APT Threats Today Need a Different Kind of Response

B. Ostergaard
B. Ostergaard

Summary Bullets:       

  • The ‘Flame’ advanced persistent threat (APT) is invisible to commercial AV defences and may lie dormant for years.
  • Combating APTs may create a new role for the ITU and further international anti-malware efforts.

The latest news on the (often purported to be state-sponsored) APT front is a massive piece of spy software, dubbed ‘Flame,’ which seems to have been around for many years – at least since 2010.  The worm was discovered by accident when security vendor Kaspersky was looking for another mystery APT dubbed ‘Wiper,’ which has been deleting files on servers in the Middle East for some time.  Much like earlier APTs such as ‘Stuxnet’ and ‘Duqu,’ Flame exploits software and hardware vulnerabilities that evade any of the known AV defences and infects desktops and servers in multiple ways (USB, LAN, drive-by etc.); similar to these other APTs, it appears to harm or spy very selectively, so it may reside dormant on a large number of Windows PCs.  Flame is different in that the remote controllers can install different modules (e.g., taking control of the PC’s microphone to record conversations) on infected machines depending on what kind of information the controllers want to steal.  So, the net-net is we do not know if our desktops or data centres are infected, and consequently whether they are actively or passively spying on us and stealing our data.  We might seek some comfort in the belief that this malicious (often Middle Eastern) activity is politically rather than commercially motivated, but state-sponsored industrial espionage is an obvious use as well. Continue reading “APT Threats Today Need a Different Kind of Response”

Time to Bridge the Security Divide That Separates CISOs and Directors/CEOs

P. Musich
P. Musich

Summary Bullets:

  • There is a huge gap between the views of senior executives/boards of directors and CISOs when it comes to managing cyber risks
  • To bridge that divide, CISOs need to speak the language of business risk, while executives must remove the blinders that keep them from seeing the depth of the problem.

A couple of recent studies that came to light underscore the very large disconnect between boards of directors/CEOs and the CISO when it comes to managing cyber risks. In the “Governance of Enterprise Security: CyLab 2012 Report,” conducted by Carnegie Mellon CyLab for RSA, some very disturbing findings came to light from the energy/utilities sector.  That study, scrutinized whether boards and CEOs were carrying out fundamental cyber governance tasks and discovered that 71% of those boards rarely or never reviewed privacy and security budgets, 79% rarely/never reviewed roles and responsibilities, 64% rarely/never reviewed top-level policies and 57% rarely/never reviewed security program assessments.  This, in a highly regulated and essential industry. Continue reading “Time to Bridge the Security Divide That Separates CISOs and Directors/CEOs”

Mobile Operating System Choice

A. Braunberg
A. Braunberg

Summary Bullets:

  • Nobody ever got fired for buying BlackBerrys. Embrace device diversity but incentivize best practices

Anyone old enough to remember the phrase: “Nobody ever got fired for buying IBM equipment”? If uttered by an IBM sales person it could be considered classic fear, uncertainty and doubt (FUD). But it was based on an industry axiom at the time: IBM hardware was the known quantity and the safe purchase. For a long time, nobody got fired for buying BlackBerry either, but the ‘consumerization of IT’ has thrown those old assumptions out the window and organizations are back to really taking a hard look at the features of each mobile OS and trying to keep the FUD at bay. I sat in a panel at Interop last week that basically asked the question: is it safe to hitch your wagon to any one mobile OS, BlackBerry or otherwise? Continue reading “Mobile Operating System Choice”

Hyper-Competition Returns to Enterprise Networking

J. Caron
J. Caron

Summary Bullets:

  • Huawei’s entrance is making the news, but networking market competition has been increasing across the board from a number of suppliers.
  • Increased enterprise networking competition sharpens the minds of suppliers and certainly benefits buyers.

The past two years have seen a remarkable resurgence in competition within the market for enterprise networking technology.  While there has always been a fairly strong collection of suppliers in this area, the emergence of Cisco as the dominant market-share leader has relegated true competition to those vying for small percentage points gained in geographical, segment or vertical niches.  Now, however, with transitions taking place in terms of multi-gigabit bandwidth demands, wireless integration and data center architecture, all players in the market sense a new opportunity to challenge the incumbent. Continue reading “Hyper-Competition Returns to Enterprise Networking”

Interop: NAC is Back

A. Braunberg
A. Braunberg

Summary Bullets:

  • Several vendors have announced enhanced network access control (NAC) products for addressing BYOD
  • The Trusted Computing Group announced a new revision to an important NAC standard (TNC IF-MAP)

I spent the week in Las Vegas at Interop and one of the meta-themes at the event was the issue of how to deal with consumerization of IT and the associated business policy of allowing employee-owned devices on corporate networks. (i.e., BYOD). As I have noted before on this blog, consumerization of IT has far-ranging impacts on enterprise IT requirements and product development strategies. This includes products being enhanced to support the increasing traffic requirements inherent in broad deployment of mobile devices, but it also includes old products finding new life when applied to mobile use cases. A great example of the latter is the re-emergence of NAC to address consumerization of IT. Continue reading “Interop: NAC is Back”

Telephone DoS: Who Are You Gonna Call?

B. Ostergaard
B. Ostergaard

Summary Bullets:

  • Recent hacktivist attacks have been aimed at the corporate phone lines, criminal hackers will launch combined DDoS/TDoS attacks
  • The good news is that MSSPs are bringing on TDoS mitigation solutions

On April 12, 2012 a hacktivist group with the ominous name ‘TeaMp0isoN’ targeted the UK counter-terror agency, MI6, claiming to be motivated by the recent decision at the European Court of Human Rights allowing suspected terrorists to be extradited to the United States. However, the attack was not the usual DDoS barrage against the MI6 Web presence. Instead, the group created a wall of phone calls for a period of 24 hours, which meant nobody else could get through. They used a script based on the Asterisk software with a SIP protocol to make calls to the agency’s offices non-stop, basically launching a telephone-based denial-of-service (TDoS) attack. Continue reading “Telephone DoS: Who Are You Gonna Call?”

Vertical Target: Financial Services Firms Under Threat

A. DeCarlo
A. DeCarlo

Summary Bullets:

  • The nature of distributed denial of service (DDoS) attacks is evolving with more frequent and intense events of shorter duration now the norm
  • Cyberattackers are training their sights on high-profile targets such as financial services but no organization is immune

The threat landscape is in a constant state of flux as hackers’ strategies shift and the targets of their attacks change.  DDoS attacks offer one very revealing window into how the threat environment is changing.  Incidents tracked by DDoS vendor Prolexic’s Engineering and Response Team (PLXsert) in Q1 2012 show that while the number of attacks remained relatively constant this quarter and last, the frequency of incidents surged 25% from Q1 2011.  Financial firms proved a particularly attractive target for DDoS attacks:  In Q1 2012, financial services firms were inundated with 65TB of data and 1.1 trillion packets of malicious data leveled against them during DDoS attacks, up from 19.1TB of data and 14 billion packets the previous quarter.  This represents an almost 80-fold increase malicious traffic volume.  Continue reading “Vertical Target: Financial Services Firms Under Threat”

Security Worries: Friday the 13th Edition

A. Braunberg
A. Braunberg

Summary Bullet:

  • Luck favors the prepared.
  • Prepare for breaches through better visibility and forensic tools.

In Western cultures, Friday the 13th is considered a particularly unlucky day.  The superstition is of relatively recent vintage, though it seems to derive from the separate but long-standing considerations that 13 is an unlucky number and Friday is an unlucky day.  Security folks are not a particularly superstitious lot, but I think we can all agree that we can use all the luck we can get.  However, any discussion about luck brings to my mind a famous quote that is usually remembered as “Luck favors the prepared (actually, the quote by Louis Pasteur is “Chance favors the prepared mind”). Continue reading “Security Worries: Friday the 13th Edition”

Taking Your BYOD on Easter Vacation – Securely

B. Ostergaard
B. Ostergaard

Summary Bullets:

  • With the holidays, we take corporate data on our mobile devices to exotic locations.
  • We are not always the best people to ensure the safety of that data.

As we all get into the Easter vacation spirit and pack our bags for holiday destinations, the mobile device and the tablet are right there with us. However, not everyone heading to a sunny destination has the same state-of-the-art mobile gadgets as the average American or European traveller has these days, and a lot of devices with corporate data on board are about to change hands, albeit illicitly.  So, what should a mobile device ‘sun screen option’ provide us holiday-makers with to protect our data, and who should be managing the device from a corporate perspective? Continue reading “Taking Your BYOD on Easter Vacation – Securely”

Enterprises Should Emphasize Secure, Not Rapid, Application Development

P. Musich
P. Musich

Summary Bullets:

  • The cost of breaches due to poorly designed applications is reaching a tipping point that will force enterprises to re-evaluate their development priorities.
  • The need for greater collaboration between development and security groups as well as better education and training in secure code development has never been greater.

The IT industry is getting to a point in the evolution of cybercrime where it will have to truly pay more attention to secure applications development.  Right now developers are not properly trained or incented to create secure applications – they are incented to write more code that addresses specific business functions.  Enterprises do not pay enough attention to how well systems and applications can stand up to malware, and that inattention has come back to haunt them. The reliance on bolt-on security—security that is largely an afterthought to the full lifecycle of enterprise applications—is the norm.  And the constant search for vulnerabilities, notification of such vulnerabilities, patching and so on is costly, complex and error prone.  Two of the largest breaches reported in 2011—the Sony and RSA breaches—were the result of unpatched software. (It should be noted that the RSA breach cost the company $66 million, and one estimate on Sony’s damage went as high as $1.25 billion.)  It should be broadly understood at this point in time that it is much more expensive to remediate vulnerabilities after applications are released into production than it is to fix those issues during the design phase. Continue reading “Enterprises Should Emphasize Secure, Not Rapid, Application Development”