More Content - Including Podcasts

Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Friday, December 16, 2011

Hacking Motivations - Where Following the Money is Going

Was a time, way back when I first got into IT, that the primary motivation for hacking was notoriety, infamy, and the occasional retribution for public flaming.  That said, there were certain financial motivations and corporate espionage aspects in those days also.

And really, the prime motivation for people to do anything is always money. As they say on the innumerable crime procedural dramas, "follow the money."

What is interesting is how things are evolving, or more accurately, being exposed, these days with respect to where following the money takes you.  We always assume hackers are targeting personal financial and health data for the purposes of identity theft.  More recently, cyber-terrorism concerns are on the rise with SCADA attacks coming to the forefront in the US and elsewhere. And these are absolutely valid, as well as the continued and large risks of corporate information being accessed or destroyed for corporate espionage or disgruntled employee revenge.

But consider a BBC Radio 4 documentary exposing how UK private detective agencies are using hacking skills to expose potential news stories that they are bringing to certain nameless major media outlets.  And if you think that activity is limited to those rascals over in the UK, I encourage you to replace your head in the sand immediately to continue your blissful ignorance.

How does this change what we do as security and privacy professionals?  Again I'll go to my standard refrain of the urgency and priority of IT security and privacy policies and governance in each of our organisations.  But what this "new" information gives us IT security professionals is additional support tin our budgetary discussions.  If we want to do our jobs, and do them well, the reality is we are competing for each dollar (particularly this time of the year) with every other IT service related initiative and operational need.  We need to make our business case concise, and tailor our plans to address the highest risk areas first.  If you work somewhere with a relatively low probability for natural disaster or civil unrest, then your local media is going to be busy trying to get stories that make them money.

Can they make money off revealing information about your organisations operations or strategies? Then that is what they will be interested in doing, and don't doubt they are already looking for ways in.

Thursday, December 15, 2011

Social Media - It's for Everyone, But Not Everyone is for Social Media.

Recent events in the professional hockey world have me thinking about SoMe at work.  Now, while I do daydream about hockey occasionally at work, this is a more direct (please hear me out) connection than you'd think.

Chicago Blackhawks winger Dave Bolland recently got caught up in the atmosphere of a live interview, and made a series of disparaging remarks about the top players on my home team. "So what?" you say, "professional athletes talk trash often." And I'll be the first to agree.  What got me thinking here though, is how quickly a few comments, thrown out without forethought or apparently malice (see article about Bolland "recanting" his comments the next day) went from radio to Twitter, Facebook, and numerous other social media channels.  The net result? Well, Bolland will have to play the Canucks on January 31. He also now has cemented a reputation for himself, that may be great with his fans, and for whatever reason, this kind of behaviour seems idolized in the celebrity world.

Now picture an employee at any public or private institution with access to a computer, and no corporate controls (read: policies more so than firewalls) around social media. What kind of damage could that employee unleash with a flippant comment about the organisation, a competitor, or worse, a valued partner or customer?

And how do you repair that damage once done? Once the post goes out on LinkedIn, Twitter, YouTube, Facebook, or any other popular channel? It's been clearly illustrated that companies that try to back-track and battle back against negative social media just look like Goliath, no matter how wronged they have been. Hey, they are the 1%, as the OWS gang would say.

The best defence is a plan. Like with all privacy and security matters, you need to understand the risk, and take the reasonable steps to mitigate.  Are we going to have 100% prevention? Nope.  But if you have social media policies drafted up (like these shared by SocialMediaGovernance.com), and a workforce educated about the use of SoMe at & about work, you have a mitigation plan.

Wednesday, December 14, 2011

Medical Education Networks Must Be Good Neighbours

This story makes an understated point for us managing medical education and research networks.

While we may not operate or support the systems on the clinical networks, we operate immediately adjacent to them.

As our educators and researchers bring devices closer between these networks, we need to illustrate leadership, good faith, and act as responsible neighbours and ensure systems under our management are as protected as possible, and users as educated as possible. This in turn lightens the load for our colleagues managing the clinical networks immediately responsible for patient care.

Malware shuts down hospital near Atlanta, Georgia
http://nakedsecurity.sophos.com/2011/12/13/malware-shuts-down-hospital-near-atlanta-georgia/

Monday, April 12, 2010

Security Perspective on Social Networking

Facebook, Twitter, LinkedIn... all words that can make the IT manager's skin crawl. The simple solution is to block the URLs at the firewall; once people are plugged in at the office, too bad, no social networking on work time. I think that's the way most IT manager's would prefer it. We're a bit of a draconian bunch, largely because this is the kind of stuff that just ends up making problems for us.

But is this the best approach? Other managers in the organisation may be concerned about morale, and want these sites available to their staff - well we certainly don't want to start creating exception rules in the firewalls or network compliance tools to manage which users get access and which don't. More business centric reasons exist as well; some business units may want to use these sites for market research, sales/marketing, recruiting, and other functions.

I've recently seen some interesting and creative use of combining the three main social media sites for marketing and recruitment processes. An organisation I was meeting with last week was telling me about how they use Facebook & Twitter accounts to monitor customer satisfaction with their products and services, and respond quickly to concerns from their customers or deal with urban myths about them that get propagated through these media. From a business perspective, that approach makes a lot of sense. This same organisation also uses individual LinkedIn accounts from their recruitment professionals as a mechanism to reach out to prospective new employees and contractors, and ties it all together with Facebook & Twitter promotion of new positions and recruitment drives.

So in this scenario, the IT team has to work with the other business units (sales, marketing, and HR) to make sure they can get timely access to the tools, ensure that they maintain corporate image and privacy, and verify the content of those sites - both what is "going out" and what is "coming in."

Where do you start?
Ensure first that the leaders of the organisation understand the challenges for the IT team, possible budget implications, and risks.

For certain, a review of existing organisational IT usuage policies. First off, so you have them in place? Secondly, have they been distributed (recently) and signed off? And lastly, does the language (hopefully not too "lawyered up" so that people understand what they are committing to) apply to this kind of scenario?

What questions should you ask?
Once you've established who's allowed to do what, it becomes a question next of enforcing the rules while allowing the business functionality that's been agreed to. Now we get into the business analysis side of the equation. Understand clearly what the business needs are so that your team can work with the rest of the business to deliver the solution that makes the most sense.

You'll need to look at technical considerations, some of which might be:
Will Twitter use be via the web interface, or 3rd party apps like TweetDeck?
Will you allow all Facebook apps, or try and block some (like games, etc.)?
Will this be allowed corporate wide, or group by group?


Who's already looking down this path?
There are developers such as Teneros and SocialWare who are developing middleware-like apps that monitor content for these sites, to ensure that the organisation knows what is going out or coming in. These tools have some limitations, so it's best to research the options closely, but it's good to know you HAVE options! SocialWare is particularly interesting to me and likely may be the subject of a future blog posting.

Check through your personal network (errr, via LinkedIn?) to see who else is in your shoes and dealing with this kind of challenge today. I was surprised to learn recently how many organisations haven't even started to deal with this from an IT perspective yet. I know we're busy, but...

As always, your feedback and input on this article is greatly appreciated; reply with your thoughts and I'll post them for continued conversation.

Wednesday, March 31, 2010

Patch Released to Remediate More Day Zero Exploits for Internet Explorer

A critical cumulative security update for MS Internet Explorer was released yesterday (March 30) as noted in security bulletin MS10-018. This patch deals with 10 (count 'em, TEN) additional vulnerabilities within the browser, 9 previously undisclosed and one that was made public. The one known vulnerability is specifically for IE 6 & 7, although the patch in general is advised for IE 5.01 through 8, and while MS rates this security patch as "moderate" for IE 8 on servers, why would you take a chance these days?

What are the Risks?
The known vulnerability for older versions of IE, referred to by the Common Vulnerabilities and Exposures group as CV-2010-0806, was first described in an older Microsoft Security Advisory and is a vulnerability that could allow remote code execution; as for the impact of the rest of the undisclosed vulnerabilities, Microsoft states the following:

"The most severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights."

Recommended Actions
Microsoft rates this patch from important to critical, depending on your desktop version of the browser. If you are leveraging automatic updating, this patch will get pushed to your end-users' desktop systems; if you manage your updates, be aware of this one and take the actions you judge as appropriate for your organisation to ensure servers & desktops using Internet Explorer are protected.

What Next?
This security flaw in the code for the browser seems to be oriented again around risks developing from phishing type attacks. IT managers & IT security professionals have to take this account in understanding the risk level and possible next steps. Applying the patch seems to be a given, looking at changing the default browser used in your organisation - well I'd be surprised if you weren't already considering that but there are usually many ramifications associated with that, including end-user training and most commonly used sites & applications.

Let's face it, for most of us there's just no getting away from IE completely.
This also brings forward the considerations around the social engineering side of the issue and how much of that we can control by managing where our users can go to on the Internet, and caching/pre-qualifying sites before users first access them.

In the meantime we contain what we can by educating our users, protecting the network as best we can without crippling the users, and staying as well informed as we are able. Hang on folks, this is going to continue to be a bumpy ride; hopefully I and other like-minded professionals can keep you educated on what is happening beneath the hype.

Friday, March 26, 2010

Five Top IT Security Trends for 2010

#1 Antiviral Products Move Away from Local Signatures
With the rate that variants of viri, trojans, and other attacks are coming out (approx 50,000 per day) signature based AV tools just can't keep up without bogging down the systems on your corporate network. So what are the AV companies doing to deal with this?

The leading AV companies are making a shift to where only a small subset of signatures are downloaded to your PC/network. The bulk of the testing happens "in the cloud" where the AV companies use cloud-based technologies to identify threats and note sites/exploits that need to be blocked and send that info to your AV clients.

The philosophy behind this is that there are basically two types of attacks; social engineering (downloads, phishing, etc) & computer attacks (exploit involved - identifies & exploits a vulnerability pre-existing in your computer).The theory is that they only need to worry about protecting against the vulnerabilities, if they are effectively dynamically blacklisting the social engineering risks via their cloud-based work.

#2 Increased Use of Application Whitelisting
The concept of whitelisting is that you block everything except a concise list of sites, addresses, or ports you wish to allow access to. This technology is being led by companies like Bit9 who have been working in this area for some time. Not a good technology for home users or large organisations to use for desktops because of the nightmare in keeping the list up-to-date, but this is a great tool for appliance-like technologies - ATMs, or any other purpose-driven technology. It is also worthy of consideration for use on servers.

#3 Enhancements in Firewall Rule Optimisation
More and more IT Managers are finding that they are struggling to keep pace with the rate of change they must apply to their firewall rules. This process also leads to omissions and redundancies in the firewall rules and ACLs. Firewall vendors and third parties have been releasing tools like Skybox's Firewall Compliance Auditor that bridge simply optimising your rules for increased efficiency and now start ensuring that they meet compliance rules .

#4 Increased Social Engineering via Social Media
Social Media sites like Facebook, LinkedIn, and others are continuing to become rampant hunting grounds for cyber-crooks, whether they are associated with organized crime or just script kiddies.

Creative cyber villains will continue finding new ways to exploit people that they'd consider high-value targets - this doesn't necessarily mean wealthy people; but instead it means a combination of the "low hanging fruit" - the people who seem to put a lot of information about themselves and their employers out on the Internet - and people who can be identified as working in organizations that are targeted for attack.


#5 Continual Evolution in Regulatory Compliance
Certainly not last but it rounds off this list as an important topic in computer security for 2010. Regulatory compliance continues to be a pressing topic for the leaders of our various organisations and therefore also for IT managers. As an IT manager, there are some key things that compliance should mean to us:
  • audits & audit trails in place & working
  • documentation showing current state of network & security (i.e.: configuration management)
  • change management processes in place & operating
  • clear understanding (& documentation) outlining key business risks how those risks are managed

For more in-depth analysis of these topics please contact itManageCast for a copy of the whitepaper titled "Top IT Security Trends for 2010."