Sunday, December 6, 2020
  • Phishing Attacks on Your Brand are Unrelenting, AI is the Only Way to Fight Back
  • Germany’s Anti-Semitic Phonetic Alphabet
  • DEF CON 28 Safe Mode Aerospace Village – Allan Tart’s & Fabian Landis’ ‘Low Cost VHF Receiver’
  • XKCD ‘Contiguous 41 States’
  • DEF CON 28 Safe Mode Aerospace Village – Matt Gaffney’s ‘MITM: The Mystery In The Middle’

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Bloggers Network
    • Latest Posts
    • Contributors
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming
    • On-Demand
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
  • Library
  • Related Sites
    • MediaOps Inc.
    • DevOps.com
    • Container Journal
    • Digital Anarchist
    • SweetCode.io
  • Media Kit

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Application Security Security Bloggers Network 

Home » Cybersecurity » Application Security » Tales from the Frontlines: Increasingly Sophisticated Cat and Mouse Games  

Tales from the Frontlines: Increasingly Sophisticated Cat and Mouse Games  

by Jason Kent on June 4, 2020

The last Tales from the Frontlines post focused on a single customer and the attack volume increase they experienced following the COVID-19 lockdown. In this installment, we will look at the increasingly sophisticated game of cat and mouse defenders are playing with attackers, including high-volume diversionary tactics commonly used as distractions from the real attacks.

When attackers change their tactics, the mitigation techniques of organizations need to evolve with them. When bad actors attempt to take over accounts, create fake accounts, steal inventory, or utilize someone else’s financial information to commit fraud, they must maintain the attack.

To understand these attacks, one must also understand the attacker’s motivation. In most instances, the motivation is purely financial. People have money, and attackers want it. Often, it is how the attacker approaches the situation that determines the outcome.

For instance, the romance industry (various dating sites and “computer dating” platforms) are highly targeted because, according to the FBI, they are the second most lucrative attack type, just behind email “phishing” campaigns.

Additionally, retailers that utilize gift card services, rewards programs, and other means to entice legitimate customers with loyalty points leading to free items, are also attracting the attention of BOT attackers. Usually, the sole intent is theft, but often it isn’t the retailer that notices the theft until after the damage is done. Loss prevention used to be cameras in stores. Now it is alerts on systems that were never intended to be used for that specific purpose.

When met with resistance to their efforts, many attackers modify their tactics and techniques to continue their malicious actions. As defenders, we must stay one step ahead of the attackers.

Here are some of the attack trends we are seeing in our customers’ environments.

Increased Use of Commercial Proxy Networks to Mask Identity and Location

Proxy networks that enable an attacker to distribute their attack, hide their identity, and mask their location have become big business. The most significant change we see is that attackers are using multiple commercial proxy networks, not just the free ones. They are available with almost any geography as the exit point for the attack and vary in price based on the bandwidth and speed needed.

As we reported in the Bulletproof Proxy update, these tools make it easier to anonymize traffic’s originating country, ISP, etc. The first assumption most attackers have is that their IP address cannot be associated with thousands of requests against the same server. Rotating this IP address has become table stakes in an attack. We often see the attackers rotating every one or two transactions, changing between ISPs and countries on each subsequent request.

When drilling down into our customers’ environments, it isn’t uncommon for a single attacker to hit a handful of URIs from as many as 30,000 different IPs.

In a few cases, we see overall volumes to well-known endpoints increasing, /login and /password-reset are examples of places that are consistently under attack. But, we’ve also noticed behaviors that use volume to hide, such as a few attempts with known dumped credentials, and sometimes the endpoints get rotated while an attack uses volume on another endpoint to disguise activity.

More Rapid Changes to User-Agent Behavior

Once the attacker has established their attack infrastructure, they will want to consider what they look like to the end (target) systems. If they are targeting Android API endpoints, attackers don’t want to be using IOS based user-agents. But, that isn’t the only behavior that attackers have to monitor and understand.

All manner of tracking cookies and session tokens might be associated with a user’s activity. The same session token may or may not work with different user accounts or browser/mobile app types. Mitigation efficacy depends on the ability to see that the same user is coming from 12,000 different IPs and uses the same session token.

As the attackers modify their behavior, mitigation efforts change. If protection isn’t automated, the attackers will begin to win for a bit, then the defenders stop them. The attackers adjust, and then the defenders change.

Without automation detection strategies, the whole thing becomes a huge game of whack-a-mole.

Automated Detection is Needed

The way we detect attacks has changed and will continue to change as the bad actors’ tactics and techniques evolve. As attack sophistication increases, mitigation efforts need to maintain pace accordingly.

One thing we have observed within our customer base is that many never had an automation strategy against automated attacks before using our platform, and the attacks initially detected aren’t very sophisticated. When they first deploy Cequence, the alerts and triggers are often on straightforward things. Over time, the attacks tend to become more nuanced, requiring more information to set off the triggers and alerts.

For example, in the early stages, username and password attempts from the MySpace dump (yes, they still use it) may occur. Then, we’ll observe things like country language mismatching combined with inferred vs. tested browser types added onto known proxy networks. As our platform adjusts to the attackers, we end up in a situation where we don’t care where the moles pop up. They will get swiftly whacked.

Though attacker volumes may be changing, and though the attackers may be distracting us with noise to keep their sophisticated attacks working, we are still catching their bad behavior.

Applying data science to user behavior and understanding attackers means that we can maintain detection efficacy no matter how much they change, staying a step ahead as defenders.

The post Tales from the Frontlines: Increasingly Sophisticated Cat and Mouse Games   appeared first on Cequence.


Recent Articles By Author
  • Moving from Threat Hunting to Threat Catching
  • Tales from the Front Lines: How Third-Party APIs Simplify Enumeration Attacks
  • Tales from the Front Lines: Whitelist and Forget, A Cautionary Tale
More from Jason Kent

*** This is a Security Bloggers Network syndicated blog from Cequence authored by Jason Kent. Read the original post at: https://www.cequence.ai/blog/tales-from-the-frontlines-increasingly-sophisticated-cat-and-mouse-games/

June 4, 2020June 4, 2020 Jason Kent account takeover, API Attack, API security, Application Security, bot attacks, Bot Defense, Bots, Customers, General, Tales from the Front Lines, Threat Research, Uncategorized
  • ← The Joy of Tech® ‘Flush Facebook!’
  • WP 2FA 1.3: 2FA setup website page & improved 2FA policies →

TechStrong TV – Live

Watch latest episodes and shows
Featured Blog

Eric Kedrosky

The Future of Multi-Cloud Security: A Look Ahead at Intelligent Cloud Security Posture Management Solutions

Michael Clark

Prevent Catastrophic Data Loss in the Cloud

Rich Gardner

CISO Roundtable: What We’ve Heard, and What We’re Looking Forward To

Subscribe to our Newsletters

Get breaking news, free eBooks and upcoming events delivered to your inbox.
  • View Security Boulevard Privacy Policy

Most Read on the Boulevard

Brazil Govt’s Huge Leak: Health Data of 243M
Securing the Office of the Future
California Federal Court Weighs In (Again) on Social Media Scraping
Web App Security: Don’t Let the Code Injection Grinch Steal Holiday Joy
U.S. Election Security (and Insecurities)
Drupal Core: Behind the Vulnerability
The Future Of Work: The Hybrid Workforce
VMware Horizon Architecture: Planning Your Deployment
There’s a RAT in my code: new npm malware with Bladabindi trojan spotted
“Free” Symchanger Malware Tricks Users Into Installing Backdoor

Upcoming Webinars

Mon 07

The Battle for Container Security

December 7 @ 1:00 pm - 2:00 pm
Tue 08

XDR (Extended Detection and Response): The Next Generation of Protection

December 8 @ 11:00 am - 12:00 pm
Thu 10

Data Security for Contact Centers Leveraging Cloud Technologies

December 10 @ 3:00 pm - 4:00 pm
Mon 14

Issues and Answers in Cloud Security

December 14 @ 1:00 pm - 2:00 pm
Tue 15

3 Things to Get Right for Successful DevSecOps

December 15 @ 3:00 pm - 4:00 pm
Wed 16

Unsolved Problems in Open Source Security

December 16 @ 11:00 am - 12:00 pm
Wed 16

Securing Medical Apps in the Age of COVID-19: How to Close Security Gaps and Meet Accelerated Demand

December 16 @ 1:00 pm - 2:00 pm
Wed 16

Deliver your App Anywhere … Publicly or Privately

December 16 @ 3:00 pm - 4:00 pm
Thu 17

Secure Your Peace of Mind and Your Mobile App While Giving Developers Back Their Happy Coding Time

December 17 @ 11:00 am - 12:00 pm
Thu 17

Solving Kubernetes Security Challenges Using Red Hat OpenShift and Sysdig

December 17 @ 1:00 pm - 2:00 pm

More Webinars

Download Free eBook

7 Must-Read eBooks for Security Professionals

Recent Security Boulevard Chats

  • Cloud, DevSecOps and Network Security, All Together?
  • Security-as-Code with Tim Jefferson, Barracuda Networks
  • ASRTM with Rohit Sethi, Security Compass
  • Deception: Art or Science, Ofer Israeli, Illusive Networks
  • Tips to Secure IoT and Connected Systems w/ DigiCert

Industry Spotlight

Why Hackers Love the Pandemic
Cybersecurity Data Security Industry Spotlight Security Boulevard (Original) 

Why Hackers Love the Pandemic

December 4, 2020 Chris Hallenback | 2 days ago 0
Security and COVID-19: Securing the New Normal
Cybersecurity Data Security Industry Spotlight Network Security Security Boulevard (Original) 

Security and COVID-19: Securing the New Normal

December 3, 2020 DAVID CANELLOS | 3 days ago 0
Web App Security: Don’t Let the Code Injection Grinch Steal Holiday Joy
Cybersecurity Industry Spotlight Security Boulevard (Original) Threats & Breaches 

Web App Security: Don’t Let the Code Injection Grinch Steal Holiday Joy

December 2, 2020 Ameet Naik | 4 days ago 0

Top Stories

Brazil Govt’s Huge Leak: Health Data of 243M
Application Security Cloud Security Cyberlaw Cybersecurity Data Security Featured News Security Boulevard (Original) Spotlight Threats & Breaches Vulnerabilities 

Brazil Govt’s Huge Leak: Health Data of 243M

December 4, 2020 Richi Jennings | 1 day ago 0
Second Swiss Firm Said to Be CIA Encryption Puppet
Analytics & Intelligence Cyberlaw Cybersecurity Featured News Security Boulevard (Original) Spotlight Threat Intelligence 

Second Swiss Firm Said to Be CIA Encryption Puppet

November 30, 2020 Richi Jennings | Nov 30 0
Unisys Adds Visualization Tools to Stealth Platform
Cybersecurity Featured Network Security News Security Boulevard (Original) Spotlight 

Unisys Adds Visualization Tools to Stealth Platform

November 30, 2020 Michael Vizard | Nov 30 0

Security Humor

via  the comic delivery system monikered  Randall Munroe  resident at   XKCD  !

XKCD ‘Contiguous 41 States’

Join the Community

  • Add your blog to Security Bloggers Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: info@securityboulevard.com

Useful Links

  • About
  • Media Kit
  • Sponsors Info
  • Copyright
  • TOS
  • Privacy Policy
  • DMCA Compliance Statement

Other Mediaops Sites

  • Container Journal
  • DevOps.com
  • DevOps Connect
  • DevOps Institute
Copyright © 2020 MediaOps Inc. All rights reserved.

Our website uses cookies. By continuing to browse the website you are agreeing to our use of cookies. For more information on how we use cookies and how you can disable them, please read our Privacy Policy.