Search This Blog

Wednesday, 13 May 2015

Social media – the new Big Bang

The net is a noisy place, with unlimited numbers of conversations happening every moment. People are talking about each other, casually, about business, about requirements, about connecting… but that’s not the end.
What is interesting is, that is the new social structure. To be seen, to be heard and to be taken seriously, every business needs a social media presence – a Big Bang presence that makes heads turn, that helps raise a voice in the din.
But mere conversations or people talking about you cannot mean business of marketing, right? There have to be strategies, plans and of course, tools and technologies to use this medium to its full capability. Once business engagements move online, the whole engagement process becomes a better experience with much further reaching effects for both customers and partners, as well as all other stakeholders, like employees. This platform’s easy adaptability has got new applications buzzing around it, giving it a key role in business strategy today.
The only issue is, how is its effectiveness measured? How do you know when investments in social media are actually paying off? The impact of a social media strategy depends on four key factors:
  • The internal collaboration structure around it (employee engagement, efficient and relevant knowledge management)
  • The sales structure and how your organisation responds to it – lead management and how the analytics work
  • Services and support offered – the technology behind the connection, and
  • Customer support models- which are about how you plan to retain customers, how much are you willing to learn about them and how much you value their time in terms of response time from you?
To map the social media applications to their ROI, you need to find the connection between your business priorities and these factors – what works. A relevant and effective content strategy then needs to be built around it. But what exactly is ‘relevant’?
In this case, content that aligns with the business goals is the most relevant. So the obvious way to get the impact from your social media strategy is to define your goals and then align the activity along them. So, what are you looking at? To get the best of your sales and marketing strategy, by using social media as a tool? Or impart greater satisfaction to customers, also gaining market intelligence in the process? Or maybe make the time to market period more fruitful, if not shorter, thus adding to brand recognition and even bottom-lines eventually? Or is the goal just to keep your brand visible to the market out there? Once you are clear in what exactly  is needed, it is easy to set a strategy in place, and also measure the effectiveness in very clear terms. With visible goals, it is easy to identify KPIs and even quantify them. Some of the indicators that will tell you if your social media strategy is working are obvious – an increase in online traffic – followers and fans, download responses through email marketing campaigns, and of course, increase in the number of online mentions. And you really know it is working when these activities indicate increased sales, reduced customer service enquiries and suddenly you are also saving costs. Values attached to the goals and aligning them with these KPIs can clearly indicate the ROI for your social media initiative.
Social media is a vast and effective strategy, especially given the spread of the online world. What is required to make use of its advantages is a strong metrics for ROI coupled with a clear governance process.

Cybercrime at 10,000 feet and above

As we were updating this article FBI today (29.04.2015) sent a warning to airlines to check for any suspicious activities where passengers are connecting unknown cables or wires to the inflight entertainment, or they have been advised to check inflight system logs frequently for any suspicious behavioural access.
All this action from world top investigative agency stemmed out of an recent event when a security researcher was offloaded a plane on 19th April 2015 from an United Airlines flight because the airlines thought he could probably hack into the aviation systems and disturb its inflight systems including EICAS (Engine-Indicating and Crew Alerting System), he tweeted something like this, “find myself on a 737/800, lets see Box-IFE-ICE-SATCOM,? Shall we start playing with EICAS messages? “PASS OXYGEN ON” Anyone? :) 
FBI had already seen his tweet and by the time his plane landed after he tweeted the above message he was escorted away and was questioned for few hours, now the point is whether or not he tweeting something as sensitive as aircraft information and claiming to hack is dumb/or was totally unnecessary but, it all points back to one key element here, that is anything and everything with an IP address connected to the all-knowing internet is vulnerable for cybercrime attack.
Airplanes are increasingly fitted with state of the art gadgetry so that passengers wouldn’t be deprived of the earthly connectivity options when they are above 10,000 ft and more. Most American airlines today provide Wi-Fi at a nominal cost and passengers have an option and wide array of choice to stream media, or to connect to internet to update their status on social media like Facebook or Twitter in real time. This combination of entertainment on the usual computer networks and an ever growing ambition to make everything connected might have just put the aircrafts flying above the ground susceptible to attacks by organizations which may have completely sinister motives which would also include threats to a national security and safety of passengers. Though the experts say this is theoretically possible might be difficult to achieve technically as of now.
The security experts also warn that there are weak encryption algorithms or insecure protocols in SATCOM technologies manufactured by some of the world’s largest manufacturers of these equipments who supply the same to airlines to be fitted in those aircrafts.
Technically though inflight systems and aircraft navigation is usually separated there usually will be a network communication which could be potentially breached by would be cyber criminals with advance knowledge of avionics systems and most modern aircrafts today have this combination of passenger systems and in aircraft controls on the same network.
In January 2008, Boeing responded to reports about FAA concerns regarding the protection of the 787’s computer networks from possible intentional or unintentional passenger access by stating that various hardware and software solutions are employed to protect the airplane systems. These included air gaps for the physical separation of the networks, and firewalls for their software separation. These measures prevent data transfer from the passenger internet system to the maintenance or navigation systems.
Aircrafts usually have a device called NED or Network Extension Device, though the way this device handles information is unique in nature, there is a slight possibility that in the future cyber criminals might come up with techniques which could probably bypass security boundaries between passenger network and the in aircraft systems.
As an example the geo position that you see on the entertainment screens comes from this devices where inflight systems transmit position frequently to the screens in front but this is usually one way communication and it has been stated that communication back to aircraft systems may be very difficult to achieve though new techniques might emerge.
This recent incident has only shown that new age technology not only affects the way you would do business on the ground but it could also affect the personal safety of people in today’s modern transport systems or endanger national safety if it falls into wrong hands.
Though the recent findings or warnings have been largely based on theoretical possibilities, Airlines and Aircraft manufacturers now have an increased pressure not only to ensure the in flight systems are safe and time tested but also they would need to imbibe state of the art cyber security controls to keep the Pilot/air traffic control systems safe from falling prey to criminals or terrorist groups.

The new age harsh reality, buying hacking and malware service online

In the barrage of cyber security news that has been making waves on international media recently, this heading somewhere in the swarm of websites would have easily missed your attention “Prices fall, services rise in malware-as-a-service market”.
There are criminal groups just waiting to sell their unique hacking skills to damage an organization, rather than using it just for fun few years ago as most of the hackers were doing. These groups see huge cash as companies would hire hackers to spy on a competition to gain a business advantage overnight or a disgruntled employee who wants to teach a lesson to his boss by formatting the server in a company that fired him.
One can hire a web root (the underground service provider) botnet of 1000 computers which can launch distributed denial of service for just under $100 and 10,000 computer botnet network will make you poorer by another $5000.
These services offer malwares which can convert a target computer into an anonymization proxies so that one can browse prohibited sites or launch attacks from an unsuspecting employees desktop which has been compromised.
There is a service which is called Capfire4 that has a web portal that offers the possibility to create customized version of malware, has an online console, and allows the buyer to control the networks which the malware has already compromised all in a trendy GUI. This service as of now offers remote control and password recovery based on what you pay through PayPal or bitcoin to maintain anonymity, most of these services are offered cloud based infamously referred to as dark cloud.
Imagine seeing one of your corporate network systems on this screen of an aspiring cybercriminal, when he logs into this online malware-as-a-service site.
The rule of hacking or malware as a service providers is simple, the more time it takes the more you end up paying. A simple DDoS would be just around $100 and complete control capabilities on a network with bots such as ZeuS would cost up to $20,000, all depending on who wants this service and how they want to utilize it, and where they want to inflict the damage, more the value is provided for a service one can be rest assured that an organization or entity is usually behind it.
Just as with legitimate and legal white hat hackers and IT/Network security professionals, various hackers also have their specialties and niche skills. There may be some who are more skilled in programming and writing viruses, Trojans or backdoors, just as there are IT security professionals who are skilled at writing signatures to detect such malware and are involved in antivirus/antimalware products. There may be others who are more skilled in identifying vulnerabilities in software or operating systems including mobile operating systems. There may be others who are masters at breaking into websites or networks.
This is as diverse as the list professional network security certifications IT professionals strive to acquire to make themselves more marketable, only that the certifications in the dark underground are based on market value of an hacker who has been successful with engagements similar to this and his/her rating within the hacker community.
The cloud based hacking/malware/Trojan as a service will only grow in size as days pass and when there are customers, who are active in buying these services.
No one can stop a criminal from engaging in an activity like this to steal or damage information from a company, but an effective security strategy to detect such attack in all corners of a corporate network surely will go a long way in keeping unwanted trouble at bay.

How not to wake up and find your data on the dark side of the internet

Data breaches have become the order of the day, just a couple of weeks back one of the major Hollywood production company and entertainment industry giant got hacked and was robbed of several gigabytes of confidential to ultra-sensitive information. The damage is still being undone as we write this and employees of that organization have been asked to stay off their mobiles, computers, and network to contain any further leakage. All the worldwide offices of that organization have been shut down from network access for more than a week, causing heaving revenue losses apart from some Hollywood flicks in HD format that have been released into torrent sites much before their premiere scheduled during March 2015. This loss might run into millions of dollars.
The targeted attack not only was designed to steal information but also wipe out data from hard disks showing the potential of some hacking groups to be disruptive in nature. It will take months for the company to get back into shape as far as recovering from the data loss that it has just experienced apart from onslaught of media attention and negative publicity. Imagine the plight of employees logging in on their workstations on a Monday morning only to be greeted by a red screen with warning message and a skull head in the background.
Though the media has already started attributing state sponsored hackers, hacktivists, and a physical access into the entertainment giant’s corporate network, a deeper investigation can hopefully reveal what exactly caused this and what are the motives of the attackers. This has become more difficult now that the worm used actually wiped off the entire hard disks on the systems that it had compromised.
This is a wakeup call for all the organizations, defence is not just in perimeter any more, in fact firewall’s, Intrusion prevention systems are fast proving to be ineffective to thwart cyber-attacks which are meticulously planned. Employees of an organization are vulnerable from everywhere, on their laptops, their smartphones, and a stranger greeting them on the street to the innocent looking website that they may have browsed for few minutes.
Organizations will have to define a robust deep skin security strategy which spans across the breadth and depth of an organization, they need to clearly map out critical information, identify bad apples within the organization, and measure the preparedness of employees in the event of a targeted spear phishing attack or a friendly access into their systems.
Organizations should not only depend on security technologies to help them thwart these attacks rather they should complement them with continuous monitoring of critical endpoints, assets and network components for anamoly and suspicious behaviours. Every touch point in a critical business operation should be able to alert when there is a possible misuse case, and there should be a SWAT team that watches these alerts and makes security sense out of them.
The reason not to rely on key security technologies is only further cemented with a fact that in one of the recent attacks a well-known security product which is famous for allowing whitelisted applications was compromised and the worm successfully included itself in the allowed whitelisted apps of the tool and compromised the systems.
Organizations need to do several things to thwart attacks which are targeted at them,
  1. Classify information based on business criticality and group them together for specific security measures
  2. Have a SWAT team which continuously tests the waters when it comes to current defence technologies
  3. Include endpoints like laptops, smart phones in their security strategy and protect them with the same level of security that is traditionally provided to servers
  4. Continuously train people on why they should be aware of cyber-attack by simulating attacks
  5. Monitor the critical assets for abnormal behaviour rather than just depending on the security technologies that are implemented on them, most of the security controls, tools throw out very important information which is usually ignored; and a centralized monitoring of them only helps to detect attacks much before they cause damage which is usually irreparable in nature.
It’s only in the interest of the CXO’s of the organizations to have a dedicated security strategy team which works with industry leaders in the security services area to draft an effective and predictive strategy to help the organization in these days of onslaught of cyber-attacks. Organization need to work with security companies to have tighter SLA’s and preventive monitoring which should help them detect attacks in seconds and mitigate them in minutes.
As you finish reading this and at this moment somewhere in the world cyber criminals would have successfully penetrated into a company which has a weak security strategy and would have floated its information on Darknet sites either for public consumption or for financial gains.
Never before in the history of computing having a solid information security strategy in this always connected world has been more important.

The Roadmap for intelligent security

Conventional security strategies are being constantly challenged by newer and smarter threats – APTs and AETs to name two. CISOs and CIOs are becoming extremely careful of where they tread, because most defense strategies are being effortlessly infiltrated.
Most high end strategies lack one thing – a single dashboard view. Only an analytics and intelligence driven security strategy can create the correct security solution. A robust Security and Events Management (SIEM) process is a basic step that’s required to achieve a single dashboard view of all the security technologies being deployed. SIEM was once a tool to ensure standards and compliance, but can also be used to generate a centralized dashboard view. This information can be used to co-relate the threat, its prevention and mitigation perspective seamlessly, in the security scenario through the analysis of structured and unstructured data- through logs and network traffic, and through some of the billions of events that occur in an enterprise daily.
However, these logs cannot allow the SIEM to see new threats like APTs. So, a new wave of SIEM products has been developed that allows them to monitor all the traffic and logs to detect specialized and business specific threats, using state of the art intelligence. Thus they can zero in on attacks that are happening or about to happen from data flowing through mails, documents, social media, audio, network traffic, click streams, accessed files, registry changes…anywhere. It makes security sense out of all this data, in terms of a possible event or offence, using ‘adaptive intelligence’. That means, it has the ability to understand network behavior over a certain period of time, and can detect any aberration almost immediately. This new age SIEM has drastically increased the ability to pre-empt threats.
But it is important that even this state of the art SIEM tool is updated with related technologies, to stay abreast of the iterative processes. For example, self-learning algorithms are increasingly available to enable complete automation of rule writing, but human intervention is required to identify business critical offences. A good MSS partner could be the answer here.
In addition, global security information feeds usually work at complementing the baseline information for SIEMs, keeping them current and updated at some level. These feeds could be a warning for dangerous IPs or latest information on threats detected globally.
A robust Security operations centre is the best investment to make all of this easy or any enterprise, instead of piecemeal solutions that may or may not talk to each other.
The function of the SIEM becomes even more crucial once the enterprise migrates to the cloud. This would give an even more holistic view of the security stand and vulnerability across the company. The cloud provider needs to station an SIEM collector on premise, to collate all the logs and events which can then be forwarded to the SIEM at the company’s premises. However, for this, a good amount of negotiation skills are necessary, since any delay in this intelligence could be fatal.
The only caveat with SIEM is that it needs to generate actionable intelligence through data analysis to detect threats, across the organisation. If fine tuned to the company’s needs and security status, and focused on a business risk, the insights provided by SIEM could be the value everybody needs for their security strategy. And once turned into quick decisions by SLA managers’ teams, they can be a priceless support.

Can you really trust your peripherals?

Global threat scenario is evolving too fast, with attackers finding different ways to pilferage and exfilterate data out of your network, security teams have to be proactively alert and defend their information. While traditional security has been largely addressing an organization’s perimeter, critical applications and servers which host critical information, hackers/cyber criminals have found the importance of targeting end points in a company largely because they are in the “trusted” zone. Perpetrators very well know that it is far easy to map an organizations network/its information and gain access to sensitive data if they masquerade themselves as trusted users.
Peripherals which you would trust to connect to your PC’s/Laptops have been recent targets of encoded firmware malware’s which exploit the basic design of how they are programmed to interact via your seemingly innocent USB ports.
Security researchers recently demonstrated that it possible to reprogram the firmware on USB peripherals, be it USB drives, USB Mice, or any device that has programmable chip. The reprogram process by attackers can leave good amount of malicious code on to the chip of USB device allowing the same to effectively hide from antivirus and malware scans and obey the instructions that exploit your data.
Imagine a scenario of social engineering where one of your employees is given a firmware infected USB drive which in turn plugged into that user’s official laptop and what can follow as a result is only limited to one’s imagination, now let’s quickly examine and see what is possible when something like this happens at your organization.

USB malware’s that can act as keyboards:

Recently demonstrated malware a.k.a BadUSB was successfully able to emulate a keyboard on users’ desktop and issue commands that were preprogrammed into the code. The level of access peripherals have being part of the operating system, malware can do variety of things by issuing commands to exfilterate data to loading a Trojan which will act as a backdoor to establishing a connection to a remote server, possibilities are only limited to the abilities of the attacker. Another interesting facet is attackers have found a way infect other peripherals which are connected onto the same system expanding their attack surface.

USB drives as network cards:

USB malware’s can create a spoofed network card which in turn will redirect most of your traffic via custom DNS server which would then point to attackers doing man in the middle attacks.

The ease of having operating systems on a USB:

A modified thumb drive or an operating system image (usually in .iso format) can be already injected with boot sector viruses which can control how the user uses the OS, and allowing an attacker to remotely take over the machine and compromise sensitive and confidential information. This will be like booting from an Virus OS.
All the above things do sound scary and we need to be be, as Karsten Nohl puts it in a recent blackhat conference there is no way this can be patched, because attackers are exploiting the very way the USB was designed.

What next?

Imagine the power this gives the attackers, they can reprogram almost every USB device which has a onboard firmware that can be reprogrammed, including, mouse, external touchpad, phones etc.
USB drives are everywhere, and this itself makes it so scary because from a CEO, to an engineer in a company at least once in a day connect an USB related device to their computers, and as the availability of this kind of exploit grows, need for a proactive security program in an organization only increases. Cottonmouth, revealed in the leaks of Edward Snowden. The device, which hid in a USB peripheral plug, was advertised in a collection of NSA internal documents as surreptitiously installing malware on a target’s machine to enable backdoor. Though the exact mechanism is not described, it is highly likely that attackers did use USB peripherals which is conceptually close to what is being discussed here.

What is the Solution?

There are workarounds for this problem, while there is no patch/tool/fix which is yet available to detect these kind of malwares, until USB peripheral companies come up with code signing on their firmware and antivirus companies are able to scan a firmware code, it is best to follow the below steps to stay secure.
  • Enable USB drives in organization system only where necessary and create awareness among users not to trust unknown devices
  • Conduct a full-fledged audit of your systems to see if you are already compromised with this kind or other security threats
  • Continuously monitor your systems including endpoints for any suspicious activities and stop perpetrators before the information leaves your company

Governance in the digital world

Governance is critical to ensure security in the more vulnerable digital world.
With our world fast becoming more virtual and less real, security is as much a scare there, maybe even more than in the real one.
Internet penetration and usage of on-line applications for day to day lives is increasing and becoming vital for any economy. The increasing number of devices connected to the Internet, make our daily transactions easier, but create newer vulnerabilities. Every passing day brings bigger and more destructive data breaches, impacting lives of common people, and damaging the reputation of enterprises.
Recently, an extremely notorious botnet was brought down by the concerted efforts of security research companies and law enforcement across various countries, but this is only a one-off case in an ocean of threats in the digital universe. We need much more strength to fight, and the reason we still can’t, is due to the lack of a governance process to tackle security issues in a focused manner.
Most states have no clearly defined borders in the digital world to implement their own data protection and cybercrime laws, as in the physical world. It is a fact that any individual can set up a server and send any kind of packet onto the internet space without any regulation, or an identity check. In fact, the digital world makes one virtually (pun intended) nameless and extremely difficult to track, and this only makes it tougher for law enforcement to locate and identify hackers. Lack of an ID and governance protocol is making hacking a huge business opportunity!
It is hence crucial that the digital world has clear governance rules, much like the physical world where we have passport and visa for border control and movement between nations/governing mechanisms. This may not be a fool-proof mechanism, but can bring some control to this chaotic situation. The technologies required for identity management already exist, but need appropriate implementation, especially one that enables them to handle large volumes of data and traffic. This also calls for Citizen Information being available in digital form with the government for identity management.
This step may create an Internet with boundaries, where most of the online traffic would be restricted to within the country and only certain traffic is allowed to go out and come in. Some people may think that this is restrictive but this may be the only way to reduce hacking and other security threats.
Having this clear process and strict governance in place may then be the only way out for countering the constant threats that makes the greatest boon of the twenty first century –connectivity, our biggest threat.