Sunday, March 5, 2017

Security 101 at Home (week 8)

Just like most of the millions of computer users out there, I’m positive, if you peruse through my personal computer, you may run into some personal information saved there. Before the introduction of computers and its saving capabilities, people saved important documents in files locked in file cabinets either at home or at work. Now that computers are available to most individuals, these physical storage (file cabinets) have converted to hard drives on computers. Due to the convenience, like many others, I am guilty of readily embracing the change and ‘sadly’ saving information that may be critical to my personal life and definitely my families too. The only advantage I can say I have is that the information is not all saved in one place and it would take some digging around to gather the information.

Having a wife and kids in the household means that multiple users have access to the files and information on the computer but the extent to which they have visibility varies. If this information was lost, it would not be as detrimental since I still believe in the traditional way of having a hard ‘paper’ copy of important documents. I can probably get away with this until when the entities I deal with decide to go all paperless. If on the other hand, the information was somehow compromised, then some personal information may be obtained and the extent of the damage would only be dependent on the motives of the attacker. I have also backed up the content of the computer in case of data loss.

It is scary thinking about what information can be retrieved from our personal computers. To try to minimize the risks, I adhere to some basic security practices like password enforcement. Having multiple users in the household means creating different user accounts to worry about and with kids, if not monitored, the extent of exposure is immense. For any activity that requires administrative privileges, a password is required. The kids are also not allowed to download or open any windows that have not been sanctioned by us, the parents. The kids use the guest account when using the computer. We also limit the usage of the computer to certain times and they are mostly allowed some free reign on the gaming console and tablets which don’t have any personal information. 

The steps or precautions I mentioned above are all educational and policy related measures but on the technology aspect of protecting personal information, I ensure that all systems in the house are patched and up to date. All computers have a paid anti-malware software installed on them which is, in my opinion, slightly better than free versions which may miss some signatures or have a delayed span between signature updates. The subscription is up to date to ensure updates are downloaded as they become available. Not many people know that Windows provides a firewall; I also have this enabled in addition to the firewall capability of the anti-virus software. For online protection, the anti-malware software provides protection. 

To ensure the weakest link doesn’t fail us, I constantly remind my kids and wife the importance of being aware of their surroundings and being vigilant when on the net.

In conclusion
I don’t think there is anything wrong with saving personal information on a computer; we just need to take extra precaution of ensuring this information is not compromised. My plan is to always save personal information on an external hard drive and only expose it to systems that are connected to the internet when I need to view that information.   

Why Cybercrime Awareness is Important (week 7)

Cybercrime photo: Courtesy of State of Jersey Police
Cybercrime is any crime that involves a computer and a network whereby the computer may be used to commit a crime or the computer may be the target of an attack. Interpol classifies Internet-related crimes as either advanced cybercrime which involves attacks against the computer hardware/software and cyber-enabled crimes which is the traditional crime being conducted with the aid of a computer.
IT professionals should be concerned with cybercrime because of the impact it has on our day to day life. Although there are a lot of devices connected to the Interconnected networks (Internet), it’s foundation is considered shaky. 

Cybercrime affects the entire society given that the Global Economy is dependent on the proper working of the Internet. Dependence means a vulnerability which can be exploited. Attackers are known to use encrypted methods to communicate amongst each other which makes it difficult for law enforcement to intercept their communication. The Internet also provides a wealth of information for hackers and cyber-terrorists to reference for different cyber-attack methods. This means that hacking pranksters who cause annoyance by taking down popular web sites and also professional hackers who are employed by criminal organizations and rogue states can easily look up how to attack an organization and get the information from the Internet easily. 

Critical infrastructure like the power grid, transportation, financial institutions are at risk and there is no capability to identify where the threat will come from and when it will even take place; the anonymity of the attacks make the battle tougher. Shutting down the power grid, the command and control center, attacks on Federal agencies are just some of the acts of cyber-terror that can be propagated. Terrorists using physical threats like bombs and also information warfare to disrupt emergency response services cause double the havoc.

Cyberattacks on the financial sector can cause the same damage as an actual physical attack on the infrastructure. Some of the major computer facilitated crimes that hit the financial sector include Web auctions, General merchandise frauds, Internet services, pyramid money laundering schemes, credit card fraud, advance fee loans among many others. These same crimes have long been propagated via wire fraud where attackers call up victims to try to con them into a bad deal, but now they are through the Internet as well.

To counter law enforcement, criminals are using police scanners which can track law enforcement activities. These helps them avoid detection and the can also intercept intel and communication that can be used to evade capture.

Conclusion

The Government cannot address cybercrime alone and it seems as though the criminals are always one step ahead in the game. Including teams like Systems Engineering and Technical Assistance (SETA) should be a common theme as the private sector has a wealth of information and they can bring a different angle and ideas to the table when it comes to trying to stay ahead of attackers. Preventing cybercrime is an all-inclusive game given that the criminals always seem to be one step ahead of the good guys. 

Firewalls, Patches and System Updates (week 6)

A firewall is a system designed to prevent unauthorized access from one point to another within a network and can be implemented as hardware or software components. Firewalls are considered gate-keepers and if setup and configured correctly can be vital in stopping a lot of potential threats. A good example would be setting up Geo-blocks for next generation firewalls if a business does not conduct any business transactions with foreign entities. Having the firewall in place instantly blocks traffic from outside the United States.

Patch Tuesday: Courtesy of Windows10update.com
Patches and Updates
If you are in IT, you should know about the infamous ‘Patch Tuesday’. This is when (second Tuesday of the month) Microsoft releases patches. As much as this is a known date, most organizations still don’t push out the patches and updates as they are released to the public. Patching and ensuring that systems are up to date is crucial in covering known vulnerabilities and having security updates current. Patching however is not always smooth sailing. Microsoft’s regular “Patch Tuesdays” have led to “Recall Thursdays,” with various patches breaking Office, affecting the functionality of Windows and even resulting in complete system crashes and the dreaded Blue Screen of Death (Shinder, 2015).

To ensure that patches and updates don’t break systems, we need to establish change control polices which should include testing the patches in non-production environments before deploying. Despite the issues that can come about from system patches and updates, the pros far outnumber the cons and systems should always be kept current. In cases where the systems cannot be updated due to some business reason, isolating those systems is advisable to prevent exposing the business to risks.

Protection against threats
Simply propping up a firewall and ensuring systems are patched and up to date is not the end of securing networks. Security needs to be approached from a multi-tiered layer. Some attacks tend to focus on the weakest link in the system; humans. A well-known avenue of this exploit is via email scams such the Nigerian (419) scams which many people fall for and lose fortunes chasing more fortunes. Phishing emails are used to compromise personal information from unsuspecting users. Counterfeit software gets installed on our systems and tracks our every move.

The Web is full of booby traps everywhere we turn or click. Malware, adware, Trojans, viruses, the list is endless. Seems like the only way to stay safe is to operate in a vacuum but for the many businesses and individuals who don’t have this luxury, steps need to be taken to at least stay safe while connected to the world wide web. Anti-malware, anti-viruses and verifying software and hidden add-ons before installing is one way of protecting ourselves from these threats.


References:
Whitman, M., & Mattord, H. (2014). Introduction to the Management of Information Security. In Management Of Information Security (Fourth ed.). Cengage Learning.
Finley, K. (2014, June 6). Online Security Is a Total Pain, But That May Soon Change. Retrieved December 6, 2015, from http://www.wired.com/2014/06/usable-security/


Shinder, D. (2015, January 14). Patch or Not? Weighing the Risks of Immediate Updating. Retrieved December 6, 2015, from http://www.windowsecurity.com/articles-tutorials/misc_network_security/patch-or-not-weighing-risks-immediate-updating.html 

Friday, February 3, 2017

Cloud Computing …Why Not? (week 5)

I believe most technically savvy individuals are aware of Amazon Web Services (AWS), Microsoft Azure, Salesforce or even Google Cloud (part of Alphabet). A commonality with all these companies, apart from the fact that they are in almost every aspect of our lives, is their cloud services. If you love to binge on Netflix shows like I do (please watch Narcos or House of Cards if you haven’t…Netflix original classics), then you should know that all those shows you love have to be stored on someone’s servers and when you ‘demand’ them, they will need to be 'served up' to you without any interruptions. Well, the ‘cloud’ makes all this possible. We will define the cloud as simply assets (i.e. infrastructure, platform, software) on someone else’s servers and premises other than yours. For this blog, I won’t talk about how wonderful the cloud is but we will approach it from this point of view:

-- Its late Friday afternoon (of course 😠), your boss walks over to your cube and anoints you the devil’s advocate. “John Doe, your weekend assignment is to come up with reasons why we should not join the cloud bandwagon. And at that, please remember to enjoy your weekend!”

No need for panic, this blogger has your back …read on


These 7 reasons should be enough to get your boss thinking

Security (cloud security) – this barrier is one of the top concerns for most businesses. Some questions to ask are: How do I secure my data in the cloud? What security measures are in place? Depending on the sensitivity and value of the data to be stored in the cloud, some businesses may not be comfortable adopting cloud computing. In-house computing ensures you have total control of all your data, whether that data is safe(er), is a story for another day; focus here is on total control of your data.

Privacy (Trusting the cloud) – with the ever-growing competitive business-world, no business wants to expose their ‘secret sauce’ to their competitors. With cloud computing, if due diligence is not done, a business may end up with a cloud provider who’s not very reliable when it comes to privacy concerns.

Independence from CSPs – most Cloud Service Providers (CSPs) prefer to lock in their customers through contracts and if there’s a need to move services to another provider, the exercise is sometimes stressful, especially with inter-operability issues amongst cloud providers.

Economic Values (Return on investment) – this in my opinion is the most heavily weighted barrier of all from a business standpoint. All businesses regardless of size, type or location are in it to make money (excluding the not-for-profit ones which actually still make money). Before migrating to the cloud, a business needs to ask whether it makes economic sense. Is the venture going to save the business money or add extra costs? The return on investments need to be analyzed and presented to the decision makers. Most business will only adopt cloud computing if it makes economic sense.

Inter-operability – most cloud infrastructure and applications are current and advanced but this is not always the case for businesses that want to integrate their infrastructure with the cloud. When you have inter-operability issues, this may mean adopting other services for example IaaS, PaaS, and SaaS even though the initial intent was to only buy one service model. You should ask yourself, is my business compatible with the cloud provider’s?

IT Governance – IT governance determines the direction that the business will take. If cloud computing is not part of the governance plan, then cloud migration may be hindered.

Political issues Due to Global Boundaries – For cloud computing to be successful, there needs to be no borders or jurisdictions. The goal for cloud computing is to enable fast and easy access to resources regardless of the user’s location. Some businesses may be reluctant to adopt cloud computing especially if the provider is geographically located in different countries. A European company for example may be skeptical or fearful of subscribing to Amazon given it operates under U.S. jurisdiction. Also, some European laws may dictate that certain data or information should not be transmitted across its borders. So, the question here is, what laws or regulation requirements bind you as a company?

And there you have it. I hope this information made your task easier. Go forth and conquer now and thank you for reading. 

References
Arellano, N. E. (2015, March 6). Top 5 cloud barriers for most businesses.
     Retrieved June 24, 2016, from IT World Canada website:
     http://www.itworldcanada.com/article/top-5-cloud-barriers-for-most-businesses/
     177871 
Mather, T., Kumaraswamy, S., & Latif, S. (2009). Cloud security and privacy.
     Beijing: O'Reilly. 

Rodrigues, T. (2012, October 1). Unseen barriers to cloud adoption. Retrieved
     June 24, 2016, from TechRepublic website: http://www.techrepublic.com/blog/
     the-enterprise-cloud/unseen-barriers-to-cloud-adoption/ 

U.S Privacy Breach Laws (week 4)

Having worked for an MSSP (Managed Security Services Provider), I had the privilege of interacting and working with many different clients from different industrial sectors. Each organization depending on the sector they fell under had different reasons for signing up with the MSSP. Even within the same sectors, the different organizations had different drives as to why they needed an information security company to partner with them. We would get the security focused kind to the ‘check-box’ kind, but what was common across board was that for most, the decision was somehow beyond their control and due to regulation, they had to have some security controls in place to avoid being in violation of whatever regulation they fell under. Currently, I work for a financial institution and I now understand how powerful the audit team within the company is. The financial sector is one of the most heavily regulated industry with healthcare being the other ‘unlucky’ candidate and seeing first-hand the pull or push regulators have, I now have a new-found appreciation of why audit is so much revered or avoided depending on when the project deadline is due.

That said, for this week I would like to talk about U.S. privacy breach laws.

You may be wondering how this relates to cybersecurity. You may be asking yourself “I thought as a cybersecurity professional, the focus would be catching the bad guys?” Well, for one, both IT security and audit teams within an organization need to be aware of their State’s data privacy breach laws in order to avoid any nonconformity to compliance requirements which may mean financial penalties and other legal ramifications. When the business gets impacted (negatively), all business units feel the pain, and this includes IT and Information security. Another thing to also note, is that IT or cybersecurity strategy should always align with the business strategy so if regulators ask the business to abide by some rules and regulations, the IT team should be also mapping out ways of meeting those requirements.

Back to U.S. Privacy Breach Laws

Security breach laws typically have provisions regarding who must comply with the law (e.g., businesses, data/ information brokers, government entities, etc.); definitions of “personal information” (e.g., name combined with SSN, driver’s license or state ID, account numbers, etc.); what constitutes a breach (e.g., unauthorized acquisition of data); requirements for notice (e.g., timing or method of notice, who must be notified); and exemptions (e.g., for encrypted information) ("SECURITY BREACH," 2016). Companies should therefore review their data privacy, data security and incident response policies and procedures to not only keep up with requirements, but also any changes that may be made to the State laws. Some of the laws may require a company to be compliant even when not located within the confines of the State. A good example is with third-party service providers who may handle PII data on behalf of their client. This means those vendors are required to adhere to the laws regardless of where they are located. The organization needs to ensure the vendor also implements security measures appropriate to the size, scope, industry and purpose of use of the information collected are implemented and maintained (Halpert & Anderson, 2015).

Another example of how different laws change is with HIPAA and ePHI. Due to the technological advancements under HIPAA, we have ePHI (electronic Protected Health Information) which covers “individually identifiable” “protected health information” sent or stored electronically. Doctors now are using mobile devices and electronic devices to review patient records and even share this information with other medical providers. ePHI dictates how this information can be handled. The HIPAA Ombibus rule defines this transitive chain of possession such that all businesses that may come into contact with ePHI are made responsible for the privacy and security of that information.  This includes many companies that previously had no idea they had to be HIPAA compliant. This shows that all businesses need to be aware of what laws or regulations apply to them even if not directly. The HIPAA Omnibus rule is one such rule that traverses supporting companies and has far reaching consequences if the 3rd party providers do not abide by those mandates.

In conclusion
Due to the rampant data breaches that have occurred over the years attributable to the advancements in technology, in the period between 2006 and 2009, forty-seven states, the District of Columbia, Guam, Puerto Rico and the Virgin Islands enacted legislation requiring private, governmental or educational entities to notify individuals of security breaches of information involving personally identifiable information (PII). The three States that do not have security breach laws are Alabama, New Mexico and South Dakota. It is important for us, as security professionals, to be conversant on what legal requirements bind our industries based on the areas of operation. We may be called upon one day by senior leadership to explain some of these requirements and staying ahead of the curve can come in handy when that time comes.

References
Halpert, J., & Anderson, M. J. (2015, July 20). Data Protection, Privacy and
     Security Alert (US). Retrieved September 9, 2016, from DLA Piper website:
     https://www.dlapiper.com/en/us/insights/publications/2015/07/
     state-breach-notification-laws/

SECURITY BREACH NOTIFICATION LAWS. (2016, January 4). Retrieved September 9,
     2016, from National Conference of State Legislatures website:
     http://www.ncsl.org/research/telecommunications-and-information-technology/

     security-breach-notification-laws.aspx

Internet of Things Overload (week 3)

The Spanish-born American philosopher, George Santayana wrote in his book titled “The Life of Reason”, 1905 that those who cannot remember the past are condemned to repeat it. Time and time again we have seen this school of thought proven true. If we look at it from a social perspective, pick fashion for example; how many times have we ‘brought back’ a style that was the ‘in thing’ back in the days? Plenty of times, I would say. While this is not necessarily a bad thing, it just shows that humans are somehow wired to repeat things. Apply this human nature to computing and information security and we see the same type of threats being resurrected from the ‘dark web cemetery’ and lo and behold! We always get a ‘Gotcha moment’.


Last year, right about this time, I wrote a blog about Botnets and the Internet of Things. The post talked about Conficker and how its logic had a mechanism for seeking out new domains on a daily basis; by mid-2009, Conficker spread to over 10 million computers (Singer, 2011). Fast forward to October, 2016; a DDoS attack began creating problems for Internet users reaching an array of sites, including Twitter, Amazon, Tumblr, Reddit, Spotify and Netflix. Researchers pegged the blame on hacked “Internet of Things” (IoT) devices, such as CCTV video cameras and digital video recorders (Krebs, 2016). This massive DDoS attack was attributed to a malware dubbed ‘Mirai’ (Japanese for ‘the future’), a name that seems to suit the MO of the malware; locate and compromise IoT devices to further grow the botnet and launch DDoS attacks. Mirai scanned the Internet for devices that were not secured; those that still used default user names and passwords and by employing a dictionary attack against those devices with a pre-configured list of default username/password combinations, was able to compromise and take over those devices (Herzberg, Bekerman, & Zeifman, 2016). 

Image Courtesy of ReadWrite.com
We can now see the trend and why George Santayana’s statement is true even for computing and information security. We’ve all seen those pesky reminders setup by IT to change our passwords every so often. Do we receive those messages with joy or view them as just another nuisance from those IT fellas? I bet most of us hope they would stop reminding us about those damn passwords. 

Most issues we observe in today’s cyber world are simply reincarnations of old threats that were existent before and the same mistakes or vulnerabilities that propagated those threats are the same ones, although slightly modified, plaguing us again. An attack could be different in that there is a variant but the core of the attack or what makes it possible most of the time remains the same. Case in point, use of default passwords in devices making it easy for a malware code to perform a brute-force attack against the device successfully.

Question therefore is, why then would IoT manufacturers not step up their game and secure their appliances?

The answer of course is the good ol’ connectivity vs security battle. IoT manufacturers are focused on getting products to market as fast as possible with their priority being connectivity and not security. Market demand and profits associated with these demands are driving decisions and the manufactures are okay with dealing with security implications down the line rather than incorporating the measures at project kick-off.  The IoT realm being relatively new also makes the decision fall on the manufacturers as there are no set standards of what the security landscape should look like for those devices. We have a situation where the product manufacturers determine the appropriate trade-offs for themselves without any best-practice references.

My take on this lack of, or poor IoT security configuration, is that eventually the market and possibly regulators will arm twist the manufacturers into incorporating more solid plans that ensure their products are somewhat secure and the public is not victimized due to negligence on their end, as observed in the case of the Mirai related DDoS attacks. We all love our smart products and the luxury they afford us but if it means compromising our privacy and security, some consumers may opt to roll back to the stone age days where we wrote down our grocery lists on paper instead of the refrigerator sending us a text. I guess the devices aren't as smart as they purport to be after all :)   

References
Denning, T., Tadayoshi, K., & Levy, H. M. (2013). Computer Security and the Modern Home. Communications Of The ACM, 56(1), 94-103. doi:10.1145/2398356.2398377

Herzberg, B., Bekerman, D., & Zeifman, I. (2016, October 26). Breaking Down
     Mirai: An IoT DDoS Botnet Analysis [Blog post]. Retrieved from Imperva
     Incapsula website: https://www.incapsula.com/blog/
     malware-analysis-mirai-ddos-botnet.html

Krebs, B. (2016, October 21). Hacked Cameras, DVRs Powered Today’s Massive
     Internet Outage [Blog post]. Retrieved from KrebsonSecurity website:
     https://krebsonsecurity.com/2016/10/
     hacked-cameras-dvrs-powered-todays-massive-internet-outage/ 


Singer, P. W. (2011, October 21). Mark Bowden’s “Worm: The First Digital
     World War”. Retrieved February 7, 2016, from https://www.washingtonpost.com/
     entertainment/books/mark-bowdens-worm-the-first-digital-world-war/2011/08/30/
     gIQAwcKO4L_story.html 

Tuesday, December 13, 2016

He Say She Say ...The Quest for Credible Information

There’s a running joke for students working on assignments; “if you do a Google search and you need to click on the 2nd page, you are in trouble”. This concept is further emphasized by digital synopsis with their joke; “The Best place to hide a dead body is page 2 of Google search results …or page 1 of Bing”. While these statements are merely jokes, they do have some truth to them and I for one rarely click on page 2 when looking up information on the Internet. Maybe my searches are just specific and I get what I need on page 1 or Google has enough analytics on my preferences that the results returned fit my profile to a T …I will go with the latter. What many people don’t know is that some of the results returned usually don’t necessarily hold the truth we seek and Google is simply ‘serving’ them to us in the order of paid services (in the case of ads) or simply what people are ‘chatting about’, aka what is popular or being clicked on the most.  

Image Courtesy of Designzzz:
Ref http://www.designzzz.com/albert-einstein-quotes/
"The Famous Quote"

We’ve all run into the famous quotes by well known, established individuals, the likes of Einstein and Lincoln. Most of these quotes weren’t even quoted by the authors attached to them; a little Photoshop magic and voila! …we have a winning quote. Not all that is published on the Internet however is fabricated. Before the Internet morphed into the ‘beast’ it is today, people would for example, go to libraries and use published books for their research or they would reach out to subject matter experts like professors for guidance. All these information is now available in the digital space and while it co-habits this space with a lot of other ‘junk’ information, credible information can still be found and used for our day to day research and knowledge adventures.

For this blog post, we will focus on how to identify credible sources of information for threats, vulnerabilities, updates, and security news in general. 

My ‘primary’ go to resources however, are as follows:

National Institute of Standards and Technology (NIST): NIST is an agency of the U.S. Department of Commerce. It publishes security standards and guidelines plus other security-related information that can be used to support decisions by individuals all the way up to industry and government. If you are looking for a ‘how to guide on securing your home wireless network’, NIST will have it. If it’s a business thinking about ‘how to protect their confidential data’, NIST has that too.

National Vulnerability Database (NVD) and Common Vulnerabilities and Exposures (CVE): If I want to know what vulnerabilities exist on my system, my two go to resource are NVD (sponsored by DHS/NCCIC/US-CERT) and MITRE’s CVE. both these sites provide valuable information on known vulnerabilities with recommendations on how to mitigate them.

SANS Internet Storm Center and United States Computer Emergency Readiness Team (US-CERT) both provide up to date news and advisories for most computer security topics. If you want to know about the latest patch, security news, bulletins, or a security update; both of these resources are credible.

Other than the resources mentioned above, I also use Information Technology & Security websites that publish peer reviewed articles. Packet storm security for example provides information on exploits, advisories, tools and whitepapers on various cyber related topics. CSO Online, Dark Reading, How-to-geek and many more provide useful information, tips and tricks and just general cyber-related information. Bloggers like Lenny Zeltser or Krebs on security are also credible and their posts can be used as resources given their expertise in the cyber realm. 

In conclusion

There are plenty of credible resources of information out there and this blog would not be enough to list them all out. When looking up information, we should not trust everything presented to us without verifying the source and backing that information up with other sources. Timelines and who wrote the article also matter; some authors hold more weight than others by virtue of being subject matter experts in their processional fields. Outdated articles may lose credibility due to changes over time; an issue that was critical 10 years ago, may not be viewed the same today. When you have a conflict of information, evaluate the sources and use the aforementioned logic; at the end of the day we can always learn from our mistakes …even misinformation.  

As a footnote, while I agree that Wikipedia should always be taken with a grain of salt, I think it does provide some basic information that can be useful in quickly determining definitions and finding well known information. For example, if you want to know what service runs on a given port based on a firewall report you just received, wiki could come in handy. However, an alternative and more credible source for that scenario would be IANA (Internet Assigned Numbers Authority). If there was a conflict in information between those 2 resources, IANA would take precedence over Wiki given IANA is an authority when it comes to protocol addresses and Internet Architecture.