Showing posts with label Infosec Institute. Show all posts
Showing posts with label Infosec Institute. Show all posts

Saturday, May 2, 2020

Big Data: Security, Trust and Integrity

In information security the jewel of all certifications is the CISSP (certified information systems security professional).  The certification is your entry key into the top tier cyber security jobs and earned respect of your peers in the industry. 

The group that hosts the coveted CISSP certification is (ISC)2: the world's leading cyber security professional organization.  They actively promote their members and insist you want one our people at the switch if threats of an attack are at your doorstep. 

A great many information security professionals have earned this certification and live up to its standards and for that they are proud card carrying members.  I salute them for their achievement. 

One of the most important aspects of the certification in my eyes is the code of ethics.  The code of ethics tells you something about the individual and the organizations they belong to.  (ISC)2 spares no dime on its code.  The code of ethics is huge and prominent.  Honor and duty are fundamental in any cyber security career.  The group lays it out like this:

  • Our code
  • Code of ethics preamble
  • Code of ethics canons
We again salute (ISC)2 for their outstanding work.  Note well that prominence of the code, its preamble and canons can not replace the responsibility of the issuing organization to aggressively maintain the standards so that they ensure its integrity.  The organization owes it to its members to police itself and has a complaint procedure, ethics committee and international working group.

As data becomes accessed from hundreds and in some cases thousands of sources we reflect on the role of the information security professional has in the work place and what a pivotal role it is.  Untimely and inaccurate intelligence/data can cause food supply shortages, it could run up the price of a barrel of oil and shift geopolitical affairs world wide.  The use of big data and concerns around integrity have never been more critical and important.  

The role of the CISSP member becomes exponentially more important and his/her integrity should not come in question, hence the focus on "Big Data" in this article.  Data can shift global markets, take down thriving economies and strip citizens of their bill of rights so the importance and focus on this topic is both timely with a need to be accurate.  As governments and citizens react to COVID-19 the initial focus was on data driven models which reported that millions were in peril if the US Government did not act quickly.  Today we see state governments restricting the movement of its citizens, baring them from accessing their properties (Michigan), removing business and liquor  licenses from businesses who refused to comply (Maine) and here in NYC the issuance of one thousand dollar fines if you are found in non compliance - wear your mask, don't get closer than six feet or else!  

As time passes we are learning that models are just that models.  Accuracy depends on the information you put into models we have learned and if the data is awful so is the model and its outcome. Thus data its custodians and security personnel take heed. I think I made the case, data its timeliness and accuracy is very, very important.  The integrity of data custodians, security personnel has never been more acute.

 

Thursday, April 16, 2020

Zooming not so fast....slow down

Video Conferencing Software/Weak Security?


Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms

Zoom, the video conferencing software maker learned a lot of lessons this past month as a result of legions of new visitors who stopped by and signed up as new customers.  The software company Zoom updates from the past weekliterally exploded with new customers during Mid March 2020 as a result of the COVID -19.  However a number of security incidents started happening and with that a fire hose of commentary poured into their email boxes, security blogs, conference calls and forums.  Security professionals came on strong.  One security practitioner commented that the right out of the box the default settings needed serious review and the general public was at the point of the spear - buyer beware.  Waiting rooms, passwords, and many other enhancements all focused on security and reducing risk were heard from all quarters.  

To the credit of Zoom, now known as that easy, cheap video conferencing software have made the changes to improve security (change to many of the default settings, like requiring password as a default for all meetings, establishing a waiting room so you can verify participants and sprinkling of the message not to share passwords, etc) and reduce the risks to many of its users. Zoom has taken it on the chin for many in this functional area: "Video Conferencing Brands" while the rest of the pack gets the opportunity to take another look at security.  Zoom brought on a security professional and kinder days seem to be in the future. Zoom also has a HIPAA compliant application separate from what general users get to use.  See the photo above for the last known update from Zoom.  Zoom is growing and has been sending out improvements as they become available.

Video Conference Software:

Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms



Here are some additional products for consideration:
  • GoToMeeting
  • Webex Teams
  • Skype for business
  • Google Hangouts
  • Join.Me LogMeIn
  • Amazon Chime
  • Microsoft Teams
  • Cisco Webex Meetings
  • Updox
  • Vsee
  • Zoom for healthcare
  • Spruce health care messenger
  • Apple Face Time
  • Doxy.me
  • Face Book Messenger Chat
  • Blue Jeans - recently purchased by Verizon
Check out each of these products and note well during a declared national emergency many if not all maybe used without compliance penalty.  However, after the emergency is over please do use HIPPA compliant software.  See shorturl.at/fijHL for future updates at U.S. H.H.S. dot gov.


NIST - Navigating the Conference Call Security Highway



Today 4/25/20 I reviewed an article from Dr Eric Cole, Secure Anchor Consulting. These are some of his thoughts:

Zooming now household word
Due to pandemic March/April 2020 video conferencing increases 1000 fold.  "Zooming" takes on a life of its own for all brands of video conference calling software.
ZOOM BOMBING:  DEFINED
Is where a person joins into Zoom video conferencing calls uninvited and either 1.) listens in, 2.) gathers important info to use at a later time or 3.) become disruptive to your meeting or event.
How do you protect a Zoom call?
    1. Remember you are a target, 2. Cyber security is your business, 3. Make sure your software is up to date. 

    • Make sure your computer operating system is up to date
    • Make sure your Zoom app is up to date and other apps as well
    • Make sure you are using anti-virus software and its up to date
    • Do not post Zoom links in the public eye
    • Don't click on links you don't know
    • Setting up meetings:
      • Use strong passwords
      • Do not share the meeting ID
      • Use a non obvious meeting ID
      • Use the waiting room function
      • Lock the meeting once everyone is in

New Post: 5/5/20


Jeff Furman my "go to guy" for Project management hosts a blog and has some Zoom fun and other suggestions check it out here:  https://www.linkedin.com/pulse/so-your-internet-crashes-middle-zoom-session-what-you-jeff-furman/

Take a peek at the: Project Management Answer book click the link.

New Post: 5/7/20 am

On a conference call today.  Discussion of fat client verses thin client again for VT software (for the young at heart this seems to reoccur every 5-10 years), functionality services were discussed (I think more of what you are used to using drives the most favorite product discussion) and end to end encryption took place.   Zoom came up and given that it is slowly improving its security posture some note it is moving into the "pack" of other VT implementations given that it will become less of a pick up and use utility because of security concerns.  Those with more security concerns and less functionality can look here: https://www.infosecnews.org/national-security-agency-releases-guide-to-secure-video-conferencing

New Post: 5/7/20 pm

Take a look at this very comprehensive post from Citizen Lab:
https://citizenlab.ca/2020/04/faq-on-zoom-security-issues/

Then this video by none other than: Dr Eric Cole

A few weeks ago there was a lot in the news about ZOOM Bombing. So ZOOM took action and set up some default security to 'appease the masses'. But here's the thing... they did too little, too late AND ZOOM meetings are still being targeted.
It's not over! The adversary is still on the prowl and creating havoc.
I recorded a quick video for you to share with your organization to help keep the awareness around how to protect against ZOOM Bombing.

Dr Coles Tips:


#security  #cybersecurity @Zoom @NIST #VideoConferenceCalling #VT #DrEricCole  #zoombombing


Last edit: Monday, 5/5/20 0930 hours











Wednesday, December 3, 2014

The Rear View Mirror

Typical in the information technology sector everyone is always focused on what’s next, the latest, hottest new application, the coolest mobile telephone and of course the work around that just makes life a little easier.  Not to be ignored are all those newly fashioned functions and features. Technology at the speed of life forever changing our lives for the better, right?  Forward looking for ever.

2014 hopefully has hopefully taught us some very important lessons that should not be ignored even if we were not directly impacted.  A look in the rear view mirror can sometimes be very revealing.  We are so focused on what’s coming directly ahead of us that we refuse to see what’s going on right behind us.  So for 2014 let me list a couple of things which could have made this a better year in the security space.

Network segmentation: You can’t get there from here should be the mantra, no? Did we learn anything this past year? Network segmentation is the act or profession of splitting a computer network into subnetworks, each being a network segment or network layer. Advantages of such splitting are primarily for boosting performance and improving security.   Please review a great eWeek article clicking here.

Service Level Agreements: Service agreements are important and a quick web search can be helpful to identify some key questions for developing such important tools for your company. The Outsourcing Center has developed ten key questions for developing effective service level agreements. It’s a solid read and you’ll find plenty of similar research on the web. A service-level agreement (SLA) is a part of a service contract[disambiguation needed] where a service is formally defined. Particular aspects of the service - scope, quality, responsibilities - are agreed between the service provider and the service user. A common feature of an SLA is a contracted delivery time (of the service or performance). As an example, Internet service providers and telcos will commonly include service level agreements within the terms of their contracts with customers to define the level(s) of service being sold in plain language terms. In this case the SLA will typically have a technical definition in terms of mean time between failures (MTBF), mean time to repair or mean time to recovery (MTTR); identifying which party is responsible for reporting faults or paying fees; responsibility for various data rates; throughput; jitter; or similar measurable details. {Attribution: Wikipedia}

Too big to fail: While not at all a technical term your company would do well to heed this warning. No company is too big to fail. No one. In our recent newsletter we talked about the breach of the week. The roadway is littered with companies failing over and over again until everyone in the industry is just tired of hearing of another breach. The breaches become “white noise” a distraction from the good work being performed by many security professionals in the field. Fight complacency, challenge everything and everyone with respect and “ASK Questions”. It won’t make you popular but it will certainly make you a very, very valuable employee.  Please read the ARS Technica article   HERE because it puts good perspective of what can happen after a breach. 

Alarms: Alarms are invitations that are yelling out, “come investigate me” I’m making noise and need your direct undivided attention. Please don’t ignore alarms. The story goes like this: Hey did you hear that alarm go off? Yeah, I’m getting a cup of coffee – you want anything? Hey, maybe I’ll come with you. Great! How many times do we ignore the obvious? Alarms are put in place for a reason to warn us, right? If the alarms are not configured appropriately and are creating noise, then someone has to go in and make a determination to turn them down and accept the consequences or turn them up and act each time they alert. 

Egress Filtering: Is that a freight train of information running out of our company? Egress filtering is protecting what’s going out as well as protecting others from malware coming from inside your own company. In computer networking, egress filtering is the practice of monitoring and potentially restricting the flow of information outbound from one network to another. Typically it is information from a private TCP/IP computer network to the Internet that is controlled. Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network. In a corporate network, typical recommendations [2][3][4][5] are that all traffic except that emerging from a select set of servers would be denied egress. Restrictions can further be made such that only select protocols such as HTTP, email, and DNS are allowed. User workstations would then need to be configured either manually or via proxy auto-config to use one of the allowed servers as a proxy. Corporate networks also typically have a limited number of internal address blocks in use. An edge device at the boundary between the internal corporate network and external networks (such as the Internet) is used to perform egress checks against packets leaving the internal network, verifying that the source IP address in all outbound packets is within the range of allocated internal address blocks. The purpose is to prevent computers on the internal network from IP address spoofing. Such "spoofing" is a common technique used in "Denial of Service" attacks. {Attribution: Wikipedia}

Enumeration: Thanks to Wikipedia we know that Network enumeration is a computing activity in which usernames and info on groups, shares, and services of networked computers are retrieved. It should not be confused with network mapping, which only retrieves information about which servers are connected to a specific network and what operating system run on them. Network Enumeration is the discovery of hosts/devices on a network, they tend to use overt discovery protocols such as ICMP and SNMP to gather information, they may also scan various ports on remote hosts for looking for well-known services in an attempt to further identify the function of a remote host. The next stage of enumeration is to fingerprint the Operating System of the remote host.

We hope that this short laundry list helps each of you.  We understand the complications of local, national and global enterprises.  None of this is easy, but neither is dealing with the stockholders and the media if your company falls victim to a breach or other such incident.

Tuesday, December 2, 2014

Ten Mistakes that Boards Make


Too often we are learning of executive level errors or omissions which cause massive breaches to the data or PI of millions of citizens.  Here's the "Ten Mistakes That Board Make".

         1. Not Asking Questions

2. Failing to Understand the Company and the Risks it Faces
3. Failing to Lead on Ethics and Compliance
4. Not Insisting on a Crisis-Management Plan
5. Speaking out in a Crisis Before the Facts are in
6. Relying on the Wrong Outside Counsel
7. Failing to Understand Attorney-Client Privilege
8. Underestimating Regulators
9. Giving too Much Leeway to Rainmakers
10. Getting Caught Up in the dilemma of False Options
Taken from the magazine Corporate Board Members, an article written by Randy Meyers.
Make Integris Security your Chief Risk Officer (CRO) as the independent keeper of oversight in your corporate enterprise.  It is the job/function of the CRO to keep regulator awareness at a high level and to let the business be in charge of risk management.
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Reference: http://operationalrisk.blogspot.com/2014/11/top-ten-mistakes-board-of-directors-risk.html
 

Wednesday, November 12, 2014

53 Million Reasons ... To Tighten Up The Ship

There are 53 million reasons to take another look at the security of your enterprise.  This past week Home Depot advised that the data (P.I.) of 53 million customers was exposed to thieves over the internet.  Home Depot joins the long list of companies that have suffered a breach during 2014.  What can we learn from Home Depot? 

Flat networks don't work.  Network segmentation is part of the answer to ensure that if a break-in occurs your exposure is vastly limited.  Cut them off at the pass and don't let them beyond your first defensive line.  Call us if you aren't sure or just need some clarification 516-750-0478 and we would be more than happy to advise your company.

Friday, June 6, 2014

Blackshades - an international hazard

It is important to note that as I start this discussion readers are reminded that while malware today is portrayed as dangerous, destructive and part of a criminal enterprise viruses, worms and trojans were and sometimes continue to be little pieces of code which help automate things.

The very first virus written wasn't an assault on a major banking institution, rather is enabled a programer to automate repetitive or tedious tasks.

With that said, The FBI has recently reported in a sterilized press release that International Blackshades - has been taken down.  What we don't read in the release is perhaps as instructive as what is placed on paper.  Thus a good reason to dig a bit deeper and try to wrap a little context around all the fanfare.  This isn't about using limited FBI resources on taking down just any cyber criminals.

For those of you who followed me at InfraGard we produced a weekly IGtv program wherein I spoke with security professionals from the world over.  In this weekly Internet show I interviewed a number of professionals from RSA Security's Israel lab.  During these reports and discussions we learned that the world of malware had developed from a freakish once and while mad scientist type of thing to a very purposeful blackmarket type of business operation.  Blackshade is not some backroom mad scientist, rather they are business people selling software and as we will learn much more.  They are careful to insist that those buying their software signoff on a statement of use and legal disclaimers carefully avoiding international and in country laws.  Because they are in fact a software company and a very good one at that, right?

Blackshades develops many different types of software and one that focuses our attention is RAT (remote application tool).  Their are many variations of the RAT and the focus of our post here is the Blackshades NET.  In reseaching Blackshades we found it useful to also take a look at DarkComet, another RAT with some pretty good potential but not nearly as powerful as Blackshades.  However, DarkComent has a history in international affairs which would be useful in reading as we move forward to learn more about Blackshades.  We can see how the development of software has worked its way into State Sponsored Actors.  Recall how Russia used technology to kill communication lines prior to the invasion of Georgia and now the Ukraine.  DarkComet has played a role in Syria.  So pay close attention when we talk about functionality of Blackshades in comparison to DarkComet, it becomes increasing important why the FBI would get involved and purposefully release a sterile press release on the takedown.

Blackshades is distributed through some common social media channels as well as phishing attacks, P2P channels and much more.  All very common and known to the industry.  Its functionality dwarfs DarkComet in comparasion.  As Malwarebytes states:

"The BlackShades web site mentions a lot of the functionality the RAT is capable of, from various system administration functions to surveillance functions and computer security.  It doesn’t actually mention ALL of its functionality, as we will discuss, and I think that they might have a hard time explaining on their website the purpose of some of the following functions."
This software toolkit is explosive and is used to hijack websites with its Ramsomeware which basically locks you out of your site or maybe encrypts everything (no key provided) until such time as you pay the fee.   Another interesting aspect of Blackshades is the Facebook Controller which basically takes over your account and posts for you.  Remember, it is said that one in fourteen people in the world are on FB.  Most FB users aren't aware that "always on" means that if the software is exposed to you even if you are logged off the web and you're still on FB Blackshades will for sure takeover.  Logging in and out is a pain, but in today security environment is a MUST do.  So when a nation state is acting, it uses many channels to build or tare down a point of view, a surveillance, etc.. This tool has built in DDOS and other attack capabilities as well as java exploits.  But more importantly as Brian Krebbs, reported:
“Blackshades was a tool created and marketed principally for buyers who wouldn’t know how to hack their way out of a paper bag,” wrote Brian Krebs of Krebs on Security. “The product was sold via well-traveled and fairly open hacker forums, and even included an active user forum where customers could get help configuring and wielding the powerful surveillance tool.”

As stated in Symantec, the Blackshades tools (rats) are popular with cyber criminals and state actors like Libya and Syria.  For forty to fifty dollars one can aquire a very effective software product which can be very destructive, but a product which has helped underground elements to extract millions of dollars from companies the world over as well as some governments.

In summary, Blackshades is a more nefarious piece of software then its predecessors that infected over 500,000 computers world wide then anyone is letting on and in hindsight the FBI takedown is a signal to those "business people" lookout we're watching and we're on top of it.  Ninety arrests in 19 different counties is telling about the scope and depth.  Uncertain is whether this is nipping at the edges or taking out the C/C capabilities and principles involved.  Most likely the FBI is both happy for the case and noticeably reluctant to say game-over.  This snake will continue to sliver in and out and pick up again under another name with more willing players looking to strike it rich quick.  Malware is no longer the mad scientist, its hit Main Street and the profit center.  Malware is making millions for some of those willing to take the risk of getting caught.  Malware has also made the center stage as a component of state actors.  International cyberwarfare is our now reality and has been for some time now.  If you weren't aware you'd do well to read up.

LINKS:

http://www.symantec.com/connect/blogs/blackshades-coordinated-takedown-leads-multiple-arrests

http://resources.infosecinstitute.com/darkcomet-analysis-syria/

http://abcnews.go.com/Technology/fed-cyber-sleuths-stop-gameover-zeus-cryptolocker-crime/story?id=23964827

http://www.washingtonpost.com/news/morning-mix/wp/2014/05/20/5-scary-things-about-blackshades-malware/?tid=pm_national_pop

More Info:

In the Bureau's custom of sharing the most accurate, vetted information, they updated others today with the latest figures:

Arrests: 103
Searches: 375
Interviews: 163
18 countries involved
Approximate victim computers globally: 700,000