Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

Friday, October 21, 2016

Cyber Security Month: Looking for Answers Part II?


NEW YORK METRO JOINT CYBER SECURITY CONFERENCE
NY Metro Joint Cyber Security Conference
I recently attended the Third Annual New York Metro Joint Cyber Security Conference (http://nymjcsc.org/), held in mid-town Manhattan.  Security conferences are now a dime-a-dozen, but this event is unique in that it is a collaborative effort developed by a consortium of eight leading security, audit, and risk focused, NY metropolitan area, not-for-profit professional associations. Each organization brings its best to the table, creating a rare combination of expertise and diversity of talent.  

There were many informative sessions – some standing room only – but some of the greatest value was in the interaction with the other professionals.  For example, in sessions, we learned that security professionals must adopt the language of Directors to be understood by a Board.  The Internet Security Alliance is even working on metrics for Boards to use in evaluating security risks and controls.  But, after all the talk of security maturity models, cyber risk management frameworks, and “cyber balance sheets,” CISOs (Chief Information Security Officers) will tell you that Boards still “just don’t get it” and don’t seem to be that interested.  Perhaps CISOs as a group aren’t very good at explaining how greater focus on preventing and mitigating cyber threats is in the self-interests of very diverse sets of Directors.  Maybe, despite approaching the problem with the best of business concepts and lingo, CISOs just don’t have influence with Directors.  (As one CISO put it, “formulas don’t work.  Relationships do.”) Or, perhaps it’s because, as one speaker put it, there is not a single instance of a cyber breach that has been demonstrated to have a material impact on a company.  In the end, the surprising takeaway may not be that CISOs are becoming more adept at speaking the language of the Board, but that some Boards are beginning to listen at all.
This sold-out event offered excellent, high-quality presentations with plenty of actionable content.  If you weren't able to attend, you can still benefit from the recordings of many of the sessions.  They are available at http://livestream.com/internetsociety/nymjcsc/.  Presentation slides may be found at http://tinyurl.com/z3fz44d. I would highly recommend reviewing them.
And, don't forget to sign up early for next year's conference.  It's one of the best values in information security education that you'll find anywhere.  Follow www.nymjcsc.org and @NYMJCSC for details.

Phil Froehlich is Chief Operating Officer of Integris Security and a member (who listens) of the Executive Board of New York Metro InfraGard.

Cyber Security Month: Looking for Answers: Part I?


LONG ISLAND BUSINESS NEWS
LI Business New Cyber Conference
Hilton, was once again informative, invigorating and enrolling. With a number of panelists participating, including both the Integris Security CTO, Blake Cornell, and United States Congressman US District 1, Lee Zeldin, nearly 100 individuals attended the breakfast event.
Topics of interest had included Cyber Terrorism, Business Continuity, Government Legislation, Small Business Best Practices and other wide ranging topics. Some of the information shared, information that attendees can use in their day to day business operations.
A goal of Integris Security CTO, Blake Cornell, was to provide “simple and sound information that is short and sweet” further stating that “if your employees are untrained then no amount of technical information will help them understand. You can’t make them understand but you can help them understand”.

Blake Cornell is the CTO of Integris Security LLC.

Sunday, October 16, 2016

Ransomware: Osterman Research Survey for Malwarebytes

https://www.integrissecurity.com/index.php?aboutus=JosephConcannon
Joseph Concannon
Today I receive a note from a friend who said he had fallen victim to a Ransomware attack.  So I figured its a good time to review some up to date expert research.  This review is a product of Integris Security LLC and we gladly share this with the community.

First, Ransomware is a global issue effecting enormous sized companies as well as my local friend.  Ransomware is a global threat/problem.  We must recognize the size and depth of this issue.  A survey was conducted during June of 2016 that included CIO's, CTO's, CISO's and other executives.  The survey included 165 corporations in the United States as well as companies from around the world.  39% percent of the companies that were contacted were impacted by a ransomware attack in the U.S. alone.  This is truly a global problem and issue but let's keep the focus here at home.  The report shows the various priorities by country.

The FBI talks about Ransomware as a, "an insidious type of malware that encrypts, or locks, valuable digital files and demands a ransom to release them". Integris Security LLC evangelizes through its President, Joseph Concannon the value of Risk Management and the ongoing development of a solid business continuity program.  Concannon states: "this isn't a once a year review, this is a daily, weekly, monthly, quarterly and semi-annual program.  Risk Management opens the eyes of the Executive Team and Boards of Directors".

Second, it comes as no surprise that the survey results identified healthcare and financial services industry as the prime target.  Each are highly dependent upon business critical information according to Osterman Research, Inc.Cyber criminals lay and weight until they find the prime target for an attack; one which they can not recover from due to the lack of ransomware fighting software.  In Osterman's survey U.S. companies were most likely to fall victim to a ransomware attack (79% fell victim according to the survey).

Third, Ransomware ranks the fourth highest security concern for senior executives in the United States as surveyed by Osterman Research, Inc., and more:

 U.S. organizations are also more likely to place a high or very high priority on investing in education and training about ransomware for their end users; and for investing in resources, technology, and funding to address the ransomware problem.

Note well: What the Osterman Research reveals is the power play between tenured industry executives and newly appointed CIO's, CISO's, CTO's learning the mine field of budgeting.  Where do these technology executives make the push to gain budget for their projects and can they convince business unit managers to join their team?  Who pays for training and education and how does that weigh in the balance of getting things done?  Here's how its playing out so far:
Somewhat ironically, however, U.S. organizations are also the least likely to have implemented any sort of ransomware training for their end users, and are among the most likely to offer only minimal training when they actually do so.  U.S. companies rate Ransomware as a high or extremely high priority, unlike their European counterparts in Germany and the UK or Canada which consider it less of a threat. 
Yet the training dollars in the U.S. continue to lag behind.   

The survey that I am reviewing is called, "Understanding The Depth of The Global Ransomware Problem" a report promoted by a company called Malwarebytes
The perceived importance of regular, on-premises backups as a ransomware-recovery tool is quite high among U.S. and German organizations, but somewhat lower among the organizations we surveyed in Canada and the United Kingdom. However, Canadian and UK-based organizations were more likely to use regular, cloud-based backups to recover from ransomware. Other capabilities in place to address ransomware included on-premises ransomware-detection solutions (highest penetration in the U.S.), network segmentation (highest in Germany), and air gaps between data stores and the Internet (highest in Canada).
At Integris Security LLC we point out that segmentation and air gaps are important as well as on-premises backups NOT connected to the network you are backing up.  Strong passwords that are changed every 90 days.  Here are the top 15 Cyber Security Precautions to follow.  Here are some very good tips for enterprise environment security teams to review (FBI):

Here are some tips for dealing with ransomware (primarily aimed at organizations and their employees, but some are also applicable to individual users):
  • Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
  • Disable macro scripts from office files transmitted over e-mail.
  • Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.

For those at home we strongly recommend backup on USB stick, or other storage drive with proper security "on board" to assess the devices health each time the device is accessed.  Saving important documents to a computer is a thing of the past.  Time to think 2016 and the threats that come with the technological age we live in.  Store important documents in a safe deposit box (whether in paper or USB or storage drive or other form).  If its important, then take the extra security steps.

https://www.stopthinkconnect.org/STOP THINK CONNECT is the U.S. Department of Homeland Security Campaign promoted during Cyber Security Awareness Month (October each year).  However, the evil email attachment continues to lure an seemly endless waterfall of users into the brink.  Nothing beats education and awareness in preventing the lost of your computer to a cyber attack.  While on the computer remember you are not in your living room.  You are in the "Wild West" and everyone's your friend.  You wouldn't leave your front door open at night, so don't leave your computer open either.  
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Wednesday, December 3, 2014

The Rear View Mirror

Typical in the information technology sector everyone is always focused on what’s next, the latest, hottest new application, the coolest mobile telephone and of course the work around that just makes life a little easier.  Not to be ignored are all those newly fashioned functions and features. Technology at the speed of life forever changing our lives for the better, right?  Forward looking for ever.

2014 hopefully has hopefully taught us some very important lessons that should not be ignored even if we were not directly impacted.  A look in the rear view mirror can sometimes be very revealing.  We are so focused on what’s coming directly ahead of us that we refuse to see what’s going on right behind us.  So for 2014 let me list a couple of things which could have made this a better year in the security space.

Network segmentation: You can’t get there from here should be the mantra, no? Did we learn anything this past year? Network segmentation is the act or profession of splitting a computer network into subnetworks, each being a network segment or network layer. Advantages of such splitting are primarily for boosting performance and improving security.   Please review a great eWeek article clicking here.

Service Level Agreements: Service agreements are important and a quick web search can be helpful to identify some key questions for developing such important tools for your company. The Outsourcing Center has developed ten key questions for developing effective service level agreements. It’s a solid read and you’ll find plenty of similar research on the web. A service-level agreement (SLA) is a part of a service contract[disambiguation needed] where a service is formally defined. Particular aspects of the service - scope, quality, responsibilities - are agreed between the service provider and the service user. A common feature of an SLA is a contracted delivery time (of the service or performance). As an example, Internet service providers and telcos will commonly include service level agreements within the terms of their contracts with customers to define the level(s) of service being sold in plain language terms. In this case the SLA will typically have a technical definition in terms of mean time between failures (MTBF), mean time to repair or mean time to recovery (MTTR); identifying which party is responsible for reporting faults or paying fees; responsibility for various data rates; throughput; jitter; or similar measurable details. {Attribution: Wikipedia}

Too big to fail: While not at all a technical term your company would do well to heed this warning. No company is too big to fail. No one. In our recent newsletter we talked about the breach of the week. The roadway is littered with companies failing over and over again until everyone in the industry is just tired of hearing of another breach. The breaches become “white noise” a distraction from the good work being performed by many security professionals in the field. Fight complacency, challenge everything and everyone with respect and “ASK Questions”. It won’t make you popular but it will certainly make you a very, very valuable employee.  Please read the ARS Technica article   HERE because it puts good perspective of what can happen after a breach. 

Alarms: Alarms are invitations that are yelling out, “come investigate me” I’m making noise and need your direct undivided attention. Please don’t ignore alarms. The story goes like this: Hey did you hear that alarm go off? Yeah, I’m getting a cup of coffee – you want anything? Hey, maybe I’ll come with you. Great! How many times do we ignore the obvious? Alarms are put in place for a reason to warn us, right? If the alarms are not configured appropriately and are creating noise, then someone has to go in and make a determination to turn them down and accept the consequences or turn them up and act each time they alert. 

Egress Filtering: Is that a freight train of information running out of our company? Egress filtering is protecting what’s going out as well as protecting others from malware coming from inside your own company. In computer networking, egress filtering is the practice of monitoring and potentially restricting the flow of information outbound from one network to another. Typically it is information from a private TCP/IP computer network to the Internet that is controlled. Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network. In a corporate network, typical recommendations [2][3][4][5] are that all traffic except that emerging from a select set of servers would be denied egress. Restrictions can further be made such that only select protocols such as HTTP, email, and DNS are allowed. User workstations would then need to be configured either manually or via proxy auto-config to use one of the allowed servers as a proxy. Corporate networks also typically have a limited number of internal address blocks in use. An edge device at the boundary between the internal corporate network and external networks (such as the Internet) is used to perform egress checks against packets leaving the internal network, verifying that the source IP address in all outbound packets is within the range of allocated internal address blocks. The purpose is to prevent computers on the internal network from IP address spoofing. Such "spoofing" is a common technique used in "Denial of Service" attacks. {Attribution: Wikipedia}

Enumeration: Thanks to Wikipedia we know that Network enumeration is a computing activity in which usernames and info on groups, shares, and services of networked computers are retrieved. It should not be confused with network mapping, which only retrieves information about which servers are connected to a specific network and what operating system run on them. Network Enumeration is the discovery of hosts/devices on a network, they tend to use overt discovery protocols such as ICMP and SNMP to gather information, they may also scan various ports on remote hosts for looking for well-known services in an attempt to further identify the function of a remote host. The next stage of enumeration is to fingerprint the Operating System of the remote host.

We hope that this short laundry list helps each of you.  We understand the complications of local, national and global enterprises.  None of this is easy, but neither is dealing with the stockholders and the media if your company falls victim to a breach or other such incident.

Tuesday, December 2, 2014

Ten Mistakes that Boards Make


Too often we are learning of executive level errors or omissions which cause massive breaches to the data or PI of millions of citizens.  Here's the "Ten Mistakes That Board Make".

         1. Not Asking Questions

2. Failing to Understand the Company and the Risks it Faces
3. Failing to Lead on Ethics and Compliance
4. Not Insisting on a Crisis-Management Plan
5. Speaking out in a Crisis Before the Facts are in
6. Relying on the Wrong Outside Counsel
7. Failing to Understand Attorney-Client Privilege
8. Underestimating Regulators
9. Giving too Much Leeway to Rainmakers
10. Getting Caught Up in the dilemma of False Options
Taken from the magazine Corporate Board Members, an article written by Randy Meyers.
Make Integris Security your Chief Risk Officer (CRO) as the independent keeper of oversight in your corporate enterprise.  It is the job/function of the CRO to keep regulator awareness at a high level and to let the business be in charge of risk management.
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Reference: http://operationalrisk.blogspot.com/2014/11/top-ten-mistakes-board-of-directors-risk.html
 

Wednesday, November 12, 2014

53 Million Reasons ... To Tighten Up The Ship

There are 53 million reasons to take another look at the security of your enterprise.  This past week Home Depot advised that the data (P.I.) of 53 million customers was exposed to thieves over the internet.  Home Depot joins the long list of companies that have suffered a breach during 2014.  What can we learn from Home Depot? 

Flat networks don't work.  Network segmentation is part of the answer to ensure that if a break-in occurs your exposure is vastly limited.  Cut them off at the pass and don't let them beyond your first defensive line.  Call us if you aren't sure or just need some clarification 516-750-0478 and we would be more than happy to advise your company.

Thursday, October 9, 2014

Cyber Security Awareness Month

Now not half way into DHS Cyber Security Awareness Month and the industries leading computer organizations in NYC have hit the ground running with their first joint conference, a success,  ushered in without nearly breaking a sweat.

NY Metro InfraGard, ISSA, ISACA, OWASP, Cloud Security and others joined together with over 300 security professionals in Brooklyn, NY at St Francis College.  The lectures showcased outstanding sessions on Active Directory and a number of security and related discussions.
The all day event produced a Women in Security panel as the
afternoon plenary event.

Most attendee's remarked that this was the opening for the 2015 joint Cyber Security Conference which all believe will now be an annual event.  Congratulations to the organizing committee who persisted and stayed on course to make this important event happen.  A big thank you to St Francis College in Brooklyn for moving heaven and earth to make this happen and for being flexible during the days events.

We look forward to seeing more of this next year.

Thursday, June 12, 2014

Careful What You Wish for

Trust is at the core of
Integris Security LLC
Have you ever wondered where to start in securing your computer operations?  Its natural to be concerned and to suffer from some anxiety. Careful what you wish for because when some people apply for CSO, CISO jobs they may suddenly find that they got what they wished for.  Now what?  Where do I start, what comes first, yikes I need priorities, but where?

Integris Security LLC with the help of some of our friends from the NY InfraGard Thursday Conference Call came up with some great resources which you should become familiar with.  We also discussed at some length ISO 27001.  It was the conclusion of the of the callers that the ISO standards are written to be very broad and do not focus the security professional on what needs to be done with any given priority.  The ISO standard could lead you down a road unfocused and without clear priorities of what's really important for your organization.

Here are some focused security and risk management resources:

Security professionals need to have a full understanding of the environment which they are securing.  These men and women need to be able to explain to others why we need this control, that defensive tool, etc...  The security professional needs to be intimately involved with the infrastructure and provide a solid understanding of every facet of the operation.  This work takes dedication - endless time and energy that becomes the life and work product of a CSO/CISO.

CSO's and CISO's would do well to build a set of books which would consist of the environment that they have been hired to protect.  In these books should be the SANS twenty controls.  Each control should be explained in detail and record of examination clearly maintained so that each fresh security face  looking at the systems will not have to hunt for the documentation.  This is part of your audit trail.

Why SANS? The SANS organization has distinguished itself as an expensive but outstanding security organization from which excellence is derived from.  The SANS top 20 security controls are maintained and updated so that security professionals can be assured they are addressing the top known threats.

How can a true security professional even begin to contemplate securing an organizations assets without knowing the environment inside / out?  It is impossible.  If your organization needs assistance in understanding these and other security issues, give Integris Security a call and let's get started today.

Trust is at the core of Integris Security. We can be counted upon to provide you with the services and intelligence to keep your information, systems and institution secure. Call us and let's get to work on improving your security/risk posture.





Friday, June 6, 2014

Blackshades - an international hazard

It is important to note that as I start this discussion readers are reminded that while malware today is portrayed as dangerous, destructive and part of a criminal enterprise viruses, worms and trojans were and sometimes continue to be little pieces of code which help automate things.

The very first virus written wasn't an assault on a major banking institution, rather is enabled a programer to automate repetitive or tedious tasks.

With that said, The FBI has recently reported in a sterilized press release that International Blackshades - has been taken down.  What we don't read in the release is perhaps as instructive as what is placed on paper.  Thus a good reason to dig a bit deeper and try to wrap a little context around all the fanfare.  This isn't about using limited FBI resources on taking down just any cyber criminals.

For those of you who followed me at InfraGard we produced a weekly IGtv program wherein I spoke with security professionals from the world over.  In this weekly Internet show I interviewed a number of professionals from RSA Security's Israel lab.  During these reports and discussions we learned that the world of malware had developed from a freakish once and while mad scientist type of thing to a very purposeful blackmarket type of business operation.  Blackshade is not some backroom mad scientist, rather they are business people selling software and as we will learn much more.  They are careful to insist that those buying their software signoff on a statement of use and legal disclaimers carefully avoiding international and in country laws.  Because they are in fact a software company and a very good one at that, right?

Blackshades develops many different types of software and one that focuses our attention is RAT (remote application tool).  Their are many variations of the RAT and the focus of our post here is the Blackshades NET.  In reseaching Blackshades we found it useful to also take a look at DarkComet, another RAT with some pretty good potential but not nearly as powerful as Blackshades.  However, DarkComent has a history in international affairs which would be useful in reading as we move forward to learn more about Blackshades.  We can see how the development of software has worked its way into State Sponsored Actors.  Recall how Russia used technology to kill communication lines prior to the invasion of Georgia and now the Ukraine.  DarkComet has played a role in Syria.  So pay close attention when we talk about functionality of Blackshades in comparison to DarkComet, it becomes increasing important why the FBI would get involved and purposefully release a sterile press release on the takedown.

Blackshades is distributed through some common social media channels as well as phishing attacks, P2P channels and much more.  All very common and known to the industry.  Its functionality dwarfs DarkComet in comparasion.  As Malwarebytes states:

"The BlackShades web site mentions a lot of the functionality the RAT is capable of, from various system administration functions to surveillance functions and computer security.  It doesn’t actually mention ALL of its functionality, as we will discuss, and I think that they might have a hard time explaining on their website the purpose of some of the following functions."
This software toolkit is explosive and is used to hijack websites with its Ramsomeware which basically locks you out of your site or maybe encrypts everything (no key provided) until such time as you pay the fee.   Another interesting aspect of Blackshades is the Facebook Controller which basically takes over your account and posts for you.  Remember, it is said that one in fourteen people in the world are on FB.  Most FB users aren't aware that "always on" means that if the software is exposed to you even if you are logged off the web and you're still on FB Blackshades will for sure takeover.  Logging in and out is a pain, but in today security environment is a MUST do.  So when a nation state is acting, it uses many channels to build or tare down a point of view, a surveillance, etc.. This tool has built in DDOS and other attack capabilities as well as java exploits.  But more importantly as Brian Krebbs, reported:
“Blackshades was a tool created and marketed principally for buyers who wouldn’t know how to hack their way out of a paper bag,” wrote Brian Krebs of Krebs on Security. “The product was sold via well-traveled and fairly open hacker forums, and even included an active user forum where customers could get help configuring and wielding the powerful surveillance tool.”

As stated in Symantec, the Blackshades tools (rats) are popular with cyber criminals and state actors like Libya and Syria.  For forty to fifty dollars one can aquire a very effective software product which can be very destructive, but a product which has helped underground elements to extract millions of dollars from companies the world over as well as some governments.

In summary, Blackshades is a more nefarious piece of software then its predecessors that infected over 500,000 computers world wide then anyone is letting on and in hindsight the FBI takedown is a signal to those "business people" lookout we're watching and we're on top of it.  Ninety arrests in 19 different counties is telling about the scope and depth.  Uncertain is whether this is nipping at the edges or taking out the C/C capabilities and principles involved.  Most likely the FBI is both happy for the case and noticeably reluctant to say game-over.  This snake will continue to sliver in and out and pick up again under another name with more willing players looking to strike it rich quick.  Malware is no longer the mad scientist, its hit Main Street and the profit center.  Malware is making millions for some of those willing to take the risk of getting caught.  Malware has also made the center stage as a component of state actors.  International cyberwarfare is our now reality and has been for some time now.  If you weren't aware you'd do well to read up.

LINKS:

http://www.symantec.com/connect/blogs/blackshades-coordinated-takedown-leads-multiple-arrests

http://resources.infosecinstitute.com/darkcomet-analysis-syria/

http://abcnews.go.com/Technology/fed-cyber-sleuths-stop-gameover-zeus-cryptolocker-crime/story?id=23964827

http://www.washingtonpost.com/news/morning-mix/wp/2014/05/20/5-scary-things-about-blackshades-malware/?tid=pm_national_pop

More Info:

In the Bureau's custom of sharing the most accurate, vetted information, they updated others today with the latest figures:

Arrests: 103
Searches: 375
Interviews: 163
18 countries involved
Approximate victim computers globally: 700,000

Thursday, March 6, 2014

The Russians Are Here...

The Russians Are Here

Estonia, Georgia and now Ukraine...

The Russian are coming, the Russians are coming!  As a modern day Paul Revere we're shouting at the tops of our lungs the Russians are coming!  But what does all this portend for those in the security and cyber security space?

In the sixties, seventies and so forth we were warned and taught in schools that the Communist were going to take over the world.  We were told they would do it without firing one single shot.  Given our current technology revolution has this become a more resolute reality?  Are we feeding our own eventual demise by participating in this ever interconnected world via the web?      

Well, if we look at Estonia, Georgia and now the Ukraine cyber invasions are most definitely front and center of every single world power and nation-state.  We invite your comments and observations as Russia leverages Crimean networks, telecom, communications capabilities and the gas pipeline infrastructure which feeds most of Europe and is most undoubtedly connected to SCADA systems.

Those of us in the security space would do well to pay close attention to methods of operation and techniques employed for both offense and defense whether as old as the hills or on the new frontier called the bleeding edge.  The global economy is not going away any day soon and we need to understand the threats-scape, our own infrastructure limits and wherein possible the bolstering of defenses to counter those threats as it may lead directly to our bottom line.  Testing to acceptable baseline defenses and offenses will only get you so far...conducting exercises for real resilience in the face of a MOST determined adversary is as they say, a horse of a different color.

We at Integris Security are here to help you prepare, test and evaluate your enterprise operations with an eye on: Can you survive in this global economy if your adversary has your company in their crosshairs?  Is your staff security aware?  Would you know an attack if it started?  Are your employees asleep at the switch, anchored in a serpentine bureaucracy or are they war-fighters listening, looking and revealing, reporting and proactively taking action?

Lastly, if sixty thousand security related alarms went off at your company would you roll over and go to sleep or more appropriately "RESPOND", "INVESTIGATE" and "REPORT"?

Here are a few links:

http://www.computerweekly.com/news/2240215674/Ukraine-and-Russia-locked-in-a-cyber-stand-off

http://defensetech.org/2008/08/13/cyber-war-2-0-russia-v-georgia/

http://www.computerweekly.com/news/2240215674/Ukraine-and-Russia-locked-in-a-cyber-stand-off

http://www.bbc.com/news/technology-26447200

http://www.huffingtonpost.com/2014/03/04/ukraine-cyberattack-mobile-phones-russia-parliament-security_n_4895287.html

http://www.stratfor.com/weekly/ukraine-and-little-cold-war?utm_source=freelist-f&utm_medium=email&utm_campaign=20140304&utm_term=Gweekly&utm_content=re

Thursday, January 30, 2014


Target Confirms Unauthorized Access...


ANALYSIS:


In recent days we have heard quite a bit about the 2014 Target Breach.  Additionally we have heard about the Neiman-Marcus breach which is said to be independent of the Target event but reports are that the malware used is similar.  Target is now investing billions of dollars to repair both its image and capabilities.  We have been discussing the Target breach and are trying to learn from each aspect of the incident as it becomes public.  The rationale has been to better our own security posture and help improve the overall security posture of the industry as a whole.  This breach investigation will evolve and we at Integris Security will evolve with it and learn as information becomes reliable and forthcoming.

Everything known at this point is speculation and inconclusive until the Target Corporation steps up to the microphone and gives a full autopsy. Not likely to happen any day soon as legal process is just now gathering information.

Law Enforcement (U.S. Secret Service or FBI) is typically very tight lipped about the circumstances and causes (operational details) leading up to such an event like this since they are in various stages of presenting materials to grand juries, attending to hearings, participating in a prosecution, etc..  Normally afterwards which could be a year or better after suspects are declared innocent or a conviction the details slowly pour out and begin to be known.

We are providing here some links which were discussed on weekly conference calls and provided to us by a number of different sources. Target is known as having very strong internal security procedures, posture and no one should take this post to mean target is not helping its own cause.  Previously we have spoken to Target personnel and know full well something seriously went awry. 

We have a deep sense of intrigue which is only natural and want to learn every single detail about this serious beach.  However as security practitioners we must be responsible and utilize some common sense and respect for the internal practitioners with the Security Teams at Target.  The security teams, their tasks, workload, etc these days must be daunting (incident response, business continuity programs and disaster recovery plans will receive plenty of scrutiny this time around).

We are posting from Neiman-Marcus as well even through the two cases have not been connected.

http://www.zdnet.com/neiman-marcus-1-1-million-cards-compromised-7000025513/
http://www.nytimes.com/2014/01/24/business/neiman-marcus-breach-affected-1-1-million-cards.htmlhttp://www.neimanmarcus.com/NM/Security-Info/cat49570732/c.cat?icid=topPromo_hmpg_ticker_SecurityInfo_0114

http://m.computerworld.com/s/article/9245877/Target_says_attackers_stole_vendor_credentials?source=CTWNLE_nlt_security_2014-01-30
http://krebsonsecurity.com/
http://krebsonsecurity.com/2014/01/a-first-look-at-the-target-intrusion-malware/
http://www.cnbc.com/id/101329300
http://www.reuters.com/article/2014/01/12/us-target-databreach-retailers-idUSBREA0B01720140112
http://www.us-cert.gov/ncas/alerts/TA14-002A
http://krebsonsecurity.com/2013/12/sources-target-investigating-data-breach/
http://pressroom.target.com/news/target-confirms-unauthorized-access-to-payment-card-data-in-u-s-stores

This listing is a short list but can lead to many solid sources.  We would also like to acknowledge the SANS organization that provides all of us some well thought out background discussion on this topic in its newsbites publication.  


CONCLUSION: 

Integris Security would be falling short not to mention to our clients and prospects that security awareness starts before a breach, before an employee is let go, before the budget cycle crows no more.  Simple security awareness proves to be an effective first step in a series of steps required to withstand the hailstorm which now befalls Target and others.   Security is not something JUST for those high tech guys and gals to mull over and talk about.  The security discussion from the smallest to the largest corporation starts with the CEO and is a culture he/she causes to infect every single part of the corporation.   This is a difficult thing for some when nothing seems to be happening.  Like fire drills being prepared with worth billions as we now see Target is prepared to spend.  



UPDATE:  3/10/2014

Thanks to our members.  The truth about the Target Breach is getting out.  Here is the latest:

"Troy Leach, the lead security standards architect for the PCI Council, testified March 5 that the vulnerabilities of magnetic-stripe card transactions have to be addressed. But he stressed that a migration to more secure chip card technology that conforms to the Europay, MasterCard, Visa standard would not, by itself, eliminate all security risks. In fact, he contended that the use of chip cards would not have prevented the exposure of card data caused by the malware attacks against Target and Neiman Marcus."

http://www.bankinfosecurity.com/target-hearings-emv-enough-a-6607


UPDATED: 3/13/2014

http://www.businessweek.com/articles/2014-03-13/target-missed-alarms-in-epic-hack-of-credit-card-data

Business week outlines the missed opportunities that TARGET had to stop the bad guys at the front door.  Some generalization about what happened overseas as well as adding to "Who" dropped the ball.  We may live in a global society but what part of the "global" isn't getting the "Security" message - this is not clear.  Assertions have been made that if kept inside the U.S., this security failure would not have happened, but that is easier said then done.  It is to be seen if analyst have the time....with all the blown data breaches if "OUTSOURCING" is in fact a savings or part of the overall cost house.  In this case it would appear as though TARGET may have save some cash by keeping things in the U.S., but all of this is very much UNPROVEN at the time of this post.

Fact was that Target was one of the big box companies at the vanguard of security.  Perhaps in hindsight they have realized that the security staff in place was not as "state of the art" or as "progressive" as one needs to be given the size and complexity of a major corporation.  Then one needs to ponder is this a problem of a CIO, CTO, CISO or other security persons?  Or is this a total miscalculation of the CEO, COO, CFO and do shareholders derserve a say in whether these individuals have earned a long term seat at TARGET?  Truly a let down, a major disappointment of a highly successful retailer here in the U.S.

UPDATED: 3/17/2014
http://www.computerworld.com/s/article/9246942/Major_companies_like_Target_often_fail_to_act_on_malware_alerts

The blog is updated with this article to highlight the fact that technology alone will not solve the IT security issues.  Ongoing professional development, exercises that test the effectiveness of staff with combined with indepth knowledge, skills and abilities about onboarding specific security tools is not cheap, but is the likely candidate for success of any security team.  Combining human resources and effective tools such as Fire Eye is a receipe for success.  Not cheap, but for certain an investment worthy of a healthy report card for any major corporation.

Joseph Concannon