Showing posts with label Cyber Ethics. Show all posts
Showing posts with label Cyber Ethics. Show all posts

Tuesday, July 6, 2010

Top Cybersecurity Threat Is Customers

Despite the best efforts of high-tech companies to deploy security defenses across public and private networks, end users often remain the weakest link

Cybersecurity is a complicated affair. In addition to the numerous and highly sophisticated technical tools in place to fend of malware and cyberattacks, so much of an organization's defense capabilities comes down to the habits of its employees, according to a panel of security experts recently convened in New York.

With data breaches making near-daily headlines and Congress in the midst of a lively debate on a major cybersecurity overhaul, the panel was timely. But what of the other factors that confound enterprise security, such as the precarious relationship between corporations and white-hat hackers?

When it comes to cybersecurity, the largest single threat to corporate and government networks is, according to some experts, customers' own risky behavior. It was certainly the assessment of a handful of Internet security and software luminaries gathered in New York City at a cybersecurity roundtable earlier this week. With new breaches in the news, and cybersecurity bills on the verge of enaction, the panel convened at a timely moment.

Yet for all the vast amount of technological resources available to those on the panel -- which included representatives from payment processor ADP, software players, including Microsoft, and security vendors, including industry leaders McAfee and Symantec -- the security issue, in many cases, still remains a people problem.

Read the full story at eSecurity Planet: Top Cybersecurity Threat Is Customers, Experts Say

Tuesday, April 13, 2010

Chinese government involvement in Cyber-attacks?

Researchers Trace Data Theft to Intruders in China

Over the past eight months a team of U.S. and Canadian researchers have spied on a gang of intruders that stole sensitive information from the Indian Defense Ministry and traced them to China. A report from the researchers indicates that the ring extensively employed Internet services such as Twitter, Yahoo! Mail, and Google Groups to automate the control of computers once they had been commandeered.


The investigators gained access to the control servers used by the gang to monitor the theft of a broad spectrum of material, and traced the attacks to intruders that appeared to be based in Chengdu. Among the stolen material were documents related to the travel of NATO forces in Afghanistan, which demonstrated that many nations can be put at risk of exposure by a single computer security hole.

I quote from the news:
"An important question to be entertained is whether the [People's Republic of China (PRC)] will take action to shut the Shadow Network down," the report says. "Doing so will help to address long-standing concerns that malware ecosystems are actively cultivated, or at the very least tolerated, by governments like the PRC who stand to benefit from their exploits though the black and gray markets for information and data."
Please refer here to read more details.

Friday, April 9, 2010

Staying Anonymous in a Time of Surveillance

Read digital books? Then your e-book provider probably knows which titles you’ve read

From Googling to e-mailing to social networking, every day millions of Internet users unknowingly leave behind digital breadcrumbs while surfing the web, sometimes at the risk of compromising their anonymity. But while there’s technology available to stay anonymous in a time of surveillance, experts say policies and legislation won’t protect us from privacy invasion or being attacked in cyberspace.

As a medium, the Internet has allowed its users an unprecedented level of anonymity. Usernames and avatars hide names and true identities in online forums and communities, and anyone can choose how much to disclose to others in cyberspace. However, while most understand how posting personal information could have severe consequences, very few realize their online activity can be monitored and cross-referenced to reveal clues about their identity.

It’s important to think about every time that you interact with a third party online, they have information about you. You may buy your books online–lots of people buy things online. It’s not just social-networking sites where we volunteer this information; we volunteer it in a lot of ways.


Take the simple task of doing a web search, for example. In 2006, The New York Times reported how
leaked records from AOL revealed how users’ search-engine queries could be linked to their identities. By collecting and analyzing a user’s web searches, AOL’s researchers peeled away the many layers of cyber anonymity, unveiling the identity of user No. 4417749: Thelma Arnold, a 62-year-old widow who lived in Lilburn, Ga.

During a three-month period, Arnold typed into AOL’s search engine sentences such as “60 single men,” “landscapers in Lilburn, Ga” and “tea for good health,” clues that led AOL researchers to her. Commenting on AOL’s practice of storing users’ information, Arnold said to The Times, “We all have a right to privacy … Nobody should have found this all out.”

Search engines are just one of many places that–unknowingly to most–track users’ activity. Traveling through cyberspace, you provide information to others almost every click of the way, including to the ISP that knows your IP address, the browser that tracks which sites you’ve visited, and the cookies that store login or registration identification and user preferences.

How you read and gather information can be very sensitive. People often go on an intellectual journey where they really discover and explore fringes of political thought or other thoughts. It’s not hard to imagine a young person reading up about homosexuality, for example, if they have questions of their sexual orientation. That’s something that’s far from illegal but something they don’t want the world to know.

However, while anonymity allows people to express themselves freely without the fear of retaliation or persecution, there is always a darker side to it: It breeds criminal behavior.

From phishing and spam to botnets and DDoS attacks, global crime rings have been able to form in an environment that fosters concealment. While anonymity in cyberspace is “generally a good thing,” one imminent problem is how criminals are using it in combination with the borderless nature of the Internet to develop international crime rings.

Cyber crime is an international problem and the lack of true authentication leads many to fall victim to scams–419 advance fee frauds, for example. Criminals can freely and openly do business via web forums because they are able to cloak themselves.

As the majority of today’s cyber threats are profit based, criminals don’t want to be caught or have their businesses hampered, either by law enforcement or by competitors, so almost all cyber threats work to be untraceable. Compromised computers act as proxies and/or illicit bulletproof hosting is used to mask true sources. Unless serious investigations are made, at best, most cyber threats can only be traced to a proxy.

The future may bring a realignment of the Internet and its network of networks–untrustworthy networks that provide cloaking for criminals may be disconnected. Businesses that are attacked from anonymous sources may well decide to pull out of those countries that allow for such attacks to [be] carried out. Google is now a prominent example of this.

Thursday, February 18, 2010

Illegal download of movies and music - You can be tracked

Three Arrested As Police Swoop on Rapidshare Link Forum
An Internet forum which provided links to movies and TV shows hosted on sites such as Rapidshare has been raided by police. Following an anti-piracy group investigation, three alleged operators of the 30,000 member site were arrested, two of which were teenagers. Searches were carried out on members in three other locations.

With 30,000 members Filmowisko was a prominent file-sharing forum. The site didn’t host any illicit material, but like many of its type, linked to movies, TV shows, music and other warez stored on hosting sites such as Rapidshare.

“Forum administrators are not responsible for content written by users. The files placed here by users are only for promotional purposes. After 24 hours you must delete all files downloaded from this forum,” said the disclaimer on the front page of the site before it disappeared.

Polish police and the Foundation for the Protection of Audiovisual Creativity (FOTA) anti-piracy group clearly didn’t think the disclaimer counted for much, and on February 12th conducted raids against the site’s operators.

Refer here to read more details.

Tuesday, January 26, 2010

Computer Network Terrorism - Biggest Challenge

Today's Threat: Computer Network Terrorism

The University of Haifa's Yaniv Levyatan says that cyberterrorism is just as much of a threat to today's governments as more conventional forms of terrorism.

"A fleet of fighter planes is not necessary to attack a power station; a keyboard is sufficient," Levyatan says. "And if you don’t have the skills, there are enough mercenary hackers who can do it for you." Among international hackers, there is a growing trend to threaten national infrastructures for ransom, he says.

Recently, most online fighting has focused on attempts to immobilize leading Web sites, but the next step is to target systems controlled by computer networks such as financial systems, power stations, hospitals, television broadcasts, and satellites, Levyatan says.

If someone still thinks that this is science fiction, Dr. Levyatan notes how just recently, in November 2009, Brazil’s electricity was blacked out for more than an hour. “It is still not clear what happened, but one assumption is that it was a cyber -terror attack,” he suggests, adding that in 2007 Estonia’s computer infrastructures were attacked, most likely by Russian hackers, bringing the country to a near standstill for about 48 hours.

The next stage is the attempt to cause damage to systems that are operated by computer networks, such as financial systems, power stations, hospitals, television broadcasts, and satellites. “A fleet of fighter planes is not necessary to attack a power station; a keyboard is sufficient. And if you don’t have the skills, there are enough mercenary hackers who can do it for you,” says Dr. Yaniv Levyatan.

Refer here to read more details.

Sunday, June 7, 2009

Classic Fraud: 6 Scams That Don't Go Away

From Check Fraud to Phishing, All the Old Tricks are Back with a Vengeance

Bank fraud has evolved over the last several years, but some classic variations keep financial institutions busy.

Here are six old fraud tricks that are back with new twists to bedevil fraud departments and information security professionals.

Check Fraud

Last week, New York indicted 18 people in a massive check counterfeiting ring that cashed more than $1 million worth of checks at major New York City banks. This case causes even the best fraud departments in financial institutions to check their own programs and safeguards.
Attempted check fraud at U.S. banks totaled $12.2 billion in 2006, according to the latest biennial survey conducted by the American Bankers Association (ABA). Bank prevention systems caught 92 percent or $11.2 billion of check fraud attempts.

Precautions: Employee training is still one of the most effective security measures against check fraud. Other prevention systems include signature verification, screening of new accounts, "positive pay" systems (a computerized check number matching program between banks and corporate customers), special check stock (water marks, micro-printing and/or holograms) and "touch signature" fingerprint programs for cashing non-customers' checks.

Elderly and Immigrant Identity Fraud

Financial institutions' mortgage and loan officers need to pay attention to this kind of fraud. While not new, elderly and immigrant fraud is regaining popularity, especially in the age of identity theft. This is currently happening in some reverse mortgage situations. Similarly, some immigrants who rent properties are discovering that their identities have been used on fabricated loan transactions.

A simple inquiry about a loan product that leverages investment or rental properties can be enough to obtain information for use on fabricated loan transactions. As foreclosure scams also continue to proliferate, loan officers need to keep track of those homeowners, making sure they don't fall prey to these scavengers.

ATM Fraud/Skimming

This type of fraud made it into President Barack Obama's speech announcing his cybersecurity initiative, when he said "thieves used stolen credit card information to steal millions of dollars from 130 ATM machines in 49 cities around the world -- and they did it in just 30 minutes." The big question is: Can it happen at your institution?

Phishing


Phishing continues to change and grow, and crimeware (or malware) is also growing. There is a notable tendency for phishing to become more technical -- for example, using advanced obfuscation to combat anti-spam techniques. At the same time, crimeware (what used to be called malware) is becoming increasingly more reliant on social engineering. Trojan horses commonly use clever social engineering techniques to improve their success rates. Bad guys have been devastatingly effective at tricking end users into installing malware and divulging personal information, but their methods for monetizing this data have been fairly crude. This is starting to change, however, and brokerage accounts are an area of particular concern.

Vishing

The increased number of "vishing" - or phone-based phishing -- scams hitting regions is cause for alarm. In the last week, there have been five different regions of USA hit by phishers using phone calls to solicit information about the person's credit union or bank account:

•New England Federal Credit Union in Williston, VT reported that a vishing scam hit residents, and the Heritage Family Credit Union in Rutland, VT also reported a similar scam.

•Customers of the Forward Financial Credit Union in Niagara, WI and the River Valley Bank in Iron Mountain, MI received calls last week from fraudsters asking for account information.

•Asheville Savings Bank, Asheville, NC was alerted last week by its customers that a vishing scam targeting area residents was trying to get debit card numbers.

•The final vishing scam of last week targeted all 22,000 residents of Guilford, CT. The calls started coming on May 24. In the Guilford, CT. case, the automated call was a female voice claiming to be from Guilford Savings Bank. It prompted those on the other end of the line to enter bank card and PIN numbers, along with their card's expiration date.

Insider Threat

The threat of a trusted employee or vendor taking sensitive information is not new, but the ways that insiders are getting to the juicy data or dollars is changing. Collusion is the new way insiders are getting sensitive data.

To put it into context, people who stole information with the intent to sell it, more than half of them were recruited to do by parties outside of the organization. When fraud is involved with insiders, half of those involved another insider.


Tuesday, April 14, 2009

Cyber spying a threat, and everyone is in on it

Growing threat of cyber espionage

The computers of Tibetan exiles and the U.S. electrical grid were recently breached by hackers, highlighting the growing threat of cyber espionage. The White House is currently finishing a 60-day review of how the federal government can better use technology to protect electronic information such as the U.S.'s electrical grid, the stock market, tax data, airline flight systems, and even nuclear weapon launch codes.

The U.S. Department of Homeland Security reports that in 2008 there were 5,499 known breaches of U.S. government computers by malicious software, a big jump from the 3,928 known breaches in 2007 and 2,172 in 2006. A former U.S. government official says the hackers who compromised the electrical grid could have left behind computer programs that will allow them to disrupt service.

He also says the sophistication of the attack indicates that it was state-sponsored and the government does not know the extent of the attack because federal officials cannot monitor the entire grid. "We expect that the attacks we've seen are only the tip of the iceberg," say the official, who requested anonymity because he was not authorized to discuss details. "We follow the attacks to their source, and many come from China."


Click here to read the story.

Sunday, May 11, 2008

Cyber Ethical Issues

Hacking & Security Community - Ethical or Unethical?

Last year,
Roger Halbheer, blogged couple of times about WabiSabiLabi. Roger questioned the world in his post that whether it is ethical to sell the exploits openly to the highest bidder?

In my opinion i think it is completely unethical to sell the exploits openly. WabiSabiLabi might be supporting the security researchers in rewarding them for their creative work but are they selling the exploits to the right people? The people who are buying the exploits might not have right motive? They might target the companies who are vulnerable to that exploit (most likely they will be vulnerable) and cause huge financial loss? These were the questions which Roger were looking answers for last year.

On WabiSabiLabi website they have mention:

Wabi-sabi is the perfect term to represent the implicit imperfection of the IT security, as well as the scope of our project, which is to contribute to its improvement. This goal is achieved by completely re-designing the traditional security research cycle, introducing for the first time ever a market-driven approach to correctly value the security researchers contributions.

I really don't understand are they really achieving their goal by completely re-designing the traditional security research cycle, ethnically or unethically?

Recently, i came across of a similar website called:
Astalavista. According to the website:

The ASTALAVISTA hacking & security community is the largest IT security community in the world. It’s a platform for both IT specialists and novices, and anyone interested in expanding and updating their knowledge regarding IT security and hacking.

They are offering paid subscription for the following prices:
  • 6 months - $39.95
  • 24 months - $99.95
  • Lifetime membership - $199.95

Okay, according to them here are the benefits for becoming the member:

  1. The latest tools
  2. Unpublished documentation
  3. The largest security archive on the Internet
  4. Zero-Days Exploits
  5. Live Hacker Reports
  6. E-Books
  7. Tutorials
  8. Source Codes
  9. Tips and Tricks
  10. Hosted Forums
  11. War Games Servers
    ..and still many more..

They claim that their members include IT security specialists and IT representatives at multinational companies like IBM, Microsoft and PWC.

Now i have the similar question which Roger Halbheer asked last year. Is these types of security forums are ethical and beneficial for security community? Is ethical, to pay some hackers and get hold of Zero-Day exploits?

If really representives from companies like Microsoft, IBM and PWC companies are supporting such forums then i personally think that we are not fighting with bad guys infact we are working with them together.