The art of cyberdefence

    • In the age of cyberwarfare, passive defence is a losing game. Preparedness, fuelled by self-knowledge and a keen understanding of adversaries, is a better strategy.
    • In the age of cyberwarfare, passive defence is a losing game. Preparedness, fuelled by self-knowledge and a keen understanding of adversaries, is a better strategy. ILLUSTRATION: PIXABAY
    Published Wed, Feb 21, 2024 · 05:00 AM

    IN THE global game of cyberwarfare, businesses are the pawns, their data the treasure, and ransomware the weapon of choice. Recently, a global firm headquartered in Singapore and with offices around the world, found itself on the front lines of this digital battle. 

    “Victim Co” (an alias) saw its IT network breached by an unseen enemy wielding a potent strain of ransomware. The invaders held the firm’s corporate data hostage, encrypting it all in a digital lockdown. About 2,000 servers and end points had been locked up and, to prove a point, the attackers exfiltrated hundreds of gigabytes of corporate information.

    It was a methodical siege, waged by a cybermercenary army, operating as a “Ransomware as a Service” (RaaS) gang where separate groups collaborate, each playing its part in the digital heist.

    There was the “researcher” sniffing out vulnerabilities, the “attacker” infiltrating the network and deploying the crippling ransomware, and the “negotiator” negotiating a hefty Bitcoin ransom for the unlocking of encrypted data and its safe return. The attacker had also extracted hundreds of gigabytes of corporate information, intending a double-extortion by threatening the exposure of such sensitive data on the underground Internet, the Dark Web. A further triple-extortion, targeting the victim’s business contacts (should the attacker uncover any related information from the exfiltrated data), would be part and parcel of the ransomware game rules.

    However, Victim Co refused to succumb to this ransomware threat. No hefty Bitcoin payouts, no negotiations – a global policy it had set for itself. Instead, it hunkered down, engaging an incident-response team of cyberdetectives to trace the invaders’ path of attack and to learn when and how it was attacked.

    The team of cyberdetectives was inspired by the Chinese military strategist Sun Tzu who lived centuries ago. His treatise on military strategy and tactics, The Art of War, though centuries old, has offered invaluable insights that have guided nations and even business leaders.

    Following the wisdom of Sun Tzu – “Know thyself, know thy enemy” – the cyberdetectives launched a counter to the offensive. A forensic investigation, akin to a cyberarchaeological dig, unearthed the attackers’ fragmented fingerprints – a collection of evidence remaining in the affected computers, such as IP addresses suggesting the possible origin of the attack and incongruous tools. Cyberforensics triage enabled the detectives to piece together the digital evidence to ascertain the timeline of the “cyberblitzkrieg”. This intel became the basis of building Victim Co’s future cybersecurity infrastructure.

    Days turned into weeks for Victim Co. The cyberdetectives closely monitored the network to check for any further intrusions and leaks on the Dark Web. The ransom note remained unanswered as the negotiator failed to engage Victim Co. After several weeks, the attack abated; the exfiltrated data had not been publicly exposed – perhaps a stroke of luck rendered it useless for extortion.

    Despite its close shave, Victim Co was one of the few enterprises that emerged relatively unscathed reputationally in a ransomware attack. Others were not so fortunate. In June 2017, shipping giant Maersk had its IT systems and network crippled by the NotPetya ransomware. The outage left Maersk unable to process shipping orders, freezing revenue from several of the company’s shipping container lines for weeks. The way the company handled the attack had been documented in earlier online reports.

    The outage cost Maersk US$300 million and took the shipping firm months to rebuild its IT systems from scratch. The key lesson it learnt was that while protecting networks and critical systems must be the ultimate goal, a data recovery plan must also be in place in the event that critical services are knocked out and business has to continue.

    Globally, ransomware is the leading threat for businesses and is estimated to cost victims around US$265 billion by 2031. Other organisations that have been held hostage by ransomware include oil and gas company Colonial Pipeline, governments such as Ukraine, and public-sector agencies such as the United Kingdom’s National Health Service.

    Technology has made these attacks even more prolific. RaaS is a platform for cybercriminals to form collectives and access anything they need for a ransomware attack. These attackers are also becoming more sophisticated, deleting computer logs to disrupt forensic investigations, and even resorting to double- or triple-ransom tactics. They might extort victims beyond the initial ransom, exposing sensitive stolen data or even threatening business partners with information leaks.

    On the computer system, the criminals can tamper with the timestamp, such as inserting a different date for a bank transaction, to throw off any forensic analysis.

    Cyber triage

    The ransomware attack on Victim Co eventually abated. But, one cannot be certain that the stolen data will not reappear on the Dark Web.

    Battered but unbowed, Victim Co emerged from the digital battlefield with lessons learnt from the intel collected by the incident-response team. It understood that in the age of cyberwarfare, passive defence is a losing game. Preparedness, fuelled by self-knowledge and a keen understanding of adversaries, could create a better defence path.

    Cyberattacks on businesses have become inevitable – they will happen; it is not a question of “if”, but “when” they will occur. Sun Tzu’s The Art of War could inspire enterprises and business leaders to use incident response as a tool in their anti-cyberweapons war chests.

    Hence, Victim Co’s story holds invaluable lessons in navigating the minefield of ransomware.

    • Know your enemy: Adopt a threat-informed-based defence for cybersecurity – understanding cyberadversaries is crucial for building effective defence. 
    • Build a robust shield: Implement a layered security framework with perimeter defences, be always vigilant through network monitoring, and create secure data backups.
    • Prepare for the inevitable: Develop an incident response plan and a business continuity strategy to minimise damage and ensure continuous operations.
    • Channel your inner Sun Tzu: Be proactive, not reactive. Turn passive defence into active mode to detect attackers as early as possible in the cyber-kill chain.

    A robust incident response along with the strategic adaptation of Sun Tzu’s ancient wisdom to modern cybersecurity would attest to the power of preparedness and knowledge in the face of modern cyberthreats. In the constant war against ransomware and cyberattacks, maintaining vigilance and tactical foresight would help businesses emerge victorious.

    The writer is head of consulting at Ensign InfoSecurity