{"id":4612,"date":"2024-07-23T13:23:48","date_gmt":"2024-07-23T18:23:48","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps"},"modified":"2024-07-23T13:23:48","modified_gmt":"2024-07-23T18:23:48","slug":"sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/23\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps\/","title":{"rendered":"Sprawling CrowdStrike Incident Mitigation Showcases Resilience Gaps"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd399556d3a8abf22\/669fd6cd436379475fe4953d\/crowdstrike_T.Schneider_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The fact that a few lines of errant code could cause disruption on the scale that CrowdStrike&#8217;s update has over the past four days has focused unparalleled attention on the urgent need for greater resiliency and redundancy in enterprise information technology stacks worldwide.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Few expect that getting there will be easy. But almost everyone agrees that the developments of the past few days underscore the need for better preparedness, better impact mitigation, and fresh ideas for recoverability from technology failures of the sort that happened last week.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/crowdstrike-outage\" rel=\"noopener\">havoc started on July 19<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> when a small CrowdStrike content update for the Windows version of the company&#8217;s Falcon endpoint security technology caused systems failures worldwide. Numerous airlines, banks, airports, hospital, hotels, manufacturing companies, and others reported their Windows systems as becoming essentially inoperable and refusing to restart despite attempts to reboot them out of a blue screen of death (BSOD) state. Microsoft estimated the faulty CrowdStrike update affected some <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blogs.microsoft.com\/blog\/2024\/07\/20\/helping-our-customers-through-the-crowdstrike-outage\/\" rel=\"noopener\">8.5 million Windows systems<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> worldwide.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As if the recovery issues were not enough of a challenge, threat actors added to them this week by taking advantage of the chaos to try and distribute phishing emails, information stealers, and other badware. On July 22, for example, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/blog\/fake-recovery-manual-used-to-deliver-unidentified-stealer\/\" rel=\"noopener\">CrowdStrike warned<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of threat actors using a fake CrowdStrike recovery manual to distribute a hitherto unseen information stealer dubbed Daolpu.&nbsp;Earlier, the security vendor warned of threat actors attempting to distribute <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/blog\/likely-ecrime-actor-capitalizing-on-falcon-sensor-issues\/\" rel=\"noopener\">a malicious zip archive<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to users in South America; it purported to be a hotfix from the company, but in actuality loaded the RemCos Trojan. Others, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blog.knowbe4.com\/crowdstrike-phishing-attacks-appear-in-record-time\" rel=\"noopener\">KnowBe4,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> reported phishing attempts using the CrowdStrike issue as a lure starting just hours after news of the problem first began surfacing.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"CrowdStrike: A National Security Issue?\">CrowdStrike: A National Security Issue?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On July 22, the US House Committee on Homeland Security demanded an explanation from CrowdStrike CEO George Kurtz on what went wrong and the measures the company will implement to prevent a similar incident in the future. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/homeland.house.gov\/wp-content\/uploads\/2024\/07\/CrowdStrike-Software-Update-Letter_FINAL.pdf\" rel=\"noopener\">In a letter to Kurtz<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the committee pointed to the sheer magnitude of the disruption in the US \u2014 more than 3,000 cancelled flights, 11,800 flight delays, surgery cancellations, 911 call center outages \u2014 as reasons why the issue cannot be ignored. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This incident must serve as a broader warning about the national security risks associated with network dependency,&#8221; Mark Green, the chairman of the committee, wrote. Malicious cyber actors backed by nation-states, such as China and Russia, are watching our response to this incident closely.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Both <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.crowdstrike.com\/falcon-content-update-remediation-and-guidance-hub\/\" rel=\"noopener\">CrowdStrike<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/techcommunity.microsoft.com\/t5\/intune-customer-success\/new-recovery-tool-to-help-with-crowdstrike-issue-impacting\/ba-p\/4196959\" rel=\"noopener\">Microsoft<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have released updates and guidance \u2014 including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=Bn5eRUaMZXk\" rel=\"noopener\">self-remediation tips<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for remote users to help organizations restore their systems. Microsoft on Monday updated its recovery tool with expanded logging, error handling capabilities, and two repair options to help organizations expedite recovery.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Mammoth Recovery Task\">A Mammoth Recovery Task<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even so, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/fallout-from-faulty-friday-crowdstrike-update-persists\" rel=\"noopener\">the task of restoring systems<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> will be enormous and time consuming says Thomas Mackenzie, director of product strategy at Lansweeper. &#8220;It depends on a number of factors, including, but not limited&nbsp;to, whether there are backups in place to roll back to, and&nbsp;whether the assets are&nbsp;virtualized&nbsp;or not,&#8221; he says. &#8220;Microsoft has released a tool to fix this problem, but if the asset has&nbsp;BitLocker&nbsp;and requires the key, then it can&#8217;t be used. It\u2019s not a trivial task if you\u2019re talking about a lot of assets across different locations.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Danny Jenkins, CEO at ThreatLocker, says his company&#8217;s testing shows it takes about 15 minutes per computer to recover manually \u2014 something that will be required in many cases.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;If all computers are office-based, it could be reduced to about four minutes per device, assuming they are close to each other,&#8221; he says, but adds that restoration will be significantly harder when remote users are involved. &#8220;A company with 10,000 devices is going to take about 666 person hours to recover. Remote recovery makes it more likely to be three times that.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Encryption recovery keys are another issue. Each device will have its own BitLocker recovery key to boot into Safe Mode. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This could extend recovery time [significantly], assuming you have them saved somewhere,&#8221; Jenkins says. &#8220;It is also a really long manual key to type in.&#8221; Organizations could try using another security tool to block CrowdStrike from running so as to enable automated recovery, he adds. &nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Dangers of an Interconnected World\">The Dangers of an Interconnected World<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This CrowdStrike incident is a reminder that in an increasingly technology-dependent and interconnected world, sometimes things will go wrong, says Melissa Bischoping, director of endpoint security at Tanium. In this case, they went wrong in a way that was technically simple to remediate but involved an astronomical amount of effort in practice because it required human intervention on nearly every impacted endpoint in the first few days.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Going forward, we must [focus] on resilience and redundancy in the technology we build and deploy across the globe,&#8221; she says. &#8220;It is inevitable that failures will happen in technology. Having layers of resilience, real-time visibility, and business continuity plans which account for the most complex remediation must be at the center of every risk management conversation.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The incident, not surprisingly, has prompted questions about the wisdom of giving technology vendors the untrammeled ability to make automatic updates to their software on customer systems, without often so much as asking permission first, Bischoping says: &#8220;We place a lot of trust in the providers that deliver software to our organizations. It&#8217;s imperative that we have conversations about allowing the customer to remain in control of changes to endpoints, and balance the need to deploy the most up-to-date information with each environment\u2019s unique risk acceptance strategy.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Allowing organizations some level of control over the rate at which endpoints receive change is critical component of risk mitigation, she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Paul Davis, field chief information security officer (CISO) at JFrog, says the CrowdStrike incident is a reminder why proactive testing and preparedness are key to preventing massive disruption.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">&#8220;<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations affected by this must also take an honest look at their operations \u2014 what pieces of your tech stack went offline, who could have done their jobs better, who was prevented from doing their jobs, who were essential to the business, what could the org live without during downtime, and what pieces of the business need to be protected the most,&#8221; he says. &#8220;The answers to these questions will define your crisis response plan and will give you a blueprint on how to act when an outage of this magnitude occurs.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The key&nbsp;takeaway for organizations&nbsp;here is that the software supply chain can be complex with multiple interconnecting parts and tools, where even small marginal errors can have massive impacts.&nbsp;&#8220;Slow ramp-ups and careful deployment are key,&#8221; when it comes to rolling out updates, Davis says. &#8220;Never let the cure be worse than the disease, where an update causes more disruption than the bug it\u2019s trying to fix.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The fact that a few lines of errant code could<\/p>\n","protected":false},"author":12,"featured_media":4613,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4612","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/sprawling-crowdstrike-incident-mitigation-showcases-resilience-gaps.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4612"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4612\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4613"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}