Computer Security Risk Assessment

Risk assessment is the process of analyzing threats to an information system and known vulnerabilities to determine the likelihood and impact of some anticipated loss. This risk analysis can then be used to design protective security controls that reduce these factors to acceptable levels.

Pre-requisite to Risk Assessment is System Characterization

NOTE – Risk Assessment is part of a greater process called Risk Management. Risk Management begins with Risk Assessment and then moves into protecting the information system with Risk Mitigation (through security controls) and closes out with Evaluation and Assessment to confirm that the Risk Managment process is actually working.

Risk Management: Define which parts of the process you have control over and which parts of the process you don’t have control over then maximize your exposure to the parts you can control and minimize your exposure to the parts of the process you can not control.

Threat Identification

The process of identifying threat sources that have the potential to exploit some weakness in the information system. The following list of common threat sources should be evaluated:

Natural threats

  • Storms
    • Floods
    • Tornadoes
    • Hurricanes
    • Electrical storms
  • Earthquakes
  • Slides
    • Landslide
    • Avalanche
  • Temperature extremes

Environmental threats

  • Power failures

Human threats

  • Unintentional
    • Data compromise
  • Intentional
    • Hacker/cracker
      • System intrusion
      • Defacement
      • Data compromise
    • Criminal
      • Bribery, extortion
      • System intrusion
      • Data compromise
    • Terrorist
      • Bribery, extortion
      • System intrusion
      • Data compromise
      • Information warfare
      • System disruption
      • Organizational disruption
    • Industrial espionage
      • System intrusion
      • Data compromise
      • Organizational disruption
    • Insiders
      • System intrusion
      • Data compromise
      • Organizational disruption

This threat analysis should be tailored to the individual organization and its environment and mission and the criticality and sensitivity of the data on the information system. In general, information, threat analysis, awareness and readiness are fairly high for natural threats and low for human sourced cyber threats.

Vulnerability Identification

A vulnerability is a weakness in a system or its protections that could be exercised, creating a breach in the security protection of the system. The goal of this step is to come up with a list of vulnerabilities that could be exercised by potential threat sources.

Vulnerabilities can be identified from lists and advisories on common vulnerabilities and also by testing the system.

Once a list of vulnerabilities that might be exercised against the system have been identified, they should be matched up against the threat sources that were previously identified, so that overall risk can be determined.

Vulnerability lists

System testing

  • Vulnerability scanning (see control RA-5)
  • Penetration testing
  • Security controls assessment (see control CA-2)
  • Previous risk assessment documentation

Security Requirements Checklist

The security requirements checklist contains the basics to evaluate and identify the vulnerabilities of information system assets, procedures, processes and information. The purpose is to determine whether security requirements are being met by either existing or planned controls.

KEY NIST DOCS:

800-42 “Guideline on Network Security Testing”
800-40 “Creating a Patch and Vulnerability Management Program”
800-115 “Technical Guide to Information Security Testing”

Patch Management

Patch Management is a critical part of security.

The need for patch management:

  • An increasing rate of exposure
  • An increasing cost of response
  • Expected results from a good patch management program
    • Reduce the time and expense of patching
    • Decrease the potential for exploitation
    • Reduce the disruption and expense of reacting to incidents
  • Security control SI-2 FLAW REMEDIATION
  • NIST SP 800-40 “Creating a Patch and Vulnerability Management Program”

A Patch and Vulnerability Group:

  • Description
  • Scope
  • Duties
  • Skill groups
    • System and network administration
    • Intrusion detection
    • Vulnerability scanning

Patch and Vulnerability Management Process:

  • Inventory
    • Laws – FISMA, FIPS-199, FIPS-200
    • NIST guidance
      • Documents – 800-18, 800-30, 800-39, 800-40, 800-53, 800-100
      • Security controls – CM-2/6/8, PE-16, RA-5, SI-2
    • CM-8 INFORMATION SYSTEM COMPONENT INVENTORY
      • System name
      • Property number
      • Owner (primary user)
      • System administrator
      • Physical location
      • Network port
      • Software configuration
      • Hardware configuration
  • Monitor
    • Types of concerns to monitor
      • Threats
      • Vulnerabilities
      • Remediations (patch, adjust configuration, remove)
    • Vendor information (web sites, email lists)
    • Third party information (web sites, databases, forums, email lists)
    • Scanning tools
    • Patch managment tools
  • Prioritize by significance of the threat, existence of malware and the patching risk
  • Create a remediation database
  • Testing
    • Authenticate the patch
    • Run a virus scan against the patch
    • Do testing in a non-production environment
    • Evaluate any effects on other patches
    • Evaluate varied configurations the patch may get applied on
    • Monitor the experiences of others in the security community with a patch
    • Reach a decision to deploy the patch
  • Remediation deployment types
    • Installation of a patch
    • Adjustment to a configuration
    • Removal of the component with the vulnerability
  • Distribute information
    • Automated – often performed by patch management software
    • Manual – email, web-based, or portable media
    • Considerations – alternate methods of distribution may be needed if the network has been compromised
  • Verifying remediation
    • Examine configuration settings
    • Vulnerability scanning
    • Network scanning
    • Host scanning
    • Review patch logs
    • Penetration testing
    • See NIST SP 800-42 “Network Security Testing”
    • See security control RA-5 VULNERABILITY SCANNING
  • Training

Metrics

  • Guidance
    • NIST SP 800-55 “Security Metrics Guide”
    • NIST SP 800-40 “Creating a Patch and Vulnerability Management Program”
  • Types of metrics
    • Susceptibility to attack
    • Mitigation response time
    • Cost
  • Metrics process
    • Targeting toward maturity
    • Metrics table
    • Document and standardize
    • Performance targets – cost effectiveness
    • Program implementation

Management Issues

  • Agent based software vs non-agent based software
  • Risks
    • Corrupted patch
    • Compromised tool
    • Countermeasures
  • Whether to combine the inventory process and the patch management process
  • Whether to combine the vulnerability scanning process and the patch management process
  • Deployment issues
  • Reduce the need for patching through smart purchasing
  • Establish standard configurations
  • Patching after a compromise can be problematic

Resources

Summary

  • Create an inventory database
  • Create a patch and vulnerability group
  • Monitor for vulnerabilities
  • Test patches
  • Deploy patches
  • Document the process
  • Automate the process as much as is practical
  • Verify vulnerabilites and patches
  • Train both network staff and users on issues

KEY NIST DOCS:

800-40 “Creating a Patch and Vulnerability Management Program”
800-55 “Security Metrics Guide”
800-42 “Network Security Testing”

Risk Analysis

Risk analysis is the process of assigning a risk status to the information system based on the information collected in the preceding steps. Threats that were analyzed according to their accompanying motivation level and capability level are paired up with matching vulnerabilities. These threat/vulnerability pairs are compared to protective security controls in order to determine how likely it is that an exploitation attempt will succeed.

Control Analysis

Analyze both planned controls and controls that are already implemented in order to determine the likelihood of a threat exercising a vulnerability

The checklist developed in the last section (Vulnerability Assessment) is used to analyze security controls.

Likelihood Determination

Take into consideration:

  • Threat source
    • Motivation
    • Capability to exploit a vulnerability
  • Security controls
    • Existence
    • Effectiveness at mitigation

Balance this information to create a likelihood rating of high, moderate, or low.

Impact Analysis

Impact levels are generally also rated at high, moderate, or low, but they may also include either qualitative or quantitative analysis. The analysis should consider criticality and sensitivity of the system and its data.

Risk Determination

By cross-referencing the determination of likelihood and the level of impact, an overall determination of risk to the system and the organization can be made.

Control Recommendations

The goal of the controls is to reduce risk to a level that is acceptable. Consider the following:

  • Effectiveness of recommendations
  • Laws and regulations
  • Organizational policy
  • Impact
  • Safety and reliability

NIST SP 800-53 contains the catalogue of controls

Documentation

The risk assessment report should include:

  • Scope of the assessment (based on system characterization)
  • Methodology used
  • Observations
  • Estimation of overall risk to the system

This report sets the stage for using security controls to mitigate risk. The report should be incorporated into the Site Security Plan.

Agile Defense with NIST Controls

Agile Defense

In the past, information systems security often focused simply on perimeter defense, wrongly assuming that a strong perimeter was the only defense needed. Then, as regulations became more complex and more legal, infosec became more “compliance-centric”, trying to pass the security audits required by law. Compliance oriented security produces reams of paperwork and reports and can accomplish good security, but too often seems to loose track of what the attackers are doing and how they do it. Now we are facing increasingly intelligent and sophisticated attackers who have studied defensive tactics and tools and regulations and understand the weaknesses in the defense better than the defenders. They have learned that is often easy to penetrate the perimeter and then the game changes from penetration to digging in for a long term presence without being discovered.

Defensive agility requires the ability to react quickly to threats and compromises and changing conditions. US Air Force Col. John Boyd taught his philosophy of OODA loops that he developed as a fighter pilot to describe the dynamics of an aerial dogfight. When two aircraft get tangled in mortal combat in the sky, the dynamics change rapidly and the pilot that can adapt faster and take advantage of the changing state before the opponent does the same thing is more likely to live longer. OODA stands for:

  • Observe – take in data about events in your environment
  • Orient – translate the event data into a framework that makes sense
  • Decide – reach a decision about what to do next
  • Act – take action on the decision

Boyd’s theory shows how the combatant that cycles through this process faster, reaches each stage before the other combatant and in a short amount of time (at least in a dogfight) generates a large advantage. In aerial combat, this can evolve in a few seconds to an advantage that produces a kill. OODA loop theory can be applied to all forms of combat, competition or contention.

Cyber security is no exception. Cyber attackers can measure the response rate of defenders and plan their attack accordingly so that they have moved on to the next stage of the attack before the defenders take action to defeat them. In order to stay alive in this cyber dogfight, the defenders must learn more about the attack tactics being used against them and know when they need to accelerate their response or change their tactics. This is called AGILE DEFENSE.

NIST SP 800-53 based security controls are too often associated with the worst of “compliance” style defense, but in fact, they offer an incredible range of protections and response tactics if you take the time to study them and know them well.

NIST security controls that can be used to create an agile defense:

  • OBSERVE – Monitor
    • CA-7 CONTINUOUS MONITORING – of the effectiveness of security controls should produce an awareness of the security “posture” that makes transition through the OODA loop faster
    • SI-4 INFORMATION SYSTEM MONITORING – real time monitoring of inbound, outbound and interior traffic to find the anomolies that allow detection of an attacker
    • SI-3 MALICIOUS CODE PROTECTION – monitoring your Anti-virus performance shows you how well protected your systems are at this layer. It can also reveal trends in attacks.
    • SI-7 SOFTWARE AND INFORMATION INTEGRITY – this is critical for exposing successful penetrations.
    • AU-6 AUDIT REVIEW, ANALYSIS, AND REPORTING – this area won’t reveal much most of the time, but it can be highly automated and is critical for building a profile of how an attack proceded.
    • PE-6 MONITORING PHYSICAL ACCESS – physical attacks can defeat all your other fancy protections. Compromising an insider (blackmail?) with physical access permission gets the attacker the keys to the kingdom. How can you tell who did what?
    • SC-31 COVERT CHANNEL ANALYSIS – once an attacker is on your network, they will most likely be trying to ex-filtrate some form of data, at least command and control stuff. Can you find it?
  • ORIENT – Correlate
    • IR-4 INCIDENT HANDLING (CE-4) correlation of incident and response information
    • RA-5 VULNERABILITY SCANNING – scan for vulnerabilities so that they can be patched before an attacker finds them
    • RA-5 VULNERABILITY SCANNING (CE-9) penetration testing is another form of assessing vulnerabilities.
  • DECIDE
    • RA-3 RISK ASSESSMENT – you must decide how much real risk is present in the threats and vulnerabilities.
    • CM-4 SECURITY IMPACT ANALYSIS – how fast can you predict the risk involved in making changes to your system?
  • ACT – Respond
    • IR-4 INCIDENT HANDLING (CE-2) dynamic reconfiguration as part of IR capability
    • IR-4 INCIDENT HANDLING (CE-3) define classes of incidents and responses
    • SI-4 INFORMATION SYSTEM MONITORING (CE-3) integration of IDS tools into access control and flow control to create rapid response mechanisms
    • SI-2 FLAW REMEDIATION – patching, making configuration changes, and removing components can remediate flaws.
    • CP-2 CONTINGENCY PLAN – do you have contingency plans for every kind of failure and do you know how long they take to implement and under what conditions they will be triggered?

[note – CE stands for Control Enhancement]