4 ms·
Thanks, I'm interested in this too. I have seen talk about the issue of your restore image containing unpatched (or even zero day) vulnerabilities. So you nee
by FiggyPudding 5y ago
Thanks, I'm interested in this too.
I have seen talk about the issue of your restore image containing unpatched (or even zero day) vulnerabilities. So you need to worry about your restored systems quickly becoming compromised again.
Also that your backups should be pulled to an independent backup system instead of pushed so the compromised machine can't potentially ruin your backups. (Then you would need to wait longer for your off site backup to restore your backup.)
If you can't audit that it was simply a successful phishing attempt and you just need to revoke keys and passwords. I suppose a super expensive solution would be to use multiple operating systems and software platforms so you have a chance to get yourself back up and running on a different environment with different vulnerabilities that aren't being presently being attacked?
I'm excited to hear from someone who sounds like a professional.
I suppose this is really a more general question of how do I prevent remote code execution? Traffic analysis probably has to be done on an independent gateway? I assume that's hard in a large network vs botnet... Block Tor ips from any ports except your application/web ports? Because I'd like to support the good guys on Tor...
- ThinkBeat 5y agoThank you for responding. Yes, the "front line" barriers of firewalls and traffic analysis and a lot of things I surely do not know much about. I have experience with that but more than a decade ago. My question was more directed towards after the breach. How do you recover. You made an excellent point that restoring from an image that contains the samle vulnerabilities that allowed the attack in the first place is not a great idea. I guess the first step is triage to figure how it got in and what it was. Then needed updates can be applied to the images prior to roll out. It think all companies now need to presume they will be victims of ransomware at some point. As I heard someone say at DefCon, there are those who have been hacked and know, there are those who have been hacked and dont know and there are the people who will be hacked in the future. It will happen. (a pessimistic but I think realistic view) After I wrote the post, I thought about a place I was working maybe 25 years ago. Iffy on the years. This was a law enforcement at the federal level. They had a WORM robot. It would continuously (or some such) store incoming data / created data to a disc (sort of like a cd/dvd but a lot more storage per disc. Given that you could write once, there was no way (or none I heard of) to corrupt data. It would of course also write post ransomware encrypted data, but the originals would be safe. It could also fetch discs a from its library automatically to restore data at a specified time in the past. I am thinking that such a system would not be able to keep up with the volume of data today. Streamer tapes are still around and have decent storage capacity at the high end. Back in the day, the drill was to back up to tape, and then rotate the tapes. 5 tapes. you could just get new tapes and have a good system. They also have robots that do that. Or at least used to have. The good old days :) I am hoping to learn from guys a lot smarter than me, who have experience.