Showing posts with label physical security. Show all posts
Showing posts with label physical security. Show all posts

Tuesday, May 28, 2013

Vulnerability in Building Control Systems

Vital buildings such as hospitals, universities and government offices are vulnerable to hackers

You're in intensive care at a hospital when the lights go out and the heating turns up. Meanwhile, doctors trying to get you to an operating theatre have been trapped in elevators for almost an hour as hackers take control.

The building control system for one of Google's offices in Sydney was hacked into by two IT security researchers who say hundreds more in Australia are also accessible via the internet.

A building control system, or building management system, is a computer-based system used to control and monitor a building's mechanical and electrical equipment using software. It monitors and controls things like ventilation, air conditioning, lighting and fire systems.

US researchers Billy Rios and Terry McCorkle of security firm Cylance found that the building control system for Google's Wharf 7 office in Pyrmont was vulnerable after finding it on the popular hacker search engine Shodan, which maps out vulnerable devices on the internet.

A search engine Shodan, indexes servers and other internet devices is helping hackers to find industrial control systems that are vulnerable to tampering. This makes it easy to locate internet-facing SCADA, or supervisory control and data acquisition, systems used to control equipment at gasoline refineries, power plants and other industrial facilities.

Please refer here for a good technical webcast explaining "How the information in SHODAN is put together and correlated".

The incident does highlight the need for sensitive systems (not just SCADA) to be isolated from hostile networks like the internet.

Hopefully, this incident will gain some more traction outside the security community.

Friday, April 6, 2012

10 Threats to IT over the Next Two Years

Threats Seen Intensifying as They Combine with Other Ones


Providing IT security will only get tougher over the next couple of years as digital threats become more numerous and complex. That's the gist of a new report from the Information Security Forum entitled Threat Horizon 2014: Managing Risks When Threats Collide.
"While individual threats will continue to pose a risk, there is even more danger when they combine, such as when organized criminals adopt techniques developed by online activists," Steve Durbin, global vice president of the Information Security Forum, said in announcing the report. 
"Traditional risk management is insufficiently agile to deal with the potential impacts from activity in cyberspace." 
The report categorizes 10 threats in three basic areas: external, regulatory and internal, including: 


External Threats 


1. Cyber criminality increases as the malware space matures: The sophistication and scale of the global industry that has evolved to commit cybercrime, espionage and other malevolent activity will grow and develop. 


2. The cyber arms race leads to a cyber cold war: Nations developing more sophisticated ways to attack via cyberspace will get better at it, those who haven't will start, and organizations will suffer collateral damage. Targets for espionage will include anyone whose intellectual property can turn a profit or confer an advantage. 


3. More causes come online; activists get more active: Anyone not using the Internet to advance their cause will start: customer affinity groups, community associations, terrorists, dictators, political parties, urban gangs - the list is endless. Online organizing will become easier and protest channels will be available to greater numbers. 


4. Cyberspace gets physical: The increasing convergence of cyber and physical worlds will bring more attacks on physical systems, from attempts to turn out lights or climate control systems to disrupting manufacturing systems. Whether attacks are successful or not, credible publicised threats will cause disruption and panic.


Regulatory Threats 


5. New requirements shine a light in dark corners exposing weaknesses: Further movement toward increasingly transparent security disclosures will publicize weaknesses, making organizations more vulnerable to attack. Organizations forced to report security risks may have as much to fear from customers and business partners as they do from hackers and regulators. 


6. A focus on privacy distracts from other security efforts: New privacy requirements from consumers, business customers and regulators impose a heavy compliance burden. Organizations will need to decide whether to invest in the necessary security and legal controls, outsource to someone who can or exit certain markets. They will also need to consider the message their actions send to their customers. Internal Threats 


7. Cost pressures stifle critical investment: An undervalued function can't keep up. It would be normal to see investment increase after the prolonged downturn, but some economies are still struggling. Even organizations that are increasing security spending have a legacy of under-investment that can't be corrected overnight. But cyber criminals have been investing, and it will become easier and less expensive to buy criminal technology and services. 


8. A clouded understanding leads to an outsourced mess. Continued cost pressure will lead to a new form of digital divide: between organizations that understand the marriage between IT and information security - and everyone else. Leading organizations will appreciate the strategic value of channels, systems and information and will invest; the others will suffer competitive disadvantage and heightened risk of damaging incidents. 


9. New technologies overwhelm: Organizations are unlikely to slow their adoption of new technology or decrease their participation in cyberspace. Along with business benefits come potential vulnerabilities and methods for attack, and organizations will continue to be hit. Organizations that don't understand their dependence on technology may have a nasty surprise if it leads them astray or suddenly goes offline. 


10. The supply chain springs a leak as the insider threat comes from outside: A modern organization's data are spread across many parties, and more organizations will fall victim to incidents at suppliers. This will increase as organizations further digitize supply chains, outsource functions and rely on external advisers. 3D printers create three-dimensional products from digital blueprints - increasing the theft of intellectual property, the frequency of attacks and the amount of counterfeit product on the market. 


Organizations are being left behind, with some seeing their finances and reputations damaged because of the speed and complexity of the threat landscape. They need to take stock now to ensure they are fully prepared and engaged.

Wednesday, April 4, 2012

Burglars watching online moves

Home Tweet Home

Being checked-in on Facebook has become the digital equivalent of an overflowing letterbox that tells burglars you're away on holidays.

ADT Security's Secure Homes report has found 86 percent of Australians are concerned their social media location data could be used for malicious purposes, including telling the world when no one is home.

Facebook, Twitter and Foursquare allow users to have their location posted online. The survey of 2000 home-owners also found while 48 percent of GEN-Y regarded identity theft as a concern, they were not as worried about it as Baby Boomers.

Savvy criminals are getting access to up to the minute details through people's status updates and posts, allowing them to learn when the home is likely to be vacant. It's important to think twice before updating your Facebook status or tweeting or checking into Foursquare.

Setting your profiles to private, turning off location finders, or a bit of self-cencorship when it comes to announcing an extended holiday, can help prevent falling victim to burglary.

Tuesday, December 6, 2011

Securing Smartphones in the Bring-Your-Own-Device (BYOD) Era

5 Security Challenges BYOD Presents

Most organizations remain uncomfortable in letting their employees use their own mobile devices to access their IT systems. Yet, in many instances, those charged with securing their enterprises' IT understand that it's just a matter of time before they must grant workers permission to employ those devices.

BYOD stands for bring your own device, and it's one of the hottest challenges IT security organizations face as a growing number of employees use their own BlackBerrys, iPhones, iPads and Droids to access their employers' IT systems. In instances where such practices are banned, employees are demanding that the prohibition be lifted.

That's causing much reflection among IT security professionals. Executives and managers charged with IT security have identified five challenges that must be surmounted before their organizations can allow secure access to their systems by smartphones and tablet computers owned by their employees. These challenges include policy enforcement, physical theft, malware prevention, IT support and employee education.

Policy Enforcement

Many IT security leaders aren't sure if their teams are ready to take on additional responsibilities of continuously monitoring these devices and people's behavior.

Physical Theft

Think about it: Chances of losing a mobile device owned by an individual - or having it stolen - is a lot greater than one owned by the employer. A personally owned device goes everywhere with its owner; that's not necessarily true with a company-owned device. That provides little comfort for IT security managers responsible for safeguarding sensitive corporate data.

Except for BlackBerrys, most other mobile devices don't readily support encryption. Someone steals an iPhone or an Android smartphone, the unencrypted data on those devices could be exposed to the thief.

But by placing proper controls on user-owned devices, gaining access by unauthorized individuals to sensitive data can be prevented. If employees want to use their own smartphones or tablet PCs for work, they must agree to seven security controls (see 7 Steps to Secure Mobile Devices), including strong passwords and remote wipe.

Such an approach places part of the security burden on the employee. And, half of the employees who had been using their own devices to access the state network decided not to so when the Delaware implemented its BYOD policy a year ago.

Malware Prevention

Devices used for personal activities are more prone to malware; after all, they're accessing a number of consumer sites that don't necessarily provide the security as do many sites designed for business-to-business transactions.

Many CIOs worries not only about insecure applications downloaded on these devices, but so-called jail-broken smartphones and tablets that are opened and altered to permit use of software the manufacturer didn't architect the device for.

Many banks scrutinizes all employee-owned devices before it allows them to access its networks to ensure they're safe and not jail broken. The bank also makes sure all personally owned devices contain anti-malware software that includes features to alert bank security personnel should a virus surface.

IT Support

Letting employees use their own devices presents a nightmarish scenario for many organizations, supporting a wide range gadgets, operating systems and software. Organizations must define which devices to support based on how they'll be used. It may be OK to limit certain devices to access specific applications, such as e-mail, and restrict their access to other programs behind the firewall.

Employee Education

Getting employee to know about the policy and why it's important for them to implement security controls requires education.

Indeed, security awareness and training is a crucial element in allowing employees to use their own mobile devices, and it's important that IT security leaders prepare their staffs - and themselves - for the advent of widespread adoption of BYOD.

Tuesday, August 30, 2011

Singapore Airport enhances airfield security with fibre-optic sensors

No system is fool-proof and perfect

Changi Airport will be the world's first airport to reinforce its perimeter fences with fibre-optic sensors to detect intruders.

More cameras will also be installed at airport boundaries, which will be integrated with the new multi-million-dollar defence system called AgilFence, made by Singapore Technologies (ST) Electronics.

Said Changi Airport Group's executive vice-president (airport management) Foo Sek Min: "No system is fool-proof and perfect."

"And as we review our existing perimeter protection, the introduction of this perimeter intrusion detection system will help us to have a better and faster response if there are any signs of intrusion."

The pressure-sensitive sensors are protected by an armoured casing to prevent tampering and for easy maintenance.

ST Electronics said the system is expected to last a decade, adding that it is immune to electromagnetic and radio frequency interferences, making it effective for deployment in an airfield.

The system is expected to be fully operational by end-2012.

Sunday, October 4, 2009

Pedestrian crossings could be monitored

Intelligent surveillance system able to detect aberrant behaviour by drivers and people

A surveillance system for monitoring whether cars and pedestrians are acting normally at crosswalks has been developed by researchers at Spain's University of Castilla-La Mancha (UCLM). "We have developed an intelligence surveillance software and related theoretical model in order to define 'normality' in any setting one wishes to monitor, such as a traffic scenario," says UCLM's David Vallejo.


Normal behavior is defined as moving when lights are green, and stopping and not crossing safety lines when they are red. The artificial intelligence system makes use of software agents to monitor pedestrian crossings. The team developed the monitoring tool to determine the effectiveness of its model. "In this way we are able to identify any drivers and pedestrians behaving abnormally, meaning the program could be used in order to penalize such behaviors," Vallejo says.

The researchers say the intelligent surveillance system also could be used to analyze behavior indoors, such as at museums, or to detect overcrowding.

Please refer here to read more details.

Saturday, April 18, 2009

Eyeball Spy Turns the Tables on Big Brother

The gaze-tracking system may well be regarded as intrusive by CCTV control-room staff

The performance of closed-circuit television (CCTV) operators could be improved by analyzing their gaze, according to researchers in Turkey. Ulas Vural and Yusuf Akgul of the Gebze Institute of Technology have developed a gaze-tracking camera system to watch the eyeballs of CCTV operators as they work.

The gaze-tracking system would train a Webcam-style camera on the irises of people who watch CCTV images in the control room. CCTV operators could miss criminal or antisocial activity because they have so many screens to monitor simultaneously. After the system uses an algorithm to analyze where CCTV operators are looking, it uses software to create a video of sequences missed during the shift.

"This increases the reliability of the surveillance system by giving a second chance to the operator," the researchers write in the journal Pattern Recognition Letters. The gaze-tracking camera system runs on a standard PC and processes the images in real time, making summary frames ready to browse, similar to a fast-motion flip book.

Source: Click here to read the original news.