Thursday, July 21, 2011

Security analysis of Dutch smart metering systems

Smart metering must offer a security level as high as for money transfers - Dutch minister of Economic Affairs

Smart meters enable utility companies to automatically readout metering data and to give consumers insight in their energy usage, which should lead to a reduction of energy usage. To regulate smart meter functionality the Dutch government commissioned the NEN to create a Dutch standard for smart meters which resulted in the NTA-8130 specification.

Currently the Dutch grid operators are experimenting with smart meters in various pilot projects. In this project we have analyzed the current smart meter implementations and the NTA using an abstract model based on the the CIA-triad (Confidentiality, Integrity and Availability). It is important that no information can be attained by unauthorized parties, that smart meters cannot be tampered with and that suppliers get correct metering data.

It was concluded that the NTA is not specific enough about the security requirements of smart meters, which leaves this open for interpretation by manufacturers and grid operators. Suppliers do not take the privacy aspect of the consumer data seriously. Customers can only get their usage information through poorly secured websites. The communication channel for local meter configuration is not secured sufficiently: consumers might even be able to reconfigure their own meters.

Also, the communication channels that are used between the smart meter and gas or water meter are often not sufficiently protected against data manipulation. It is important that communication at all stages, starting from the configuration of the meter to the back-end systems and websites, is encrypted using proven technologies and protected by proper authentication mechanisms.

It is important that communication at all stages, starting from the configuration of the meter to the back-end systems and websites, is encrypted using proven technologies and protected by proper authentication mechanisms.

Refer
here to download the full report.

Wednesday, July 20, 2011

International Strategy for Cyber Space

Preparing for 21st Century Security Challenges

Cyberspace, and the technologies that enable it, allow people of every nationality, race, faith, and point of view to communicate, cooperate, and prosper like never before.

Today, as nations and peoples harness the networks that are all around us, we have a choice. We can either work together to realise their potential for greater prosperity nd security, or we can succumb to narrow interests and undue fears that limit progress.

Cyber security is not an end unto itself; it is instead an obligation that our governments and societies must take on willingly, to ensure that innovation continues to flourish, drive markets, and improve lives. While offline challenges of crime and aggression have made their way to the digital world, we will confront them consistent with the principles we hold dear: free speech and association, privacy, and the free flow of information.

Envision a future in which reliable access to the Internet is available from nearly any point on the globe, at a price that businesses and families can afford. Computers can communicate with one another across a seamless landscape of global networks permitting trusted, instantaneous communication with friends and colleagues down the block or around the world.

Content is offered in local languages and flows freely beyond national borders, as improvements in digital translation open to millions a wealth of knowledge, new ideas, and rich debates. New technologies improving agriculture or promoting public health are shared with those in greatest need, and difficult problems benefit from global collaboration among experts and innovators.

This, in part, is the future of cyberspace that the United States seeks—and the future we will work to realize.

You can download this paper from here: http://www.logicalsecurity.com/resources/whitepapers/Cyberspace_Strategy_INTL%20051611.pdf

Monday, July 18, 2011

Department of Defense Strategy for Operating in Cyberspace

"Cybersecurity threats represent one of the most serious national security, public safety, and economic challenges we face as a nation"

The Department of Defense released today the DoD Strategy for Operating in Cyberspace (DSOC). It is the first DoD unified strategy for cyberspace and officially encapsulates a new way forward for DoD’s military, intelligence and business operations.

The five primary pillars of the strategy are:
  1. DoD is treating cyberspace as an operational domain, like land, air, sea, and space.
  2. DoD introducing new active cyber defenses. Active defenses use sensors, software and signatures to detect and stop malicious code;
  3. Working with Department of Homeland Security and the private sector to protect critical infrastructure;
  4. DoD building collective cyber defenses with our allies and international partners;
  5. Enhance network security. A more secure and resilient internet is in everyone´s interest.
Dowload the document here: http://www.defense.gov/news/d20110714cyber.pdf

Sunday, July 17, 2011

Videos to Understand NERC CIP Requirements for Smart Grid Security

Smart Grid Security East 2011 NERC CIP compliance pre-conference workshop

The North American Electric Reliability Corporation (NERC) enforces electric reliability standards under the authority of the Federal Energy Regulatory Commission (FERC). A large part of these enforcement efforts include Critical Infrastructure Protection (CIP), which is currently a key area of cyber security enforcement for NERC, and the set of guidelines are referred to as the NERC CIP guidelines. Organizations who are subject to enforcement under NERC CIP face fines of up to 1 million dollars per day for failing to comply with set requirements. This workshop will focus on the following:
  • Understanding NERC CIP Requirements
  • How to prepare for a NERC CIP Audit
  • Tips and Findings from organizations that have experienced a NERC CIP Audit
  • Overview of the direction NERC CIP is heading























Saturday, July 16, 2011

Attorneys General seek to co-operate in terms of Cybercrime

Cyber security and crime represents a significant and growing threat to everyone around the world

The Attorneys General from the US, the UK, Canada, Australia and New Zealand plan to co-ordinate their efforts to combat internet crime more closely. The prosecutor quintet's third meeting since 2009 will be held on Thursday in Sydney, Australia.

According to a media release by the hosting Australian Attorney General, Robert McClelland, the meeting will focus on joint and cooperative actions that can be taken to address the growth of international cyber-threats. McClelland's spokesperson denied reports of potential plans for a cybercrime agreement between the quintet countries, pointing out Australia's ongoing preparations to sign and ratify the 2001 Council of Europe Convention on Cybercrime.

In late June, McClelland and the Australian home secretary, Brendan O'Connor, introduced a bill that is designed to prepare Australia for adopting the Convention on Cybercrime. In addition to the ability to "quick freeze" telecommunications data, the bill aims to regulate confidentiality obligations in terms of data access, and contains minor amendments to the criminal laws against intrusions into computers and data manipulations. The bill is currently being discussed by the Joint Select Committee on Cyber Security.

With Australia intending to adopt the Convention on Cybercrime, the only remaining quintet member that will have not done so is New Zealand. However, the Convention still needs to be put into practice, not only in Australia, but also in the UK and in Canada. The Convention on Cybercrime is currently
only in force in the US. The UK will follow in September 2011.

At their meeting in Sydney, the five Attorneys General will also lead discussions on a range of key national security and legal policy issues. For example, the UK Attorney General, Dominic Grieve, will report on the disclosure of digitally stored material, while Robert McClelland will present Australia's strategy for countering violent extremism on the internet.

The Australian authorities say that they will spend up to a million dollars (about £660,000) on supporting citizens' rights groups that raise public awareness on violent extremism and build community resilience to radicalisation and extremist views.

Friday, July 15, 2011

Virtual Event: Mitigation Strategies for Today's Global Enterprise

ISACA: Enterprise Risk Management

As companies become more global, risks increase, as does the need for effective enterprise risk management (ERM). Join ISACA and SearchCompliance.com on 10 August, 6:45AM-4:30PM EDT (UTC -4), for a free virtual seminar and tradeshow, Enterprise Risk Management, Mitigation Strategies for Today's Global Enterprise, that will provide practical ERM advice from leading experts.

By attending, you will learn how to spot opportunities and develop an action plan, understand why risk management should be part of your business culture, and gain insight about who should be contributing to the risk process. You will also have the opportunity to network with peers from around the world and earn up to 5 continuing professional education (CPE) hours.

Register now, for 10 August and make a difference in your enterprise by learning how to implement effective ERM.

Educational Sessions:

Session 1: Enterprise Risk Management in the European Landscape
Session 2: Enterprise Risk Management: Your Role in Reducing Risk to Business
Session 3: Sustainability and Enterprise Risk Management
Session 4: Supply Chain Risk Management
Session 5: Managing Network Security Threats with an ERM Strategy

Thursday, July 14, 2011

Mobile Security Summit

Free Online Event

Consumer-oriented devices are used to access the enterprise network, email and applications on the move. While the productivity gains and strategic opportunities of accessing data remotely are real, enterprise decision makers are increasingly challenged by cost and security.

Join industry experts, analysts and end users as they identify the key vulnerabilities you should be aware of and the solutions that will allow you to keep your business running securely.

Sign up to attend the live interactive webcasts on Wednesday, July 13, 2011, or view them afterward on demand here: http://www.brighttalk.com/r/Grz .

Presentations include:

‘Thriving in the Era of the Mobile Workforce’
Christian Kane, Forrester Research; Gaston Brown, Hobart Brothers Co.; Matthew Dieckman, SonicWALL

‘Strategic Mobile Security: A Practitioner Panel’
Chenxi Wang, Forrester; Anil Karmel, Los Alamos Nat'l Lab; Terrell Herzig, UA Medical Center

‘The Composition of Mobile Security – Risks and Results’
Daniel Miessler; Principal Security Consultant, HP Application Security

‘Top 10 Mobile Risks’
Vladimir Jirasek, Senior Enterprise Security Architect, Nokia

‘Leveraging Mobile Devices for Strong Authentication’
David Mahdi, Product Manager, Entrust

You can view the full lineup and sign up to attend any or all presentations at http://www.brighttalk.com/r/Grz . This summit is part of the ongoing series of thought leadership events presented on BrightTALK(TM). I hope you are able to attend.

Tuesday, July 12, 2011

The KNOS Project: Secure Internet for Network & Cloud Clients

KNOS is a solution for the protection of internet-connected

KNOS provides a unique operating system and comprehensive application environment which CANNOT be infected or exploited and protects privacy as well as security. KNOS is a fully locked-down client system based upon BSD, the foundation of Macintosh OSX, secure military systems and secure servers in use by major entities.

KNOS provides a "secure lockdown" because nothing can ever be written to its read-only memory filesystem. KNOS leaves the existing computer hard disk completely untouched and fully protected because the existing hard disk is no longer connected to the network. KNOS is perfect for use on unsecured networks, by untrusted users including children or on public computers or networks. It provides military quality "high side" trust because it cannot be infected. Ever. With KNOS there is no need for internet "security" software which has failed to protect valuable machines and their content against the ever-increasing security risks on the internet.

KNOS also provides significant cost savings by eliminating the costs associated with cleanup and maintenance of infected machines in addition to significantly reduced software licensing costs. KNOS is the perfect answer for strained IT budgets and staffing levels and with its full complement of applications, client computers can be run solely on KNOS at even greater savings.

KNOS is intended for distribution by ISP's, IT Departments for their own users, and other situations where a mass distribution of our disks with specific application sets and portals is desired. KNOS is an excellent front end for "cloud" computing, remote access to institutional sites, portable computers in secure environments, as well as individuals who wish to protect their security and privacy in a world of ever increasing "zero day attacks" from "trusted sources."

Refer here for more details and here for demo about KNOS. You can get KNOS from here.

Monday, July 11, 2011

Biometrics Seen as SecurID Alternative?

Exploring Multifactor Authentication

RSA customers who feel victimized by last March's breach of the security vendor's computers have viable options that include continued use of the SecurID authentication tokens, those offered by competitors, or something entirely different: biometrics.

In March, RSA revealed intruders broke into its computers, exposing secret codes for its two-factor authentication SecurID token. Since then, RSA has been working closely with its customers to assure the safety of the product.

The proper precautions RSA provides could satisfy many SecurID user but there is an another option of switching to a competitors' product. Still, at the end of the day, the use of these technologies maintains the status quo. They let you do the same-as-usual type of security. If attacked once, and hacked once, it can certainly be done again. Another approach, would be to implement an alternative factor, such as biometrics.

The concept behind multifactor authentication is that the user provides at least two different factors - something the user has, such as a token; something the user knows, such as a password; and something the user is, such as a fingerprint. In the case of tokens such as SecurID, the factors are what the user has and knows. But users jittery about the security of the has factor could substitute it with the is factor, such as an image of the eye's iris or the sound of a voice.

The enterprise security expert points out that many users own smartphones that, with the right, inexpensive software, can scan an iris or record a voice to produce biometrics that can be employed for authentication. It's not something that can be easily copied from a forensic perspective. Biometrics are a strong play, and they're gaining a lot more acceptance in the industry. What do you think?

Friday, July 8, 2011

Microsoft BitLocker Administration and Monitoring (MBAM)

Enterprise solution which streamlines management

According to Microsoft, organizations around the world rely on BitLocker Drive Encryption and BitLocker To Go to protect data on Windows 7 PCs and portable storage devices. To make large-scale BitLocker implementations easier to manage, enterprises turn to Microsoft® BitLocker® Administration and Monitoring (MBAM).

Microsoft BitLocker Administration and Monitoring, enhances BitLocker by simplifying deployment and key recovery, centralizing provisioning, monitoring and reporting of encryption status for fixed and removable drives, and minimizing support costs.

Simplify BitLocker provisioning and deployment

Microsoft BitLocker Administration and Monitoring can provision BitLocker as part of your Windows 7 upgrade or configure BitLocker deployment to take place after the operating system is installed. Using the additional Group Policy controls in MBAM, it is easier for IT to provision BitLocker specific to their business needs. The controls are checked regularly at intervals set by an IT administrator and any changes are immediately infused.

Additionally, the hardware-blocking feature can be used to identify BitLocker-capable computers and exclude specific hardware that you don’t want encrypted.

Improve compliance

With out-of-box reports that detail compliance with corporate-defined BitLocker policies can get a better view of your compliance status for the organization or individual devices, and easily determine if lost or stolen devices were encrypted. IT staff can also create custom compliance reports using built-in SQL Server Reporting Services tools to show them just the information that they need to see.

MBAM also provides the ability to store BitLocker recovery keys in an encrypted database with granular access controls and creates an audit trail of who has accessed recovery key information, keeping this information protected and only accessible to the right people in the organization.

Reduce support costs
By reducing the burden on IT staff and making it easier for them to support end users, MBAM helps to reduce the support costs and gets the end users up and running quickly if a problem arises.

With a secure, web-based key recovery portal, it is easy for authorized help-desk staff to support end users if they need to recover their BitLocker enabled machine. By automating pre-BitLocker setup steps and making it easy for end users to perform basic tasks such as starting the encryption process and managing their BitLocker PIN—without providing users with administrator rights.

MBAM will be available in Q3 2011 and a beta version of Microsoft BitLocker Administration and Monitoring is now available for download here (Windows Live ID required).

Wednesday, July 6, 2011

Webcast: Cloud Security and Smart Security

Security in the cloud – where are we now?

Cloud security is now a very different proposition compared to a year ago with expanding access points, more personal devices, and increasingly sophisticated threats.

In light of this, I thought you might be interested in SC’s upcoming webcast which will give you a valuable, real-world update on where we are today.

The full session and sign up can be found at http://www.scwebcasts.tv.

I have pasted a few more details below though for your reference.

SECURING THE CLOUD - LOCKING DOWN 2011’s MULTIPLE ACCESS POINTS

Going live on 14th July 10:00 am ET / New York, 3pm / London @ http://www.scwebcasts.tv

The webcast will give you tools to:
  • Facilitate strong end user and multifactor authentication in public and private clouds to secure identity and protect your business
  • Keep up to date with current cloud technology and gain architectural perspectives to manage user activity and log ins
  • Gain visibility across the multiple layers of cloud security and assure data protection and ownership in storage and encryption
  • Integrate outsourced IT services with in-house programmes to maximize staff productivity and reduce costs
You may also be interested in another 2 of SC’s recent projects which have proved very popular with group members:
  1. SC WEBCAST: Smart Security for SMEs: Key Cyber-Threats And How To Tackle Them – Going live on July 12 at 10:00 am ET / New York, 3pm / London at http://www.scwebcasts.tv.
  2. SC STUDIO SHOW: The Risks and Rewards of Archiving – hard-hitting video available now at http://www.scstudio.tv.
If you can’t make the live date of the webcasts, you can of course watch them on-demand in the archive at your leisure at http://www.scwebcasts.tv .

As always, feel free to get in touch with any questions.

Monday, July 4, 2011

Hole in Google Chrome that granted unauthorised access to gmail accounts

Web extensions to become a new attack vector

A penetration tester has exploted a hole in Google Chrome that granted unauthorised access to gmail accounts.

WhiteHat Security researcher Matt Johansen identified the vulnerability in a Chrome OS note-taking application. He disclosed the hole to Google which patched it and gave him US$1000 as part of its Chromium security initiative.

Johansen told Reuters he intercepted data travelling between a Chrome browser extension and the Google cloud. Google has not yet revealed details of the security hole which Johansen plans to release at the Black Hat conference in Las Vegas this year.

Google extensions, written by third party software developers, were a ripe target for attack because they were granted more privileged access rights to Google cloud data than what the browser offered to web sites.

WhiteHat security detailed in a 2007 research paper a series of web application security vulnerabilities that could also be used to attack web browser extensions in Chrome and Mozilla FireFox.

Chrome OS director Caesar Sengupta said there are "significant benefits to security" by storing apps within the browser.

Sunday, July 3, 2011

Top free Firewalls for Windows

Looking for a top free firewall for Windows 7?

Here you find top free firewalls for Windows 7 including, but not limited to, the Windows 7 built-in firewall. There used to be much more free firewalls software for Windows until Microsoft built in a firewall in its Windows XP operating system. That Windows integrated firewall has been beefed up in Windows Vista and further improved in Windows 7.

Free firewall for Windows 7
  • Ashampoo FireWall
  • Comodo Firewall
  • Online Armor Firewall
  • Outpost Firewall
  • PC Tools Firewall Plus
  • Sunbelt Personal Firewall Version
  • VirusBuster Internet Security Suite
  • Windows 7 Firewall Control
  • ZoneAlarm Basic Firewall
References

Comodo Internet Security - http://personalfirewall.comodo.com/

Online Armor Free - http://www.online-armor.com/products-online-armor-free.php

Outpost Security Suite - http://free.agnitum.com/

PC Tools Firewall Plus Free Edition - http://www.pctools.com/firewall/

VirusBuster Internet Security Suite - http://www.virusbuster.hu/en/products/home-users/vb-internet-security-suite#rendszerkovetelmeny

ZoneAlarm Free Firewall - http://www.zonealarm.com/security/en-us/zonealarm-pc-security-free-firewall.htm

Wednesday, June 29, 2011

New FFIEC Guidance will help to reduce the increasing security threats?

Final FFIEC Authentication Guidance Issued

The
Federal Financial Institutions Examination Council has formally released the long-awaited supplement to its "Authentication in an Internet Banking Environment" guidance, which was first issued by the FFIEC in October 2005.

Formal assessments for compliance with the
new guidance will begin in January 2012.

The purpose of the supplement is to reinforce the risk-management framework described in the original guidance and update the FFIEC member agencies' supervisory expectations regarding customer authentication, layered security, and other controls in the increasingly hostile online environment.

The official supplement highlights the need for:
  • Better risk assessments;
  • Effective strategies for mitigating known online risks;
  • Improved customer and employee fraud awareness.
In a news release about the official update, the FFIEC says growing sophistication of online threats have increased risks for financial institutions and their customers. "Customers and financial institutions have experienced substantial losses from online account takeovers," the FFIEC states. "Effective security is essential for financial institutions to safeguard customer information, reduce fraud stemming from the theft of sensitive customer information, and promote the legal enforceability of financial institutions' electronic agreements and transactions."

The FFIEC says it will continue to work closely with financial institutions to promote security in electronic banking. Examiners have been directed to formally assess financial institutions under the enhanced expectations outlined in the supplement beginning in January 2012.

The FFIEC is made up of the following regulatory agencies:
the Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, National Credit Union Administration and Office of Thrift Supervision.

Please refer here to read the changes in the new FFIEC guidance.

Monday, June 27, 2011

Ten Rules for Cyber Security

Is these Ten Rules should be addressed in a comprehensive legal approach to cyber security?

Before the
Estonian incident, organisations tended to treat their risks and arrangements in isolation. Cyber security was merely the sum of individual contingency plans having little to do with more temic risks.

The spectrum of cyber conflict ranges from breaches of internal policy or regulations (not patching software, for example) to breaches of legal obligations (such as not reporting illegal activity) to crime to national-security threats to outright cyber warfare ("cyber armed attack").

Ten rules focused on issues and working solutions arising from discussions among experts or in the course of cyber-incident handling can be identified:

1. The Territoriality Rule
2. The Responsibility Rule
3. The Cooperation Rule
4. The Self-Defence Rule
5. The Data Protection Rule
6. The Duty of Care Rule
7. The Early Warning Rule
8. The Access to Information Rule
9. The Criminality Rule
10. The Mandate Rule

In
this paper, the Author analyses these ten rules that outline key concepts and areas that must be included or addressed in a comprehensive legal approach to cyber security. They are intended to raise awareness about existing legal complications involving cyber security and the ways to overcome them, to serve as a focus for debate and coordination within and across disciplines, and to inform wellgrounded proposals for additional legislation on the international level.