Showing posts with label business. Show all posts
Showing posts with label business. Show all posts

Friday, 1 April 2011

Hackers target business secrets

Filing cabinet, Eyewire Many net-savvy thieves are scouring corporate networks for saleable secrets


Intellectual property and business secrets are fast becoming a target for cyber thieves, a study suggests.

Compiled by security firm McAfee, the research found that some hackers are starting to specialise in data stolen from corporate networks.

McAfee said deals were being done for trade secrets, marketing plans, R&D reports and source code.
It urged companies to know who looks after their data as it moves into the cloud or third-party hosting centres.

"Cyber criminals are targeting this information based on what their clients are asking for," said Raj Samani, chief technology officer in Europe for McAfee.

He said some business data had always been scooped up when net thieves compromised PCs using viruses and trojans in a search for logins or credit card details.

The difference now was that there exists a ready market for the data they are finding. In some cases, said Mr Samani, thieves were running campaigns to get at particular companies or certain types of information.

The McAfee report mentioned cases in Germany, Brazil and Italy in which trade secrets were either stolen by an insider or cyber thieves tried to get hold of via a concerted attack.

In some cases, said the McAfee report, companies made the job of the criminals easier because they did little to censor useful information about a corporate's culture or structure revealed in e-mails and other messages.

Such information could prove key for thieves mounting a "social engineering" in which they pose as employees to penetrate networks.

The report detailed efforts by firms to watch casual and contract employees and the use of behavioural analysis software to spot anomalous activity on a corporate network.


Perimeter defences

Thefts of intellectual property or key documents could be hard to detect, said Mr Samani.

"You may not even know it's stolen because they just take a copy of it," he said.

Defending against these threats was getting harder, he said, because key workers with access to the most valuable information were out and about using mobile devices far from the defences surrounding a corporate HQ.

"Smartphones and laptops have crossed the perimeter," said Mr Samani.

The report comes in the wake of a series of incidents which reveal how cyber criminals are branching out from their traditional territory of spam and viruses.

2010 saw the arrival of the Stuxnet virus which targeted industrial plant equipment and 2011 has been marked by targeted attacks on petrochemical firms, the London Stock Exchange, the European Commission and many others.

Mr Samani said that, as firms start to use cloud-based services to make data easier to get at, they had to work hard to ensure they know who can see that key corporate information.

Otherwise, he warned, in the event of a breach, companies could find themselves losing the trust of customers or attracting the attention of regulators.

"You can transfer the work but you cannot transfer the liability," said Mr Samani.

[BBC]

Monday, 21 March 2011

Five security secrets your IT administrators don't want you to know

As valued members of your organization, IT administrators work every day to keep your infrastructure up and available. But in today’s rush to contain operational costs, your IT administrators could be taking more shortcuts than you’d expect. And perhaps no aspect of IT suffers more from cutting corners than does security. Here are five facts about IT security that your administrators probably don't want you to know.

Most passwords never change

Certainly, regulations may call for frequent password changes on all accounts in your infrastructure. But though your IT administrators may be tasked to change passwords on a regular basis, your organization probably lacks the automation to reliably change what could be thousands of the passwords that matter most.

Sensitive accounts like administrator logins, embedded application-to-application passwords, and privileged service accounts often keep the same passwords for years because IT staff may not have the tools to track and change them. And, because systems and applications often crash when IT personnel attempt to change interdependent credentials, many of your organization’s most privileged logins can go unchanged for extended periods of time.

Ad-hoc change processes and handwritten scripts might succeed in updating the passwords of some types of privileged accounts, but unless your organization has invested in privileged identity management software you can be sure that many of the passwords that grant access to your organization’s most sensitive information are never changed. This means that access to this data – whether by IT staff, programmers, subcontractors and others who ever had access – will continue to spread over time.

Too many individuals have too much access

Regardless of your written policies, highly-privileged account passwords are almost certainly known to large numbers of IT staff. And chances are, for the sake of convenience these logins have been shared with individuals outside of IT.

As a result contractors, service providers, application programmers, and even end-users are likely to have the ability to gain privileged access using credentials that may never change. Unless you’ve got technology in place to track privileged logins, delegate access, and change these powerful credentials after each time they’re used you’ll never know who now has access.

Your CEO's data isn't private

With all the recent headlines about corporate and government data leaks, you might still be surprised to know how many individuals have access to the files on your executive’s computers, and to the data resident in the applications that senior managers use every day. Anyone with knowledge of the right credentials can gain anonymous access to read, copy and alter data – including the communications and application data belonging to your executive staff. In many cases these credentials are known not only to senior IT managers, but also to IT rank and file, application programming teams, contractors and others. More than likely your low paid help desk workers have access to more sensitive data than your CFO. And those subcontractors in India? It’s likely that they can access the CEO's account, too.

IT auditors can be misled

If your administrators know about security gaps or failed policies that your IT auditors haven’t discovered they will most likely try to take the knowledge to their graves. IT staff have limited time to complete higher-visibility projects that influence performance ratings and paychecks, so in most cases you can forget about them fixing any security holes that your auditors fail to notice.

Security often takes a back seat

Is your IT administrators’ pay structure tied to security? No? Then they’re probably not as proactive as you might expect when it comes to securing your network. Most IT administrators won’t tell you about the security vulnerabilities they discover in the course of their jobs because they’re not paid to fight losing battles to gain resources necessary to close each discovered security gap.

Because pay packages are rarely tied to safeguarding your network, your IT administrator is also probably not taking the initiative to update her technical skills when it comes to security. As a result, even when budgets allow for purchases of new security technologies, your staff may have no clue how to actually use these new tools effectively.

Fundamentally, the security of each organization hinges on how well IT balances convenience with controls and accountability. All too often IT is given free reign to operate under its own rules when it comes to security and resists working under the same types of controls that apply to others in the organization.

Those organizations that work to bring IT into balance – introducing accountability through segregation of duties and adequate auditing controls while providing sufficient resources and incentives to provide proactive security – often come out ahead.

[Net-Security]

Wednesday, 9 March 2011

Security on a Shoestring Budget


For many, security is like going to the dentist--you have to deal with it, but that doesn't mean you have to go willingly, or like it once you get there. One of the main problems with IT security, though, comes down to money. While new servers or PCs can be justified as an investment, security is seen simply as an expense and a headache. But, what if you could protect your network and your PCs without breaking the bank?

Well, General Motors and JP Morgan Chase Bank may not be able to do it on the cheap, for obvious reasons, but small and medium businesses--as well as individuals--have a variety of open-source tools and free software available to keep PCs and networks safe on a shoestring budget.

Protect the Perimeter

A firewall is a de facto requirement for any network security implementation. The firewall is the gatekeeper of the network--blocking unauthorized traffic from entering your internal network, and restricting the flow of traffic in and out of your network based on the rules you establish. Think of it as locking down the "perimeter" of your home or office network.

Brush the dust off of that old Pentium desktop you shoved in the closet and put it good use--it can house your firewall software. SmoothWall Express is a Linux-based open-source firewall delivering advanced features and perimeter protection capable of running on any Pentium-class PC with at least 128MB of RAM.

Smoothwall Express was designed to be simple enough to be installed by an average home user with no Linux experience, to run efficiently on seemingly obsolete hardware by today's PC standards, and to provide intuitive management and configuration through a browser-based console.

Smoothwall Express supports local networks, wireless networks, and what IT pros call DMZs (demilitarized zones). It performs all of the basic firewall functionality one would expect--port forwarding, outbound filtering, blocking bad IP addresses--and also delivers quality-of-service (QoS) features and network traffic statistics that can be broken down per network interface or per IP address.

Watch the Network

Filtering the traffic that is allowed into or out of the network at the perimeter is one thing, but you should also be monitoring the traffic flowing through the internal network for signs of suspicious or malicious activity. An intrusion detection or intrusion prevention system (IDS/IPS) will do the trick, and--when it comes to IDS--Snort basically wrote the book.

Snort combines monitoring based on signatures of known threats (think virus definitions in antivirus software) with monitoring based on detecting suspicious network activity to identify potential threats. With millions of downloads and 300,000 registered users worldwide, Snort is the most widely deployed intrusion detection system in the world, and the established standard for IDS. Snort is available for both Linux and Windows.

Snort is a shining example of the benefits of a robust open-source community. As new malware threats and attack techniques are discovered, rules have to be created and implemented in Snort to allow the IDS to detect and identify them. But because of the size and the contributions of the vast Snort user community, the rules are almost constantly updated and there is no shortage of support available.
While Snort can be run on just about any PC, the Smoothwall Express firewall also includes the ability to provide IDS functionality with integrated support for Snort rules. If you do set up a Smoothwall Express firewall, you can just use Snort rules for intrusion detection without having to install Snort separately.

Guard the PCs

Even with the perimeter locked down, and the internal network being actively monitored, some threats may still slip through to PCs on the network. A firewall and an IDS are not a replacement for having antimalware protection installed locally on each PC.

A variety of free antimalware applications are available, but the terms of engagement are generally limited to consumer use. Businesses are expected to pay up in most cases. Microsoft took the initiative, though, of making its Microsoft Security Essentials software free for small businesses running up to ten PCs.

Microsoft subsequently began automatically pushing Security Essentials to unprotected PCs through its Microsoft Update Service. So, even businesses with more than ten PCs may find their Windows computers proactively protected by Microsoft.

Bolster Your Passwords

Do you have a password policy at your office? If not, you should. But I'll let you in on a little secret about password policies--just because they appear to offer security on paper doesn't mean that users can't find a way to effectively circumvent their intent. Users can sometimes follow the letter--but not the spirit--of the password policy and create passwords that leave your network open to trivial compromise.
If you want to verify the strength of your password policy, or ensure that your users are not weakening your network security with simple passwords, just try cracking them yourself.

Tools like John the Ripper or Cain and Abel will use dictionary, brute force, and hybrid techniques to try to crack your passwords. A dictionary attack just tries every possible password from a dictionary database, while brute force tries literally every possible character combination. The hybrid approach combines the two to crack passwords like "p@ssw0rd"--those that are based on a dictionary word but substitute some letters with alternative characters.

Depending on the results, you can either modify the entire password policy to make it more secure in general, or simply identify those accounts with weak passwords and work with individual users to implement stronger ones.

These tools aren't just useful in a small business environment--try them out on your PC at home, and see how well your personal passwords hold up.

Manage Risk

To plug the holes and strengthen your network and PC defenses, you first have to know where the weak points are. A vulnerability scanner can be an effective tool for identifying where and how you are vulnerable so you can manage the risk and either patch the holes or implement additional protection to mitigate the risk.

Nessus has been the gold standard for vulnerability scanners. At one point it was available for free as an open-source tool, but it is now a commercial product available through Tenable Network Security. The Nessus software can be downloaded for free, but in order to use it businesses must also subscribe to the Nessus feed, which supplies the tests and audits that Nessus needs to probe your network. The Professional Feed subscription costs $1200 per year.

While not as robust, the Nessus 2 engine is still open-source and forms the backbone of free tools such as OpenVAS. It may not be as robust or well known as Nessus, but IT admins who can't stomach the $1200 subscription should at least take a look at what it can do.

Home users can check out Microsoft Baseline Security Analyzer. This free tool from Microsoft scans your Windows PCs to detect common security misconfigurations and missing security updates on your computer systems.

Protecting your network and PCs with free and open-source tools can be every bit as effective as expensive security software and services. The tools highlighted here are a mere drop in the bucket. Check out the list of Top 100 Network Security Tools for a more comprehensive list of software to choose from.

Open-source tools are often not as polished as commercial software--or filled with the familiar bells and whistles that bloat packaged applications in an effort to justify their cost--but they work, and it's hard to argue with free.

[ComputerWorld]

Sunday, 6 March 2011

Cyber Crime Costs Over $1 Trillion Globally?

A recent post on LinkedIn's Information Security Community piqued my attention yesterday with the following teaser for a Webinar:
As you may have read recently, Cybercrime is now costing the UK $43.5 billion and around $1 trillion globally.
The UK government report UK Cyber crime costs UKP 27BN/year published on the BBC’s website offers a top-level breakdown of the costs of cybercrime to Britain and is one of the most dubious reports I have seen recently in a long list of security-vendor and political hype around the cyber crime story.

Regardless of how badly UK businesses are hit by cybercrime, there are several extremely weak points in the work done by Detica for the UK government.

a) First  - they don’t have any empirical data on actual cybercrime events.
Given the number of variables and lack of ‘official’ data, our methodology uses a scenario- based approach.
Which is a nice way of saying
The UK government gave us some money to do a study so we put together a fancy model, put our fingers in the air and picked a number.
b) Second – reading through the report, there is a great deal of information relating to fraud of all kinds, including Stuxnet which has nothing to do with the UK cyber crime space.

Stuxnet does not seem to have put much of a dent in the Iranian nuclear weapons program although, it has given the American President even more time to hem and haw about Iranian nuclear threats.

What this tells me is that Stuxnet  has become a wakeup call for politicians to the malware threat that has existed for several years. This may be a good thing.

c) Third – the UK study did not interview a single CEO in any of the sectors they covered. This is shoddy research work, no matter how well packaged. I do not know a single CEO and CFO that cannot quantify their potential damage due to cyber crime – given a practical threat model and coached by an expert not a marketing person.

So – who pays the cost of cyber crime?

The consumer (just ask your friends, you’ll get plenty of empirical data).

Retail companies that have a credit card breach incur costs of management attention, legal and PR which can always to leveraged into marketing activities. This is rarely reported in the balance sheet as extraordinary expenses so one may assume that it is part of the cost of doing business.

Tech companies that have an IP breach is a different story and I’ve spoken about that at length on the blog. I believe that small to mid size companies are the hardest hit contrary to the claims made in the UK government study.

I would not venture a guess on total global cost of cyber crime without empirical data.

What gives me confidence that the 1 Trillion number is questionable is that it just happens to be the same number that President Obama and other leaders have used for the cost of IP theft – one could easily blame an Obama staffer for not doing her homework….

If one takes a parallel look at the world of software piracy and product counterfeiting, one sees a similar phenomenon where political and commercial organizations like the OECD and Microsoft have marketing agendas and axes to grind leading to number inflation.

I have written on the problems associated with guessing and rounding up in the area of counterfeiting here  and software piracy.

Getting back to cyber crime, using counterfeiting as a paradigm, one sees clearly that the consumer bears the brunt of the damage – whether it’s having her identity stolen and having to spend the next 6 months rebuilding her life or whether you crash on a mountain bike with fake parts and get killed.

If consumers bear the brunt of the damage, what is the best way to improve consumer data security and safety?

Certainly – not by hyping the numbers of the damage of cyber crime to big business and government. That doesn’t help the consumer.

Then – considering that rapid rollout of new and even sexier consumer devices like the iPad 2, probably not by security awareness campaigns. When one buys an iPhone or iPad, one assumes that the security is built in.

My most practical and cheapest countermeasure to cyber crime (and I will distinctly separate civilian crime from terror ) would be education starting in first grade. Just like they told you how to cross the street, we should be educating our children on open, critical thinking and not talking to strangers anywhere, not on the street and not on FB.

Regarding cyber terror – I have written at length how the Obama administration is clueless on cyber terror.

One would hope that in defense of liberty – the Americans and their allies will soon implement more offensive and more creative measures against Islamic and Iranian sponsored cyber terror than stock answers like installing host based intrusion detection on DoD PCs

[InfoSecIsland]

Man sentenced for breaching former employer's computers

A Texas man has been ordered to pay restitution of $16,600 and a $5,000 fine after admitting he breached the server of an engineering firm that fired him and deleted sensitive files.

Ismael Alvarez of Andrews, Texas, was also sentenced to five years of probation and one year of home confinement.

In December, federal prosecutors accused Alvarez of accessing a protected computer owned by Gray Wireline Service and deleting about 68 files, many of which contained proprietary reports related to oil and natural gas wells. During the breach, which happened a few weeks after Alvarez was fired, he created a directory titled “RENEGAGE RULES.” Renegade is the name of a Gray Wireline competitor.

FBI agents tracked down Alvarez through the IP address used to access the Gray Wireline server. It corresponded to the account his used with his ISP.

Alvarez, who had worked for the company for more than seven years, joins a long list of disgruntled employees who sought revenge by breaching their employees' computer systems. ®

[The Register]

Saturday, 5 March 2011

Five Myths About Fraud

We’ve all heard so much in the news about fraud over the last several years. Not a day goes by that we don’t hear about an executive caught with his hand in the cookie jar, a company that failed to follow proper accounting rules, or a compensation structure that led someone to cheat with the numbers.

In some ways, I think people are becoming immune to fraud. The cases don’t seem as significant as they would have been five years ago. They’re not as shocking as they used to be. It is sad that fraud is becoming more commonplace. And the more we hear about fraud, the more I think companies run the risk of not taking it seriously.

Most importantly, I think people are running around with some big misconceptions about employee fraud. If they mistakenly believe their company is not at risk, they are probably not actively preventing fraud. Companies must know the truth about fraud and its perpetrators in order to actively protect themselves.

The following are five of the fraud myths that I regularly run into in my fraud investigation practice. Whether owners and executives actually utter these out loud or not, merely buying into these myths mentally can be a recipe for disaster.

1. Our company does not have an internal fraud problem.


While companies would like to believe they have good employees and adequate controls to prevent fraud, the fact of the matter is that 45 percent of companies will be significantly affected by fraud, according to one international study. A separate study estimates that the average internal fraud will cost $159,000, and that almost one-fourth of fraud cases will cost companies over $1 million each.

Companies cannot afford to ignore the risk of fraud and the likelihood that fraud is occurring internally. It is too expensive, particularly when one considers the fact that there are many indirect costs of fraud, including investigation and legal costs, employee attrition, and decreased employee morale.

Actively fighting fraud means implementing policies and procedures that prevent and detect fraud. Anti-fraud professionals who are experienced with the common methods of fraud can be invaluable to this process. Whether a company gets there with employees or outside consultants, it is important to secure company information and assets to prevent internal fraud.

2. Most people are honest and won’t commit fraud.


This is a dangerous approach to take to the business of fraud. It is true that most people are generally honest. But to rely on this instead of putting controls in place to prevent fraud is a big mistake.

While it’s wise to hire those with a track record of honesty, past behavior doesn’t necessarily predict future behavior. Almost 88 percent of employees and executives who commit fraud against their employer have never before been charged or convicted of a fraud-related offense. This means it’s nearly impossible for companies to predict who is going to commit fraud and when they are going to do it.

It is a fact that honest people can and do commit fraud. Outside pressures can cause people to behave in ways they normally would not. Things that could push someone toward fraud include addictions, divorce, overwhelming debt, and gambling problems. When pressures like this are present, it’s difficult to predict who will commit fraud.

In the end, those who commit fraud come from all walks and ways of life. From clerks to executives, no one is immune. Thieves come from all social classes and all economic backgrounds. If given a strong motivation and ample opportunity, anyone can commit fraud against her or his employer.

3. If our company follows government regulations, we will be protected against fraud.


Unfortunately, the current accounting rules and regulations do not really provide protection against fraud. Sarbanes-Oxley is probably the most widely-recognized regulation dealing with fraud. It has had some positive effects because it has forced companies to review and document their policies and procedures.

Companies have spent enormous amounts of money on implementing Sarbanes-Oxley, and it’s probably discouraging to admit that even such an extensive project isn’t really preventing fraud. The regulation forces management and the board of directors to accept responsibility for issuing accurate financial statements, however, it doesn’t really ensure that companies have fraud prevention procedures in place.

In order to effectively prevent fraud, companies must create and implement policies and procedures specifically designed to deter and detect fraud. Again, this should be accomplished with the help of an anti-fraud professional who is experienced in the methods used by corporate fraudsters. A good fraud prevention program will actively prevent and detect fraud while still complying with the applicable regulations.

4. Small frauds aren’t important enough for management to worry about.


Virtually every big fraud started out as a small fraud at one point. Whether it is a minor theft of cash or a financial statement manipulation intended to cover up a substandard quarter, what starts out as a small fraud can quickly grow into a major fraud scheme. A theft of $500 may not seem significant enough for management to devote time and effort to the problem. But what if an employee was stealing $500 a week for three years? Suddenly, there is a theft of over $75,000, which could be very material to the company.

It’s important for companies to take small frauds and ethical lapses seriously. Not only does management want to cut off frauds while they are in their early stages, they also should be sending a message to employees that dishonesty is not tolerated. A zero tolerance policy is a necessary part of any good fraud prevention program.

It may be expensive to monitor and investigate smaller thefts from the company. However, in the long run, the cost will be worthwhile because the company will have stopped frauds from growing into the hundreds of thousands and millions of dollars. Therefore, an effective fraud prevention program will contain components that help the company discover fraud early.

5. Fraud will be detected by our auditors.


History has shown us that a company’s independent auditors cannot be relied upon to find fraud. This is true primarily because audits are not designed to detect fraud. They are designed to give “reasonable assurance” that the numbers shown on the financial statements are materially accurate.

Because fraud involves the active concealment of the truth, it makes it difficult for auditors to discover. Further, auditors have a tendency to become complacent with their clients. They see the same things year after year in the audit, and they may stop paying close attention. Employees who are concealing a fraud may also be comfortable with the auditors and know what procedures are coming. If that’s the case, count on the employees to be very careful with the fraud as it relates to those expected procedures.

Auditing rules have attempted to address how auditors approach the potential for fraud within companies. While the current rules are somewhat better than those of several years ago, a traditional independent audit still cannot be relied upon to detect fraud. Executives who believe differently are setting their companies up for disaster.

The Solution


Preventing fraud in companies all comes back to active prevention techniques and educating employees about fraud. First, owners and executives must be aware that they are very much at risk of experiencing internal fraud, and that the statistics show that the losses can be expensive. Then they need to take decisive action in formulating a fraud prevention program.

Education of everyone is still a very important part of fraud prevention. No company is immune to the problem, and no employee is completely free from the possibility of committing a fraud one day. After owners and executives appreciate the true magnitude of the problem, it will be through action that fraud will be prevented at their companies.

Tracy L. Coenen, CPA, CFF is a forensic accountant and fraud investigator with Sequence Inc. in Milwaukee and Chicago. She has conducted hundreds of high-stakes investigations involving financial statement fraud, securities fraud, investment fraud, bankruptcy and receivership, and criminal defense. Tracy is the author of Expert Fraud Investigation: A Step-by-Step Guide and Essentials of Corporate Fraud, and has been qualified as an expert witness in both state and federal courts. She can be reached at tracy@sequenceinc.com or 312.498.3661. 


[InfoSecIsland]

Wednesday, 2 March 2011

Workers expose businesses to malware and data loss


Organizations are at risk of malware as 76% of workers plug unknown USB flash drives into company PCs, potentially compromising corporate network security, according to BlockMaster.

“This is alarming as many viruses on USB sticks can run as soon as they are plugged into a PC, without user activation and causing widespread damage to a corporate network,” says Anders Kjellander, CSO, BlockMaster.

Even if unprotected USB sticks are not infected with viruses or worms, they can contain sensitive corporate data, leaking important information to external organizations causing harm for the party that lost the device.

The research of over 1,000 UK office workers initiated by BlockMaster to reveal attitudes to handling portable devices, such as USBs, also revealed that 20% have lost unprotected USB drives holding sensitive information, exposing businesses to huge potential risks, such as loss of IP and reputational damage.

Around 83% of office workers use USB sticks today, making them almost as common as the mobile phone. However, although we often have work email on our mobile phones, it’s quite rare to store a significant quantity of sensitive business data on them.

Unsecure USB drives pose a unique security threat, as they are usually small, easy to lose and have a high capacity for storing documents, videos or corporate presentations.

The survey also discovered that approximately 85% of lost USB sticks are later found, so office workers hoping that lost sensitive data will simply ‘vanish’ will frequently be disappointed.

Organizations need to put technology and policies in place to secure and remotely manage their USB devices.

A lost unsecure and unmanaged USB stick can contain sensitive data including customer details – or in the case of public sector organizations, details of patient records, benefits or tax details – so it is imperative that organizations put in place a managed secure USB drive solution that automatically protects stored data and allows administrators to centrally manage them to perform policy updates and remotely erase any lost device.