Showing posts with label Threat. Show all posts
Showing posts with label Threat. Show all posts

UAVs Hacking Wireless Networks - Latest Threat, Military Strategy, or Surveillance Tool?


At the famous hacker convention in Las Vegas, some of the computer security industry professionals there have created a UAV which can fly around and break into computer systems via their wireless connections. Is this a new scheme? Is this an innovative idea? I would submit to you that it's not a new original thought, as I had written an article about this a year or so ago on such a concept, and there are old tales of UFOs flying over missile silos containing ICBMs during the Cold War, and shutting down the entire system.

Yes I know, talking about UFOs, or unidentified flying objects, seems a little bizarre. But, whether or not those stories are true, hardly matters, because the stories go back to the 1970s and really this new hacking technique, which will probably be used by the US military is not a new thought, we can trace its origins back over four decades. Nevertheless, it is interesting new technology, and perhaps we should discuss this.

There was an interesting article in Physorg [dot] com recently on August 6, 2011 titled; "Hacker drone launches airborne cyber attacks," written by Glenn Chapman which stated;

"Computer security specialists built a small MAV drone aircraft that can launch airborne cyber attacks, hijacking mobile phone calls, or even delivering a dirty bomb. It is loaded with software to attack Wi-Fi, Bluetooth, and GSM cell networks. The MAV grabs packets of data sent on wireless networks or unsecured hot spots as gateways to get in to computer systems. It can get GMS mobile phone IDs used to bill outgoing calls. Hackers can impersonate cell phone towers and eavesdrop on people's calls."

Perhaps, this is a good reason for people to secure their Wi-Fi at home, or in their businesses, and not leave open networks, because hackers can break in. It's also a good reason for government computer systems, and large corporations to think twice about having any sort of wireless communication too accessible, or allowing too much information to flow through them, which is of high value, proprietary, secret, or involving financial transactions.

We've always known that someone can park a Van near a Wi-Fi connection, and attempt to break into the computer system. In Silicon Valley there were computer professionals which did this quite often to test the security of various corporations. Flying a small model airplane or micro air vehicle, or even a military UAV over a location to get into the system might indeed help the cyber warfare division of the US military. We can also expect that our enemies will try to do this to us too, and unfortunately we can also expect criminal hackers to try to break into our personal information in this way.

Indeed, just when you thought it was safe to use your mobile phone, Wi-Fi, or wireless network - someone has invented a new way to get in. Be careful out there folks, indeed I hope you will please consider all this and think on it when you are devising a strategy for Internet security and safe mobile phone transactions.




Lance Winslow is a retired Founder of a Nationwide Franchise Chain, and now runs the Online Think Tank. Lance Winslow believes writing 24,444 articles by September 4th at 4:44 PM will be difficult because all the letters on his keyboard are now worn off now..




Cyber Crime - A Threat to Every Internet User


According to the Federal trade Commission (FTC), there are around 10 million reported cases of identity theft each year in the United States. A recent report by Eugene Kaspersky, founder and head analyst of Kaspersky Labs (a leading internet security company), indicates that the level of criminal activity on the internet has doubled in the past year, and there is reason to believe this trend will continue to grow exponentially in the future.

Cyber crime has become a serious problem for everyone who uses the internet. The biggest threats to all internet users are malicious software programs known as crimeware and social engineering schemes, often referred to as phishing and pharming scams.

Although computer viruses have always presented a big problem regarding potential loss of data or damage to our computers, spyware and phishing scams are where the real danger is. These forms of internet crime don't hurt our computers - they cause personal damage.

Spyware

The most common form of crime-ware comes in the form of spyware, which is a small program or piece of code that is designed to "spy" on your online activity and/or personal information. There are many types and forms of spyware and new versions are introduced into the internet every day.

Although not all spyware is used for illegal purposes, much of it can be very dangerous due of its ability to record keystrokes, take snapshots of our PC screen, and monitor everything we do online. Spyware usually installs without anyone's knowledge and runs silently in the background.

The information gathered by spyware is secretly transmitted to the person who planted it. It is sometimes sent out via email without our knowledge, but more often it is relayed to a hijacked "slave" computer, where it is picked up by the criminal who installed it. He/she will either use it to access bank accounts or credit cards, sell it to another thief, or perhaps steal our identity altogether.

Some spyware is used to "hijack" computers, turning them into "slaves" that are used to collect and store data that was obtained illegally. The computer's owner rarely knows that his PC is being used to house illegal information. Many "slave" computers are also used to help social engineers collect data via Pharming scams.

Phishing Scams

One of the most popular criminal activities on the internet is Phishing. In fact, this type of scam is so prevalent that an estimated 99% of email users have seen at least one phishing scam in their inbox. Phishing is mostly done via email, and is usually performed in conjunction with Pharming. Social engineers often send email letters that appear to come from your bank or other financial institution. The message urges you to click the link, log in, and verify your credentials. These emails sound and look very legitimate, and this is why so many people follow through by clicking the link.

Pharming

Once a person has clicked a link in a fraudulent Phishing email, they are taken to a website that appears to be legitimate. This is because the social engineer has copied the home page of the financial institution. What most victims don't realize is that the website they are on is really in some third world country, or on a "slave" computer that has been hijacked by spyware. The Pharming occurs when the person enters his/her credentials to "log on" to their account. This provides the Pharmer with all the information he needs to quickly wipe out the account or charge up a fortune on the associated credit card.

How to Protect Yourself Online

There are several things you can do to protect yourself from cyber-crime. The most obvious is to use good internet security products. At minimum, everyone who uses the internet should be using a good personal firewall, anti-spyware software, and anti-virus software.

The easiest, most effective way for most home computer users to stay protected is to purchase an internet security suite. A suite will include antivirus, anti-spyware/anti-adware, software firewall, and possibly some extras like a spam filter and password protection software. Suites are easy to use because everything is controlled via one interface.

There are many "free" things you can and should do to protect yourself from cyber-crime, such as keeping your computer's operating system and all applications up-to-date. This combined with the implementation of cautious browsing and email habits will have a big impact on your safety.




Internet Security Suites [http://www.antivirus-firewall-spyware.com/computer-security-suites.html]

How to Protect Yourself Online [http://www.antivirus-firewall-spyware.com/Free-Report.html]

Computer Security for Everyone




New Insider Threat Blog Entry

Hi, this is George Silowash and recently, I had the opportunity to review our insider threat database looking for a different type of insider threat to the enterprise�paper. Yes, paper. In particular, printouts and devices that allow for extraction of digital information to paper or the management of paper documents. This area is often overlooked in enterprise risk assessments and I thought I would share some information regarding this type of attack.

Our database of over 500 cases contains the following types of cases in which a scanner, copier, printer, or FAX machine were used as part of the insider�s attack:

Device Used
Number of Incidents

It should be noted that our database contains one instance in which a copier, FAX, and printer were all used in the same attack. More on that later.

Technology in the workplace enables employees to efficiently do their jobs and accomplish the mission of the organization. It is often these technologies that also enable malicious insiders to cause harm to the organization. Management, Information Security, and Information Technology support teams must work to secure both the physical and virtual environments. This typically entails implementing physical protections for servers, workstations, and mobile devices while Access Control Lists (ACLs) restrict access to data. Often times other devices are overlooked and left with little to no protection.

These devices should be included in organizational risk assessments:

printersscannersFAX machinescopiers

Printers can allow a malicious insider to extract sensitive company documents and remove the documents from the organization to share with competitors or even start their own business.

In one case, the insider was a disgruntled scientist at a technology component manufacturer. The insider exfiltrated research documents using his access privileges. He downloaded the documents onto his laptop, sent them to his email account, and physically carried the document printouts out of the workplace. He also mailed some of the research documents to the component manufacturer's competitors. The total losses were estimated to be about $3 million. The insider was sentenced to five years probation, fined over $7000, and ordered to perform 200 hours of community service.In another case, the insider worked with a conspirator to sell physical blueprints and trade secrets to a competitor organization. Although potential losses were estimated to be between $50 million and $100 million, the victim organization was able to prevent the information from being used by the competitor. The insider was sentenced to prison and fined $20,000.

Organizations should carefully monitor printer activity and retain logs of printed documents. These logs should be audited as part of an organization�s continuous log monitoring program. Personnel should be alerted when anomalies occur, such as printing before or after business hours or printing an unusually high number of documents for that particular user.

Companies must also ensure that hardcopy documents are properly disposed of when they are no longer needed. Documents containing proprietary information must be destroyed by those who are authorized to do so. Organizations should consider who has access to hardcopy documents during the document�s lifecycle. The CERT database has cases where janitors took documents containing personally identifiable information (PII) or other sensitive information from the organization. If the documents had been properly managed and disposed of, the risk of malicious insider activity may have decreased.

Scanners also pose a threat to organizations. Documents that are not in digital form or are not accessible in electronic form due to access restrictions can be scanned by a user who has authorized access to a scanner.

In one case, an insider was contracted by a telecommunications company to scan physical trade secret documents into digital form. After scanning the documents, the insider stole some of the electronic files and posted them on a hacking website. The total potential damages were estimated to be $25 million while the insider was ordered to repay over $145,000 in restitution.An insider was employed by a document imaging company. The imaging company was a trusted business partner of a university. The insider stole 1,700 student transcripts containing the students' PII while digitally archiving them for the university. The insider was never identified, and the monetary impact of the incident was never fully understood.

Companies need to provide commensurate levels of protection to printed documents as they do for digital files. People receiving printouts must have a valid need to know and permission to have access to these hard copies. In the above cases, trusted business partners had access to physical documents to perform a contractual obligation. Contracts with trusted business partners need to stipulate the need for thorough background investigations. In addition, if company sensitive documents are being scanned, a company representative should monitor the process to ensure that the contractor is not mishandling company information.

FAX machines are an older technology that continues to exist in many organizations. These devices can be used by an insider to send documents out of the organization, often without being detected. .

Insiders were employed by a financial institution and used the institution's computer systems to access PII of 68 customers, including the customers' credit card numbers. They then faxed this information outside of their organization to their accomplices. In total, almost $600,000 was stolen through the fraudulent activity. The insider was sentenced to over one year imprisonment, two years of supervised release, participate in a drug/alcohol program and repay over $99,500 in restitution.In another case the insider was a disgruntled engineer for a product manufacturing company. Fearing his job was in jeopardy, he sent technical drawings to a competitor organization via fax and email. The damage to the victim organization was estimated to be roughly $1.5 million. The insider was sentenced to over two years in prison and ordered to repay $1.3 million in restitution.

In the above examples, the insiders were able to FAX documents to accomplices or competitors. One solution to reduce this threat is to limit access to FAX machines whereby employees in the organization must submit their documents to another individual to review and transmit.

Copiers allow insiders to duplicate company documents without the worry of having to remove original documents from the organization, which could lead to faster detection.

The insider was employed as a mail room supervisor by the victim organization, which was a financial institution. While on site and during work hours, the insider opened the organization�s mail and copied checks that customers had sent in for deposits. The insider sold the copies to an identity theft group, which used the valid account numbers to make fraudulent checks. The insider was arrested, but information regarding the monetary impact was unknown.


Access to copiers needs to be limited when company sensitive information is at stake. In the above example, the insider was able to copy customer checks for identity theft purposes. The insider�s activities should have raised red flags when opened mail was delivered.

Finally, the malicious insider who used all of the methods that we have been discussing, worked as an administrative assistant to a top executive at the victim organization. As part of her job responsibilities, she had access to confidential trade secrets and other proprietary information. She was caught making copies of confidential documents and leaving with them from her workplace and attempting to sell them for money. She handed over some of the copies to buyers, as well as faxed some. The insider also printed out some of the executive's emails which contained confidential project information. The only monetary impact reported was $40,000 restitution ordered to be paid by the insider.

These cases highlight the need for organizations to be more vigilant about all technologies used in the organization. Scanners, copiers, printers, and FAX machines all have a place in an organization. However, incorporating them into enterprise risk assessments as well as polices that govern their use will help to identify and mitigate risks associated with their use.

Our team would like to hear what you are doing to counter this threat. If you have any questions or comments please email us using the feedback link.


View the original article here

 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Information Computer and Technology - All Rights Reserved
Template Modify by Creating Website
Proudly powered by Blogger