As is usual the guys running Black Hat organized another stellar event this year. The threats are real and very chilling. Bottom line is that the security “researchers” have moved into exploit territory where nearly all companies have grossly inadequate defensive measures in place. The dominant themes were exploiting web services, client web browsers, and other types of application security weaknesses. And yes, a healthy dose of hardware/driver based exploits were presented as well. After hearing these talks it becomes apparent that firewall, VPN, and IPS technology is just not going to help us defend ourselves against these emerging attacks. However, newer defensive tools like application firewalls, web/xml firewalls, and HIPS may help us in some cases. The issue I see is that most corporations just don’t have any of these things running in production right now.
I found the most interesting, and most deadly, topic to be about virtualized malware, or stealth malware. The most famous rendition of virtualized malware is the blue pill project by Joanna Rutkowska. Joanna has been researching this for about 2 years now. This stuff is not theoretical, if you want the code you can go to her site and download it here http://bluepillproject.org/. Also here is her Black Hat presentation called IsGameOver(), anyone?
Here is how blue pill works:
The name Blue Pill (think the Matrix Movie) is no accident. In the movie, if Neo would have chosen the Blue Pill offered by Morpheus he would have forgotten everything and remained in the ignorant bliss of the Matrix. When force fed, the Blue Pill rootkit, developed by Joanna Rutkowska, has this same effect on PCs in real life. Once infected with Blue Pill your host operating system is experiencing the same thing as Neo was before he got pulled out of the Matrix. Basically they are both living a lie. The Blue Pill, just like the Matrix, is controlling the minds of its hosts. The hosts are completely oblivious to the fact that what they are experiencing is not real but instead a completely fabricated environment that feels as authentic as the real one. The host looses the ability to determine what is real from what is not real, “how do you define real?” in an environment that yields the perception of self-control but secretly retains ultimate control. The operating system, like a person in the Matrix, is a slave to the Blue Pill. It will blindly trust anything that the Blue Pill tells it. But unlike the Matrix, the Blue Pill is completely undetectable (at least to date).
I just hope someone discovers the “déjà vu effect” in the Blue Pill soon!
So it brings about the obvious question, is my or your PC already infected with the Blue Pill? How would you know???
Jamey Heary, CCIE #7680, sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey is the author of Cisco NAC Appliance: Enforcing Host Security with Clean Access. (Check out all of Jamey Heary's books from Cisco Press.) He also has a patent pending on a new DDoS mitigation technique.
Jamey sits on several security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is an experienced speaker who is recognized as an expert in network security architecture, regulatory compliance, and routing and switching. His other certifications include CISSP, CCSP, and he is a Certified HIPAA Security Professional. He has been working in the IT field for 15 years and in IT security for 10 years. Jamey is currently a Distinguished Systems Engineer at Cisco Systems.