Thursday, April 5, 2018

Cybersecurity News CYBR650 Week 4

Coming into week 4, this class continues to be very interesting. Cybersecurity is definitely not a boring topic! The Microsoft STRIDE threat modeling tool was quite useful in this week’s assignments. This week I decided to take a closer look at some relevant cybersecurity news from various organizations.

McAfee Threat Intelligence: for latest in-depth security threat research reports, insights from security experts, and learning how to protect enterprise from malware, cybercrime, and other cybersecurity threats. The McAfee Labs Threats Report from March 2018 was quite informative, highlighting the switch from threats like ransomware, to newer tools and techniques like PowerShell malware and cryptocurrency mining. The report also stated that new malware has reached an all-time high of 63.4 million new samples, with PowerShell malware growing 267% in the fourth quarter. The report can be viewed here: https://www.mcafee.com/us/resources/reports/rp-quarterly-threats-mar-2018.pdf.

McAfee also had some good information on ransomware; this is a type of malware that uses asymmetric encryption to hold a victim’s information at ransom. In a ransomware attacker, the victim must pay up before the attacker will make the private key available to the victim; it is almost impossible to decrypt the files that are being held for ransom without access to the private key. The reality is that users and organizations can follow simple cyber security advice to avoid becoming a victim of ransomware. Sometimes victims can regain access to their encrypted files or locked systems, without having to pay. This is made possible by McAfee’s creation of a repository of keys and applications that can decrypt data locked by different types of ransomware.

One of my all time favorite cybersecurity report is the annual Verizon Data Breach Investigations Report. This report is an incredibly valuable tool to help any organization prepare themselves from being the next victim of a data breach. The 2017 report was no different. It reminded organizations they don’t have to be huge or well-known to become a target. As an example, the healthcare industry could be hit by both external and internal attackers. Many employees and others have access to valuable patient information that could result in identity theft and cloning of identities. Attackers can also use other organizations as a soft target useful as a stepping stone to their partners’ systems. You can download the 2017 report here: http://www.verizonenterprise.com/resources/reports/rp_DBIR_2017_Report_en_xg.pdf.

CNET Security and Privacy: And it’s time to report yet another data breach. This time it’s Delta, Sears, and Kmart who suffered a data breach, in which customers’ names, addresses and credit card numbers may have been stolen during September 26th and October 12th, 2017. However, this breach was a bit different from the others. None of these companies' internal databases were actually breached. Rather, a piece of malware temporarily residing in their online chat service possibly harvested customers’ payment information after they completed a transaction. While Delta reported that multiple hundreds of thousands of its customers could potentially have had data stolen, Sears believes fewer than 100,000 of its customers were affected by the breach. Read more about this at https://www.cnet.com/news/delta-sears-kmart-data-breach-credit-card-address/.

And finally! Some commonsense ruling: A judge allows Massachusetts to sue Equifax for data breach. I believe this was long overdue. Equifax has been entrusted with our most private and sensitive data and they should have been better prepared to deal with data security attacks. Not only that - it seemed, based on their response, that they were more interested in preserving their reputation and brand, rather than alerting consumers properly and thoroughly. Read about it here: https://www.cnet.com/news/massachusetts-judge-says-state-can-sue-equifax-for-data-breach/.

Here’s another data breach: Hackers steal data from 5 million Saks, Lord & Taylor customers. 

Friday, March 30, 2018

Threats and Vulnerabilities CYBR650 Week 3

These past three weeks have been quite interesting and frankly, almost frightening, as we delve more into threats and vulnerabilities that companies face today. The discussion topics made me conduct further research into the STRIDE threat model, which, to me, is probably the best threat classification model one can use when thinking about threats that exist in the computer security world. The six threat categories of STRIDE are Spoofing identity, Tampering with data, Repudiation, Information disclosure, Denial of service, Elevation of privilege. More information can be obtained from the Microsoft website at https://msdn.microsoft.com/en-us/library/ee823878(v=cs.20).aspx.

During 2017, there were some remarkable vulnerabilities and exploits. One that was very interesting was KRACK (Key Reinstallation Attack). This allowed attackers to exploit vulnerabilities in the Wi-Fi Protected Access 2 (WPA2) protocol to allow an attacker to eavesdrop on the network traffic between the device and Wi-Fi access point. Frankly, I was surprised to find out that there were security flaws in the WPA2 protocol. I was even more surprised to find out that over 41% of Android devices were vulnerable to variants of KRACK, with Linux systems also being heavily impacted. Some best practices to mitigate possible attacks on Wi-Fi networks and devices were recommended, including regularly updating your Wi-Fi router’s credentials, enabling your firewall, using a Virtual Private Network (VPN), and updating firmware often. You can read more on this at https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/vulnerabilities-in-wpa2-reportedly-expose-wi-fi-enabled-devices-to-eavesdropping

Being an avid user of iPhones (I won’t trade my iPhone for the best Android device in the world), I did some research on vulnerabilities and exploits that exist in the Apple world. I didn’t have to look too hard. It seems that every iPhone and Mac computer is affected by the Meltdown and Spectre chip vulnerabilities, which can be exploited by hackers using malicious apps running on a device. This is why it is so important that users download apps and software only from trusted sources. The fact is that smartphones has become a way of life us today. It’s hard to imagine that only two decades ago, people were able to survive with only analog phones! Our smartphones now hold very valuable and sensitive data, like our banking information, credit card information, and lots of other private data. With the millions of Apple devices being used around the world, the risk factor is global, as users throughout the world can be impacted negatively. Read more at http://www.newsweek.com/apple-iphone-chip-vulnerability-most-disturbing-security-issue-decades-771638.

In today’s world of technological convenience and mobility, the threats and vulnerabilities seem to be ever-increasing. Like many people. I handle my bank transactions through my mobile phone. And attackers seem to be aware of the rise in popularity in online banking, often targeting individual users’ bank accounts with an increased number of mobile malware and mobile bank Trojans. It was pretty disturbing to learn that a research by the Kaspersky Lab's Global Research and Analysis team found over 1.6 million malicious mobile installation packages circulating, including 323,000 new malicious mobile programs and 2,500 mobile banker Trojans. Read more about it here http://www.darkreading.com/vulnerabilities---threats/mobile-malware-makes-mobile-banking-treacherous/d/d-id/1322957

One of my favorite security readings is the yearly Verizon Data Breach Investigations Report (DBIR), and I’m not just saying that because I work for Verizon. This annual report explores the existing cybersecurity landscape, and uses the experience of many organizations to provide a detailed overview on the state of cybercrime today. Part of this task is to analyze thousands of incidents, including data breaches. Organizations would do well to use this report to prioritize and discover new ways to protect against threats. The fact is that if a company hasn’t suffered a cybersecurity breach yet, it’s because they are extremely-prepared, or lucky. My bet is the latter!

Tuesday, March 20, 2018

Credible Sources CYBR650 Week 2

These first two weeks in the ‘Current Trends in Cybersecurity’ class has made me think beyond my comfort zone, as I have never been involved in any threat modeling during my 25 year plus career in IT. As I delve more into the class and its reading assignments, and look online for related information, I see a rise in cyber threats, even as corporations and organizations continue to spend millions trying to ensure they implement the best security measures.

Looking back at 2017, there was a rapid onslaught of cyber threats. The SC Magazine published a good article on some of the top cybersecurity threats of 2017 https://www.scmagazine.com/the-top-cybersecurity-threats-for-2017/article/720097/ which included the exploit called KRACK (Key Reinstallation AttaCKs). KRACK empowered attackers to access any Wi-Fi device using WPA2 and remotely read and steal sensitive personal information. What was even more troubling, was the DDoS-for-Hire Services being offered online, publicly! Tech Republic published an article on ‘The top 5 cybersecurity threats of 2017’ https://www.techrepublic.com/article/report-the-top-5-cybersecurity-threats-of-2017/ and listed DDoS-for-Hire Services being offered by attackers as a major threat during 2017.

It is not very difficult to identify sources of information for threats, vulnerabilities, updates, and security news; the important thing is to make sure these sources are credible. Several sources I consider to be credible are:

  • https://www.securityweek.com/. This organization provides an all-encompassing set of security news on malware and threats, cybercrime, risk and compliance, and the list goes on. It is a source that I review every week, just so I can stay on top of the latest data breaches and the latest on cybercrime happening around the world.  There is a very interesting article on “the other side of terrorism” https://www.securityweek.com/online-other-side-terrorism which details how terrorism groups are using the latest technology to wage war beyond our physical and geographical barriers.
  • https://www.ftc.gov/. The purpose of the Federal Trade Commission collaborates with law enforcement partners in the United States and around the world to protect consumers and promote competition. They have a very helpful Tips & Advice section for consumers and businesses, and their News & Events section has the latest information on fighting attackers and cyber threats.
  • https://www.fbi.gov/ is probably my favorite place to look for information on threats, vulnerabilities, updates, and the latest security news. The News section on their homepage gives information on their top stories and latest busts, and it brings some idea of comfort, knowing that the government is actively going after attackers. Currently the FBI investigates computer and network intrusions, ransomware, identity theft, etc.: information that is very relevant to companies and consumers.
  • https://csrc.nist.gov/ Computer Resource Security Center contains great publications on threats and vulnerabilities. Their Security and Privacy section contains papers on cryptography, privacy, and risk management among others. The Laws and Regulations identify many federal laws that are applicable to the Information technology industry. NIST also has an Information Technology Lab with monthly newsletters on its projects and activities I particularly enjoy reading their News and Updates section. Their latest article “NIST Releases Report on Fog Computing for Internet of Things Devices” https://csrc.nist.gov/News/2018/Fog-Computing-for-Internet-of-Things-Devices discusses fog computing as an alternative to cloud computing. This is a new concept for me, and it describes fog computing as providing a significant reduction in the amount of time it takes to access data locally.
Stay tuned for more blogs next week!

Friday, March 16, 2018

Top Security Threats CYBR650 Week 1

My name is Bickram Mark Singh. I am a Systems Engineer Manager; working for Verizon for the past 25 years. Much of my daily functions include trouble-shooting and problem solving; it is a fast-paced, hands-on, non-stop work environment with deadlines to meet and emergencies occurring constantly. My major is Cyber Security, and this is my final Masters class with Bellevue University.

Each week I will post information on some of the top security threats we face, both personally and in the corporation. I will also share recommended ideas and steps to help mitigate some of these threats. In today's rapid pace technological environment, we all can use as much information as possible to stay safe.

The MIT Technology Review website https://www.technologyreview.com/s/609641/six-cyber-threats-to-really-worry-about-in-2018/ gives an interesting take on the top cyber threats to look out for during 2018. The author, Martin Giles describes some worrying scenarios; threats that can cause a magnitude of problems and with some serious, worrying consequences. Two that were particularly worrying to me are:

* Increasing data breaches like the one on Equifax. You'd think that with such top security, a company like Equifax could never be hacked successfully. That data breach showed us all that there is never really anything like 100% security, and that we are as strong as our weakest link. And just when you think you’ve heard it all, the bad news continue to grow. CNN wrote a good article last month describing how more information, including tax IDs and driver's license details were probably obtained in the Equifax data breach http://money.cnn.com/2018/02/09/pf/equifax-hack-senate-disclosure/index.html. As more information on the data breach is made public, you can’t help but wonder if Equifax is withholding any vital information from us, in their quest to reduce the damage done to their brand.

* Hacking elections. Although the debate rages on as to whether or not Russia really hacked the 2016 elections or to what extent their activities influenced our elections, the fact is that cyber attacks on our voting process is a clear and present danger. As much as we try to identify and mitigate vulnerabilities in our voting systems, it seems these hackers are way ahead of the game. NBC News published an interview with Jeanette Manfra, the head of cybersecurity at the Department of Homeland Security, where Jeanette stated that Russian successfully penetrated the voter registration rolls of several U.S. states preceding to the 2016 presidential elections https://www.nbcnews.com/politics/elections/russians-penetrated-u-s-voter-systems-says-top-u-s-n845721. It seems the same technology that has provided mobility, flexibility, and comfort has reared its ugly head to bite us.

Stay tuned!

Thursday, November 6, 2014

FBI Cyber Crime Stories Week 11

We are plagued by cyber threats every day. Just as steps and controls are taken to mitigate one threat, another one appears in its place, often harder to detect, and even harder to combat.
ABC News reports a new form of malware, WireLurker, is monitoring devices connected by a USB cable to an infected computer and is installing malicious applications onto Apple devices, stealing valuable information from these mobile devices.
The Tech News World website, http://www.technewsworld.com/, provides valuable information on the latest cybersecurity threats. In one of the reports, hackers affiliated with the Russian government were able to breach some unclassified computer networks at the White House; users experienced  service disruptions as the FBI, Secret Service and NSA worked to contain the intrusion. No longer are intruders armed with guns where they can be contained before they reach the front doors. In this case, they were able to enter the White House while sitting in their room all the way in Russia. Computer users and organizations must ensure a considerable budget is allocated to counter the ever-rising security threat that comes with fast-evolving technological advances.

http://abcnews.go.com/Technology/wireStory/cybersecurity-firm-ids-apple-targeting-malware-26727467
http://www.technewsworld.com/story/81312.html

Saturday, November 1, 2014

FBI Cyber Crime Stories Week 10

Today I received an email supposedly from Yahoo, asking me to click on a url to upgrade my mail account. Reading the email thoroughly, I discovered a comma where a period was supposed to be, and immediately deleted the email. It was just another scam to allow a hacker access to my system! One must give these hackers some credit .... they are persistent!
The FBI most recent cyber crime story is from a few days ago, "Purchase Order Scam Leaves a Trail of Victims". The attackers are using online and telephone social engineering techniques to trick retailers into fulfilling fake Purchase Orders that are purportedly from legitimate businesses. The products end up in  Nigeria. A new tactic, but using old tricks. Like always, businesses must look for e-mails that contain unusual phrases or spellings, and phone numbers that are hardly ever answered by a live person. Again the emphasis is not on any complicated security measures, but on plain old common sense!

http://www.fbi.gov/news/stories/2014/october/cyber-crime-purchase-order-scam-leaves-a-trail-of-victims/cyber-crime-purchase-order-scam-leaves-a-trail-of-victims

Saturday, October 25, 2014

FBI Cyber Crime Stories Week 9

Today I was notified by Capital One that a new debit card is on the way, since my account could have been one of those compromised by the attack on Home Depot. Now, even Ebola has found its way in cyber threats. Hackers are using people's fear of Ebola to attack computer users by installing malware via an email attachment purportedly sent by the World Health Organization.

Like the threat of Ebola, cyber threats are widespread, can cause panic, and often extremely difficult to contain. The U.S. Department of Homeland Security is now investigating cybersecurity flaws in medical devices and hospital equipment that could be exploited by hackers to overdose a patient with drugs, or manipulate a heart implant....and the list goes on. Just when we think we have a handle on cyber threats, here comes another one that we did not foresee!

http://www.valuewalk.com/2014/10/now-ebola-become-threat-cyber-security/
http://www.foxnews.com/tech/2014/10/22/us-government-probes-medical-devices-for-possible-cyber-flaws/