You canโt swing a digital cat without hitting a major cybersecurity breach somewhere. It feels like a world of black-hat hackers, with no white hats coming to the rescue.
The white hats are hard at work, too, though, sharing information amongst themselves to prevent breaches that can compromise personal data and finances, among many other prizes that hackers crave.
The Roanoke Blacksburg Technology Council hosted an IT security forum this month, its annual Defense Against the Dark Arts event, at Virginia Western Community College. Two of the presenters were Thomas โTweeksโ Weeks, director of future technology at Virginia Tech, and Caeland Garner, lead penetration tester and security researcher in the universityโs IT department. Weeks and Garner chatted a few days afterward with Cardinal News about security in the corporate world, at the university and the personal level.
This Q&A has been edited for length and clarity.
Cardinal News: I just wanted to start with kind of a general question that sort of eats at me, seemingly once a week when a report emerges of a massive hack at an institution that holds millions of regular peopleโs critical identifying and financial information. And I just wonder: Why are large companies so bad at protecting their customers and clients?ย
Thomas Weeks: Well, a lot of companies donโt want to spend the money or time or resources on designing secure systems to start with. They oftentimes donโt put the needed financial resources behind protecting their corporate assets or their clientsโ assets until itโs too late, and theyโre in the news and the media, and their stock takes a hit.
Even companies that do due diligence, that isnโt quite enough anymore. We saw for example in the Target hack that they had secured their point-of-sale systems and kept their corporate credit card information safe. But the black hats, or the hackers that got into the system, came in with a [fake] service, an air conditioning vest on, saying, โWeโre here to service your air conditioning systemโ and came in the back and plugged into the infrastructure there.
So itโs important to have audits so that youโve secured your systems, but you need to make sure that youโre having some third parties come in โฆ that think outside the box to come in and do whatโs called penetration testing of your infrastructure.
Cardinal: Youโre partnering with RBTC on Defense Against the Dark Arts, which I unfortunately could not attend. That was for IT specialists.
Weeks: I actually run the IT security forum for the RBTC, and it started off as just a bunch of us guys wanting to talk about things weโre seeing in the wild, and it was very popular and itโs kind of ebbed and flowed. Last year we only had one presenter, but each year we have between three to four presentations on attacks.
Weโre seeing in the real world how to replicate them โฆ and then also how to defend against them. And so everyone walks away with some how-to information on how to detect and mitigate and/or prevent said attacks.ย
Cardinal: Youโre sharing your information about preventing encroachment with the group of people that come in. But I wonder what youโre learning, if anything, from the folks youโre presenting to. As I heard you say earlier, it just started out with guys getting together and talking about sort of real world experiences. Is there that kind of back and forth in these sessions?
Weeks: Yeah, itโs a group of experts talking. So this is not your average high-level, glossy CEO-type talk. This is a room full of IT experts. So itโs getting pretty down and dirty. Very technical presentations typically. Even during my talk Iโm like, OK, hereโs the X, Y and Z of what I saw on my system. Hereโs what I did. What do you guys think? What are you guys doing? What are you guys seeing? And I often get some really, really good feedback from the audience.
Cardinal: Virginia Tech is obviously a pretty massive institution with arms dedicated to the defense industry and intelligence, among other things. I just assume that attempted attacks are relentless. Am I correct? And is that what you spend a large part of your time doing? Break that down for me a little bit.
Caeland Garner: Yeah, I mean, it is relentless. But my whole philosophy is wherever there is a digital device that plugs into the internet, itโs susceptible to an attack. Being especially that weโre a research institution, that definitely puts a target on our back.ย
Iโm not actually looking for the attacks. Thatโs blue team side. Iโm red team. And in red team, what we try to do is we try to be proactive. Itโs called offensive security. Defensive would be blue team.ย
Weโre trying to be proactive in finding the holes that attackers, other countries, script kiddies [unskilled hackers using pre-existing, malicious tools], nation states, anyone trying to do malicious things on the internet towards us. Iโm trying to find those holes and then find remediation efforts to mitigate these vulnerabilities before the attackers can get in.ย
But also in what we do, we always assume that if we found a critical or high vulnerability โ something that allows sensitive data to come out or someone to have an internal foothold to our internal infrastructure โ the attackers have already found it. That kind of ties into your question of looking for these events, looking for these threats. Thatโs where the blue team comes into play, trying to find, when did this threat happen?
A lot of times weโll work together. In a purple team episode, weโll do exercises in trying to reverse-engineer the threat. So if the blue team has seen an incident, the red team will come in and then try to figure out, OK, well, this is what I see on this device. And if I was an attacker, this is how I would go about it.
Cardinal: Tell me about a specific recent threat and how you handled it.
Weeks: Weโll often see when things happen on the internet, itโs kind of like a storm blowing through. When you get some hot new malware or some hot new vulnerability, youโll see scans across the entire internet start to surge.ย
On our network, our security office is always watching the incoming and outgoing traffic, and theyโre looking for trends and theyโre looking for anomalies. So you baseline your network. You know what the general input and output is.ย
If you see a spike going to China at 3 a.m., then you flag that and then you decide to either take automated action or manual intervention, or you just watch. So thereโs a lot of things that you look at from a monitoring perspective. And then you have the actual red teams and blue teams who are doing things kind of actively and working in conjunction with our network, network scans and network monitoring.
Some of the big things that black hats or nation states will scan for is Microsoft open ports. Open port is like an open door or window, unlocked door or window in your house. Theyโll be scanning for, if thereโs a new remote desktop protocol exploit, then youโll see that surge. As soon as we see those kinds of surges, our security office will make a decision on whether to ride out the storm or to lock things down, depending how bad it is.
Cardinal: As developers make programs, is it really difficult to avoid missing something that can become a vulnerability?
Weeks: Absolutely. A lot of people take solace in running open-source software, but even open-source is vulnerable there. There have been serious, serious bugs with the biggest web server on the planet, Apache, for example, or OpenSSL, which are used to encrypt traffic to these websites and things.ย
These vulnerabilities are human errors that have been left in place for over a decade and no one knew about it. And we wonโt know about it until we start seeing scans or exploits or systems behaving weird.ย
Luckily, the open-source community will often catch those types of things and submit bug reports. For example, a new vulnerability will be discovered and before a hacker or black-hat exploit actually comes out, the open-source community will have already created a patch and put it out there for distribution. The important thing is the next step, is people keeping their systems patched. If that happens, then people are much, much less likely to get bit. But there are zero-day exploits, which are exploits no one knows about, or nation states may have tucked in their back pocket and they never announce. And those are the things that are probably the most dangerous.
Cardinal: So essentially youโve got a black-hat type out there, working all the time to try to find vulnerabilities and exploit them, whereas on your side, you are also trying to find them and patch them. Itโs like a game of spy vs. spy, in a way.
Weeks: Itโs a chess game. And the thing is, we have to be right all the time. They only have to be right once. So itโs a challenge. Itโs a real challenge. And thatโs where weโre talking about resources.ย
Companies need to be putting more and more resources into making sure what they put online is secure by design and that they keep up with it. One big fallacy is, well, we secured our new product, our new router or whatever, and put it out there. Yeah, thatโs not good enough, because all the software your product is built on has to get regular updates.ย
Thatโs where the โinternet of thingsโ is a perfect example of these home routers and network devices and web phones and web cameras, things you put online or put in your home โ smart home devices. You donโt think about that Google appliance or that Amazon device. listening to your words. Those things have to get patched too, because if they donโt get patched, they become the big target.ย
People donโt think about IoT devices and the things we have plugged in all around us that are never paid attention to. Theyโre treated as appliances, not as network-attached computers.
Cardinal: Iโve had to wonder why everything has to be attached to the internet.
Weeks: I donโt buy home appliances that can get online, or if I do, I disable them or keep them off because โฆ youโre just expanding your network profile, your security profile online. If it gets bigger and bigger and bigger, youโve got more and more to protect, and youโll slip up and forget.
Cardinal: Thatโs going to lead me into a final question, but I wanted to interrupt that flow for a second because I also realize that in that rapidly changing landscape, thereโs a lot of AI now being used for attacks, and I guess thatโs a new thing youโll have to deal with. Could you talk a little bit about that and how youโre approaching it?
Garner: Thereโs kind of two parts to it. I feel like thereโs a social, political mentality that AI is being used autonomously by itself. And we have used the AI tools. They are not autonomous yet. So the idea that actors are out there just with an AI thing that can just break in and do everything โ they are there, but [hackers] still need to be technical.ย
How I feel that a lot of attackers are using AI is in its ability to code, its ability to debug code. To touch back on something Tweeks said, he had mentioned zero-day attacks. Zero-day attacks are these huge things, or they can be a very small thing thatโs easy to fix. But imagine that thereโs something that China has got, or some other nation state has got โ a little vulnerability in Windows machines that allows them to get all data, anything that you type on your keyboard, it gets them able to record that. Now thatโs highly dangerous.ย
Itโs even more dangerous if they launch the attack and nobody knows how to fix it right off the bat. So until thereโs a fix for it on these zero days, thereโs that huge span. Where AI is being used is they can now take these drivers, they can take the code, everything in these software applications, everything in OS and new updates. Every time they fix something, theyโre looking to break that next update โ what did the engineer overlook, and what little bug in their code can they now leverage for that new exploit.
Usually it takes a lot of time to dig in, and itโs kind of like looking for arrowheads. I love looking for arrowheads. You could walk the same little patch and walk by an arrowhead a million times. Itโs just like trying to find a bug in code. If itโs just solely relying on your ability, youโre probably more likely four times out of 10 going to miss that error. Now letโs take AI that is [error-free] in code. Itโs really, really good at coding. And now youโre just asking it to find the bug.ย
A huge, huge vulnerability that we have to be aware of in the future is how quickly AI is going to be able to find these bugs that can be exploited in zero days.ย
Weeks: Iโd also add from the client side, from the user perspective, [client] operating systems, โฆ phones and devices are being embedded with AI thatโs recording your every keystroke, taking screenshots and knows your patterns.ย
Thatโs the new target, because thatโs the gold mine.ย
If they can say, hey, show me all Windows systems online that have Windows 11 and exploit the operating system, exploit RDP [remote desktop protocol] or whatever to get in, and then start harvesting that data that Microsoft is collecting โ thatโs scary because thatโs something thatโs being trusted.ย
People are clamoring for AI on devices and a lot of us security guys are like, Iโm not putting AI on any of my systems. You need to prove itโs secure before you start deploying stuff like that.
Cardinal: That leads into my final question. I was hoping that you could talk a little bit about what a regular person can do to protect their own property and what they can do, or not do, in their workplaces to defend against the โdark arts.โ
Weeks: Kind of classic: Think before you click. [For example], when you install new apps. I recently saw a system Iโm over get compromised, and it was because I didnโt think before I clicked. I installed some Chrome plugin that had malware attached to it.ย
When things ask for permissions on your phone, your little free game that you just downloaded for your phone doesnโt need access to your microphone and your camera, and access to your files and your photos. I donโt care how cool the game is, donโt install it.
Iโm constantly having to stop my family members from installing apps that are asking for questionable permissions. And you wonโt know about it until itโs too late. So itโs better to be safe than sorry.
Same thing with devices. Thereโs no reason to have your washer and dryer connecting to servers in China, which is a lot of these devices. Theyโre calling home to apps that are running to back-end systems in China or other countries. Even if itโs in the U.S., you donโt want these devices that are never getting patched to be on your network and calling home.ย
I have Blu-ray players and smart televisions. I have a separate network at the house for non-human devices. I have a human network for me and my wife, my laptop, my kids. And then we have a separate, I call it my IoT network that my Blu-ray player, my smart TV all connect to, so they canโt get to the humans and the data on my network.ย
So, compartmentalizing. A lot of routers now have an IoT network and a kind of a home network, what I call the โBSG model.โ In โBattlestar Galactica,โ thatโs how they kept the bad guys from hacking, because the bad guys were computers and they hacked the entire planet Earth. The only place they didnโt hack was the Battlestar Galactica, because it was an older system that was disconnected and had compartmentalized all their networks. So itโs a good model.
Garner: Weโre in a generation where we all are looking for that easy fix. โฆ Everybody wants like that secret password manager thatโs easy. And then they canโt forget that password. Well, you havenโt fixed the core problem, which is ourselves, and youโre relying on something that can be hit. LastPass got hit, and it was a huge debacle when that went down [in 2021]. โฆ A lot of that got dumped into the [password list leak] Rockyou 2021 TXT.
The main thing we can do is educate ourselves. Thereโs plenty of little online things, and the big one being how does your average person interact with the internet, email and websites?ย
Thereโs so many little things that I tell my parents about that they didnโt know. For instance, when you go to a Google search and you type in โ letโs say you have a problem on Facebook. I have seen this before. You type in โFacebook phone number service desk.โ Well, Facebook doesnโt have a phone number out there, but someone that may not know that will put it in. And then at the very top you would see โFacebookโ and then above it you would see โsponsored.โย
These attackers are out there sponsoring these fake sites of very well-known places. So you can click on it and then it goes to their controlled server. And now theyโre controlling everything that you see. Theyโve got phone numbers that you can talk to a real person, think youโre at Facebook. But in reality, probably what theyโre trying to do is say they can help you if you open a bitcoin account and put $1 in it.ย
They do these things all the time. I believe that as we take our own security into our own hands and we just educate ourselves a little bit, that goes a long way.
Weeks: And just to add what youโre saying: The biggest problem weโre seeing right now is social engineering.ย
Weโve all had a parent story, right, where Mom got hacked or Grandma got tricked into getting on the phone with her bank with a malware person on the other line sharing her motherโs maiden name and account information. I mean, thatโs insane.ย
But it all starts through getting you, the human, to do something. People are motivated through fear and urgency. So if you ever get an email or a text or anything thatโs giving you this sense of urgency, if Amazon is saying your account is hacked, click here, change your password โ donโt click there. Go out to Amazon yourself and check it.
If your bank sends you a text message, which they donโt do, saying you need to go here and change your online security, donโt go there. Call the credit card number or the number on the back of your card or go to the website first. Donโt blindly trust these things that are trying to motivate you to do something.ย
We see that more and more, this fear motivation. Now theyโre using AI to, for example, record your kidsโ voices and then call you using AI [with] a deep fake on your childโs voice saying, โMom, Dad help me. โฆ I need to get bailed out.โ And theyโll take payment in this form or that form or whatever.ย
Itโs going on left and right nowadays. We really need to be adamant about checking, especially our older folks. They trust authorities and they trust doctors and banks and lawyers and Amazon and Google. They just trust them. We need to not automatically trust.
If itโs motivating through fear or urgency, let that be a little red flag saying, Hey, I should not do the thing they want me to do, but Iโll go do it my own way, a more legitimate way. Thatโs one way of getting around the social engineering aspect thatโs really hurting a lot of our elderly community, too.
Cardinal: Deep faking childrenโs voices. Diabolical, man. Thatโs wild.
Weeks: Yeah, itโs happened to several people I know.

