Tampilkan postingan dengan label cyberdefense. Tampilkan semua postingan
Tampilkan postingan dengan label cyberdefense. Tampilkan semua postingan

Rabu, 14 September 2011

How hackers find their targets

experian.com

The rash of large-scale data breaches in the news this year begs many questions, one of which is this: how do hackers select their victims?

The answer: research.

Hackers do their homework; in fact, an actual hack typically takes place only after many hours of first studying the target.

Here’s an inside look at a hacker in action:


  1. Using search queries through such resources as Google and job sites, the hacker creates an initial map of the target’s vulnerabilities. For example, job sites can offer a wealth of information such as hardware and software platform usage, including specific versions and its use within the enterprise.
  2. The hacker fills out the map with a complete intelligence database on your company, perhaps using public sources such as government databases, financial filings and court records. Attackers want to understand such details as how much you spend on security each year, other breaches you’ve suffered, and whether you’re using LDAP or federated authentication systems.
  3. The hacker tries to identify the person in charge of your security efforts. As they research your Chief Security Officer or Chief Intelligence Security Officer (who they report to, conferences attended, talks given, media interviews, etc.) hackers can get a sense of whether this person is a political player or a security architect, and can infer the target’s philosophical stance on security and where they’re spending time and attention within the enterprise.
More...

Kamis, 01 September 2011

Expert says UK government is too preoccupied with launching cyber attacks

computing.co.uk

A security expert has claimed that the UK is devoting most of its cyber crime fighting efforts to cyber attack, leaving limited resources for defence.

Speaking exclusively to Computing, Ross Anderson, professor of security engineering at the Cambridge University computer laboratory, stated that 90 per cent of the government's recent funding injection into cyber security was going to the UK's offensive capability.

"The spooks - GCHQ [Government Communications Headquarters, pictured] - are getting 90 per cent of this new £650m for cyber security [they are responsible for cyber attacks]. The rest, about £65m, is going to the police."

Anderson blamed the imbalance on the fact that the UK's cyber defence capabilities are organisationally placed within GCHQ, the body responsible for electronic espionage, or cyber attack.

"Like the US, the UK has unfortunately got the government's offensive and defensive arms linked together.

"CESG [Communications-Electronic Security Group], which is supposedly defending the core functions of government against for example cyber espionage by the Chinese, is a small subsidiary of GCHQ whose job is exploiting those sources abroad.

"This mixed mission is very bad policy, because it means defensive interests are always less important than an offensive approach."

Rabu, 24 Agustus 2011

Global information security execs urge - "Assume You Are Compromised"

zawya.com



Dubai, August 24, 2011 -- RSA, The Security Division of EMC (NYSE:EMC), released a new report that takes an in-depth look at the seismic shift in the cyber threat landscape, as enterprises are increasingly targeted for corporate espionage and sabotage. The report, the latest in a series from the Security for Business Innovation Council (SBIC), asserts that for most organizations, it's a matter of when, not if, they will be targeted by advanced threats. In an environment where the focus shifts from the impossible task of preventing intrusion to the crucial task of preventing damage, the report includes instructive guidance from 16 global security leaders for confronting this new class of threat.



More...

Selasa, 16 Agustus 2011

Cyber-Espionage Against U.S. Firms More Widespread than Previously Thought

nationaldefensemagazine.org



That foreign adversaries are using computer network vulnerabilities to steal military data from the U.S. government and its contractors is well known and hardly surprising.



Nations for centuries have long sought to steal such secrets from one another and spy-craft has simply moved into cyberspace.



However, the unveiling of a massive cyber-espionage network in August goes well beyond the unwritten rules that informally govern nations when it comes to the theft of technical data or insights into the minds of leaders and their intentions, said Dmitri Alperovitch, vice president of threat research at network security firm, McAfee.



Alperovitch analyzed one command-and-control server that had been used to spread malware for five years before McAfee exposed it.



“Even we were surprised by the enormous diversity of the victim organizations and were taken aback by the audacity of the perpetrators,” he wrote in a blog.



Examining the logs to determine who the victims were, and how long the intrusion lasted before it was detected, Alperovitch found 30 different industries on the list.



More...

Kamis, 09 Juni 2011

Attacks on Sony, others show it's open hacking season

cnet.com
There seems to be a groundswell of hacking activity recently. From the Epsilon breach that touched dozens of major U.S. companies and their millions of customers, and RSA replacing its customers' SecurID tokens after attacks on several defense contractors to Sony sites getting pummeled by hackers on a regular basis--all within the last few months. What's going on?

"I truly don't think there's a higher instance of hacking right now. I think there's been a wave of media coverage," said Bruce Schneier, chief security technology officer of BT and one of the most respected security experts around. "We saw the same thing with shark attacks. It's not that there are more shark attacks. It's that they made the news when people started looking for them." No one can really say if there are more attacks happening. Reports indicate that the number of breaches is rising every year, as can be expected. But those statistics are based only on incidents that are reported; there are untold numbers that happen all the time that no one knows about except the attacker and, eventually, the victim.

Rabu, 01 Juni 2011

Cyber attack shows constant threat to key intel

cbsnews.com
(CBS/AP)

The attempted hacking of defense contractor Lockheed Martin once again shined the spotlight on the security of the high-tech infrastructure guarding the United States' most closely held secrets.

The threat of attacks by enemies of the United States on the country's cyber security is one that has been known about for years, officials and experts in the field of national security have said.

(Last year, a former chief of U.S. intelligence told "60 Minutes" that the United States was unprepared for cyber attacks.)

Cyber war: Sabotaging the system
Video: Full "60 Minutes" segment
Video: Hacking the D.O.D.

Joel Brenner, who held the title of national counterintelligence executive from 2006 to 2009, told the Reuters news agency Tuesday that not just Lockheed Martin but most large defense contractors, if not all of them, have had their networks breached.

"This has been happening since the late '90s," he told Reuters before referring to China, Iran and Russia, three countries he said are the American government's main suspects of cyber espionage. "They're after our weapons systems and R&D."

That research and development is of interest to the more than 100 intelligence groups the Defense Department says have tried to crack American cyber security, Reuters reported.

More...

Selasa, 24 Mei 2011

Cyber-Hackers: Faster, Better Equipped Than You...

registeredrep.com

Mark Clancy is intimately familiar with the in’s and out’s of cyber hacking attacks. As managing director and Corporate Information Security Officer at the Depository Trust and Clearing Corporation (DTCC), Clancy’s job is to pay attention to how crooks use virtual highways to steal data and assets — and stay a step ahead. Today that means much more than loading up some anti-virus software and patching an operating system.

“Mass attacks still continue, but the more sophisticated ones are targeted attacks,” says Clancy. “This style uses social engineering where they collect information they can find on the Internet about a broker or a client, and then send an email so the conversation seems more plausible. And in the broker/dealer world, bad guys are going after more high-net-worth clients. You go where the money is.”

Cyber attacks are not just the territory of large Wall Street firms—independents too have chinks in their armor. And while an 8-man advisory may not have seemed like the prime target for a hack a few years ago, that’s no longer true as criminals have gotten more specific about who they target, in an effort to maximize their return on investment.

More...

Kamis, 05 Mei 2011

‘Osama Bin Laden’ Trojan Horse Spying on Online Banking Sessions

inaudit.com
May 05, 2011 /

Online or offline, the specter of Osama bin Laden hounds internet users no end as cyber criminals and scammers are resorting to different tactics to lure willing victims to bite on their trap, including a new Trojan horse that purports to contain death images of the notorious al-Qaeda leader.

Some instances of spreading the bin Laden malware across the cyber space include the use of phony claims in emails with malicious texts presumably leading to the “shocking video” and the classic Nigerian Letter or “419” Fraud that asks for an advance fee in exchange for a percentage of millions of dollars that the sender purports to spirit away from Nigeria.

More...

Kamis, 14 April 2011

Self-wiping hard drives from Toshiba

net-security.org
Toshiba announces a family of self-encrypting hard disk drives (HDDs) engineered to automatically invalidate protected data when connected to an unknown host. The new Toshiba Self-Encrypting Drive (SED) models enable OEMs to configure different data invalidation options that align with various end-user scenarios.

Designed to address the increasing need for IT departments to comply with privacy laws and regulations governing data security, the drives are ideally suited for PC, copier and multi-function printer, and point-of-sale systems used in government, financial, medical, or similar environments with an acute need to protect sensitive information.

More...

Minggu, 10 April 2011

DOJ To Congress: We Shouldn’t Need A Warrant To Snoop Through Gmail


For years, privacy advocacy groups have been trying to make sure digital data has the same kinds of search and seizure protections that physical documents have. In recent times, even some major companies like Microsoft (NSDQ: MSFT) and AT&T (NYSE: T) have joined together in the Digital Due Process coalition, which wants to modernize the nation’s out-of-date wiretapping laws. Those corporations want law enforcement agents to get a warrant issued by a judge before they are able to tap into sources of data stored in the cloud, such as web email. It’s been an uphill fight—to say the least—and today, the Department of Justice took a position that’s going to make their quest even harder.

According to a report from CNET, a DOJ lawyer told a Senate committee that if cops are required to get a search warrant to tap into email stored online, it could have an “adverse impact” on investigations. “Speed is essential,” he said. “If Congress slows down the process, this would have real-life consequences, particularly where human life is involved.”

More...

Rabu, 23 Maret 2011

Attack Code for SCADA Vulnerabilities Released Online

wired

The security of critical infrastructure is in the spotlight again this week after a researcher released attack code that can exploit several vulnerabilities found in systems used at oil-, gas- and water-management facilities, as well as factories, around the world.

The 34 exploits were published by a researcher on a computer security mailing list on Monday and target seven vulnerabilities in SCADA systems made by Siemens, Iconics, 7-Technologies and DATAC.

Computer security experts who examined the code say the vulnerabilities are not highly dangerous on their own, because they would mostly just allow an attacker to crash a system or siphon sensitive data, and are targeted at operator viewing platforms, not the backend systems that directly control critical processes. But experts caution that the vulnerabilities could still allow an attacker to gain a foothold on a system to find additional security holes that could affect core processes.

SCADA, or Supervisory Control and Data Acquisition, systems are used in automated factories and in critical infrastructures. They came under increased scrutiny last year after the Stuxnet worm infected more than 100,000 computers in Iran and elsewhere.

More...

Kamis, 06 Januari 2011

Utah's $1.5 billion cyber-security "Spy" center underway

deseretnews.com

CAMP WILLIAMS — Today's groundbreaking for a $1.5 billion National Security Administration data center is being billed as important in the short term for construction jobs and important in the long term for Utah's reputation as a technology center.

"This will bring 5,000 to 10,000 new jobs during its construction and development phase," Sen. Orrin Hatch, R-Utah, said on Wednesday. "Once completed, it will support 100 to 200 permanent high-paid employees."

Officially named the Utah Data Center, the facility's role in aggregating and verifying dizzying volumes of data for the intelligence community has already earned it the nickname "Spy Center." Its really long moniker is the Community Comprehensive National Cyber-security Initiative Data Center — the first in the nation's intelligence community.

A White House document identifies the Comprehensive National Cyber-security Initiative as addressing "one of the most serious economic and national security challenges we face as a nation, but one that we as a government or as a country are not adequately prepared to counter." The document details a number of technology-related countermeasures to the security threat.

More...

Sabtu, 04 Desember 2010

Cyberespionage At A Crossroads


darkreading.com
Aurora and Stuxnet-type attacks are here to stay, so organizations need a new defense strategy

It has been a milestone week in cyberespionage developments that smacked of a spy movie, with a confession, a killing, and a leaked intelligence cable: Iranian President Mahmoud Ahmadinejad issued a statement that "enemies" of Iran had successfully used software to disrupt centrifuges in Iran's nuclear facility, Iran's top nuclear scientist was assassinated, and a U.S. State Department cable obtained by WikiLeaks suggested the Chinese government had ordered the Aurora attack against Google.

While these events and disclosures fell short of providing actual proof about the success or even who was really behind these high-profile breaches, they punctuated what has been a game-changer of a year for cyberattacks.

More...

Kamis, 30 September 2010

The 7 worst cyberattacks in history (that we know about)

dvice.com
We get a little taste of cyber attacks all the time — look no further than this week's Twitter virus — but what about full-on cyber warfare? Recently the true destructive potential of a cyber attack became frighteningly clear: whole government, banking and military networks overloaded and shut down, vital data and money stolen, and even physical damage if the right components are targeted. The worst part? We usually only find out after the fact.

More...

Kamis, 04 Februari 2010

Google Asks NSA to Help Secure Its Network


wired.com

Google is teaming up with the National Security Agency to investigate the recent hack attack against its network in a bid to prevent another assault, according to The Washington Post.

The internet search giant is working on an agreement with the controversial agency to determine the attacker’s methods and what Google can do to shore up its network.

Sources assured the Post that the deal does not mean the NSA will have access to users’ searches or e-mail communications and accounts. Nor will Google share proprietary data with the agency.

But the move is raising concerns among privacy and civil rights advocates.

The Electronic Privacy Information Center filed a Freedom of Information Act request on Thursday, shortly after the agreement was made public, seeking more information about the arrangement. (.pdf)

Cisco's Backdoor For Hackers

forbes.com

ARLINGTON, Va. -- Activists have long grumbled about the privacy implications of the legal "backdoors" that networking companies like Cisco build into their equipment--functions that let law enforcement quietly track the Internet activities of criminal suspects. Now an IBM researcher has revealed a more serious problem with those backdoors: They don't have particularly strong locks, and consumers are at risk.

In a presentation at the Black Hat security conference Wednesday, IBM ( IBM - news - people ) Internet Security Systems researcher Tom Cross unveiled research on how easily the "lawful intercept" function in Cisco's ( CSCO - news - people ) IOS operating system can be exploited by cybercriminals or cyberspies to pull data out of the routers belonging to an Internet service provider (ISP) and watch innocent victims' online behavior.

More...

Selasa, 26 Januari 2010

Security specialist: USA made Google hack possible

h-online.com
Backdoors in internet services such email, social networks or the telephone network aren't just a counter-terrorism device for government agencies, they also open doors for cyber espionage and spamming attacks. This is the opinion of security expert Bruce Schneier expressed in a guest comment on the website of American TV broadcaster CNN.

Schneier says that, as an example, Chinese hackers reportedly used a backdoor in Google's Gmail service, created at the US government's request, to spy on political opponents. Such systems are almost an invitation to criminals to snoop on private internet communication and gain knowledge of information such as account or credit card details, said Schneier. The security expert lists further examples such as the intercepting of phone calls after the September 11 attacks and the mobile phone surveillance of members of the Greek government in 2004 and 2005.

More...

Companies unprepared for cybercrime

news.cnet.com
Many organizations are focused on stopping random hackers and blocking pornography when they should be concerned with bigger threats from professional cybercriminals, according to a new cybersecurity report.

In a survey conducted last year of 523 IT and security managers, top-level executives, and law enforcement personnel, hackers were rated the biggest threat, followed by insiders and foreign entities--probably because hackers are the "noisiest and easiest to detect," the 2010 CyberSecurity Watch Survey concluded.

However, attackers from nation-states and organized crime syndicates use more sophisticated techniques that can do more economic damage and go undiscovered, said the report, sponsored by Deloitte and conducted in collaboration with CSO Magazine, the U.S. Secret Service, and the CERT Coordination Center at Carnegie Mellon.

More...

Jumat, 22 Januari 2010

Botnets: "The Democratization of Espionage"

csoonline.com

The cyber attacks against Google, Adobe and a raft of other top U.S. corporations late last year were by most accounts sophisticated and targeted attempts to steal proprietary data. But lost in all of the resulting media hoopla over who the remaining victims were and whether Chinese hackers or indeed the Chinese government itself were responsible is the simple, terrifying truth that individual hackers now have access to the same arsenal of cyber weapons once reserved only for nation states.

The weapons at issue are, of course, botnets -- agglomerations of remotely controlled, hacked computers that are used for a variety of criminal purposes, from spam, to high-powered, distributed online attacks against virtual targets. In these attacks, the botnets acted as a sort of "cloud" data collection and storage network.

More...

Kamis, 21 Januari 2010

Foreign Companies Concerned Over Intellectual Property Theft in China


theepochtimes.com
The recent Internet attack on Google has alarmed Western enterprises in China. It has, in addition to China's loose patent rights and increasing pressure on companies to release sensitive information, prompted some high-tech German executives to warn of a possible exodus from the country.

According to a Jan. 15 article in Germany’s Handelsblatt (Commerce paper), Beijing will launch Chinese Compulsory Certification (CCC) regulations in May 2010 that will require companies to submit their IC design blueprints or software source codes in exchange for approval to enter the Chinese market. The potential dangers for misuse of the regulations are very big, the article said.

The EU Chamber of Commerce in China has publicly criticized China several times regarding the espionage problem, and one position paper mentioned that the standard demanded by the CCC’s could result in sensitive, detailed information not directly relevant to certification finding its way into the hands of corrupt Chinese.

More...
Related Posts Plugin for WordPress, Blogger...