any access to the raw intrusion data at all, which has some political advantages.

Our particular technical options

The simplest way to indicate that we are a "nation-state" and not a "criminal group" is to share a private key and cryptographically sign a random data blob within as many sections of your intrusion chain as possible. The more places you sign, the more likely you are to be "validatable" by the Nation State Incident Response team (which also has the private key).

Of course, to "hide" this from automated detection techniques, you could make both the Blob and the signature something computed by code that, in some cases, is never even run during normal use.

Encryption routines are common inside implants. Likewise, most implants gather data from the machines they are installed on, for use as a key to encryption routines. This is valuable to them because it makes incident response harder (even INNUENDO does this). This is valuable to us because it means that a signature cannot be stolen from one trojan, and added to another trojan on a different machine.

Imagine an even tinier protocol, where you simply decide on a large set of 32-bit numbers, and if you see any three of them inside the analysis of your trojan, it is part of the Group. There is plenty of cover data to hide these numbers in. They could be register values computed during an initialization operation, for example. Or even text included within the program as a "forgotten debug variable". This kind of protocol would be more vulnerable to a theoretical "automated detection", but is more resistant to other kinds of analysis (no way to steal a signature if you can't figure out what part of the code is the signature). Likewise, this scheme operates without needing additional information from the host systems. Another benefit to this kind of scheme is that it is applicable to "data in motion" as well as data at rest (aka, Exploits).

The end result may be a multi-layered scheme, with each layer operating at a different level of confidence and security.

In the end you get a "uniform" for your intrusion efforts, but one that has camouflage and is not transferable to criminal groups.

Social Protocol Design


In addition to a technical design, we also need to decide when and how things such as keys will be distributed, what does a revocation look like, what does a "challenge" look like in case you think someone is overstepping the acceptable norms, or failing to sign their work, etc. I will leave all thoughts of this to another paper as it largely depends on having a working technical solution first. But this protocol will initially offer at least the possibility of an anonymous group "Red Phone" to avoid crisis when we need it most. A worthy goal?




Monday, March 7, 2016

The Cyber Domain is Different - Part 2

One major difference between cyber, and how we handle Nuclear/Chem/Bio is in the origin. If you are a self-defined "policy person" it might be wise to ask yourself how the below group of people, all of them PhD's essential in the beginnings of Nuclear efforts, differed from the people that you know are smart about strategy in the cyber domain:

If you gathered the people essential to building a cyber war doctrine for the US, none of them would have PhDs or teaching positions at Universities. A pretty big difference!

This is a difference extremely under-rated in Government policy circles, as I've seen first hand.



Tuesday, March 1, 2016

How are 90's hackers relevant to policy people, anyways?

TL;DR: All those 90's hackers have built things that warp the Internet in strategically interesting ways.


I had a comment from one of the policy experts who reads this blog. She asked "That was interesting, but how is that relevant to policy people?"

That's a good question! One quick answer to that is that analyzing the "birth" of cyber is a good way to understand why Cyber is not the same as Nuclear/Bio/Chem when it comes to regulation.

The first thing I want to help policy-peeps understand is that a cyber weapon is anything that changes the terrain of cyberspace.


  • This can be by allowing you to offer information without it being blocked by your adversary: think Wikileaks, Pirate Bay, or Tor Servers 
  • It can also be something that allows you to access confidential information (think NSA's QUANTUM)
  • Or it can be something that offers situational awareness (like Shodan or a rack-mount of Qualys servers with a team of people that really know how to use it)
  • Or a program that offers a hardware implant for every router on the market


But in general, real "Cyber Weapons" are very large programs - staffed by ten people minimum each. And they change the fundamental way the network works, as opposed to having a list of features like a commercial product.

And every one of those groups from the 90's knows that and has been in places where they have built them and many of those people continue to build them to this day. This is one of the differences between, say, Nuclear and Cyber. Whereas Nuclear was largely started in one place, Cyber started all over the world at about the same time. Remember that it took a letter from Einstein himself to start the Manhattan program, because only he understood the ramifications of the theories, and had the political push to make it happen.

But it is not a mistake that ten years ago there was a huge exodus of offensive talent from the intelligence community to Microsoft and Google and now they are at the forefront of the strategic war. It is not a mistake that the people involved in those 90's hacker groups have a different understanding of the possibilities of cyber.

And so WhatApp has strong end-to-end crypto, Napster offered files that were hard to remove from the net, and Wikileaks and Pirate Bay still exist even after massive US Government attempts to blot them from the Internet. What do you think the members of "Hacked By Owls" did after they were done defacing things? Lots.

I could go on, but think as a policy person to yourself: How would the world be different from a policy perspective if every major country on Earth had nuclear technology at first, instead of just the US? Too often the policy world asks itself "How is Cyber similar to Nuclear Weapons?" instead of asking how they are different.

And if you see something in the news that changes the Internet, anything really, ask yourself where it came from. Chances are one of those 90's hackers teams is behind it.

Sunday, February 28, 2016

A plausible platform for cyber norms

While at times we discuss "cyber norms" with other States, I think it is good to start byte-sized and build a platform for reciprocal trust that mirrors our technical capabilities.

For example, last year we had a problem where we accused Russia of a state sponsored attack on JP Morgan. The United States defines financial utilities and companies as critical infrastructure, and it is easy to see how a simple malware incident can result in serious consequences. For example, we find ourselves trying to draw very subtle lines in the sand when it comes to penetrations of power plants and other utilities.

Watermarking implants can help solve these issues: in particular the issue of not knowing whether an intrusion is the result of a known responsible actor following accepted norms, or a rogue nation or third party.

Watermarking does not have to solve the attribution problem - they can be shared watermarks that attribute an implant (or "trojan" in common parlance) to a group of nations. For example, Russia, China, Israel, Germany, France, 5Eyes, etc. These nations can share a watermarking protocol which would allow them to provide a technical platform for "Red Phone" activities, or higher-level norms, including "off limits" targets or activities.

Take, for example, the 5eyes penetration of Belgacom. If the Cyber Group has decided that a norm they are following is that they will not perpetrate credit card/financial fraud, and they will not conduct economic espionage, the liability of Belgacom is much reduced when discovering a trojan on their network that has been "Signed" as a participating nation state.

This proposal increases all of our safety, and a follow-on paper is potentially available for people interested in technical details of how exactly you can provide signing protocols for watermarks that are shared, covert, and non-transferable.

(Think of this proposal as the opposite of the Tallinn Cyber Manual, which simply ports in one fell swoop current laws of war to "cyberized versions", including such hilarious nonsense as banning cyber-booby-traps, whatever those are. :> )

A Brief Introduction to Ancient History for Policy People

The technical community is often amazed by how little the policy world knows about the history of software vulnerabilities. So I want to take this post to introduce a few members of the pre-historical world, much as a Disney movie introduces you to a large plant eating reptile.

Both hackers and dinosaurs are equally adorable!

Let me put it bluntly: The people in these groups are now in places of influence in both Government and Industry all over the world. Like many fields, it takes decades to get a deep understanding of the issues involved in information security. This post is designed to give policy people the context they need to understand historical tribal factions which remain important today. All these groups were notable for performing a level of security research which eclipsed most nation-states during their time (and perhaps today, as well).

The CEO of Duo Security has an interesting take on the D&D alignment chart, which gathers historical groups with modern ones.

TESO


You may not recognize the pseudonyms "Halvar Flake" or "Zip" or "Stealth" or "Caddis". But I guarantee you that you would recognize their real names and the capabilities they have built in recent years, and those of us who were active in the 90's recognized TESO as the premium brand of quality exploits. In many ways, TESO and ADM changed public perceptions around exploits as things that could be developed with a level of quality crafting that was strategically better than just "proof of concept" but was in fact operational in the wild, with real science and artistic care.

TESO was largely a European group. But they were respected world-wide.

w00w00




Was Duke w00w00 or ADM?
People know about w00w00 a little bit because they had a few members who did very well in the media space ("Napster" was a w00w00 hacker and "WhatApp" was written by one as well. Hacker Billionaires!). But that undervalues the research and influence of other members in the largely American-based group.

ADM 

This group's name is short for "Association of Mobsters" in French. And it comes from a French base but of course like all hacker groups was international. ADM was also known for high quality exploits in the "Remote Unix Hacking" arena. 

ADM did a lot of research into early exploit automation (c.f. ADMHack) - integrating many exploits in one package which made intelligent decisions as it tried to exploit a given network. They did one known defacement: Of the DEFCON website.

-------------
ADMmountd.c
-------------

/*
 *
 *
 * Linux rpc.mountd 2.2beta29 exploit
 *
 * Coded by plaguez, Antilove, Mikasoft at the ADM Party (7/98)
 *
 * Credits:
 *    - DiGiT for finding the vulnerability
 * Compile: rpcgen mount.x ; gcc exmnt.c
 */

Are those names you know? They should be. Plaguez inspired some of my early shellcode, but ADM was another one of those teams (no picture is available) who were far ahead of their time. You would know the real names of these hackers should I mention them here, which I am not rude enough to do.


GOBBLES



"GOBBLES were auditing the Roxen webserver packages for holes that can be
used to comprimise servers so that GOBBLES could have the holes patched so
that no servers could be comprimised."

Enigmatically GOBBLES was famous for both having a sense of humor and broken English in their exploits, which were often against targets chosen purely for comedic effect, but also for poking fun at the developing security industry and its hypocrisy and lack of skill. Their most famous work was the exploit Apache Nosejob, which exploited a rather tricky overflow in the Apache web-server on the "Secure" OS OpenBSD, using a vulnerability previously declared unexploitable by the ISS X-Force researchers who discovered the issue.

They became famous via posts of humorous "Advisories" to the Bugtraq mailing list, but below is a video at DEFCON (the famous "Wolves Among Us" talk) which added to their popularity by examining cultural issues in the security community itself. You'll also notice the famously tall Stephen Watt make an appearance.




l0pht Heavy Industries

This group includes now-Government executives, and the beginnings of the security consulting industry.

This sprawling Boston-based group is famous for many things, including the hackers which released l0phtcrack and Back Orifice 2000 (an early Windows RAT). They later sold themselves as a company to @stake (which I joined when I left the NSA), and also testified in front of Congress on cyber-issues, highlighting the risks long before they were a political hot potato.

One odd fact is that this crew also started the practice of issuing formal "Advisories" for security vulnerabilities that the group GOBBLES was well known for making fun of.


Phenoelit


Since I am currently at a NATO workshop with a member of Phenoelit talking about policy with Government officials, I cannot avoid pointing out that this German-based team still, in fact, exists and is doing good work in the space. They also run the ph-neutral hacking conference, which is unique in having no "talks". Their most famous member "FX" is well known for doing router hacking before it was cool enough for Alex Wheeler to do. Router hacking is still important! Think of it as "Internet of Things" work, but before the marketing droids got their beady little eyes on it. 

Phrack and Phrack High Council (PHC)/Project Mayhem

These two are very different but easy to confuse. Phrack magazine is a a well known research publication in the space, whereas PHC was known for hacking other hackers and releasing their private information, especially those who were "White Hats". 

Conclusion

Not listed here are cDc, LSD.pl, SYNNERGY, 8lgm, and many others, each of which remains highly influential in the space. If you are annoyed you are missing, please feel free to send me a paragraph.



Sunday, February 21, 2016

Cyberwar and Breaking the Forth Wall

Immunity is a company, but corporate survival required that long ago we develop a braintrust to understand large sweeping ideas about cyber war.

In particular, we attributed the Sony Pictures attack to North Korea very early on , we have a different understanding of what a cyber weapon is, and we see the current conflict between Apple and the FBI in a very different light from most people.

When my friends from Apple ask me for the Immunity take on the lawsuit, the honest answer is that the lawsuit is a tiny part of an ongoing re-alignment between Governments and the tech industry we all rely on, much as the war in Iraq was a realignment of the balance between the Sunnis, Kurds, and Shia.

We see everything post-Snowden, including this lawsuit, as a failure of the US Government to understand how national sovereignty has changed due to the Internet and a complete lack of understanding that they are in the middle of an insurgency that requires counter insurgency tactics, and not simple legal efforts. This is not a popular position, needless to say.

Insurgencies are always a battle of ideas, would be our response.

And of course, the most famous insurgency of all time had a bit to do with the limits to search and seizure. But let's take a look at the optics for a sec:



The FBI's position on Apple is the most telling thing, because it is every government's position, in the sense that Apple's desire to protect their reputation isn't worth two cents of consideration by the FBI. As far as the FBI is concerned, a 1% chance of finding anything useful on that iPhone is worth a 99% chance of destroying Apple's reputation or international market position. That's not what a COIN scholar would call "Sharing the risk".

But not wrong. :)

Let me put it broader: The FBI does't think the tech industry's opinion matters, because the tech industry is part of a much larger population that the FBI represents. But if you took a national survey of Iraq as to how the country should be run, all the oil profits and national decisions would of course rest with the Shia in Baghdad. The FBI's lawsuit against Apple is exactly that national referendum. They may win it legally. They may win it in the court of public opinion. But they will have already lost it in the places that matter precisely because the FBI doesn't think they matter.

The CEO of Twitter thinks your strategy is bullshit, Jim Comey.
So no matter if they win a court case based on a law created before electricity, the idea of prosecuting it is a stupid stupid idea by an FBI team that doesn't even realize what kind of war it is fighting. Has anyone asked them what happens if they win? What happens when every customer, instead of getting a U2 album on their phone, gets free end to end encryption that inter-operates with Google's Android and does voice as well? All they have to do is put Signal on the top of both app stores and wait.

What the FBI needs to do at the top level is realize a slow managed landing from the golden age of surveillance is preferable to a sudden crashing exit where now you're fighting a tech war you can't win against all the former government engineers that you can no longer attract to work for you.

But it may be too late to do the smart thing. Our only hope of resolution might be just to buy the FBI all a copy of Snow Crash. Honestly it boggles my mind when policy people haven't read that book. If you're reading this and you're doing policy work, spend the two hours it takes to look at Neal Stephenson's take on how this ends up and tell me why he's wrong. :)



Tuesday, February 16, 2016

Why 0day is a nebulous concept, part 1!

There is an inherent problem with taking things that come out of the technical community as slang and then attaching legal meanings to them. But of course, the law profession is not without its hubris and thinks that it can pretty much define anything. Sometimes they even try to redefine mathematical constants such as Pi.

In that way, law is not a science, as much as engineering. So not to pick on any particular lawyer, but I want to quote some brief twitter exchanges to help illustrate the concept.


My analysis of how OPSEC decisions are made is entirely aligned with everyone else in the field, but we don't usually let lawyers in on it because we have to start our discussion from scratch, is what I read from that. :)

I enjoyed her responses a lot more knowing she had no idea what my background was. Someday Susan and I will have a beer and a good laugh about it.

Let's talk about a better mental model for lawyers to use when they are talking about the wild and wonderful world of vulnerabilities! It may help them understand why the concept of "0day" is so slippery in real life, and even of "exploit" and "vulnerability". (c.f. This Phrack Paper for some historical details on terminology dating to 2002, which were already widely used within the world of security engineers.)


Here are some key concepts:

  1. Code flaws are often used to create multiple primitives. Multiple primitives are used to create exploit logic - and you can combine them in lots of exciting ways, like when you create cookies. 
  2. 0day is a label that assumes what other people don't know. It is a model of the mind, not a scientific principle you can hang regulation on.
  3. Exploit engineers don't generally use the term "payload" - and incident response people use it to mean "trojan stage" or "dropper" which is confusing.
So in this sense, when lawyers say they handle the term "Vulnerability" just fine, neveryoumind, what they mean is "We don't know if it means code flaw, exploit primitive, use of that exploit primitive in an exploit, or what?" and when they say "0day" they are expecting you to be omniscient, which is optimistic, at best.