Home Blog Page 130

SolarWinds Hackers Accessed Source Code: Microsoft

SolarWinds Microsoft

Microsoft has issued an update about its ongoing internal investigation of the SolarWinds hack that had reportedly compromised a few of its internal systems. The tech giant has now confirmed that it traced a compromised account used to “view source code” of its internal code structure.

Earlier in December 2020, the entire world shook to the tremors of the SolarWinds supply chain attack. The White House issued a press release stating multiple that government agencies and departments, including the U.S. Department of Treasury, a section of the U.S. Department of Commerce, and the National Nuclear Security Administration (NNSA), among others, were compromised during the widespread attack.

Mayday for Tech Giants

This hack was not just limited to the government institutions, but tech giants like Microsoft, Boeing, FireEye, etc., were also affected. In mid-December 2020, Microsoft, in an official notification, accepted that they “were hacked.” As a precautionary measure, they successfully created a Killswitch in collaboration with other industry heavyweights like FireEye and GoDaddy. The killswitch was devised to stop the spread of Sunburst malware. Microsoft further informed its partners and customers that the investigation of their compromise was ongoing and that they would issue regular updates about it.

Microsoft Issues Update

Staying true to its word, Microsoft issued an update of its internal investigation on New Year’s Eve. The update noted the following observations:

  • No evidence of the attackers accessing production services or customer data of Microsoft.
  • No indications of Microsoft’s systems being used to attack others.
  • No evidence of the common TTPs (tools, techniques, and procedures) related to the abuse of forged SAML tokens found being used against Microsoft’s corporate domains.
  • Detected unusual activity with a small number of internal accounts. Upon review, it was found that one of the compromised accounts was used to view source code in several source code repositories.
  • This unauthorized access has however not put Microsoft under any security risk as the compromised account had only viewing rights and no modification rights.
  • The affected accounts have now been remediated.
  • Evidence of multiple attempts to penetrate the systems has been recorded by Microsoft. However, its usage of Privileged Access Workstations (PAW) along with a host of other industry proposed standard protection practices made it possible to thwart these attacks.

Viewing the Source Code, No Big Deal!

Generally, when attackers gain access to the source code of any structure, software, application, and so on, it makes the developers break into a sweat simply because they can then find the vulnerabilities and attack them again in the future. However, Microsoft in its update suggested otherwise.

At Microsoft, we have an inner source approach – the use of open-source software development best practices and an open source-like culture – to making source code viewable within Microsoft. This means we do not rely on the secrecy of source code for the security of products, and our threat models assume that attackers have knowledge of source code. So, viewing source code is not tied to elevation of risk.

 

As with many companies, we plan our security with an ‘assume breach’ philosophy and layer in defense-in-depth protections and controls to stop attackers sooner when they do gain access.

Ticketmaster to Pay $10 Mn as a Criminal Fine for Unlawful Intrusion

ICO fined Ticketmaster

Ticketmaster L.L.C., the U.S.-based ticket sales and distribution firm, has agreed to pay a $10 million fine to settle a class-action lawsuit with the U.S. Attorney’s Office for the Eastern District of New York for illicitly breaking into a competitor’s network systems.

Ticketmaster’s Criminal Act

The U.S. Department of Justice (DoJ) stated that Ticketmaster misused passwords held by a former employee of a competitor firm. “Ticketmaster employees repeatedly, and illegally, accessed a competitor’s computers without authorization using stolen passwords to unlawfully collect business intelligence.   Further, Ticketmaster’s employees brazenly held a division-wide ‘summit’ at which the stolen passwords were used to access the victim company’s computers, as if that were an appropriate business tactic.  Today’s resolution demonstrates that any company that obtains a competitor’s confidential information for commercial advantage, without authority or permission, should expect to be held accountable in federal court,” said Acting U.S. Attorney DuCharme.

Plan to “Choke off” the Competitor

Based on the investigation, Ticketmaster exploited the proprietary information that belonged to its competitor for its advantage, promoting two dishonest employees involved in the scheme. “When employees walk out of one company and into another, it’s illegal for them to take proprietary information with them. Ticketmaster used stolen information to gain an advantage over its competition, and then promoted the employees who broke the law. This investigation is a perfect example of why these laws exist — to protect consumers from being cheated in what should be a fair marketplace,” said FBI Assistant Director-in-Charge Sweeney.

The illegal actions and corporate violations of Ticketmaster and its employees involved in the lawsuit were condemned by Seth D. DuCharme, Acting U.S. lawyer for New York’s eastern district, and William F Sweeney Jr, assistant director of the FBI’s New York Field Office.

Security Trends: Hackers Will Up Their Game in 2021

ciso mag editoria

EDITORIAL: We welcome all our readers back to work, on the first working day of the year! And we hope that 2021 will be a much better year for you. Here are some of the Cybersecurity trends you can expect in 2021.

Health and health care are going to be important considerations for the world in 2021. With the availability of vaccines, the world will limp back to normalcy this year. With that, the rate of unemployment should drop, and the crime graph will also dip. And hopefully, cybercriminals will mend their ways.

Yet, the bad guys are now thinking of ways to leverage the current situation. The tone and content of phishing emails will now be about the availability of vaccines. Bad actors will choose to exploit the naivety of gullible folks, this time turning their attention to vaccine distribution and health insurance fraud.  And since we shop online more often, they will target e-commerce sites and logistics companies too.

So, please be prudent and mindful about emails or texts from people impersonating health authorities or from fake insurance or logistics companies. Make a few calls to verify.

Bigger Agendas

It is also worrisome to see cybercriminals moving to sophisticated agendas, as their involvement in cyber warfare and attacks on critical infrastructure, with malicious intentions of disrupting life and destabilizing economies. Attacking nuclear facilities (Iran) or turning off the national grid used to be the stuff of James Bond and Mission Impossible movies. It’s very much a reality today. And it makes those that peddle credit card numbers on the dark web look like rookies.

Thirty years ago, hackers were contented with attacking browsers or applications and disrupting enterprise networks. They pursued intellectual property and customer data – and sold that to competitors. They still do. But today, they are after something much bigger than that.

The bad guys are also going to up their game and look at new modes of attack – like deepfakes – and the use of artificial intelligence. This year you can expect more deepfake news videos that sound and look so much like the real thing. And if you get a call from your CEO or CFO, which sounds so much like them, would you fall for it? It could be a case of deepfake – yes, the bad guys can do voices too, like the late Hollywood actor Robin Williams (watch the 1993 American comedy-film, Mrs. Doubtfire). That’s taking spear-phishing and whaling to a whole new level!

Cybersecurity Trends in 2021

We’ll see more ransomware attacks this year, and industries centered on critical infrastructure will be targeted. The Ransomware Task Force is already putting a strategy and plan in place to counter ransomware. But governments need to step in and give such initiatives more momentum. Organizations are already thinking about ways to counter Ransomware, and CISO MAG will report on this in its February 2021 issue.

Likewise, expect to see new standards to counter BEC attacks, particularly at the email gateway level. CISO MAG will report on these new developments during the course of the year.

 

Our January issue, which is fresh out of the oven, has viewpoints from industry experts about the nature of cybersecurity threats this year. Don’t miss our Cover Story: 5 Cybersecurity Approaches That All Businesses Should Consider in 2021. It offers wisdom and advice for CISOs.

Subscribe Now

 

We pledge to offer you more useful cybersecurity news and information this year, with more analysis. In fact, we just kicked off our Explainer series over the weekend, and you can read our first two explainer articles elsewhere on this website. Last year, we launched our Podcast channel and webinar series. So more podcasts and video content will be coming your way this year.

Stay safe, cautious, and healthy in 2021.


We’d like to hear from you, so write to us at: [email protected]
View our 2021 Editorial Calendar here.

 

“All sectors can benefit from a simulated targeted attack”

Red Teaming

On the surface, a Red Team exercise appears like a scene straight out of a Hollywood movie. Spies masquerading as employees walking straight into the office so instinctively that no one bats an eye. Plugging things into your devices that are not supposed to be there. Tapping cameras, telephones, microphones, rolling out emails, or even walking around with a banana so you may assume the new guy/girl didn’t have time to grab a proper lunch. By the time you figure out they weren’t supposed to be where they were, it’s already too late. And the only sigh of relief is the fact that they were on your side — and they were working for you.

So, before your company humors itself with a Red Team assessment it might be of use that you talk to an expert about it. And for that, we have Tom Van de Wiele, Principal Security Consultant at F-Secure. With nearly 20 years of experience in information security, Tom specializes in red team operations and targeted penetration testing for the financial, gaming, and service industry. When not breaking into banks Tom acts as an adviser on topics such as critical infrastructure and IoT as well as incident response and cybercrime. With a team that has a 100% success rate in overcoming the combination of targeted organizations’ physical and cybersecurity defenses to end up in places they should never be, Tom is possibly one of the best red team experts in the world. In an exclusive interview with Augustin Kurian of CISO MAG, Tom discusses key questions a company should ask before it engages in a Red Team assessment.

It is often said that Red Teaming is much better than regular penetration testing? What are your thoughts about it?

Red teaming, penetration testing, source code review, vulnerability scanning, and other facets of testing play a key part in trying to establish the level of control and maturity of an organization. They all have different purposes, strengths, and limitations. A penetration test is usually limited and only focused on a certain aspect of the business e.g. a certain network, application, building, or IT asset; a red team test is based on the attacker’s choice and discretion on what to target and when. Keeping in mind the actual objectives and goals of what the client wants to have simulated that is relevant to them. That means anything with the company logo on it could be in scope for the test — keeping in mind ethics, local and international laws, and good taste.

In general, Red Team Testing is only for organizations that have already established a certain maturity and resilience when it comes to opportunistic and targeted attacks. This resilience can be expressed in many ways, hence we want to make sure that we are performing it at the right time and place for our clients, to ensure they get value out of it. The goals are three-fold: to increase the detection capabilities of the organization tailored towards relevant attack scenarios, to ensure that certain attack scenarios become impossible, and increase the response and containment time to make sure that a future attack can be dealt with swiftly and with limited impact. Ultimately, all efforts should be focused on an “assume breach” mentality while increasing the cost of attack for a would-be attacker.

Knowing that red teaming and target-based attack simulations are at the proverbial finish line for an organization, it is still beneficial to have a red team as an end-goal as part of a real simulation. It forces organizations to look at their own security from a threat-based approach, rather than a risk-based approach, where the past defines the future for the most part. For instance, just because you haven’t been hit by ransomware in the past, doesn’t mean you won’t get impacted by one in the future. “Forcing” organizations to look at their own structure and how they handle their daily operations and business continuity as part of threat modeling, sometimes brings surprising results in positive or negative form. But at the end of the day, everyone is better off knowing what the risks might be of certain aspects of the business, so that an organization can take better business decisions, for better or for worse, while they structure a plan on how to handle whatever it is that is causing concern to stakeholders.

When should a company realize that it is an apt time to hold a Red Team assessment? What kinds of industries should invest in Red Teaming? If so, how frequent should the Red Teaming assessment be? Should it be a yearly process, half-yearly, quarterly, or a continuous one? How often do you do one for your clients?

All sectors can benefit from a simulated targeted attack to test the sum of their security controls, as all business sectors have something to protect or care about, be it customer data, credibility, funds, intellectual property, disruption scenarios, industrial espionage, etc. What kind of testing and how frequently depends on the maturity of the organization, its size, and how much they regard information security as a key part of their organization, rather than a costly afterthought, which unfortunately is still the case for a lot of organizations.

Major financial institutions will usually schedule a red team engagement every 1 – 1.5 years or so.

In between those, a number of other initiatives are held on a periodical basis in order to keep track of the current attack surface, the current threat landscape as well as trying to understand where the business is going versus what technology, processes, and training are required to ensure risk can be kept at an acceptable level. As part of an organization’s own due diligence, it needs to ensure that networks and application receive different levels of scrutiny using a combination of preventive and reactive efforts e.g architecture reviews, threat modeling, vulnerability scanning, source code review, and attack path mapping, just to name a few.

Is it only the big corporate companies or companies of all sizes that should engage a Red Team assessment?

Smaller or mid-sized companies might not be able to budget elaborate red teaming exercises nor should they, as long as they know what to protect — and schedule scanning and penetration testing exercises as part of a formal vulnerability management process, which should be mandated by someone or a department specifically responsible for cybersecurity. This should be combined with a number of business impact and crisis management exercises to try and prevent as many of the relevant attack scenarios as possible while trying to detect and respond to the ones that are too expensive to mitigate or where the mitigation does not scale well. Once those things are under control and a certain maturity is established, then mid-sized and smaller companies can start thinking about protecting themselves against a coordinated targeted attack.


Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.


This interview first appeared in the March issue of CISO MAG. Get your preview here.
To read the full version, Subscribe now!

These are the Biggest Data Sets Sold on Darknet in 2020

biggest data sets sold on darknet, data leak, data auction website, cybercriminals, ransomware gang, ransomware gang auction, biggest data sets sold, biggest data sets sold on the darknet, data sold in underground market, underground market auction, data sold on the darknet

“Digital” and “Data” were the two words heard loud and clear in 2020. Digital transformation drove data collection and subsequently gave rise to the flipside of this blessing – data theft. Cybercriminals had a gala time stealing it and then selling it on the darknet. While this gave sleepless nights to security teams and their respective CISOs and CIOs, cybercriminals made a fortune out of these by selling the data for as low as $0.002 to a few thousand dollars per record.

By Mihir Bagwe, Technical Writer, CISO MAG

So, let us look back at the biggest data sets of 2020 sold on the darknet that might have missed your eyes.

Related News:

A Look Back at the Top 9 Data Breaches of 2020

1. LiveAuctioneers Database

biggest data sets sold on darknet , data leak, data auction website, cybercriminals, ransomware gang, ransomware gang auction, biggest data sets sold, biggest data sets sold on the darknet, data sold in underground market, underground market auction, data sold on the darknet,
Records Sold: 3.2 Million
Offer Price: $2,500

LiveAuctioneers is an online auction platform headquartered in the U.S. On July 11, 2020, it issued a press release stating, “An unauthorized third-party accessed certain user data through a security breach at a LiveAuctioneers data processing partner that occurred on June 19.” The security incident compromised 3.4 million user records from the database. The stolen data was being sold on the dark web for a total of $2,500.

As per LiveAuctioneers, the affected information included names, email and mailing addresses, phone numbers, and encrypted passwords. However, the cybercriminal selling this data claimed that the database included decrypted passwords and social media profiles of LiveAuctioneers’ users.

2. Dave Users Database

Records Sold: 7+ Million
Offer Price: $16,000

In July 2020, Dave, a digital banking and overdraft protection service provider, confirmed that a data breach incident compromised 7,516,625 of its user details. The leaked data included personally identifiable information (PII) like names, email IDs, birth dates, physical addresses, and phone numbers. The leaked information first surfaced when a cybercriminal put a sale advert on an underground forum called RAID. The sale of the entire database was offered for $16,000 (approximately $470 per record).

The ad was later removed, probably due to the successful sale of the leaked database. However, the same database later appeared on other forums but this time as a free download by a notorious threat actor named “ShinyHunters,” the same threat actor who was responsible for various other hackings and publishing of user records like Tokopedia, Unacademy, Wishbone, and many more.

3. Multiple MySQL Databases

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

Records Sold: 85,000+ Databases
Offer Price: $550 Per Database

Recently, in December 2020, a portal that is a part of a ransomware scheme was brought to light by a security researcher. It has reportedly been active since the beginning of 2020 and contains 85,000+ MySQL databases that are offered at a mere selling price of $550 per database.

According to ZDNet, cybercriminals have been breaking into MySQL databases, downloading tables, deleting the originals, and leaving ransom notes behind for server owners to get their data back. The initial ransom notes asked victims to contact the attackers via email; however, as the operation flourished, the attackers automated their database ransom scheme with the help of a web portal, first hosted online at sqldb.to and dbrestore.to, and then moved to an Onion address on the dark web.

4. Tokopedia Database

biggest data sets sold on darknet, data leak, data auction website, cybercriminals, ransomware gang, ransomware gang auction, biggest data sets sold, biggest data sets sold on the darknet, data sold in underground market, underground market auction, data sold on the darknet

Records Sold: 91 Million
Offer Price: $5,000

In May 2020, Indonesian e-commerce giant, Tokopedia, suffered a massive data breach after hackers leaked over 15 million of its user records.  Threat actors kept the details of 91 million users of Tokopedia up for sale on the Darknet for $5,000. According to Under the Breach, the leaked records contained names, emails, password hashes, and other personal information.

Tokopedia’s spokesperson, Nuraini Razak, confirmed the breach and claimed that the company had ensured the security of its users’ information. Razak had clarified that users’ financial details like credit/debit card numbers and e-wallet information were, however, not affected in the breach.

5. Multiple Stolen Credentials

biggest data sets sold on darknet , data leak, data auction website, cybercriminals, ransomware gang, ransomware gang auction, biggest data sets sold, biggest data sets sold on the darknet, data sold in underground market, underground market auction, data sold on the darknet,

Records Sold: 15+ Billion
Offer Price: An Average of $70 Per Financial Credential and $10 Per Social Media and Other Services Credential

As per research from cybersecurity firm Digital Shadows, more than 15 billion stolen account credentials are being sold on the darknet, including 5 billion unique data sets, meaning that they have never been offered for sale more than once. The researchers spent a year and a half analyzing the tactics of the cybercriminals and found that the amount of misappropriated credentials has risen by 300% since 2018. The researchers noted that accounts, which allow infiltrating the critical systems of an organization, are auctioned and can fetch an average price of over $3,100; the most valuable to be known was auctioned for $120,000.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

Big Game Hunting was gaining momentum in 2020: Dmitry Volkov

Dmitry

The global shift to remote work due to the COVID-19 pandemic and massive downsizing have catalyzed a spike in cybercrime. In 2020, the majority of cybercriminal groups switched to ransomware attacks, which helped them gain more with easier technical implementation. For instance, Cobalt and Silence hacker groups, which used to target banks, became participants of private ransomware affiliate programs.

By Dmitry Volkov, CTO and the Head of the Threat Intelligence & Attribution Department, Group-IB

In addition, Big Game Hunting was gaining momentum in 2020: attackers focused heavily on large networks to get a higher ransom, new cybercriminal groups joined the game, and new collaborations between representatives of various cybercrime segments emerged.

According to Group-IB Hi-Tech Crime Trends report, the total damage of ransomware operations in 2020 reached at least $1 billion, while their main targets were located in the U.S., the United Kingdom, Canada, France, and Germany. The top five industries in terms of the number of attacks were manufacturing, retail, public sector, health care, and construction.

Another trend of the outgoing year was the tremendous growth of the sale of access to the networks of compromised companies, which increased 2.6-fold. It is noteworthy that the market for the sale of access to corporate networks has correlations with ransomware attacks: most threat actors offered access to U.S. companies (27%), while manufacturing was the most frequently attacked industry in 2019 (10.5%).

Selling access to a company’s network is usually only one stage of the attack: the privileges gained might, for example, be used for both launching ransomware and stealing data, with the aim of later selling it on underground forums or spying.

The direct consequence of the pandemic will be the long-term growth of cybercrime. The pandemic has caused many people to lose their jobs and search for new sources of income.  In the next 3-5 years, we’re likely to see the rapid growth of digital crime due to the dire economic situation in various parts of the world that is likely to encourage more individuals to go over to the dark side. Financially motivated threat actors will most likely evolve, and such attacks will be quite widespread. Сyber espionage attacks — political, interstate, and corporate ones — will also hold a prominent place.

Next year, Group-IB expects to see new hacker groups that will specialize in attacks on industrial enterprises and gaining access to supervisory control and data acquisition (SCADA) systems in order to manipulate the manufacturing process. In light of the rising tensions in the Middle East, we will possibly see the first attacks on the control systems of transport ships in the Persian Gulf. In addition, Group-IB expects more sabotage operations against Iran’s critical infrastructure facilities, especially those related to nuclear energy.

Against the backdrop of growing confrontation between various states, we also expect that threat actors will attack telecom operators for the first time in order to cause logical network congestion, which would lead to a cascading effect and affect multiple industries. Attacks on energy facilities are likely to take place in the Middle East or in other countries where new military conflicts arise.  Hacker groups using JS-sniffers will pose a major threat to online retail, especially in the U.S. Meanwhile, the main business risks will be associated with fines for security violations rather than with compensation for damage to customers or reputational losses. Next year, Group-IB doesn’t foresee a large number of traditional attacks on banks for theft purposes. There may be rare incidents, but this type of activity will no longer be as widespread as it used to be.


About the Author

As a first-year student at Russia’s leading engineering university the Moscow State Technical University of N.E. Bauman, Dmitry Volkov co-founded Group-IB, a cyber investigations startup back then. Currently, he serves as the CTO and the Head of the Threat Intelligence & Attribution Department. Volkov is the mastermind behind most of Group-IB’s products. From day one, he has been a prominent voice leading Group-IB toward becoming the go-to expert in threat hunting and intelligence.

Volkov is a recognized visionary leader. In 2015, he was listed by Business Insider as one of the top 7 professionals behind influential security companies. Volkov is a great believer in the idea of engineering neutrality and an advocate of cyber weapon non-proliferation. In 2013, he became a member of the UN Open-ended Intergovernmental Expert Group aimed at conducting a comprehensive study on the problem of global cybercrime. Since 2016 he is a member of the Europol EC3 Advisory Group on Internet Security.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related stories: 

Seven Impactful Cyber-Tech Trends of 2020 and What it Means for 2021

2021 Predictions: Holistic, Centralized, Software-Defined, and Automated Security that is Everywhere

2021 Cybersecurity Predictions: From the Rise of Ransomware to Remote Working, it is Time to Shore Up Tour Defenses

South Country Health Alliance Suffers Security Incident

South Country Health Alliance Suffers Security Incident

South Country Health Alliance (SCHA), a public health department in Minnesota, suffered a security incident that may have affected the personal information of some SCHA community members. SCHA discovered unauthorized access to an employee email account on June 25, 2020. After a primary investigation, SCHA confirmed that certain private information belonging to some of its community members may have been stored in the account.

The exposed information included personal and protected health information like names, Social Security numbers, addresses, Medicare and Medicaid numbers, health insurance information, diagnostic or treatment information, date of death, provider name, and treatment cost information.

While there is no evidence of any misuse of the exposed information in the incident, SCHA has notified about the breach to the impacted members. The health service provider provided information about the incident and recommended the necessary security steps to protect their personal information. In addition, SCHA offering complimentary credit monitoring and identity protection services to the affected members.

Cyberattacks on health care organizations have become rampant in 2020. With multiple data breaches and ransomware attacks, the health care providers continued to be the primary target for cybercriminals. According to the “U.S. Health Care Data Breach Statistics” survey, around 70% of the U.S. population is affected by health care data breaches, with over 230,954,151 health records lost, stolen, or exposed in various security incidents. 2018 and 2019 witnessed a sharp increase in the number of individuals affected by health care data breaches, with a six-fold increase between 2017 and 2019.

How Intel’s Homomorphic Encryption Can Process Ciphertext

Network Encryption, DSCI Whitepaper on Encryption

Data Privacy is a big concern for governments and institutions. There are many debates about data residency, data stewardship, data ownership, and data privacy on the cloud. The introduction of acts/laws such as GDPR, CCPA, LGPD, and industry standards like HIPAA, have kept data privacy in check. Data custodians are bound by data privacy laws. That can be a real inhibitor to bringing larger data sets together, which in turn limits how much we can infer from that data. Data is encrypted at rest and in transit, but it must be decrypted to be processed on the cloud or elsewhere. So, there is a window of opportunity where data privacy can be compromised. Well, Intel Labs has been working on a homomorphic encryption standard to address this issue. However, there are some speed bumps to be tackled before the technology is ready for widespread adoption. CISO MAG had earlier reported on a related development called Federated Learning. Both are part of Intel’s Confidential Computing mission, which aims to tackle the issue related to the restrictions around data privacy.

By Brian Pereira, Principal Editor, CISO MAG

Speaking at Intel Labs Day on December 3, 2020, Jason Martin, Principal Engineer, Secure Intelligence at Intel Labs, updated the audience on Intel’s progress with Homomorphic encryption.

“Homomorphic encryption is a new cryptosystem that allows applications to perform computation directly on encrypted data, without exposing the data itself. The technology is emerging as a leading method to protect the privacy of data when delegating computation. For example, these cryptographic techniques allow cloud computation directly on encrypted data, without the need for trusting the cloud infrastructure, cloud service, or other tenets,” said Martin.

How Does Fully Homomorphic Encryption Work?

What is homomorphic encryption? You are familiar with the concept of public and private keys for encryption and decryption. In traditional cryptography, a public key is used to encrypt the data. And a secret private key is exchanged between the two parties for decrypting it. When this processing happens on the cloud, the cloud server must have access to the secret key to unlock the data for processing purposes. Homomorphic encryption simplifies and secures this process by allowing the cloud to perform computations on ciphertext or the encrypted data. And then return those encrypted results to the owner of the data. So, the data is never decrypted at any point in time, and complete privacy is maintained, regardless of where data is stored.

Intel Labs researchers discovered that any arbitrary computation can be constructed from addition and multiplication. They also found that in fully homomorphic encryption, you can perform those basic operations on encrypted data using any algorithm of arbitrary complexity. And when you decrypt the data, those operations are applied to the plain text.

Speed Bumps

But why hasn’t homomorphic encryption gone mainstream yet? There are some technical challenges to overcome as traditional hardware and software cannot handle the huge overhead presented during homomorphic encryption.

“In traditional encryption mechanisms to transfer and store data, the overhead is relatively negligible. But with fully homomorphic encryption, the size of homomorphic ciphertext is significantly larger than plain data. In some cases, 1,000 to 10,000 times larger. This data explosion then leads to a compute explosion,” explained Martin.

As the ciphertext expands, it requires significantly more processing. This processing overhead increases not only from the size of the data but also from the complexity of those computations. And that will require significant hardware resources like memory. Current hardware cannot handle such a scale and that’s why homomorphic encryption is not already in widespread use.

“At Intel, we wanted to democratize access to this technology. To do this, we are investigating new hardware and software approaches. And engaging with the ecosystem and standards bodies,” added Martin.

The answer to these limitations lies in emerging computing technologies like Quantum Computing.

There is yet another challenge. When data sets are owned by multiple entities and stored on multiple systems, exchanging sensitive data and consolidating it for processing becomes a challenge due to privacy. Intel Labs demonstrated Federated Learning that allows multiple parties to collaborate securely with their sensitive data.

Read more about Federated Learning here.


Brian Pereira

About the Author

Brian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Axio Offers a Limited Time Free Coverage Analysis for SolarWinds Impacts

cyber insurance, Axio for SolarWinds Impact

Axio, a cyber risk management service provider, in the wake of the SolarWinds event, has come up with a limited time offer to perform rapid analysis of insurance coverage by making the Axio360 policy analysis engine available to anyone interested. The offer is valid through January 31, 2021.

Scott Kannry, CEO of Axio, explained his company’s stance giving an example of the NotPetya attack of 2017 stating, “After that attack, certain insurers cited the ‘act of war’ exclusion to deny claims related to that event because the attack originated from nation-state actors. SolarWinds could open that can of worms again so any potentially impacted company should understand the possible pitfalls in their insurance coverages. To help gain quick insight into potential problem spots, we are making the Axio360 policy analysis engine available for free through the next month to any company that is interested.”

Related News:
U.S. Government Takes the Wind Out of SolarWinds’ Sails…for the Time Being!

How Axio Will Help for SolarWinds Based Claims

Axio’s AI engine identifies exclusions and clauses that may create hurdles in policy coverage for SolarWinds-related losses. These could include exclusions such as the act of war, targeted attack exclusions, and even newer exclusions introduced that specifically can be referenced to the SolarWinds event.

Axio has requested the interested companies to provide their policy for analysis. Within one business day, the companies would receive a complete analysis email, which would be flagged with clauses identified and suggestions for further steps and deeper analysis of the entire policy.

Kannry added, “The SolarWinds hack is an unprecedented event with a very high magnitude that has potentially affected over 300,000. Now is the time for these companies to understand what could be at risk and if their insurance coverages will be there when most needed.”

Related News:
Microsoft and FireEye Create a “Killswitch” for Sunburst Malware Affecting SolarWinds’ Orion

How to Boost Amazon S3 Bucket Security

DEO data breach

Misconfigured S3 buckets have led to major hacking incidents, for which the Magecart Group has been largely responsible. The Capital One data breach (100 million customers impacted), Facebook data breach, the Honda database leak, and the data breaches at British Airways, Ticketmaster, and numerous other companies – were all incidents due to misconfigured Amazon S3 buckets. While the blame cannot be put squarely on Amazon (which issues plenty of documentation on how to secure S3 buckets), it is the responsibility of the companies who avail of S3 services from Amazon. In this article, I will cover the functions of the S3 buckets, how cloud storage repositories become vulnerable, and how to secure S3 buckets.

By Brian Pereira, Principal Editor, CISO MAG

S3 buckets are an object storage service offered by Amazon called Simple Storage Service (S3). It is cloud storage. At some point traditional, on-premise databases could not handle the immense scale required by modern enterprise applications served to millions of users, and hence storage technology had to evolve. Mobile applications and big data analytics on cloud also require object storage. And then there is the explosive growth of data generated by users and IoT devices. Scalability is a key advantage of cloud computing and services like Amazon S3 can handle mega databases with billions of records. The other advantage of cloud storage services is high availability. Amazon, for instance, claims to offer 99.999999999% (11 9’s) of “durability,” though there have been occasional outages.

Why Do S3 Buckets Get Hacked?

S3 buckets are storage repositories or storage containers on the cloud, which means they could be accessible to anyone, unless the administrators configure the S3 buckets and their Access Control Lists (ACLs) to give explicit or exclusive access to certain users. More often than not, this configuration is not correctly done, and hence S3 buckets become vulnerable.

Amazon S3 access control lists (ACLs) enable you to manage access to buckets and objects. Each bucket and object has an ACL attached to it as a subresource. It defines which AWS accounts or groups are granted access and the type of access. When a request is received to access a resource, Amazon S3 checks the corresponding ACL to verify that the requester has the necessary access permissions (Source: Aws.Amazon.com).

When you create a bucket or an object, Amazon S3 creates a default ACL that grants the resource owner full control over the resource.

Let’s step back and explain what all that means.

S3 buckets, How Amazon S3 Buckets get hacked, How to protect S3 bucketsAlmost every organization has its IT infrastructure deployed on the cloud today. Virtual Private Clouds (VPCs) are like private clouds hosted within the public cloud. VPCs are private and secure spaces for organizations, on the public cloud, and are not to be confused with the private cloud. A private cloud, on the other hand, is single-tenant and exclusively for the use of one organization. Public clouds are multi-tenant and shared.

If an organization has a VPC, on say, the Amazon Public Cloud, then its ecosystem of employees, partners, and customers will access its resources on the VPC via a gateway. The VPC itself is divided into logical segments called subnets (security groups). Technically, a subnet is a range of reserved IP addresses within a network that is not available to everyone within the network. Subnets divide part of the network for private use. Similar functions and resources are grouped in a subnet. But to access those resources, users need to go through an ACL that specifies who is allowed to access which resource in that subnet.

The problem is ACLs and S3 buckets are poorly configured, and the cloud customer is to blame. By default, S3 buckets are private and secured, but someone in the organization (or a consultant) changes the security settings, leaving the buckets exposed. It allows even unauthorized persons (hackers) to get in and access storage repositories in the subnet.

What Can You do to Protect Your S3 Buckets?

In 2017, Amazon introduced encryption and other features to secure S3 buckets. They also offer guidance and advice, like AWS Config to monitor for and respond to Amazon S3 buckets allowing public access.

So, the first step to securing S3 buckets is to take advantage of all these features by reading the Amazon documentation and following the instructions.

Always comply with the Amazon S3 policies to define who can access the objects stored within the bucket. Train your IT and security teams to never open access to the public, unless necessary. Open access will expose PII and other sensitive data. Be sure to take advantage of capabilities like AWS Config to prevent unauthorized access to your data.

Document these best practices and create policies. Train your IT staff to follow these policies. The actions of third parties, such as consultants, should be closely monitored. If they have high-level access to your storage containers, check what kind of configuration changes they are making.

Closing notes

Protecting S3 buckets is about careful configuration — don’t ever expose your storage containers to the public. Train your IT staff in the nuances of security configurations and keep a Hawkeye on anyone who has access to S3 configurations and ACLs.