Search This Blog

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, 13 May 2015

Cybercrime at 10,000 feet and above

As we were updating this article FBI today (29.04.2015) sent a warning to airlines to check for any suspicious activities where passengers are connecting unknown cables or wires to the inflight entertainment, or they have been advised to check inflight system logs frequently for any suspicious behavioural access.
All this action from world top investigative agency stemmed out of an recent event when a security researcher was offloaded a plane on 19th April 2015 from an United Airlines flight because the airlines thought he could probably hack into the aviation systems and disturb its inflight systems including EICAS (Engine-Indicating and Crew Alerting System), he tweeted something like this, “find myself on a 737/800, lets see Box-IFE-ICE-SATCOM,? Shall we start playing with EICAS messages? “PASS OXYGEN ON” Anyone? :) 
FBI had already seen his tweet and by the time his plane landed after he tweeted the above message he was escorted away and was questioned for few hours, now the point is whether or not he tweeting something as sensitive as aircraft information and claiming to hack is dumb/or was totally unnecessary but, it all points back to one key element here, that is anything and everything with an IP address connected to the all-knowing internet is vulnerable for cybercrime attack.
Airplanes are increasingly fitted with state of the art gadgetry so that passengers wouldn’t be deprived of the earthly connectivity options when they are above 10,000 ft and more. Most American airlines today provide Wi-Fi at a nominal cost and passengers have an option and wide array of choice to stream media, or to connect to internet to update their status on social media like Facebook or Twitter in real time. This combination of entertainment on the usual computer networks and an ever growing ambition to make everything connected might have just put the aircrafts flying above the ground susceptible to attacks by organizations which may have completely sinister motives which would also include threats to a national security and safety of passengers. Though the experts say this is theoretically possible might be difficult to achieve technically as of now.
The security experts also warn that there are weak encryption algorithms or insecure protocols in SATCOM technologies manufactured by some of the world’s largest manufacturers of these equipments who supply the same to airlines to be fitted in those aircrafts.
Technically though inflight systems and aircraft navigation is usually separated there usually will be a network communication which could be potentially breached by would be cyber criminals with advance knowledge of avionics systems and most modern aircrafts today have this combination of passenger systems and in aircraft controls on the same network.
In January 2008, Boeing responded to reports about FAA concerns regarding the protection of the 787’s computer networks from possible intentional or unintentional passenger access by stating that various hardware and software solutions are employed to protect the airplane systems. These included air gaps for the physical separation of the networks, and firewalls for their software separation. These measures prevent data transfer from the passenger internet system to the maintenance or navigation systems.
Aircrafts usually have a device called NED or Network Extension Device, though the way this device handles information is unique in nature, there is a slight possibility that in the future cyber criminals might come up with techniques which could probably bypass security boundaries between passenger network and the in aircraft systems.
As an example the geo position that you see on the entertainment screens comes from this devices where inflight systems transmit position frequently to the screens in front but this is usually one way communication and it has been stated that communication back to aircraft systems may be very difficult to achieve though new techniques might emerge.
This recent incident has only shown that new age technology not only affects the way you would do business on the ground but it could also affect the personal safety of people in today’s modern transport systems or endanger national safety if it falls into wrong hands.
Though the recent findings or warnings have been largely based on theoretical possibilities, Airlines and Aircraft manufacturers now have an increased pressure not only to ensure the in flight systems are safe and time tested but also they would need to imbibe state of the art cyber security controls to keep the Pilot/air traffic control systems safe from falling prey to criminals or terrorist groups.

The new age harsh reality, buying hacking and malware service online

In the barrage of cyber security news that has been making waves on international media recently, this heading somewhere in the swarm of websites would have easily missed your attention “Prices fall, services rise in malware-as-a-service market”.
There are criminal groups just waiting to sell their unique hacking skills to damage an organization, rather than using it just for fun few years ago as most of the hackers were doing. These groups see huge cash as companies would hire hackers to spy on a competition to gain a business advantage overnight or a disgruntled employee who wants to teach a lesson to his boss by formatting the server in a company that fired him.
One can hire a web root (the underground service provider) botnet of 1000 computers which can launch distributed denial of service for just under $100 and 10,000 computer botnet network will make you poorer by another $5000.
These services offer malwares which can convert a target computer into an anonymization proxies so that one can browse prohibited sites or launch attacks from an unsuspecting employees desktop which has been compromised.
There is a service which is called Capfire4 that has a web portal that offers the possibility to create customized version of malware, has an online console, and allows the buyer to control the networks which the malware has already compromised all in a trendy GUI. This service as of now offers remote control and password recovery based on what you pay through PayPal or bitcoin to maintain anonymity, most of these services are offered cloud based infamously referred to as dark cloud.
Imagine seeing one of your corporate network systems on this screen of an aspiring cybercriminal, when he logs into this online malware-as-a-service site.
The rule of hacking or malware as a service providers is simple, the more time it takes the more you end up paying. A simple DDoS would be just around $100 and complete control capabilities on a network with bots such as ZeuS would cost up to $20,000, all depending on who wants this service and how they want to utilize it, and where they want to inflict the damage, more the value is provided for a service one can be rest assured that an organization or entity is usually behind it.
Just as with legitimate and legal white hat hackers and IT/Network security professionals, various hackers also have their specialties and niche skills. There may be some who are more skilled in programming and writing viruses, Trojans or backdoors, just as there are IT security professionals who are skilled at writing signatures to detect such malware and are involved in antivirus/antimalware products. There may be others who are more skilled in identifying vulnerabilities in software or operating systems including mobile operating systems. There may be others who are masters at breaking into websites or networks.
This is as diverse as the list professional network security certifications IT professionals strive to acquire to make themselves more marketable, only that the certifications in the dark underground are based on market value of an hacker who has been successful with engagements similar to this and his/her rating within the hacker community.
The cloud based hacking/malware/Trojan as a service will only grow in size as days pass and when there are customers, who are active in buying these services.
No one can stop a criminal from engaging in an activity like this to steal or damage information from a company, but an effective security strategy to detect such attack in all corners of a corporate network surely will go a long way in keeping unwanted trouble at bay.

How not to wake up and find your data on the dark side of the internet

Data breaches have become the order of the day, just a couple of weeks back one of the major Hollywood production company and entertainment industry giant got hacked and was robbed of several gigabytes of confidential to ultra-sensitive information. The damage is still being undone as we write this and employees of that organization have been asked to stay off their mobiles, computers, and network to contain any further leakage. All the worldwide offices of that organization have been shut down from network access for more than a week, causing heaving revenue losses apart from some Hollywood flicks in HD format that have been released into torrent sites much before their premiere scheduled during March 2015. This loss might run into millions of dollars.
The targeted attack not only was designed to steal information but also wipe out data from hard disks showing the potential of some hacking groups to be disruptive in nature. It will take months for the company to get back into shape as far as recovering from the data loss that it has just experienced apart from onslaught of media attention and negative publicity. Imagine the plight of employees logging in on their workstations on a Monday morning only to be greeted by a red screen with warning message and a skull head in the background.
Though the media has already started attributing state sponsored hackers, hacktivists, and a physical access into the entertainment giant’s corporate network, a deeper investigation can hopefully reveal what exactly caused this and what are the motives of the attackers. This has become more difficult now that the worm used actually wiped off the entire hard disks on the systems that it had compromised.
This is a wakeup call for all the organizations, defence is not just in perimeter any more, in fact firewall’s, Intrusion prevention systems are fast proving to be ineffective to thwart cyber-attacks which are meticulously planned. Employees of an organization are vulnerable from everywhere, on their laptops, their smartphones, and a stranger greeting them on the street to the innocent looking website that they may have browsed for few minutes.
Organizations will have to define a robust deep skin security strategy which spans across the breadth and depth of an organization, they need to clearly map out critical information, identify bad apples within the organization, and measure the preparedness of employees in the event of a targeted spear phishing attack or a friendly access into their systems.
Organizations should not only depend on security technologies to help them thwart these attacks rather they should complement them with continuous monitoring of critical endpoints, assets and network components for anamoly and suspicious behaviours. Every touch point in a critical business operation should be able to alert when there is a possible misuse case, and there should be a SWAT team that watches these alerts and makes security sense out of them.
The reason not to rely on key security technologies is only further cemented with a fact that in one of the recent attacks a well-known security product which is famous for allowing whitelisted applications was compromised and the worm successfully included itself in the allowed whitelisted apps of the tool and compromised the systems.
Organizations need to do several things to thwart attacks which are targeted at them,
  1. Classify information based on business criticality and group them together for specific security measures
  2. Have a SWAT team which continuously tests the waters when it comes to current defence technologies
  3. Include endpoints like laptops, smart phones in their security strategy and protect them with the same level of security that is traditionally provided to servers
  4. Continuously train people on why they should be aware of cyber-attack by simulating attacks
  5. Monitor the critical assets for abnormal behaviour rather than just depending on the security technologies that are implemented on them, most of the security controls, tools throw out very important information which is usually ignored; and a centralized monitoring of them only helps to detect attacks much before they cause damage which is usually irreparable in nature.
It’s only in the interest of the CXO’s of the organizations to have a dedicated security strategy team which works with industry leaders in the security services area to draft an effective and predictive strategy to help the organization in these days of onslaught of cyber-attacks. Organization need to work with security companies to have tighter SLA’s and preventive monitoring which should help them detect attacks in seconds and mitigate them in minutes.
As you finish reading this and at this moment somewhere in the world cyber criminals would have successfully penetrated into a company which has a weak security strategy and would have floated its information on Darknet sites either for public consumption or for financial gains.
Never before in the history of computing having a solid information security strategy in this always connected world has been more important.

The Roadmap for intelligent security

Conventional security strategies are being constantly challenged by newer and smarter threats – APTs and AETs to name two. CISOs and CIOs are becoming extremely careful of where they tread, because most defense strategies are being effortlessly infiltrated.
Most high end strategies lack one thing – a single dashboard view. Only an analytics and intelligence driven security strategy can create the correct security solution. A robust Security and Events Management (SIEM) process is a basic step that’s required to achieve a single dashboard view of all the security technologies being deployed. SIEM was once a tool to ensure standards and compliance, but can also be used to generate a centralized dashboard view. This information can be used to co-relate the threat, its prevention and mitigation perspective seamlessly, in the security scenario through the analysis of structured and unstructured data- through logs and network traffic, and through some of the billions of events that occur in an enterprise daily.
However, these logs cannot allow the SIEM to see new threats like APTs. So, a new wave of SIEM products has been developed that allows them to monitor all the traffic and logs to detect specialized and business specific threats, using state of the art intelligence. Thus they can zero in on attacks that are happening or about to happen from data flowing through mails, documents, social media, audio, network traffic, click streams, accessed files, registry changes…anywhere. It makes security sense out of all this data, in terms of a possible event or offence, using ‘adaptive intelligence’. That means, it has the ability to understand network behavior over a certain period of time, and can detect any aberration almost immediately. This new age SIEM has drastically increased the ability to pre-empt threats.
But it is important that even this state of the art SIEM tool is updated with related technologies, to stay abreast of the iterative processes. For example, self-learning algorithms are increasingly available to enable complete automation of rule writing, but human intervention is required to identify business critical offences. A good MSS partner could be the answer here.
In addition, global security information feeds usually work at complementing the baseline information for SIEMs, keeping them current and updated at some level. These feeds could be a warning for dangerous IPs or latest information on threats detected globally.
A robust Security operations centre is the best investment to make all of this easy or any enterprise, instead of piecemeal solutions that may or may not talk to each other.
The function of the SIEM becomes even more crucial once the enterprise migrates to the cloud. This would give an even more holistic view of the security stand and vulnerability across the company. The cloud provider needs to station an SIEM collector on premise, to collate all the logs and events which can then be forwarded to the SIEM at the company’s premises. However, for this, a good amount of negotiation skills are necessary, since any delay in this intelligence could be fatal.
The only caveat with SIEM is that it needs to generate actionable intelligence through data analysis to detect threats, across the organisation. If fine tuned to the company’s needs and security status, and focused on a business risk, the insights provided by SIEM could be the value everybody needs for their security strategy. And once turned into quick decisions by SLA managers’ teams, they can be a priceless support.

Can you really trust your peripherals?

Global threat scenario is evolving too fast, with attackers finding different ways to pilferage and exfilterate data out of your network, security teams have to be proactively alert and defend their information. While traditional security has been largely addressing an organization’s perimeter, critical applications and servers which host critical information, hackers/cyber criminals have found the importance of targeting end points in a company largely because they are in the “trusted” zone. Perpetrators very well know that it is far easy to map an organizations network/its information and gain access to sensitive data if they masquerade themselves as trusted users.
Peripherals which you would trust to connect to your PC’s/Laptops have been recent targets of encoded firmware malware’s which exploit the basic design of how they are programmed to interact via your seemingly innocent USB ports.
Security researchers recently demonstrated that it possible to reprogram the firmware on USB peripherals, be it USB drives, USB Mice, or any device that has programmable chip. The reprogram process by attackers can leave good amount of malicious code on to the chip of USB device allowing the same to effectively hide from antivirus and malware scans and obey the instructions that exploit your data.
Imagine a scenario of social engineering where one of your employees is given a firmware infected USB drive which in turn plugged into that user’s official laptop and what can follow as a result is only limited to one’s imagination, now let’s quickly examine and see what is possible when something like this happens at your organization.

USB malware’s that can act as keyboards:

Recently demonstrated malware a.k.a BadUSB was successfully able to emulate a keyboard on users’ desktop and issue commands that were preprogrammed into the code. The level of access peripherals have being part of the operating system, malware can do variety of things by issuing commands to exfilterate data to loading a Trojan which will act as a backdoor to establishing a connection to a remote server, possibilities are only limited to the abilities of the attacker. Another interesting facet is attackers have found a way infect other peripherals which are connected onto the same system expanding their attack surface.

USB drives as network cards:

USB malware’s can create a spoofed network card which in turn will redirect most of your traffic via custom DNS server which would then point to attackers doing man in the middle attacks.

The ease of having operating systems on a USB:

A modified thumb drive or an operating system image (usually in .iso format) can be already injected with boot sector viruses which can control how the user uses the OS, and allowing an attacker to remotely take over the machine and compromise sensitive and confidential information. This will be like booting from an Virus OS.
All the above things do sound scary and we need to be be, as Karsten Nohl puts it in a recent blackhat conference there is no way this can be patched, because attackers are exploiting the very way the USB was designed.

What next?

Imagine the power this gives the attackers, they can reprogram almost every USB device which has a onboard firmware that can be reprogrammed, including, mouse, external touchpad, phones etc.
USB drives are everywhere, and this itself makes it so scary because from a CEO, to an engineer in a company at least once in a day connect an USB related device to their computers, and as the availability of this kind of exploit grows, need for a proactive security program in an organization only increases. Cottonmouth, revealed in the leaks of Edward Snowden. The device, which hid in a USB peripheral plug, was advertised in a collection of NSA internal documents as surreptitiously installing malware on a target’s machine to enable backdoor. Though the exact mechanism is not described, it is highly likely that attackers did use USB peripherals which is conceptually close to what is being discussed here.

What is the Solution?

There are workarounds for this problem, while there is no patch/tool/fix which is yet available to detect these kind of malwares, until USB peripheral companies come up with code signing on their firmware and antivirus companies are able to scan a firmware code, it is best to follow the below steps to stay secure.
  • Enable USB drives in organization system only where necessary and create awareness among users not to trust unknown devices
  • Conduct a full-fledged audit of your systems to see if you are already compromised with this kind or other security threats
  • Continuously monitor your systems including endpoints for any suspicious activities and stop perpetrators before the information leaves your company

Governance in the digital world

Governance is critical to ensure security in the more vulnerable digital world.
With our world fast becoming more virtual and less real, security is as much a scare there, maybe even more than in the real one.
Internet penetration and usage of on-line applications for day to day lives is increasing and becoming vital for any economy. The increasing number of devices connected to the Internet, make our daily transactions easier, but create newer vulnerabilities. Every passing day brings bigger and more destructive data breaches, impacting lives of common people, and damaging the reputation of enterprises.
Recently, an extremely notorious botnet was brought down by the concerted efforts of security research companies and law enforcement across various countries, but this is only a one-off case in an ocean of threats in the digital universe. We need much more strength to fight, and the reason we still can’t, is due to the lack of a governance process to tackle security issues in a focused manner.
Most states have no clearly defined borders in the digital world to implement their own data protection and cybercrime laws, as in the physical world. It is a fact that any individual can set up a server and send any kind of packet onto the internet space without any regulation, or an identity check. In fact, the digital world makes one virtually (pun intended) nameless and extremely difficult to track, and this only makes it tougher for law enforcement to locate and identify hackers. Lack of an ID and governance protocol is making hacking a huge business opportunity!
It is hence crucial that the digital world has clear governance rules, much like the physical world where we have passport and visa for border control and movement between nations/governing mechanisms. This may not be a fool-proof mechanism, but can bring some control to this chaotic situation. The technologies required for identity management already exist, but need appropriate implementation, especially one that enables them to handle large volumes of data and traffic. This also calls for Citizen Information being available in digital form with the government for identity management.
This step may create an Internet with boundaries, where most of the online traffic would be restricted to within the country and only certain traffic is allowed to go out and come in. Some people may think that this is restrictive but this may be the only way to reduce hacking and other security threats.
Having this clear process and strict governance in place may then be the only way out for countering the constant threats that makes the greatest boon of the twenty first century –connectivity, our biggest threat.

How NOT to be caught off guard

With the rapidly changing security threats intensity and landscape, the last decade’s strategy of defensive apps is not enough. It is time to integrate vulnerability information with security operations in the Enterprise, to ensure the strength to fight it.
Defence was the only way to fight infosec threats, just a few years ago. Not anymore. Today, with the fast growing technology landscape that is so finely tuned to security threats, enterprises need to ensure complete preparedness for the attacks. In fact, this should be the first point in the strategy for IT roadmap – implementation of monitoring mechanisms to detect vulnerability, or early stages of attacks.
Every enterprise’s security strategy increasingly needs to be about early detection of suspicious activity, and maybe even vulnerability analysis. This needs to be a clear basic mandate, over and above the basic infosec policy roadmap. Security readiness to protect vulnerable targets demands 24X7surveillance – coupled with state of the art security applications. The demands on the IT team being what they are, and considering the criticality of this operation, it is best to outsource the entire Security Operation centre to a stable support partner.
So what value should your security vendor deliver to justify the investment?
It goes without saying, a security support partner will have state of the art technology and cutting edge applications to help keep enterprise secure, plug every hole, stitch up every vulnerable point. But very often, that’s not enough. What you need to do is get business and IT apps on one platform; thus saving costs and increasing efficiencies. Unifying security operations and creating one integrated security operations centre will help add a big punch to the existing security strategy. Ensuring that vulnerability data is integrated with the network security solutions will help early detection, pushing up the ability to fight off the threat successfully.
A single, coordinated view of the security landscape, vulnerabilities, threats, and security apps- all on one platform- is the only smart way to keep your IT and data safe. A tech support partner who excels in integrating all this intelligence within the company network, allowing security teams to process collective memory, identify vulnerabilities and keep the preparedness updated, is the need of the hour. Historical insights into previous attacks or threats can help create and implement an effective mitigation strategy that will help enterprises to be armed, if not lethal.
Outsourcing this activity to a vendor with focused security technology skills and resources will help save costs and also serve to open up the resources available for more business critical activities.

Is any place connectivity our biggest threat?

With better networking technologies, we are now able to actually access anything anywhere. An increasing number of public areas are now Wi-Fi friendly, and in some ways, this seems like a boon. There is no reason to be out of touch, no time is wasted, and our twenty-four hours connected lifestyle has never had it so good.
However, in enterprise context, is this safe? This connectivity comes at a massive price; most of it is about ease of security outages, in unprotected conditions.
In public places like airports, where Wi-Fi is available freely, the threats are enormous. Just a month ago, Sourcefire, (now part of Cisco), commissioned a ‘Beach to Breach’ research that threw up some seriously noteworthy observations:
From the surveyed workforce in UK, 77% usually carry their work devices even on holiday. Almost the same percentage of those who did, checked a couple of hours a day on office activities they might be missing- logging into the office mail from external networks. Not many realize that staying connected to their workplace with their work devices (which may have security apps in place), but using unsecured connections, poses a huge threat to enterprise security.
Here are a few of them:
  • All email traffic over unsecured networks can be captured. Since most e-mails are in clear-text, and IMs in HTML, it does not require very high end coding knowledge to capture the traffic specifics. These can then be mined offline for information that a hacker or someone with vested interests may need.
  • Not everyone realises that there are some apps that share the account details including password in clear text over a network, when a login happens. For instance, every time a POP3 mail account has a new email login and check, the used account name and password are a part of the data transfer- in clear text. Accounts details are, hence, extremely vulnerable for anyone who wants to create a breach, and access data, communications and everything that the user can share over mail. The extent of damage is unimaginable.
  • With freely available hacking tools on the net, any hacker can use unsecured networks as an entry point to launch spam or virus attacks on large mail communities, including enterprise locations. One system being compromised is all it takes for the virus to become an epidemic in the organisation.
These are just a few cases in points of the kind of risk a device faces when connecting to enterprise network on insecure Wi Fi networks.
Although strict end point security is a must, it has also a lot to do with the security status and vulnerability weaknesses of the enterprise as a whole. Frequent vulnerability or threat assessments and device security updates can help detect vulnerabilities and breach points. This may just be the only solution to fight security compromises of the entire enterprise infrastructure – brought on merely due to a SINGLE insecure login.

Create a superman to protect your network and keep your intruders at bay

CISO’s and CIO’s are increasingly becoming wary of these new age threats like APT (advanced persistent threats)’s, AET (advanced evation techniques)’s, zero day advanced malware. These have the capability to deflect all kinds of defense strategies and exfilterate confidential information to criminals sitting in remote locations.
Cisco’s global threat report says 54% of the time, it takes months to detect a compromise and 75% of the time, the compromise of information would have happened in minutes. This level of compromise on information surely creates huge risks to the business and reputation of an organization and there is no choice but to stay one step ahead of the attackers who are more motivated than before.
We were recently faced with a customer problem where they had invested in a wide range of security technologies from APT detection, Intrusion prevention to database attack monitoring. The real problem was that they were unable to get a single view of all their organization issues despite the millions of $ investments in their security strategy.
An answer to the above problem is having a robust Security Information and Event Management (SIEM) tool that provides a single dashboard view of all security events for an organization in real-time, especially in the light of recent security outages on organizations. Gone are the days, when SIEM was seen as a tool to generate compliances to various standards, infact organizations have long moved from this stance and now use SIEM more from a threat detection, prevention and mitigation perspective, especially in the current connected scenario.
But the world is constantly changing, we need to study data and derive patterns through them to secure our borderless organization. Imagine if your security solutions implemented had advanced security analytics ability. This is what is transpiring in the new world of SIEM. A new wave of SIEM products are entering the market offered by managed security providers. These solutions have capabilities to do advanced security analytics and the possibility to feed virtually anything into the SIEM (ex: Network traffic data, endpoint data etc). The power of looking at network traffic, server logs, endpoint logs, application flow data has given immense capabilities to new generation SIEM’s to detect specialized and business specific threats more effectively. They achieve this through correlation of all the events and packet information that are gathered from the infrastructure. This state of the art threat intelligence is applied to zero in on an attack which might be in progress or is about to happen. This pre-emptive monitoring and warning the SOC on an impending attack, gives the organization enough time to prepare for an attack to ensure that there is no loss to revenue of reputation. In many times pre-emptive knowledge can also thwart the attack.
So do you have your superhero ready? Or do you have gaps in your security infrastructure which leaves the door open to unwelcome intruders?

HeartBleed shows the mirror- how secure we really are

The internet is increasingly become the place where all the information about us as individuals reside. Our preferences, activities, social connections and even critical data like bank account details, income details and even password details reside online today.
Confidential data residing online makes web security an important concern. Secure Sockets Layer (SSL) protocol and Transport Layer Security (TLS) are used by websites as security standards to transmit information securely between the server and the user via client authentication, data encryption and data integrity checks.
Communication between a user and the server is established by sending a specific signal to the server to check if it is online and this signal is called “heartbeat”. Earlier this year, a google researcher and a Finnish firm (Codenomicon) independently discovered a bug in the OpenSSL’s implementation of the TLS/DTLS heartbeat extension and called it the “HEARTBLEED” Bug.
HeartBleed exploits a heartbeat request by sending a malicious heartbeat that tricks the server into sending random chunks of information including email addresses, usernames, passwords or any sensitive data thus enabling hackers to access and exploit information throughout the internet. Although HeartBleed is the result of a small coding error, it has affected several major websites like Google, Facebook, Yahoo, Amazon, Pinterest, SoundCloud and hence a majority of internet users. Mobile security has been another casualty and android is among the most affected operating systems due to the HeartBleed Heartbleed bug. Several tools such as Tripwire SecureScan, App check, McAfee’s test tool and Qualys’ ssllabs.com have been made available pronto to test the presence of or effect of HeartBleed on site data.
HeartBleed has far reaching consequences as it has remained undetected for about two years. The solution has been identified, but applying the patch to all the affected platforms could take almost a year and Hackers can continue to exploit the flaw until the bug is completely fixed. According to sources, even after 2 weeks of disclosure, about 300,000 websites were still on the vulnerability scanner.
To protect the user data and encryption keys, sites must upgrade to the patched version of OpenSSL, revoke compromised SSL certificates and get new ones issued. Smaller online stores and services affected by HeartBleed could take time to provide remedial measures. To assure complete protection users are advised to wait until the patch is fixed, apply new, long, unique passwords and change them regularly thereafter.
As HeartBleed could also have been due to an economic crunch, Linux Foundation has announced a multimillion dollar project “Core Infrastructure Initiative” to provide funds to critical elements of the global information infrastructure.
Whatever the reason may have been, the shockwaves that HeartBleed sent out were enough to jolt a large number of enterprises awake to their vulnerability. It is yet another reminder of just how insecure information technology intrinsically is, and how seriously we need our vulnerability management.

Security II- How do we integrate vulnerability tests within the network?

Threats abound, and of course, as our possession grow more valuable, our threats become scarier.
Just a few years ago, defence was the only strategy to adopt against these threats, but today, the rapidly changing landscape has made early detection critical. Preparedness for the attacks is crucial, and so is implementing monitoring mechanisms to detect early stages of attacks.
It is now established that early detection helps so security is now strategising to gear up for detection of any kind of suspicious activity in addition to defences already set up in enterprise. There are agencies constantly scanning for targets and damage. This 24X7 surveillance is a job that needs close attention and full attention, and is best outsourced. In fact it is becoming increasingly important for enterprises to outsource security monitoring activities to vendors who do it in a focused manner.
While investments are mandatory and applications are necessary, they do not seem enough to help enterprises cope with security threats. What then is the answer? More apps and higher budgets? That defeats the whole purpose, doesn’t it? An intelligent move would be getting business and IT apps on one platform; it saves costs, increases business efficiencies, and adds teeth to both. Getting security operations into one integrated centre will help add teeth to the fight against threats. Integrating vulnerability data within the network allows for early detection and hence is a good defence mechanism can be put in place as well.
For many enterprises, the way forward needs a long hard look at how different activities can be integrated within the security organisation to facilitate a single view and a coordinated defence mechanism can be built around it, within the network. Then, we need to integrate vulnerability tests and look for ways to prevent threats by working around this intelligence. What is critical is early detection of threat and preparedness for the attacks, implementing monitoring mechanisms to detect for early warning and not waiting for the outage. This is possible if all the intelligence is integrated within the company network, allowing security teams to process collective memory identify vulnerabilities and keep the preparedness updated.
That requires a consolidated data and knowledge on the previous attacks, and then a concerted effort to study the vulnerability that caused it, understand how it can be mitigated and put in an effort to be armed, if not lethal.
Creating a security history, accumulating a threats and mitigations data base allows learnings that can be an enterprise’s only defence very soon. Outsourcing this activity is a good idea, one that helps save costs as well as opens up the resources available to doing more business critical activities. A single view and a coordinated defence mechanism built as a security strategy, and integrated with vulnerability tests within the network, can actually help prevent some of the persistent threats, giving some measure of relief.

Security – Growing Threats, and vulnerability

March 27, 2013, was a red letter day in the history of cyber security in the civilized world. We saw for the first time, an actual Cyber war. The ammo used jammed the World Wide Web highway almost to a halt. The open hostilities between ‘spam-fighters’ at SpamHaus and the free thinking Dutch Web-hosting company Cyberbunker gave a new meaning to the word ‘security outage.
It was a DDOS(distributed Denial of Service), attack on unprotected Domain Name System (DNS) servers which were flooded with big amounts of useless information, jamming up bandwidth and processing time bringing down almost half of the infrastructure on the London Internet Exchange, and triggering similar shutdowns in many banks worldwide. The losses were not disclosed, but the fact that the Internet is so vulnerable, is scary. Then there are persistent targeted attacks on institutions as well as individuals. They could come in the form of phishing, or spear phishing, hacking, poisoning of websites, malware injection. These are just a handful of different ways of attacking individual or enterprises.
Over USD 60 billion was spent in 2012 to fight security threats, according to Gartner. The spending is slated to grow to USD 86 billion to 2016, and the global security software sales that grew to $20.4 billion in 2012, is expected to grow 7.9% to $24 billion in 2014.
Open security threats to vulnerable systems across industries are stuff IT nightmares are made of. Airline outages involving millions of passengers and hours of flight time, easier to bust ATMs or ability to siphon money by exploiting IT vulnerabilities, to bring down utility infrastructure or hacking into the extensive network of oil and gas pipelines (the Iranian Stuxnet attack), even the tweet war declared on the Whitehouse that effected the stock market globally – the list is endless, it is cyber terrorism.
Today, the digital world has come to a stage where there is no telling where the next attack will come from. Hacking and breach strategies are changing every day, enterprises need to have a constant surveillance on whether they are falling in the high risk category, specially where there is money, data or market standing involved. Banks, financial institutions and other institutions that deal with finances, are the most effected, as are organisations dealing with direct consumer data.
Threats come in many guises – networking, the human connectivity with machine and the worldwide web. Then there is the threat brought in by emerging technologies such as Cloud and enterprise mobility and the most controversial one – about employee freedom to use varied devices for company uses – the Bring Your Own Device (BYOD) arguments.
As we get more connected, more tech dependent for our business needs, as data becomes more and more valuable, so will our security risks increase, our vulnerabilities rise and our threat detection will need to be more streamlined, much, much more effective than it is now.
Thoughts, what is the best way to fight this increasing scare???

SOC- the new SPOCK in town (the paradigm shift to security)

Evolution of technology has made us many times smarter, miles more efficient and able to deliver services and products that were unheard of a few decades ago. But is has brought with it its own threats and challenges. Information technology, and more recently, mobility technologies, the magic wand that miraculously provided rocket fuel to all our business processes, has sweat holes that can also leak away the entire future of enterprise. Security concerns hit hardest where there is most to secure. Banks! Everybody’s money, all the transactions, billions of dollars’ worth of businesses, not to mention market standing, …and trillions of dollars’ worth of savings- can be eliminated in just one bug’s worth. A hacker, sitting in the remote innards of a countryside, can bring the worlds’ biggest financial systems, aviation systems, business and all activities, on their knees.
We are all aware of the threats, and enterprises are becoming increasingly conscious of the fact that not strategizing for an Advanced Persistent Threat or lack of preparedness for a DDOS( Disturbed Denial of Services)- attack can bring the entire business down. They also know that having policies, processes coupled with Perimeter security appliances are not enough. While compliances are driving the basic security framework, the ever emerging and ever evolving threats needs some more focused measures. And the current ad hoc measures, mostly knee jerk and point solutions, add no muscle to the fight.
The focus has to shift from prevention to detection. Most enterprises have an extremely heterogeneous technological environment when it comes to security. Getting all this heterogeneity on one platform, integrating it and analysing the situations would be difficult. This is the ripe time for integration of security devices and measures. What will be needed then is a Security Information and Event Management (SIEM) solution that will help log, analyse, classify and assess data.  Monitoring, analysis and response – could all be centralised under a sharpshooting team – manned by skilled people, run by mature and tested processes, written in stone by an efficient and clearly defined governance structure and enabled by the bests in class technology. A Security Operations Center (SOC) built on a standard SIEM with an integrated vulnerability management system could well be the answer to the gnawing and growing security threats.