Home Blog Page 142

Hanna Andersson to Pay $400K to Settle CCPA-related Class-Action Lawsuit

California Consumer Privacy Act, Hanna Andersson to Pay $400K to Settle CCPA-related Class-Action Lawsuit

Hanna Andersson, U.S.-based kids wear retailer, has agreed to pay $400,000 to settle a data breach lawsuit related to the California Consumer Privacy Act (CCPA). The class-action lawsuit, which is the first monetary settlement under CCPA, was filed in the U.S. District Court for the Northern District of California in February 2020. The lawsuit claimed that Hanna Andersson and its third-party vendor Salesforce violated the CCPA by exposing customers’ personally identifiable information (PII) in a 2019 data breach.

As per the settlement, more than 200,000 U.S. customers, who made purchases from the Hanna Andersson online store from September 16 to November 11, 2019, will receive $500 to $5,000 compensation.

How Hanna Andersson got Hacked

According to a statement from Hanna Andersson, unknown threat actors hacked Hanna’s retail website during the holiday season of December 2019. The attackers stole the credit card details, including customer name, payment card number, CVV code, expiration date — along with billing and shipping addresses of its customers from the checkout and payment page of the online portal. The hackers also sold credit card details of the customers on the dark web.

The cyber forensic team’s investigation confirmed that Hanna Andersson’s third-party eCommerce platform, Salesforce Commerce Cloud, was infected with malware that may have scraped information entered by customers into the platform during the purchase process.

In addition to the settlement, Hanna Andersson also agreed to enhance its security posture to prevent future security incidents by conducting a risk assessment of its data assets; enabling multi-factor authentication; hiring a new director of cybersecurity; conducting phishing and penetration testing; and deploying additional intrusion detection, prevention, and monitoring applications.

“Plaintiffs strongly believe the settlement is fair, reasonable, and adequate and that the court should grant it preliminary approval and notice distributed to class members. The settlement provides quick relief for class members, including compensation for the alleged unauthorized dissemination of their PII,” said the attorneys for the class-action plaintiffs in the settlement agreement.

Third-Party Risk: Reactive to Predictive

Endpoint Security

Third-party risk management: the process, technology, and people whose goal is to lower the risk created by third-parties (vendors).  Surveys of a wide range of companies, across multiple industries, routinely find that less than 50% have a program to manage this risk. Those that do perform it, do it minimally: part of a compliance exercise, designed to keep the regulators and oversight bodies satisfied.  After COVID-19 sent many onshore and offshore resources to work from home and cyber-threats exploded over 800%, this lack of a serious approach to third party risk (when compared to how firms perform their own internal security controls) became apparent in the corresponding explosion of third party breaches and security incidents.

By Gregory C. Rasner, CISSP, CIPM, CCNA, ITIL

Many firms rely on point-in-time assessments.  These are typically classified as remote or onsite assessments.  Remote assessments are questionnaires sent to a vendor with relevant questions that are reviewed for any items that do not meet your firm’s security requirements.  Remote assessments are a great way to perform intake security reviews for new vendors or new services.  The weakness of remote questionnaires is they typically cannot share sensitive documents or data because of their restrictive classification.  For example, viewing a third-party’s access management policy documentation will not typically be allowed.

Onsite assessments are performed at the vendor’s location.  These allow for a more transparent sharing of data because anything sensitive is not leaving the room where the assessment is taking place.  In addition, being onsite allows a more direct conversation with the vendor about their security and any potential gaps.  The weakness of onsite assessments is they take more time to plan, execute, and complete.

Both types of assessments, remote and onsite, are valuable and have excellent use-cases.  First, understand the limitations of each type: a remote assessment is akin to asking your children if their room is clean.  If going to their room is physically challenging, getting their feedback on clean status is acceptable; however, that definition of clean is likely not the same as your definition of clean. The onsite is similar to going to your kids’ room to validate that their room is actually clean.  As most of us can attest, the results of the two types of assessments are different.  Remote assessments are effective on time-sensitive, higher volume processes as found on new vendor security evaluations.  The results need to be taken with a lower level of confidence, given the vendor is attesting to their security controls.  Onsite assessments will find security gaps that provide a very high confidence level, but due to their higher resource cost, should be done on vendors with a risk level that warrants that extra cost.

If your organization isn’t performing these types of security evaluations, begin by reviewing third parties at the highest risk.  This can be done by the number of records and/or a connection to your network.  Send out a remote assessment questionnaire to get a level-set; follow this activity up with a review of those remote assessments with a look at those with the most concerning responses for an onsite assessment.  In this time of inability to travel and gather, leverage collaboration tools to do these virtually, until they can be performed safely at the vendor location.

Cybersecurity Third-Party Risk

Many companies focus on all the third-party risk domains, not cybersecurity risk.  There is a financial risk, reputational risk, country risk, and many others.  However, cybersecurity risk is most often the largest financial and reputational risk to your firm.  Countless public breaches that are associated with large, well-known companies were the result of a cybersecurity breach at their third party.  While there are other domains for review with third-party risk management, it is cybersecurity risk that involves the most frequent and public breaches.  Focusing on the cybersecurity domain requires the third-party risk team has information security expertise.

Third-party risk management organizations do not often have this level of experience or expertise.  Many companies compensate for this by creating a checklist for the assessor to follow.  There are two major problems with this approach: first, without that expertise, it is very unlikely the assessor will recognize any inconsistency or illogical answer from a vendor; second, the checklist approach does not allow for follow-ups that provide a more complete picture of the security at the vendor.

Continuous Monitoring

As mentioned in the first section, point-in-time security evaluations are common and necessary.  However, there is a need to perform something more ongoing and active; this is called Continuous Monitoring.  It is designed to fill in the gap between the point-in-time assessments discussed above.  This activity has typically been reliant solely on vendor reputation software: the tool sends an alert of a bad score on a particular third party, and the third-party risk team member will engage with the vendor about the alert. This has resulted in a lot of fatigue among third-parties and often is a conversation that does not change the risk.  There is a need to change this approach and can be accomplished by correlating the alerts from vendor reputational software with internal due diligence and the nature of the threat in the alert.

An example of how this would be an alert from a vendor reputation software is seen for open port detected on FTP at a vendor who maintains ten-thousand confidential customer records.  Diving into the existing due diligence or risk acceptance at the firm is the next step; this example finds a risk acceptance performed on this vendor for inadequate Data Loss Prevention (DLP), providing more context about the alert.  All this data combined and provided to the vendor is more complete about the alert combined with known gaps.  Now the conversation with the third party is about the alert in context with their risk acceptance and a high number of protected records for your customers.

Moving to Predictive

Almost every third-party risk management organization is reactive: reliant on a breach or security incident notification from a vendor.  As due diligence efforts, point-in-time assessments, and Continuous Monitoring, produce results and data, it becomes possible to change into predictive.  Use the data to change to a predictive model. Much like vulnerability management, this approach allows CISOs and their teams to focus on what is the highest risk, not the totality of all vendors.

The vendor due diligence results, risk acceptances, contract deviations, threat intelligence engines, vendor reputation tools, and other data sources are all inputs to this updated approach.  The front-end can be a Business Intelligence or Analytics engine, but the algorithm is the key.  For example, confidence levels for the data are part of the consideration: due diligence findings from an onsite assessment have higher confidence than remote.  An open risk acceptance has high confidence, but the vendor reputation tool is lower.  The higher the confidence of the data, these have a higher weight in the algorithm.

In a dashboard view, the simplest form for this predictive model is a stoplight approach: red, yellow, green.  Vendors who have no open findings, no open risk acceptances, no alerts would be shown as green. Vendors with low to medium risk findings and/or risk acceptances could be yellow. Those with higher risk findings, risk acceptance, and an alert show up as red.  At a high level, this allows staff to focus on the highest risk for engagement. A further example is a vendor who is yellow, with an open finding for not allowing admin access of laptops by standard users; there are ten thousand confidential customer records at their site, and there is an alert that shows botnets coming from their network that are known browser add-ins with key-logging capabilities: this bumps them up in the dashboard to red. Now the conversation with the third party is proactive: going to them with this level of detail in a system that provides alerting changes the timing of the conversation.

Timing is Everything

The number of firms that need to perform third party risk still needs more adherents; however, due to COVID-19 and the increased cyberthreats, there is an obvious need to change the approach to include and improve Continuous Monitoring.  Firms that get to this level of due diligence on their third-parties can then begin to benefit from a predictive, near-real-time engagement with vendors on a risk-based approach. Getting ahead of the risk leads to lowering the risk.


About the Author

Gregory C. RasnerGregory Rasner leads Corporate Cyber Security Third-Party Risk at Truist Financial Corp. Prior, he held cybersecurity and information technology leadership roles in technology, biotech, and finance. Teaching part-time at local community colleges and volunteering time for veterans’ causes are his passions. He is proud of his service in the U.S. Marines and is also a father of five children along with a beautiful, smart wife who also is a cybersecurity professional. He can be reached at [email protected]

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related story: The Role of Third-Party Management in Cybersecurity

FireEye Acquires Respond Software to Boost its Cybersecurity Products

FireEye Acquires Respond Software

Cybersecurity services provider FireEye announced the acquisition of security investigation automation firm Respond Software in a $186 million deal. FireEye caters to enterprises and helps businesses thwart cyberattacks. With the addition of Respond Software, FireEye can now deliver its eXtended Detection and Response (XDR) capabilities to a broad set of customers.

As per the acquisition deal, the Respond Software XDR engine will be integrated into FireEye’s Mandiant Advantage, bringing cloud-native AI together with Mandiant intelligence and expertise to automate the investigation of alerts. The acquisition also offers a combination of Respond Software’s XDR capabilities with deep, real-time knowledge of attacker tools and techniques to enable customers to more quickly identify the weak signals of an attack, understand their adversary, and respond quickly to stop an attack.

“Customers rely on our XDR engine to investigate more alerts, at a deeper level, for far less cost than existing processes and tools. Respond’s product dramatically reduces time spent investigating false positives as it connects the dots among siloed, multi-vendor security controls in an easy-to-deploy cloud-based package. This results in more coverage, faster resolution of incidents, and ultimately, less risk at lower cost.” said Mike Armistead, Chief Executive Officer, Respond Software.

FireEye’s Strategic Investment

FireEye also announced that it has raised $400 million strategic investment in a funding round led by Blackstone Tactical Opportunities. The company stated that the new proceeds will be used to support the company’s vision to create the industry’s leading intelligence-led cybersecurity platform and services company.

Earlier, FireEye made its private bug bounty program public, with a focus on business applications and corporate infrastructure security. The company stated the bug hunting event is open to all security researchers and ethical hackers who are willing to find vulnerabilities in FireEye’s services and domains including fireeye.com, fireeye.market.com, verodin.com, isightpartners.com, cloudvisory.com, fireeyecloud.com, and mandiant.com. Click to read more…

Chinese E-Commerce Scammers Trade Customer PII and Payment Card Data on Dark Web

e-skimming attacks , Chinese e-commerce scammers

A Chinese e-commerce cyber-espionage campaign is suspected to be illicitly collecting payment information of unwitting consumers via hundreds of fraudulent e-commerce websites that appear to be genuine, the latest research from Gemini Advisory revealed. The researchers stated that multiple banks in the U.S. and Europe experienced a spike in online frauds that are linked to China-based e-commerce sites. Over 200 of the 600 online scam sites are said to be linked to the Chinese acquiring bank, Jilin Jiutai Rural Commercial Bank.

Shoppers’ Data Trading on Dark Web

Gemini’s researchers stated that cybercriminals created various online stores to advertise their fake products, luring customers with unbelievable offers. Once the user clicks a product link, it redirects to a different page asking the customers to enter personal information. The Chinese hacking group, identified by Gemini, likely recorded more than $500,000 profits in the past six months by selling compromised customers’ financial data and PII on the dark web markets.

“The China-based e-commerce fraud groups, including the group identified by Gemini, follow the same pattern except they operate on a large scale with hundreds of sites. Once they have their sites up and running, some of these groups work to expand their sites’ exposure by building a parallel presence on Facebook,” the researchers said.

Related story: Online Shopping or Scam? FBI Alerts Consumers About Fraudulent E-Commerce Schemes

“Based on the common link and an analysis of the sites’ past activity, Gemini analysts assess with moderate confidence that these China-based domains were not infected through Magecart attacks, but were actually malicious sites themselves that stole payment card data from unwitting shoppers, and then sold that data across various dark web marketplaces,” researchers added.

With Black Friday around the corner, online shoppers need to be vigilant about scamming sites luring them into discounts and fake e-commerce schemes.

Did a Cyberattack Cause Power Outage in India’s Financial Capital?

Mumbai power outage cyberattack

On October 12, Mumbai was crippled with a power outage that caused chaos and disturbance in the daily business.

It was considered to be a technical failure at a power sub-station; however, the latest reports suggest this could well be an effect of a cyberattack on the power grid.

Mumbai, the financial capital of India, is known to have an almost uninterrupted power supply. The city has more power consumption than demand but is able to cope with the load, throughout the year. Yet, Mumbaikars faced their worst nightmare on October 12, which caused chaos and disturbance in daily business as it was the first working day of the week. Even the stock market and local trains came to a halt for some time.

Soon the local electricity board relayed messages across social media platforms and official websites stating that the massive outage was due to cascaded tripping at a substation of state-run transmission company MSETCL. This meant the entire Mumbai Metropolitan Region (MMR) that includes Mumbai, Navi Mumbai, and Thane were cut-off completely.

Theoretically, getting the power grid up at full capacity from zero watts was not possible as it would have blown off the circuit lines. Thus, the restoration was done in a phased manner and was complete only by late afternoon. A city that boasts of being unstoppable came to a grinding halt.

The October incident was swept under the rug as a one-off occurrence; however, a committee was set up to investigate and avert similar grid failures in the future. After a month-long probe, the latest reports suggest this was not just a technical failure but could well be an effect of a targeted cyberattack on the power grid.

Why is it being called a Cyberattack?

As per a local daily Mumbai Mirror, multiple suspicious logins into the servers connected to the power grid’s sub-station have been logged from accounts operating from Singapore and other south Asian countries. A senior minister from the state cabinet said that this was not a “small issue” as the number of DoS and IP Hijacking attacks have already seen a sharp rise in recent months.

A report suggested that the growing geopolitical tension with its neighbor China, resulted in more than 40,000 such attacks on critical Industrial Control Systems (ICS) and banking systems alone in the month of June.

Not the First Time

This is not the first time that a national power grid has been targeted by a cyberattack. In 2016, Ukraine’s national electric grid was also targeted, which the investigators claimed was carried out by Russian state-sponsored threat actors. A malware, dubbed as “Crash Override” or “Industroyer” (which was also used in the first known act of a Cyberwar – the Stuxnet attack), was supposedly used to trigger this attack. Experts said that the malware used in the Ukrainian attack was sophisticated enough to cause power outages of a few days in portions of the national grid.

Related News:

Cyber Security Threat to National Power Grids Reported

A similar instance was recorded in India last year, a few thousand kilometers down south from Mumbai in the Kundankulam Nuclear Power Plant (KKNPP). The cyberattack on the internal systems of the nuclear power plant reportedly compromised a certain set of data that could be used in future attacks. However, the attackers could not penetrate the entire network as the core network was isolated from the rest. This was an important lesson to learn as opposed to what happened in Stuxnet, where the entire network came down in one go.

How to Protect Critical Infrastructure

So, amid the rising attacks on ICS, here is a list of things that can help prevent or at least control damages that take place from these targeted attacks:

  • Create air-gapped or isolated networks. Although this is not full proof, it helps in controlling the spread.
  • Maintain privileged access control. Design a role-based access control (RBAC) to all the systems and grant limited access as per the employee’s roles, because the majority of times it is the humans who falter and not the systems.
  • Reduce the attack surface by locking down all the unused ports and services. Allow only real-time connectivity to external networks which will make it easier to monitor traffic.
  • Ensure patch management. Keep all your systems updated and patched with the latest updates to defer the latest attack vectors.
About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 

How Cybercriminals Abuse AI and ML for Launching Sophisticated Cyberattacks

Cybercriminals Abuse AI and ML for Launching Sophisticated Cyberattacks

Threat actors can misuse advanced technologies like Artificial Intelligence (AI) and Machine Learning (ML) to launch sophisticated cyberattacks and invent new kinds of malicious operations. A joint report from the United Nations Interregional Crime and Justice Research Institute (UNICRI), Europol, and cybersecurity firm Trend Micro highlighted the current and predicted cyberthreats leveraging AI technology. It is predicted that AI systems are being developed to enhance the effectiveness of malware and disrupt anti-malware and facial recognition systems.

The report revealed that hackers could use AI to support:

  • Convincing social engineering attacks at scale
  • Document-scraping malware to make attacks more efficient
  • Evasion of image recognition and voice biometrics
  • Ransomware attacks, through intelligent targeting and evasion
  • Data pollution, by identifying blind spots in detection rules

Deepfake: A Popular AI-based Attack Vector

According to the report, threat actors are mostly using AI to launch Deepfake attacks. Deepfakes are specially crafted images and videos using AI and ML technologies, to look like legitimate content. Hackers often use Deepfakes to cause confusion and spread disinformation campaigns, mostly political.

“One of the more popular abuses of AI are Deepfakes, which involve the use of AI techniques to craft or manipulate audio and visual content for these to appear authentic. Because of the wide use of the internet and social media, Deepfakes can reach millions of individuals in different parts of the world at unprecedented speeds,” the report stated. 

The trio also listed several recommendations for organizations to follow:

  • Harness the potential of AI technology as a crime-fighting tool to future-proof the cybersecurity industry and policing.
  • Continue research to stimulate the development of defensive technology.
  • Promote and develop secure AI design frameworks.
  • De-escalate politically loaded rhetoric on the use of AI for cybersecurity purposes.
  • Leverage public-private partnerships and establish multidisciplinary expert groups.

“AI promises the world greater efficiency, automation and autonomy. At a time where the public is getting increasingly concerned about the possible misuse of AI, we have to be transparent about the threats, but also look into the potential benefits from AI technology. This report will help us not only to anticipate possible malicious uses and abuses of AI, but also to prevent and mitigate those threats proactively. This is how we can unlock the potential AI holds and benefit from the positive use of AI systems,” said Edvardas Šileris, Head of Europol’s Cybercrime Centre.

“As AI applications start to make a major real-world impact, it’s becoming clear that this will be a fundamental technology for our future. However, just as the benefits to society of AI are very real, so is the threat of malicious use,” said Irakli Beridze, Head of the Centre for AI and Robotics at UNICRI.

Level-Up! Five Security Precautions for Online Gamers

battle of galaxy game

The Internet is not fair. From harmful scam emails to cybercriminals trying to break into your systems, the online space is full of uncertainty. When talking about online threats, cyberattacks have become more common in the online gaming industry. Attackers often target online video games and gamers by compromising their accounts and launching attacks. According to a research, the gaming industry suffered more than 10 billion credential stuffing attacks, 3,000 unique DDoS attacks, and 152 million web application attacks between 2018 and 2020.

By Rudra Srinivas, Feature Writer, CISO MAG

As online games become more vulnerable to attacks, it is imperative for gamers to level up their security to defend against various cyberthreats. Here we tell you how:

1. Avoid Public Internet

Use only a secure internet connection and avoid public internet/Wi-Fi networks while playing online. Even when accessing your home network, use a VPN for additional security. Cybercriminals often track/compromise users in the same public Wi-Fi network by exploiting flaws in WPA2 encryption.

2. Visit, Download, and Play from Genuine Sources

Recently, Google delisted 21 malicious Android apps disguised as gaming apps containing the HiddenAds Trojan. Hackers often hide malware on popular game download links. Always check the legitimacy of the website before playing online and look for only official repositories to download.

3. Always Remember to Log Out

Open network gaming platforms ask for login details before playing their games. As these gaming accounts hold users’ sensitive information, it is recommended to log-out from the accounts after your sessions. Also, remember to never save your username and password on the browser you’re using, as anyone can have instant access to your accounts.

 4. Keep Your System Up to Date

Cybercriminals are getting more sophisticated by the day and exploiting known vulnerabilities.  Strengthen your systems’ security defenses by updating with regular patches, security upgrades, and firewall fixes. Software updates often include critical patches to security loopholes. This way you are ensuring the information on your system is protected.

5. Be Vigilant About the Data You Share

Most gamers join online forums for gaming partners, cheat codes, and to explore new games/game techniques. But cybercriminals often target these communities, pretending to be gamers, to illicitly obtain users’ credentials. It is better to limit the information you share on these forums to avoid unnecessary data misuse.

Ensure that you follow these precautions for a secure gaming experience. It is better to be cautious right now before things went wrong.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 

Several CISOs and CIOs are Not Aware That VA Chatbots Need Protection

VA Chatbots

Chaitanya Hiremath is the CEO of San Francisco-based AI firm, Scanta Inc. He is the first Indian-origin entrepreneur to win the Shark Tank Showcase and the prestigious Draper University ‘Summer Pitch’ in 2018 in San Francisco. In 2019, he was listed in the ‘Top 25 People in Tech’ list by Entrepreneur Magazine, after also being chosen for the Forbes ‘30 Under 30’ list, in the Startup category. He was named as the “Youth Icon” for 2019 by Fame India. He is a dynamic, results-oriented leader with a strong track record in cutting-edge technologies at fast-paced organizations. His expertise in artificial intelligence, machine learning, and cybersecurity has helped him build a worldwide team of innovators at Scanta. His latest challenge has been to develop market-leading security technology to protect (Virtual Assistant) VA Chatbots.

In an exclusive interview with Augustin Kurian from CISO MAG, Chaitanya talks about his journey, the future of chatbots, and security. 

What was the problem with ML that you have set out to fix? How often are VA (virtual assisted) chatbots being targeted in cyberattacks? What kinds of damages can an unprotected ML-powered VA system cause to an organization?

Interestingly enough I think the basic thesis here is that you are working on the larger vision of protecting machine learning systems, and when you are looking at how you use machine learning systems as a use case, the first risk which has a lot of adoption was virtual assistant chatbots. That’s because machine learning is a vast ocean of use cases. So, when we hoard it in VA chatbots, there are different vulnerabilities that arise from it.

I was working on a larger thesis of what makes a machine learning system vulnerable. It’s just a simple process if you look at it, I can give you an example of Tesla self-driving cars. Tesla self-driving cars are able to classify a “STOP” sign or a “GREEN” light and make decisions based on the interpretations. What happened last year was shocking, which also compelled us to begin looking into this space. It led to people losing their lives. In this scenario, one of Tesla’s self-driving cars was operating in autopilot mode and did not interpret the “STOP” sign, which led to a car crash and killed the driver. Everybody looked at this problem saying that this is a one in a million case, something like this happens if a machine learning system is not able to detect the signs.

But actually, it was much deeper than that. Somebody had attacked the system externally, not internally. We would normally interpret the Stop sign with red-colored letters “S.T.O.P,” right? However, for a machine learning system, Stop, signs are based on patterns. Similarly, in Tesla’s case, somebody put a tape on top of the Stop sign. Hence, the system classified the Stop sign as a green light and the car went on driving autonomously and failed to recognize the sign. If you look at this, this has mass repercussions. If somebody can misclassify a decision by just adding tape, it is like scratching the tip of the iceberg of what’s really with machine learning systems. This is a problem in ML systems and particularly with VA Chatbots.

Well, now that we have discussed threats vectors and this is a new niche, we can assume VA has been occupying a special niche in the global IoT ecosystem. They have been playing a major part in home automation as well. Do you think a cyberattack on VA can have a domino effect at multiple vectors across the entire line-up?

Yes, and it is simple, specifically with the IoT devices. They don’t have any security embedded in them. They lack layers of protection and they don’t have any authentication or verification. These systems are particularly vulnerable because they all work in a network. If I’m attacking an IoT system somewhere around San Francisco, I can get on a system anywhere. It’s based on the network effect. It is not only confined to somebody getting into the system but once somebody is in the system, there are thousands of ways in which it can impact. Just to give you an example about interacting and sharing confidential information, which people always do these days. If you have an app on top of Alexa or anything else, you can possibly extract that information out easily if it is left unprotected.

These are sophisticated mechanisms but they are more than possible.

There’s a massive demand for VA (virtual assistants) around the world, but one of the things that have caused many vulnerabilities is that organizations usually find it difficult to balance between the coolness of the VA/VR features and the security, often making security an afterthought. Do you agree that even when the world is so much aware of cybersecurity, a lot of makers of VA chatbots are considering security as an afterthought?

Interesting question! So, you are basically saying that people are focusing too much on the coolness factor rather than the security aspect. The issue is that you can make your chatbot or VA as cool as possible. It is subjective but at the same time even if it has all the trendy features it doesn’t matter because according to us nobody is focusing on security. At least the ones we have spoken to, and we have spoken to few Fortune 500 companies, but nobody has been protecting the chatbots at a level we are talking about and it’s very different to protect a chatbot through a firewall because these are not correlated things. Chatbots are vulnerable at the conversational level and not just at the HTTP level, and that is the difference that we are trying to drive here.

Irrespective of how you set up the security architecture or you think you have a completely safe system, the training data set, all in-house and not open source, it still doesn’t matter. It’s still possible for anybody to get into the system and try to extract information or at the backend manipulate it in such a way that it does activities that you are not aware of, or that are adversarial in nature.

Do you think attacks against VA chatbots is getting its due share of importance? Are CISOs considering attacks against chatbots as an emerging threat? How can CISOs be instrumental in averting this threat vector? What best practices should CISOs have in place?

I have spoken to at least 50 CISOs and CIOs, some from Fortune 500 companies. Apart from two or three CISOs/CIOs, none of them were aware of this threat vector at all. So, the first reaction to “the chatbot can be attacked” is “Oh My God! I didn’t really know that we have to protect this also now.” Well, you have to. If you are making sure that your data is protected and spending millions of dollars for smooth functioning, then it is your responsibility to make sure that nothing can be extracted from the chatbot as well. I mean it is as important, right? You cannot protect yourself at the data level or the public/private cloud or whatever you have set up; it expands to more than that.

If somebody can directly extract the information from the chatbot, then that’s an issue and I haven’t really seen many CIOs or CISOs being aware of this threat vector. So firstly, it’s about being aware even beyond chatbots. If you are using anything in ML, the data can be poisoned and one way to really look at this is to know that more than 80% of all chatbots are built on an open-source training data set or an open-source algorithm, and you need to make sure that if you are making anything on open source, then you don’t take that as faith value. There have been examples of back-door channels with malicious codes inside the algorithm, so make sure you are betting this to the best of your capabilities when you are taking anything from the open-source. And the last aspect, which is sort of my recommendation, is when you are setting up the architecture itself you can protect it in a certain way but again, on the chatbot side particularly, that is something that the critical aspect is to analyze to see what goes in and comes out of the chatbot.

One more question, about the knowledge of the vendor. How often do you think vendors realize the need for security updates of their devices’ firmware on a regular basis? Because that was something Amazon had to focus on after the discovery of the KRACK bug. How much of this entire role is on the vendor’s side?

Well, the fundamental aspect here is that you need to be aware that the problem exists and the biggest issue that we face particularly in machine learning is that you may come across a case like Delta Air Lines six months down the line. One of the aspects here is to ensure some sort of Q&A is constantly added in your chatbot. Looking at where are different edge cases falling short—and that’s something vendors need to be really proactively on when these kinds of solutions are pushed into the market—but again it’s sort of a black box machine learning where we are not actually been able to know what kind of result you are getting, where is the request coming from, where is the response going. It’s an automated process, which is a common industry practice that is something we see changing now. We are getting numerous requests when we explain this new threat vector to people, we get a response like, “Oh it is something we are also affected by, or how can we check this?” If you deep dive into what goes in and comes out of the chatbot, it will give you a lot of exposure to where you stand with your security protocols.

Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

Artificial Intelligence in Cybersecurity Operations

Artificial Intelligence, AI, neural, machine learning

The attack surface is rapidly expanding and continues to evolve at an unprecedented pace. Cyberattacks are becoming more sophisticated and are proliferating at lightning speed. There are innumerable and varying cyberthreats that need to be detected, prevented, and analyzed to accurately calculate their danger or risk. One of the biggest challenges is that cybercriminals, state-sponsored attackers, cyber terrorists, and hacktivists are now using Artificial Intelligence (AI) techniques to circumvent many controls, gain privileged access to an organization’s confidential data, and erase their traces to avoid detection. They use AI to automate and enhance cyberattacks and expand their attack-surface. Furthermore, AI is going through continuous advancements that can yield a new chain of cyberthreats.

By Muhammad Tariq Ahmed Khan, Head of Information Security Audit, Internal Audit Division, Arab National Bank, Riyadh

In response to this unprecedented challenge, organizations (private and public) are inclined to adopt AI-based solutions to deal with cybersecurity risks/threats and to fine-tune their security posture efficiently and effectively. While the cybersecurity outlook appears bleak, there is an immediate need to augment AI technology, with the help of Machine Learning (ML) and Deep Learning (DL), with today’s cybersecurity threats and attacks landscape. This is necessary to cope with the constant battle against cybercrime.

AI and Cybersecurity – Key Considerations

Here are some key points to be considered while augmenting AI technology with Cybersecurity operations.

Firstly, organizations should focus on building a well-thought-out and integrated strategy, rather than merely deploying an additional burden on the network in the guise of best of breed AI technology. It is vital to ascertain realistic security requirements and business expectations, in addition to risks and success criteria to measure the success of implementation for deploying AI into cybersecurity.

Secondly, the quality of data input is an integral part of employing AI. So, data should be consistent, complete, and compact. In addition, a complete and accurate inventory of all devices, users, applications, and infrastructure, with all types of access to information systems, along with the business criticality, should be established. Combine data from multiple sources and fold it together, so it becomes cohesive enough – and then feed it to ML.

ML, a subset of AI, is an approach to the science of AI. It provides computers the capability to learn through experience, without being explicitly programmed. Basically, the idea is to supervise a machine so it can learn, find patterns, solve problems, and predict outcomes based on various algorithms available in ML. As an example, existing signatures of malware can be used to train ML algorithms to discover any zero-day or unknown emerging malware.

Thirdly, sometimes the algorithms do not predict and learn the right things but something else. In addition to available algorithms in ML, organizations should consider developing customized AI-based use-cases to analyze patterns and learn from them, to prevent similar attacks, and respond to changing behavior, per the organizations’ risk appetite. For example, AI-based use-cases can be developed to learn from malicious activities and stop attacks, to analyze mobile endpoints, to enhance human analysis, to automate repetitive tasks, and to close zero-day vulnerabilities. With this, ML is expected to predict the right outcomes with a minimum of 70% accuracy.

Improving the Accuracy

To achieve 90% accuracy, Deep Learning (DL) comes into the picture. DL is a subset of ML, where machines are capable of unsupervised learning. In DL, the machine’s algorithms learn through their own algorithms to reach decisions in real-time, without human intervention. A large amount of data stored and processed by various hosts on the network is analyzed, and decisions are made using predictive reasoning. It can understand the relationship between multiple events and then provide automatic threat scoring for compromised hosts. For example, DL can be used to distinguish between normal and abnormal traffic for anomaly detection. So, it can only be achieved by understanding, defining, and integrating the entire infrastructure (e.g. the network, applications, databases, hosts, etc.) with the AI solution.

As DL algorithms have been developed based on neural networks and layers, they function as an independent brain. The key to success lies in adequately managing the architecture of this brain.

AI is a need of the hour as a substitute for human decision-making, and it uses scientific algorithms and evaluations to form a decision. It plays a significant role in cybersecurity and has many advantages. It can think like an attacker, and as a result, enhance the security posture of a specific area. It can almost eliminate human error from the process and works efficiently and effectively in cases where there is a large amount of traffic and human involvement is not possible.

Organizations should use the combinations of supervised and unsupervised learning to make the most of AI. The key to success will be choosing the appropriate input that can be processed by the algorithms for making decisions automatically.

No matter how powerful and expensive the AI technology is, achieving effectiveness is limited to only specified desired outcomes. We have yet to see a machine that can function and learn completely on its own.


About the Author

Muhammad Tariq Ahmed Khan is Head of Information Security Audit, Internal Audit Division, Arab National Bank, Riyadh. He has more than 21 years’ experience in the Banking industry, in areas such as IT, Information Security, and IT Audit. He has a solid understanding and application of Risk-Based Audit methodology, ISMS (ISO 27001), ISO 22301, NIST and COBIT, IT & Information Security regulatory compliance. To his credit, Khan also has sound technical knowledge in various IT platforms and IT project management – with experience in Disaster Recovery and Business Continuity Management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Google Set to Bring End-to-End Encryption in Android Messaging

PhantomLance Targets Android App Store to Spread Malware and Spyware, message encryption for Android

Google is finally ready to roll out end-to-end encryption (E2EE) in its latest RCS standard for Android messaging.

With this upgrade, Google has taken its user privacy offering a notch higher by shielding the content of the messages from everyone — including the law enforcement and Google itself.

RCS messaging has long been in talks as the able successor of SMS and MMS messaging, but it had a few shortcomings. However, Google is finally ready to overcome them by releasing end-to-end encryption (E2EE) in its latest RCS standard, which will be available for all Android Beta users soon.

Explaining the importance of end-to-end encryption, Google’s Product lead, Drew Rowny said, “End-to-end encryption ensures that no one, including Google and third parties, can read the content of your messages as they travel between your phone and the phone of the person you’re messaging.” It implies that no one will be able to snoop into your conversations.

Related News:

Google Ads Gear-up to Implement SCC Post EU-U.S. Privacy Shield Invalidation

As per the technical details mentioned in The Verge, the end-to-end encryption implementation is based on the Signal protocol, which is also used by WhatsApp. The Signal protocol is a cryptographic protocol that combines the Double Ratchet algorithm, prekeys, and a triple Elliptic-curve Diffie–Hellman (3-DH) handshake, and uses Curve25519, AES-256, and HMAC-SHA256 as primitives. It provides confidentiality, integrity, and authentication to the content exchanges between two users.

Talking about the usage, the end-to-end encryption in RCS can only be used for one-on-one chats where both users are using Android Messages and have received the applicable update. However, enabling end-to-end encryption for group chats is a problem for which Google is still finding a solution.

This feature is part of an upgrade from SMS to the RCS standard with additional features for images and videos. Many digital rights activists have welcomed Google’s move; however, few law enforcement agencies around the world think otherwise. They believe strong encryption may enable criminals to hide their tracks.

Both parties are right at their place; thus, it will be interesting to see how we can find some middle ground through this tussle.

Related News:

Google Chrome Introduces Improved Password & Phishing Protection