10 Steps to Detect Lateral Movement in a Data Breach

3 min read

Many enterprises spend millions of dollars on solutions that promise to bolster their security. However, much less focus is placed on the ability to detect lateral movement during a breach. We’ve seen time and time again that once an attacker gains an initial foothold in a network, they will typically perform internal reconnaissance to solidify their presence. From this point onward, most attackers follow the same basics strategy – gain access to a lower privileged, less secured host, escalate privileges, and then begin seeking out additional targets on the network.

If you can identify the attacker during lateral movement, it’s game over for them.

Unfortunately, it’s not easy to dig deep into internal networks. When the amount of data generated is in petabytes, even the best data breach security solution will produce a large number of false positives. The problem is so severe that 55 percent of security alerts organizations receive are considered as erroneous. Hence, the irrelevance and volume of alerts lead enterprises to ignore or disable their logging solutions

However, it doesn’t have to be that way.

If you can set up barriers along the way, you may be able to protect against high-value breaches, or at least slow the adversary down enough that you’re ready to contain the outbreak. Here are ten steps you can take to detect lateral movement:

Once inside a network, attackers prefer using native tools to avoid detection by EDR and anti-virus software. This is an anomaly that security teams can detect. Try to identify what tools your network administrators use and what resources they typically access, such as an Intranet site or an ERP database. With that information, you can spot discrepancies in the way administrative tasks are performed. Also, a combination of directory services like Active Directory and network information (NetFlow data) can help you winnow down the list of expected behaviors, and from that provide a benchmark for comparison.

A significant challenge to all the indicators of a data breach is that they demand detailed analysis of data that can’t be readily accessed. Also, the security team must cross-reference a variety of information sources to gain insight. So, the best thing to give attention to is the login. By carefully monitoring login activity, you may be able to detect compromises before critical actions, such as data access and third-party compromise, take place. That makes login monitoring a pre-attack indicator – logon after hours or at a strange time of day can indicate lateral movement.

Hackers love credentials to remain unidentified and ease their process. They steal user accounts and use them to gain privileges and explore the network. Therefore, analyzing credential usage can help you spot outliers. Moreover, log analysis from your authorization and authentication infrastructure can help you identify credential abuse. For instance, data extraction and analysis will give you a sense of how many devices each authenticated user interacts with. Baseline the average user, then look out for anomalies.

One step an adversary usually takes is to identify what file servers can be broadly accessed to either encrypt confidential data remotely or extract essential data, such as credit card numbers or social security numbers. Therefore, discrepancies in file share access can be a vital indicator of lateral movement and may also lead you to a malicious insider. Monitoring and analyzing logs from your file servers is the most efficient way to do this yourself.

If you’re using perimeter security tools, they may already be keeping tabs on command and control activity.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at resources.infosecinstitute.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.