Home Blog Page 209

Optimizing Security for Your Business

business security - cloud

Just as in personal life, professional life can be filled with questions and pitfalls regarding security-related issues. While people can be tempted to cut costs and corners and hope for smooth sailing, unquestionably the best option is to plan. Cover your bases, both in terms of general security and in special cases related to your business, and better financial outcomes, as well as lower stress, will inevitably result.

In this article, we want to cover some of the most popular and most popularly ignored ways in which businesses can increase their security standards. While we will focus on digital security, other aspects also need to be considered. Only with all these components together, combined with consistent effort, will you truly be covered from the most unanticipated events that business life can throw at you.

General Daily Security

The most fundamental forms of security in business are going to the most regular. On a basic level, this means keeping all points of access secure and maintaining high levels of password strength. For optimal results here, you’ll want to adopt passwords that are at least 12 characters long. These do not have to be gibberish but ensure they aren’t related to the business itself, or pop-culture terms.

Another element of basic safety is making sure that your systems go into auto-lock after several minutes of inactivity. This combined with longer passwords can seem a nuisance, but it will also vastly mitigate the risk of compromised systems and data theft. This is especially important on any devices which have access to payment information such as credit card data.

The final part of consistent daily security should come from an emphasis on malware scans. These can be scheduled at the end of every day before a system shuts down, though extra attention should also be paid to active coverage running throughout the day. Some of the most popular anti-virus systems even have business versions available, which tend to be better suited than personal single-system versions.

"Password" (CC BY 2.0) by wuestenigel
Image source: “Password(CC BY 2.0) by wuestenigel

Backup Security

Once daily security is covered, you will also want to take into account the possibilities for massive system failure. This can occur as the result of a wide range of unforeseen consequences, such as fires, electrical surges, floods, and malicious unexpected attacks. The best way to combat these problems is to shore up recovery methods beforehand, through the proper application of cloud-backups and software.

Cloud backups can be an enormous boon because they can constantly run in the background, never requiring much more input from the workers of a business. By automatically updating data, any essential databases can then be redownloaded in the case of emergency, such as the loss of regular storage.

Cloud-friendly applications can operate in much the same way. By having online versions of programs available, a business can access regular operations even if the primary computer storage goes down or is wiped. These also come with a possible benefit of allowing access from mobile devices, which can help if workers need to make small adjustments on the go.

"Cloud Security - sky art" (CC BY-SA 2.0) by perspec_photo88
Image source: “Cloud Security – sky art(CC BY-SA 2.0) by perspec_photo88

Exterior Security

While these previous options cover most of the predictably unpredictable, it is also a good idea to consider the necessities which can arise through more individual business needs. Specifically, we would be remiss if we did not mention the constant and pressing need for professional insurance policies. These will have a high degree of variability depending on the business, though the overall idea remains constant.

Insurance importance here applies just as much for businesses involved in digital pursuits as physical ones. Take, for example, the realm of handyman insurance. This specialized insurance covers a business against potential issues such as sudden medical or property damage bills, with the flexibility for different policies and levels of coverage. Depending on your business, such insurance might also offer forms of digital coverage, so an investigation into these areas is a must.

Staying Vigilant

The most important binding aspects of all these options is the requirement that businesses stay active and aware. Small daily and weekly checks whenever necessary can make all the difference in spotting problems and addressing them before they get out of hand. Stay vigilant, and what will undoubtedly start off alienating and challenging will eventually become simple and second nature. In the long term, your business’s security and health will be all the better for it.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Ethical Hackers Earn US$100 Mn in Bounties on HackerOne Platform

Sardonic, BitMart

Popular security and hacking platform, HackerOne recently announced that it paid ethical hackers $100 million in bounties so far for finding and reporting security flaws in various devices and software via bug hunting programs.

According to Mårten Mickos, CEO of HackerOne, there are around 100 million security vulnerabilities still in the wild, by which cybercriminals can break into systems to steal data, install malware, disrupt vital operations, or distort facts. Mickos stated that HackerOne delivered around 170,000 valid vulnerability reports to its clients and averted more than ten thousand security breaches.

“Hacker-powered security has already made the world much more secure. And with three quarters of a million of ethical hackers signed up, we are making sure we have the capacity to keep finding vulns (vulnerbilities) and helping customers even as the volume of software keeps increasing at a tremendous rate. With a community that size, we represent the creative and inquisitive power of around 65 quadrillion neurons. There is no cybersecurity challenge that a large group of human brains acting towards a common goal cannot tackle,” Mickos added.

Image source: HackerOne

Some Notable Facts about HackerOne:

  • 84 new hackers sign up to the HackerOne platform every hour
  • Around $6,000 paid in bounties on the platform every hour
  • Nearly 214% year-over-year hacker-powered security growth in the federal government
  • Around 85.6% growth in total bounty payments, with a 17.5% increase since February when COVID-19 was declared a pandemic
  • 343% increase in signups over the past year on Hacker101 – HackerOne’s free online classes for aspiring hackers
  • 38% increase in average weekly new registrants for Hacker101 since February, when COVID-19 was declared a pandemic
  • Over 170,000 number of vulnerabilities hackers have uncovered in nearly 2,000 customer programs

HackerOne stated that it is planning to produce over 500 Chief Information Security Officers (CISOs) from its large team of ethical hackers in the next 15 years. It also predicted that white-hat hackers will earn around $1 billion in bug bounties within five years, protecting private and government entities from persistent threats.

 

Truecaller Denies Data Leak After 4.75 Mn Users’ Info Emerges on Darknet

Truecaller Denies Data Leak After 4.75 Mn Users’ Info Emerges on Darknet

Cybersecurity research firm Cyble reported that unknown hackers are selling personal information of 47.5 million Indian users of Truecaller, a caller-identification app, on darknet forums for $1,000. The leaked data included details like users’ phone number, name, gender, city, carrier, email ID, Facebook account, and telco details.

In its primary analysis report, Cyble stated that the users’ personal details were kept on dark web forums in a categorized format based on state, cities, and telecom carriers. It also found that the exposed data is from 2019.  Cyble said that such leaked data might impact users in India via spam, phishing scams, and identity theft attacks.

“We were sceptical, but considering we have a large number of subscribers and enterprises in India, we decided to go ahead with the validation stage. And soon we realized that we didn’t make a wrong decision,” Cyble researchers said.

On the flipside, Truecaller denied the data breach allegations claimed by Cyble. “We were informed about a similar sale of data in May 2019. What they have here is likely the same dataset as before. It’s easy for bad actors to compile multiple phone number databases and put a Truecaller stamp on it. By doing that, it lends some credibility to the data and makes it easier for them to sell,” Truecaller said in a media statement.

The Swedish caller identity app is popular among the Indian users. The app provides a set of features to smartphone users including call-blocking, flash-messaging, caller-identification, call-recording, and Chat & Voice services.

Vulnerabilities in Truecaller App

Earlier, researchers discovered a security flaw in the Truecaller app that could expose sensitive users’ data, location, and system information to attackers. The flaw came to light after an India-based security researcher Ehraz Ahmed reported the issue. In a video post, the researcher described how a malicious link can be injected as a profile URL to potentially target attacks on users clicking on the profile. According to Ahmed, the malicious script will get executed without user consent. “The flaw could allow attackers to mount serious attacks on target machines, although this was not the scope of the proof of concept and has been played down by the company,” Ahmed said in a statement.

 

Building Pro-Active Security Hygiene Helps in Preventing Ransomware Attacks: Microsoft

Building Pro-Active Security Hygiene Helps in Preventing Ransomware Attacks: Microsoft

Threat actors have reinvented their attack approaches during the ongoing COVID-19 outbreak. Several new cybersecurity scams and ransomware activities have risen during the pandemic. According to the Microsoft Threat Protection Intelligence Team, cybercriminals have been using the current situation to gain information from organizations to plan future attacks. The team said that they have observed multiple hacking groups activating dozens of ransomware deployments in the first two weeks of April 2020.

“These attacks can even be fatal, given their impact on aid organizations, medical billing companies, manufacturing, transport, government institutions and educational software providers. However, despite this global crisis, ransomware groups seem to give little regard to the critical services they impact,” Microsoft said in a post.

Vulnerable Systems Are First Targets

Microsoft’s Security Intelligence and Detection and Response team stated that attackers infiltrate target networks and then wait to monetize their attacks by deploying ransomware. To gain access to target networks, threat actors exploited internet-facing systems that had weaknesses such as a lack of multi-factor authentication (MFA). Hackers also preyed on older Windows platforms which were not updated, had weak passwords, or systems with specific existing vulnerabilities. Microsoft observed that hackers used the same techniques in all human-operated ransomware campaigns including initial access, credential theft, lateral movement, and persistence.

Microsoft recommends certain investigation procedures to prioritize if an organization is hit by a cyberattack, these include:

  • Investigate affected endpoints and credentials
  • Isolate compromised endpoints
  • Address internet-facing weaknesses
  • Inspect and rebuild devices with related malware infections

Building Pro-active Security Hygiene

As cybercriminals continue reinventing their attack approaches to compromise new targets, organizations are taking proactive measures to handle the risks.  Microsoft suggested some measures to make networks more resilient against evolving threats, these include:

  • Apply an Account Lockout Policy so that someone who attempts to use more than a few unsuccessful passwords logging onto the system will be blocked.
  • Ensure good perimeter security by patching exposed systems and applying mitigating factors, such as MFA or vendor-supplied mitigation guidance, for vulnerabilities.
  • Utilize host firewalls to limit lateral movement and prevent endpoints from communicating on TCP port 445 for SMBs. This can significantly disrupt malicious activities.
  • Turn on cloud-delivered protection for your antivirus product to cover rapidly evolving attacker tools and techniques. Cloud-based machine learning protections block a huge majority of new and unknown variants.
  • Follow standard security baselines guidance for all your software. A tool like Microsoft Secure Score can also assist in measuring your security posture and recommending actions for improvement, guidance, and control.
  • Turn on tamper protection features to prevent attackers from stopping security services.
  • Turn on attack surface reduction rules, including rules that can block ransomware activity.

“What we’ve learned from the increase in ransomware deployments in April is that attackers pay no attention to the real-world consequences of disruption in services that their attacks cause, even in this time of global crisis. Organizations shouldn’t expect hackers to be concerned about anything other than disruption and potential financial reward, regardless of the impact on people or society as a whole,” Microsoft added.

Organizations must be prepared with the latest preventive actions to protect themselves from evolving threats and safeguard their valuable information.

 

Five Key Cybersecurity Concerns Amid COVID-19

cybersecurity

The COVID-19 pandemic has disrupted global health, the economy, and social systems. From emptying office spaces to dispersing the workforce, corporates have yet ensured seamless delivery of services. However, remote work environment has also led to a surge in unseen threats in the digital space. Threat actors are prying on potential victims to deploy cyberattacks on home and public networks.

By Pooja Tikekar, Feature Writer at CISO MAG

Corporates are addressing several cybersecurity concerns to protect personal data and information systems. Some of the key concerns include:

1. Security of Remotely Located Devices

The drastic shift to remote working has led to a rise in the use of personal devices for business operations. Leaving sensitive data and work-related documents on unsecured devices could result in data leaks. According to a study from HiveIO, nearly 85% of organizations anticipate a larger remote workforce will threaten operations because of new risks, while 22% fear an increase in business costs to support remote staff. IT teams are undertaking security measures to protect computers from malware.

2. Weak Remote Access

Now that employees are working from home, security professionals need to ask: How many employees use company VPNs when working from home? According to a survey conducted by CISO MAG, only 70% of respondents stated that they were using company VPNs to securely log into the company network. Corporates need to encourage all employees to use VPNs for a secure connection, as communication through a home or public networks could pose a greater risk as they are carried over untrusted networks. It could also result in the exploitation of client and user credentials to collect sensitive data. It is essential for security teams to deploy secure multi-site remote access servers dispersed at various geographic locations.

3. Improving Incident Response and Cyber Hygiene

According to a study conducted by Barracuda Networks, almost half (46%) of global businesses have encountered at least one cybersecurity incident since shifting to a remote working model. Security teams are advising remote employees to maintain good cyber hygiene and asking them to keep their devices up-to-date, patched, and protected. Organizations need to ensure they have a best-in-class remote patch management solution to overcome a security breach. Implementing two-factor authentication (2FA) where possible will also go a long way in preventing data breaches.

4. Cyber Risk Mitigation

Phishing emails sent in the name of the World Health Organization (WHO) continue to be popular among hackers and cyber scammers. To mitigate cyber risks such as phishing campaigns, third-party apps, and malicious adverts, CERT-In has published an advisory urging security teams to stress the avoidance of clicking on links and attachments in email. IT administrators are also advised to monitor outgoing traffic to prevent cyber infections from occurring.

5. Amendment to Business Continuity Plans

Since employees started working from home, the Zoom videoconferencing app found itself millions of users. Unfortunately, its popularity led to increased cyber risks such as password theft. Cyble was the first cybersecurity firm to discover Zoom credentials being stolen and sold on the dark web. It found more than 500,000 Zoom accounts on hacker forums. To avoid the recurrence of such threats, organizations are now devising a holistic business continuity plan (BCP) and making amends to their standard operating procedures (SOPs) for work-from-home employees through a company-specific communication channel or other channels such as MS Teams, Google Meet, and Skype.

Conclusion

Considering all the above concerns, loss of a client or organizational data cannot be risked in the current uniquely challenging environment. It is a crucial time for organizations across all industries to be alert and address the adequacy of their cyber policies.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

75% Of Security Pros Say Remote Work Led to Changes in Financial Services Cyber Programs: Survey

75% Of Security Pros Say Remote Work Led to Changes in Financial Services Cyber Programs: Survey

An opinion poll from the Financial Services Information Sharing and Analysis Center (FS-ISAC) revealed that 75% of cybersecurity professionals in financial institutions across the globe made sudden changes to their firm’s cybersecurity programs to deal with remote working conditions.

The survey revealed that 11% of respondents said third-party risk concerns led to dramatic changes in their cyber programs. 46% reported their financial institution are likely to invest more in cybersecurity, post-pandemic. Digital banking tools were ready to securely handle a huge increase in volume as only 3% percent of respondents saw these tools driving significant program changes.

FS-ISAC is a non-profit organization responsible for cyber and physical threat intelligence analysis and sharing for the financial and banking institutions. Organizations across the globe leverage FS-ISAC’s intelligence platform, resiliency resources, and network of security experts to anticipate, mitigate, and respond to cyberthreats.

FS-ISAC polled 871 cybersecurity professionals from financial institutions from more than 50 countries, including the U.S., Canada, Brazil, U.K., India, and Singapore. The opinion poll evaluated which trends driven by the pandemic had the most impact on their cybersecurity programs.

Steve Silberstein, CEO of FS-ISAC, said, “The accelerated shift to remote work has fueled a rapid evolution of the cyber threat landscape. As the effects of this pandemic continue to unfold, CISOs and cybersecurity teams are constantly adapting their cybersecurity programs to meet a new reality that is everything but normal.”

Financial Organizations – Hackers Prime Target

A recent study from the cybersecurity firm Intsights revealed that the banking and financial sectors were hit with a constant stream of cyberattacks when compared to other sectors. According to the Intsights report titled, “Banking & Financial Services Cyber Threat Landscape”, around 25.7% of all malware attacks last year was targeted on banks and financial organizations. The study also exposed that the number of data breaches reported in Q1 2019 doubled to any of the quarters of 2018.

Another study from cybersecurity firm Keeper Security stated that lack of cybersecurity resources and strategies lead to an increase in the number of cyberattacks on financial institutions. It is found that 69% of financial organizations globally have suffered a cyberattack in their lifetime. While half of the organizations reported experiencing an attack in the last 12 months.

 

3 Digital Transformation Shifts Amid Global Uncertainty and How to Handle Them

Digital transformation, security transformation

For most organizations undergoing digital transformation (DX), was already a challenging, complex, and costly journey, and it just got a dose of rocket fuel from COVID-19. The remote workforce has exploded in size seemingly overnight, networks are rapidly changing, and employees, applications and trust zones are more distributed than ever.

By Karl Van Den Bergh, Chief Marketing Officer, Gigamon

As a result, we’re seeing increased pressure on existing IT systems that were never designed for this scenario, as well as an expanded attack surface. And as businesses ask their employees to do more with less amid economic uncertainty, simultaneously, network operations and security teams face the challenge of lowering risk and removing blindspots as traffic patterns change — all while maintaining network performance, security and a positive end-user experience.

The next five years in digital transformation must now happen in the next five weeks. Below I’ve outlined three DX shifts happening in the midst of today’s global workplace transition to remote work and how to handle them. While our current situation will be fluid for some time, what is here to stay is the need for performance and security in a rapidly shifting network, with an eye toward cost containment.

1. WFH requires rapid scaling of remote access infrastructure. On average, organizations have 59% more East-West traffic than North-South. New work from home (WFH) policies are driving the entire LAN traffic base to VPN and have left IT teams with little time to scale their remote access infrastructure for employees. As they scramble to bring remote working capacity online quickly, by repurposing older or existing infrastructure, issues such as failures and bottlenecks can arise in the new network segments and infrastructure. Detecting these issues in a timely manner is critical. But with already stretched resources, these issues become a truly significant challenge.

a. Pro tip: During this transition, with even more changes pending, having accurate visibility into your traffic profile is critical. You need visibility into exactly what’s happening in your network, so you never miss an opportunity, for example, to do accurate capacity re-planning, identifying critical traffic and optimizing bandwidth usage. Networks need to run smoothly, even with a multitude of moving parts.

2. Apps are suddenly pushed to the limit. Customers are now engaging with companies mostly through mobile applications or online. As new application containers, microservices and virtual machines are being stood up rapidly to meet sudden growth in user demand, IT and infrastructure teams risk being left behind by fast-working DevOps and applications teams. This mismatch in alignment can have serious consequences. While application capacity may ramp up, infrastructure capacity may lag and network bandwidth issues, reduced user experience, and application and data access or usage may not be monitored adequately for threats.

a. Pro tip: To achieve the best possible customer and user experience for digital apps, it is important to monitor and visualize application usage and user experience, and take action based on the performance and behavior of these applications. For example, surges in video conferencing traffic due to the intensive use of applications like Cisco WebEx, GoToMeeting, Skype and Zoom can very quickly overwhelm intrusion detection methods. IT teams must be able to quickly visualize which applications are causing these traffic surges, decide whether to analyze this traffic and at what depth, and then filter out safe or low-risk traffic to preserve bandwidth for other applications.

3. When organizations turn inside out, it demands borderless security. Organizations are turning inside out, meaning user traffic previously inside the firewall is now flooding in from outside. Any additional network user activity in new network segments can become a source for threats, such as data leakage or ransomware. Bad actors are quickly exploiting the prevailing paranoia and uncertainty in an effort to compromise users’ systems. These threats use droppers, which are then used to download additional malware on users’ systems to compromise credentials, ultimately leading to ransomware attacks, and potential data exfiltration.

Compounding the inside out challenge is that remote workers use their home network and/or personal devices for work. And it’s not certain that every worker is following recommended security protocols. Even the mandated use of VPNs may not solve the problem, especially if endpoints have not been recently patched. As an example, vulnerabilities are being found and reported in various VPN and firewall manufacturers, which allow Mirai botnet–type variants to take control.

a. Pro Tip: In an effort to ramp up capacity, enterprises need to make sure that if they are using older gear, it is fit for purpose and can be patched and secured. Also, the need for a Zero Trust approach to the network is greater than ever. You need every corner of your network illuminated to provide better visibility and threat detection.

As IT and security teams race to support a remote workforce that is two to three times larger than was ever planned, borderless security needs to be maintained as network traffic has turned from the inside out, not to mention that the applications we depend on are all being pushed to previously untested limits. Visibility and infrastructure agility have become key success factors in an organization’s ability to respond to these challenges, both now and as they continue to manage massive DX shifts as we hurdle toward the new tomorrow.

About the Author

Karl Van Den BergKarl Van Den Bergh is the Chief Marketing Officer at Gigamon. He is a Senior GTM and Product Executive focused on Data and Cloud, with a passion for making a difference by building great teams, products, and businesses. He has a history of successful roles, both strategic and operational, in early-stage startups as well as $1B+ high-tech companies, with extensive international experience.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

70% Of Mobile and Desktop Apps Contain Open-Source Security Flaws: Report

cyberthreats, bug

According to Veracode’s annual report, 70% of mobile and desktop applications that are being used today have at least one security flaw which stems from the use of open-source library. The report, “State of Software Security,” revealed that lack of awareness about where and how open-source libraries are being used are major factors in contributing toward security issues. Open-source library is free to use centralized code repositories that provide ready-made applications for developers. These libraries are not only ubiquitous but also risky, the research stressed.

The research examined 351,000 external libraries in 85,000 applications and found that these libraries have several security bugs. Even a single bug can affect hundreds of applications. According to the report, the majority of the open-source flaws found in applications like Swift, .NET, Go, and PHP. Swift has specialized use in the Apple ecosystem and has the highest density of flaws. It also has a low percentage of flawed libraries in terms of volume while .NET has the lowest percentage of flawed libraries out of the four, and on a volume it is more than 17 times larger than Swift.

Around 47% of the flawed libraries in applications are transitive i.e. they are not pulled in directly by developers. This means that developers are introducing much more code, and often flawed code, than they might be anticipating.

Veracode also found that Go has a high percentage of libraries with flaws, but an overall low number of flaws per individual library. And PHP has a higher rate of flawed libraries than Go – but more than double the density of flaws in any given library. The report also found that cross-site scripting (XSS) is the most common vulnerability category found in open-source libraries, followed by insecure deserialization (23.5%) and broken access control (20.3%).

“Prominent in almost every application today, open-source libraries allow developers to move faster by quickly adding basic functionality. In fact, it would be nearly impossible to innovate with software without these libraries. However, lack of awareness about where and how open source libraries are being used and their risk factors is a problematic practice,” the report said.

“We found insecure deserialization was a relatively rare flaw among in-house applications. Having such a high ranking when looking at libraries is troubling as this category of flaws can result in unexpected code paths being executed, which means that portions of libraries that we are not even intending to use may be inserted into the execution path of their hosting applications through use of this flaw,” the report added.

 

India Reports 37% Rise in Cyberattacks in the First Quarter of 2020

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

According to the Kaspersky Security Network (KSN) report, India has witnessed a 37% surge in cyberattacks in  Q1 2020, as compared to  Q4 2019. Kaspersky stated that it detected around 52,820,874 cyberthreats affecting Indian organizations between January to March 2020, while the number of threats detected in Q4 2019  were 40,700,057.

The report highlighted that India ranked 27th globally in the number of threats detected in Q1 2020 when compared to the 32nd position globally in Q4 2019. In addition, India also ranked 11th worldwide in the number of security incidents caused by servers that were hosted in the country, with 2,299,682 security incidents in Q1 2020, as compared to 854,782 incidents in Q4 2019.

It was also found that most users were affected by malware attacks, which are distributed via removable USB drives, CDs and DVDs, and other offline methods. “Protection against such attacks not only requires an antivirus solution capable of treating infected objects but also a firewall, anti-rootkit functionality, and control over removable devices,” the report said.

Saurabh Sharma, Senior Security Researcher, GReAT Asia Pacific at Kaspersky, said, “There has been a significant increase in the number of attacks in 2020 Q1 that may continue to rise further in Q2 as well, especially in the current scenario where we notice an increase in cybercriminal activities, especially in the Asia Pacific region.”

“We see smartphone users being targeted more due to mass consumption and increased digitalization. Risks like data leakage, connection to unsecured wi-fi networks, phishing attacks, spyware, apps with weak encryption are some of the common mobile threats that Android users face,” Sharma added.

“In order to mitigate some of the major risks like data breaches, targeted ransomware attacks, large scale (distributed denial-of-service) DDoS attacks, etc, businesses will need to allocate their budgets correctly to build a stronger security infrastructure,” said Dipesh Kaura, General Manager for South Asia, Kaspersky.

Cyberattacks on Indian Firms

A number of cyberattacks have been reported on organizations in India, causing a huge financial impact on the banks and their users. Recently, security firm Quick Heal Technologies detected a new wave of Adwind Java Remote Access Trojan (RAT) campaign targeting Indian co-operative banks by taking advantage of the COVID-19 pandemic. The company warned that attackers were trying to take control of employees’ devices to steal sensitive data like SWIFT logins. “These banks are usually small in size & may not have a large team of trained cybersecurity personnel, which, potentially, has made them a target for cybercriminals,” Quick Heal said.

 

Is Samsung’s New Data Security Chip a Game Changer?

Samsung data security chip
Image Credit: Samsung

Samsung Electronics, known for its advancements in various turnkey technologies, has now introduced a standalone security solution comprised of a Secure Element (SE) chip (S3FV9RR) that is managed by enhanced security software. This security chip from Samsung offers a secure gateway to perform tasks such as booting, isolated storage, mobile payments, and other applications. Samsung first introduced a SE-chip (S3K250AF) in its S20 device, which had a Common Criteria Evaluation Assurance Level (CC EAL) of 5+. However, with the SE-chip (S3FV9RR), Samsung has taken its own security standards a notch higher as it has achieved a CC EAL certification of 6+, the highest level acquired by a mobile component.

With the new standalone security element solution (S3FV9RR), Samsung is now enabling smart devices to safeguard user’s private information.

Samsung’s Data Security Chip – A Game Changer

The EAL ranking is given by Common Criteria, an organization that certifies the security level of IT products from EAL0 to EAL7, with seven being the most secure. Thus, the CC EAL certification of 6+ is deemed as a game-changer because it is utilized in applications that demand the most stringent security requirements in the market such as high-end smartphones, e-passports, and hardware wallets for cryptocurrency.

Samsung data security chip
Image Credit: Samsung

This new data security chip also supports the following:

  • The hardware-based root of trust (RoT)
  • Secure boot, and
  • Secure device authentication

While running applications on a mobile device, a boot loader initiates a chain of trust, i.e. all the firmware with approved keys is validated sequentially. This boot process is carried out by the RoT, which guards the device against any possible malicious threats and unauthorized software updates.

Dongho Shin, Senior Vice President of System LSI marketing at Samsung Electronics, said, “In this era of mobility and contact-less interactions, we expect our connected devices, such as smartphones or tablets, to be highly secure so as to protect personal data and enable fintech activities such as mobile banking, stock trading, and cryptocurrency transactions. With the new standalone security element solution (S3FV9RR), Samsung is enabling smart devices to safeguard private information.”

This is not the first attempt of hardware-based security and security chips were introduced earlier.

Google’s Titan M Security Chip

Google’s Titan M is an enterprise-grade security chip custom-built for Google’s smartphone brand, Pixel. This chip secures the most sensitive on-device data and operating system. Titan M helps the bootloader (the program that validates and loads Android when the phone turns on) — make sure that the latest Android version is loaded. It stores the last known safe Android version and restricts attackers from moving to an older and potentially vulnerable Android version on the device. Titan M also prevents attackers’ attempts to unlock the bootloader.

The other salient features of Titan M are:

  • Lock screen and On-Device Disk Encryption protection
  • Secure Third-Party App Transactions
  • Insider Attack Resistance

In 2019, Google announced a $1.5 Mn bug bounty reward for cracking Pixel’s Titan M secure element chip. The reward amount though is at the discretion of the rewards committee and depends on several factors.

Trusted Platform Module

In 2009, a computer industry consortium called Trusted Computing Group created a specification for Trusted Platform Module (TPM). TPM, also known as ISO/IEC 11889, is an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys. A TPM chip has a unique RSA key burned in and a computer program can use a TPM to authenticate hardware devices. In this way hardware-level security complements software-based security, further strengthening the security of the system.

Any application can use a TPM chip for:

  • Digital rights management
  • Protection and enforcement of software licenses
  • Prevention of cheating in online games