Showing posts with label Response. Show all posts
Showing posts with label Response. Show all posts

Wednesday, April 3, 2013

What's your personal Disaster Recovery Strategy?

After the Storm Comes a Rainbow

If you've ever had a computer device unexpectedly fail on you, you know how it feels - like a flash flood, taking you by surprise and washing away everything you need.

Lets say, you have an external hard drive which stopped. Completely. Unexpectedly.

Did you had backups of that data? Do you make backups of your data regularly?

Here are some recommendations to help you from feeling the pain of a failed hard drive:

  • Invest in an external backup drive for storing your backups. You can see some good guidance here.
  • For data that is especially valuable (income tax data, photos, business data), make another copy on a different external drive and store at a different, secure location, such as a bank safety deposit box.
  • Back up your email at least once a week; more often if you depend on it for business and would be lost without it.
  • Most external hard drives can be configured to automatically make backups at specified intervals; look for external hard drives with these capabilities.
  • If personal information is on your backup drive, encrypt it!
  • If you want to use a cloud service to store your backups, make sure they will encrypt your data, and that they have terms of service that will allow you ample time to remove your data, completely, if there is ever the need.
  • Regularly test backups to ensure the backup data is actually good.

Wednesday, February 22, 2012

Half of the Fortune 500 companies are still infected with DNSChanges Virus!

FBI could take down Internet for millions on March 8

On March 8, the FBI may be forced to shut down DNS servers, originally installed to stop the spread of the DNSChanger virus, which would cut off Internet access to millions of Web users worldwide.

The Federal Bureau of Investigation may soon be forced to shut down a number of key Domain Name System (DNS) servers, which would cut Internet access for millions of Web users around the world, reports BetaBeat.

The DNS servers were installed by the FBI last year, in an effort to stop the spread of a piece of malware known as DNSChanger Trojan. But the court order that allowed the set up of the replacement servers expires on March 8.

In November of last year, authorities arrested six men in Estonia for the creation and spread of DNSChanger, which reconfigures infected computers’ Internet settings, and re-routes users to websites that contain malware, or other illegal sites. DNSChanger also blocks access to websites that might offer solutions for how to rid the computer of its worm, and often comes bundled with other types of malicious software.

By the time the FBI stepped in, DNSChanger had taken over computers in more than 100 countries, including half-a-million computers in the US alone. To help eradicate the widespread malware, the FBI replaced infected servers with new, clean servers, which gave companies and individuals with infected computers time to clean DNSChanger off their machines.

Unfortunately, DNSChanger is still running on computers “at half of the Fortune 500 companies,” and at “27 out of 55 major government entities,” reports cybersecurity journalist Brian Krebs. These computers rely on the FBI-installed DNS servers to access the Web. But if the court order is not extended, the FBI will be legally required to remove the clean servers, which would cut off the Internet for users still infected with DNSChanger.

Companies or other agencies that are unsure whether their systems are infected with DNSChanger can get free assistance here. And private users can find out if they are infected using instructions provided here.

Friday, November 25, 2011

The FUD: Cyber Attacks on Illinois Water Systems?

US Water System Hacked: A Community-Wide Issue

On November 17th Joe Weiss, a well-known member of the Industrial Control System (ICS) community, posted on his blog about a recent US water system hack.

Joe points out that the disclosure concerning the Nov 8th supervisory control and data acquisition (SCADA) hack was made by Illinois Statewide Terrorism and Intelligence Center on Nov 10th.

Joe's post stated that the SCADA software vendor was compromised and that customer usernames and passwords were stolen as well as possible physical damage to the utility. He further states that the IP address of the attacker traced back to Russia, which does not provide any attribution but is nevertheless interesting.

The compromise of a US water facility should be concerning for a number of reasons. Firstly, the idea of anyone or any group (nation state or not) breaking into SCADA and control systems in the US highlights a weakness in our nation's infrastructure.

What is hard to discern though is how many attacks are prevented on a daily basis by the men and women taking up the very difficult challenge of cyber defense. Regardless though, this is a fight that must continue to get support and attention in the cyber community.

Secondly, a water facility has a direct impact over the health of the citizens that it provides. A compromise of such a facility, depending on the scale of the compromise, could reasonably lead to the loss of life. This is to say that the concern for security of the ICS and SCADA community is not and cannot simply be financial.

The reported attack against this water SCADA system, although it is in no way possible to determine at this time, could be this style of attack. This is important to think about in regards to what future attacks may hold, what the motives for the attacks are, and what attacks may currently be going unnoticed.

Please refer here to read more interesting analysis.

Saturday, October 22, 2011

DHS: “Anonymous” Sniffing around SCADA systems

Hacktivist group "Anonymous" are considering attacking SCADA system

A recently leaked DHS document (Download Here) warns that Hacktivist group “Anonymous” are considering attacking SCADA systems and Critical Infrastructures in some countries.

The document labelled as “for official use only” quotes several “twitter” posts believed to belong to Anonymous members discussing and exchanging information about SCADA projects.
”On 19 July 2011, a known Anonymous member posted to Twitter the results of browsing the directory tree for Siemens SIMATIC software. This is an indication in a shift toward interest in control systems by the hacktivist group.”
another tweet
“An anonymous individual provided an open source posting on twitter of xml and html code that queries the SIMATIC software. The individual alleged access to multiple control systems and referred to “Owning” them. The Twitter posting does not identify any systems where privileged levels of access to control systems have been obtained.”
The report insinuates that experienced Anonymous hackers can quickly gain the knowledge required to hack ICS “Industrial Control Systems” which is correct. But the report didn’t mention the fact that currently there is a gold rush amongst researchers to come up with SCADA vulnerabilities, just in the past couple of weeks anyone following the right and publicly available sources can count more than a dozen zero-day vulnerabilities out there.

Just by looking around, I am afraid to say that ICS are going to be the next target after the current wave of attacks on financial institutions “Occupy wall-street”.

Looking at the flow of events, Anonymous, LulzSec and Co. have already targeted Governments, Big corporates, Defense contractors,Banks and Stock exchanges….the next logical step down the food chain is Energy.

More on the topic:

- Washington times
- The register

Friday, August 5, 2011

Cyber Storm III participants found shortcomings in its cybersecurity “escalation procedures”

Australian report identifies cybersecurity gaps during Cyber Storm III exercise

An Australian report issued Monday found gaps in cybersecurity procedures and processes for both government and industry, based on a review of the US-sponsored Cyber Storm III exercise held last September.

The report, commissioned by the Australian government and carried about by former Australian Army intelligence officer Miles Jakeman, said that Cyber Storm III identified "gaps” in cybersecurity procedures, processes, and plans by government and industry.

The Australian government identified gaps in its interim cybersecurity crisis management plan, and industry found shortcomings in its cybersecurity “escalation procedures”, according to the report.

The Cyber Storm III exercise included participants from seven US federal agencies, 11 US states, 60 private companies, and 12 international partners. The Australian government sent representatives from the Defence Signals Directorate, Computer Emergency Reponse Team (CERT) Australia, and Australian Federal Police; industry was represented by Telstra, ASX, Woolworths, ANZ, and domain name registrar AuDA.

Australian Attorney General Robert McClelland said that more than 50 Australian organizations participated in Cyber Storm III. He said in releasing the report: “The Cyber Storm III exercise provided a good test of new government processes including the interim cybersecurity crisis management plan, which allowed agencies to identify gaps and revise processes.”

McClelland added: “The exercise revealed many areas where internal and cross-sector partnerships worked effectively to communicate and resolve issues, but also highlighted areas where communications and planning could be further developed….While it did highlight gaps within existing government and business cyber incident processes, particularly in regards to escalation procedures, this feedback allows both government and businesses to take steps to improve our cybersecurity.”