<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Luc Meier on Senthorus Blog</title><link>https://blog.senthorus.ch/author/luc-meier/</link><description>Recent content in Luc Meier on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Mon, 29 Jul 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/luc-meier/index.xml" rel="self" type="application/rss+xml"/><item><title>AI in Cybersecurity: SOC vs Hackers</title><link>https://blog.senthorus.ch/posts/ai_in_cybersecurity/</link><pubDate>Mon, 29 Jul 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/ai_in_cybersecurity/</guid><description>&lt;img src="https://blog.senthorus.ch/ai_in_cybersecurity_0.png" alt="Featured image of post AI in Cybersecurity: SOC vs Hackers" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>As cybersecurity threats continue to evolve, attackers are increasingly leveraging sophisticated strategies aided by advanced technologies. One such approach involves the utilization of artificial intelligence (AI) to craft highly convincing social engineering attacks, including AI-powered phishing attacks and imitation of real users&amp;rsquo; behavior.&lt;/p>
&lt;p>However, within a Security Operation Center (SOC), AI also plays a pivotal role in fortifying defenses and responding effectively to these evolving threats. At Senthorus, we harness AI-powered solutions like Microsoft Sentinel and Darktrace to bolster our clients&amp;rsquo; cybersecurity posture.&lt;/p>
&lt;p>In this article, we delve into the dynamic landscape of AI usage within a SOC, examining innovative tools and future possibilities that empower SOC analysts to streamline workflows, accelerate incident response, and proactively adapt to emerging threats.&lt;/p>
&lt;h2 id="on-the-attackers-side">On the attacker&amp;rsquo;s side
&lt;/h2>&lt;p>For an attacker, these tools can be extremely useful. They can use them for different sophisticated strategies.&lt;/p>
&lt;p>One such approach involves the imitation of real users&amp;rsquo; behavior, where attackers leverage machine learning algorithms to create bots that mimic human interactions. That way they can more easily bypass traditional security measures.&lt;/p>
&lt;p>Additionally, AI-powered phishing attacks have become more prevalent, with attackers leveraging data analysis and content generation algorithms to craft highly convincing and personalized phishing emails tailored to specific target groups.&lt;/p>
&lt;h3 id="imitation-of-real-users-behavior">Imitation of real users’ behavior
&lt;/h3>&lt;p>Attackers utilize bots that use machine learning algorithms to behave like real users. They train these models with data created by real people: keystrokes, mouse movements, browsing patterns, and more. That way, these bots can behave like humans. For instance, they realistically randomize the movement of the mouse when they click on webpage elements, and they make small mistakes when typing, just like a real user.&lt;/p>
&lt;p>All these techniques add more difficulty to the detection of an attack. For example, hackers have the capability to scan a network or a web application discreetly, looking for exploitable vulnerabilities, while acting like genuine users. In other instances, cybercriminals were reported fraudulently boosting the number of clicks to gain a quick reputation on a malicious website.&lt;/p>
&lt;h3 id="ai-powered-phishing-attacks">AI-Powered Phishing Attacks
&lt;/h3>&lt;p>This kind of phishing attack uses machine learning algorithms to create very convincing and highly personalized phishing emails.&lt;/p>
&lt;p>To generate these emails, attackers train the AI with victim data, often bought on the darknet. These datasets contain Open-Source Intelligence (OSINT) information about the victim (social media, enterprise website, &amp;hellip;) and/or leaked data (emails, messages, &amp;hellip;). With this dataset, the machine learning algorithm finds relationships between employees or customers, creating a uniquely tailored attack pattern for the victim.&lt;/p>
&lt;p>In the last step, the AI generates custom content for the phishing email that, through its high specialization, is very hard to detect as malicious. Even though each email content is tailored for the designated victim, attackers can automate the above process, allowing them to operate on a large scale.&lt;/p>
&lt;h2 id="on-the-soc-analyst-side">On the SOC Analyst side
&lt;/h2>&lt;p>In the dynamic realm of a SOC, the utilization of artificial intelligence (AI) has become integral to our daily operations at Senthorus. The usage of AI-powered solutions like Microsoft Sentinel and Darktrace allows us to fortify the security posture of our clients, at last establishing Senthorus as a true Next-Generation SOC. These advanced technologies enable us to detect and respond to threats with unprecedented speed and accuracy, enhancing our ability to safeguard critical assets and mitigate risks effectively.&lt;/p>
&lt;p>In this section, we’ll first dive into two AI-powered tools that we use at Senthorus. Secondly, we will talk about possible future implementations of AI that could help us, and other SOCs, to automate incident response, accelerate investigations, and optimize detection capabilities.&lt;/p>
&lt;h3 id="microsoft-sentinel-ai-powered-anomaly-detection">Microsoft Sentinel AI-powered Anomaly Detection
&lt;/h3>&lt;p>At Senthorus, we leverage Microsoft Sentinel extensively across our client base, this close partnership with Microsoft was just recently fortified by them nominating Senthorus as one of the leaders for Swiss SOC.&lt;/p>
&lt;p>In a security information and event management (SIEM) solution, AI, and machine learning are used to detect suspicious behavior in the organization of our clients.&lt;/p>
&lt;p>A prominent example is &lt;a class="link" href="https://learn.microsoft.com/en-us/azure/sentinel/anomalies-reference" target="_blank" rel="noopener"
>Microsoft Sentinel&lt;/a> which leverages machine-learning algorithms to detect anomalous behavior across several log sources. To do this, the algorithm is trained with various data like network traffic, user, and system logs. After this training, the algorithm establishes a baseline, any deviation from this baseline will trigger an alert. When an alert is raised, one of our analysts immediately investigates the activity of the device or user in question.&lt;/p>
&lt;h3 id="darktrace-cyber-ai-analyst">Darktrace Cyber AI Analyst
&lt;/h3>&lt;p>&lt;a class="link" href="https://darktrace.com/" target="_blank" rel="noopener"
>Darktrace&lt;/a> is a cybersecurity company that uses artificial intelligence (AI) and machine learning to provide real-time threat detection, response, and prevention capabilities. Within this platform, there are several key components, designed to address different aspects of cybersecurity, and &lt;a class="link" href="https://darktrace.com/news/darktrace-cyber-ai-analyst-investigates-threats-at-machine-speed-4" target="_blank" rel="noopener"
>Cyber AI Analyst&lt;/a> is one of them.&lt;/p>
&lt;p>When the Darktrace immune system detects an anomaly, the Cyber AI Analyst automatically investigates those leads. It works with a huge dataset that grows every day by capturing investigation information. When a model breach occurs, the AI Analyst waits one hour to have sufficient evidence for the analysis, before starting an automatic investigation. The automatic investigation does not differ too much from the one a “classical” SOC analyst does. First, the AI analyst starts with a lead, and then forming a hypothesis, before checking the large dataset maintained by Darktrace for further information corresponding to the incident. In the end, the AI Analyst makes a conclusion and shows his work in the AI Analyst UI.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/ai_in_cybersecurity_1.jpg"
loading="lazy"
alt="Cyber AI Analyst"
>&lt;/p>
&lt;p>Source: « Cyber AI Analyst - The augmented security analyst | Darktrace » on YouTube.&lt;/p>
&lt;h2 id="future-possibilities">Future possibilities
&lt;/h2>&lt;p>As SOCs continue to evolve in response to the ever-changing threat landscape, the integration of artificial intelligence (AI) holds immense promise for enhancing efficiency, effectiveness, and agility in cybersecurity operations.&lt;/p>
&lt;p>By harnessing the power of AI, SOC analysts can enhance their workflows, accelerate incident response, and proactively adapt to emerging threats, while ushering in a new era of resilience and proactive defense in cybersecurity operations.&lt;/p>
&lt;p>In the next sections, we are going to present three possible implementations of AI that can help SOC analysts further improve their workflows, accelerate incident response, and adapt proactively to emerging threats.&lt;/p>
&lt;h3 id="automatic-pre-filling-of-ticket">Automatic pre-filling of ticket
&lt;/h3>&lt;p>AI-driven automatic pre-filling of tickets promises to streamline incident response in SOCs. In this case, the AI model is trained with tickets previously completed by SOC analysts. Once the training is done an incoming alert will be analyzed and treated by the AI model, before closing the ticket a “four eyes check” with a human must be conducted. That way, tickets will still have the SOC’s personal touch.&lt;/p>
&lt;p>AI models are able to automatically set the corresponding &lt;a class="link" href="https://attack.mitre.org/" target="_blank" rel="noopener"
>MITRE ATT&amp;amp;CK&lt;/a> tactic and technique, rate the severity of the incident, and much more. This helps drastically save time and enables SOC analysts to focus on investigating and mitigating high-priority threats.&lt;/p>
&lt;h3 id="investigation-recommendation">Investigation recommendation
&lt;/h3>&lt;p>When a SOC Analyst starts investigating a ticket, it often takes some time to find where to search for further information. Drawing historical data based on older tickets, AI algorithms can guide analysts through the entire investigation: which logs to examine, which tools to use, and so forth. This proactive assistance can speed up investigations significantly, enabling analysts to swiftly identify and mitigate security threats.&lt;/p>
&lt;h3 id="rule-tuning-suggestion">Rule tuning suggestion
&lt;/h3>&lt;p>This future implementation of AI can help SOC teams optimize their detection rules effectively, particularly in scenarios where a high volume of alerts is triggered by poorly defined rules. Leveraging AI algorithms, the system analyzes tickets written by SOC analysts to identify rules with a favorable true positive to false positive ratio. By prioritizing these rules for optimization or refinement, SOC analysts can significantly reduce alert fatigue, focusing their efforts on investigating genuine threats, and enhancing overall detection efficacy.&lt;/p>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>Throughout this article, we&amp;rsquo;ve delved into the crucial role of artificial intelligence (AI) from the vantage point of both attackers and defenders, with a particular focus on Security Operation Centers (SOCs). Attackers are increasingly leveraging AI-driven techniques, such as imitation of real users&amp;rsquo; behavior and AI-powered phishing attacks, to evade traditional security measures and orchestrate highly convincing attacks. However, SOC analysts have also powerful AI-driven tools at their disposal, enabling them to detect and respond to threats with unprecedented speed and accuracy.&lt;/p>
&lt;p>Looking forward, the future of SOC operations lies in further leveraging AI, allowing SOCs to always stay ahead of the quickly changing threat landscape. Automated pre-filling of tickets, AI-driven investigation recommendations, and rule tuning suggestions represent promising avenues for enhancing SOC capabilities and staying ahead of evolving threats. As the cybersecurity landscape continues to evolve, the integration of AI will remain essential for resilience and proactive defense in SOC operations, ensuring organizations can effectively mitigate risks and safeguard their assets against ever-evolving cyber threats.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://darktrace.com/news/darktrace-cyber-ai-analyst-investigates-threats-at-machine-speed-4" target="_blank" rel="noopener"
>Darktrace Cyber AI Analyst&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.youtube.com/watch?v=Y0eLSRIFgFU&amp;amp;ab_channel=Darktrace" target="_blank" rel="noopener"
>Cyber AI Analyst on YouTube&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.youtube.com/watch?v=nqYJ1ReIdVU&amp;amp;ab_channel=Welcome.AI" target="_blank" rel="noopener"
>Darktrace AI Overview on YouTube&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://cyberaiworks.com/Cyber-AI-Analyst.asp" target="_blank" rel="noopener"
>Cyber AI Analyst Product Page&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://learn.microsoft.com/en-us/azure/sentinel/anomalies-reference" target="_blank" rel="noopener"
>Microsoft Sentinel Anomalies Reference&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/microsoft-sentinel-customizable-machine-learning-based-anomalies/ba-p/3624436" target="_blank" rel="noopener"
>Microsoft Sentinel Custom ML Anomalies Blog&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>CVE-2023-4911 A buffer overflow in the GNU C library</title><link>https://blog.senthorus.ch/posts/cve_2023_4911/</link><pubDate>Tue, 03 Oct 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2023_4911/</guid><description>&lt;img src="https://blog.senthorus.ch/cve_2023_4911/CVE_2023_4911_0.png" alt="Featured image of post CVE-2023-4911 A buffer overflow in the GNU C library" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;h3 id="what-is-this-new-cve">What is this new CVE?
&lt;/h3>&lt;p>This vulnerability, charmingly nicknamed &amp;ldquo;Looney Tunables,&amp;rdquo; affects version 2.34 of the GNU C library (GLIBC). It was discovered on October 3rd of this year. It is a buffer overflow impacting the processing of the environment variable &lt;code>GLIBC_TUNABLES&lt;/code>, in the dynamic loader &lt;code>ld.so&lt;/code>. This vulnerability enables a local attacker to exploit specially crafted &lt;code>GLIBC_TUNABLES&lt;/code> environment variables when executing binaries with SUID permissions, then run code with elevated privileges.&lt;/p>
&lt;p>This is a high-risk vulnerability due to its potential for elevating privileges and its broad impact across various devices. Indeed, numerous Linux distributions, including Fedora, Ubuntu, and Debian, are susceptible to this vulnerability. However, certain distributions such as Alpine Linux remain unaffected since they employ MUSL LIBC rather than GLIBC.&lt;/p>
&lt;h3 id="what-is-a-buffer-overflow">What is a buffer overflow?
&lt;/h3>&lt;p>A buffer overflow is a critical software vulnerability that occurs when a program writes more data into a designated storage area (buffer) in memory than it can hold. This excess data can spill over into adjacent memory locations, potentially corrupting or overwriting important information or code. In the worst cases, malicious actors can exploit buffer overflows to inject and execute arbitrary code, gaining unauthorized access or control over a system. Buffer overflows are a significant security concern and are typically addressed through secure coding practices, bounds checking, and other protective measures to prevent potential exploits.&lt;/p>
&lt;h3 id="what-is-the-dynamic-loader-ldso-and-glibc_tunables">What is the dynamic loader &lt;code>ld.so&lt;/code> and &lt;code>GLIBC_TUNABLES&lt;/code>?
&lt;/h3>&lt;p>The &lt;code>ld.so&lt;/code> program collaborates with &lt;code>ld-linux.so&lt;/code> to locate and load the necessary shared libraries for a program, ready it for execution, and then execute the program.&lt;/p>
&lt;p>The environment variable &lt;code>GLIBC_TUNABLES&lt;/code> is a feature in the GNU C library that enables the modification of the runtime library behavior.&lt;/p>
&lt;h2 id="demonstration">Demonstration
&lt;/h2>&lt;h3 id="setting-up-the-vm">Setting up the VM
&lt;/h3>&lt;p>I utilized an Ubuntu 22.04.3 ISO to perform the installation on my virtual machine, without internet connection. By doing this, I ensured that the GLIBC remained not updated. All other installation settings were left at their default values.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_4911/CVE_2023_4911_1.png"
loading="lazy"
alt="Setting up the VM"
>&lt;/p>
&lt;h3 id="proof-of-concept">Proof-of-Concept
&lt;/h3>&lt;p>After the VM installation is complete, I can execute the Proof-of-Concept command as specified in the Qualys Security Advisory.&lt;/p>
&lt;p>Let’s explain this command first:&lt;/p>
&lt;ul>
&lt;li>&lt;code>env -i&lt;/code>: Run the command with an empty environment.&lt;/li>
&lt;li>&lt;code>GLIBC_TUNABLES=glibc.malloc.mxfast=glibc.malloc.mxfast=A&lt;/code>: Assign this value to the GLIBC_TUNABLES environment variable.&lt;/li>
&lt;li>&lt;code>Z=\&lt;/code>printf &amp;lsquo;%08192x&amp;rsquo; 1``: Assign to the environment variable Z the command printf that generates a long string of 8192 &amp;ldquo;1&amp;rdquo;. (That’s the buffer overflow.)&lt;/li>
&lt;li>&lt;code>/usr/bin/su --help&lt;/code>: The command executed, just shows the help message of the su command.&lt;/li>
&lt;/ul>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_4911/CVE_2023_4911_2.png"
loading="lazy"
alt="POC image"
>&lt;/p>
&lt;p>In this scenario, when we receive the message &amp;ldquo;Segmentation fault (core dumped)&amp;rdquo;, it signifies our effective memory injection, confirming the device&amp;rsquo;s vulnerability. Although we&amp;rsquo;ve injected only a few &amp;ldquo;1s&amp;rdquo; in this instance, it demonstrates our capability to inject more malicious code if desired.&lt;/p>
&lt;h2 id="lets-update">Let’s update!
&lt;/h2>&lt;p>Now, we are going to fix it with a good old: &lt;code>apt update &amp;amp;&amp;amp; apt upgrade&lt;/code>&lt;br>
GLIBC is now up to date and if we enter the same command as before, we receive a different message. The system is no longer vulnerable!&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_4911/CVE_2023_4911_3.png"
loading="lazy"
alt="Vulnerability fixed image"
>&lt;/p>
&lt;p>If you want to update just the GLIBC package, you can do so with this command: &lt;code>apt install libc6&lt;/code>&lt;/p>
&lt;h2 id="how-to-prevent-this-in-a-soc">How to prevent this in a SOC
&lt;/h2>&lt;p>If you are using Microsoft Defender for Endpoint, you will find it in the Vulnerability section.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/cve_2023_4911/CVE_2023_4911_4.png"
loading="lazy"
alt="Threat Hunting image"
>&lt;/p>
&lt;p>If not, you can check the version of GLIBC with this command: &lt;code>/lib/x86_64-linux-gnu/libc.so.6&lt;/code>&lt;/p>
&lt;p>If the version is 2.34, watch out! You may be vulnerable to Looney Tunables. To be sure, you can enter the Proof-of-Concept command seen above.&lt;/p>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>In summary, we&amp;rsquo;ve established that this CVE affects GLIBC version 2.34, impacting a multitude of Linux distributions. This vulnerability allows the attacker to inject and execute code with root privilege. Fortunately, patching it is relatively straightforward, thanks to the package manager. All it takes is a system upgrade. However, it&amp;rsquo;s crucial to exercise caution, as many Debian/Ubuntu servers may not receive regular updates, making this vulnerability a significant concern.&lt;/p>
&lt;p>The &amp;ldquo;Looney Tunables&amp;rdquo; vulnerability serves as a vivid example of the constantly evolving threat landscape that security experts grapple with. Nevertheless, it also underscores the unwavering commitment and diligence of the open-source community, tirelessly engaged in identifying and remedying such vulnerabilities.&lt;/p>
&lt;h2 id="sources">Sources
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://nvd.nist.gov/vuln/detail/CVE-2023-4911" target="_blank" rel="noopener"
>NIST Vulnerability database&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.gnu.org/software/libc/manual/html_node/Tunables.html" target="_blank" rel="noopener"
>GLIBC_TUNABLES documentation&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt" target="_blank" rel="noopener"
>Qualys Security Advisory&lt;/a>&lt;/li>
&lt;/ul></description></item></channel></rss>