Rodolfo Saccani, CTO Libraesva

Cyberwarfare is a reality, with evolving geopolitical tensions constantly shaping and modifying the cyber risk for organizations and states.

Cybercrime vs cyberwarfare

Malicious actors have learned to move fast and to capitalize on situations that draw attention and trigger emotions. Cybercriminals take advantage of the tension and fear created by conflict for all kinds of financially-driven swindles, including phishing and ransomware campaigns. Malicious campaigns are now being targeted at a national level, such as those aimed at disrupting infrastructure and the delivery of foreign assistance to Ukraine. In response, national-level computer security incident response teams (CSIRTs) have issued guidelines for mitigating the potential risk of cyber-attacks on companies, institutions, infrastructure, and communication systems at a time of heightened threats.  

However, unlike criminal attacks which capitalize on geopolitical instability, cyberwarfare involves state-sponsored and politically motivated attacks. The US Cyber Security & Infrastructure Security Agency clearly identifies those nations it considers to be presenting an advanced persistent threat, and regularly publishes advisories to help organisations to reduce risk and build their security capacity.

The EU, UK and US have all imposed sanctions for cyber-attacks (such as against Russia for NotPetya)NATO has established the Cooperative Cyber Defence Centre of Excellence, but a unified doctrine is still lacking

Some countries, such as France and the UK, have publicly declared that they will respond to cyberattacks with all necessary means, including military action.

L'email è il punto di partenza della maggior parte degli attacchi

L'email è il canale di comunicazione più utilizzato (e abusato) tra le organizzazioni, ed è per questo che è da qui che parte la maggior parte delle violazioni dei dati. Le campagne mirate sono un vettore di attacco comune per gli attori statali e i criminali informatici con motivazioni politiche, e il modo più comune di usare le armi della posta elettronica è attraverso attacchi di phishing e malware.

La guerra informatica non fa necessariamente leva su argomenti legati a tensioni geopolitiche o escalation militari. Gli attacchi sono di solito progettati da attori esperti che cercano di rimanere al di sotto dei radar, il che significa che le email di phishing pericolose possono sembrare abbastanza innocue, e non quello che ci si potrebbe aspettare.

Geoblocking – the logical line of defense

Geoblocking restricts content access based on a user’s location. It uses IP addresses, GPS, and end-to-end delay measurement to identify where a user is and either approve or deny access. It is commonly used to protect copyright and licensing, such as preventing US viewers from watching movies on a European streaming site.

Geoblocking can also be used to prevent the delivery of content originating from specific states or nations. While bad actors can still route attacks through different countries, this involves additional steps and increases the chances of detection. Geoblocking may not be a silver bullet, but it is a logical measure to take when the risk of attack from certain geographical areas increases.

Esistono due approcci per il geoblocking delle email:

???????? Rejecting email from certain locations

Il rifiuto delle email a livello SMTP può essere gestito eliminando le connessioni provenienti da indirizzi IP appartenenti a un determinato Paese. Questa semplice strategia di blocco è efficace in termini di utilizzo delle risorse, ma fa trapelare informazioni al potenziale attaccante, che riconoscerà immediatamente il blocco e cambierà strategia.

Inoltre, non avete visibilità su ciò che è stato respinto: non saprete se c'era del traffico legittimo che cercava di passare e non sarete a conoscenza di eventuali tentativi di attacco mirato in corso. Inoltre, come già detto, un'email proveniente da una località bloccata potrebbe essere stata inoltrata attraverso altri Paesi.

For some organizations, rejecting traffic from an entire country or countries is feasible, but for others it isn’t, and a more refined approach may be needed. This is where quarantining proves to be the better alternative.

???????? Quarantining email for evaluation

In alternativa al rifiuto assoluto, raccomandiamo la quarantena come approccio migliore per prevenire gli attacchi via e-mail attraverso il geoblocking. Ciò comporta l'accettazione e l'analisi di tutte le email e la messa in quarantena silenziosa (non consegna) dei contenuti provenienti da località specifiche.

  • Attackers are not alerted to the measures you are taking
  • È possibile analizzare i campioni di email per rilevare i tentativi di attacco.
  • You can investigate the tools and strategies that attackers are using (our analysts can support you with this if you need help)
  • You can define where quarantine measures are instigated, whether on the last hop (the final relay that is attempting to deliver the email) or on any of the intermediate hops (which could include countries that the email has been relayed through)
  • Avete piena visibilità di tutto il traffico in quarantena, in modo che le email legittime possano essere rilasciate per la consegna.
  • È possibile definire delle eccezioni, ad esempio bloccare le email provenienti da un intero Paese, ad eccezione di quelle provenienti da organizzazioni specifiche con cui si è stabilito un rapporto.

Naturally, geoblocking and quarantining are both included in our award-winning Libraesva Email Security solution, as well as threat analysis and remediation, spoofing protection, sandbox defenses, our AI-driven Adaptive Trust Engine and much more.

Ready to find out more?