Home Blog Page 132

Greater Cybersecurity Threat Predictions with a Primer in Machine Learning

Artificial Intelligence, AI, neural, machine learning

With the increased number of cyberattacks, especially in light of the COVID-19 pandemic, the process of manually or semi-automatically receiving cyberthreat alerts that need to be analyzed by a human is not feasible. By the time an organization determines that an attack has happened and with the possibility of a breach, an organization or end-user may already be under a second or third attack. Being able to predict and within a timeframe that permits organizations or end-users to act before negative outcomes ensue is critical to withstand cyberattacks.

By Samir Souidi, M.S., MBA, Indiana University, Population Council; and Stan Mierzwa, M.S., CISSP, Director, Kean University Center for Cybersecurity

However, given the increase in cyberthreats resulting from the COVID-19 pandemic, especially with ransomware and Phishing attempts, better proactive and identification of threats is a must!  Integrating Machine Learning (ML) with cybersecurity protection is a must if making better predictions of threats is to occur. To utilize Machine Learning, organizations either need to purchase or incorporate tools that already have the technology integrated. They will need to train-up staff to create and utilize ML. However, in order to be effective or useful for the general consumer, awaiting for higher-level tool use or knowledge is not practical.

Machine Learning and Artificial Intelligence Clinic

For those who are new to the topic of ML, in essence, it is the science of programming computers so they can learn from data by themselves. By a general definition stated by computer gaming and Artificial Intelligence expert Arthur Samuel in 1959, “[ML is the] field of study that gives computers the ability to learn without being explicitly programmed.”  In a more engineering-oriented definition, defined by Computer Scientist and ML learning pioneer, Tom Mitchell in 1997, it is “A computer program is said to learn from an experience E with respect to some task T and some performance measures P, if its performance on T as measured by P, improves with experience E.” In other words, ML is learning to predict a task T from the experience E (data); the accuracy of the prediction will improve by learning more from E (data).

So, how does the ML algorithm learn? The goal of the ML Is to learn the weights,  in the context of the problem, the weights are numerical values and are associated with each feature and measure how important this associated feature is to the accuracy of the prediction. If the accuracy is high, it indicates the weight is very significant, and if the accuracy is low (error) it indicates the weight is not significant. The ML will try many rounds while learning about the training data and assign new weights until it finds the best accuracy. In our example of an email spam filter, the algorithm will assign a mathematically educated guess of the weight for each feature in the email (e.g., one feature indicating if a capital letter is used, or IP address, or repeated words), then will predict if the email is spam or not  (T) and then compare to Y (target or actual) email status (spam or not spam) in the training data, if they are different (P), then this an error and the weights are not correct. The ML will try again with the same data input, but this time it will assign new improved weights because the ML is starting to know the data and can guess better weight values. The ML will repeat his process until it reaches the best accuracy. If we can write all this process in a linear mathematical equation, just for simplicity, we will get something like this:

f(x)=w_0 x_0+w_1 x_1+⋯+w_m x_m

There are many different types of ML models and they can be classified into three major categories:  Supervised Learning; Unsupervised Learning; Reinforcement Learning. Based on the data and the problem that needs to be solved, you can select the best ML category that will help to choose the best algorithm and how you can evaluate the accuracy. In Supervised Learning, the training set you feed to the algorithm includes the desired solutions, called labels, a typical Supervised Learning task is classificationing.

Although most of the applications of ML today are based on Supervised Learning, most of the available data is unlabeled – which creates an unmet need in Supervised Learning. Unlabeled data generally requires a human to go through the data and label them manually. Going forward, new inventions in ML via Self-Supervised Learning, which requires one to provide a small amount of trained data that is labeled, will be beneficial.  We let the ML learn by itself and label the unlabeled data. But Unsupervised learning in its current state is very useful to allow us to understand and cluster data in caser we have massive data that we know about it. For example, Clustering, which is a great tool for data analysis, search engines that will group similar instances into clusters. Unsupervised Learning is well used in Anomaly and fraud detection, the objective is to learn what “normal” data resembles, and then use that to detect abnormal instances. Reinforcement Learning is one of the most exciting fields of Machine Learning today and one of the oldest. It is mainly used in the gaming industry where many applications use Reinforcement Learning in their games, and it received attention when the startup British company DeepMind developed ML using Reinforcement Learning that allows the system to learn to play an Atari game from scratch and eventually outperformed humans at these games. In Reinforcement Learning, the learning system called an agent, can observe the environment, select and perform actions, and get rewards in return or penalty in the form of negative rewards. It must learn by itself the best strategy, called a policy, to get the most reward over time. A policy defines what action the agent should choose when it is in a given situation.

Beside game applications, Reinforcement Learning is heavily in combination with Deep Learning in self-driving cars, where the Deep Learning is detecting on the fly the physical objects that a car senses and the Reinforcement Learning absorbs these inputs and tries to learn how to drive without crashing or hitting any object or person (get rewards).

Existing Systems and Solutions Utilizing ML Cybersecurity Threat Prevention

There do exist cyberthreat and protection vendors that do have ML integrated into their platforms. As reported by Built-In, large firms such as Microsoft have defended against the installation of malicious cryptocurrency miners by using Windows Defender, their software that uses ML to identify and block perceived threats.  It is just this sort of integration of ML that proves effective because of the focus on “learning”. This is even more important as more and more cyberthreats are emerging during the global, transnational pandemic event. In addition, ML is well implemented by Cloud providers to monitor unusual login activity to their platform with the use of anomaly detection algorithms that allow analyzing unusual activities.  For example, if the same user account login took place from two different geographical locations in a close time range, this would be flagged or an alert created. Also, ML algorithms are used by cybersecurity providers to analyze “on the fly” massive DNS records to prevent Domain Generation Algorithms (DGA) based malware.

Predicting Where ML will Further Grow in Cybersecurity Tools

Given the increases in cybersecurity threats and threat actors, and the amount of data flowing in cybersecurity operations centers, more in the way of intelligence is inevitable to help those analysts tasked with protecting organizations and agencies.  It is quickly becoming extremely challenging to simply respond to cyber incidents.  What will assist the cyber operations staff is to provide solutions that can predict and auto-respond to incidents where possible.  ML may lead the way especially, in Unsupervised Learning, where we can see ML trying to learn by itself with less supervision from humans to check all system events manually, cluster them and predict which event will cause harm to the system, and taking action.  In essence, instead of just receiving an alert, the Machine Learning algorithm will take action and stop these said determined events.

Think gaming, simulation, and self-driving cars where there is the potential to handle so many different constraints and movements with the use of ML – why can’t we do the same with cyber?


References

Research paper: A Machine Learing Framework for studing Domaon Generation Algorithm (DGA) -Base Malware, by Tommy Chin, Kaiqi Xiong, Chengbin Hu, YiLi


About the Authors

Samir SouidiSamir Souidi is the Global Enterprise Systems/Software Architect at the Population Council, headquartered in New York City, New York, and owner of the startup Atlas Data Services. Samir is an expert in data analytics and science, having received his MBA from Indiana University with a specialization in data in 2020.  Souidi is the recipient of the 2016 Excellence Award in Information Systems from InsideNGO, now known as Humentum.  Souidi has a BA in Business Administration from the Supérieure de Commerce in Morocco and an MS in information systems from Pace University and a member of IEEE. He is fluent in Arabic and French and traveled globally in implementing mHealth and eHealth solutions.

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean University

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean University in the United States. He lectures at Kean University on Cybersecurity Risk Management, Cyber Policy, Digital Crime and Terrorism and Foundations in Cybersecurity.  He is a peer reviewer for the Online Journal of Public Health Informatics journal, a member of the FBI Infragard, IEEE, ISC(2), and a board member (Chief Technology Officer) of the global pharmacy education non-profit, Vennue Foundation. Stan holds an M.S. in Management with specialization in Information Systems from New Jersey Institute of Technology and a B.S. Electrical Engineering Technology from Fairleigh Dickinson University, is also a Certified Information Systems Security Professional (CISSP).

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


A more detailed version of this article will be available in the February issue of CISO MAG.

‘DevSecOps’ Mitigates Cybersecurity Risk from Digital Transformation

devsecops

Achieving customer value with any digital transformation initiative requires an organizational and cultural shift across the enterprise to align people’s efforts with customer priorities. We see such cultural change in software development shops in particular, as DevOps becomes the standard approach to delivering quality software at the velocity the business requires.

By Jason Bloomberg, President, Intellyx

There is a dark underbelly to digital transformation-driven customer value, however: cybersecurity risk. The more technology-centric our organizations become and the faster they go, the greater the chance that a hacker will find that one vulnerability that will suck away all that hard-earned customer value.

The downside of cybersecurity risk certainly garners more headlines than the upside of digital efforts to be sure – and an increasing number of executives are realizing that they must address both together.

The inevitable conclusion: how organizations deal with cybersecurity risk must also transform. They cannot simply keep dealing with such risks as they have in the past.

The Transformation of Cybersecurity

Just as digital transformation requires breaking down organizational silos, so too with cybersecurity. “Security needs to be part of everyone’s job,” explains Fraser Scott, Cloud Security & DevSecOps at Capital One. “Security being a constant blocker just won’t scale. Either that or you end up with shadow IT.”

Traditional IT shops relegate ‘information security,’ or InfoSec, to a separate department. Developers must then run their code by InfoSec for approval. This state of affairs slows application development (‘appdev’) down and creates an adversarial relationship between the appdev and InfoSec teams.

From the perspective of modern appdev, such blocking both impacts customer value and also doesn’t serve the goals of cybersecurity. “The problem for the security person who is used to turning around security reviews in a month or two weeks is they’re just being shoved out of the game,” says Gene Kim, DevOps thought leader and co-author of The Phoenix Project. “There’s no way with how InfoSec is currently configured that they can keep up with that. So, InfoSec gets all the complaints about being marginalized and getting in the way of doing what needs to be done.”

Large enterprises are clearly understanding this transformation within the cybersecurity ranks. “In order for InfoSec and agile to be effective in an organization, you can’t have it locked up with a few people or a few departments that are narrowly looking at their portfolio of work,” says Julie Tsai, director of engineering in information security at Walmart Global eCommerce.

The Rise of DevSecOps

If breaking down the siloed InfoSec team and spreading the responsibility for security across the organization sounds familiar, you’d be right – it’s an extension of DevOps, the cultural and organizational shift that has been dissolving the boundaries between appdev and operations for several years now.

The result is ‘DevSecOps’ (or ‘SecDevOps’ or even ‘DevOpsSec,’ depending on whom you ask). “Because developers drive the software agenda, their participation is crucial for achieving a more secure framework,” explains a white paper from security vendor Veracode. “Yet simply acknowledging this fact won’t get the job done. As a developer, you need to position yourself at the center of an application security strategy, and DevSecOps represents the natural evolution of the concept.”

In other words, DevSecOps doesn’t simply amount to dropping a security person onto a DevOps team, a mistake many organizations have made. “The security teams, however, face the biggest adjustment,” the white paper continues. “Security people need to abandon the mindset of check-box compliance, or else get left behind as DevOps takes off.”

Capital One’s Scott emphasizes this point. “DevOps doesn’t mean one unicorn engineer doing all the things. It means breaking down the traditional silos,” Scott explains. “You might end up with a single functional team that has a mixture INSIGHT of software engineers, QA, and security. Or maybe separate teams working together. The trick is getting the right people involved earlier on.” Zane Lackey, who built the cybersecurity effort at Etsy, ties the InfoSec team’s role closely to DevOps. “Its role shifts from being this blocker or gatekeeper to actually thinking about, how do I enable the rest of the business to move faster—whether that’s the development team, whether that’s the DevOps teams—whatever side of the business they’re interfacing with, the real shift becomes, how do we enable them to move faster?” Zane Lackey is currently the CoFounder/CSO at Signal Sciences.

The Role of Tooling in DevSecOps

While DevOps is more of a culture change than a technology effort, it unquestionably depends upon better automation tooling – and so too with DevSecOps. “Automation has a big part to play here because it removes the typical human barriers that introduce slowness and latency,” Scott explains. “Instead of emailing some team a document containing changes to review, a git commit could trigger automated tests that effectively carry out the decision-making process the person would have made.”

Joshua Corman, Chief Security Officer, SVP at PTC emphasizes this point. “DevOps involves processes and toolchains, but I think the defining attribute is culture, specifically empathy,” Corman says. “If you show DevOps teams how security can make them better, then as a reciprocation they tend to ask, ‘Well, are there any choices we make that would make your life easier?’”

Security vendors also see the importance of tooling to DevSecOps, even though it takes a supporting role to the necessary organizational transformation. “We’re baking DevSecOps into the entire software development process,” says Otto Berkes, EVP, and CTO of CA Technologies. “We need an understanding that customers are going through a culture change. We can’t dump tools like Veracode into an organization and expect good use.”

Berkes’ boss, CA CEO Mike Gregoire, echoes this sentiment with advice for management. “Mandating DevSecOps is a fool’s errand,” Gregoire says. “You have to provide tools and training.”

Lackey adds some words of warning. “A lot of the security tools or vendors … have caused us more problems than they’ve actually solved, and so you see developers or DevOps folks … wince when they hear a new security tool coming or something because they’ve had negative experiences in the past,” Lackey warns. “When I think about … enabling those teams with security resources directly, it’s about plugging into what they’re already doing, and really thinking about security as a piece of the DevOps toolchain that folks are already thinking about.”

Better tooling and automation are thus important enablers of DevSecOps, but more important is including security considerations in the DevOps effort broadly – and by extension, across the digitally transformed organization as a whole.

For such organizations, the central principle must be that security is everyone’s responsibility. Given the fact that most of today’s cyberattacks begin with phishing schemes that can target anyone in an organization, this principle is already of primary importance. DevSecOps is one way of making such a principle a reality across the software development efforts essential for any digital enterprise.


About the author

Jason Bloomberg is a leading IT industry analyst, author, keynote speaker, and globally recognized expert on multiple disruptive trends in enterprise technology and digital transformation. He is ranked #5 on Thinkers360’s Top 50 Global Thought Leaders and Influencers on Cloud Computing for 2020, among the top nine low-code analysts on the Influencer50 Low-Code50 Study for 2019, #5 on Onalytica’s list of top Digital Transformation influencers for 2018, and #15 on Jax’s list of top DevOps influencers for 2017.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Managed Security Services: Big Brothers and Guardian Angels

managed services provider (msp)

Big Brother is a fictional character in George Orwell’s dystopian novel “Nineteen Eighty-Four,” published in 1949. The story is about an imaginary state called Oceania, where there is great suffering and social injustice. Its citizens are under the constant surveillance of the governing authorities, mainly through telescreens. The people are constantly reminded of this through the slogan “Big Brother is watching you.” Today, “Big Brother” denotes abuse of government power, particularly in respect to civil liberties, often specifically related to mass surveillance. But “Big Brother” is not always negative. In the context of cybersecurity, an enterprise needs a “Big Brother” or “Guardian Angel” to watch over its infrastructure. And so, this article focuses on the companies who look after your IT infrastructure through managed security services (MSS). We’ve got viewpoints from global CISOs, industry analysts, and Managed Security Service Providers (MSSPs).

By Brian Pereira, Principal Editor, CISO MAG

Here are the key findings of our research:

1. Every type of business and industry is vulnerable

All businesses, regardless of size and sector, are exposed to cyberattacks today. Organizations are digitizing and connecting infrastructure to the cloud and the Internet. Even manufacturing companies, which for decades used operational technologies (OT), are now using SCADA (supervisory control and data acquisition) and IoT devices that are prone to cyberattacks. Ransomware impacted several healthcare companies in 2019.

Malicious actors tend to compromise intellectual property, financial data, credit card details, personally identifiable information (PII), electronic health records (EHR), customer transaction records in retail, blueprints for components, business secrets — and sell it on the Dark Web.

2. Threat landscape is expanding; the nature of attacks is sophisticated

To make threats more sophisticated and targeted in nature, threat actors are employing artificial intelligence, machine learning-based techniques, and stealth technology.

D.C.S. Hariharan, Information Security Risk & Compliance Head, Syngene International Ltd., said, “The emergence of threats such as DDoS attacks, targeted ransomware, cyber extortion, and advanced malware attacks, has led to a higher uptake of advanced security solutions.”

3. Shortage of experienced manpower

The lack of cybersecurity skills and declining security budgets has made it impossible for organizations to monitor its infrastructure effectively and block recurring attacks.
This is more so in the case of small and medium businesses and government organizations that don’t have budgets for hiring high-salaried security professionals.

Dick Wilkinson, IT Security Officer, New Mexico Judicial Information Division, informs us that, in the U.S., a shortage of qualified security employees is driving companies to use a shared resource like a MSS provider or a SOC (Security Operations Center).

“Security employees are in high demand and thus more expensive to hire, so the coverage of an MSS SOC can be a way to close that gap at a lower cost,” said Wilkinson.

4. Regulation & Compliance

With the introduction of new regulations and compliance mandates, organizations will find it a challenge to keep up and yet focus on their core businesses. Non-compliance can also prove to be expensive and lead to business losses, as we have seen in the case of GDPR.

“Organizations must have in-depth knowledge of current privacy laws, regulations and compliance frameworks that affect their business,” said Jason Albuquerque, Chief Information Officer & Chief Information Security Officer, Carousel Industries, Inc. “With the rapidly changing governance, risk and compliance landscape, it becomes extremely difficult to stay up to date with these changes. For this expertise, organizations can look to MSSPs for help.”

MSSPs have experts on compliance and regulation and they can ensure adherence to regulations for data localization, storage, and protection requirements.

“Global MSSPs must have a global data management strategy to be sure that they are not adding a business or compliance risk to their clients. Also, to add additional value for the customer, these subject matter experts can act as consultants to the clients to help build strategies to strengthen their security posture,” added Albuquerque.

5. Traditional security monitoring is inadequate

Traditional security monitoring practices don’t stand a chance when it comes to detecting and blocking modern-day threats. Two traditional approaches, SIEM (security information and event management) and LM (log management), are no longer enough.

“There is a need to have next-generation security operations where Managed Detection and Response (MDR) providers can support enterprises by providing advanced detection, faster incident mitigation, global threat intelligence, and deep threat analytics,” said Hariharan.

Pankit Desai, Co-founder and CEO at SEQURETEK, said, “Companies are now seeking MSSPs with an integrated model. Earlier, there were separate entities for monitoring, for response, and managing. Today there is a capability that looks at identification to remediation and response, to detection. You need one value chain—someone who orchestrates it end-to-end.”

managed security services

The move to Managed Security Services

Boards in companies take cybersecurity very seriously today, more so after digitalization. A cyberattack on IT infrastructure could bring business operations to a halt, peeving customers, partners, and shareholders. That could lead to a decline in the share price of a company, loss of customers, and irreparable damage to its reputation.

An organization can take two paths to reduce the chances of that happening: They could either have an in-house security team working round the clock in shifts to monitor and manage infrastructure. The other option (and a more cost-effective one) is to outsource their security management to a third-party or MSSP.


About the Author

Brian PereiraBrian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).


managed security services

This cover story first appeared in the February issue of CISO MAG. Get your preview here.
To read the full version, Subscribe now!

 

Ghost of the Cyber Past, Present, and Future [INFOGRAPHIC]

Gift Cards, cyber ghosts

HOHo Ho! It’s Christmas! The holiday season is the perfect time to re-read Charles Dickens’ timeless classic, “A Christmas Carol.” To those of you who don’t know, the story revolves around an obnoxious hermit, Ebenezer Scrooge, who despises Christmas. He breathes bitterness by saying, “BAH! Hambug” in response to his nephew’s “Merry Christmas!” However, he seeks redemption after the ghosts of Christmas Past, Present, and Yet to Come impart him with lessons of morality.

But Scrooge is not limited to Dickens’ classic. Today, he has made his way to the digital world, spewing malware strains and data breaches. While we’re stuck indoors – thanks to the pandemic – sales of online stores are booming. Holidays are a hot favorite of cybercriminals for targeting both the retail industry and shoppers. Thanksgiving, Halloween, Black Friday, and now Christmas!

While we frantically search for the best deals, let’s be vigilant about all the malicious websites, emails, and links aiming to pilfer our financial information.

Cyber Ghosts


About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author.

 

Visibility is Power – What You Don’t Know Can’t Get You Further

Jason Lim is the Founder & CEO of Cydentiq. Having 15 years of expertise in the information technology industry and identity security domain, Jason gained substantial experience in various roles including leadership, strategic advisory for identity security, service delivery, business development, marketing strategy, team development and success mentoring. He is highly passionate in the areas of identity management and insider threat. He is also the subject matter expert of privileged access management and has been providing extensive advisory service across different industries especially financial services. Jason is an active public speaker in cybersecurity & technology conferences such as EC-Council, ISACA Malaysia Chapter & Malaysia Institute of Accountants (MIA), and others.

Prior to this startup journey, he was the Vice President of Cybersecurity at Wiki Labs, responsible to build the new cybersecurity business division and drive go-to-market strategies. Under his leadership, Jason has successfully transformed the business into a growing & profitable model. As part of his cybersecurity journey, Jason has established his remarkable milestones at MasterSAM, was responsible to drive company operation & strategic direction in Malaysia & Singapore, and also the business expansion to the Asia Pacific region before the company was acquired by Silverlake.

In an interesting conversation with CISO MAG, Jason Lim discusses the challenges he faced while setting up the cybersecurity division at Wiki Labs, his views on Privileged Access Management Risk, and much more.

Do you think the current cybersecurity measures would be relevant in another two years, or will it become obsolete?

Today, cyber threats are evolving. Cyber attacks are getting more sophisticated and organized. Prevention is no longer an effective strategy because you can’t protect if you don’t have the visibility. Visibility is the key in today’s complex environment. While we have billions of data collected from different sources, it is important to know how can we get good information and provide better insights from it to make decisions. Organizations should start leveraging a good analytical platform that uses artificial intelligence, machine or deep learning technologies to accelerate data processing and analysis for quicker business value and decision. Organizations today also lack response capability. Many times, when they are under attack, they often panic.

I realize organizations today spend so much time and effort in ensuring they have good policy and they stay compliant to the regulations such as PCI DSS, ISMS, etc. There is nothing wrong with this, but the fact is that it is not just about gaining a tick at the compliance level. Even if you are 100% compliant, it does not mean you are 100% hack-proof. Organizations need to start building a holistic approach to cyber resilience. Cyber maturity assessment is recommended to provide an in-depth review of an organization’s ability to protect its information assets from cyber threats. It combines the view of people, process, and technology to identify areas of vulnerability, prioritize areas for remediation, and demonstrate both corporate and operational compliance, turning information risk to business advantage. My advice for organizations would be to continuously review their cyber resilience strategy and preparedness against cyber threats.

According to a recent Privileged Access Management Risk and Compliance Report, 70 percent of organizations fail to fully discover privileged accounts and 40 percent do nothing at all to discover these accounts. How worrying is this and what can be done to counter this?

Visibility is the power – what you don’t know can’t get you further. Privileged accounts are always the prime target of attackers as they provide the direct path to your network. There is no need to break the windows if you have the key. With privileged account access, you become the “king” and you could do anything you want, including suspending critical service, extracting sensitive information, installing malware, injecting malicious code into programs, deleting entire filesystem, etc. Statistics show that most of the data breach incidents reported today are caused by compromised credentials, lack of visibility and access control, and unauthorized access to critical systems. Ask yourself a few questions – how many firewalls and servers are there in your organization? How many privileged accounts are there within each system? Has anyone changed the default passwords? Do you control who can access those critical systems? How do you monitor third-party vendor access? How do you mitigate the risk of password sharing?

I would recommend the 4A principles to complete your privileged access management framework:

Authentication: It is important to know that securing a system with just the password is no longer a good protection strategy. Password is always a hacker’s best friend. Hackers may take time to crack the password, depending on its complexity and algorithm. But, the fact is, once the password is compromised, they can access your critical data freely. There is a need to build an extra layer of protection for privileged access to reduce the attack surface. Many security compliance standards have emphasized the need for multi-factor authentication in their regulatory guidelines as a part of the best security practice today.

Authorization: It is highly recommended to adopt the least privilege model as the best security practice. At Zero-Trust principle, it emphasizes trusting nobody by default, meaning that nobody should have the access to the system until they are granted proper authorization.

Access: To satisfy the Role-Based Access Control (RBAC) principle, the access should always be restricted and relevant to the user’s function role. Use auto-login technology to connect to critical systems, thus, eliminating the exposure risk of privileged credentials. Each privileged access should be restricted within a specific period and none should have administrative access at all times. The privileged credentials must be periodically randomized – either right after use, schedule, or manual trigger, based on strong password complexity requirements.

Audit: Auditing is an important process that examines and ensures proper security control is always in place to fulfill regulatory compliance standards. Some of the frequently asked questions from auditors are: when was your last change of password, how do you audit their activities performed on the server? Do you restrict your administrators’ access? What is your approval process? Be sure to monitor and record user activities; the recorded data must be available instantly to allow real-time monitoring or session playback so that one can take immediate action when necessary.

You also hold great expertise in Identity and Access Management. According to you, what are the major challenges in this area?

In the past, cyber attackers spent their time devising ingenious malware, hunting vulnerabilities, stealing credit card information, and exploiting systems for financial gain. Today, cyber-attacks are getting more sophisticated and identity theft has become one of the prominent attacks. Attackers just need to find only one weakness among millions of exposure points to gain the door access to the organization. The top three challenges are:

Compliance gap due to lack of access review

It’s often a nightmare for IT department when it comes to access review audit – processes tend to be manual and they struggle hard to collaborate with business units to generate application entitlement reports, and often collect inconsistent outcomes, run manual consolidation, and eventually fail the regulatory compliance. Most organizations struggle to answer the basic question: “Who has access to what?” Over time, certain employees may have been granted excessive rights or privileged access to critical systems. Organizations tend to be weak in this visibility context, as a result, the audit does flag out these scenarios. There is no centralized and holistic view of the user access matrix across the entire organization. You can never get it right without fundamental visibility.

Manual provisioning and de-provisioning of access

I have seen several examples where a new hire, especially a replacement, is simply granted the same access rights as the existing staff – often by “cloning” their account – without reviewing his/her appropriateness of existing access. During the hiring process, HR would typically inform IT to manually create an identity and assign appropriate rights to the new employee. Over time, the employee may have requested additional access which requires manual grant and revoke operations according to the approved timeframe. If an employee gets promoted or transferred to a different department, his/her current and new roles will also need to be managed properly. When the employee leaves the organization, his/her account would eventually be deactivated and removed one day. Can you imagine there are so many gaps that exist due to a huge hassle of manual operation running behind this? Orphan accounts are the best scenario to prove this challenge.

Too many passwords to manage

We’ve all been there before. We waited too long, and our password expired. Or we made a change, and somehow that change didn’t trickle down to all of the relevant systems we need to access. If we need to use multiple applications at work, do we use different passwords and make it complex? Most people hate complex and expired passwords and figure out another easy password to remember. Password creation, update, and deletion (CRUD) is a real issue with real costs that IT wants to reduce. Having automated tools that are easy to use and can integrate with existing systems can alleviate much of the pain here along with a single-sign-on solution that is protected with multi-factor authentication.


Disclaimer

When this interview was taken, Jason Lim was the Vice President of Cybersecurity at Wiki Labs. Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Operation Nova: Global Law Enforcement Agencies Seize ‘Safe-Inet’ Criminal VPN Service

Safe-Inet VPN

A coordinated effort led by German Police, with support from other global law enforcement bodies including Europol and FBI, among others, has resulted in the seizure of Safe-Inet VPN service, which was touted as the hot favorite of cybercriminals to carry out malicious activities. The VPN provider’s service was shut down completely on Monday, December 21, followed by a physical seizure of its infrastructure in Germany, Switzerland, France, the Netherlands, and the U.S.

Safe-Inet VPN
Image Credit: Europol

Why Safe-Inet VPN Services were Shut Down?

According to Europol, the Safe-Inet VPN service has been active over the past decade. Europol said that its service gained popularity among the underground cybercriminals as a “Bulletproof” service since it boasted of tools having up to five layers of anonymous VPN security. This degree of protection allowed cybercriminals a virtual shield that law enforcement organizations around the globe found difficult to penetrate.

Riding the wave of its popularity, the VPN service was sold at a higher premium to underground threat actors whose operations included ransomware attacks, e-Skimming frauds, data breaches, and various other forms of cybercriminal activities.

Europol said, “The Law enforcement was able to identify some 250 companies worldwide which were being spied on by the criminals using this VPN. These companies were subsequently warned of an imminent ransomware attack against their systems, allowing them to take measures to protect themselves against such an attack.”

The Takedown

The international takedown was codenamed “Operation Nova.” The law enforcement agencies involved in the takedown include:

  • Germany: Reutlingen Police Headquarters (Polizeipräsidium Reutlingen)
  • Europol: European Cybercrime Centre (EC3)
  • The Netherlands: National Police (Politie)
  • Switzerland: Cantonal Police of Argovia (Kantonspolizei Aargau)
  • United States:  Federal Bureau of Investigation (FBI)
  • France: Judicial Police (Direction Centrale de la Police Judiciaire)

The takedown was a coordinated effort by the agencies mentioned above, as Safe-Inet’s infrastructure was spread across the globe. Europol, however, played a pivotal role in making it possible. The European Cybercrime Centre (EC3) led the path forward to bring all the law enforcement agencies together for devising a joint strategy to prepare for the final takedown.

Edvardas Šileris, Head of Europol’s European Cybercrime Centre, said, “The strong working relationship fostered by Europol between the investigators involved in this case on either side of the world was central in bringing down this service.”

Safe-Inet’s seizure served as an example of the much-needed international cooperation between countries to take down cybercriminals and make the internet a safer space.

What the U.S. DoJ Said

According to the statement by the U.S. Department of Justice,  Operation Nova helped seize three domains providing similar services – SAFE-INET.COM, SAFE-INET.NET and INSORG.ORG – which were used for criminal activities. It added that the service websites were offered in English and Russian languages, shedding light on the geo-targets of its providers.

Post the seizure, all agencies are further investigating the log files and physical infrastructure confiscated from Safe-Inet to get a hold of all the cybercriminals using it as a service.

Related News:

Europol and European Commission Launch New Decryption Platform to Combat Encryption Misuse

Google Explains the Root Cause of the 47 Minutes Global Outage of its Services

Google Announced US$1 Million for its “Be Internet Awesome” Initiative

A recent outage of Google services such as Gmail, YouTube, Google Drive, and Maps  severely affected the operations of users and organizations across the globe. All customer-facing Google services that require Google OAuth access were unavailable for 47 minutes. The search engine giant stated that the disruption was caused due to a security flaw in its global authentication system.

“The majority of authenticated services experienced similar control plane impact: elevated error rates across all Google Cloud Platform and Google Workspace APIs and Consoles. Products continued to deliver service normally during the incident except where specifically called out below. Most services recovered automatically within a short period of time,” Google said.

 The Root Cause

In an official statement, Google stated that its User ID Service maintains a unique identifier for every account and handles authentication credentials for OAuth tokens and cookies. This service rejects users’ requests when it detects outdated data.

“As part of an ongoing migration of the User ID Service to a new quota system, a change was made in October to register the User ID Service with the new quota system, but parts of the previous quota system were left in place which incorrectly reported the usage for the User ID Service as 0. An existing grace period on enforcing quota restrictions delayed the impact, which eventually expired, triggering automated quota systems to decrease the quota allowed for the User ID service and triggering this incident,” Google explained.

Nearly 15% of users’ requests to Google Cloud Storage (GCS) were affected in the incident, especially the users of OAuth, HMAC, or email authentication.

“The majority of impact was resolved, however, there was lingering impact, for <1% of clients that attempted to finalize resumable uploads that started during the window. These uploads were left in a non-resumable state; the error code GCS returned was retryable, but subsequent retries were unable to make progress, leaving these objects unfinalized,” Google added.

Google and Microsoft Join Facebook’s Legal Battle Against Israel’s NSO

Facebook NSO lawsuit

Facebook has been at loggerheads with Israel-based hacking company NSO since last year. It has accused the NSO of exploiting a bug in WhatsApp that wrongfully rendered them rights to surveil more than 1,400 people. NSO has since maintained that its products are strictly used to curb crime and combat terror. However, some reports suggest it has been using the proprietary spyware – known as “Pegasus” – against top lawyers, reporters, and even nutritionists. Noting this as a grievous issue, other tech companies, namely, Google, Microsoft, CISCO, and Dell Technologies-owned VMware have now announced their support towards the social media giant.

Related News:

Facebook sues NSO Group for violating Computer Fraud and Abuse Act

NSO Claims “Sovereign Immunity”

In April 2020, the NSO group filed a request to dismiss the lawsuit pressed by Facebook arguing that it provided hacking tools to police and spy agencies around the globe, and hence, it should be granted “Sovereign Immunity” as foreign governments enjoy in any lawsuit.

The basis of NSO’s arguments was made on two grounds:

  1. The Foreign Sovereign Immunities Act (FSIA): The law that limits whether a foreign state can be sued in U.S. court.
  2. Federal Rule of Civil Procedure 19 (Rule 19): The rule that governs the joinder of parties in civil lawsuits.

The justification provided was not enough and found unfit on both counts. The appeal was correspondingly dismissed by the Northern District of California in July 2020. The NSO has, however, filed once again with the Ninth Circuit for overturning this ruling.

Why Other Tech Giants Support Facebook

Based on a Citizenlab report,  four Pegasus operators had successfully abused an exploit chain known as “KISMET.” KISMET exploited a zero-day vulnerability in the then-latest iPhone 11 iOS 13.5.1. The targets of these operators were 36 personal phones of Al Jazeera employees, including journalists, producers, anchors, and executives. Facebook found the same vulnerability being abused in its case as well; however, the number of targets grew to 1,400.

Considering the NSO’s client base, the targeted numbers unearthed until now are only a fraction of the actual number. Fearing this and the subsequent violation of human rights, other tech giants have joined forces with Facebook to argue against granting sovereign immunity to the NSO. In a brief argument filed with the Ninth Circuit, they said,

This would lead to a proliferation of hacking technology, and in the foreseeable future, we will have more foreign governments with powerful and dangerous cyber-surveillance tools. That, in turn, means dramatically more opportunities for those tools to fall into the wrong hands and be used nefariously.

It will now be interesting to see whether the U.S. court still agrees with the argument presented by Facebook and other tech giants or accepts the defendant’s plea of overturning the previous ruling and abolishing the lawsuit altogether.

Leaked Ledger Database Dumped on Raidforums Dark Market

Compromised Email Accounts

Cryptocurrency wallet manufacturer Ledger is facing the consequences of a data leak on its website, which took place in June 2020. The company recently found that threat actors are posting the leaked data of millions of Ledger wallet customers on the dark web marketplace “Raidforums” for free. The data dump contains sensitive information, including email addresses, contact details, and residential addresses.

Data Breach Overview

Earlier, Ledger stated that an unauthorized third party accessed a portion of its e-commerce and marketing database via exploiting an Application Programming Interface (API) Key.

“Contact and order details were involved. This is mostly the email address of our customers, approximately 1M addresses. Further to investigating the situation we have also been able to establish that, for a subset of 9,500 customers were also exposed, such as first and last name, postal address, phone number or ordered products,” Ledger said in a statement.

Related Story: How to Safeguard Your Cryptocurrency Wallet

Breached Data on Dark Web

Following the data breach, most of Ledger’s customers received phishing emails and malicious messages tricking them into entering personal details. Hackers shared two files that contained the breached data. The first file “All Emails (Subscription).txt” holds the email addresses of 1,075,382 Ledger users, whereas the second file, “Ledger Orders (Buyers) only.txt,” includes sensitive data like names, mailing addresses, and phone numbers for 272,853 people.

Several cryptocurrency traders are reporting about the data dump on social media.

Ledger says…

Suit Up! Ransomware Task Force is Here

ransomware task force

Ransomware has continued to plague digital transformation since the onset of the pandemic. A recent survey from cybersecurity firm CrowdStrike, revealed that nearly 56% of organizations reported a ransomware attack in the last year. With reports of an extended lockdown in parts of Europe being enforced again, there seems to be no stopping for digitization, which inversely means a larger threat surface is exposed and, that ransomware threat will keep growing larger by the day.

To counter this threat, the Institute for Security and Technology (IST) has decided to bring together a formidable team that can help steer the ship away from rough waters; they call this team – the Ransomware Task Force (RTF).

What is the Ransomware Task Force?

The Institute for Security and Technology launched the Ransomware Task Force in partnership with experts from multiple domains like the industry, government, law enforcement, nonprofits, cybersecurity insurance, and international organizations. The RTF’s founding members believe that ransomware is a much larger and complex threat for any organization to handle single-handedly. Thus, having a consortium or council of members who can provide clear recommendations for both public and private sector organizations will significantly reduce the threat and the impact posed by such cybercriminals.

Ransomware incidents need a check as this economically destructive cybercrime has increasingly led to dangerous, physical consequences. Hospitals, Schools, City Governments, and others have been targeted and held hostage by malicious actors seeking ransoms or payouts in exchange. The ransomware menace is not just limited to one sector; this is the prime reason why the IST has involved people from various sectors.  They aim to get a closer perspective of every sector and not only cybersecurity.

The Ransomware Task Force will synthesize a clear framework of actionable solutions. It will assess existing solutions at varying levels, identify the gaps in solution application, and create a roadmap of clear objectives and actionable guidelines for high-level decision-makers. To achieve the goals of the final roadmap, the RTF will share their expertise through papers and catalogs and engage stakeholders across industries to implement vetted solutions.

Partners of the RTF

The founding members of the Ransomware Task Force include some known names like:

  • Aspen Digital
  • Citrix
  • The Cyber Threat Alliance
  • Cybereason
  • The CyberPeace Institute
  • The Cybersecurity Coalition
  • The Global Cyber Alliance
  • McAfee
  • Microsoft
  • Rapid7
  • Resilience
  • SecurityScorecard
  • Shadowserver Foundation
  • Stratigos Security
  • Team Cymru
  • Third Way
  • UT Austin Stauss Center
  • Venable LLP

The official Ransomware Task Force website, with information on the membership plans and leadership roles, will be launched in the first half of January 2021.