Home Blog Page 183

Middle East Employee Security Training is Essential Amid Remote Working

Infosec-Middle-East

Across the Middle East, the COVID-19 pandemic is causing Middle East organizations to rapidly enable remote working for their knowledge workers. As these trends toward remote work or mixed environments become the “New Normal,” there are major cybersecurity implications. Employees are often the weakest link in cybersecurity. What happens now that they are working at home?

By Dr. Moataz Bin Ali, Vice President, Trend Micro Middle East & North Africa

While many Middle East employees have become more aware about the importance of cybersecurity, they are often lacking on the practical deployment – and CISOs need to develop personalized strategies.

Head in the Clouds – How big of a cloud security nightmare are you?

As part of Trend Micro’s Head in the Clouds survey, we interviewed 13,200 remote workers across 27 countries, including 502 remote working knowledge workers in the United Arab Emirates (UAE) and 501 in Saudi Arabia about their attitudes towards corporate cybersecurity and IT policies.

First, the good news: Among two of the largest markets in the Middle East, more than four fifths of remote workers in Saudi Arabia (86%) and the UAE (82%) say they are more conscious of their organisation’s cybersecurity policies since lockdown began in March. Among respondents, 88% in both the UAE and Saudi Arabia say that they take the instructions from their IT teams seriously.

However, many remote workers in the Middle East are continuing to break their organizations’ cybersecurity policies due to limited understanding or resource constraints.

One of the biggest but also most frequent mistakes that employees are making is accessing non-work applications on a corporate device – whether personal email, social media, or entertainment streaming.

The majority of employees admit to using non-work apps on a corporate device – including 58% in the UAE and 59% in Saudi Arabia. Respondents gave numerous reasons – including giving a work-related reason, trying out the latest apps, and thinking that it’s acceptable because the IT team hasn’t yelled at them yet.

Nearly half of respondents – including 42% in the UAE and 42% in Saudi Arabia – have said they uploaded corporate data to non-work apps. While some of these uploads may seem fairly routine, such as transferring files through a third-party service or using a third party chat platform, the security risks can be immense.

Just as much of a concern are the employees who are using their work laptops for personal browsing (40% in the UAE, 37% in Saudi Arabia). While the top results – search engines, personal email, and news – may seem fairly harmless, employees may not fully understand the risks that they are posing to corporate data,

Furthermore, about one-third of employees in the region also say that they access corporate data from a personal device (36% in the UAE, 34% in Saudi Arabia). In our always-on work culture, employees may face burdens to reply quickly from whichever device that they are using. But these devices may not be fully secure in terms of separate passwords, virtual private networks (VPNs), or two-factor authentication.

COVID-19 Threats Present New Challenges

As the COVID-19 coronavirus continues to spread, the topic is being used in many malicious campaigns — including email spam, business email compromise (BEC), malware, ransomware, and malicious domains. Fraud activity is still on the rise as communities remain in and are starting to emerge from quarantine.

In the countries that comprise the Gulf Cooperation Council (GCC), during H1 2020, Trend Micro recorded 163,774 COVID-related threats: 36,312 email spam attacks; 127,415 URL attacks, and 47 malware threats detected. The UAE led the GCC with 138,584 COVID-19 attacks, including 13,229 email spam attacks, 125,330 URL attacks, and 7 malware threats detected. Similarly, Saudi Arabia was not far behind with 8,509 attacks in H1 2020– including 7,970 email spam attacks, 514 URL attacks, and 25 malware threats detected.

As employees across the GCC and the Middle East continue to adapt to new methods of working, they should also be wary of cybercriminals using popular online tools, sharing software, and file attachments in their scams. Unverified mobile apps tracking COVID-19 can also present major risks.

Tailoring Cybersecurity Programs to Meet the Middle East’s Needs

When it comes to cybersecurity, not everyone has the same habits and attitudes towards risk. As a result, we’ve worked with leading cyber-psychologists to identify four typical key character types. Rather than take a one-size-fits-all approach, Middle East organizations should tailor their cybersecurity training and risk management to these character types.

  • Fearful – Anxious about doing something wrong or exposing themselves or their organization to risk, highly accountable for their own behaviour, not always aware of what cyber risks are out there or how to manage them, may deploy risk avoidance strategies at the cost of productivity.
  • Conscientious – Well-versed in understanding cybersecurity risks, always takes proactive steps to avoid or manage risk, highly accountable for their own behaviour, and mindful of their role in protecting the organization.
  • Ignorant – Distinct lack of cybersecurity awareness, absence of accountability for their own behaviour, careless and regularly takes risks, and does not understand the significance of their actions as they relate to cybersecurity.
  • Daredevil – Careless and lacks any sort of diligence around cybersecurity, has no regard or accountability for their own behaviour, reckless and has a perceived superiority that the rules do not apply to them, and believes that infosecurity responsibility lies elsewhere within their organization.

What are the practical steps that Middle East organizations can take in their cybersecurity readiness?

In addition to delivering a more personalized approach to cybersecurity training sessions, we are also recommending that organizations take a multilayered protection approach to protect all fronts. Middle East organizations need to prevent users from accessing malicious domains that could deliver malware.

For example, Trend Micro’s connected threat defense enables organizations to deploy security solutions at all touchpoints in an IT system – endpoints, hybrid cloud and networks. Trend Micro solutions can detect and block malware, malicious domains, and spear phishing emails; find unknown malware using machine learning; thwart spam and email attacks; and use AI to identify email attacks.

Ultimately, remote working only works if there is a high degree of trust between managers and their teams.

As lockdown measures continue to loosen across the Middle East, organizations and their employees will have to re-earn trust if they are to continue benefiting from the work from home environment.

About the Author

Dr. Moataz BinaliAs Vice President for Trend Micro Middle East and North Africa (MENA), Dr. Moataz Binali is responsible for spearheading the company’s strategy across the region, and advancing its position as a leader in cybersecurity that is passionate to make the world safe for exchanging digital information. A significant part of Dr. Binali’s role is to oversee Trend Micro’s efforts in enhancing the cybersecurity posture amongst governments and enterprises, contributing to the digital economy of MENA. Prior to joining Trend Micro, he held pivotal roles on regional level in global technology organizations such as SAP, IBM, and Microsoft.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

Researchers at Barracuda, a provider of cloud-enabled security solutions, has warned users about threat actors who create accounts with legitimate email services and use them to launch business email compromise (BEC) attacks. The researchers identified 6,170 malicious accounts that use Gmail, AOL, and other email service providers and were responsible for more than 100,000 BEC attacks on nearly 6,600 organizations since the beginning of 2020.

Image Source: Barracuda

The number of organizations attacked by a malicious email account ranged from one to a single mass scale attack that impacted 256 organizations and the number of email attacks sent by a malicious account ranged from one to over 600 emails, with the average being only 19.

Malicious Email Accounts

According to the researchers, malicious email accounts were responsible for 45% of all BEC attacks detected since April 1, 2020. Cybercriminals targeted several enterprises with multiple attacks from the same email accounts with specially crafted messages and URLs. Usually, attackers do not use their malicious accounts for a long period of time. Nearly 29% of malicious accounts were used for only a 24-hour period.

Cybercriminals design BEC attacks to bypass email gateways which is the reason why they only use each malicious account in a small number of attacks to avoid detection.

“While most malicious accounts are used by attackers for a short period of time, some cybercriminals used these accounts to launch attacks for over year. It is not unusual for cybercriminals to return and re-use an email address in attacks after a long break,” researchers said.

 

Image Source: Barracuda

Attackers Prefer Gmail

Hackers prefer Gmail for their malicious accounts as it is easily-accessible, free, easy to register, and is able to pass through email security filters. Gmail accounted for 59% of all email domains used by cybercriminals. Yahoo! was the second most popular one, with 6% of all observed malicious account attacks.

Image Source: Barracuda

“By nature, business email compromise is a highly targeted attack. After an initial research period, cybercriminals will impersonate an employee or trusted partner in an email attack. Usually, email is used first to establish contact and trust. Attackers will expect replies to their BEC attacks. Therefore, these attacks are usually very low volume and highly personalized to ensure a higher chance of reply,” researchers added.

How to Protect against Malicious Accounts

  • Barracuda researchers concluded that identifying accounts used by attackers is not always easy. Threat actors use the technique of spoofing, wherein they pretend to be someone else in an attempt to gain illegitimate advantage. However, organizations can implement the following measures to avoid BEC attacks:Leveraging artificial intelligence to identify unusual senders, requests, and other communications will help detect BEC attacks and other fraud.
  • Working with a vendor that can share this type of threat intelligence between different organizations in real time will allow for a greater level of protection.
  • Train your users to recognize targeted phishing attacks. User training should always be part in your security posture. Make sure your employees know how to recognize messages that come from outside of your organization and are aware of the latest tactics used by cybercriminals.

 

“Unauthorized Third-Party Access Took Place” : Mitsubishi

Mitsubishi network breach

Mitsubishi Heavy Industries (MHI Group) has confirmed a third-party unauthorized network access to its systems located in the Nagoya region of Japan. The network breach was observed on May 21, by its IT team when an unauthorized external communication was detected on a Group server located in Nagoya. As per reports from the MHI Group, no confidential personal or business data was compromised in this network breach.

 Key Highlights 

  • MHI Group confirmed that its network system in Nagoya, Japan, was accessed by an unauthorized third-party.
  • The hack took place in the form of social engineering through social media misuse.
  • At the time of the incident, there was no preventive protocol to restrict connection of a company mobile computer to an external network, this led to a successful social engineering compromise.
  • As per the MHI Group’s internal investigation, no confidential personal or business data was compromised in this network breach and there was no reason to worry for its business affiliates.

How the Investigation Unfolded

Upon discovery of the unauthorized access, the IT team instantaneously launched an internal investigation to find and curb further damages. In a day’s time, they were able to identify the source of the hack and the affected stakeholders by analyzing the Nagoya region’s unauthorized data communications. The affected systems were immediately blocked from the network to stop the spread.

The MHI Group has operations across various critical projects related to power systems, aircraft, defense, and space. Thus, they store a lot of confidential and highly sensitive data which, if compromised, would have resulted in a major setback to the technology giant.

Mitsubishi network breach

Cause of the Hack

The company in its announcement attributed this incident to being a social engineering attack carried out in the form of social media misuse. According to a detailed analysis, an MHI Group employee connected to an external network while working from home on April 29. Instead of using a secured MHI in-house network, the employee used a social networking service (SNS) to connect. It was here that he unknowingly downloaded a virus-infected file from a third-party, which infected the employee’s company mobile computer. Further, on May 7, when the employee joined back and connected on the in-house MHI Group network, the virus entered into its internal network.

Within the next 10 days, it began spreading to the other systems on the MHIs in-house network and started exfiltrating data in the form of encrypted packets. On carefully decoding the encrypted data packets, it was found that the leaked information consisted mainly of employees’ personal data (names and email addresses) using the MHI Group network. Additionally, other information including server logs, communication packets, server setting information, and IT-related information of the Nagoya region network was also leaked.

The Way Forward

The investigation precisely pointed to the cause and spread of this network breach. At the time of the incident, there was no preventive protocol or measures to restrict the connection of a company mobile computer to an external network, which led to a successful social engineering compromise. Thus, going forward whenever an employee wants to connect a company’s computer to an external network, it can be only done through an in-house virtual private network (VPN) connection.

Similarly, while investigating the cause of the spread, the IT team found out that “privileged local accounts of several servers within the affected area used the identical password.” Hence, it is believed that these passwords were reused to log in to the other systems for spreading the infection. Thus, the IT team has now changed all the passwords of privileged local accounts so that no two remain the same.

Mitsubishi Heavy Industries has already informed all the affected stakeholders and are keeping them updated about the network breach investigation proceedings. Meanwhile, they are also strengthening and improving their internal monitoring systems to avoid similar incidents in the future.

“Ghostwriter” Uses Fabricated News as an Attack Vector

ProxyShell Vulnerabilities

Security experts from FireEye discovered a fake news campaign spreading false stories, quotes, and other documents related to the North Atlantic Treaty Organization (NATO).  The campaign is targeted at people in Lithuania, Poland, and Latvia.

The disinformation campaign, dubbed as “Ghostwriter” has been active since 2017, wherein attackers compromised real news websites to post anti-U.S. and COVID-19-themed  falsified narratives. In addition, the attackers also mixed black SEO, Google Sites, and spam pages to trick the victims into clicking malicious URLs. While it is unknown who is behind this campaign, FireEye researchers stated that the campaign is aligned with Russian security interests.

“Many, though not all of the incidents we suspect to be part of the Ghostwriter campaign, appear to have leveraged website compromises or spoofed email accounts to disseminate fabricated content, including falsified news articles, quotes, correspondence and other documents designed to appear as coming from military officials and political figures in the target countries,” FireEye researchers said in a report.

Disinformation Campaign

The Ghostwriter operators have been using compromised websites and spoofed email accounts to distribute fake content, including fabricated correspondence from military officials. “For example, a quote falsely attributed to the commander of the NATO eFP Battle Group was used to push a narrative that Canadian soldiers stationed in Latvia had been diagnosed with COVID-19, stating: “Yes, 21 soldiers have tested positive for the virus. We have taken the necessary security measures, but not everyone has the same immunity. All necessary measures are being taken. The soldiers are isolated,” the report said.

In another case, the hackers posted a fake letter pretending to be from NATO Secretary General Jens Stoltenberg, carrying news about Atlantic partnership planning to withdraw from Lithuania in response to the COVID-19 pandemic.

The attackers exploited the compromised content management systems (CMS) of multiple news agencies and replaced original articles with fake news.  “Multiple indicators suggest that at least 14 suspected Ghostwriter personas have published articles promoting narratives corresponding with at least 15 suspected Ghostwriter operations since 2017. We have observed at least six of these personas leveraged in multiple Ghostwriter operations. Many claim to be locals, journalists, or editors of the target countries in biographies they have listed on sites to which they contribute content,” the researchers added.

Identifying fake news has become a challenge for users and organizations. And unfortunately, there is no proper method, as of now, to stop the spread of fake news. However, implementation of appropriate legal regulations may curb threat actors from spreading fake news, while at the same time, readers also should be vigilant to identify/report such stories.

 

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Information security provider CynergisTek and network detection and response company Awake Security joined hands to help protect health care providers from cyberthreats. The California-based firms are jointly developing an online threat assessment program that combines human expertise in digital forensics, incident response and threat intelligence. The program will help health care organizations to identify attacker activities and provide forensics across network systems to enable autonomous responses.

The new partnership combines Awake Security’s network detection and response technology with CynergisTek’s security platform to offer cybersecurity services to CynergisTek’s network health care providers. With this, hospitals will be able to  track every digital asset in their network, whether on-premises or from remote users working in the cloud, while identifying high-risk incidents and compromised entities without any middlemen or manual configuration.

CynergisTek and Awake Security stated that they are assembling resources in networking, machine learning, data science, cybersecurity, privacy, and compliance to help health care organizations get a complete view and understanding of their potential attack surface — including every user, medical device, and application on the network.

Ben Denkers, CynergisTek SVP of security and privacy services, said the alliance was made after the global pandemic changed the health care sector’s working practices. “As America’s hospitals scrambled to respond to the pandemic, the entire threat landscape and the associated attack surface completely changed, placing America’s hospitals squarely in the crosshairs for adversarial activity. New vulnerabilities from telemedicine combined with an increased network footprint due to work-from-home employees, and we have a perfect storm for increased cyberattacks. This partnership allows us to identify adversarial activity including reconnaissance in its early stages allowing organizations to re-baseline their security posture as they return to normal operations,” Denkers added.

Sensitive healthcare data is extremely valuable to hackers, and we know they aren’t sitting on the sidelines during the pandemic, but are in fact attacking both hospitals and pharmaceutical companies during this volatile time 

 

–  Rahul Kashyap, CEO of Awake Security

Health Care Devices at Risk

Most health care organizations in the U.S. are running their medical devices on outdated operating systems, leaving them vulnerable to cyberattacks. According to a research from Atlas VPN, 83% of healthcare providers in the U.S. are running on outdated software.  Out of the 1.2 million IoT devices used in thousands of health care organizations across the U.S., 56% of devices were still running on the Windows 7 operating system, for which Microsoft discontinued support in January 2020.

 

“Future of workspace will significantly differ from what it was before the pandemic”

Vishal Salvi is Senior Vice President, Chief Information Security Officer and Head of the Cyber Security Practice at Infosys. He is responsible for the overall information and cybersecurity strategy and its implementation across Infosys Group. Salvi is additionally responsible for the Cyber Security Business Delivery, driving security strategy, delivery, business, and operations enabling enterprise security and improving overall security posture.

In a video interview with Augustin Kurian from CISO MAG, Salvi spoke about cybersecurity during the COVID-19 pandemic, how the organization should channelize its cybersecurity resources into several verticals.


Here’s an edited excerpt from the transcript of the interview:

As soon as the COVID-19 pandemic was announced, several industry leaders were apprehensive about security with WFH format. It was a big task and something that the companies weren’t sure of, as they were not aware of how dynamic the changes would be. From that perspective, how has the transition been from that period and what are the alternatives if you just cannot work from the office but still must maintain high security?

I think the transition has been smooth for us at Infosys. We were planning it well in advance in terms of looking at how the pandemic was unfolding. And we were planning for a scenario where we would eventually look at a complete lockdown. If you look at organizations the size of Infosys, it is a massive workforce. Some of our development centers (DC) have more than 40,000 employees in them. So, it was important that we had to plan well in advance and then it was all about execution.

The power of Infosys is that all the teams came other, whether it is our leadership team, our business continuity management team, our technology team, our information security team, our delivery teams, our DC heads. As a result of that, just before the lockdown, 80% of our employees were working from home. So, to answer your question, I don’t think we could have done any better than what we did. I think in many ways we were ahead of the leaders in the industry when it came to that. We made sure that people working from home are enabled and that all the approvals that were required from customers in terms of obligations and contractual requirements were also in place before a massive change happened.

As soon as the pandemic occurred, you said every industry had a void, and “every industry is now a hunting ground for cybercriminals.” And there are a lot of cases when it comes to data security, where many times industries do not know what their critical data is. So, how do you think we can combat it?

If you see cybersecurity as a topic, it has been very important for organizations for a couple of years now and every year you are seeing a different type of attack coming in, the frequency and the impact of the breaches are only growing. So, it should come as no surprise to us that when the whole world is growing through a situation where we are testing the home networks infrastructure and different models of connectivity, it is quite natural to expect that there is going to be an avalanche of phishing attacks using COVID as a theme.

If you look at all the publicly discoursed attacks which have happened in the past three months, you will also see that the frequency of the number of ransomware attacks, or malware related attacks has gone up pretty significantly. Now all of this is requiring us to (a) be aware of what is happening and (b) take necessary steps to respond to that. Because as the threat landscape changes, one also needs to change the strategy on how you are going to defend your organization.

In many organizations, cybersecurity is an opportunity, and if it is driven strategically then it can become a big potent weapon for you, for your business. So, my message is that this is something that you should all be cognizant of and we should defiantly take note of how the threat landscape as evolved. You have to, therefore, recalibrate your approach and your strategy for combating it.


If you observe the anatomy of most attacks, they are directed towards exploiting vulnerabilities, for which patches have always been available, which is incumbent on most organizations. My message to the industry is very sharp: You must get your fundamentals and basics right and should not compromise on this.


How far has Infosys or clients gone with leveraging AI and ML to curb attacks when every employee was working from home?

I think overall there is a heightened interest by the threat actors in the issue of ransomware in terms of economics. There are gangs which have started taking ownership and accountability of some of the incidents that have happened. There is some clear dynamics on how that whole activity is playing out.

I think we can see the aftermath and that is where, fundamentally, IT hygiene comes in. But it is also a high-end problem to solve, and the reason is because as you grow and become a large organization, you start getting the visibility of your IT infrastructure, and the threat surface becomes extremely hard. And after you get the visibility, you have to also make sure that every time you are able to patch and deliver the regular updates, operating systems and applications–and software keeps on becoming obsolete–the rate of obsolescence is far higher in the security and software world as compared to any other system that you can think of.

If you observe the anatomy of most attacks, they are directed towards exploiting vulnerabilities, for which patches have always been available, which is incumbent on most organizations. My message to the industry is very sharp: You must get your fundamentals and basics right and should not compromise on this. We are seeing a high degree of incidents and impacts due to the increasing contact of malware/ransomware with the systems. Based on our research and publicly known attacks, we have witnessed over 111 ransomware attacks in 2020.

The reality of cybersecurity systems and software today is that we cannot survive or deliver value without artificial intelligence (AI) and machine learning (ML). Most of the security solutions we have been using for the past decade have always had ML embedded into it as a feature,  well before it was well-known as a concept. Nearly 92% of the world’s emails are spam. The fact that the whole security world is blocking that is because it is done by intelligent software and not human beings.

When we look at threat intelligence or normalization, there is a lot of AI and ML involved to work effectively. Cybersecurity is one industry that has truly embedded AI and ML in the way it delivers value.


We are in an “in-between phase,” which is basically between the post-COVID and pre-vaccine era. It is just like implementing proper patches and segmentation in cybersecurity, which is equivalent to physical/social distancing today. We have been applying these strategies all throughout. We will continue to adopt this throughout this pandemic until we have a vaccine.


A lot of industries can’t afford to have CISOs. If a company cannot afford a CISO, what should be the benchmark that they should follow? How can they be instrumental in using their security team and their existing resources?

There are a few areas to focus on. Firstly, I do not think that the CISOs are coming into the limelight or that their importance has grown. It is not about the CISOs; it is all about securing the enterprise. A CISO is only an incidental character whose role is to protect your enterprise. We should not give too much importance to the CISOs; it is the whole team and the ecosystem that drives the implementation.

Secondly, cybersecurity has always been a mainstream issue for years now. For the last two to three years, it has prominently been on the board agenda. COVID-19 is not driving the change, it is merely validating the fact that it is an important topic. It has just highlighted the fact that cybersecurity is important.

Thirdly, when it comes to the affordability of any organization to hire a CISO or otherwise, it depends. It is for the organization to decide what is more important for them. I always say that cybersecurity is a very strategic problem for an organization. If they look at it strategically, one can make it a differentiator for them. For instance, I was a banking CISO for many years. A lot of products in banking can only be successful because of security. If they remove security even for a fraction of five minutes, there would be mayhem in terms of incidents and breaches that can happen. So, security plays a strong enabler to allow banks to work with confidence. It allows them to open their reach and access to a broader set of customers. Security can play a strategic and enabling role for any organization.

Augustin Kurian is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news features on cybersecurity trends.

Need Based Evaluation of Cloud Services in the Wake of COVID-19

Cloud Forensics

For many organizations, particularly those that may be considered legacy, or older existing enterprises, the recent COVID-19 pandemic may be pushing them to further progress into the realm of cloud services. With the global population asked to quarantine or shelter-in-place during the pandemic spread of 2020, many businesses that were able to function with their workforce remotely had no choice but to do so. Having information systems available with true remote access capabilities was a must. For those organizations who had already moved to a cloud-based model, they found themselves in a far better situation than those firms who still had traditional server-based or “legacy” applications still in use. In a poll from ScienceLogic and Forrester, 86% of more than 200 IT professionals across a variety of business and government entities, still use at least one legacy tool with regard to infrastructure and application monitoring. This leaves a tremendous opportunity for cloud providers and may demonstrate that the movement for many enterprises to a true remote operation of critical applications during the COVID-19 pandemic may have been a bumpy one, and continue to be difficult. It is even possible that enterprises are still struggling to deal with having legacy applications used in critical functions. A legacy application can be defined as one architected in a traditional model requiring on premise hardware and software implementations. In comparison, a modern platform, based on the cloud, would be of the service models: Software as a Service (SaaS); Platform as a Service (PaaS); Infrastructure as a Service (IaaS).

By Stanley Mierzwa, M.S., CISSP, Director and Lecturer, Center for Cybersecurity, Kean University 

This article will discuss how widespread legacy applications are still being used, and in what main sectors, along with possible reasons why cloud adoption may not be pursued. In addition, the article will cover resources that organizations can use to evaluate and analyze a cloud service or vendor to ensure they are appropriately implementing security safeguards to protect those moving to their services will be provided.

Background on Legacy Application Use

Many organizations that have been considered mature in both operation and business for many years, with continued evolvement and growth can contain systems and applications written for older hardware and software operating platforms. There may be a number of reasons for continuing to operate such legacy systems, including significant prior investment into these custom developed systems, and they would not be practical candidates for movement to the cloud. In a proceedings and technical report, researchers have estimated that between 180-200 billion lines of legacy code are in current use. With such a vast amount of intellectual property, there is a strong possibility that some of these applications will simply remain in a legacy model. In these cases, a cloud hybrid deployment model might be valuable. In a hybrid approach, a mix of an on-premise solution and equipment can be integrated with a cloud-based private or public platform. In such a design, integrating the legacy custom solution that has a large amount of investment and intellectual property capital could possibly be leveraged.

A survey conducted by O’Reilly of 590 practitioners, managers, and CxOs from around the world resulted in several key findings related to companies moving to the native cloud. These included:

  • 27% of survey respondents whose organizations have not moved to native cloud have no plans to do so.
  • 32% of survey respondents not having moved to cloud native infrastructure, were asked why they haven’t, and the main reasons were: 1) Lack of skills 2) Company culture 3) Migrating from monolith architecture.

Industries that have moved into cloud native environments, be they either new, early, or sophisticated  users, were led by the software industry, finance &  banking and consulting and professional services. The industries with the lowest percentage of cloud native experience were government, telecom, retail/e-commerce and health care.

In a July-August 2019 cloud migrations trends survey provided by CISO MAG, when participants were asked how far their organizations have gone with migrations to the cloud, over 25% said they were assessing their migration strategy and just under 20% said they were not migrating to the cloud at all. One of the most critical factors for deciding on a cloud service provider from the survey was ensuring that compliance requirements are met. In the same CISO MAG survey, another key cloud challenge reported was having the ability to detect and respond to security incidents in the cloud.

Although there may be hesitations to immediately move all applications to the cloud, there will continue to be a yearning to move them for several reasons. These will include a greater ability to access them via true broad network access, as considered an essential element via the NIST model of cloud computing. In addition, since these legacy applications may have been developed with older coding languages, such as COBOL, there is the risk of a skills shortage in such tools as time evolves. Finally, even if an entire legacy system cannot be migrated to the cloud in one full motion, there may be opportunities to move modules over, one at a time, and thus introduce less reliance on the legacy applications.  For example, a legacy organization may have a combination of systems utilized in their enterprise resource and financial operations.  As part of this configuration, there can exist older or legacy modules that integrate into the general ledger system, these could be in the form of a timesheet, expense reporting or inventory module.  Perhaps the legacy enterprise general ledger system cannot yet be migrated to the cloud, but considering if any of the integrated modules can be moved to the cloud, with connection to the legacy headend system would be a step in the direction of a gradual move to the cloud. In this strategy, one could analyze which legacy applications are most used by the general population of the organization to create a priority module migration plan.  In this scenario, the legacy organization can begin their journey to the cloud by using some of the resources freely available to help analyze Cloud Service Providers, as detailed in the next section.

Several Resources for Analyzing Cloud Service Providers

The Cloud Security Alliance (CSA) Trust Assurance and Risk (STAR) is an overarching security program that provides a varied set of tools to help potential cloud customers, cloud providers, auditors and anyone who wishes to pursue cloud solutions, with pertinent background information to aid decision-making.

From the customer’s perspective, one could search for a particular cloud solution in the CSA Star Registry and if the company submitted an entry, the Consensus Assessments Initiative Questionnaire (CAIQ) could be reviewed. The CAIQ is a list of over 300 standardized questions answered by the cloud vendor and transparently provide you their responses. This could be very helpful if there is a particular cloud requirement that your company must meet because you could find a potential answer ahead of contacting the cloud provider. The CAIQ questions are pulled from the Cloud Control Matrix, a spreadsheet that breaks up the questions into 16 distinct categories or domains ranging from application and interface security to datacenter security and mobile security.

With the CSA Star Registry, cloud service providers are able to validate their solutions and offer transparency of their approaches to handling the many Cloud Control Matrix domain areas. Additionally, for those who audit or consult in the cloud sphere, they will have the opportunity to review the specific cloud security approaches and become more familiar with solutions prior to embarking on audits or solution design.

  • The STAR program provides for three different levels of registry entries.
    • CSA STAR Level 1 – Cloud providers offer a self-assessment, which is to be done annually.
    • CSA STAR Level 2 – In addition to the cloud provider’s self-assessment, a rigorous third-party independent assessment is performed.
    • CSA STAR Level 3 – Includes a continuous fully automated process that ensures security controls are monitored and validated at all times. This is most rigorous and highly challenging level and results in an issuing certificate.

Other evaluation tools of cloud computing services are available from the United States National Institute of Standards and Technology (NIST) via the Special Publication (SP) 500-322, which is based on the NIST SP 800-145. The NIST SP 500-322 includes a simple worksheet that one can utilize to help determine if a service being provided is actually classified as a cloud service. This worksheet can be helpful to small and medium businesses that may not necessarily have an Information Technology department or specialist available to help guide the firm with such a determination. In addition, for these small to medium businesses, a helpful list of marketing terms often used or profiled with cloud services, is provided in the SP 500-322.

Additionally, the U.S. Federal Risk and Authorization Management Program (FedRAMP), is a program that potential cloud service providers and customers can utilize to both demonstrate security standings as well as compare themselves to other vendors. One of the goals of the FedRAMP program is to help organizations accelerate the adoption of cloud solutions through assessments, authorizations, and consistent security standards. A potential cloud customer can review the FedRAMP Marketplace, where one can review already authorized and approved cloud solutions and vendors, or perhaps those that are in the evaluation process. FedRAMP utilizes the NIST 800-53 baseline security controls as well as additional elements that are cloud computing unique. Similar to the Cloud Security Alliance CAIQ, the FedRAMP process provides a workbook grid of controls that are mapped to the NIST 800-53 controls and what a potential vendor will be required to provide, depending on whether a model of low, moderate, or high security controls are required. An example of the general family of low security controls one will find include:

  • Access Control
  • Awareness and Training
  • Configuration Management
  • Contingency Planning
  • Identification and Authentication
  • Incident Response
  • Media Protection
  • Physical and Environmental Protection
  • Personnel Security
  • System and Information Integrity

If an organization is looking to get started with the cloud and requires a more general cloud adoption roadmap, one can be found at the non-profit Cloud Industry Forum. Their Cloud Adoption Roadmap includes guidance and resources breaking up the movement into the cloud into 5 sections and 21 individual and unique stages. The stages include items such as learning about cloud essentials, creation of a strategy, assessing your current and destination environments, evaluating service providers, and reviewing data governance and security.

Conclusion

The recent global pandemic forced many organizations to switch to remote computing operations and it is likely that some end users experienced difficulties in accessing their critical information systems. Although the cloud computing as a paradigm movement has been in existence for almost two decades, there are still many opportunities for organizations to make the switch for the purpose of better access, efficiencies, and effectiveness gains. In the O’Reilly survey, almost 30% of respondents said they expect to adopt a cloud infrastructure in the next two years. This finding can point these respondents and organizations to using tools already available to begin to evaluate the credibility and security of certain cloud service providers, and possibly to the Cloud Security Alliance and NIST available resources. At a minimum, using available outfits to start the process of doing “homework” and gaining valuable knowledge about the cloud, can provide a consumer greater situational awareness and confidence.

There are myriad ways to evaluate potential cloud solutions with respect to security, but rather than start from scratch, it would be beneficial to start with a ready-made assessment strategy. The Cloud Security Alliances’ set of tools can be approached to begin your journey into discovering potential cloud options to replace or at a minimum, augment, your legacy applications.

Kean University Background

Kean University enrolls almost 16,000 students and offers more than 50 undergraduate majors and 60-plus graduate options, with four campuses in New Jersey and the only public university in America to have a campus in China. U.S. News & World Report has recently ranked Kean University among the top universities in the northern United States for helping economically disadvantaged students enroll and graduate within six years. Kean is ranked 41st for social mobility out of 170 universities in the region.

References
  1. Greig, Jonathan; Just 12% of Companies have fully Transitioned to Modern IT Tools; Digital Transformation – TechRepublic, September 11, 2019
  2. Forrester; Prevalence of Legacy Tools Paralyze Enterprises’ Ability to Innovate; Forrester Opportunity Snapshot: A Custom Study Commissioned by ScienceLogic, September 2019
  3. Ganesan, Sivagnana; Chithralekha, T.; A Survey on Survey Migration of Legacy Systems; ACM – ICIA-16: Proceedings of the International Conference of Informatics and Analytics; August 2016
  4. Magoulas, Roger; McDonald, Nikki; How Companies Adopt and Apply a Cloud Native Infrastructure; O’Reilly; April 30, 2019
  5. Batlajery, Belfrit, et al.; Industrial perception of legacy software system and their modernization; Technical Report Series UU-CS-2014-004; 2014
  6. Khadka, Ravi, et al.; How do professionals perceive legacy systems and software modernization; Proceedings of the 36th International Conference on Software Engineering; ACM pp 36-47; 2014
  7. CISO MAG; Cloud Security Power List, Showcasing the Powerhouses in Cybersecurity; Volume 3, Issue 7, July-August 2019

About the Author

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean UniversityStanley Mierzwa is the Director, Center for Cybersecurity at Kean University in the U.S. He also lectures at Kean University in the U.S. on Cybersecurity Risk Management, Cyber Policy and Foundations of Cybersecurity. Mierzwa is a peer reviewer for the Online Journal of Public Health Informatics journal, a member of the FBI Infragard, IEEE, ISC(2) and a board member of the global pharmacy education nonprofit, Vennue Foundation. He holds a M.S. in Management Information Systems from New Jersey Institute of Technology and a B.S. Electrical Engineering Technology from Fairleigh Dickinson University, and is also a Certified Information Systems Security Professional (CISSP).

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Why Organizations Push Vulnerable Code in Their Application Security Program

cybersecurity pressure

According to a research report from Synopsys, 48% of organizations deliberately push vulnerable code in their application security programs due to time pressures. As a result, 60% of respondents stated that their production applications were exploited by OWASP top-10 vulnerabilities in the past 12 months.

The report entitled “Modern Application Development Security” highlights the extent to which security teams understand modern development and deployment practices, and where security controls are required to lower the risk.

Pushing Vulnerable Codes

The research stated that certain organizations push vulnerable codes knowingly and with a thorough understanding of the risks that they are taking.

Image Source: Synopsys

“Application security requires a constant triage of potential risks, involving prioritization decisions that allow development teams to mitigate risk while still meeting key deadlines for delivery. Note that vulnerabilities discovered too late in the cycle often don’t get mitigated, reinforcing the importance of shifting application security as far left as possible to leave enough runway to resolve critical issues in time for delivery,” the report said.

Image Source: Synopsys

Other insights from the study include:

  • Most organizations believe their application security program is effective, though many still push vulnerable applications into production. 69% of survey respondents rate the efficacy of their current program as an 8 or higher on a scale of 0 to 10 (with 10 being the most effective). However, as nearly half of the organizations consciously push vulnerable code on a regular basis, most have experienced production application exploits involving OWASP Top 10 vulnerabilities in the past 12 months.
  • DevOps integration is a critical element for improvement. More than one-quarter of respondents say that their current application security tools add friction and slow down development cycles, while 23% identify poor integration with development/DevOps tools as a common challenge. Additionally, 26% of respondents note a difficulty with or lack of integration between different application security vendor tools as a common application security challenge.
  • Developers play an important role in application security, but they lack the skills and training. Nearly one-third (29%) of respondents express that developers within their organization lack the knowledge to mitigate issues identified by their current application security tools. Furthermore only 17% say that their developers utilize just-in-time training available within their security tools and just 29% are required to participate in training at least once per quarter.
  • Organizations are planning to increase application security spending. More than half (51%) of respondents report plans for significant increases in application security spending over the next 12 months. 44% plan to target application security investments toward cloud.
  • AppSec tool proliferation is driving many organizations to invest in consolidation. Many organizations are struggling to integrate and manage the number of tools in place, often leading to a reduction in the effectiveness of their security program while also directing an inordinate amount of resources to manage them. With 70% utilizing more than ten tools, complexity becomes a key issue, and as a result, more than a third are focusing investments on consolidation.

Patrick Carey, Director of Product Marketing for the Synopsys Software Integrity Group, said, “The key insights identified within this study underscore the fact that organizations need to address application security holistically throughout the development life cycle. Of the organizations consciously pushing vulnerable code into production, 45% do so because the vulnerabilities identified were discovered too late in the cycle to resolve them in time. This reaffirms the importance of shifting security left in the development process, enabling development teams with ongoing training as well as tooling solutions that complement their current processes so that they may code securely without negatively impacting their velocity.”

 

Meet Lindy Cameron! Soon to be the First Woman CEO of NCSC

new CEO of NCSC

The World is taking note and lauding the efforts of female leaders at the helm in countries like New Zealand, Denmark, Finland, Germany, Iceland, and Taiwan in their fight against the ongoing pandemic. Reports suggest that women are managing the crisis better than their male counterparts because certain traits like resilience, pragmatism, benevolence, trust in intellectual suggestions, informed decision making, mutual aid, humility, and humbleness come naturally to them. Thus, when the National Cyber Security Centre (NCSC) announced the change of guard at the CEO’s office and decided to pass the baton to Lindy Cameron, a hardened cybersecurity veteran with 20+ years of experience, the world was not shocked, instead, it welcomed the notion with open arms.

Meet Lindy Cameron

  • Cameron graduated from the Ministry of Defence’s Royal College of Defence Studies in 2011.
  • Earlier, she also completed a BA in Modern History from Oxford (1991-94) and acquired a Master’s in Law and Diplomacy from the Fletcher School at Tufts University in the U.S. (1996-98).
  • She started her career in the private sector with McKinsey.
  • Later, she worked as the Head of the Department of International Development’s (DFID’s) country offices in Iraq (2004-05) and Afghanistan (2006-07).
  • She joined the Cabinet Office in 2008 as Deputy Director, Africa, Trade, Development & International Institutions.
  • She is currently serving as the Director-General at the Northern Ireland office.

With such an impressive resume to back her nomination, it looked like a no brainer for not getting the job. Cameron, who is currently the second chair in the Northern Ireland office, shall join the NCSC – a public-facing division of GCHQ and primary technical authority on cybersecurity – in London on August 31, 2020. She will however get a complete handover and walkthrough for the next two months about her daily curriculum from her predecessor Ciaran Martin, the current CEO and founding member of the NCSC, since its establishment in October 2016. Only after the handover period is completed in October, will Cameron take complete control over the CEO’s office.

Ciaran Martin’s Retirement Plan

Ciaran Martin was originally appointed as the GCHQ board member for cybersecurity in December 2013. He played a vital role in setting up the NCSC in 2016, and thus was awarded the CEO’s office for his immaculate knowledge in this domain. After four years in office, he is now all set to step down on August 31, 2020, and slip into the robe a professor. Oxford University has formally announced that “Ciaran Martin will be taking up an appointment as a Professor of Practice in Public Management, based at the Blavatnik School of Government. His new appointment at the University of Oxford – which has been made in full accordance with the Business Appointment Rules for Civil Servants – will commence on September 1, 2020.”

Real or Imposter? Everything You Need to Know About “Homoglyph” Phishing

Domain Name Security

Security experts from Malwarebytes discovered cybercriminals using a combination fake domains with favicons to launch “Homoglyph Attacks.” The attackers used Homoglyph attack — also known as homograph attack, script spoofing, or homograph domain name spoofing — in phishing scams, credit card skimming attacks, and on several domain names to load the Inter skimming kit inside of a favicon, a file containing one or more small icons associated with a particular website.

What is a Homoglyph Attack?

A Homoglyph attack is a deception technique that uses homoglyphs or homographs,  in which an attacker abuses the similarities of character scripts to create phony domains of existing brands to trick users into clicking.  A homoglyph is one of two or more characters or glyphs with shapes that appear identical or very similar. Hence, the name of the attack.

The idea is simple and consists of using characters that look the same in order to dupe users. Sometimes the characters are from a different language set or simply capitalizing the letter ‘i’ to make it appear like a lower case ‘l’. Examples of such are the Latin small letter O (U+006F) and the Digit zero (U+0030). Hypothetically, one might register bl00mberg.com or g00gle.com and get away with it.

 

– Malwarebytes said in a report

Image Source: Malwarebytes

Most of the users read the above domain as “cigarpage” when in fact it is “cigarpaqe”. Malwarebytes confirmed that the correct website is indeed cigarpage.com and cigarpaqe.com is the imposter.

“The legitimate site was hacked and injected with an innocuous piece of code referencing an icon file. It plays an important role in loading a copycat favicon from the fake site, using the same URI path in order to keep it as authentic as possible. The reason why the attackers are loading this favicon from a different location becomes obvious as we examine it more closely. While the legitimate file is small and typical, the one loaded from the homoglyph domain contains a large piece of JavaScript,” the report stated.

Image Source: Malwarebytes

Connection with Magecart Group

The researchers stated that they found several domains, including the malicious infrastructure (51.83.209.11), which are registered using the same homoglyph technique. Here are the original domain names on the left, and their homoglyph version on the right:

cigarpage.com – cigarpaqe.com
fieldsupply.com – fleldsupply.com
wingsupply.com – winqsupply.com

“A fourth domain stands out from the rest: zoplm.com. This is also an homoglyph for zopim.com, but that domain has a history. It was previously associated with Magecart Group 8 (RiskIQ)/CoffeMokko (Group-IB) and was recently registered again after several months of inactivity,” the report added.

Image Source: Malwarebytes

Malwarebytes reported the issue to the victim site and clarified that the malicious code had been removed.

Protection Against Homograph Attacks

Malwarebytes suggested users to be vigilant when browsing online and maintain cybersecurity hygiene, including:

  • Regularly updating your browser (They may be your first line of defense against homograph attacks).
  • Confirming that the legitimate site you are on has an EVC (Extended Validation Certificate).
  • Avoid clicking links from emails, chat messages, and other publicly available content, most especially social media sites, without ensuring that the visible link is indeed the true destination.