4 ms·
"For example, such information is critical to protecting the US Defense Industrial Base" is not an overly convincing argument for purchasing "NetFlow"[1]. The
by dhx 3y ago
"For example, such information is critical to protecting the US Defense Industrial Base" is not an overly convincing argument for purchasing "NetFlow"[1].
The US State department Exchange Online hack is an example of where "NetFlow" being purchased could be more interesting as an example. IP addresses such as those registered in Russia and to OVH data centres logging into State Department executive mailboxes at 3:00AM in US time zones should be laughably easy to detect.[4] Rented US virtual servers and AWS/Azure/GCP servers outside federal government availability zones would also be trivial to detect as suspicious source locations. The question that purchased "NetFlow" would help answer is what is connecting to those suspicious IP addresses, what is connected to those, what else do the chain of IP addresses found communicate with, etc.[5]
- Worst case there was no one was watching that attack as it occurred over ~4 months through use of "NetFlow" that may have been available and useful to use.
- Controversial case is someone was watching (possibly including attacker's use, if any, of US servers) and decided that it was better to keep watching and following the attackers than to immediately prevent a few State Department emails being leaked.
- Best case (not implemented) would seemingly be to fix terribly configured government systems so they can only be accessed from trusted locations and not random rented virtual server IPs, and "NetFlow" analysis is then probably not required. Security features such as "We've noticed your account is accessing this system from a new ISP--confirm this is really you?" aren't new.
[1] https://en.wikipedia.org/wiki/NetFlow https://en.wikipedia.org/wiki/NetFlow
[2] https://en.wikipedia.org/wiki/DShield https://en.wikipedia.org/wiki/DShield
[3] https://web.archive.org/web/20010205010100/http://dshield.org/top10.html https://web.archive.org/web/20010205010100/http://dshield.or...
[4] https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/ https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...
[5] https://blog.torproject.org/traffic-correlation-using-netflows/ https://blog.torproject.org/traffic-correlation-using-netflo...