Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, December 23, 2013

DDoS attacks during the holiday season: Don't be a victim

Read about the importance of determining the ROI of implementing DDoS mitigation controls. Also, find out why small online retailers are left the most exposed to DDoS attacks. 



ddosattack1.jpg
 As we approach the holiday season, there is no shortage of tech articles about distributed denial of service (DDoS) attacks and how they're such a huge Q4 problem that necessitates awareness and, of course, a comprehensive DDoS mitigation strategy. From all of the buzz, one might actually believe that DDoS is not a problem outside of e-commerce or the holiday season. Even the security professionals who know better often find themselves making last-minute contingency plans despite the knowledge that proper planning months in advance would have reduced the cost of the mitigation solution and substantially mitigated any damages during an attack. DDoS mitigation is not substantially different than commercial travel; this is the season when security firms begin ratcheting up their prices and launching holiday season awareness campaigns.

Don't miss: IT Security in the Snowden Era (ZDNet Special Feature)
It is important to avoid tunnel vision and remember that everyone from the average consumer to large enterprises can be a victim of DDoS attacks, and the risk remains substantial year-round. The scope of the threat will vary from individuals to organizations between industries and seasons. Any organizations that generate revenue online and their customers can be victims of DDoS attacks. For the organizations, the cost of advance continuity planning cuts into earnings. Those that fail to plan find themselves taking costly emergency DDoS mitigation services and suffering damage to their reputations and customer confidence levels. Irrespective of the category in which an organization falls in terms of DDoS attack planning, every single customer becomes a victim, since the expense of information security becomes a pass-through cost. This is the digital equivalent of shoplifters increasing costs at brick-and-mortar establishments.  
Major e-commerce brands are year-round targets. It is hard to imagine Wal-Mart or Best Buy not having comprehensive defenses in-house. Certainly, nearly every online retailer has planned for these attacks. One might recall that the first major attacks in 2000 were against e-commerce and included Amazon, Buy.com, and eBay. Unfortunately, it has been consumers and investors that foot the bill for this added security. 

The ROI of implementing DDoS mitigation controls

In major companies, decision makers weigh the case for investment in information security by evaluating the expected loss from information security incidents, such as DDoS attacks, and determining the return on investment (ROI) of implementing controls, such as DDoS mitigation. For illustrative purposes, we will use Amazon as an example.
Amazon reported $21 billion in sales for Q4 2012, which breaks down to $9.7 million per hour. At a gross margin of 24.75 percent, the profit per hour was roughly $2.4 million. Assume that without DDoS mitigation in place that Amazon would have lost one hour of sales to attacks and that the cost of DDoS mitigation would have been $1 million, mitigating exposure to five minutes of downtime for a loss of $120,000 with controls in place. This gives Amazon the choice of accepting the risk at a cost of $2.4 million or mitigating the risk at a cost of $1.12 million.In this example, Amazon can demonstrate a ROI of 46.67 percent, which will lead to the company deciding to mitigate the risk and purchase the DDoS mitigation system.

Why the smaller retailer is much worse off

Imagine the same scenario with a company having Q4 sales of $200,000 resulting in a gross margin of $49,500. It is cost-prohibitive and impractical for small companies to use in-house DDoS mitigation systems, so the company will look to a service-based solution. An emergency DDoS mitigation service with a 12-month term may have a total contract of $120,000, placing the small retailer immediately into negative ROI. This means that the company is forced to accept the risk of DDoS attacks. If an attacker learns that the company has no DDoS mitigation whatsoever, the result could be near permanent downtime, quickly leading to lost sales, loss of consumer confidence, and eventually bankruptcy. 
Essentially, everyone shares some of the pain when it comes to DDoS attacks, but it is the smaller online retailers that are left the most exposed. Small firms generally cannot afford enterprise-grade solutions and often lack the organic information security capabilities. An emergency DDoS mitigation service is a quick solution but at a substantial cost, easily reaching into the thousands of dollars per month.

Consider your company's size when shopping for mitigation solutions

A decade ago the Internet was viewed as an emerging technology that could allow anyone to bootstrap a company and sell online. Today, it has manifested into a complex, insecure environment that continues to favor well-capitalized corporations.
This problem is best quantified using the aforementioned ROI model. Where major retailers can easily find ROI in costly security solutions, smaller retailers are left facing more difficult decisions as to whether to mitigate or accept the risk of attack. In practice many small companies choose the latter, as it is the option that offers the greatest upside, but at the risk of exposing the company to devastation if targeted by an attacker.
Fortunately, there are practical solutions available for smaller companies. These require advanced planning and an understanding that DDoS protection and information security are fundamental concepts that must be incorporated into a company's business plan year-round.
All companies should work with a security firm or consultant with experience in mitigating DDoS attacks to determine those solutions that make the most sense for the size of the business being protected, thereby facilitating the most attractive ROI.
Jeffrey A. Lyon, CISSP, is the founder of Black Lotus Communications, a secure hosting firm specializing in DDoS attack mitigation.

Friday, December 6, 2013

AutoCAD malware: Rare but malignant

There's no better way for thieves to steal design secrets than straight from the engineers and designers who create them. CAD software programs are ripe for exploit.

AutoCad malware 1.jpg
With all the recent industrial espionage, it was only a matter of time before malware developers would take a look at Computer-Aided Design (CAD) programs as a way to exfiltrate proprietary documents and drawings from engineering firms. I can’t think of a better way to steal design secrets than right from the engineer or designer working on them. 
 
CAD has been around since the early 1980s, so there are many packages to choose from. Which software did the digital bad guys go after? The most popular of course—AutoCAD. 

I have several clients in the manufacturing sector, and they all use AutoCAD. Working with these clients, I learned a few things about AutoCAD. For one, it is expensive. So when a company has AutoCAD in place, they tend to stay with the version they bought.

What this does is pave the way for malware coders; they have a sizable population of computers running noncurrent, and more than likely, vulnerable versions of AutoCAD. 

The malware coders have something else in their favor; engineering can involve multiple departments and outside consultants—a perfect way for malware to propagate if certain precautions are not in place. And, I’m finding that precautions are not in place. That’s because most IT pros consider CAD-based malware a non-issue.

ACAD/Medre.A

I tended to agree. The first time I read about an AutoCAD malware was last year when ESET.com reported a strange anomaly on their LiveGrid network. It was strange because the malware attacked AutoCAD, but only in Peru of all places. 

After some investigation, it was determined the malware ACAD/Medre.A was a worm programmed to send AutoCAD drawings via email to an account (you guessed it) in China. The experts at ESET had this to say:
ACAD/Medre.A is a serious example of suspected industrial espionage. Every new design created by a victim is sent automatically to the authors of this malware. Needless to say this can cost the legitimate owner of the intellectual property a lot of money as the cybercriminals could have designs before they even go into production by the original designer.
Something else that ESET pointed out bothered one of my clients when I told them about ACAD/Medre.A: “The attacker may even go so far as to get patents on the product before the inventor has registered it at the patent office. The inventor may not know of the security breach until his patent claim is denied due to prior art.”
This particular client was applying for several patents at the time and under my advisement took several additional precautions. Yet, everyone’s concern (even the client) eventually faded, as CAD-related malware never amounted to anything. That is until a few weeks ago.

ACM_SHENZ.A

That’s when a new trojan popped up on Trend Micro’s radar—ACM_SHENZ.A, and it was targeting AutoCAD programs. But with a twist, the malware was benign. Like most trojans, its job was to gain a foothold on the victim’s computer. 

Once safely entrenched, ACM_SHENZ.A obtains administrative rights which make it simple for the malware to create network shares for all drives. The malware also opens ports: 137, 138, 139, and 445. Doing so allows access to files, printers, and serial ports. 


Obtaining administrative rights also allows the attacker to plant additional malware. It’s this additional malware, experts at Trend Micro suspect will be used to steal drawings and engineering documents. What makes this malware especially deadly is that more than likely users will not consider a file with the .FAS extension unusual and just ignore it. According to Trend Micro, “It appears to be a legitimate AutoCAD component with a .FAS extension, but on analysis it actually opens up systems to exploits, specifically those targeting old vulnerabilities.”

Trend Micro engineers mirrored ESET experts’ sentiment that “being rare” is an advantage afforded AutoCAD malware: “Historically, AutoCAD malware is very rare, although not completely unheard of.”

Final thoughts

AutoCAD malware is still scarce, and it may seem like I’m making a big deal out of nothing. But, it is a big deal to companies that pump time and money into a design, only to have it stolen and patented by someone else. 

I asked the experts what we should be expecting and what additional protection manufacturing companies can put in place. The responses were, “It’s early, we are not sure what the secondary malware payload is.” Their suggestion was to exercise additional security with sensitive drawings. 

More than anything, engineering departments need to be aware that CAD drawings are now a valid attack vector.

Thursday, December 5, 2013

Secure your Apache server from DDoS, Slowloris, and DNS Injection attacks

Find out which three modules to install on your Apache server to lock it down and prevent DDoS, Slowloris, and DNS Injection attacks.

security-access-300-225.jpg
Apache is the most widely used web server on the planet, and it's also one of the most widely attacked. To that end, it's always smart to lock down your Apache server as best as possible. This goes well beyond just locking down your network -- you need to give that Apache server as much attention as it might get from outside sources.
 
I'll walk you through the process of preventing your Apache server from Distributed Denial of Service (DDoS), Slowloris, and DNS Injection attacks. These breakins are quite simple to prevent, as long as you take the time to lock down that server.

I'm assuming that your Apache server is up and running and (for simplicity's sake) that it's running on the Ubuntu platform -- for any other platform, you'll need to make minor adjustments. All of this work will be done from within a console window, so prepare to get "the flavor of console" all over your fingertips. 
Don't miss: IT Security in the Snowden Era, a ZDNet Special Feature 

DDoS

There is an Apache module that was created to prevent a DDoS attack, although it's probably not installed by default. Follow these steps to install the module.
1. Open your terminal window.
2. Issue the command sudo apt-get -y install libapache2-mod-evasive.
3. Issue the command sudo mkdir -p /var/log/apache2/evasive.
4. Issue the command sudo chown -R www-data:root /var/log/apache2/evasive.
5. Open the /ete/apache2/mods-available/mod-evasive.load file (using sudo and your favorite text editor) and append the following to the bottom of that file (this is one configuration per line):
DOSHashTableSize 2048
DOSPageCount 20  # maximum number of requests for the same page
DOSSiteCount 300  # total number of requests for any object by the same client IP on the same listener
DOSPageInterval 1.0 # interval for the page count threshold
DOSSiteInterval 1.0  # interval for the site count threshold
DOSBlockingPeriod 10.0 # time that a client IP will be blocked for
DOSLogDir “/var/log/apache2/evasive”
DOSEmailNotify admin@domain.com
6. Save the file and restart Apache.
You should now be better protected from DDoS attacks.

Slowloris

Slowloris is software written by Robert Hansen that allows one machine to take down another machine's web server using minimal bandwidth. Apache has a module to help prevent such attacks. Here's how to get it working for you.
1. Open a terminal window.
2. Issue the command sudo apt-get -y install libapache2-mod-qos.
After the installation is complete, check the configuration in /etc/apache2/mods-available/qos.conf to make sure it perfectly fits your needs. After you tweak the module (if necessary), restart Apache and enjoy a Slowloris-free web server.

DNS Injection

Spam from web forms is not only prevalent, it's a fast-track method of getting your domain blacklisted by the likes of Spamhaus. To prevent DNS Injection attacks, which are attacks that can inject fake DNS names into your server's cache, you need to add another module to Apache. Follow these steps.
1. Open a terminal window.
2. Issue the command sudo apt-get -y install libapache2-mod-spamhaus.
3. After the installation completes, issue the command sudo touch /etc/spamhaus.wl.
4. With the module installed, open the /etc/apache2/apache2.conf file (using sudo and your favorite text editor) and append the following to the bottom of your configuration file:

  MS_METHODS POST,PUT,OPTIONS,CONNECT 
  MS_WhiteList /etc/spamhaus.wl 
  MS_CacheSize 256 

5. Save the apache2.conf file and restart Apache so the new module will take effect.

Summary

Your Apache web server is now better protected from three popular attacks, each of which could take down your server or network. But even with these modules working for you, it's always best to keep a close on your Apache log files (which you should find in /var/log/apache2/).
With a diligent eye to preventing attacks and a proactive stance on watching the logs, Apache should serve you well for a very long time.

10 tips for spotting a phishing email

Phishing emails insinuate themselves into inboxes year-round, but the holidays bring out a rash of new scams. Help your users spot "fishy" emails.

6_secure_email_iStock.jpg
 Every day countless phishing emails are sent to unsuspecting victims all over the world. While some of these messages are so outlandish that they are obvious frauds, others can be a bit more convincing. So how do you tell the difference between a phishing message and a legitimate message? Unfortunately, there is no one single technique that works in every situation, but there are a number of different things that you can look for. This article lists ten.

1. The message contains a mismatched URL

One of the first things that I recommend checking in a suspicious email message is the integrity of any embedded URLs. Often times the URL in a phishing message will appear to be perfectly valid. However, if you hover your mouse over top of the URL, you will see the actual hyperlinked address (at least that’s how it works in Outlook). If the hyperlinked address is different from the address that is displayed. then the message is probably fraudulent or malicious.

2. URLs contain a misleading domain name

Often times people that launch phishing scams depend on their victims not knowing how the DNS naming structure for domains works. It is the last part of a domain name that is the most telling. For example, the domain name info.brienposey.com would be a child domain of brienposey.com because brienposey.com appears at the end of the full domain name (on the right hand side). Conversely, brienposey.com.maliciousdomai.com would clearly not have originated from brienposey.com because the reference to brienposey.com is on the left side of the domain name, not the right.
I have seen this trick used countless times by phishing artists as a way of trying to convince victims that a message came from a company like Microsoft or Apple. The phishing artist simply creates a child domain bearing the name Microsoft, Apple, or whatever. The resulting domain name looks something like this: Microsoft.maliciousdomainname.com.

3. The message contains poor spelling and grammar

Whenever a large company sends out a message on behalf of the company as a whole, the message is usually reviewed for spelling, grammar, legality, and a number of other things. As such, if a message is filled with poor grammar or spelling mistakes it probably didn’t come from a major corporation’s legal department.
To give you a rather amusing example, I received an email message a few weeks ago that was supposedly from one of the large real estate companies. However, the body of the email merely said, “Me buy house fast”. Obviously, that email was not legit.
I’ll concede that this particular message was more of a spam than a phishing message, but the same basic principle applies to phishing emails as well.

4. The message asks for personal information

No matter how official an email message might look, it is always a bad sign if the message asks for personal information. Your bank doesn’t need you to send them your account number. They already know what it is. Similarly, a reputable company should never send an email asking for your password, credit card number, or the answer to a security question.

5. The offer seems too good to be true

There is an old saying that if something seems too good to be true, it probably is. That saying holds especially true for email messages. If you receive a message from someone unknown to you who is making big promises, then the message is probably a scam. After all, why would a Nigerian prince that you have never heard of contact you to help him smuggle money out of his country?

6. You didn’t initiate the action

Just yesterday I received an email message informing me that I had won the lottery!!!! The only problem is that I never bought a lottery ticket. If you get a message informing you that you have won a contest that you did not enter then you can bet that the message is a scam.

7. You are asked to send money to cover expenses

One telltale sign of a phishing E-mail is that you will eventually be asked for money. You might not get hit up for cash in the initial message, but sooner or later a phishing artist will likely ask for money to cover expenses, taxes, fees, or something like that. If that happens, then you can bet that it’s a scam.

8. The message makes unrealistic threats

Although most of the phishing scams seem to try to trick people into giving up cash or sensitive information by promising the victim instant riches, other phishing artists try to use intimidation to scare the victim into giving up information. If a message makes unrealistic threats then the message is probably a scam. Let me give you an example.
About ten years ago, I received a very official looking letter that was allegedly from US Bank. Everything in the letter seemed completely legit except for one thing. The letter said that my account had been compromised and that if I did not submit a form (which asked for my account number) along with two forms of picture ID then my account would be canceled and my assets seized.
I’m not a lawyer, but I’m pretty sure that it’s illegal for a bank to close your account and seize your assets simply because you didn’t respond to an email message.
The amusing part however, was that the only account that I had with US Bank was a car lease. There were no deposits to seize because I did not have a checking or savings account with the bank.

9. The message appears to be from a government agency

Phishing artists who want to use intimidation don’t always pose as a bank. Sometimes phishing artists will send messages claiming to have come from a law enforcement agency, the IRS, the FBI, or just about anything else that could scare the average law abiding citizen.
I can’t tell you how government agencies work outside of the United States. In America however, government agencies do not normally use email as the initial point of contact. That isn’t to say that law enforcement and other government agencies do not use email – they do. However, law enforcement agencies follow certain protocols. They do not engage in email-based extortion (at least that hasn’t been my experience).

10. Something just doesn’t look right

In Las Vegas casino security teams are taught to look for anything that JDLR (as they call it). The idea is that if something just doesn’t look right, then there is probably a good reason why. This same principle almost always applies to email messages. If you receive a message that seems suspicious then it is usually in your best interest to avoid acting on the message.

Tuesday, December 3, 2013

SANS Technology Institute now accredited

Coinciding with a big demand for security professionals. the SANS Technology Institute has been accredited by The Middle States Commission of Higher Education.
The SANS Technology Institute announced today that it is now accredited by The Middle States Commission of Higher Education (3624 Market Street, Philadelphia, PA 19104 – 267.284.5000) an institutional accrediting agency recognized by the U.S. Secretary of Education and the Council for Higher Education Accreditation.
The SANS Technology Institute was established in 2005 as an independent subsidiary of the SANS Institute to offer Master of Science degree programs in Information Security Engineering and Information Security Management.
The SANS Technology Institute offers the key qualities students seek in a cybersecurity master's program:
  • Cutting-edge technical courses that establish and specialize their skills;
  • Teaching faculty with a reputation for industry leadership;
  • Simulation and group projects that teach students to write, present and persuade effectively;
  • Flexibility to attend courses when and where they are most convenient, either live in classrooms or online
In 2014, the SANS Technology Institute will admit 100 students to its graduate cybersecurity programs.  Learn more about SANS Technology Institute’s programs and admissions requirements at http://www.sans.edu/info/144857.

Continuous security monitoring: Wave of the future

The new wave of continuous security monitoring solutions bring together views of security-related data that are often in different silos throughout the organization.

skull-crossbones-security-091013.jpg
Unlike the NSA, most IT security teams struggle to establish and maintain ongoing awareness of the state of information security in their company. Many security professionals, when asked the “are we secure” question by executives, are unable to articulate the answer in a manner that resonates with management (gurgling noises often accompany the response). Why can’t we answer this question? The chief reason is the lack of continuous monitoring and real-time visibility into the overall security picture that plagues many organizations. 
 
NIST defines an information security continuous monitoring (ISCM) program as the ability to “collect information in accordance with pre-established metrics, utilizing information readily available through implemented security controls.” There is a great need to collect and analyze security data continuously in order to effectively manage information risk. Given the dynamic nature of modern threats, security teams are operating at a strategic disadvantage if they are unable to gauge their security posture in real-time.  Setting the course for an organization’s ISCM strategy is needed to enable data driven control of the security information that is floating in different silos throughout the organization’s security architecture. 

So, we can all get behind the theoretical aspect of continuous monitoring, but how do we realistically implement it without losing our minds in the process? Security offerings that specialize in continuous monitoring are entering the marketplace with increasing frequency. Companies such as Conventus (Symantec global partner) are at the forefront of this burgeoning field in the security realm.

Evaluating continuous monitoring solutions

Dennis Norris, VP of Product with Conventus, said that the creation of their SOLVE (Simple On-Line Visualization Engine) product, can be attributed to their clients wanting to be better able to answer the “are we secure” question. According to Norris, the monitoring and reporting on traditional security, security operations, and risk/compliance tend to be done in isolation, reducing their value. This isn’t a mature market space yet, but there are some guidelines you should bear in mind when evaluating potential continuous monitoring solutions:  
  1. Provide unified “single pane of glass” view that gleans information from all security and network tools. This provides consolidated reporting on security data from products you already have running on the network.
  2. The information summarized on the pane of glass needs to be multi-dimensional. Norris explained that SOLVE gathers data based on security configurations, if security products are operating as intended, and event processing (the “here’s what’s happening” outlook. SIEMs tend to only show this dimension).
  3. Remember ISCM is meant to supplement, not replace your security infrastructure. Norris refers to it as the “chief integrator”.
  4. Pricing – currently ISCM tends to be adopted by larger enterprises. That being said, more mid-size companies are seeing the value. Well priced offerings should be represent a small fraction (under 5%) of your overall security investment. 
Have you looked into continuous monitoring or SIEM solutions? Beyond expense, what are the biggest barriers to implementation?

Thursday, November 21, 2013

Encryption for the paranoid: Verifying TrueCrypt source code and binaries

TrueCrypt is open source and verifiable, but until someone actually does the verification, recent events have taught us to be skeptical.

TrueCrypt is easily the most popular and highly-regarded encryption program there is. TrueCrypt is capable of encrypting complete drives, partitions, folders, or individual files. Somewhat ironically, TrueCrypt is also well known for its ability to hide data in plain sight.
TrueCrypt Verify 1.png
Along those lines, it is interesting to note that all of the TrueCrypt developers have remained anonymous, with all communications going through the TrueCrypt Foundation. I did find a 2005 interview, supposedly with one of the developers, code-named Ennead. 

Recommended by experts

Cryptography experts' willingness to recommend TrueCrypt is in part due to TrueCrypt software being open source, meaning it’s reviewable. This is something that’s happening all the time according to the TrueCrypt FAQ web page

"In fact, the source code is constantly being reviewed by many independent researchers and users. We know this because many bugs and several security issues have been discovered by independent researchers while reviewing the source code."

But most people do not download the source code, and then compile it. They install TrueCrypt using one of the executable files. And that’s when the validity of the software becomes questionable. The FAQ web page mentions one way to verify that the downloaded files are compiled from the advertised source code:

"In addition to reviewing the source code, independent researchers can compile the source code and compare the resulting executable files with the official ones. They may find some differences (for example, time stamps or embedded digital signatures) but they can analyze the differences and verify that they do not form malicious code."
Unfortunately, I’m unable to find any documented evidence of this having been done. After downloading the source code, I can see why. It was almost two MB of data. Reverse engineering a program that complex cannot be simple. 

Up until recently, this has not been an overly-pressing issue with encryption experts. But that changed when Mr. Snowden released information about the NSA Bullrun program:

"Documents show that the NSA has been waging a war against encryption using a battery of methods that include working with industry to weaken encryption standards, making design changes to cryptographic software, and pushing international encryption standards it knows it can break."

Bruce Schneier, in this blog, affirms the New York Times claim: 

“Defending against these attacks is difficult. We know from subliminal channel and kleptography research that it's pretty much impossible to guarantee that a complex piece of software isn't leaking secret information. We know from Ken Thompson's famous talk on ‘trusting trust’ that you can never be totally sure if there's a security flaw in your software.”

Cryptographers, a nervous bunch to begin with, finally had enough. Matthew Green, cryptographer and research professor at Johns Hopkins University, and Kenneth White, Principal Scientist at Social & Scientific Systems decided to audit the executable files derived from the current version (7.1a) of TrueCrypt source code, and complete the following:
  • Create a verified independent version control history of the TrueCrypt source and executable code.
  • Document the building of executable files from the source code for the various advertised operating systems.
  • Conduct an audit (security and cryptanalysis) of the programs.
On their website istruecryptauditedyet.com, the gentlemen mention, "Many of our concerns with TrueCrypt could go away if we knew the binaries (executable files) were compiled from source." They also want to eliminate any concern that TrueCrypt has been compromised, most notably with a backdoor.

"The real dream of this project is to see the entire code base receive a professional audit from one of the few security evaluation companies who are qualified to review crypto software."

As you can well imagine, this kind of undertaking is not cheap. Green and White came up with a novel idea: use crowd sourcing to finance the project. It seems to be working, having raised 50,000 dollars since October 14. Donations are still being accepted at FundFill and IndieGoGo.

Final thoughts

I’ve read that Green and White have reached their financial goal, so TrueCrypt should get its day in court. The entire story behind TrueCrypt has been a source of fascination for me, and I hope TrueCrypt passes muster. If I were a betting man…

Saturday, November 16, 2013

Build core tenets to guide your security team

A mission statement that demonstrates how the IT security team will support the business focuses on priorities and establishes a base for consistent decision-making.

Business meeting
Security teams face off against the bad guys every day, and every day there is a new threat, a new opening that has to be guarded. The rest of the company looks to you and your team to keep users and data safe, but they don't necessarily feel they have a part in the process. This can be a stressful situation if you are always in reaction-mode. The poor state of many security programs can be attributed to a lack of vision and guiding principles. I suggest that you create an IT security mission statement for your team that outlines how it will support your company`s mission in accordance with core tenets and principles. This ensures that when you make security decisions you are doing so in a consistent manner that your business colleagues come to expect. Below are the major areas that it needs to address. 
 
SUSTAINABILITY - Develop processes, procedures, and policies required for the prolonged protection of confidential information. These are your foundational building blocks so refrain from making knee-jerk reactions based off one-time events. Focus on the long term rather than the splashy short term gains as this will ensure that the security processes and policies are effective and efficient in delivering sustainable information security that supports business drivers.
Example: Consult with business units when writing security policies (get their input on the company Acceptable Use policy) 

RISK MANAGEMENT - Proactively identify risks to the security of information and systems. Mitigate these risks to levels acceptable to the organization. Develop a consistent process to weigh the information security risks against business rewards of different initiatives. Establish information risk consultancy approach by partnering with business counterparts in managing information risks and coordinating consistent and more holistic enterprise risk management. 

Examples: Risk management frameworks, protocols for third-party risk assessments, mapping controls to business processes, regularly report on status of risks

PARTNERSHIP - Consult with business partners to investigate security issues and evaluate products and processes. Effective information security requires the integration of people, process, and technology. Each of the components should be managed considering the capabilities and limitations of the others. When the security decisions are reached collectively between security and business partners, the decisions are that much stronger. By embracing the partnership approach you demonstrate greater business value and consequently and security is that much likelier to be involved as you are now seen as a trusted ally. 

Example: Data classification, implement controls to agreed upon security standards and meeting security SLAs (service level agreements), ensure business processes meet security control requirements

VISION - Collaborate with all business (not just IT) stakeholders to develop a truly business-oriented information security strategy. Build a truly transformative information security program that embraces new approaches and security paradigms to defending against advanced threats by integrating information security into business and technology strategies.

Example: Collaborate with other factions of IT and other business units (such as marketing, finance) and develop long-term plans to address future trends and proactive strategies. 

RESILIENCY - Be able to respond to and recover from disruptive and destructive information security events by developing and implementing response plans. Assume breaches will occur and increase your resiliency by reducing the focus on purely defensive measures. RSA estimates that most organizations spend approximately 80% of their security budgets on preventative measures, with monitoring and remediation splitting the remaining 20%. Given the security realities of today by it would be prudent to increase your detection and response capabilities.

Example: Provide forensics and malware analysis capabilities; incident response plans that address legal, PR, HR aspects of response (not just technical)

CULTURE - Increase organizational awareness of information security through training and constant communication. Creating a risk aware culture that makes security the responsibility of the many and not of the few. Remember the maxim: culture trumps strategy and principles (tenets) beat rules. 

Examples: Internal awareness campaigns, build strong network of security champions, regularly meet with senior executives to discuss information risks

Friday, November 15, 2013

Infographic: What happens after a data breach?

High profile data breaches that expose customer information are in the news. This graphic shows how the thieves sell the info and make their money.

This infographic from ThreatMetrix illustrates the typical chain of events that occur after a successful data breach plunders customer account information. Once the theft occurs, there's little to be done except the mopping up. ThreatMetrix is a provider of business security and fraud prevention solutions, relying on:
  • Comprehensive data collection across web, client and mobile devices
  • Sophisticated real-time risk scoring, with built-in security expertise
  • Real-time insight from the ThreatMetrix Global Trust Intelligence Network containing the collective knowledge of billions of past transactions, across thousands of businesses
Cybercrime-Infographic.jpg





Wednesday, November 13, 2013

Security's weakest link: Technology no match for social engineering

A security researcher says there is a 100-percent success rate any time pen-testing uses social engineering to target victims. Here are some of the techniques used.

beyond-virtualization-advantages-of-automation.jpg
Many of us in the security industry feel that the last couple of months have been a very busy time, centered primarily around the technological means that the NSA, along with other government agencies, are using to break security, get into our private networks, and read our data. We've also covered how criminals and other bad guys can harness that same technology to accomplish basically the same thing, but with a much more mundane goal  typically to make money on the back of our own users. However, it's important to remember that most break-ins historically, and many still to this day, have nothing to do with technology. In fact they are carried out by people who rely primarily on the human factor, not devious code or malware creation. This is what the Social Engineer Capture the Flag contest is all about, and now the report about the latest version, which was held at DEF CON 21, has just been released.

The contest itself is organized by Social-Engineer Inc, a team sponsored by many security groups, and which hosts this event at the security conference every year. This year, 198 people and groups of social hackers entered the contest, and the selection team picked 10 men and 10 women to test their skills against real Fortune 500 companies, including popular brands like Apple, Boeing, Exxon, Walt Disney, and more, to see if they could get in by using social engineering. The goal of these events is to raise awareness of the threat of social engineering against our security, a threat that many organizations have a hard time understanding. Providing a budget for a new firewall or IDS is something that can easily be quantified, but putting hard numbers on social threats is much harder.

Social engineering techniques

The goal of the people entering the contest is to gain access to flags, or specific pieces of information, inside of these particular companies. The 20 contestants were randomly assigned companies, with one male and one female social engineer per target. The EFF provided a legal advisory for how far the contest could be pushed. Each contestant had two weeks to gain intelligence on their target company, and could only use Open Source Information (OSI) through popular sources like Google, Facebook, Twitter, LinkedIn, etc. During DEF CON 21 at Las Vegas, the contestants then had a short period to do live calls to the target company.

Various techniques could be used including Caller ID Spoofing, and a panel of judges decided the scoring. Points were given to contestants who could gain a variety of information, like whether IT is being sourced in-house or elsewhere, whether the company uses wireless networks, what browser and other software programs are being used, trying to get one of their employees to go to a target URL, and so on. Some of the results were expected, and others gave an insight as to what social engineers would use to gain what they are after. Here is a table of sites used by the contestants during the information gathering phase according to the report:
socengchart.png
 
Pretexting is another common tactic that was heavily used, where contestants would impersonate a corporate employee to gain additional information. In 65% of cases, the pretext employed was an employee, in 10% of cases a student, 10% a survey, 10% a vendor, and 5% a job seeker. While both male and women contestants scored fairly closely during the information gathering phase, the report shows that women had a much easier time gaining the advantage during live calls.

Operation "Facebook hottie"

To further illustrate the validity of these findings, a research team at RSA Europe just presented their own doozy of a penetration-testing experiment that successfully socially-engineered an unnamed US government agency into handing over the "crown jewels" of its network. ZDNet's Violet Blue describes the path the researchers took: by using fake social media accounts and emails from an attractive young woman posing as a new employee, members of the agency were fooled into all sorts of lapses, including:
  • Opening a malicious holiday card link that helped the pen-testers to "gain administrative rights, obtain passwords, install applications and [steal] documents with sensitive information - some of which, according to the hackers, included information about state-sponsored attacks and country leaders"
  • Bypassing the usual controls for issuing a company laptop and access to the network
Researcher Aamir Lakhani had the chilling quote to sum it all up: "Every time we include social engineering in our penetration tests we have a hundred percent success rate."

The weakest link

In the end, what these experiments demonstrate is that social engineering is still a major threat today. Even in the controlled environment of pen-testing agreements, the DEF CON contestants and RSA research team members managed to gain access to most of the information that they needed. This includes the huge amount of private information that can be gathered from simple web queries. The winner of the DEF CON contest was not even a professional social engineer and scored most of her points through extensive information gathering.

The report goes on to talk about some of the steps organizations can take to mitigate this problem. First, information handling is critical. Too often, private information ends up on publicly available servers, even social networks. Consistent, real world education is an important mitigation factor, and so is regular penetration testing.
Would your users and employees be duped by these exploits? Is there a balance to be found between instilling the right amount of paranoia into users and not having daily routines grind to a halt?

Five ways CIOs can improve IT security

IT security is a difficult issue, especially with the topic gaining unprecedented exposure in the press as of late. Here are five pragmatic and quick steps you can take to increase security in your organization.

IT security is a difficult issue, especially with the topic gaining unprecedented exposure in the press as of late. Not only do you have to worry about nefarious governments and freelance hackers, but now must add government agencies like the NSA and even organized crime to the list of security concerns. Budget discussions are no longer simple matters of dollars and cents, but questions about the very security of your company’s proprietary, financial, and customer information. So what are some pragmatic and quick steps you can take to increase security? Here are some ideas:

1.  Determine the risk

There are dozens of risks that could disable or destroy your business, from market conflagrations, to terrorism, to natural disaster. Rarely do executives wring their hands and obsess over the “what ifs”; rather, they assess the risk of the disaster, plan mitigations, and purchase appropriate protections. IT security should be regarded with the same approach, recognizing the stakes, investigating mitigations, and employing external expertise and tools where appropriate.

2.  Provide a voice of reason

With much of the discussion about security bordering on hysterics, the CIO can present a voice of reason. It may be tempting to stoke fears about security in order to capture a larger budget, but bringing calm, reasoned information to the discussion, grounded in your technical and organizational expertise, will build IT’s credibility in the long run.

3.  Identify and highlight the human factor

Based on recent front-page news headlines, it might be tempting to think that government agents cracking your encryption should be a top concern; however, the simple human factor is likely the largest risk your company is facing. Every IT organization tries, generally in vain, to highlight the risks the human factor presents to security, but rather than sending yet another stern warning, run a test that highlights the risks posed by simple “social engineering.” Several companies have sent emails of unknown providence, asking users to click a link that then explains the risks presented by phishing attacks in a far more compelling manner.

4.  Simplify security

Like many business problems, security is one where technical and human factors need to be considered. Early responses to security focused on the technical, creating complex and onerous password requirements that resulted in post-it notes plastered to end user PCs with lists of complex passwords. Rather than employing increasingly esoteric complexity requirements, consider using technologies that don’t rely solely on complexity, like two-factor and biometric authentication. Even simply consolidating and eliminating access to unnecessary systems can reduce the complexity of your security environment.

5.  Plan and execute

Your security plan will never be perfect, and will never cover every potential eventuality. Rather than waiting to develop the absolutely perfect plan, iteratively improve your security and regularly exercise your countermeasures and response plan. An imperfect plan backed by flexible and well-tested processes is better than an extra six months spent planning.
For many CIOs, modern IT security is more of a challenge than many of us ever imagined. However, bringing a calm and reasoned approach to the discussion, combined with disciplined planning and execution, and outside expertise as necessary, will help CIOs guide their companies through these current security challenges.

Tuesday, November 12, 2013

How web-browser automation helps purveyors of malware

Once again, convenience is at odds with security. Learn how web browsers making life easy for users also helps the bad guys. 


Web browsers have matured into capable software tools. Getting to this point required significant effort by dedicated developers, who continue to enhance their code in order to provide an ever more gratifying user experience.
Prefetch1.png
These enhancements come at a price—increased complexity. Like today's automobiles, web browsers are extremely complicated, so complex that like cars, it’s almost a waste of time to look under the hood when something’s not operating correctly.
Sadly, there’s additional fallout from the inherent complexity; it’s easier for nefarious types to find cracks in the code or manipulate existing code to further their own agenda. 

Fortunately, there are developers willing to think like bad guys, figure out possible attack scenarios, and tell us about them. One such developer is Kyle Adams of Juniper Networks. In his blog post, What is Your Browser Doing Behind Your Back, Kyle takes a look at several automated "behind the scenes" browser processes that attackers could leverage to steal sensitive user information such as bank account numbers. Let’s start by looking at DNS Prefetching.

DNS prefetching

Take a second, and count the number of links on this article’s web page. Click one. It loads fast doesn’t it? That's because web browsers use DNS prefetching to resolve DNS information for every link on the rendered web page, just in case the user clicks on one of the links. 

Kyle explains how an attacker could leverage DNS prefetching: "If an attacker puts a hidden link on a page that points to their domain, and sets up his DNS server, he can be notified when you view the page and get your IP address—even if you never click the link. This is bad in the case of emails and forums."

The key piece of information is “even if you never click the link.” What if a nefarious type managed to get a link placed on a high-traffic website? And that link pointed to a malicious website devised to download malware automatically? If the computer is vulnerable, it’s a done deal. Unfortunately, this happens all the time, particularly when websites use third-party advertising. Next on Kyle’s list was page prefetching.

Page prefetching

I became aware of page prefetching when I wrote this article about Google Instant. Google Instant guesses what you are typing into Search. Then, Instant displays (along with prefetching the associated DNS information) what it thinks you are looking for, usually before you finish typing. Great idea. The bad guys think so as well, now that they have figured out how to game the system.

In my article, I used the search entry of Antivir Solution Pro as an example. At that time, Antivir Solution Pro was the name given to some nasty malware. Notice in the slide below what Google Instant guessed after I typed in just "anti," Sure enough, Antivir Solution Pro was Instant’s first choice.
Prefetch2.png
Many people thought they were going to a website offering an official antivirus product like Antivir or Antivirus Solution, but ended up getting a computer full of malware. Kyle then moved on to session cookies.

Session cookies

Web browsing without session cookies would be a major pain. Session cookies allow a web browser to remember the user’s information when moving from one web page to another on the same website. There is a problem though. Kyle explains, “Some browsers, most notably Chrome, do not delete session cookies when you clear the cookies. This means even if you clear your cookies, sites can keep tracking you until you close your browser.”
I’m trying to determine which web browsers retain session cookies, and which do not. It seems there are varying opinions. Retaining session cookies is not normally an issue, but it is important to understand if session cookies are persistent, another user could resume an earlier session and access potentially sensitive web pages—something you may not want to happen. And, finally Kyle looks at plug-ins.

Plug-ins

Plug-ins are software that allow users to customize an application, adding significant versatility to web browsers. I’d be lost without my ad blocking plug-in. Kyle states his concern: “Each plug-in operates with an immense amount of privileges. They can look at everything the user does, mess with content on their system, and make requests without the user knowing.”
Kyle offered this example:
Plug-ins commonly shipped with antivirus applications are designed to warn you when you visit a malicious page. However, in order for the AV vendor to know you’re visiting a malicious page, they need to know every page you do visit. This means that as you browse the Internet, the entire sum of your Internet activity is being silently shipped to a third party.
Kyle went on to mention that he would consider most AV vendors trustworthy, but Kyle also noted that some plug-ins do not encrypt the data, so the data is fair game in transit to the AV vendor’s servers.

Final thoughts

I’m afraid the “cat is out of the bag” on the four web browser processes Kyle talked about. I intend to keep using them. But knowing what Kyle has uncovered allows us to be careful in how we use them.

Saturday, November 9, 2013

Review: ESET Smart Security 7

If you are looking for an all-in-one security package that gives Microsoft's basic protection a run for its money, you might want to consider ESET's Smart Security 7.
eset_logo.jpg
Despite Microsoft's recent moves to bake in a rather competent Defender anti-virus and anti-malware solution right into Windows 8, third-party security software vendors believe that they have nothing to fear quite yet, since they can tout more comprehensive scans and heuristic analysis. One of these products called ESET NOD32 is one of my personal favorites amongst commercial antivirus software, particularly due to its efficient use of system resources. In October 2013, ESET released a new version of their full featured security suite, Smart Security 7.

Product Information

  • Title: Smart Security 7
  • Company: ESET
  • Supported OS: Windows XP, Vista, 7, and 8.x

Smart Security 7

From first installation to first startup, the entire setup experience is fast and easy, with no annoying nags for toolbar installations to be seen anywhere (which is something you would hope to expect from paid software anyway). The main interface itself is by far one of the most straightforward and simple, with all the options available within a quick mouse click or two, and not having to rummage through a plethora of pop up dialog boxes.
ESET_1.png
On my first scan, I elected to choose the Quick Scan mode first to see how long it would take on my Windows 8.1 test machine. Within about four minutes, it covered all the memory space and essential operating system files that were loaded at the time with no incident. Shortly thereafter, Smart Security offered to perform a more detailed custom scan, which you can run at your leisure. If such a scan is likely to take a while, Smart Security includes options to either shut down or reboot the host machine. If you are working on something at the time a shut down or reboot is about to be initiated, you are given a 30 second grace period to save your work or cancel the operation as deemed necessary.
ESET_2.png
ESET engineering hard at work

Real-time protection

As far as the background real-time protection goes, I noticed hardly any performance penalty when running all of my regular software programs. ESET has done a great job leveraging aggressive resource management, ensuring that any incognito scans don't impede on whatever the user is working on at the time. Smart Security offers a feature called HIPS or Host-based Intrusion Prevention System, which serves as something of a guardian angel, watching to see if any rogue processes surface during day-to-day operation and puts a stop before any malicious deed is taken. In certain resource-starved systems, HIPS can potentially add some drag to performance, and it can be easily disabled via the Settings area if need be.

If your system is in use by children, or you wish to prevent employees from looking up smut at work, the parental control area allows you to set up basic web and email filtering in order to prevent unsuitable content from being viewed by others. Although I applaud ESET for thinking of the children, I find local, software-based web filtering to be woefully inadequate and easy to override if account security isn't locked down tightly. A better alternative would be to use a network-wide filtering service like OpenDNS, which is administered from the router and not on a local PC.
ESET_3.png
Traverse the wrong path online, and you shall encounter this.
Finally, in what seems to be a newcomer to the ESET toolkit, is the inclusion of a free anti-theft option, which can be activated after Smart Security is installed and run for the first time. It touts the ability to utilize your PC's webcam and GPS hardware, in an effort to photograph and track the thief. Although the gesture by ESET is much appreciated, most software-based anti-theft can be worked around, simply by booting off other media and wiping the main hard drive. Therefore, ESET Anti-Theft is likely to help when dealing with less tech-savvy criminals.

Bottom line

So is ESET Smart Security 7 worth buying at a price of $59.99? The extras bundled on top of the base anti-virus package, like the web filter, social media scanner and anti-theft are nice to have, but the real appeal is the base NOD32 product. Since the aforementioned extras can be replaced by free or cheaper alternatives, like LoJack for anti-theft and OpenDNS for web filtering, which work just as well, if not better than what Smart Security can provide, ESET's NOD32 seems to be a better value proposition at $39.99 a license, with volume discounts available for multi-PC installations. The engine is robust, yet the software will stay out of your way while you work for the most part.