chg: [workshop-0] update content, more about pdns

Jean-Louis Huynen 2019-09-23 13:44:55 +02:00
parent cf27e4eb25
commit dddd3abdef
3 changed files with 310 additions and 80 deletions

View File

@ -10,6 +10,7 @@
\usepackage{fancyvrb} \usepackage{fancyvrb}
\usepackage{tabularx} \usepackage{tabularx}
\usepackage{ulem} \usepackage{ulem}
\usepackage{listings} \usepackage{listings}
\definecolor{main}{RGB}{47, 161, 219} \definecolor{main}{RGB}{47, 161, 219}
%\definecolor{textcolor}{RGB}{128, 128, 128} %\definecolor{textcolor}{RGB}{128, 128, 128}
@ -303,7 +304,7 @@ The D4 server provides a {\bf web interface} to manage D4 sensors, sessions and
\begin{frame} \begin{frame}
\frametitle{} \frametitle{}
{\center Use-case: migrating a legacy network capture model into a D4 network sensor {\center Example use-case: migrating a legacy network capture model into a D4 network sensor
} }
\end{frame} \end{frame}
@ -378,106 +379,327 @@ The D4 server provides a {\bf web interface} to manage D4 sensors, sessions and
\end{block} \end{block}
\end{frame} \end{frame}
\begin{frame} \begin{frame}
\frametitle{} \frametitle{}
{\center Use-case: D4 analyzer to detect DDoS attacks in backscatter traffic \begin{center}
} {\bf A distributed Network telescope to observe DDoS attacks}
\end{frame} \end{frame}
\begin{frame} \begin{frame}
\frametitle{Observing SYN floods attacks in backscatter traffic} \frametitle{Motivation}
Attack description DDoS Attacks produce an observable side-effect:
\begin{tikzpicture}{scale=0.4} \begin{center}
\node[rectangle,draw,fill=red!80] (a) at (0,0) {Attacker}; \scalebox{0.8}{\input{../../preso/03-PassTheSalt/bsvol.tex}}
\node[anchor=west] at (0.93,0.25) {Spoofed requests $H_{0},H_{1},H_{2},H_{3},...$}; \end{center}
\node [rectangle,draw,fill=blue!25,anchor=east] at (8,0) (v) {Victim};
\draw [->](a) --(v);
\foreach \x in {0,1,2,3} {
\node [rectangle,draw,fill=green!25,anchor=east] at (\x*2+1,-2) {$H_{\x}$};
%Horizontal lines
\draw (\x*2+1, -\x*0.25-0.5)--(7.0+\x*.25,-\x*0.25-0.5);
%Links to the victim
\draw (7.0+\x*.25,-\x*0.25-0.5) -- (7.0+\x*.25,-0.25);
%Links to hosts
\draw[->] (\x*2+1, -\x*0.25-0.5)--(\x*2+1,-1.70);
\end{frame} \end{frame}
\begin{frame} \begin{frame}
\frametitle{What can be derived from backscatter traffic?} \frametitle{What can be derived from backscatter traffic?}
\begin{itemize} \begin{itemize}
\item External point of view on ongoing denial of service attacks \item External point of view on ongoing Denial of Service attacks:
\item Confirm if there is a DDoS attack \begin{itemize}
\item Recover time line of attacked targets \item {\bf Confirm} if there is a DDoS attack
\item Confirm which services are a target (DNS, webserver, $\dots$) \item {\bf Recover} time line of attacked targets
\item Infrastructure changes or updates \item {\bf Confirm} which services (DNS, webserver, $\dots$)
\item Assess the state of an infrastructure under denial of service attack \item {\bf Observe} Infrastructure changes
\item {\bf Assess the state of an infrastructure under denial of service attack}
\begin{itemize} \begin{itemize}
\item Detect failure/addition of intermediate network equipments, firewalls, proxy servers etc \item {\bf Detect} failure/addition of intermediate network equipments, firewalls, proxy servers etc
\item Detect DDoS mitigation devices or services \item {\bf Detect} DDoS mitigation devices
\end{itemize} \end{itemize}
\item Create probabilistic models of denial of service attacks \item {\bf Create} models of DoS/DDoS attacks
\end{itemize} \end{itemize}
\end{frame} \end{frame}
\begin{frame} \begin{frame}
\frametitle{Confirm if there is/was a DDoS attack} \frametitle{D4 in this setting}
D4 - for data collection and processing:
\begin{itemize} \begin{itemize}
\item Distinguish between compromised infrastructure and backscatter \item {\bf provide} various points of observation in non contiguous address space,
\item Look at TCP flags $\to$ filter out single SYN flags \item {\bf aggregate} and {\bf mix} backscatter traffic collected from D4 sensors,
\item Focus on ACK, SYN/ACK, ... \item {\bf perform} analysis on big amount of data.
\item Do not limit to SYN/ACK or ACK $\to$ ECE (ECN Echo)\footnote{\url{}}
\end{itemize} \end{itemize}
\input{flags.tex} D4 - from a end-user perspective:
\item {\bf provide} backscatter analysis results,
\item {\bf provide} daily updates,
\item {\bf provide} additional relevant (or pivotal) information (DNS, BGP, etc.),
\item {\bf provide} an API and search capabilities.
\end{frame} \end{frame}
\begin{frame} \begin{frame}
\frametitle{Passive Identification of Backscatter (WiP)} \frametitle{First release}
language=bash, \begin{itemize}
backgroundcolor=\color{gray!25}, \item[\checkmark]
basicstyle=\ttfamily, analyzer-d4-pibs\footnote{\url{}}, an analyzer for a D4 network sensor:
\item {\bf processes} data produced by D4 sensors (pcaps),
\item {\bf displays} potential backscatter traffic on standard output,
\item {\bf focuses} on TCP SYN flood in this first release.
\item {\bf processes} data produced by D4 sensors (pcaps),
\item {\bf analyze} ICMP packets,
{\bf Passive DNS}
\frametitle{Problem statement}
\item CIRCL (and other CSIRTs) have their own passive DNS\footnote{\url{}} collection mechanisms
\item Current {\bf collection models} are affected with DoH\footnote{DNS over HTTPS} and centralised DNS services
\item DNS answers collection is a tedious process
\item {\bf Sharing Passive DNS stream} between organisation is challenging due to privacy
\frametitle{Potential Strategy}
\item Improve {\bf Passive DNS collection diversity} by being closer to the source and limit impact of DoH (e.g. at the OS resolver level)
\item Increasing diversity and {\bf mixing models} before sharing/storing Passive DNS records
\item Simplify process and tools to install for {\bf Passive DNS collection by relying on D4 sensors} instead of custom mechanisms
\item Provide a distributed infrastructure for mixing streams and filtering out the sharing to the validated partners
\frametitle{First release}
analyzer-d4-passivedns\footnote{\url{}}, an analyzer for a D4 network sensor:
\item {\bf processes} data produced by D4 sensors (in passivedns CSV format\footnote{\url{}}),
\item{\bf ingests} these into a {\bf Passive DNS server} which can be queried later to search for the Passive DNS records,
\item{\bf provides} a lookup server (using on
redis-compatible backend) that is a Passive DNS REST server compliant to the Common Output Format\footnote{\url{}}.
\begin{frame}[t]{Common Output Format}
\item {\bf Consistent naming of fields across Passive DNS software} based on the most common Passive DNS implementations
\item Minimal set of fields to be supported
\item Minimal set of optional fields to be supported
\item Way to add "additional" fields via a simple registry mechanism (IANA-like)
\item Simple and easily parsable format
\item A gentle reminder regarding privacy aspects of Passive DNS
\begin{frame}[t,fragile]{Sample output}
keywords={typeof, new, true, false, catch, function, return, null, catch, switch, var, if, in, while, do, else, case, break},
ndkeywords={class, export, boolean, throw, implements, import, this},
breaklines=true, breaklines=true,
columns=fullflexible showtabs=false,
} captionpos=b
\input{pibs.tex} }
Early version is available of PIBS\footnote{\url{}} \lstset{breaklines=true, language=JavaScript}
with a focus on TCP traffic. \begin{lstlisting}
\begin{tabular}{l|l} {"count": 868, "time_first": 1298398002, "rrtype": "A", "rrname": "", "rdata": "", "time_last": 1383124252}
Options & Explanations\\ {"count": 89, "time_first": 1383729690, "rrtype": "CNAME", "rrname": "", "rdata": "", "time_last": 1391517643}
\hline {"count": 110, "time_first": 1298398002, "rrtype": "AAAA", "rrname": "", "rdata": "2001:610:148:dead::6", "time_last": 136670845}
-r & read pcap file\\ \end{lstlisting}
-b & display IPs under DDoS on standard output\\ \end{frame}
\begin{tabular}{l} \begin{frame}[t]{Mandatory fields}
Dependencies\\ \begin{itemize}
\hline \item \textbf{rrname} : name of the queried resource records
libwiretap-dev\\ \begin{itemize}
libhiredis-dev\\ \item JSON String
libwsutil-dev\\ \end{itemize}
\end{tabular} \item \textbf{rrtype} : resource record type
\item JSON String (interpreted type of resource type if known)
\item \textbf{rdata} : resource records of the query(ied) resource(s)
\item JSON String or an array of string if more than one unique triple
\item \textbf{time\_first} : first time that the resource record triple (rrname, rrtype, rdata) was seen
\item \textbf{time\_last} : last time that the resource record triple (rrname, rrtype, rdata) was seen
\item JSON Number (epoch value) UTC TZ
\begin{frame}[t]{Optional fields}
\item \textbf{count} : how many authoritative DNS answers were received by the Passive DNS collector
\item JSON Number
\item \textbf{bailiwick} : closest enclosing zone delegated to a nameserver served in the zone of the resource records
\item JSON String
\begin{frame}[t]{Additionals fields}
\item \textbf{sensor\_id} : Passive DNS sensor information
\item JSON String
\item \textbf{zone\_time\_first} : specific first/last time seen when imported from a master file
\item \textbf{zone\_time\_last}
\item JSON Number
\item Additional fields can be requested via \url{}
{\bf Passive SSL revamping}
\frametitle{Objectives - TLS Fingerprinting}
{\bf Keep} a log of links between:
\item x509 certificates,
\item ports,
\item IP address,
\item client (ja3),
\item server (ja3s),
``JA3 is a method for creating SSL/TLS client fingerprints that should be easy to produce on any platform and can be easily shared for threat intelligence.''\footnote{}
{\bf Pivot} on additional data points during Incident Response
\frametitle{Objectives - Mind your Ps and Qs}
{\bf Collect} and {\bf store} x509 certificates and TLS sessions:
\item Public keys type and size,
\item moduli and exponents,
\item curves parameters.
{\bf Detect} anti patterns in crypto:
\item Shared Public Keys,
\item Moduli that share one prime factor,
\item Moduli that share both prime factor,
\item Small factors,
\item Nonces reuse / common preffix or suffix, etc.
\frametitle{First release}
\item[\checkmark] sensor-d4-tls-fingerprinting
{\bf Extracts} and {\bf fingerprints} certificates, and {\bf computes} TLSH fuzzy hash.
\item[\checkmark] analyzer-d4-passivessl
{\bf Stores} Certificates / PK details in a PostgreSQL DB.
\item snake-oil-crypto
{\bf Runs} weak crypto attacks against the dataset.
\item lookup-d4-passivessl
{\bf Exposes} the DB through a public REST API.
\item {\bf Sensitive information sanitization} by specialized analyzers
\item {\bf Previewing datasets} collected in D4 sensor network and providing {\bf open data stream} (if contributor agrees to share under specific conditions)
\item {\bf Leverage MISP sharing communities} to augment Threat
Intelligence, and provide accurate metrology.
\frametitle{Use it}
\item {\bf Create} sensors easily with the generator \footnote{\url{}},
\item {\bf Manage} your own sensors and servers, {\bf find} shameful bugs and
{\bf fill} in github issues
\item Even better, {\bf send} Pull Requests!
\item {\bf Share} data to public servers to improve the datasets (and detection,
response, etc.)
\item {\bf Feed} your MISP instances with D4's findings - {\bf Share} yours
\item {\bf Leech} data, {\bf write} your own analyzers, {\bf do} research
\end{frame} \end{frame}
\begin{frame} \begin{frame}
@ -485,9 +707,17 @@ Options & Explanations\\
\begin{itemize} \begin{itemize}
\item Collaboration can include research partnership, sharing of collected streams or improving the software. \item Collaboration can include research partnership, sharing of collected streams or improving the software.
\item Contact: \item Contact:
\item \url{} - \url{} \item \url{}
\item \url{}
\item \url{}
\href{}{Passive DNS tutorial}
sharing tutorial}
\end{itemize} \end{itemize}
\end{frame} \end{frame}
\end{document} \end{document}

View File

@ -18,7 +18,7 @@
\author{Team CIRCL} \author{Team CIRCL}
\titlegraphic{\includegraphics[scale=0.20]{d4-logo.pdf}} \titlegraphic{\includegraphics[scale=0.20]{d4-logo.pdf}}
\institute{Team CIRCL \\ \url{}} \institute{Team CIRCL \\ \url{}}
\date{20190329} \date{20190923}
\begin{document} \begin{document}
\begin{frame} \begin{frame}