Search This Blog

Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Sunday, December 28, 2014

Northrop Grumman & Cybersecurity

From Northrop Grumman:




On today’s electronic battlefields, we’re bringing #cyberand #EW together to keep warfighters safe.

Tuesday, August 28, 2012

RSA Chief Rallies for Intelligence-Driven Security to Help Ensure Trust in the Digital World


EMC Press Release
RSA Chief Rallies for Intelligence-Driven Security to Help Ensure Trust in the Digital World
RSA Executive Chairman Art Coviello Addresses Chinese IT Security Community with Ideas to Rethink and Rebalance Security Spending, Address IT Skills Shortage and Promote Cyber-Information Sharing Globally
RSA CONFERENCE CHINA 2012 – CHENGDU, China - August 28, 2012

News Summary:

  • RSA Executive Chairman Art Coviello outlined an intelligence–driven model for cyber security in his opening keynote at RSA® Conference China 2012.
  • Mr. Coviello challenged conventional thinking on security – attributing shortages of qualified IT talent, the lack of understanding and cooperation on security issues between nations and budget inertia as key drivers holding security back from where it needs to be.
  • Mr. Coviello advanced four major recommendations for how the industry must adapt to help ensure trust in the digital world.

Full Story:

In his opening keynote at RSA® Conference China 2012, Art Coviello, Executive Vice President of EMC and Executive Chairman of RSA, The Security Division of EMC (NYSE: EMC), outlined an intelligence-driven model for cyber security. While addressing the crowd at the third RSA Conference in China, held in Chengdu, Mr. Coviello challenged conventional thinking on security – attributing shortages of qualified IT talent, the lack of understanding and cooperation on security issues between nations and budget inertia as key drivers holding security back from where it needs to be.
Mr. Coviello pointed out that today the vast majority of IT security spending is still allocated towards static and inflexible perimeter-based technologies that are increasingly ineffective against today’s threats. In an age of interconnectivity and openness where breaches are to be expected even among the best-defended networks, the balance must shift to accommodate timely detection and response.
"Without rebalancing this spend it will become increasingly difficult, if not impossible, to detect sophisticated attackers quickly and with enough detail and accuracy to mount an effective defense," Mr. Coviello said. "The perimeter is easily breached and as attacks inside the perimeter continue to become more sophisticated, only equally sophisticated detection capabilities and analytics can enable a response that is quick enough to help avoid loss."
Mr. Coviello also addressed several other issues "holding back security," including the severe skills shortage of competent IT security professionals. A 2011 Global Information Security Workforce Study by Frost & Sullivan suggests that despite a forecasted addition of more than two million new IT security professionals by 2015, it may still not be enough to support global demand. Mr. Coviello also pointed out the lack of cooperation among government entities and a broad lack of understanding among these governments, media, consumers and private and public organizations which position the security industry at a disadvantage against the constantly evolving threat landscape.
"The implication of these forces is holding security back. Security models are not moving fast enough to make the transition from perimeter-based to intelligence-based security, while adversaries become more sophisticated," Mr. Coviello said.
Mr. Coviello advanced four major recommendations for how the industry must adapt:
  • Commitment to intelligence-based security – The industry must evaluate risk from both the inside out and outside in, looking at risk in the context of vulnerability, probability and materiality. Based on that information, re-evaluate budgets and balance spending priorities accordingly.
  • The best defense is a layered defense – The focus in a layered defense must be on controls that deliver the situational awareness, deep visibility and environmental agility to deter, detect, and defeat sophisticated targeted attacks.
  • Find the "right" talent – The "right" talent will be people with more education and training and those working in anti-fraud groups. More value should be placed on security analytic skills over capabilities in traditional security or IT infrastructure management.
  • Cooperation – Collectively nurture an ecosystem of governments, vendors and user organizations that work together to foster more trust in the digital world. Additionally, markets have to operate on mutual international respect for intellectual property
Mr. Coviello added, "We are only as strong as our weakest link and we are interdependent as never before. Attacks on one of us have the potential to be attacks on all. We must adapt and change…The economies of the world are too fragile to run the risk of not tackling this problem head on."
Reflecting on the challenge facing the global security industry and the need for all parties to work cooperatively against mounting digital threats, Mr. Coviello invoked the wisdom of Zhuge Liang, chancellor of the state of Shu Han in second century China:
"In closing I turn again to the wisdom of Zhuge Liang about the need to work together – he said 'It is not wise to continue on alone. We need to wait for our allies.' Let us all be allied in meeting this challenge."
Mr. Coviello's written keynote remarks are available by request in both Mandarin and English. Please email the RSA press contacts listed below.
About RSA

RSA, The Security Division of EMC, is the premier provider of security, risk and compliance management solutions for business acceleration. RSA helps the world's leading organizations succeed by solving their most complex and sensitive security challenges. These challenges include managing organizational risk, safeguarding mobile access and collaboration, proving compliance, and securing virtual and cloud environments.
Combining business-critical controls in identity assurance, encryption & key management, SIEM, Data Loss Prevention and Fraud Protection with industry leading eGRC capabilities and robust consulting services, RSA brings visibility and trust to millions of user identities, the transactions that they perform and the data that is generated. For more information, please visit www.EMC.com/RSA.

Monday, August 27, 2012

Saudi Oil Producer’s Computers Restored After Cyberattack


The following is an excerpt from an article in 



The New York Times
Monday, August 27, 2012

Saudi Oil Producer’s Computers Restored After Cyberattack

By REUTERS DUBAI (Reuters) — Saudi Aramco, the world’s biggest oil producer, has resumed operating its main internal computer networks after a virus infected about 30,000 of its workstations earlier this month, the company said Sunday.

Immediately after the Aug. 15 attack, the company announced it had cut off its electronic systems from outside access to prevent further attacks.

On Sunday, Saudi Aramco said the workstations had been cleansed of the virus and restored to service. Oil exploration and production were not affected because they operate on isolated systems, it said.

“We would like to emphasize and assure our stakeholders, customers and partners that our core businesses of oil and gas exploration, production and distribution from the wellhead to the distribution network were unaffected and are functioning as reliably as ever,” Saudi Aramco’s chief executive, Khalid al-Falih, said in a statement.

However, one of Saudi Aramco’s Web sites taken offline after the attack — www.aramco.com — remained down on Sunday. E-mails sent by Reuters to people within the company continued to bounce back.

The company said that the virus “originated from external sources,” and that an investigation into the causes of the incident and those responsible was continuing. It did not elaborate.

For more, visit www.nytimes.com.

Saturday, March 31, 2012

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities 

U.S. Attorney’s OfficeMarch 26, 2012
  • Central District of California(213) 894-2434
LOS ANGELES—A Florida man pleaded guilty today to a series of cyber-related crimes relating to his hacking into the personal e-mail accounts of more than 50 individuals associated with the entertainment industry.
Christopher Chaney, 35, of Jacksonville, Florida, pleaded guilty to nine felony counts of a 28-count first superseding indictment, including unauthorized access to protected computers in furtherance of wiretapping and wire fraud, unauthorized damage to protected computers resulting in more than $5,000 loss and physical harm, and wiretapping. At the conclusion of the hearing, United States District Court Judge S. James Otero ordered Chaney taken into custody.
During the hearing, Chaney admitted that from at least November 2010 to October 2011, he hacked into the e-mail accounts of Scarlett Johansson, Mila Kunis, Renee Olstead, and others by taking the victims’ e-mail addresses, clicking on the “Forgot your password?” feature, and then re-setting the victims’ passwords by correctly answering their security questions using publicly available information he found by searching the Internet. Once Chaney gained exclusive control of the victims’ e-mail accounts, he was able to access all of their e-mail boxes. While in the accounts, Chaney also went through their contact lists to find e-mail addresses of potential new hacking targets.
In pleading guilty to the wiretapping charges, Chaney admitted that, for most victims, he also changed their e-mail account settings by inserting his alias e-mail address into the forwarding feature so that a duplicate copy of all incoming e-mails to the victims—including any attachments—would be sent virtually simultaneously to Chaney without the victims’ knowledge. Most victims did not check their account settings, so even after they regained control of their e-mail accounts, Chaney’s alias address remained in their account settings. As a result, for many victims, copies of their incoming e-mails, including attachments, were sent to Chaney for weeks or months without their knowledge, causing Chaney to receive thousands of victim e-mails. In addition, when a victim reset his/her password to regain control of the account, Chaney sometimes hacked into the account again and reset the password, sometimes multiple times, in order to continue illegally accessing that victim’s account.
Chaney admitted that as his hacking scheme became more extensive, he began using a proxy service called “Hide My IP” because he knew what he was doing was illegal and wanted to “cover his tracks” so that law enforcement agents could not trace the hacking back to his home computer. Even after his home computers were seized by law enforcement agents pursuant to a federal search warrant, but before he was arrested, Chaney used another computer to hack into another victim’s e-mail account.
Chaney further admitted that as a result of his hacking scheme, he obtained numerous private communications, private photographs, and confidential documents from the victims’ e-mail accounts. The confidential documents included business contracts, scripts, letters, driver’s license information, and Social Security information. On several occasions, after hacking into victim accounts, Chaney sent e-mails from the hacked accounts to friends of the victims, fraudulently posing as the victims to request more private photographs. Chaney downloaded many of the confidential documents and photographs he stole to his home computer, where he saved them on his hard drive in separate computer file folders. Chaney e-mailed many of the stolen photographs to others, including another hacker and two gossip websites. As a result, some of those stolen photographs, several of which were explicit, were later posted on the Internet.
“Today’s guilty pleas shine a bright light on the dark underworld of computer hacking,” said United States Attorney André Birotte, Jr., whose office prosecuted the case. “This case demonstrates that everyone, even public figures, should take precautions to shield their personal information from the hackers that inhabit that dark underworld. It also demonstrates that the Department of Justice will take whatever steps are necessary to protect Americans from harm in cyberspace.”
“Mr. Chaney’s admission to compromising victim accounts, utilizing both technically and socially engineered means, demonstrates the persistence and extent to which a hacker will go to obtain private information,” said Steven Martinez, Assistant Director in Charge of the FBI’s Los Angeles Field Office. “This case sends an important message to all users of Internet-accessible media that practicing good computer security makes us less vulnerable to this type of attack. The FBI remains committed to investigating cyber adversaries who target protected computers, whether of private citizens or the nation’s critical infrastructure.”
Each charge of unauthorized access to a protected computer carries a maximum of five years in prison, each charge of unauthorized damage to a protected computer carries a maximum charge of 10 years in prison, and each charge of wiretapping carries a maximum of five years in prison. As a result of all of today’s guilty pleas, Chaney faces a total statutory maximum sentence of 60 years in federal prison. In addition to the possible prison term, as part of his plea agreement filed in federal court, Chaney agreed to forfeit his computers and related devices seized during the investigation, to pay restitution to all of the victims for any losses they suffered, and to comply with strict restrictions regarding his future use of computers and computer-related devices. In exchange, the government agreed to dismiss the remaining counts, including nine counts of aggravated identity theft, at the time defendant is sentenced.
Chaney is scheduled to be sentenced by United States District Judge S. James Otero on July 23, 2012.
The investigation of this case was led and conducted by the Federal Bureau of Investigation.

Wednesday, March 28, 2012

ESET Foundation to Support Securing Our eCity® Initiative and Drive Awareness and Education for Cyber and Societal Challenges

Note to visitors: We have moved!  For current news and information, please visit our successor blogs: http://JBK-BizTech.blogspot.com and http://JBK-Current-Events.blogspot.com.  Thank you. 




San Diego, CA, March 14, 2012

ESET Foundation to Support Securing Our eCity® Initiative and Drive Awareness and Education for Cyber and Societal Challenges

ESET today announced that it has established the ESET Foundation, a non-profit, 501(c)(3) organization. ESET has established the ESET Foundation to further support its Securing Our eCity initiative and commitment to community collaboration to support cybersecurity awareness, education and societal challenges within the San Diego community and across the nation.

“The ESET Foundation is strongly committed to providing support to the greater San Diego area and to computer users across the world,” said Anton Zajac, president of ESET North America and ESET Foundation president. “We believe that cybersecurity is a shared responsibility and are working to arm computer users with the tools and knowledge necessary to become safer in cyber space. We are honored by the support that the community and nation have given to Securing Our eCity and are thrilled to have such prominent representatives from industry and community on our board of directors for the foundation.” 

In mid-2008, Securing Our eCity was established and a movement to educate San Diego’s digital citizens was born. Securing Our eCity provides awareness of potential issues and offers free cybersecurity information and education that assists businesses, families, youths and seniors to better prepare for a safer cyber experience in rapidly changing technology driven environments.

“With cybersecurity being a critical issue, programs like Securing Our eCity are crucial in providing the necessary resources related to education to help keep businesses and consumers safe in cyber space,” said Jessie J. Knight Jr., chairman and CEO of San Diego Gas & Electric (SDG&E) and ESET Foundation chairperson. “At SDG&E, we are committed to protecting our critical infrastructure and working with the community to create a new generation of cyber-savvy citizens. I look forward to working with the ESET Foundation to continue to bring cybersecurity awareness, education and preparation to the residents of San Diego.”

This past year, Securing Our eCity worked with organizations like the San Diego Police Foundation, Girl Scouts USA, The Boy Scouts of America and others to bring cybersecurity awareness and education to the San Diego community. Additionally, Securing Our eCity expanded nationally by aligning with other various cyber initiatives across the nation including: Cyber City USA in San Antonio, TX, WC4 in Washtenaw County, MI, and Cyber Maryland to advance cybersecurity awareness, education and preparation through community driven programs. Furthermore, Securing Our eCity’s 2011 fall symposium and awards ceremony was attended by more than 350 security professionals, business executives and managers, IT consultants, government and law enforcement officials.

“Securing Our eCity has done a tremendous job of working to make San Diego a place where people can build a better cybersecurity environment through community engagement,” said Michael Kaiser, executive director of the National Cyber Security Alliance and ESET Foundation board member. “We are excited that the National Cyber Security Alliance has been a part of Securing Our eCity from the beginning, and we look forward to continuing to support the program, both in San Diego and across the nation.”

ESET Foundation board members and officers include, Jessie J. Knight Jr., chairperson, Anton Zajac, president, Randy Frisch, treasurer and Pamela Richardson, secretary. Additional board members include, Andrew Lee, CEO of ESET North America, Darin Andersen, general manager North America for Norman Defense Systems, Michael Kaiser, executive director of the National Cyber Security Alliance, Liz Fraumann, director of cybersecurity awareness and education at ESET North America, as well as other members of the San Diego community.

For additional information about Securing Our eCity, upcoming events and ways to get involved, please visit, http://www.securingourecity.com/.

About The ESET Foundation
Founded in late 2011, the ESET Foundation’s mission is to foster community collaboration to create educational awareness for cyber and societal challenges. Headquarted in San Diego, the ESET Foundation’s signature program is the award-winning Securing Our eCity®, recognized in 2010 by the White House and the Department of Homeland Security (DHS) for the best local and community program. The ESET Foundation brings together like-minded organizations whose primary goal is to encourage cybersecurity for business, families, youth and seniors. For more information visit www.esetfoundation.org or, please email Steve.Kovsky@esetfoundation.org
 
About Securing Our eCity
Securing Our eCity (SOeC) is an initiative created and led by ESET North America, a San Diego based software security company. SOeC is focused on fostering public/private partnerships at local, state, national and international levels while helping counter cyber threats and creating more cyber secure communities across the globe. Stakeholders from coast to coast including consumer advocates, business owners, and governmental agencies (law enforcement and legislative bodies) have come together to raise awareness, education and help individuals and businesses prepare for cyber security challenges now and in the future. The founding stakeholders include ESET North America, San Diego Business Journal, San Diego Gas & Electric (SDG&E), San Diego Regional Chamber of Commerce, UCSD and SDSU. To learn more, visit: www.securingourecity.org

For the latest cyber threat and education information, follow Securing Our eCity on Twitter, become a fan on Facebook or follow our blog at http://www.securingourecity.org/blog.

Thursday, March 22, 2012

Real Cost of a Cyber Attack

A new surbey reveals malicious hacking of government and corporate data accounted for more than half of all data thefts last year.  A CNBC interview provides insight on the cost of security threats, with Janet Napolitano, Department of Homeland Security secretary.


http://video.cnbc.com/gallery/?video=3000080031

Thursday, March 15, 2012

LMT: 4th Annual IT Day

Lockheed Martin to Hold Fourth Annual Information Technology Day in Jackson, Miss. on March 30


JACKSON, Miss., March 15, 2012 – Lockheed Martin [NYSE: LMT] will host the fourth annual Information Technology (IT) Day at the Jackson Convention Complex on Friday, March 30 to increase IT education and awareness, as well as to encourage networking and collaboration in industry, academia and the community. The day-long event, which runs from 9 a.m. to 4 p.m., is free of charge and open to the public.
The 2012 IT Day theme is “Forecast the Future” and will feature an expanded agenda. Attendees are invited to participate in educational sessions including business collaboration via cyber security, mobility, cloud computing and big data.  The agenda also features a panel of industry experts discussing topics such as big data and cloud computing; a seminar on how to do business with Lockheed Martin; and a workshop on growing your business.
“We are honored to host IT Day once again this year,” said MacArthur DeShazer, director, Small Business Development, Lockheed Martin Information Systems & Global Solutions (IS&GS).  “We opened a state-of-the-art Mission Support Center in nearby Clinton six months ago, so this event allows us to increase our presence in this community and region—one that we value based on its outstanding talent, economic partnerships and wealth of academic resources.”
The IT Day luncheon will feature a keynote address by Stephen S. Pawlowski, senior fellow, chief technology officer for the Datacenter and Connected Systems Group, and general manager for Datacenter and Connected Systems Pathfinding for Intel Corporation. Pawlowski will speak on Intel’s vision of what the rapid evolution of cloud computing will look like in 2015 and also will take questions from the audience.
More than 800 area high school and college students will participate in the IT Day program, as well as compete in sponsored quiz bowl challenges. These events, in partnership with Jackson State University and Tougaloo College, are designed to increase the students’ knowledge and interest in Science, Technology, Engineering and Math (STEM) subjects, as well as provide them with a look at what’s happening in the IT industry.  The educational track sessions have been expanded based on feedback from area high schools, colleges and universities.
“JSU is delighted to partner with Lockheed Martin in sponsoring the IT Day STEM Bowl,” said Rita Presley, associate vice president for Research & Sponsored Programs, Jackson State University. “We will provide an important opportunity for area high school students to compete in solving a unique challenge. This event encourages the students to think outside the box, which is an acute skill needed to foster technology innovation.”
A vendor expo will be open throughout the day, showcasing technology and services from more than 50 local and national IT vendors and academic partners. The expo provides a unique opportunity to network and exchange information in a more relaxed setting. Attendees will be able to experience Lockheed Martin’s innovations such as its Human Immersion Laboratory— an advanced technology virtual reality and simulation laboratory that offers cost effective, unique collaborative solutions for exploring and solving customer specific missions; insight on how to harness new capabilities through nanotechnology; iPhone Rapid Prototyper—a Lockheed Martin-designed tool to make smartphone development easy for the masses; and a variety of touch-screen displays. Additionally, an entertaining robot named Sprockit will make an appearance again this year to provide a light-hearted connection to technology innovation. Lockheed Martin recruiters also will be on-site to share information about jobs in the Mississippi area.
For more detailed event information, visit http://www.itdaymississippi.org.
Lockheed Martin opened a 33,000-square-foot Mission Support Center in 2011 in Clinton, Miss., to support diverse mission and technology services that the corporation provides to federal agencies. This facility also establishes Lockheed Martin's Gulf Coast Technology Hub, which partners with existing East and West Coast Technology Hubs to offer innovative cloud computing, cyber security, big data and mobile computing solutions to federal customers.

Wednesday, February 29, 2012

25 Suspected Hackers Arrested

Excerpt from an article in

The New York Times
Wednesday, February 29, 2012

25 Suspected Hackers Arrested in International Raids

By THE ASSOCIATED PRESS

PARIS (AP) — Twenty-five suspected members of the loose-knit Anonymous hacker movement have been arrested in a sweep across Europe and South America, Interpol, the global police agency, said on Tuesday.

The arrests, in Argentina, Chile, Colombia and Spain were carried out by national law-enforcement officers working under the support of Interpol’s Latin American Working Group of Experts on Information Technology Crime, Interpol said in a statement.

Those arrested, who ranged in age between 17 and 40, are suspected of planning coordinated cyber-attacks against institutions including Colombia’s defense ministry and presidential Web sites, Chile’s Endesa electricity company and national library, and other targets.

The arrests followed an ongoing investigation begun in mid-February, which comprised searches of 40 locations in 15 cities and included the seizure of 250 pieces of information technology equipment and mobile phones, Interpol said.

Among the 25 people arrested were four suspected Anonymous hackers seized in connection with attacks on Spanish political party Web sites, the Spanish police announced. A national police statement said two servers used by the group in Bulgaria and the Czech Republic have been blocked. It said the four arrested included the suspected manager of Anonymous’s computer operations in Spain and Latin America, who was identified only by his initials and the aliases “Thunder” and “Pacotron.”

The four are suspected of defacing websites, carrying out denial-of-service attacks and publishing data online about police assigned to the royal palace and the premier’s office.

Anonymous has no real membership structure. Hackers, activists, and supporters can claim allegiance to its freewheeling principles so it is not clear what impact the arrests will have. Some Internet chatter appeared to point to the possibility of a revenge attack on Interpol’s Web site, but the police organization’s home page appeared to be operating normally late Tuesday.

Monday, February 13, 2012

Beware of Valentine's Day Malware Distribution

News release from Panda Security:


Beware of Valentine’s Day Malware Distribution Campaigns, PandaLabs reports

  • Here are some examples of malware that used social engineering to infect users on this festive occasion
  • PandaLabs offers tips to avoid computer viruses on Valentine’s Day
Malware that uses events like Valentine’s Day, Christmas or Halloween as a lure to trick users and infect computers is now a well-established feature of the IT security calendar. Once again, this year it will be no surprise to see numerous emails in circulation with links for downloading romantic greeting cards, videos, gift ideas, or Facebook and Twitter messages related to Valentine’s Day.
Social engineering is cyber-crooks’ preferred technique for deceiving users. In these cases it basically involves obtaining confidential information from users by convincing them to take a series of actions. Crimeware and social engineering go hand-in-hand: a carefully selected social engineering ploy convinces users to hand over their data or install a malicious program which captures information and sends it on to the fraudsters.
Cyber-crooks, however, are also exploiting other channels, such as Facebook, Twitter or Google+, and given the access to millions of users that these social networks provide, they have become just as popular among the criminal fraternity for spreading malware as email.
A new Facebook attack has recently been discovered that uses users’ walls to spread. An apparently harmless message invites users to install a Valentine’s Day theme on Facebook. However, if the user clicks the wall post, they are redirected to a page where they are prompted to install the theme. This installs a malware file which, once run, displays ads from other websites. It also downloads an extension that monitors Web activities and redirects sessions to survey pages that request sensitive information like phone numbers.
Some weeks ago, the PandaLabs blog reported on a link included in a Twitter profile that took users to a dating site: http://pandalabs.pandasecurity.com/sex-lies-and-twitter/. Special dates like Valentine’s Day can see a proliferation of malicious Twitter posts used to steal users’ confidential data and empty their bank accounts through social engineering.
Here is a collection of some of the Valentine’s Day-themed malware campaigns detected by PandaLabs, the anti-malware laboratory of Panda Security, in recent years:
Waledac.C: This worm spread by email trying to pass itself off as a greeting card. The email message included a link to download the card. However, if the user clicked the link and accepted the subsequent file download they were actually letting the Waledac.C worm into their computer. Once it infected the computer, the worm used the affected user’s email to send out spam.
I Love.exe you: This was a RAT (Remote Access Trojan) that gave attackers access to the victim’s computer and all their personal information. The Trojan allowed the virus creator to access target computers remotely, steal passwords and manage files.
Nuwar.OL: This worm spread in email messages with subjects like “I love You So Much”, “Inside My Heart” or “You in My Dreams”. The text of the email included a link to a website that downloaded the malicious code. The page was very simple and looked like a romantic greeting card with a large pink heart. Once it infected a computer, the worm sent out a large amount of emails, creating a heavy load on networks and slowing down computers.
Website that downloaded the Nuwar.OL worm
Valentin.E: This worm spread by email in messages with subjects like “Searching for True Love” or “True Love” and an attached file called “friends4u”. If the targeted user opened the file, a copy of the worm was downloaded. Then, the worm sent out emails with copies of itself from the infected computer to spread and infect more users.
Desktop wallpaper displayed by Valentin.E.
Storm Worm: This worm spread via email by employing a number of lures, one of them exploiting Valentine’s Day. If the targeted user clicked the link in the email, a Web page was displayed while the worm was downloaded in the background.
Web page displayed by Storm Worm
PandaLabs offers users a series of tips to avoid falling victim to computer threats:
  • Do not open emails or messages received on social networks from unknown senders.
  • Do not click any links included in email messages, even though they may come from reliable sources. It is better to type the URL directly in the browser. This rule applies to messages received through any mail client, as well as those in Facebook, Twitter, or other social networks or messaging applications, etc. If you do click on any such links, take a close look at the page you arrive at. If you don’t recognize it, close your browser.
  • Do not run attached files that come from unknown sources. Especially these days, stay on the alert for files that claim to be Valentine Day’s greeting cards, romantic videos, etc.
  • Even if the page seems legitimate, but asks you to download something, you should be suspicious and don’t accept the download. If, in any event, you download and install any type of executable file and you begin to see unusual messages on your computer, you have probably been infected with malware.
  • If you are making any purchases online, type the address of the store in the browser, rather than going through any links that have been sent to you. Only buy online from sites that have a solid reputation and offer secure transactions, encrypting all information that is entered in the page.
  • Do not use shared or public computers, or an unsecured WiFi connection, for making transactions or operations that require you to enter passwords or other personal details.
  • Have an effective security solution installed, capable of detecting both known and new malware strains.
Panda Security offers you several free tools for scanning computers for malware, like Panda Cloud Antivirus:www.cloudantivirus.com

Thursday, February 9, 2012

Sandia to Help IT Professionals w/ DNS Vulnerabilities

News release from Sandia Labs:

January 11, 2012


Sandia cyber project looks to help IT professionals with complex Domain Name System (DNS) vulnerabilities

LIVERMORE, Calif. — Sandia National Laboratories computer scientist Casey Deccio has developed a visualization tool known as DNSViz to help network administrators within the federal government and global IT community better understand Domain Name System Security (DNSSEC) and to help them troubleshoot problems. (Click here to see a short video of Deccio discussing the DNSViz tool.)
DNSViz
Sandia computer scientist Casey Deccio developed a software tool called DNSViz to help network administrators with Domain Name System (DNS) vulnerabilities. DNSViz provides a visual analysis of the DNSSEC authentication chain for a domain name and its resolution path in the DNS namespace. 

DNSSEC is a security feature mandated for all federal information systems by the White House’s Office of Management and Budget (OMB). The 2008 mandate requires that “the top level .gov domain will be DNSSEC-signed, and processes to enable secure delegated sub-domains will be developed.”

The entity that serves to translate the hostname of a Uniform Resource Locator (URL) into an Internet Protocol (IP) address is known as the Domain Name System (DNS). A DNS “lookup” is a prerequisite for doing almost anything on the Internet, including Web browsing, emailing or videoconferencing.

Although the mandate made perfect sense, said Deccio, there soon emerged a problem when .gov organizations actually began deploying DNSSEC.

“DNSSEC is hard to configure correctly and has to undergo regular maintenance,” he said. “It adds a great deal of complexity to IT systems, and if configured improperly or deployed onto servers that aren’t fully compatible, it keeps users from accessing .gov sites. They just get error responses.”

The still-new DNSSEC security feature is designed to allow user applications like Web browsers to ensure that the IP addresses they have received from the DNS have not been “spoofed” by anyone with ill intent. As such, Internet-connected systems within the government can verify that the responses are authoritative and have not been altered. Still, the hiccups with implementing DNSSEC convinced Deccio that there was a need for a tool like DNSViz.

DNS, said Deccio, is inherently insecure. Without DNSSEC, tampering by third-party attackers could go undetected, thus redirecting online communications to unwanted destinations. This represents a particularly troublesome problem for .gov addresses owned by government organizations guarding national security information and other vital data.

Deccio believes DNSSEC is of little use if network administrators don’t know how to configure or use it.
He describes DNSViz as a “tool for visualizing the status of a DNS zone.” It provides a visual analysis of the DNSSEC authentication chain for a domain name and its resolution path in the DNS namespace, made available via a Web browser to any Internet user at http://dnsviz.net/. It visually highlights and describes configuration errors detected by the tool to assist administrators in identifying and fixing DNSSEC-related configuration problems.

DNSViz brings together all the components that work together for DNSSEC to function properly into a single graphical representation. The resulting visualization is a collection of configuration data and relationships that are otherwise difficult to assemble, assess and understand.

To help network administrators in their DNSSEC deployment, Sandia’s DNSViz tool functions in two primary ways: It actively analyzes a domain name by performing pertinent DNS lookups and it makes the analysis available via the Web interface. The active analysis occurs periodically to build a history of DNSSEC deployment over time and provide a historical reference for DNS administrators.

Currently, the Web interface is the primary source for viewers to observe data, though Deccio intends to expand DNSViz functionality to allow access via other means. For example, alert mechanisms might be used to inform affected parties, and application programming interfaces (API) can be designed to allow administrators to programmatically access the information instead of manually browsing the DNSViz website.
Deccio has the tool running in the background on Sandia/California’s servers, monitoring a list of some 100,000 DNS names. It performs an analysis a couple times each day and offers a situational awareness of what the DNS configuration for each name looks like from top to bottom.

Though the functionality provided by DNSViz could potentially be included in a marketable software product that’s sold by a for-profit company, Deccio says he envisions it as an open-source tool available to anyone who needs it. With further funding, he hopes to expand the tool so that it can analyze DNS health and security on a continuous basis, essentially creating a full-blown monitoring system that is scalable, versatile and more informational.

Safer Internet Day


News release from IBM:


IBM Releases Free Internet Security Training Tools to Educate Students, Teachers and Parents on Digital Responsibility

IBMers Volunteer to Teach Students How to Protect their Personal Data in an Online Environment


ARMONK, N.Y. - 07 Feb 2012:  IBM (NYSE: IBM) today announced that in conjunction with Safer Internet Day, (#SID2012) it will release free Internet safety training tools for students and have thousands of volunteers working to help raise awareness and educate students and businesses on Internet safety and digital responsibility.
IBM is unveiling three free volunteer kits to better educate students, parents and teachers on Internet safety:
  • Control Your Online Identity  - A volunteer education kit, it is designed to help teenagers learn to protect personal data online and reputation online. Teenagers are typically savvy about how to use the Internet, but often unaware about what happens to personal data once it's shared. This presentation and volunteer information helps students learn how to protect personal data and control how they present themselves online.
  • Internet Safety Coaching - Aimed at teachers or adults working with children, this is a general primer on Internet safety providing basic information about common Internet activities by young people including instant messaging and social networking.   This kit is designed to raise awareness of Internet safety and how to have a meaningful and open dialogue with children on this topic.
  • Cyberbullying -- Aimed at parents or adults who work with children, this activity helps adults learn about how young people use the Internet today and how to recognize cyberbullying symptoms, how to prevent online bullying from happening and how to intervene if it does happen.
"IBMers are committed to helping educate people on ways to safely and securely use the Internet," said Harriet Pearson, IBM Security Counsel and Chief Privacy Officer. "The resources we are donating will help teachers and parents raise awareness that most Internet-based threats to individual and computer security can significantly be reduced by actions that informed users take themselves."
In conjunction with today's announcement, IBM volunteers around the world are educating communities about Internet safety. Some select activities include:
  • In Italy, an IBM team will conduct events in local schools using both the IBM materials and afilm from Safer Internet Day to discuss Internet safety and cyberbullying.
Last year IBM employees donated more than three million hours of volunteer service.  The company has donated 34 volunteer kits to help both IBMers as well as community members have meaningful activities and dialogues in the community about various issues.
Since its inception in 2004, Safer Internet Day interest has grown to reach all five continents and almost 80 countries, from Canada to South Korea and Russia to Kenya, including all 27 countries of the European Union. The goal of the day is to help make the Internet a better place for our children and young people.
About IBM
For more information on IBM volunteer and citizenship efforts, please visit www.citizenibm.com
About InsafeInsafe is the European Safer Internet awareness-raising network co-funded by the European Commission. It comprises national contact centres across the European Union and in Iceland, Norway and Russia, with partner organisations around the world. Insafe aims at empowering users to benefit from the positive aspects of internet whilst avoiding the potential risks. Further information is available at www.saferinternet.org or contact info-insafe@eun.org.
About Safer Internet Day
Safer Internet Day is part of a global drive by awareness-raising partners to promote a safer Internet for all users, especially young people. It is organised by INSAFE in the framework of the European Commission's Safer Internet Programme.

Thursday, February 2, 2012

Malware Creation Hit Record High in 2011


News release from Panda Security:

January 31, 2012


Malware Creation hit a New Record High in 2011 with 26 million samples

  • Trojans continue to be the most pervasive malware threat
  • China, Thailand and Taiwan are the world’s most infected countries
  • Data theft, social media and cyber-war take the spotlight
  • The full report is available at http://press.pandasecurity.com/press-room/reports/
PandaLabs, the antimalware laboratory of Panda Security, has released its 2011 Annual Security Report, which details an extremely interesting year of data theft, social networking attacks and cyber-warfare. According to the report, malware creation hit a new record high in 2011 with 26 million new strains in circulation, nearly one-third of all malware that has ever existed and been classified by the company (88 million).
These figures show cyber-criminals’ sheer capacity to automate the creation of new malware variants, further evidenced by the average number of new threats created and released every day increasing from 63,000 to 73,000 since last year. Panda Security leverages Collective Intelligence, a cloud-based proprietary system that automatically detects, analyzes and classifies 99.4 percent of all malware received, leaving just 0.6 percent to be dealt with manually. In November 2011, PandaLabs announced that Collective Intelligence had reached a historic milestone by processing 200 million files, and this number has already reached 210 million.
Malware
In 2011, Trojans dominated the threat landscape more than ever before. Whereas in 2009 Trojans made up 60 percent of all malware, the percentage dropped to 56 percent in 2010. Last year, however, the percentage jumped up to 73 percent, so that three out of every four new malware strains created were Trojans, followed by viruses (14.24 percent) and worms (8.13 percent).
The countries leading the list of most infections are once again Thailand, China and Taiwan, with 60, 56 and 52 percent of infected computers respectively. These are actually the only countries that exceed the worldwide average of 38.49 percent.
2011: The year of cyber-attacks, social media and cyber-war
The report offers a general view of the most important events regarding computer security in 2011. Sony suffered a massive breach that led to the theft of data belonging to 100 million user accounts in what is probably the largest-ever Internet security break-in, whereas the Steam video game service, used by 35 million people, was also compromised by hackers.
Social networking sites, mainly Facebook and Twitter, play a vital role in the life of Internet users and are extensively covered in the report. 2011 witnessed the launch of a new social media service in a bid to rival Facebook: Google+. Despite its rapid growth, with more than 25 million users registered in just few weeks, Google+ is still far away from its direct competitor, Facebook, which makes it less of a target for cyber-crooks.
Cyber-war also grabbed headlines in 2011. The number of cyber-attacks multiplied all over the world, affecting governments and government contractors -like weapons manufacturers- alike.  Besides offering an overview of the most significant events in the computer security field, the 2011 Annual Security Report also forecasts future trends for 2012.
The full report is available at: http://press.pandasecurity.com/press-room/reports/. Visit the PandaLabs blog for more information about these and other threats:  http://pandalabs.pandasecurity.com/