Showing posts with label Guideliness. Show all posts
Showing posts with label Guideliness. Show all posts

Friday, July 6, 2012

Why Business Continuity is Critical For Your Business?

4 Tips to Gain Upper Management Attention


Companies often make many strategic decisions such as outsourcing, off-shoring and long supply chains without full consideration of the consequence of business interruption.


They primarily focus in adding short-term value to the bottom-line, but when these strategies fail to deliver, reputation and brand image are compromised. Short-term financial losses might be containable, but long-term loss of market share is often much more damaging.


By implementing effective business continuity plans, businesses can increase their recovery capabilities dramatically. And that means they can make the right decisions quickly, cut downtime and minimize financial losses. So, getting buy-in at the top is crucial. It requires professionals to have better understanding of the concerns of top management and an ability to communicate risk issues in a common language.


Here are a few ways business continuity practitioners can seek upper management attention.


Emphasize business consequences: Many leaders were shaken by the corporate impact that the Gulf of Mexico oil spill incident had on the finances, share-price and reputation of British Petroleum.


Business continuity managers need to bring these real-life cases in their presentation to management and further use their skills to identify their own organization's potential high consequence events. 


Implement innovative tests and exercises: A traditional difficulty is that BCM practitioners do not report at a high enough level to affect decisions. Although often true, they are not without influence, and one way to use it is in developing an innovative testing and exercising program.


In the past, too many exercises have concentrated on evacuation, safety and emergency response. Although these are required, top management employs specific specialists to handle safety and security on their behalf. 


What BC practitioners need to do is choose scenarios and techniques in their exercises that really interest the leadership team. Using scenarios that highlight fundamental business threats and challenging top management to respond can be scary, but it also can raise the profile of BCM rapidly.


Techniques such as war games, stress testing, scenario planning and horizon scanning are becoming important to business continuity tests. These are areas in which the BCM professional could and (in the future) really should take a leading role.


Be more assertive: BCM professionals can get top level attention by taking a more assertive position to organizational change. Clearly, there are limits to which individuals can become involved in strategic decisions, but by producing a well considered analysis of the consequences of change, they can often get senior management interest.


Decisions can be reviewed or modified if consequential risks are better articulated. BCM professionals can do this through a risk management organizational framework and can make their voice heard.


Communicate BCM benefits: Practitioners must concentrate on finding value and benefits for BCM and promoting them.


For example, if having proper BCM in place helps the organization get on the approved supplier list for a major customer, it's the BC professional's job to ensure that everyone knows about it. If it were a key deciding factor that actually won a big contract, make sure that sales, marketing and finance recognize and publicize that fact.


If BCM helps procurement eliminate high-risk suppliers, again getting that message out through whatever communication vehicles is key.

Wednesday, July 4, 2012

Facebook Email: What You Need to Know!

Facebook Knocks Your Email off the Podium


Facebook is receiving a decent amount of backlash from its most recent privacy misstep. The social media giant recently forced their @facebook.com email addresses upon all users who had not previously signed up to use it - and did so without their permission.


If you don't want this default email used by your Facebook friends, read this article to learn how to change your email back to the preferred address.


From a privacy standpoint, I'd recommend you not use the @facebook.com email address at all. That is unless you want to give everyone at Facebook (and possibly their third parties) access to your email messages.

Wednesday, April 6, 2011

'Tricked' RSA Worker Opened Backdoor to APT Attack

APT Presents New Attack Doctrine Built to Evade Existing Defenses

A well-crafted e-mail with the subject line "2011 Recruitment Plan" tricked an RSA employee to retrieve from a junk-mail folder and open a message containing a virus that led to a sophisticated attack on the company's information systems, a top technologist at the security vendor says in a blog.

An Excel spreadsheet attached to the e-mail contained a zero-day exploit that led to the installation of a backdoor virus, exploiting an Adobe Flash vulnerability, which Adobe has since patched, writes Uri Rivner, head of new technologies, identity protection and verification at RSA, in a blog posted Friday.

RSA unveiled on March 17 that an attacker targeted its SecurID two-factor authentication product in what it termed an advanced persistent threat breach. An APT refers to sophisticated and clandestine means to gain continual, persistent intelligence on a group such as a nation or corporation. The RSA official says the attacker initially harvested access credentials from the compromised employee and performed privilege escalation on non-administrative users in the targeted systems, and then moved on to gain access to key high value targets, which included process experts and IT and non-IT specific server administrators.

If the attacker thinks they can exist in the environment without being detected, they may continue in a stealth mode for a long while. If they think they run the risk of being detected, however, they move much faster and complete the third, and most 'noisy' stage of the attack. Since RSA detected this attack in progress, it is likely the attacker had to move very quickly to accomplish anything in this phase.

While RSA made it clear that certain information was extracted, it's interesting to note that the attack was detected by its Computer Incident Response Team in progress

Thursday, March 31, 2011

SC Magazine’s recent study of less-shouted-about THREATS

Risks and Rewards of Archiving!

Cloud and social media security are much discussed areas of focus within our profession but what about some of the less shouted-about threats? I thought you might be interested in SC Magazine’s recent study of some of these, which will be discussed in greater detail in 3 of their upcoming webcasts; found at http://www.scwebcasts.tv and http://www.scstudio.tv respectively.

Below is a little more info on the 3 topics to help you assess their relevance to your organisation:

STAMP OUT COSTLY SECURITY DEFECTS IN SOFTWARE DEVELOPMENT
Going live at 2pm GMT, 30th March


The Coverity Scan found an alarming 50,000 defects in just 300 open-source software products. This webcast will give you an instant understanding of the secure coding practices that you should adhere to to eliminate these increasingly costly security vulnerabilities.

Speakers: Robert Seacord, Secure Coding Director, CERT - Software Engineering Institute, Michael White, Technical Director, Coverity

You can secure your free place at: http://www.scwebcasts.tv

ARE RISKY APPLICATIONS UNDERMINING YOUR BUSINESS SECURITY?
Going live at 3pm GMT, 12th April

With 75% of new attacks (CERT) targeting applications and with the lines blurring between personal and business devices, this webcast will shed vital light on the real security repercussions of risky apps in the workplace and what you can do to secure them.

Speakers: Tim Mathias, Director of Security, Thomson Reuters Chris Wysopal, Co-founder & CTO, Veracode

You can secure your free place at: http://www.scwebcasts.tv

THE RISKS AND REWARDS OF ARCHIVING

This webvideo is live now on SC’s site at http://www.scstudio.tv

83% of the 200 IT professionals that SC spoke to (representing both SMEs and larger enterprises) reckoned the cost of email downtime to their business to be over $500,000. This interesting SC Studio show which you can watch right now at http://www.scstudio.tv , offers some interesting pointers on one of the most effective ways to reduce this risk/cost – archiving.

Speakers: Brian Shorten, Risk and Security Manager, Cancer Research UK Giovanni Alberici, Archiving & Continuity Specialist, Symantec.cloud

I hope the shows are relevant to your organisation. As always, do feel free to get in touch with any thoughts on these topics or ideas for future ones.

For the webcasts, if you can’t make the live date of the webcasts you can of course watch them live in the archive at your leisure at http://www.scwebcasts.tv. The studio show you can watch whenever you like at http://www.scstudio.tv .

Sunday, March 27, 2011

9 Ways to Help Safeguard RSA's SecurID

RSA Strongly Urges Customers to Act Immediately

Security vendor RSA is providing remediation steps for customers to strengthen their RSA SecurID implementations in light of an advanced persistent threat attack against the company, which it says was directed at its SecurID two-factor authentication product (see Hackers Target RSA's SecurID Products).

Here are the nine steps RSA recommends customers take:

1. Increase focus on security for social media applications and the use of those applications and websites by anyone with access to their critical networks.

2. Enforce strong password and PIN policies.

3. Follow the rule of least privilege when assigning roles and responsibilities to security administrators.

4. Re-educate employees on the importance of avoiding suspicious emails, and remind them not to provide user names or other credentials to anyone without verifying that person's identity and authority. Employees should not comply with email or phone-based requests for credentials and should report any such attempts.

5. Pay special attention to security around their active directories, making full use of their SIEM (Security Information and Event Management) products and implement two-factor authentication to control access to active directories.

6. Watch closely for changes in user privilege levels and access rights using security monitoring technologies such as SIEM, and consider adding more levels of manual approval for those changes.

7. Harden, closely monitor and limit remote and physical access to infrastructure that is hosting critical security software.

8. Examine help desk practices for information leakage that could help an attacker perform a social engineering attack..

9. Update security products and the operating systems hosting them with the latest patches.

"We strongly urge immediate customer attention to this advisory," the company said.

Friday, March 25, 2011

The CIO 2011 Global State of Information Security Survey tracks the trends and how they affect Australian businesses

My Interview / VIEW on Global state of Information Security by CIO Australia

Australia isn’t often heralded as being at the bleeding edge of technology on the global stage. A former CIO of the United States National Security Agency, however, says the country is leading the way in security.

The focal point for praise from Prescott Winter, now CTO of the public sector division at security vendor, Arcsight, is a voluntary code of practice established by ISP sector representative body, the Internet Industry Association (IIA). The ‘iCode’ recommends a set of best practice methodologies for dealing with botnets, educating customers and addressing deficiencies in network monitoring.

“Australia is going to be very interesting to watch,” he says.

The code isn’t set to go live until December 2010, but IIA’s CEO, Peter Coroneos, has already briefed the US Federal Communications Commission, the Organisation for Economic Cooperation and Development, and even the White House’s cyber security chief, Howard Schmidt, among others on the proposal — in the hope of seeing similar codes adopted globally.

But while some organisations are working towards global collaboration on information security issues, Winter does have a warning for CIOs: Understand your threat landscape, and proactively work to mitigate internal risks.

“They’re just now getting their hands wrapped around this problem,” he says. “But I’m afraid many are still reactive.”

The issue is borne out in the results of the CIO 2011 Global State of Information Security Survey. Conducted in 2010 by PricewaterhouseCoopers, the survey is made up of responses from 12,847 technology and business executives from 130 countries, including 754 answers from Australia.

One of the more alarming findings — there are several — is the number of Australian respondents who reported noticing one or more security-related incidents within their company over the last 12 months. In most cases, software and confidential customer or employee records were altered or compromised, with up to $500,000 in financial losses at stake. Worse, of the known sources of the threat, employees were the culprits in 27.7 per cent of cases, outstripping hackers, former employees and other external deviants.

Denial of service, vulnerable firewalls and compromised security at the hand of consumer technology in the workplace may remain a major concern for the CIO, but it appears the problem may be much closer to home.

It is a sentiment that Shoaib Yousuf agrees with. As an information security strategist and consultant, he has seen the worst of internal security risks. The Stuxnet worm that shook critical infrastructure across the world — including 30,000 computers in Iran — could be sourced to a single USB drive, plugged into the all-too-vulnerable SCADA network. The malware, according to Yousuf, has become a “wake up call” that has highlighted the gaps in endpoint security which could bring down an entire power, water or transportation grid.

“In the hacking and security world we used to use the term ‘weakest link’ all the time, but the threat landscape for critical infrastructure has changed,” he says. “Hackers are no longer targeting the weakest links.”

Winter agrees. Drawing from experience, he points to a nuclear energy producer which found two separate botnets operating within its network; another engineering firm discovered its network was the source of a distribution network for pornography. Internal reflection, he says, is ultimately vital to ensuring threats aren’t passed by without notice.

“There’s a lot of stuff out there that people don’t know, simply because they’re not looking.”
For better or worse, the mounting concerns have pushed security awareness amongst C-level executives through the roof. Despite the economic rollercoaster, 18.8 per cent of Australian respondents are forecasting increases to information security budgets by 10 per cent over the next 12 months, while a further 19.1 per cent will look to increase budgets by up to 30 per cent.

A little under half of all respondents claim security budgets in excess of $US50,000 in 2010. Information security has become much more than small change.

Third party security

Principal for the advisory service division of PricewaterCoopers, Mark Lobel, points to the survey results as a sign that expectations have been ‘reset’ among respondents.

“There’s a real sense of tension in this year’s numbers,” he says. Employee distrust aside, Lobel says much of the tension can be attributed to the increasing reliance companies must place on third parties for their security, “whether they like it or not”. “Those partners need access to your IT infrastructure and your data. That’s tough when times are good and scary when times are bad.”

But according to Andrew Milroy, vice-president of ICT practice at analyst firm, Frost & Sullivan, the trend toward third parties is inevitable.

“Security is just going to be built-in,” he says. “As a discrete issue, I think it will disappear over time because the service provider will offer service levels around privacy and data.”

Migration towards the Cloud, telecommuting and remote access will all accelerate that trend, Milroy says, as companies become accustomed to the notion of their sensitive and often confidential data moving at the speed of light over networks that are not their own, beyond the controls of a corporate firewall.

Vendors and service providers are gearing up for the trend too, boosting in-house security expertise and buying intellectual property outright as a means of integrating security portfolios without having to start from scratch. Intel’s $US11.5 billion McAfee merger, Juniper Networks’ SMobile buy and Verizon Business’ Cybertrust acquisition serve as examples.

Outsourcing the totality of security, however, may require some getting used to and, as Lobel says, perhaps a ‘reset’ of priorities. Australian companies remain ambivalent: Almost half of the survey respondents said increasing reliance on managed security services was either important or the company’s top priority for the coming year, but only 35.6 per cent were looking to reduce the amount of full-time security personnel on-site.

Survey results also indicate Cloud adoption continues to lag at a local level. About 36.4 per cent of Australian respondents said they used Cloud services, behind 52.4 per cent of companies in the rest of the Asian market. Some 47.7 per cent of respondents were apprehensive or lacked confidence in the information security of suppliers and partners, mainly due to a lack of control over others’ security policies. A total 50.6 per cent did not or were not considering any form of security outsourcing or management. Nonetheless, the more companies do outsource information security or the information itself, the greater the focus on service level agreements and ensuring compliance to security standards and strategies.

The latter rings true for Andy Pattinson, formerly from Carnival Australia. As interim IT director of a firm that represents six of the international cruise brands in Australia, including P&O Cruises, he had oversight of all information security, although strategies and priorities are ultimately dictated by global headquarters in the United States.

Unlike the rest of Carnival’s local operations, which are reported to through Carnival UK, security compliance and risk management go direct.

Two employees also oversee security risk and compliance and directly report back to US headquarters, bypassing Pattinson and local management.

As a result, most of Pattinson’s security duties largely revolved around ensuring Sarbanes Oxley (SOX) and Payment Card Industry (PCI) standards compliance, effectively amounting to 5 per cent of the company’s approximate $10 million operational expenditure. Ongoing enterprise risk assessments are carried out by three of his 20-strong IT team, and penetration testing is outsourced, but for a strong local organisation overlooking four major cruise ships there are no pressing security concerns.

“We have a baseline [that is] dictated by the group and we get to that level, then do whatever other work we need to do that might be pertinent,” he says.

The maturity of the systems has it advantages; six months into the interim role, Pattinson hardly had to lift a finger on the security side. “It was a pleasant surprise because it means you’re not firefighting issues, you’re not having to override concerns about the day-to-day operations,” he says. “It lets me focus much more on strategic aspects and actually takes a weight off my shoulders — it doesn’t mean you lose sight of it, but you know the processes are in place to maintain it.”

The CSO role in Australia

Given the importance of security in any organisation, it would seem logical to have an executive with absolute oversight direct report to the CEO or board of directors. Yet the roles of chief security officer (CSO) and its more specific variant, the chief information security officer (CISO), are rare creatures in the Australian business landscape.

Only eight respondents identified themselves as such in the survey and, while a greater proportion make mention of an existing CSO role within the company, the requisite mug shot is notably absent from executive lineups on company websites. Those who do exist are often tied directly to vendors — with a stake in the arena — and according to Milroy, the title is a luxury more than anything.

“It’s like having a chief Cloud officer — how many chief officers do you want on the board? You have to draw a line somewhere,” he says.

“Security really should be on the minds of a CIO or even a CEO across the board. Everybody should be onto it.”

Only 37.9 per cent of Australian survey respondents, however, said their equivalent security manager reported directly to the chief financial officer, chief executive or board of directors; the rest, it seems, are held back by restrictive governance structures.

“I think there’s a need for any security manager to directly report to management,” Yousuf says. “You can give him whatever title you like, but I’d worry more about his reporting functionality. These guys are responsible for approving your budget and strategy. If they don’t know what you’re talking about, the threats and issues, and if you don’t bring them to their attention, you will have a problem achieving your goals.”

The CSO’s role should extend beyond information security to physical fraud and internal corruption reviews within the company, he says. Its existence also provides a direct line of reporting and communication to executives and, therefore, a greater chance to be heard. It has ultimately been beneficial to Yousuf’s attempts to raise security awareness among the engineers and accountants within the organisations he works with.

“I used to struggle. I would send invites to the executives [for meetings], and they would send one person. Now, if I don’t send an invite they’ll actually ask me: ‘You’re not coming to the executive meeting? Are you not providing an update?’”

As a simple means of reporting, the CIO can fulfil much the same role, but the possibility of oversight afforded by a dedicated security executive allows for extension beyond the bits and bytes of information security threats.

Even those steeped in the technical aspects recognise a holistic security strategy must extend beyond the IT department to risk and compliance. For Yousuf, the ideal security environment would comprise four security professionals from IT, auditing, and risk and compliance departments to oversee various aspects of the company’s potential threats and developing mitigation strategies.

Security must be executed by IT, but both Yousuf and Pattinson concede that strategy and governance ultimately shouldn’t be led by it.

Cloud, green IT and governance

Governance and security priorities will likely continue to come at odds when it comes to implementing and sustaining information security, but it is clear the threat landscape remains vast and the number of potential vulnerabilities are no small feat to overcome. As issues on the periphery such as the Cloud, Green IT and governance undergo change, however, effective risk mitigation will follow suit.

For Yousuf, it is a matter of multi-tasking.

“I need to pick up on the small issues in the bigger picture, rather than going to the bigger picture and forgetting the small issues,” he says. “I believe breaches always come from the small issues, not the perimeter.”

In a climate where only 29 per cent of Australian companies appear completely satisfied with existing information security strategies, the area is ripe for improvement.


The 2011 Global State of Information Security Survey is the eighth such survey from CXO Media, publisher of CIO magazine and CSO magazine in the United States. Conducted globally with PricewaterhouseCoopers between 19 February and 30 April 2010, the survey comprised responses from 12,847 technology and business executives from 130 countries in roles ranging from analyst to the chief executive or president of the company. With 754 respondents Australia ranked fifth in the world in terms of response.

Refer here to read the original post on CIO Australia.

Wednesday, March 23, 2011

Information security in 2011

2011 Global State of Information Security Survey

Over the past year, it has been hard to predict when, where and with what strength global economic conditions might improve.

So it isn’t surprising to discover this year, that – according to the results of the 2011 Global State of Information Security Survey® – executives across industries and markets worldwide have been reluctant to release funding supporting the information security function.

This financial restraint is in spite of clear evidence that as information security emerges from the smoke of a brutal year – and, in effect a “trial by fire”, as last year’s survey revealed – it is sporting a new hard-won respect, not just from many but from most of this year’s respondents.

This includes more than 12,000 CEOs, CFOs, CIOs, CISOs, CSOs and other executives responsible for their organisation’s IT and security investments in more than 130 countries.

Key Highlights:
  • Asked about their expectations about security spending in the coming year, respondents are more optimistic than at any time since before 2005.
  • This year’s spending drivers aren’t new. But here’s the surprise: almost every one of these factors are trending at, or near, four-year lows.
  • For the second year in a row, increasing the focus on data protection is the single most common strategy worldwide.
  • This year, there is a significant shift in the ongoing evolution of the CISO’s reporting channel away from the CIO in favor of the company’s senior business decision-makers.

Sunday, March 20, 2011

Sharing some Information Security Resources

Latest Information Security whitepapers

Web 2.0 Security Summit (Webcasts, March 16, 2011 or afterward on demand)

Hear from OWASP, SonicWALL, Accenture, Websense, Aberdeen Group, Fortinet and other security visionaries as they look into the new paradigm of web 2.0 security threats, the issues of privacy, and practical tips on how to prevent large scale data leaks from happening to you.

Register: http://bit.ly/fElMev

Social Networking and Security Risks (White Paper)

The popularity of social networking sites has reached astonishing levels. How protected is your company against risks from these platforms?

Download: http://bit.ly/gmPIDv

The Big Shift to Cloud-based Security (White Paper)

Keeping IT systems secure and running within regulatory compliance mandates seems next to impossible. There are many reasons for this — but fortunately, several recent technological trends show that it doesn't have to be this way.

Download: http://bit.ly/hrUzHV

How to Protect Your Organization against Advanced Persistent Threats (White Paper)

This paper outlines the evolution of APTs, explains the motivation behind them, and determines best practices for defending against these threats.

Download: http://bit.ly/e1HHrv

Security for Google Apps Messaging and Collaboration Products (White Paper)

Read this whitepaper to get a comprehensive look at the security controls, processes and technologies that we have implemented in Google Apps.

Download: http://bit.ly/g6NS4h

Friday, March 18, 2011

AM & Fraud: Risk that put burdens on Banks

AML & Fraud: The Global Challenge

Just when you think you've filled all the gaps by investing in all the right technology, crafty criminals will come up with an unexpected way to commit fraud. Increased cross-border transaction volume means more opportunity not just for money laundering, but also for ACH fraud, card fraud and identity theft, and that means greater need for real-time transaction monitoring.

As global transactions increase, and political unrest in Northern Africa continues, U.S. regulators will more closely scrutinize compliance with the USA Patriot Act and the Bank Secrecy Act, to name two regulations.

In other parts of the world, such as Europe, where privacy mandates often conflict with U.S. policy, regulators are just as intent on ensuring standards and sanctions are adhered to by banks and businesses operating within their borders.

From an AML perspective, most international banks are complying well with existing regulatory mandates. But enhanced monitoring, going forward, will be a must.

Regulators are looking for more efficient monitoring, and now banks are going to be expected to have more streamlined fraud-detection tools. Centralizing data is the only cost-effective way to streamline.

Centralizing your data is so important, for fraud detection, as well as knowing your customer. After all, knowing your customer leads to better service and fewer fines in the long run
Compliance is always looked at as a cost center. But when you know your customers and how they behave, not only can you meet the requirements of regulatory compliance, but you also can more effectively target your customers and shape your products around what they need, rather than around what you assume they want.

Monday, March 14, 2011

2010 Annual Study: U.S. Cost of a Data Breach

Data breach costs rise with criminal attacks

Criminals are driving up the cost of data breaches for U.S. business, according to researchers at the Ponemon Institute and Symantec.

The
U.S. Cost of Data Breach survey released today by the Ponemon Institute and sponsored by Symantec, showed the cost of a data breach rose for the fifth straight year to an average $7.2 million per incident, up 7 percent from 2009. That’s $214 for every compromised customer record breached.

The most expensive breach reported in 2010 was $35.3 million, and the least expensive was $780,000, both up from the previous year. A key factor in the rising cost is the fact that criminals account for a larger share of the data breaches and they significantly more expensive to contain and fix.

Deliberate, criminal attacks rose nearly 30 percent last year, now accounting for 31 percent of all attacks (negligence, like lost hard drives or document, still accounts for 41 percent of breaches) and the cost of malicious attacks is is rising even faster, jumping 48 percent, to an average of $318 per compromised, wrote Dr. Larry Ponemon, founder and chairman of the institute, on his
blog.
Malicious attacks create more costs because they are harder to detect, the
investigation is more involved and they are more difficult to contain and
remediate. Another reason malicious attacks are so expensive is the criminal is
out to monetize their work; they’re trying to profit off the breach.

Other factors behind rising costs:

Better awareness: Breaches are less likely to go undetected and/or unreported. This is motivated by the threat of potential legislation and legislation. So far, 46 U.S. states have passed such measures, with varying definitions of a breach, deadlines for notifying customers and punishments for failing to comply.”

Faster (costlier) response: More companies favor a rapid response. This 43 percent of companies notified customers within 30 days.

From Dr. Ponemon’s blog:

“For the second year, we’ve seen companies that quickly respond to data breaches pay more than companies that take longer. This year, they paid 54 percent
more."

For more details please refer here.

Tuesday, March 8, 2011

Watch out for "Boy-in-the-Browser" attacks - (BitB)

Boy-in-the-Browser attacks are hard to detect, BUT easier to execute

The Boy in the Browser is a sophisticated trojan, a "dumbed-down" version of MitB. In essence, a BitB is a less mature version of the MitB trojan, hence the name.

With a BitB, the trojan takes control of the victim's traffic and re-routes the information through an attacker's proxy site. It is very difficult to detect since the victim's address bar continues to present the address of the intended destination. For example, you as an infected victim are surfing to a bank's website, but in fact, that traffic is sent to the attacker. Yet, on your browser, you continue to the bank's normal website.

Once all traffic is re-routed via the attacker, the attacker can do whatever it wants with that data. For example:

  • It can act as a proxy just logging sensitive information before passing the request on to the original destination.
  • It can act as an "active" proxy modifying requests (for example, to transfer sum to a different bank account) before passing it on.
  • Committing fraud schemes. For example, we have seen a scheme which defrauds Google.

This is a growing, resurging, trend amongst hackers, since, in short, it works. Since these trojans are so quick to evolve, anti-viruses do not always detect variants. More people fall prey to these attacks as they are so difficult to detect. Hackers have realized this and are continuing to release more and more variants of BitBs.

A Man in the Browser intercepts user requests and server responses while "sitting" on the victim's browser. In effect, it listens directly on that communication. For example, when the victim is authenticated to the bank and requests a transfer from his checking account to savings account. The trojan may modify that request in order to make a transfer from the checking account to an account in the Ukraine.

In the case of a BitB, the trojan redirects the traffic to a 3rd-party site which is an attacker-controlled server. This means that all traffic does not go immediately to the bank, rather it passes through that extra link. Only at that server, can the attacker modify the transaction request before continuing to pass it along to the original destination.

Let's consider first MitBs – these are a huge deal for enterprises and banks to deal with for the following three reasons:

  • Impact user transactions.
  • Very difficult to detect. - They last a long time.

Similarly to the MitB, BitB is just as dangerous and just as hard to detect. However, this sort of attack requires much less resources for attackers to execute. There are two main required resources:

1. The trojan code.
2. Attacker- controlled server.

As opposed to MitB, the BitB trojan code is much simpler to write. It is a very short piece of code to redirect the traffic. As for the server, they just require a domain. Today's automated tools will set up the server within just a couple of clicks. The BitB setup is a no-brainer. However, the MitB code is much more complicated. Consider your banking application. It has tabs for different operations, different options for transactions and in general, quite a complex application. The MitB code needs to be customized for each of these operations in order to hook into each of the application's feature. The big guns are required to carry out these MitB schemes.

Each of these Trojans have the same impact and scare banks and businesses alike. BitB is much easier for an attacker to pull off. However, they are most useful for a one-shot sting operation. Once uncovered, the attacker-controlled server is shut down and business is as usual. On the other hand, MitB attacks are a continuing process much more difficult to fight out once uncovered. In that case there is no single pain-point to bring down.

Imperva have witnessed BitB as a resurging as a tool of attack. Below are a couple of notable ones that they have seen:

1. Nine Latin American banks were targeted. This is one more supporting evidence that BitB is in fact a lucrative scheme. As hackers gain from this sort of attack, they continue to target numerous banks.

2. Click fraud. This is an interesting scheme since the target is not a banking application, rather it is used in order to commit fraud. In this case, to defraud Google. The victim accessing a regional domain of Google, for example www.google.co.uk would be redirected to the attacker-controlled server. When a user performs a query, the attacker would fetch the results and ads from Google, but serve them on his own page. The result is that when a user clicks on a specific ad, the commission is attributed to the attacker, and not to Google. 36 Google regional domains were targeted in this scheme showing that the attacker's aimed to target victims worldwide.

The Latin banks were a classic case which provided no visual clues as to the traffic take-over. On the other hand, with the click fraud campaign, the visual clues were ridiculously apparent as we show in our advisory on the site.

Imperva's research arm, the ADC, has established the Hacker Intelligence Initiative (HII). Under this initiative, the researchers attempt to understand the threat landscape. Their research methods involved:

1. Tapping into hacker forums
2. Monitoring and recording attacker traffic
3. Analyzing attacker resources

As part of the HII
ongoing research, they witnessed these campaigns being carried out. The team started investigating and this lead to further understanding of hacking operations.

Although BitB is presumably the consumer's problem, one cannot expect the user to know that his browser is under an attacker's control. For sake of comparison – even anti-anti virus do not flag most of these Trojans as malware as they are so quickly being modified. It is time then for online services, such as banks and retailers, to recognize this problem and provide solutions. Similar to the car industry where accidents drove the manufacturers to deal with car safety by providing seat belts, anti-brake lock systems, air bags, etc, the online banks need to consider how to deal with infected customers.

Boy-in-the-Browser attacks have the same impact as a Man-in-the-Browser attack and are just as hard to detect, BUT they are easier to execute. Banks need to start paying more attention to these types of attacks and provide the correct response to deal with them.

Monday, February 28, 2011

New Authentication Guidance

Draft Puts More Responsibility on Banks

A preliminary draft of new online authentication guidance from the Federal Financial Institutions Examination Council puts greater responsibility on the shoulders of financial institutions to enhance their security and prevent fraud.

The FFIEC has yet to formally unveil its long-awaited update to 2005's authentication guidance, but a December 2010 draft document entitled "Interagency Supplement to Authentication in an Internet Banking Environment" was reportedly distributed to the FFIEC's member agencies.

While it's likely that this draft will be amended before the final release of the new guidance, the current document calls for five key areas of improvement:

•Better risk assessments to help institutions understand and respond to emerging threats, including man-in-the-middle or man-in-the-browser attacks, as well as keyloggers;

•Widespread use of multifactor authentication, especially for so-called "high-risk" transactions;

•Layered security controls to detect and effectively respond to suspicious or anomalous activity;

•More effective authentication techniques, including improved device identification and protection, as well as stronger challenge questions;

•Heightened customer education initiatives, particularly for commercial accounts.

Risk Assessments

Risk assessments are addressed first in the draft, leveling some criticism at banking institutions for not being diligent about regular assessments.

The document says risk assessments should include regular reviews of internal systems, analyzing their abilities to:

•Detect and thwart established threats, such as malware;

•Respond to changes related to customer adoption of electronic banking;

•Respond to changes in functionality offered through e-banking;

•Analyze actual incidents of security breaches, identity theft or fraud experienced by the institution;

•Respond to changes in the internal and external threat environment.

Authentication for High-Risk Transactions

The FFIEC's definition of "high-risk transactions" remains unchanged. But the supplement does acknowledge that, since 2005, more consumers and businesses are conducting online transactions.

Layered Security

Layered security includes different controls at different points in a transaction process. If one control or point is compromised, another layer of controls is in place to thwart or detect fraud. Agencies say they expect security programs to include, at minimum:

•Processes designed to detect and effectively respond to suspicious or anomalous activity;

•Enhanced controls for users who are granted administrative privileges to set up users or change system configurations, such as defined users, users' privileges, and application configurations and/or limitations.

Effectiveness of Authentication Techniques

Part of the layered security approach, the draft suggests, should include stronger device identification, which could include use of "one-time" cookies to create a more complex digital fingerprint of the PC by looking at characteristics such as PC configuration, Internet protocol address and geo-location.

Although no device authentication method can mitigate all threats, the supplement says, "the Agencies consider complex device identification to be more secure and preferable to simple device identification."

The need for stronger challenge questions is also noted, as yet another layer institutions can use to authenticate and identify a device and a user.

Customer Education and Awareness

As part of the effort to educate consumer and commercial customers about fraud risks and security measures, the draft states financial institutions should explain what protections are and are not provided under Regulation E. The drafted guidance also suggests banking institutions offer:

•An explanation of under what circumstances and through what means the institution may contact a customer and request the customer's electronic banking credentials;

•A suggestion that commercial online banking customers perform a related risk assessment and controls evaluation periodically;

•A listing of alternative risk control mechanisms that customers may consider implementing to mitigate their own risk;

•A listing of institutional contacts for customers' discretionary use in the event they notice suspicious account activity or experience customer information security-related events.

Stronger Fraud Detection

Beyond the supervisory expectations, the draft guidance includes an appendix that discusses the current threat landscape and compensating controls, including anti-malware software for customers, as well as transaction monitoring/anomaly detection software.

Similar Guidance in Australia?

Well - I am not sure, if we have something like Federal Financial Institutions Examination Council (FFIEC) or similar council in Australia. Until, we find the answer for the question, we should start using the available guideliness available.

Wednesday, February 9, 2011

Monitoring of Power Grid Cyber Security

Efforts to Secure Nation’s Power Grid Ineffective

The official government cybersecurity standards for the electric power grid fall far short of even the most basic security standards observed by noncritical industries, according to a new audit.


The standards have also been implemented spottily and in illogical ways, concludes a Jan. 26 report from the Department of Energy’s inspector general (.pdf). And even if the standards had been implemented properly, they “were not adequate to ensure that systems-related risks to the nation’s power grid were mitigated or addressed in a timely manner.”

At issue is how well the Federal Energy Regulatory Commission, or FERC, has performed in developing standards for securing the power grid, and ensuring that the industry complies with those standards. Congress gave FERC jurisdiction in 2005 over the security of producers of bulk electricity — that is, the approximately 1,600 entities across the country that operate at 100 kilovolts or higher. In 2006, FERC then assigned the North American Electric Reliability Corporation (NERC), an industry group, the job of developing the standards.

The result, according to the report, is deeply flawed.

The standards, for example, fail to call for secure access controls — such as requiring strong administrative passwords that are changed frequently. or placing limits on the number of unsuccessful login attempts before an account is locked. The latter is a security issue that even Twitter was compelled to address after a hacker gained administrative access to its system using a password cracker.

The report is particularly timely in light of the discovery last year of the Stuxnet worm, a sophisticated piece of malware that was the first to specifically target an industrial control system — the kind of system that is used by nuclear and electrical power plants.

The security standards, formally known as the Critical Infrastructure Protection, or CIP, cybersecurity reliability standards, were in development for more than three years before they were approved in January 2008. Entities performing the most essential bulk electric-system functions were required to comply with 13 of the CIP requirements by June 2008, with the remaining requirements phased in through 2009.

The report indicates that this time frame was out of whack, since many of the most critical issues were allowed to go unaddressed until 2009. For example, power producers were required to begin reporting cybersecurity incidents and create a recovery plan before they were required to actually take steps to prevent the cyber intrusions in the first place — such as implementing strong access controls and patching software vulnerabilities in a timely manner.

The standards are also much less stringent than FERC’s own internal security policy. The standards indicate passwords should be a minimum of six characters and changed at least every year. But FERC’s own, internal security policy requires passwords to be at least 12 characters long and changed every 60 days.

One of the main problems with the standards seems to be that they fail to define what constitutes a critical asset and therefore permit energy producers to use their discretion in determining if they even have any critical assets. Any entity that determines it has no critical assets can consider itself exempt from many of the standards. Since companies are generally loathe to invest in security practices unless they absolutely have to — due to costs — it’s no surprise that the report found many of them underreporting their lists of critical assets.

“For example, even though critical assets could include such things as control centers, transmission substations and generation resources, the former NERC Chief Security Officer noted in April 2009 that only 29 percent of generation owners and operators, and less than 63 percent of transmission owners, identified at least one critical asset on a self-certification compliance survey,” the report notes.

Refer here to download the report.

Saturday, February 5, 2011

What is network Scanning?

Examine your Network With Nmap

Network scanning is an important part of network security that any system administrator must be comfortable with. Network scanning usally consists of a port scanner and vulnerability scanner.

Port scanner is a software that was designed to probe a server or host for open ports. This is
often used by administrators to verify security policies of their networks and can be used by an attacker to identify running services on a host with the view to compromise it. A port scan sends client requests to a server port addresses on a host for finding an active port. The design and operation of the Internet is based on TCP/IP. A port can have some behavior like below:
  • Open or Accepted: The host sent a reply indicating that a service is listening on the port.
  • Closed or Denied or Not Listening: The host sent a reply indicating that connections will be denied to the port.
  • Filtered, Dropped or Blocked: There was no reply from the host.
Port scanning has several types such as: TCP scanning, SYN scanning, UDP scanning, ACK scanning, Window scanning, FIN scanning, X-mas, Protocol scan, Proxy scan, Idle scan, CatSCAN, ICMP scan.

TCP scanning

The simplest port scanners use the operating system’s network functions and is generally the next option to go to when SYN is not a feasible option.

SYN scanning

SYN scan is another form of TCP scanning. Rather than use the operating system’s network functions, the port scanner generates raw IP packets itself, and monitors for responses. This scan type is also known as halfopen scanning, because it never actually opens a full TCP connection.

UDP scanning

UDP is a connectionless protocol so there is no equivalent to a TCP SYN packet. If a UDP packet is sent to a port that is not open, the system will respond with an ICMP port unreachable message. If a port is blocked by a firewall, this method will falsely report that the port is open. If the port unreachable message is blocked, all ports will appear open.

ACK scanning

This kind of scan does not exactly determine whether the port is open or closed, but whether the port is filtered or unfiltered. This kind of scan can be good when attempting to probe for the existence of a firewall and its rule sets.

FIN scanning

Usually, firewalls are blocking packets in the form of SYN packets. FIN packets are able to pass by firewalls with no modification to its purpose. Closed ports reply to a FIN packet with the appropriate RST packet, whereas open ports ignore the packet on hand.

Nmap support large number of this scanning. A vulnerability scanner is a computer program designed to assess computers, computer systems, networks or applications for weaknesses. It is important that the network administrator is familiar with these methods.

There are many types of software for scanning networks, some of this software is free and some are not, at Sectools you can find list of this software. The significant point about Nmap (Network Mapper) is Free and Open Source. Nmap is a security scanner originally written by Gordon Lyon (also known by his pseudonym Fyodor Vaskovich) for discover hosts and services on a computer network. Nmap runs on Linux, Microsoft Windows, Solaris, HP-UX and BSD variants (including Mac OS X), and also on AmigaOS and SGI IRIX.

Nmap includes the following features:
  • Host Discovery
  • Port Scanning
  • Version Detection
  • OS Detection
  • Scriptable interaction with the target
Nmap Works in two modes, in command line mode and GUI mode. Graphic version of Nmap is known as Zenmap. Official GUI for Nmap versions 2.2 to 4.22 are known as NmapFE, originally written by Zach Smith. For Nmap 4.50, NmapFE was replaced with Zenmap, a new graphical user interface based on UMIT, developed by Adriano Monteiro Marques. Working with Zenmap is easy and have a good environment for work.

Friday, January 21, 2011

Twitter Worm redirects to fake anti-virus

SCAREWARE - warning message claims the computer is running suspicious applications and the user is encouraged to run a scan

A fast-moving Twitter worm is in circulation, using Google’s goo.gl redirection service to push unsuspecting users to a notorious scareware (fake anti-virus) malware campaign.


At 8:45 a.m EST today, this Twitter search shows thousands of Twitter messages continuing to spread the worm.

According to malware hunters tracking the threat, the worm’s redirection chain pushes users to a Web page serving up the “Security Shield” Rogue AV. The page is using obfuscation techniques that include an implementation of RSA cryptography in JavaScript to obfuscate the page code.

Once a user’s browser session is redirected to the malicious site, a warning message claims the computer is running suspicious applications and the user is encouraged to run a scan. As usual, the result is that the machine is infected with malicious threats and the scam is to trick the user into downloading a fake disinfection tool.

Source: ZDNet News

Sunday, January 16, 2011

Hire a Hacker?

Russian Hackers are offering Collection of Advanced Hacking Guide & Tools

I came across a website "http://www.russianhackers.ru". I was not surprised to read that they are offering a service to "Hire a Hacker". On their website I found:

"Russia Hackers is pleased to announce RH2.5 KIt ver 2011 that users can use to Hack & secure computer systems by knowing exactly how a hacker would break into it."

Collection of Advanced Hacking Guide & Tools.

PDF Guide:


1. Advanced Hacking Guide with Metasploit

2. Malware Development (RATS, botnets, Rootkits)

3. Convert exe into PDF, XLS, DOC, JPG

4. Exploit development guide

5. Tech Tricks (Spoofing-Sms,email,call)

6. Download any Apple Apps Free of cost

7. Credit Card HAcking
8. Netbanking Hacking-bypass Virtual KEyboard

9. Spreading guide to Infect 100K/Victims per day

10. Advanced Email Hacking Tricks

11. SET(Social Engineering Toolkit) module
12. Links for other russian hacking sites

Cost: 100 USD

If you are not interested in reading or learning about the hacking, you can directly buy their hacking services, details are given below:

Tools/Services:
{Value more than 1500 USD}


1. Polomorphic Crypter's (to make Files undetectable-bypass all AV Scantime,runtime)

2. Java Driveby FUD (deploy your exe by URL on target)

3. Immunity Canvas (Hack remote pc with IP address)
4. Paid Botnets (Spyeye,etc)

5. IRC Bots(Ganga, niger,etc)
6. Yahoo messenger zeroday exploit (run exe on target yahoo messenger ID without any alaert)

7. Ice pack Enterprise (execute exe using php script)

8. Bleeding_Life_V2_pack /

Other Packs
Service's:

1. One Linux Based VPS with Root access for Lab Setup (Safe & Secure)

2. VPN Double + Triple Encrypted (Hide your real Ip Address)

3. Fake Emailer with attachment

4. Email Bomber (Send 1 million emails into Inbox)

5. DDOS Attacks Shells

tools+services :
250 USD

Futhermore I also found the following on their website:

"We sell latest zero day exploits (doc, xls, PDF FUD), Java driveby, browser packs, remote pen testing tools, VPN, VPS, Bots, etc.."

The above details are self-explanatory. You can imagine why security is so important for your corporate or home environment. Your enemies, competitor or anyone who doesn't want you to be in the business or want to take revenge can do nasty things with your environment. In worse case scenario, they might not do themselves because they can "Hire a Hacker".

Saturday, January 15, 2011

A Beginners Guide to Ethical Hacking

Learn how to hack and defend attacks

A Beginners Guide to Ethical Hacking is a great resource for people interested in ethical (White Hat) hacking. It is targeted at "beginners”, but some "intermediate” users may find value in this book as well.

This book defines the ethical boundaries of hackers – what the cognoscenti considers too far. It also gives the explanation on realm of programming and how code-writing can be leveraged to achieve the readers’ goals.

The author has given detailed illustration and explanation on hacking and cracking of passwords, Microsoft Windows OS, Wi-Fi, web applications, malware and viruses.

This book will helps you to learn the both hacking and defensive side of information security.By providing a good balance of both offense and defense, the reader is presented with the tools needed to make accurate and educated decisions regarding not only ethical hacking, but also how to properly secure themselves when doing business online.

URL: www.hacking-book.com
Cost: $20

Monday, November 8, 2010

SCADA security issues will be the shiny hot topic

Metasploit and SCADA Exploits: Dawn of a New Era?

On 18 October, 2010 a significant event occurred concerning threats to SCADA.

That event is the addition of a zero-day exploit for the RealFlex RealWin SCADA software product into the Metasploit repository.

Some striking facts about this event follow:

  1. This was a zero-day vulnerability that unfortunately was not reported publicly, to a organization like ICS-CERT or CERT/CC, or (afaik) to the RealFlex vendor.

  2. This exploit was not added to the public Exploit-DB site until 27 October, 2011.

  3. The existence of this exploit was not acknowledged with a ICS-CERT advisory until 1 November, 2010.

  4. This is the first SCADA exploit added to Metasploit.
Shawn Medinger at InfoSec Island shared some interesting thoughts:

First, the SCADA community can expect to see an explosion of vulnerabilities and accompanying exploits against SCADA devices in the near future.

Second, the diverse information sources that SCADA vulnerabilities may appear must be vigilantly monitored by numerous organizations and security researchers.

Afaik, the first widely-disseminated information on the RealFlex RealWinbuffer overflow occurred on 1 November, when I sent the information to the SCADASEC mailing list.

Third, people should recognize that the recent Stuxnet threat has cast a light on SCADA security issues. Put bluntly, there is blood in the water.

Quite a few people, companies and other organizations are currently investigating SCADA product security, buying equipment and conducting security testing for a number of differing interests and objectives.

Fourth, understand that because of the current broken business model, security researchers are often frustrated by software vendors’ action, or inaction, when it comes to reporting vulnerabilities.

Often, there is no security point-of-contact at the vendor. Even worse, the technical support who are contacted by the security researcher often do not understand the technical and security implications of the issue reported.

Even in the case of specialty SCADA security shops reporting vulnerabilites to the vendor, we are seeing documented cases of “vendor spin” furthering the bad blood between vendors and ethical research.

All of these factors lead to frustrated security researchers, some of whom will simply expose the vulnerability and exploit to the world, rather than take a disclosure path through a CERT.

Fifth, folks should recognize that attack frameworks like Metasploit enable a never-before-seen level of integration of these kinds of targeted critical infrastructure-relate exploits into a powerful tool.

Monday, October 25, 2010

Verizon report connects PCI non-compliance and data breaches

Verizon Business report shows a correlation between non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) and data breaches

A new Verizon Business report released today shows a correlation between non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) and data breaches. The results revealed that organizations that had suffered data breaches were 50% more likely to exhibit PCI non-compliance.

The report also ranked the top attack techniques used to steal payment card data. Remote access to systems via backdoors was the top attack, followed closely by SQL injection attacks. Poor authentication was also a problem, in particular, attackers exploiting default or easily guessable passwords to gain access to systems storing or processing payment data.

Further, 11% of companies met less than half of the requirements, while 22% met 100% of the requirements. The report also covers compensating controls, and determined that Requirement 3.4, which mandates that a primary account number (PAN) be unreadable, is the control most compensated for.

Quick Summary
  • 22% of organizations were validated compliant at the time of their Initial Report on Compliance (IROC). These tended to be year after year repeat clients.

  • On average, organizations met 81% of all test procedures defined within PCI DSS at the IROC stage. Naturally, there was some variation around this number but not many (11% of clients) passed less than 50% of tests.

  • Organizations struggled most with requirements 10 (track and monitor access), 11 (regularly test systems and processes), and 3 (protect stored cardholder data).

  • Requirements 9 (restrict physical access), 7 (restrict access to need-to-know), and 5 (use and update anti-virus) showed the highest implementation levels.

  • Sub-requirement 3.4 (render the Primary Account Number (PAN) unreadable) was met through compensating controls far more often than any other in the standard.

  • Organizations do not appear to be prioritizing their compliance efforts based on the PCI DSS Prioritized Approach published by the PCI Security Standards Council.

  • Overall, organizations that suffered a data breach were 50% less likely to be compliant than a normal population of PCI clients.
Please refer here to download the report.

Friday, October 22, 2010

NIST Scientists Offer Tips to Defeat Keyloggers

How to Beat Keyloggers

Keyloggers monitor and record keyboard use, including the information typed into a system, which might include the content of emails, usernames and passwords for local or remote systems and applications, as well as financial information like credit card numbers, Social Security numbers or PINs.

Some keystroke loggers require the attacker to retrieve the data from the system, whereas others actively transfer the data to another system through email, file transfer or other means.


NIST scientists identify three main types of keyloggers:

Hardware -- Tiny inline devices placed between the keyboard and the computer. Because of their size, they can go undetected for long periods of time. These devices have the power to capture hundreds of keystrokes, including banking and email username and passwords. But for the criminal, the threat of being caught breaching the machine is a deterrent.

Software -- This type of keylogging is done by using the Windows function SetWindowsHookEx that monitors all keystrokes. The spyware will usually appear packaged as an executable file that initiates the hook function, plus a DLL file to handle the logging functions. An application that calls SetWindowsHookEx is capable of capturing even autocomplete passwords.

Kernel/driver -- This kind of keylogger is at the kernel level and receives data directly from the input device (typically a keyboard). It replaces the core software for interpreting keystrokes. This type of keylogger can be programmed to be virtually undetectable by being executed when the computer is turned on, before any user-level applications start. Since the program runs at the kernel level, one disadvantage to this approach it that it fails to capture autocomplete passwords, as this information is passed in the application layer.

Defending Against Keyloggers

There are several kinds of defenses that can be used to spot or prevent keyloggers from embedding on machines:

Physical Security -- The physical protection of the computer must be considered. Whether the computer is at home, in an office or during traveling, keeping the computer secure and making sure no one has access to it is a primary concern.

Application whitelisting -- is a way to prevent any software that isn't already approved or on the "white list" from being downloaded on to the computer. This is an emerging approach in combating viruses and malware. Application whitelisting tells the computer a list of software considered safe to run, and the machine is instructed to block all others.

Some experts see this approach as superior to the standard signature-based, anti-virus approach of blocking/removing known harmful software (essentially blacklisting), as the traditional approach generally means that exploits are already in the wild.

Detection Software -- Be careful where you go to on the Internet. Drive-by downloads from ads that have been laced with malware are being found now even on popular news sites - not just on the fringes.

At a minimum, at least have anti-virus and anti-spyware loaded, and make sure they're kept up to date. Again, buy from a reputable vendor.
Consider operating a "virtual" machine environment to browse the Internet.

Virtual machines -- are separated into two major categories, based on their use and degree of correspondence to any real machine. A system virtual machine provides a complete system platform that supports the execution of a complete operating system. The other type, a process virtual machine, is designed to run a single program. An essential characteristic of a virtual machine is that the software running inside is limited to the resources and abstractions provided by the virtual machine -- it cannot break out of its virtual world.


Future Trends

"Moving forward in the next 12-18 months, the major computer manufacturers will begin offering virtual machine technology. "We're going to see more consumer-friendly operating systems being designed by vendors that will limit malware by having the user on a virtual machine while on the Internet, and the 'home' environment separate.

Cloud-based whitelisting will also become more popular, making whitelisting more available.

Another advancement in the fight against keyloggers and other types of malware is the move by anti-virus vendors to set up reputation-based systems, which checks programs and tells the user whether it is legitimate or malicious.

The addition of a third component in the fight against malware is the use of operating systems and browsers that don't allow the malicious programs to be pushed down in the first place. By isolating and "sandboxing" the user's specific browsing session,
no software is downloaded to the user's computer.