It is hard to believe that not one single zero-day exploit – or a previously undisclosed vulnerability – has been used against the United States in the last 24 months, and even harder that that fact could be viewed as a negative. But according to Curtis Dukes, deputy national manager for national security systems at the NSA, adversaries did not need to use such exploits, instead taking advantage of poor security and poorly patched systems.
Once adversaries had the initial foothold, he said Oct. 18 at an event hosted by the American Enterprise Institute in Washington, they elevated privileges and moved to mission objective, which is either exfiltration of personally identifiable information, intelligence or in the case of the attack on Sony pictures, actual destruction.
Dukes said he wants to raise the cost for adversaries, seemingly inviting them to have to use zero days against U.S. systems. He said he wants the U.S. government and the private sector to start using mitigation measures he outlined during his presentation to raise the cost on adversaries so they could start using zero days. This will help industry better prepare the U.S. against these types of attacks, he said.
This mirrors what some other officials in government have said.
“We have to drive the bad guys up the value chain, we have to cause them to spend more money [and] we have to slow them down so we can have a better chance of spotting them and containing them,” Deputy CIO for Cybersecurity at DoD Richard Hale said in February. “We think that if you have to use zero days against us, for instance, that ups the expense for a bad guy and potentially slows down the development of certain tools.”
“If you’re a network exploitation team, you don’t want to use those zero days, you want to keep those in reserve for the hardest targets that you’re going after,” Dukes said. “That’s why I said in the last 24 months [Office of Personnel Management] and the State Department weren’t particularly well-protected so the adversary didn’t have to use a zero day. They used a known exploit that they knew had not had a patch installed for that.”
In the last 24 months, the NSA has been involved in every major intrusion the federal government has had, Dukes said listing off high profile cases such as OPM, the State Department, Defense Department Joint Chiefs of Staff network, and two commercial companies that do background investigations on behalf of the federal government.
“Within NSA, my authorities are limited to national security systems, however, I have the ability to support the Department of Homeland Security and FBI through what we call request for technical support,” he said. This “gives me the ability to be deputized under their authorities to come in and actually help with incident response.”
Dukes provided a six-step intrusion lifecycle which every adversary employs, regardless of capability or capacity. It starts with basic reconnaissance escalating to exploits – or the initial process of gaining access through spearphishing or other means – then to establishing persistence to provide greater network access, to the installation of tools – which is where the adversary now “owns you,” Dukes noted – to the ability to move laterally through the network, to finally, the collection, exfiltration or destruction of data.
For each example, he provided a number of mitigation methods to combat each stage, which range from enabling anti-exploitation feature, use of anti-virus file reputation service, controlling of administrator privileges and backing up files offline to prevent data manipulation.
Dukes noted that there have been a number of active defense measures under evaluation to help overall cyber defense. “We’ve been looking at active cyber defense for probably five years now,” he said noting that they’ve looked into a security orchestrator, which enables security from the boundary to the device.
“You actually want to get to a point where based on [a] playbook, if you see these three or four things, then you have moderate to high confidence there’s probably this type of an attack and then you can actually have some type of an automated response,” he said. “You’ve got to get the humans out of the loop. The time that a human can respond and make a decision on whether or not to actually block, typically in cyber time the advantage is to the adversary.”
Dukes said there have been tests of these types of solutions at Johns Hopkins University as well as industry engagement.
Dukes explained to C4ISRNET following his appearance the emergence of offensive-minded defense as it applies to so-called hunt teams, or individuals within defensive cyber units that actively search networks and seek out intruders to irradiate them.
“Historically we have three teams. We have vulnerabilities assessment teams, also known as blue team, we had red teams, adversary emulation, and then in the last decade or so we actually started what we call these advanced hunt teams,” he said. “Basically what we were finding was is that we needed a certain skill set to be able to be looking hard on our networks for an adversary, because we may not be able to see them from the boundary so we needed teams that could actually deploy tools and techniques in that regard.”
Within the last 24 months, Duke said there has been some blending of these three teams as it relates to incident response. “For OPM we had blue, red and hunt teams that were part of the incident response,” he said, the reason being “we wanted to have that adversary mindset looking for signs of that adversary on our network and where they would be hiding.”
These teams are trained with an offensive mentality, he said, despite being employed on defensive teams with most of them being pulled from red teams. “They use threat intelligence that that we’ve gotten from our offensive folks to actually defend and develop tool [and look] for signs of an adversary” on the network, he said.
The concept of hunt teams has been something the Defense Information Systems Agency has been pushing as well with their cyber protection teams, which fall under the control of U.S. Cyber Command.
“I’ll say you are almost like the ‘new infantry’ in my perspective because on the cyber domain — it is a domain — we’re being attacked daily and we need people who can hunt key terrain,” John Hickey, DISA’s cyber development executive, said to members of cyber protection teams during a recent capstone training course.
NSA: No zero days used in last two years




