Okay, let's try to explain and answer your questions with this presentation. Can you hear me well, by the way?
Perfect, super. So, a quick introduction about me. My name is Sergio Albea. I'm working in SWITCH. SWITCH is the national research and education network in Switzerland. We are protecting all the universities and research centers in Switzerland in terms of identities. We have EdoID, in terms of networking, in terms of SOC, and also we are managing the top-level CS domains.
So, regarding my hobbies, I love all things related with football. I'm from Barcelona, so if some of you are familiar with football, it was a sad night for Barcelona fans yesterday, but let's see if we can have a good presentation.
So, I think that nowadays that most of us, we have multiple things in place to secure our different identities, multi-factor, Agua for the access, passkeys, CM solution, defendant response options, but there is a reality that I found in my company that is, in a big manner, sometimes that security relies on user behavior. Why?
As I said, we are working with universities and research institutions, so by law in Switzerland, I could say that we cannot block by default. What it means is a student could be able to connect from a risky country, such as Russia, using a Raspberry, and use it to a browser, and we cannot block. We have to monitor, and we have to monitor the user behavior.
So, to start with that, I will show you a real case that happened to me in 2006, and it was one of the scenarios about user behaviors that I think is a good way to start these different scenarios that I will show during the presentation. So, basically, my boss was going on vacation and was configuring an auto-reply message, an auto-toffee message, explaining I will not be available for one month, if in case of emergency, you can contact this email address or these phone numbers.
But already in 2006, we had phishing campaigns, of course, not as sophisticated as nowadays, not as massive, but was already there, and an attacker was sending a phishing email to my boss. They were having the auto-reply message back, and the password complexity for 2006 was not as nowadays, and with the phone number, they were able to access to a personal email address. Unfortunately, we had another user behavior. My boss was configuring an email forward rule to move all the emails of the enterprise mailbox to a personal one.
It ends that during this month that my boss was outside, the hackers were sending on behalf of his name in the personal email address, fakes to be invoiced by the customers, data was stolen. So, it ends with multiple penalties, no?
So, it where the question pop-ups, how many people is still nowadays communicating externally, hey, I will not be working for one month, so do whatever that you want with my account, because I will not be aware. I will be totally one month without accessing to my account. I'm sharing another email address, so you can start phishing campaigns, spam campaigns, because I'm giving you some information, and then also phone numbers.
So, how we can control that? I would like to share with you an initiative. This is a website, and basically what I'm doing is analyzing all the things that we are allowing to the users. What they can do? They can open, they can send emails, they can access with identities to your data, to your systems.
So, based on every source, as you can see here, I'm identifying what they can do with every source. When they use emails, they can open emails, they can configure email rules or not. I will go to this point. When they open emails, which are the no interactions, they can click on URLs, they can file attachments. When they are using email rules, they can configure forwarding rules. But if you, for example, in the protection, you have a policy that is not allowing for forwarding email address, perfect, you are protected. In this case, use a behavioral scenario, you are covered.
You don't have to be worried. This is the scenario that is covered. But if not, you have the threat, and you have to monitor the threat, for example, with DLP, with information right management, or other things, to ensure that when the information is sent outside of your company, it's monitored. Same happens when they open files in an email. You have to verify which are the type of files. If you have some threat intelligence source, you can verify the file hashes, for example, if they are targeted as malicious by different vendors.
When they click in a URL, for example, you have your click analyzer, if I remember well in Microsoft, that checks traffic redirection, so you are monitoring this case. There's no interaction. But if for business reasons or for other requirements, you cannot log that, you cannot add this protection, you have to assume this threat and monitor it. So for that, I will go with a classification that are expected user behaviors and unexpected user behaviors. I call them also paranoical, so you will see why I'm talking about that. Expected user behaviors, quickly about that. Devices.
People or students using OneDrive to execute software in a device. So imagine students using Photoshop at home with their computers, and they are using some kind of crack to use Photoshop. But they decide that they want to have Photoshop also in their company or organization device.
Luckily, your antivirus, your anti-malware has the last signature, so file is blocked, file is not executed. They go with another ones.
Hey, have Photoshop at home, let's try with your computer if you want. But luckily, other devices were also updated. Unfortunately, you can say some name, Matthias arrived after one month that was on vacation and the device was not updated for one month. So when this person arrived, they were saying, I have Photoshop at home, do you want to try it on your computer?
Yeah, I have been one month without working on it, but let's try it. But this device that was not updated during the last month was not having the last updates and the device was affected. So this is a common mistake, I would say error that I have seen in the last years that we are really focused on search new TI source, add new IOCs to the tech, malicious domains, URL, file hashes. But when something is stopped by or antivirus or anti-malware, we have to go until we end with that. Because I have seen that a lot of times, something is blocked, perfect, we are safe.
No, no, the threat can be still living in your environment. So it's important not just about device, can be in OneDrive, can be in SharePoint, can be a file that has been downloaded in a zip and when it was extracted, just a file that was extracted was blocked. But the zip is there, the zip is there and the threat is there. So it's important when something is blocked, we have this information, so we have to really use it. Second one, networking.
I think that nowadays there are a lot of organizations that to access to sensitive data, company data, they are required to be in our network, connected with VPNs and when they are connected, we have different mechanisms, different technologies that block the access to malicious URLs, domains or files or other stuff. But what happened? For example, in my case, students can connect from whatever they want. So it means that they can connect from different hotspots, they can connect from different internet service providers. Some of these internet service providers can be more risky or not.
I will talk about that in the last slide. So it's important to identify this user behavior, that is we know that they use open networks. So what we can do with that? We can use new approach, for example. I don't know if some of you work with Defender for Endpoint, but Defender for Endpoint have the three threat intelligent indicators where you cannot defend IOCs. So what is happening? Doesn't matter where the user is connected, because if the user clicks on some of these malicious URLs, domains or IPs, automatically it will be blocked. So it's like another layer of security.
Other ones, the last ones about expected user behavior, you know about that. Basically, it's important to monitor the traffic regulation when a QR is scanned. And finally, this is something that I have seen growing in the last years, that basically you go with your device, your phone, and you're connected to some charging station in a cafeteria, restaurant, in the airport. Every time there are more cases about a small raspberry connected behind, and when you connect your device, the data is stolen.
So there is a new mechanism that is called condom, like that, which basically filters which is the pin that will be allowed to connect with the charge station, which is just one, the one in red. The other one is for data, but the one that is really useful, I use it for the battery, is one. So what this condom is doing is just allowing to connect one of the pins. So that's all about expected user behavior, and my last one is about unexpected ones.
For that, I will show you quickly a funny real case that we had in Spain. I don't know if some of you know Mercadona. Mercadona is basically a chain of supermarkets in Spain, and which is expected user behavior in a supermarket. People go to buy things, people go to buy food, drinks, but in Spain we are really original, and instead of user, normal user behavior, we decide that supermarket was a good place to go from 7 to 8 am, put a pineapple in a shopping trolley, and if you crash with something, with someone sorry, you can start to flirt. So we reinvent Tinder, we could say.
So imagine someone at 9am arriving to a risk evaluation of the company of Mercadona saying, there is a risk like that, that someone can arrive and have this stuff. So this is totally unexpected user behavior, and this was the reality. A small thing, something that in our mind can be crazy that can happen, if it happens, can cause a big damage, because it was not just one supermarket. If you talk with someone from Spain, they will explain you funny things about that.
So what is funny about this unexpected user behavior, and interesting by the way, is that they were using the incident response flow, the TEC, which is the incident that was detected. They were arriving at 7pm to have fun. So response, move out all the pineapples outside. Lesser length, we know that they will back the day after, so let's move out all the pineapples. Incidents mitigated.
So, same happened with real cases in our walls with identities. This is also a real case.
Basically, a person was receiving an email from a hacker saying, I have seen your profile in LinkedIn and it looks amazing, you have the best profile for this position, where I can offer you this amount of money, but the job description file is blocked. So can you admin your sender list, please? This user was adding the email address of the hacker in the sender list, and basically it was kind of funny, it changed the target email as malicious, but as the email was in the sender list, the threat was delivered and the device was totally infected.
And the last scenario, suspicious connections, suspicious hotspots, and suspicious risk internet service providers. We are not expected that our users connect to malicious Wi-Fi, to malicious hotspots, but it can happen. So if some of you are threat hunters or work with threat hunting, if you evaluate this scenario, for example, when someone is sharing a connection with an iPhone, always, always the connection is sharing this gateway.
So based on this user behavior, that they can connect to open Wi-Fis, we know that if the hackers share connection, they used to share it with phones, can be iPhones, can be other ones. So let's try to monitor all the gateways with this specific direction, and where the network name is free open restaurant, it's kind of suspicious. So it's also a kind of unexpected user behavior that we can monitor. And the last one, suspicious internet service providers.
Basically, nowadays, we have around 40,000 internet service providers around the world, and there are different ones that has more or less investment in terms of money, about their different features. Okay, we are not really good on time. So basically, what I'm going to show you is a reality. If some of you know URL house, so you can check which are the autonomous system numbers. Autonomous system number is a group of IPs associated to every internet service provider.
And basically, they tell you if some autonomous system number is directly under the control of similar criminals, or directly if you see on top, this pointing at one is telling you that the average takedown of a site is 14 days. So if I see connections, like these ones, where if we check the last one, that where the signing attempts, user signing attempts, they are using 123 different IPs. And the ratio of success is just 11. It's totally suspicious for me. And if you see that in the middle, smart phone, mobile communications, and the second one, they are from Korea.
They are using 69 and 61 different IPs to sign with my users, and zero success or failure. So this is kind of as internet service providers that I will monitor. I will come to URL house, I will validate the reputation, and then I will take a decision to monitor them. That's all.
Basically, as I said, don't take me wrong. All this is planned, all these services and techniques that we are using to protect our identities are required.
Of course, I didn't talk about security awareness, but more trained, and more security awareness that we have to our users, more secure will be. And insecurity will never be 100% secure, but if we apply these three layers, including user behavior, I think that every time we will be more close to it. Thank you.
Oh, thank you very much, Sergio. As usual, we have time for a couple of questions. Thanks for that talk. It's very interesting. I'm from one identity, so a vendor, but I'm curious, automatically blocking somebody that looks like a threat. I think you said at the start, sometimes you can't do that. Do we ever do that? I personally have never found a customer that actively, automatically blocks somebody. It's like we've got all this fancy AI stuff, but we don't trust it enough to actually make a decision, human in the loop. I think you said it may have been not possible due to regulation.
You're not allowed to do that. That could be a reason. But I just wonder what you see around that. Will we get to the point if these AI tools become good enough, if we have strong enough signals? Martin said in his presentation, if we have enough signals, then we have reliability. I would question that. If you have a lot of signals, you can end up with noise, right? It's not clear to me.
Sorry, I know. I'm just wondering what your experience is with that. Thanks.
No, thank you. It's a good question, in fact. What I used to suggest is that if you have the possibility, for example, imagine that you have different websites or different services that are exposed to the internet. So you identify some ISPs or group of ASNs that are triggering usually malicious activities. As you said, we don't want to block them because the information that we can obtain for that can be really useful. So why not to have kind of a gateway where you have two backends and you can all the traffic that is risky can go to this backend. It's giving the same service.
But in that way, for example, imagine a DDoS attack. If I know which are the ISPs or the range of IPs or countries that used to be valid, I can go to one backend and the second one that is more risky to a second one. So in that way, I'm kind of filtering in case that there is something. Because as you said, it's complicated to block. So you are giving the service to all of them, but also you are kind of mitigating a bit the possible risk. About IAEA, I cannot help you a lot because I'm not working with IAEA.
Okay, great. Well, thank you very much again. Thank you.