Home Blog Page 217

Tokopedia Data Breach: Hackers Leaks 15 Mn User Records

Compromised Email Accounts

Indonesian e-commerce giant Tokopedia suffered a massive data breach after hackers leaked over 15 million user records, data breach monitoring firm Under the Breach reported. It was also discovered that threat actors kept the details of 91 million users up for sale on the Darknet for $5,000. According to Under the Breach, the leaked records contained names, emails, password hashes, and other personal information.

“I’ve decided to share with you, part of March 2020, Tokopedia dump, Hashes contained have an unknown algorithm, and I’m looking for someone who can crack them. I acquired a copy of the dump however it didn’t contain the possible Salt, needed to crack the hashes. I will share 15 million out of much more, just google Tokopedia to see,” the hackers said in a post.

Tokopedia’s spokesperson, Nuraini Razak, also confirmed the breach and claimed that the company had ensured the security of its users’ information. While Tokopedia is investigating the incident, Razak clarified that users’ financial details like credit/debit card numbers and e-wallet information were not affected in the breach. She also advised the users to change their passwords to prevent further damage.

“We have detected an attempt to steal data belonging to Tokopedia users. However, we have made sure that our users’ personal information, such as passwords, remain protected,” Razak said in a media statement.

“Although passwords and other crucial user data remain encrypted, we still encourage Tokopedia users to change their passwords periodically to ensure their safety and security,” the statement added.

The popularity of the e-commerce industry and an exponential increase in online shopping in recent times have led to the problem of online payment frauds. Recently, Indonesian Police and Interpol arrested three men who belong to Magecart hacking group for their involvement in Magecart attacks. The police officials stated that it’s the first arrest of Magecart gang members.

The suspects, identified by initials ANF (27 years), K (35 years), and N (23 years), were accused of injecting JavaScript sniffers into websites to capture information entered by the site visitors. It’s said that the suspects allegedly used the stolen payment card data to purchase electronic and luxury goods.

Collaboration will be Integral in a Post COVID-19 World: Chris Roberts

chris roberts webinar

CISO MAG recently hosted its second Fireside Chat with hacker, security researcher and CISO, Chris Roberts; the audience comprised of CISOs, security professionals and other C-Suite executives from the U.S., UK, EU, UAE, and Asia. The topic for the webinar was “The Superhero CISO,” who is instrumental in empowering the workforce, optimizing processes, and leveraging technology to secure business operations in a distributed ecosystem. The Fireside Chat, held on April 30, 2020, was moderated by Brian Pereira, Principal Editor of CISO MAG.

For the uninitiated, Roberts possesses a rich experience within the domain of information security and is globally recognized as one of the pioneering wizards on vulnerability research and counter threat intelligence. He has worked on a multiplicity of projects specializing in intelligence gathering, DarkNet research, deception technologies and cryptography with several organizations and has been credited by many of the top Information Technology and Security disciplines. Roberts’ hacking exploits have also been widely reported in the media and, in some cases, attracted the attention of certain three letter government institutions.

Roberts started the webinar by drawing parallels between computer viruses and biological viruses and how the situation of COVID-19 has affected countries, globally. According to him, the similarities between computer viruses and biological viruses are uncanny and the preventive measures adopted by healthcare experts and cybersecurity experts are also similar.

“While we encounter malware and viruses, the step that even we adopt are identification, isolation and analysis which is not very different from the methods adopted by healthcare professionals,” he added.

He also shed light on the attacks targeted at the healthcare systems during the onset of COVID-19 in several counties. “Even though, for the sake of humanity, several bad actors and malware groups came out stating that they will not target the healthcare sector during this dire situation, several groups continued their nefarious activities. The attacks were one of the reasons why several collaborations between cybersecurity experts, organizations and governments occurred. It all comes to the modus operandi of these attacker group — make money and exploiting a situation.”

Roberts said there needs to be a more collaborative approach to counter cyberattacks.

The discussion then shifted to businesses connected to a network of supply chains, and the need for companies to secure its own infrastructure as well as their partner networks, third-party vendors, dealers, sub-contractors, and customers involved.

Responding to this Roberts stated, “For businesses, it is important to understand where the risks are. It is impossible to secure everything. And several times, small companies do not take security seriously while big companies, which have partnered with them forget that they should secure the smaller companies.” He highlighted the need for better communication and collaboration between small and big companies. “In fact, in a post COVID-19 world collaboration will be key. We need to understand that,” he stressed. He also spoke about the need for securing endpoints, understanding where the endpoints are, and the need for better awareness and education toward safeguarding the supply chain.

Towards the end, Roberts took questions from the audience on the need for contact-tracing apps surrounding the COVID-19 cases. He answered,

 

Toward the closing, Roberts teased the audience with a device in his background and how he has lately been exploring methods of hacking the human through nanotechnology, and that is where his research is headed, for now.

Listen to excerpts from the Fireside chat here.

The next Fireside Chat on ‘Reinventing the Cybersecurity Strategy to Overcome the Business Implications of a Pandemic’ will be held on May 14, 2020, with Thomas Tschersich, CISO, Deutsche Telekom AG.

Through the Fireside Chat series, CISO MAG will be partnering with industry experts and solution providers from across the world to host similar webinars thrice a month to discuss some of the pressing issues and trends in cybersecurity. Stay tuned.

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants, was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyber Attack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world. For more information, visit https://www.eccouncil.org/.

Lessons That Can Be Learned from Reviewing How We Manage Cybersecurity and Applying it to an Anti-Coronavirus Campaign

coronavirus, covid-19

In recent years, some in the cyber world recognized that there is a lot to learn from the biological world when protecting systems against viruses. Now, the Corona epidemic presents an opportunity for the medical world to learn something from the cyber world. To analyze the strategies selected by various countries, let’s review them through the lens of cybersecurity.

By Zohar Rozenberg, Chief Strategy Officer for Elron

Let’s begin by recognizing that cybersecurity is built in layers. There is no one magic solution or layer that will prevent all possible attacks. Furthermore, in the cyber world, it has been understood for some time that it is impossible to protect everything for all eternity. There will be incidents. Computers will be attacked, information will be stolen, activity will be interrupted. It has already been accepted in the business world that it is not possible to maintain an extremely high level of protection while at the same time enabling a business to run at its required pace.

A compromise will always be found, and risks managed. Extremely high levels of security are possible, but this will give rise to a situation where work may grind to a halt. Businesses accept that by running freely, they expose themselves to various levels of cyberthreats.

“The challenge, which has become the main responsibility of information security managers and with their organizations, is to learn how to live with day-to-day compromises and to understand the risks they take, determine what level of risk they can accept, and what level of risk is too great.”

Just as businesses weigh various protection approaches in cybersecurity, we can see several strategies for protection against Coronavirus being implemented by various countries. In South Korea and Taiwan, a relatively advanced approach has been adopted of detecting the threat, finding where it is harbored, and dealing with it surgically wherever identified. These methods are used in conjunction with a basic layer of disinfecting large areas.

As in the cyber world, this can be seen in the use of advanced concepts of threat hunting and extensive investment in detection and incident responses. All this is above and beyond the basic layer of a standard firewall and endpoint protection in order to provide some basic level of protection throughout the whole organization. This approach reflects an understanding that the “point of contact” to the world will be breached, or in the professional slang, “the perimeter is dead.” It is not possible to achieve full protection and keep the threat outside the perimeter forever. The threat must be sought out on a targeted basis and dealt with wherever identified without giving up a basic layer of protection, which will succeed in preventing the simpler threats from penetrating.

Most countries in the world, including Israel, Italy, and the U.S. have initially adopted approaches that are similar to traditional and older methods in the cyber world. Israel began with an approach that derives from the belief that there is indeed a “perimeter” and that the threat can be blocked externally. In the cyber world, this approach is now widely thought to be inherently irrelevant. Subsequently, Israel, like Italy and the U.S., transitioned to taking the approach of a callous and aggressive policy. In the cyber world, such an approach equates to a policy of a strong lock-down of the network, preventing the transmission of information between points in the network. This makes any utilization of the resources of the network difficult and, in general, tends to reduce traffic on the network. Such an approach can indeed succeed in producing achievements in terms of preventing breaches of the network and the endpoints, but it also has the effect of preventing most of the activity on the network and, consequently, having an adverse effect on the organization’s business activity. Such an approach to protection was previously beneficial at sensitive locations such as defense establishment institutions, but over the years, they have also understood that it is impossible to operate over time with such difficulties preventing the activity of the organization.

“Throughout the industry, it is now difficult to find organizations that have stuck with the approach of a robust and aggressive cyber policy. In the last decade, we have witnessed a shift towards more sensible and considered risk management that attempts to strike a balance between the need to facilitate activity and the desire for protection.”

Britain has attempted to adopt its own unique approach towards the Coronavirus crisis, relying more on the Herd Immunity theory, that the cyber world finds slightly illogical. This approach, similar to installing basic anti-virus software on each endpoint, has been outdated for decades and there are currently no organizations in existence that use it as their approach for protection, with the possible exception of very small businesses.

Since the Covid-19 began to spread across Asia, some countries were quick to understand this will become a global issue and take initial measures such as closing borders to arrivals from Asia, and later from more and more countries which showed signs of an outbreak. Other countries seemed to have rejected the notion and insisted on “business as usual” for some time before realizing they too had to take similar measures.

In the cyber world, this may be analogous to using Threat Intelligence. Today in the cyber world, there is a growing acknowledgment of how difficult it is to build a layer of protection against cyber threats without engaging in the acquisition of advanced information related to threats and their nature. Currently, the leading organizations worldwide, with their own ability to protect themselves, are widely reliant upon information when addressing cyber threats.

The public reactions of various countries towards the crisis and the guidance given by governments vary. Apparently, in Singapore, Taiwan, South Korea, and perhaps other places, the public has strictly complied with governmental directives, understanding the risk, and responding well to the threat. On the other end of the spectrum is Italy, which for weeks reacted complacently, did not heed governmental instructions, and didn’t understand the size of the threat. There is a direct parallel in cybersecurity: end-user awareness and training. In cybersecurity, training the personnel of the organization to appreciate the threat and educate them on proper procedures in the presence of a threat is an important part of every cybersecurity program. This is regarded as maintaining “cyber hygiene,” which reminds employees not to open suspicious emails, how to report something suspicious to the organization, etc.

Organizations that have invested actively in educating people regarding awareness and correct actions have reported an improvement in the immunity of the organization to cyber threats. In organizations that have not invested in this at all, most people find themselves falling prey to cyber-attacks such as email phishing.

It appears that in the cyber world, more advanced organizations are adopting more innovative approaches, and the use of advanced tools such as threat hunting, detection, incident response, as well as employee awareness have produced better results in coping with cyber threats. Thus, in the physical world, countries that have adopted similar approaches appear to have succeeded, at least for now, in containing the virus’s threat in terms of a dramatic reduction in the number of cases of infection and are on the point of at least a partial return to routine. Countries viewed as maintaining more traditional approaches and that are attempting to sanctify the perimeter or apply tough, aggressive policies as their major effort, are finding it very difficult to contain the threat. Some of these countries are still seeing a rise in cases, coupled with a widespread paralysis of economic activity and the economy as a whole.

“If countries wish to learn lessons from the world of cyber protection in order to deal with the Coronavirus threat, then they must bear in mind that building defenses must consist of several layers. No one method can avoid the threat.”

Investment efforts must be put toward prevention. It is essential to create a basic level of control and monitoring of entrances, but the action is also necessary on the level of detection and treatment. This can only be done properly by adequately gathering and analyzing the latest data. It is hoped that more and more countries will consider adopting more advanced protection approaches, finding ways of applying them in the physical world in order to accelerate the end of the threat, and bring about a return to a normal routine.

About the Author

Zohar Rozenberg (Col. Ret.) is the Chief Security Officer at Elron, an Israeli holding company dedicated to building technology companies, actively investing in startup companies. He is also acting as Member of the Board for several cyber companies. Zohar was also involved in the establishment of the National cyber bureau and the formalization of the Israeli national cyber strategy.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

 

French Newspaper Le Figaro Exposes 7.4 Bn Users’ Records

106 million Thailand visitors

Le Figaro, the oldest national daily in France, is the latest victim of a data leak that exposed 7.4 billion records that contain readers’ personal information, security researchers at Safety Detectives revealed. The researchers stated they found an 8TB Elasticsearch database, hosted by Dedibox, exposed online without password protection.

The database contained API logs that hold records of new subscribers and previously subscribed users. The exposed users’ personal data included full names, emails, home addresses, IP addresses, server access tokens, countries of residence, postal codes, and passwords for new users both in cleartext and hashed with the unreliable MD5 algorithm. In addition, researchers found around 42,000 new users registered on Le Figaro between February and April 2020, which were also exposed in the data breach.

“The exact number of people exposed is uncertain due to the structure of the data. It would have required more time to investigate the database and calculate precisely how many individual users were recorded across each type of data entry. Due to the sensitivity of the leak, we decided it was better to contact Le Figaro quickly rather than spend more time investigating,” the researchers stated.

Apart from the API logs containing PII data, Safety Detectives said, “The compromised database also contained numerous technical logs exposing more of Le Figaro’s backend servers and possibly additional, potentially sensitive data that could be valuable for attackers hoping to compromise the company’s data infrastructure, including SQL query errors, Traffic between different servers, Communication protocols, and Potential access to admin accounts.”

Risks from Data Breaches

The researchers warned that attackers might take advantage of the sensitive information exposed to database leaks. Hackers could exploit the data to launch identity theft, credential phishing attacks, spear-phishing attacks against Le Figaro’s users, journalists, and employees, and on Le Figaro’s network and backend servers, the researchers concluded.

Recurring Elasticsearch Server Leaks

Elasticsearch servers have continued to leak protected personal information of millions of people and organizations. The most recent server breach occurred when Peekaboo’s app developer, Bithouse, left the Elasticsearch database open, which contained more than 70 million log files comprising nearly 100 GB data stored from March 2019. The exposed data included detailed device data, links to photos and videos, and around 800,000 email addresses.

There was always been a security concern about Elasticsearch servers. Security experts stressed that breach occurs due to lack of built-in protections, when there are no password protections or firewalls. Even ElasticSearch provided some recommendations on how to secure their servers, which include secure authenticated sign-in, proper encryption, layered security, and audit logging.

Malware Alert! New Android Mobile Banking Trojan ‘EventBot’ Debuts

Armor Piercer

Researchers at Cybereason Nocturnus have discovered EventBot, a new type of Android mobile malware that exploits Android’s accessibility features. It steals the victim’s data from financial applications installed on their Android mobile(s) by reading the inbox messages and thus allowing the malware to bypass user security measures like the two-factor authentication (2FA).

EventBot Android Malware

  • EventBot is an Android banking Trojan belonging to the mobile malware
  • Theft of one’s financial information by exploiting Android’s accessibility feature is the modus operandi of this malware.
  • On its successful installation, EventBot collects a victim’s personal data including passwords, keystrokes, banking information, and more. This set of information can be used for identity theft, transaction hijacking, and more.
  • It is known to specifically target users across the U.S. and Europe, including Italy, the U.K., Spain, Switzerland, France, and Germany.
  • Over 200 finance-based applications are potentially affected by EventBot Android malware, which includes banking, money transfer services, and e-wallet applications like Paypal Business, Revolut, Barclays, UniCredit, CapitalOne UK, HSBC UK, Santander UK, TransferWise, Coinbase, Paysafecard, and many more.

Preventive Measures for EventBot

  • Download mobile apps from official and authorized sources only. Avoid unofficial links sent by unknown people and from bulk marketing SMSs and Emails. It could be a smishing or phishing For legit Android apps go to the Google Play Store and double-check for Verified by Play Protect assurance symbol.
  • Check the app permissions requested. Critically analyze whether these permissions are required and should be granted to a certain application.
  • Even if a slight doubt persists, check the APK signature and hash values of the application in sources like VirusTotal before installing it on your device.
Threat Summary
Threat Name EventBot
Threat type Android malware, a mobile banking trojan
Target Industry Finance (including banking, money transfer services, and e-wallets)
Target Audience Europe & the U.S.
Campaign Active Since From at least March 2020
Features Dynamic library loading, encryption, and adjustments to different locales and manufacturers.
Domain Indicators ·    themoil[.]site

·    ora.carlaarrabitoarchitetto[.]com

·    ora.studiolegalebasili[.]com

·    rxc.rxcoordinator[.]com

·    Ora.blindsidefantasy[.]com

·    Pub.welcometothepub[.]com

·    marta.martatovaglieri[.]it

IP Indicators ·    185.158.249[.]141

·    185.158.248[.]102

·    50.63.202[.]81

·    185.158.248[.]102

·    31.214.157[.]6

·    208.91.197[.]91

Damages caused Financial and confidential data of the victim can be compromised.

Indicators of Compromise (IOC)

SHA256

1cfce7df49ce5dc37d655d80481a3a6637d2e7daff09ceede9d8165fae0fce5f

05782e267bd62de78a3db22b1a83ddd3c72cbef95f5a5bc9defdd42a4f5786ec

199859a2929af5431df4a4760f93c83472dc21ea0b9e33d9e45439052de44ab3

6cbb2040ab1f8244fc1bbfdb2af0452ff2bb4fef738011e82af38aac4b7255e5

43d08b8c16d1d26872206c99c93785cac75c983eaae8c8030e5b0ce9defe1755

f4dd5da58965893bd7011aa02aa41d7fae835789c71ad97df2dc77f85e357abc

41cf4ca70cf52b6682303a629193da78ab00701da6aed5650b72015c056920da, and more.

Reliance Jio’s Coronavirus Symptom Checker App Exposes User Data

Reliance Jio’s Coronavirus Symptom Checker App Exposes User Data

A technical glitch in Reliance Jio’s COVID-19 symptom checker app exposed its core database that contained users’ sensitive information, TechCrunch reported. The Indian telecom giant launched the self-checking app last month to help users to check for coronavirus infection from their phones.

Along with the COVID-19 tests results, the exposed database contains millions of individual logs and records starting from April 17, 2020, to till date. The other information included users’ age, gender, location, symptoms, health data, information about the user’s browser version, operating system, and other profile information. The issue came to light after security researcher Anurag Sen discovered and reported the issue. TechCrunch stated the database was taken offline and is now secured after notifying Reliance authorities.

TechCrunch stated that it was able to find users’ precise locations using the latitude and longitude records found in the database. It was discovered that most of the users’ geo locations pointed around Indian cities like Mumbai and Pune, including users in the U.K. and North America.

“We have taken immediate action. The logging server was for monitoring performance of our website, intended for the limited purpose of people doing a self-check to see if they have any COVID-19 symptoms,” said Jio spokesperson Tushar Pania in a media statement.

Coronavirus-related Data Breaches

In a similar data breach incident, hackers compromised a database that contains details of all the COVID-19 patients, which was maintained by Aythala district administrator’s office computers in the Indian state Kerala. The data included information on people coming into the district from abroad and those kept in self-quarantine, their recent travel history, residential addresses, and contact details, etc.

The list of confirmed and quarantined patients in the district was handed over to the police and the district health administration to help them in the continuous monitoring of respective individuals. However, the same list started appearing locally on various social media groups and forums.

Hackers Attack Blogging Platform “Ghost” To Mine Cryptocurrency

Patchwork BADNEWS, APT31 threat group

Ghost, a blogging platform, recently admitted that it suffered a security breach in which hackers exploited critical vulnerabilities in its servers. In an official release, the Singapore-based company stated that unknown threat actors abused two vulnerabilities CVE-2020-11651 and CVE-2020-11652 in its Saltstack master to mine cryptocurrency on its servers. Saltstack is an open-source software used by data centers and cloud servers. Ghost stated that the incident came to light when hackers’ mining attempts spiked its CPUs and systems.

Ghost is an open source and free to use blogging platform aimed at simplifying the process of online publishing for individual bloggers and online publications.

According to Ghost, the hacking incident occurred on May 3, 2020, at 03:24 BST when the company updated its status checker page and noticed the abnormal activity when its server reported a service outage. At 10:15 BST the same day, Ghost revealed the incident, and a fix has been released to restore its servers.

“We’ve introduced multiple new firewalls and security precautions today which are unfortunately causing instability on our network and affecting some customer sites. We have restored all services and everything should be functioning as normal. We are still investigating the root cause of the issue with our upstream providers,” Ghost said in a statement.

It is said that the attack affected both Ghost (Pro) sites and Ghost.org billing services. Ghost also clarified that there is no evidence that personal data of its customers like passwords, and any credit card or financial information was compromised.

“We’re continuing to monitor all systems closely, whilst also working carefully to cycle all sessions, passwords and keys on every affected service as a precaution. Our additional firewall configurations are now running and working as expected. All connectivity issues have been resolved and customer sites are loading as normal again,” the statement added.

AI in Networking: Improving Security

Artificial Intelligence, AI, neural, machine learning

In 2004, a few unmanned vehicles showed up at the starting gate of the lengthy course across the Mojave Desert — this was the inaugural DARPA Grand Challenge. It signified the beginning of the technological race to develop a practical self-driving car, which sparked a global movement that continues even today.

The networking community too embarked on a similar journey to provide production-ready, economically feasible, Self-Driving Networks. Self-Driving Networks are autonomous networks that use Artificial Intelligence (AI) and Machine Learning (ML) to program independently and carry out prescribed intentions while eliminating complex programming and management tasks required today to run the networks. In view of this, the proliferation of data breaches and cyberattacks in today’s networking environment has also increased, leading to extensive repercussions across businesses. As such, ML-based security solutions have become a major cybersecurity investment for organizations today.

By Rohit Sawhney Systems Engineering Manager at Juniper Networks India

Leveraging AI to enhance your network security

Many experts believe that AI and ML will dominate cybersecurity in the future. Last year, at the Gartner IT Symposium/Xpo, analysts discussed how these two technologies will augment human decision-making, emotions, and relationships.

Rapid technological advances are enabling AI to disrupt the networking industry with new insights and automation. AI in the networking domain will be able to reduce IT costs and offer the best possible user experience. Not only will AI be able to reduce IT costs, but it will also bring in more productivity and efficiency in networking. Together, machine learning and AI could be key enablers, helping to reduce human effort and make cybersecurity faster, more consistent and accurate.

In fact, many Enterprises are already making greater investments to integrate solutions with machine learning algorithms into their existing security infrastructure. While traditional antivirus programs are still widely used to detect and neutralize threats, they do not have the capability to detect and mitigate sophisticated threats. ML-based security solutions like the Juniper ATP can help monitor potential threats in the network through threat intelligence features – allowing IT security teams to detect any suspicious activity before the attack occurs.

AI comes to the rescue as it reduces the number of monotonous tasks that take up an engineer’s time, while ensuring they are always completed accurately, regardless of frequency and quantity. This allows engineers to focus on other business strategic tasks while maintaining network health and safety.

Building an AI system for your network

In a recent survey conducted by KPMG for its report, Living in an AI World 2020, analysts found that 92% of respondents agree that leveraging spectrum of AI technologies will make their companies run more efficiently. However, in the networking domain, IT simply can’t meet the needs of today’s stringent network requirements, without a robust AI strategy. The following are some technology elements that an AI strategy should include:

  • Data – Needless to say, without adequate and relevant data, ML algorithms are as good as the data one ingests in them. The more diverse the data collected, the smarter the AI solution becomes. The collection of real-time data with accuracy and speed is just as important. Edge devices like routers, mobiles, and IoT enabled solutions not only need to collect the data but get it processed quickly in a nearby edge computer or on the cloud, using AI algorithms, to make the network more adaptive.
  • Domain-specific expertise – Unless you are a domain expert, it is simply impossible to replicate an AI system to diagnose wireless problems. Placing the metadata at the center of these problems and breaking it into small fractions will enable the AI system to understand the complexity and get trained.
  • Data science deep dive – Machine Learning and Big Data techniques empower the data by extracting insights from the multiple chunks of metadata, divided into several domains.
  • Virtual network assistants – When Netflix or Prime Video recommends movies basis the ones you’ve been watching, they’re using an ML technique known as collaborative filtering. Apart from recommendations, collaborative filtering can also be applied to sieve through large data sets and identify and correlate those that form an AI solution to a problem.

Benefits of AI/ML in the networking domain

ML a subset of AI, is a prerequisite for any successful deployment of AI technologies. ML uses algorithms to parse data, learn from it, and determines or predicts without requiring explicit instructions. With that said, AI/ML can be leveraged for the following tasks in the networking domain:

  • Cybersecurity practices: Machine Learning is critical in building a secure networking infrastructure and is considered a top priority for most organizations today. ML enables security automation and helps in data classification, processing, filtering, and significantly managing and reducing the workload of the IT security team. Automating this task increases workload efficiency and reduces the risk of missing an important threat alert.
  • Predict user experience to dynamically adjust bandwidth demand – When traffic spikes occur in today’s networks, it is difficult to distinguish between DDoS attacks from widespread downloading, of say, Arijit Singh’s latest album. By leveraging ML algorithms that interpret copious amounts of traffic behavior data, the Self-Driving Network will be able to predict performance issues before users are affected. In such an example, connections with algorithms that scrape Twitter feeds will confirm the hypothesis: Have hacking groups been threatening action against an enterprise? Or have fans been demanding for Arijit Singh’s album in the weeks leading up to the spike? The Self-Driving Network will analyze and adapt accordingly, either shutting down ports to isolate the DDoS attack or adding bandwidth to accommodate the surge in album downloads.
  • Self-correct for maximum uptime – AI, through its intelligent algorithms, complemented by ML capabilities, enable systems to have a self-correction process in places to ensure maximum uptime. The powerful AI-driven networks can even capture data prior to a network event or outage, which accelerates troubleshooting.
  • Instantly find root causes – AI can leverage multiple data-mining techniques to explore terabytes of data in a matter of minutes. This allows IT departments to instantly identify what network feature – be it the OS, device type, access point or switch – is most related to a network problem. This in turn allows IT departments to accelerate this problem resolution.

About the Author

Rohit Sawhney, Systems Engineering Manager at Juniper Networks India. AI in NetworkingRohit Sawhney is a Systems Engineering Manager at Juniper Networks India. He leads the team of Technical Consultants supporting Juniper’s North/East India & SAARC business. Prior to joining Juniper Networks, he has worked with IBM India and has industry experience of over 20 years. Rohit is a certified by Juniper Networks, Cisco and VMWare. He holds a master’s degree in Computer Application from Sikkim Manipal University of Health, Medical and Technological Sciences and a Bachelor’s of Science in Electronics from Delhi University.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

The Impact of COVID-19 On Global Cybersecurity Sector is Severe: Research

Cybersecurity Investment Estimated to Grow up to 6% in 2020

A recent survey revealed that the impact of COVID-19 on the global cybersecurity market size is expected to grow from $183.2 billion in 2019 to $230.0 billion by 2021, exhibiting a CAGR of 12% during the forecast period. The survey stated the ongoing crisis has transformed the thought process of a company’s management toward cybersecurity. Especially, SMBs, startups, and large enterprises, except technology giants, were considering cybersecurity budgets as unavoidable capital expenditure due to regulatory and compliance measures.

The research also highlighted that endpoint security segment is expected to show the highest growth rate during the forecast period in the cybersecurity market. Also, health care segment to record higher investment and growth in 2020.

“As the remote and teleworking modes are adopted in the healthcare industry, the possibility of using personal devices and the home internet connections that do not have the enterprise-grade security would result in remote users vulnerable to malicious cyberattacks,” the report stated.

The study on global cybersecurity market was aimed at estimating the market size and the growth potential by technology segments like network security, application security, endpoint security, cloud security, database security, web security, and ICS security. It also includes different business verticals like banking, financial services and insurance, healthcare, manufacturing, IT/ITeS, telecom, utilities, and public sector.

A similar survey from Fortune Business Insights revealed that global cybersecurity market value is projected to reach $281.74 billion by 2027, exhibiting a CAGR of 12.6% during the forecast period from 2020 to 2027. According to the report, the requirement for advanced cybersecurity solutions is growing exponentially with the growth in the number of cyberthreats. The survey also highlighted that cybersecurity market growth is driven by the rising adoption of e-commerce online platforms and the emergence of disruptive technologies like Artificial Intelligence, Internet of Things, Blockchain, and others.