Home Blog Page 38

Unleashing the Full Power of AI and ML for Your Cybersecurity

Artificial Intelligence, AL and ML

The growth of data and the increasing complexity of extracting intelligence from information have led businesses and governments across the globe to implement artificial intelligence and machine learning technologies. AI and ML applications to supplant and enhance human capabilities range from image recognition in healthcare to failure prediction in industrial to natural language processing in customer service to identifying fraud or criminals in financial services or governments.

 

By Vats Srivatsan, President and Chief Operating Officer at ColorTokens Inc.

 

So what roles have AI and ML played in enterprise cybersecurity? On the face of it, cybersecurity seems like a perfect use case for AI and ML techniques. Security threats continue to grow by the day. The amount of security data collected by multiple cybersecurity sensors is growing exponentially, and there is a significant shortage of trained cybersecurity professionals. The industry has a clear need for AI and ML technologies.

 

Yet AI and ML are not as prominent in cybersecurity as they have been in other fields. But why are their applications in cybersecurity restricted to niche use cases, and how should organizations consider these technologies from their cybersecurity or AI/ML vendors?

What Limits the Effectiveness of AI and ML in Cybersecurity Today?

The answers to those questions are complex and multifaceted but revolve around three key issues.

Lots of data yet very little trainable data: In this environment, security professionals have relied on vendors to provide alerts on any abnormalities, but those alerts add up to several tens of thousands per day. Very few, if any, of these alerts would translate to attacks, often with over 99% false-positive rates.

From a threat-detection perspective, this means that organizations could really apply predictive AI and ML to only 0-1% of transactions. ML models need data to predict accurately, so this limits the ability to train models on actual threats. New threat patterns, which attackers are busy exploring every day, render useless any prediction based on past attacks.

Insufficient business risk context: The cybersecurity industry is fragmented with vendors for each security problem. It is not atypical for a large organization to rely on 50-plus security tools, often from different vendors. Each tool collects data relevant to its use but misses the overall context outside of its intended use.

For example, firewalls are used very widely and collect transactional network flow data, but rarely can they attach that data to the application and user context simultaneously. Similarly, endpoint systems collect lots of information on processes that run or can run on the endpoints but lack the context of how critical an application that the endpoint is trying to access is or the vulnerabilities within it.

The net result is that the basic context needed to apply ML becomes fragmented. A simple business question such as, “Should you allow or block a specific transaction into an application?” becomes difficult to answer at scale. It requires information on the inherent security risk posed by that transaction, estimated business risk from allowing such a compromised transaction, and the level of business disruption that could happen from blocking the transaction. Typically, this information does not exist or is scattered across multiple tools and is not available at the time such a decision needs to be made.

After-the-fact analysis vs. new attack vectors: Companies have addressed their data fragmentation through data-aggregation mechanisms like security information and event management, known as SIEM. While this is better than having no information, after-the-fact analysis of such aggregated data is passive by definition — meaning that it allows you to analyze a past threat and prevent that exact attack pattern if it recurs, but it won’t help prevent threats that don’t follow historical attack patterns.

So How Do You harness AI/ML in Your Cybersecurity Posture?

Some companies have recognized the challenges above and stated to address them in their offerings. Broadly, there are three stages to the application of AI and ML tools in terms of their effectiveness in cybersecurity:

Stage 1: AI/ML to simplify operation – Identify assets or users and detect abnormal behavior


AI can be an effective way to automate routine areas that usually take a lot of manual effort, particularly if those tasks are routine and don’t need broad business context and increased data sources to facilitate better training over time.

Automatic identification, or tagging categorization of assets being secured, is a surprisingly complex problem in large organizations with tens of thousands of assets under management. Here, an AI/ML model can identify but tag the asset based on processes or software running on other assets with which it communicates. This is similar to how photos can be tagged based on visual recognition.

More data from an organization or multiple organizations improve these predictions over time. Similarly, flagging anomalous behavior or deviations from known “good” or “trusted” behavior is a good application area, where just the sheer volume of good transactions makes AI effective and manual analysis difficult at the same time.

Stage 2: AI/ML for security policy definition – With appropriate business risk context

If a cybersecurity tool can embed the context of business risk from a security threat by using knowledge of the request (user and device) and what is being accessed (an application or data) and the medium (a network), then ML would have enough contextual intelligence to be powerful in security policy setting.

To achieve this in practice, cybersecurity vendors must assign “business security risk scores” to transactions, either to one transaction or to a group to which one transaction belongs, all while the transaction is executed. This is like how a bank would assess any online request for a transaction.

Assigning a business security risk score is not always simple. It requires holistic information on whether the user, network, or transaction is known or trusted; how vulnerable the asset being assessed is in terms of exploitability; and how business-critical a compromise of that asset could be in terms of if its breach exposes customer or employee confidential data that could harm the company. A system that can do that will be really powerful in using AI to define and recommend automated policies or dynamic policy updates as risk changes.

See also: “AI and ML will be an enabler for cybersecurity for the foreseeable future”

Stage 3: AI/ML to adapt security posture – Continuously trading off business velocity vs. security risks

Most companies have invested in many security tools, yet CIOs find it difficult to determine whether their security posture is better than before. Zero Trust-based policies and tools address this by allowing nothing except trusted interactions, processes, and users. By definition, they enable organizations to block out new threat vectors and unknown interactions instantly instead of allowing time for such interactions to happen. They then learn over time, as ML models or human analyst models would typically do.

While this enables a higher security posture, narrowly defining trust zones could impact business and prevent or slow down low-risk transactions that enable the business. However, AI/ML can get that tradeoff right. Organizations can start with very small zero-trust zones in critical applications and use ML over time to expand the trust zones based on risk and behavior patterns.

AI and ML have not been utilized to their full potential in cybersecurity yet. However, when used appropriately, AI and ML can play a very effective role in your cybersecurity. Proper applications can assist humans in security analytics and operations, recommend low-security-risk policies, and enable CISOs to maintain the best security posture that allows the business to operate at the necessary velocity.


About the Author

Vats Srivatsan Vats Srivatsan is president and chief operating officer at ColorTokens Inc., a SaaS-based Zero Trust cybersecurity solution. As a member of the ColorTokens leadership team, he uses his extensive knowledge of cloud and cybersecurity across multiple industries to help customers in their Zero-Trust cybersecurity journey. Srivatsan’s previous three decades of experience include executive roles at leading companies including Palo Alto Networks and Google Cloud. At Google, Vats founded and led the Advanced Solutions Lab that helped apply Google’s AI to core business problems for some of the leading enterprise customers.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Zero-Day Exploits on High Demand on Dark Web

zero-day vulnerabilities

While security admins struggle to address the significant risks from unpatched vulnerabilities, adversaries are becoming more advanced and finding new ways to exploit security flaws. Cybercriminal groups usually search for unpatched vulnerabilities to exploit and compromise the targeted devices. And they continue to trade information on security vulnerabilities and exploits on various darknet forums.

Vulnerability Industry on Dark Web

As per a report from Digital Shadows, several cybercriminal groups and state-sponsored actors are increasingly willing to purchase information on vulnerabilities and exploits from various cybercrime affiliates on the dark web. The market for zero-day vulnerabilities is reportedly high as many ransomware operators are interested in buying them. Digital Shadows claim that the price range of zero-day flaws could go up to $10 million.

“This environment is bursting with a variety of widespread actors who boast a whole range of technical expertise and motives. The technical discussions of this eclectic underground cohort have actually contributed to a pretty cohesive, crowd-sourced body of knowledge about vulnerabilities and exploits. The top of the cybercriminal pyramid is represented by the market for zero-days. This market is an extremely expensive and competitive one, and it’s usually been a prerogative of state-sponsored threat groups,” the researchers said in the report.

Exploit as a Service Model

The research also found several cybercriminals discussing ideas on the Exploit-as-a-Service business model to attract adversaries who are unwilling to spend more money. The exploit-as-a-service model allows threat actors to lease zero-day exploits to perform their criminal activities. Along with zero-day vulnerabilities, the cybercriminal community also shares insights on old vulnerabilities that have not been properly patched.

Also Read: From Data Leak to Dark Web: What Happens to Your Stolen Data?

“We don’t know how long this model will remain viable. Zero-day exploit developers can certainly generate large profits by selling to government-backed threat actors, but this process can eat up time and drive the developers to seek alternative revenue sources. And that’s when exploit-as-a-service becomes viable ― generating their desired income from various interested parties. The result? More and more financially motivated threat actors with their hands on dangerous tools,” the researchers added.

CISA’s Order on Unpatched Vulnerabilities

The threat of unpatched vulnerabilities has become one of the pressing security issues for organizations worldwide. The Cybersecurity and Infrastructure Security Agency (CISA) recently issued a Binding Operational Directive (BOD) to reduce the risk of actively exploited vulnerabilities. The new Directive, which applies to all software and hardware found on federal information systems, requires federal civilian agencies to remediate such vulnerabilities within specific timeframes.

Emotet Botnet Resurfaces via TrickBot

Glupteba botnet, Emotet botnet

Emotet, a banking-trojan-turned-botnet that primarily spread via emails, has raised its head after a hiatus of 10 months. Emotet made headlines when Europol announced that eight global law enforcement authorities disrupted it under “Operation Ladybird.”

Abuse.ch released a list of botnet Command&Control servers (C&Cs), which are presently associated with Emotet and other malware.

As observed this time, threat actors leveraging Emotet are again using TrickBot to send spam email chains with malicious attachments and links. In the past, TrickBot originated as a banking trojan to steal sensitive financial information via brute-force attacks or credential harvesting.

 The 2021 Disruption

The industry applauded the takedown of Emotet, however, with a few reservations. Experts were delighted that the successful action would help various organizations and over a million Microsoft Windows systems that were compromised with Emotet malware. But the happiness has been short-lived.

The law enforcement authorities had distributed a new Emotet module in the form of a 32-bit EmotetLoader.dll to the users of all infected computers to automatically uninstall the malware. The new variant was noticed around 14, November 2021.

Security researcher Luca Ebach of cyber.wtf, in a post shared, “On Sunday, November 14, at around 9:26pm UTC we observed on several of our Trickbot trackers that the bot tried to download a DLL to the system. According to internal processing, these DLLs have been identified as Emotet. However, since the botnet was taken down earlier this year, we were suspicious about the findings and conducted an initial manual verification. Currently, we have high confidence that the samples indeed seem to be a re-incarnation of the infamous Emotet.”

Expert Speak

In an exclusive to CISO Mag on the re-emergence of Emotet malware, Adam Meyers, SVP of Intelligence, CrowdStrike opined, “CrowdStrike Intelligence confirms the return of Emotet malware as reported publicly by media. From our perspective this is likely a new version of MUMMY SPIDER’s Emotet. This assessment carries moderate confidence and is based on extensive code similarities to prior versions of Emotet as well as MUMMY SPIDER’s long-standing relationship with WIZARD SPIDER. Emotet is Adam Meyers, CrowdStrikecurrently being distributed via TrickBot, which we associate with the eCrime adversary group: WIZARD SPIDER. To protect themselves, it is really down to organizations ensuring they identify compromised hosts quickly and remediate. Based on our research on breakout time – i.e., the time it takes for an adversary to move laterally within a victim environment – security teams should detect threats on average in 1 minute, understand them in 10 minutes and contain them in 60 minutes to be effective at stopping breaches.”

Also lending his thoughts on the revival of the botnet, Lotem Finkelstein, Director, Threat Intelligence and Research for Check Point Software Technologies, said, Emotet, the most successful botnet in the history of cyber is making a comeback after the famous shutdown of its global operation almost 10 months ago. Emotet is responsible for the explosion of targeted ransomware we have seen over the past three years and its comeback might lead to a further increase in such attacks. It is no surprise that Trickbot and its infrastructure are being used to deploy the newly resurgent Emotet. This will not only shorten the time it would take for Emotet to build a significant enough foothold in networks around the world but it also a sign that, like in the old days, Trickbot and Emotet are united as partners in crime.”

Also Read: Intrusions Increase by 60% Across all Sectors: CrowdStrike Report

 

Phishers Leverage Bait Attacks to Harvest Personal Data

Bait attacks, Email Attacks

Adversaries constantly look for new techniques to make their phishing attacks more effective; bait attacks are one of those techniques. Most phishers leverage bait attacks to estimate which victim is willing to respond to their phishing scams. The latest report from cybersecurity solutions provider Barracuda revealed that bait attacks launched via free email services like Gmail make organizations in Asia-Pacific vulnerable to phishing and other email threats. More than 10,500 (35%) organizations worldwide admitted that they’d been targeted by at least one bait attack in September 2021.

To avoid detection, most bait attacks are launched using new email accounts from free email services, such as Gmail, Hotmail, and Yahoo! Mail. The analysis reveals that  91% of phishers use Gmail to launch bait attacks.

What is a Bait Attack?

A bait attack, also called a reconnaissance attack, is an initial email designed to harvest the targeted victims’ data, used in future phishing attacks. Attackers often use bait attacks to find out the victim’s email account or trick the victim into an email conversation that eventually leads to phishing attacks. Bait emails usually don’t have any text, malicious links, and attachments, making it difficult for traditional phishing detectors to prevent these kinds of emails.

Also Read: 5 Best Practices to Strengthen Email Security in your Organization

Barracuda’s Experiment

Barracuda’s research team experimented on bait attacks by responding to one of its employees’ bait emails. Initially, the attackers sent the bait email with a subject line ‘HI’ and empty body content. But after the employee’s response, the attacker sent a targeted phishing attack email. Phishers sent the initial email to verify the email address and the victim’s willingness to respond to emails.

Mitigation

While traditional phishing email filters and detectors are helpless in preventing bait attacks, Barracuda recommends certain email security measures to mitigate the risks associated with email threats. These include:

  • Deploying artificial intelligence-based techniques to identify and block bait attacks
  • Training employees to recognize and report bait attacks
  • Avoiding bait emails in employees’ inboxes

Mark LukieCommenting on how organizations can mitigate the significant risks of email attacks, Mark Lukie, Systems Engineer Manager, Barracuda, Asia-Pacific and Japan, said, “Email scamming accounts for about 39% of all spear-phishing attacks, and can take many forms, though in general these attacks are designed to steal the identity of the victim or trick them into disclosing personal information. Many of these scams include fake invoices, charities, and other schemes meant to lure the victim into sending money to the attacker.

To protect against email attacks, it’s important to make sure you deploy a robust email gateway to filter inbound and outbound email messages for malicious content, helping to detect malicious intent across all emails. But while this is a great start, as in the case of bait attacks, no gateway solution is watertight, so having a good API-based inbox solution as a secondary defense, can help to significantly strengthen your security posture overall. In addition to this, making sure your team receives regular security awareness training and is aware of the latest threats is crucial. Continuous spear-phishing stimulation training will help them to minimize online behaviors which could leave your organization vulnerable, while allowing them to recognize and report malicious content, as an additional line of defense.”

Lukie also stressed on how email attacks affecting businesses and organizations in Asia-Pacific region. “Cyberattacks are a global issue, and it’s rare for any attack type to be focused on one particular market or region. Instead, attacks such as these tend to permeate across the world, making it imperative for all businesses to remain vigilant in the face of these threats. Asia-Pacific continues to be an attractive target for cybercriminals, largely due to the sheer scale of the region, which is poised to take its position among the world’s top digital economies. In addition to this, countries across the region have varying levels of cyber readiness, and there is currently no unifying framework when it comes to cybersecurity strategy or policy, which again makes the region a prime target for cyberattacks,” Lukie added.

“AI and ML Will Be Enablers for Cybersecurity for the Foreseeable Future”

AI and ML

In the first half of 2021, cyber adversaries pried on opportunities to attack enterprise infrastructure and critical industries. Even the slightest security mismanagement motivated them to disrupt operations and exfiltrate data. As the year draws to a close, and with the holiday season around the corner, attack sophistication and scale could see a new shift. Looking at the current cybersecurity landscape, cryptocurrencies, mobile wallets, ransomware attacks targeting supply chains, and deepfakes are the most talked-about topics. At the same time, Artificial Intelligence (AI) and Machine Learning (ML) are among the hottest trends because, if leveraged appropriately, they can identify vulnerabilities and reduce incident response time.

To discuss this further, Pooja Tikekar, Sub Editor at CISO MAG interviewed Chuck Brooks, President of Brooks Consulting International and Adjunct Faculty at Georgetown University. Chuck is a Technology Evangelist, Corporate Executive, Speaker, Writer, and a Government Relations, Business Development, and Marketing Executive.

With over 74,000 followers on LinkedIn, 16,000 followers on Twitter, and 5,000 followers on Facebook, Chuck has built a sizeable community on social media, where he regularly shares the latest happenings and updates from the cybersecurity industry.

He was named The Top 5 Tech People to Follow on LinkedIn. He’s among the world’s 10 Best Cyber Security and Technology Experts, by Best Rated; in the Top 50 Global Influencer in Risk, Compliance, by Thomson Reuters; the Best of The Word in Security, by CISO Platform, and IFSEC’s #2 Global Cybersecurity Influencer.

Chuck was featured in the 2020 and 2021 Onalytica Who’s Who in Cybersecurity as one of the top Influencers for cybersecurity issues and risk management. He was also named one of the Top 5 Executives to Follow on Cybersecurity by Executive Mosaic; the Top Leader in Cybersecurity and Emerging Technologies by Thinkers360, and Top Global Top 50 Marketer by Oncon in 2019.

Chuck has an MA in International Relations from the University of Chicago, a BA in Political Science from DePauw University, and a Certificate in International Law from The Hague Academy of International Law.

Edited excerpts from the interview follow:

You’ve been named the Top Tech Person to Follow by LinkedIn. Would you like to tell our readers how you joined the cybersecurity industry and what your journey has been like as a leading influencer?

My journey as a cybersecurity expert and an influencer has been concentrated on four pillars: government, industry, media, and academia. In government, my journey in security first began as a senior legislative advisor to the late Senator Arlen Specter on national security, international, tech, and other issues. Next, I joined the Department of Homeland Security (DHS), where I was one of the first people brought on to help form the new agency. In my DHS role in government affairs, I had to keep abreast of policies, programs, budgets, and issues. But I also had to understand technologies to counter chemical, biological, radiation, and explosive threats (CBRNE), and learn about cybersecurity and interoperable communications. Back then, CBRNE was the prevailing concern, but homeland security quickly morphed into understanding cybersecurity threats from being digitally connected. I dove right into learning as much as I could on the subject matter and worked closely with leading experts from both government and industry from the outset.

After I left DHS several years later for the private sector, I kept my government networks active and continued to build my subject matter expertise on cybersecurity, technology, and policy. I served in executive roles relating to security for several major global corporations, including Xerox and General Dynamics Mission Systems.

The world of media has also been a passion for me as cybersecurity and emerging tech evangelist. I serve as a contributor to FORBES and a Cybersecurity Expert Advisor to Yahoo and The Washington Post. I am also the Visiting Editor at Homeland Security Today. In the last couple of years alone, I have written well over 200 articles and have been a featured speaker at dozens of conferences, events, and podcasts on homeland security, cybersecurity, and emerging tech.

In academia, I serve as Adjunct Faculty at Georgetown University’s Graduate Applied Intelligence Program and the Graduate Cybersecurity Risk Management Programs, where I teach courses on risk management, homeland security, and cybersecurity. I was an Adjunct Faculty Member at Johns Hopkins University, where I taught a graduate course on homeland security for two years. Teaching students who will be future leaders about cybersecurity is particularly gratifying.

In all, I enjoy being an influencer and sharing knowledge and insights on key issues, concepts, and policies relating to cybersecurity to everyone interested. What I want to accomplish as an influencer is to continue writing and speaking about the varied aspects of the topic and especially in educating others on how to help protect themselves. My advisory and board director roles with organizations and companies, and my role as a professor at Georgetown University are reflections of that passion and interest.

Cybersecurity has been a priority for most businesses; however, attack sophistication was amplified in 2021, and organized cybercrime groups profited due to the new normal of distributed work environments. Could you stress on some of the traditionally organized cybercriminal activities and their long-term impacts?

Several factors have transformed the cyberthreat landscape. Certainly, COVID-19 usurped the digital landscape and forced organizations to adapt to a remote working paradigm with little notice and preparation. Cybercriminals took advantage of security gaps and launched many successful attacks, and the number of breaches in 2021 has already surpassed the previous years.

Also, although it has been around for almost two decades, ransomware became a weapon of choice for hackers in the expanding digital landscape. The transformation of so many companies operating in a primarily digital mode had created more targets for extortion. And with the ability to get compensated in cryptocurrencies that are hard to trace, organized hacker gangs have taken advantage of the low-hanging fruit by exfiltrating data and holding it hostage to hospitals, municipalities, and critical infrastructure operators.

Another factor is the cooperation of cybercriminal gangs. They are being more collaborative and sharing both targets and sophisticated hacker tools on the dark web and dark web forums. There has been a consolidation of smaller hacker affiliates into larger hacker criminal families for a wide mix of attacks, including exploit kits, malware, and other coordinated activities, including hacking-as-a-service, and money laundering.

Also, threat actors, especially state-sponsored and criminal enterprises, have been investing some of their resources in emerging tech such as machine learning to employ more sophisticated means for discovering target vulnerabilities, automating their phishing attacks, and finding new deceptive paths for infiltrating malware.

Exploiting vulnerable supply chains has also been trending. Cyberattackers will always look for the weakest point of entry, and mitigating third-party risk is critical for cybersecurity. Supply chain cyberattacks can be perpetrated by nation-state adversaries, espionage operators, criminals, or hacktivists. Their goals are to breach contractors, systems, companies, and suppliers via the weakest links in the chain.

The bottom line is that as internet connectivity exponentially expands, so will the opportunities for attacks. Hybrid work environments, although more fortified, will likely still be successfully targeted by hackers who are collaborating and using sophisticated hacking tools. In the future, businesses and government must ramp up their capabilities to discover, monitor, and mitigate attacks, but that will not be an easy task.

Humans play a critical role in cybersecurity, and they’re often termed the “weakest link.” Cisco’s 2021 Cyber Security Threat Trends report reveals an alarming dominance of phishing attacks, accounting for 90% of data breaches. How can employers raise the bar in avoiding the exploitation of human behavior or psychology? And how can we have a better-integrated approach to security?

Humans certainly are the weakest link in cybersecurity. Usually because of negligence, but sometimes because of insider threats. The one consistent statistic I encounter every year is that phishing attacks account for most successful breaches. It is because phishing is easy to do for hackers, and it works. It used to be that you would get an email from a prince in a faraway land saying that he needs your bank account number to deposit funds. Now, a phish may appear to be a message from your boss, from a store where you shop, a bank, or even a friend. Hackers have come a long way in being able to mimic graphics and logos; they use social engineering to gain knowledge of your work, interests, and friend groups on social media platforms.

Companies can raise the bar by doing regular training with employees on how to recognize a phish. They need to teach the psychology of human behavior and where the vulnerabilities may lie in networks and devices from people. Gamification is a popular tool for that kind of training. Corporate programs need to include cyber hygiene to include strong passwords, multi-factor authentication, and incident response as a part of their operational mission. Also, if they must, they can restrict who has access to databases and sites on the interest via identity and access management tools. For insider threats, monitoring aberrant behaviors can work, but it is a challenge.

While on the topic, do you think businesses should assess employees’ security performance/awareness while evaluating other KRAs/goals? And would it help reinforce the human firewall?

I am a strong believer in accessing security performance awareness because a breach may have major consequences to a business legally and operationally. For many small and medium businesses, a breach could be fatal to their flow of commerce, reputation, and ultimately their future. Reinforcing the human firewall through access controls is also sensible. The more that your security team can control and monitor, the better the likely outcome.

What are some of the emerging technologies in security? Would these generate opportunities and create challenges?

We are proceeding in an era of “Malthusian” advances in science and technology, enabled by faster computing and ever-expanding data analytics. Those emerging technologies are significantly impacting cybersecurity. They include artificial intelligence (AI), machine learning, high-performance computing, cloud, edge computing, 5G, and eventually quantum technologies.

Computing systems that employ AI and ML are becoming more pervasive and critical to cyber operations and have become a major focus of cybersecurity research development and investments. Advanced 5G and wireless networks will benefit higher traffic capacities, lower latency, increased reliability, and enable processing and analytics in real-time. Edge computing strives to bring real-time computation, data storage, and operations closer to the device, rather than relying on a central location, avoiding latency issues. Technologies that improve capabilities for discovering, categorizing, monitoring, synthesizing, and automating the analysis of data are advantages in mitigating cybersecurity threats. Specifically, such tech can be used to bolster botnet detection and mitigation technology, data visualization tools, active malware protection, rootkit detection and mitigation technology, and incident response analytics.

Emerging tech can be a two-way street for good and bad. Artificial intelligence and machine learning can be used by hackers to automate target selection and more. Threat actors, especially state-sponsored and criminal enterprises, are becoming more sophisticated by searching for vulnerabilities and infiltrating malware by adapting (and automating), enabling machine learning, deep learning, artificial intelligence, and other analytic tools. SolarWinds was more than a wakeup call for those realities.

Also, the emergence of the Internet of Things presents special security challenges. There are an estimated 44 billion IoT endpoints today and trillions of sensors connected to those endpoints.  Hackers have many attack options and entries for inserting malware into such a large and unregulated attack surface.

In addition to my previous question on emerging technologies, what are some of the AI and ML trends in cybersecurity that we can expect in 2022?

The core of AI smart capabilities is rooted in its subcomponent of machine learning, ML. AI is largely used to protect networks as well as increase data security and endpoint security. There are some specific areas where AI technology will contribute to making cybersecurity smarter include:

  • AI can provide a faster means to detect and identify cyberthreats. Cybersecurity companies will be using software and a platform powered by AI that monitors real-time activities on the network by scanning data and files to recognize unauthorized communication attempts, unauthorized connections, abnormal/malicious credential use, brute force login attempts, unusual data movement, and data exfiltration. This allows businesses to draw statistical inferences and protect against anomalies before they are reported and patched.
  • AI will impact Incident Diagnosis and Response capabilities.
    While descriptive analytics provided by network surveillance and threat detection tools can answer the question “what happened,” incident diagnosis analytics address the question of “why and how it happened.” To answer those questions, new software applications and platforms powered by AI can examine past data sets to find root causes of the incident by looking back at change and anomaly indicators in the network activities
  • AI will also enable better cyberthreat intelligence reports by analysts. Next year analysts will be able to use AI tools to generate automated cyberthreat intelligence reports (CTI). Cyberthreat intelligence reports provide the indicators and early warning necessary to better monitor unusual activities on a given network and detect more rapidly cyber threats.

AI and ML will be an enabler for cybersecurity for the foreseeable future. As the computational capabilities and digital complexity of global enterprises continue to grow, AI-powered tools and automation enablement will play an increased and integral role in keeping us cyber-safe in 2022 and beyond.

Tell us your top three cyberthreat predictions for 2022.

  • Critical Infrastructure (CI) and supply chain will be targeted even more in 2022 (state-sponsored, cybercriminal gangs) with ransomware and malware attacks. CI is a high-profile target for both geopolitical and economic considerations for hackers. This CI includes defense, oil and gas, electric power grids, health care, utilities, communications, transportation, education, banking, and finance. Protecting CI Industrial Control Systems (ICS), Operational Technology (OT), and IT systems from cybersecurity threats is a difficult endeavor. They all have unique operational frameworks, access points, and a variety of legacy systems and emerging technologies. Protecting the CI supply chain in IT and OT systems will be a public and private sector priority. A special concern for the supply chain is Third Party risk and visibility of partners in the chain. Investment and risk strategies will expand in conducting vulnerability assessments and filling operational gaps with cybersecurity tools. Tools include Data Loss Prevention (DLP), encryption, identity and access management solutions, log management, and SIEM platforms.
  • Despite efforts to attract workers to security and tech jobs, the qualified cybersecurity worker shortage will continue to pose major operational challenges. Both the public and private sectors are currently facing challenges from a dearth of cybersecurity talent. A report out from the firm Cybersecurity Ventures estimates there are 3.5 million unfilled cybersecurity jobs in 2021. 2022 is not showing any signs of improvement in hiring. 
  • The Internet of Things (IoT) will pose a growing cybersecurity risk. IoT’s exponential connectivity is an ever-expanding mesh of networks and devices. IoT incorporates physical objects communicating with each other, including machine to machine and machine to people. It encompasses everything from edge computing devices to home appliances, from wearable technology to cars. IoT represents the melding of the physical world and the digital world.  They differ from conventional computers as they are highly specialized and usually small, both in physical size and computing capacity. A cybersecurity challenge of IoT is the lack of visibility and the lack of ability to determine if a device has been compromised and not performing as intended. The increased integration of endpoints combined with a rapidly growing and poorly controlled attack surface poses a significant threat to the internet of things. Protecting such an enormous attack surface is no easy task, especially when there are so many varying types and security standards on the devices. It will only get worse in 2022 as connectivity grows. 

Lastly, is there anything you’d like to add?

Thank you for allowing me to share some of my cybersecurity perspectives with your readers.


About the Author

Pooja Tikekar is the Sub Editor at CISO MAG, primarily responsible for quality control. She also presents C-suite interviews and writes news features on cybersecurity trends.

More from the author.

Cybersecurity is a Low Priority for India’s Private Sector

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

In the movie Die Hard 4.0, John McClane and a young hacker team up to thwart the plans of cyber-terrorist Thomas Gabriel in Washington D.C. Gabriel’s plan is known as “fire sale” which is a coordinated attack on the US critical infrastructure such as financial and utility systems. But the consequences of cyberattacks were not fully understood as the cyberattack was a fantasy till it become a prolific feature in the second half of the 21st century.

By Mangesh Sawant, Partner, Homeland Security, Global Security, Geopolitics and Military Studies ExeSTAT India Columbia University Alumni

Cyber operations are an integral part of modern warfare. Cyberweapons are tools of war that disable a nation’s critical infrastructure without firing a single bullet. It provides states such as North Korea and China with a degree of plausible deniability. China uses cyberattacks as a way to advance its economy. Critical infrastructure the lifeline of any nation is the prime target as attacks can have a devastating effect on the economy. Electricity grids, hospitals, and telecommunications, and transportation networks will come to a standstill. Ships will be sent off course to unplanned locations. Logistics will be disrupted as supplies will arrive late or not at all.

Nation-states hire hackers who exploit the operational technology (OT) systems gaps in critical infrastructure networks. Targets are no longer limited to the defense industry as multinational organizations and small businesses have been disrupted by cyber attacks. US and India are the prime targets for Chinese cyber operations in an era of geopolitical competition.

Colonial Pipeline suffered a ransomware cyberattack that impacted computerized equipment managing the pipeline.  The cyberattack which shut down 5,500 miles of pipeline from Texas to New Jersey was the largest cyberattack on the oil and gas industry target in U.S. history.

Apart from oil and gas the electricity sector is the favorite target of nation-states. Hackers target companies that generate and distribute electricity across the country. About 70% of power transformers in the US are at least 25 years old and were not designed for the digital age. Disruption of power generation across the grid for five days would cause an economic loss of $193.5 billion. This is equivalent to approximately 30 percent of the Department of Defense’s 2021 budget. The US could only afford another three to five days with the Colonial Pipeline crisis before mass transit would have to limit operations according to a confidential assessment prepared by the Energy and Homeland Security Departments. Ransomware will be the prime threat to the private and government sectors.

India: An Ostrich Between a Wolf Pack

Cybersecurity is becoming a top priority for the U.S. as the government and the private sector are implementing cybersecurity standards. U.S. President Joe Biden, Congress, and the senate are implementing plans to protect the critical infrastructure. US Department of Defense has created a Cyber Command which is an integral part of war planning. The U.S. Justice Department has prioritized ransomware attacks on the same level as terrorism. The U.S. private sector is installing access management systems and upgrading security measures. The U.S. government is sharing cyber intelligence with the private sector. The NSA and DHS have been issuing advisories to the private sector and the public about the increase in adversary capabilities and activities for years. The NSA had issued an advisory for critical infrastructure owners to review their OT systems. A national security memorandum outlined the implementation of better cyber security standards while the US government had warned pipeline operators about ransomware threats. Cyberthreat is so serious that the FBI director made direct comparisons to 9/11.

India remains vulnerable to cyber-attacks while the U.S. has taken measures to fortify its cyber defenses. It is a widely known but little appreciated fact that cyber security is a low priority for India’s private sector. India seems to be lacking in cyber security culture, installation of security controls, and implementation of best practices and compliance and regulatory requirements. The present cyber governance management has a negligible impact on lowering the cost of cybercrime.

India is the second most targeted country for cyber attacks globally while ransomware accounted for 40% of all attacks. India was among the top three Asian nations affected by DNS cyber attacks. In India, an organization was being attacked on average 1,738 times per week in the first six months of 2021, compared to 757 attacks per organization globally. Manufacturing, insurance, legal, and healthcare are the most impacted sectors.

The private sector seems to prefer the ostrich approach. A large part of the private sector depends on legacy infrastructure with inadequate cyber security protection. Organizational networks are at risk as backend security infrastructure is not installed even though there is widespread digital adoption across the private sector. The level of understanding of cloud security remains dangerously low. Cyber attacks are becoming more sophisticated yet there is a lack of understanding among the end-user. Prevention continues to be limited to the installation of antivirus and malware protection software by employees on their personal devices. There is a largely unorganized and fragmented sector of cyber security service providers who install illegal software. An absence of a stringent legal cyber framework is affecting the identification and prosecution of cybercriminals.

India’s organizational cyber infrastructure is out of date and poorly maintained. Hackers have unimpeded access to networks. Companies don’t patch the old software, default passwords are not changed, security and incident response plans are lacking and two-factor authentication is not implemented. At the Colonial pipeline, it came down to the lack of multi-factor authentication on an old employee account.

A majority of the business sector consists of small and medium-scale enterprises which remain highly vulnerable to sophisticated attacks. The sector is unprepared to deal with a cyberattack as businesses don’t employ sufficient IT professionals while budgetary allocations are acutely insufficient.

Costs to Company

The impact of a cyber incident will lead to business disruption. Ransomware breaches are financially damaging because they affect the balance sheet, productivity, and cost efficiencies. The cost of the ransomware payment – the issue that receives most of the attention – is minor compared to the cost of repairing the breach, information loss, reputational loss, equipment damage, and erosion of profit margins. A class-action suit was filed in federal court in Georgia against Colonial Pipeline. Plaintiffs alleged that the Defendants failed to implement and maintain security measures and procedures.

Ransomware costs businesses more than $75 billion per year while companies lost around $8,500 per hour due to ransomware-induced downtime. According to a survey 90% of clients of 1,100, IT professionals suffered ransomware attacks. The average ransomware payment in 2021 increased by 82% year over year to $570,000 and around 121 incidents have been reported in the first half of 2021, up 64% year-over-year. The largest ransom demand observed so far in 2021 is $100 million. Around 41 percent of insurance claims in the first quarter of 2021 were related to ransomware. High levels of investments are required to improve the private sector’s cybersecurity framework and regulatory compliance in India.

Conclusion

The IT landscape is vulnerable to cyber attacks due to global interconnectedness and the widespread use of devices. Traditional network defenses with multiple layers of disjointed security technologies are unable to meet the cybersecurity needs of the 21st century. The use of IoT devices will accelerate as 5G is implemented which will lead to large-scale, multi-vector fifth-generation attacks. Organizations need a better way to secure their infrastructure and provide unified access control to data, services, and applications.

The digital age has increased productivity and efficiency, but many Indian organizations are unable to manage the risks that accompany it. Organizations are prioritizing short-term growth and cost-cutting at the expense of cyber security. Cyber risks have increased due to the expansion of remote work access during the COVID-19 pandemic. This has led to an increase in cybercrimes by 600%. The pandemic has widened the attack surface.

In another Die Hard movie John McClane takes on the terrorists who hijack ATC systems leaving aircraft stranded midair but John is unavailable in the offline and the real world.  A whole government approach in collaboration with the private sector is required as digital technology is now the most valuable asset in the world. Deploying the latest technologies is what separates secure companies from their weaker peers.

Adversaries such as China, terrorists, and cybercriminals have learned how little it takes to provoke chaos across the country through the disruption of critical services. This underscores the need for effective cyber defenses to protect critical infrastructure. Cyber operations against strategic targets will increase in the future. Consider it as an electromagnetic attack on the infrastructure which disrupts services but does not destroy the infrastructure.

Future conflicts will be fought in organizations and not on the battlefields of traditional warfare. Geographical borders are disappearing only to be redrawn in company premises. Adversaries will invade countries through organizational networks. The private sector should harden its cyber defenses while the military protects the nation’s borders.  Cyberattacks are the 21st national security threats comparable to conventional warfare.


About the Author

Mangesh SawantMangesh Sawant has a Masters in International Affairs Degree from Columbia University, New York, where he concentrated in international security policy. He is a subject matter expert on global security, military studies, Homeland Security, and geopolitical risk analysis. Mangesh has more than 18 years of experience in studying military strategy and tactics, warfare, conducting research, policy analysis and formulation and developing case studies and lessons learned. His articles are published in The National Interest, Small Wars Journal, Modern Diplomacy, Eurasia Review, E-International Relations, Indian Defense Review, Security Management. Geopolitical Monitor, Internationale Politik, Over the Horizon Journal and The Geopolitics. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

BotenaGo – A New Malware Targeting Millions of IoT Devices

BotenaGo, malware over encrypted connections

Cybersecurity researchers at AT&T Labs uncovered a new malware variant targeting routers and IoT devices. Tracked as BotenaGo, the malware is leveraging over 30 exploit methods to compromise the targeted devices, exposing millions of IoT devices and routers to malware infections. The researchers stated that BotenaGo could deploy malware payloads that are difficult to detect and reverse engineer. While the threat actors behind the BotenaGo malware campaign are unknown, multiple anti-virus suites found that BotenaGo is a variant of Mirai malware.

“The malware creates a backdoor and waits to either receive a target to attack from a remote operator through port 19412 or from another related module running on the same machine. It is yet unclear which threat actor is behind the malware and number of infected devices,” the researchers said.

Using Go Language

Researchers stated that attackers wrote BotenaGo malware codes using the Go programming language.  Go, also known as Golang, is an open-source programming language designed by Google. The demand for Go language has increased dramatically after several malware creators leveraged it to write malware codes.

“Some of the reasons for its rising popularity relate to the ease of compiling the same code for different systems, making it easier for attackers to spread malware on multiple operating systems,” the researchers added.

How BotenaGo Exploit Works

Initially, the BotenaGo malware attack scans for vulnerabilities online and maps the potential victims to attack functions. It then queries the target with a GET request and starts exploiting it. BotenaGo attackers mainly exploit the vulnerabilities in connected devices and execute remote shell commands.

BotenaGo incorporates 30 exploiting techniques based on the target and vulnerability type. Some of the vulnerabilities that BotenaGo has targeted include:

  • CVE-2020-9377, CVE-2015-2051, CVE-2016-11021 – D-Link routers
  • CVE-2016-1555, CVE-2016-6277, CVE-2017-6077, CVE-2017-6334 – Netgear devices
  • CVE-2020-8958 – Guangzhou 1GE ONU
  • CVE-2017-18368, CVE-2020-9054 – Zyxel routers and NAS devices
  • CVE-2020-10987 – Tenda products
  • CVE-2019-19824 – Realtek SDK based routers
  • CVE-2014-2321 – ZTE modems

Mitigation

Cybercriminals continue to create new malware and malware deploying techniques to target unwitting users. Practicing robust cyber hygiene and some actionable security measures could help mitigate the risks from evolving malware threats.

How Cross-Site Scripting Attacks Work and How to Prevent Them

Cross-site scripting attacks

With the prevalence of hacker intrusions, the consequences of not addressing the vulnerabilities and other security loopholes in your network systems could be severe. Adversaries often target unpatched vulnerabilities to compromise targeted systems, and one of their most common attack vectors is Cross-Site Scripting (XSS) attack.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is a Cross-Site Scripting (XSS) Attack? 

Cross-site scripting (XSS) attack is an injection attack that allows hackers to inject malicious code into the targeted website or web application. XSS attackers primarily target web pages or web applications that use unsecured processes to validate user inputs. Threat actors often leverage forums, search engines, login forms, comment sections, message boards, and websites that allow user comments to deploy their malicious script via XSS attacks.

How a Cross-Site Scripting (XSS) Attack Works

Cross-site Scripting (XSS) is a common vulnerability observed in websites and web applications that accept user inputs. Threat actors exploit this vulnerability by injecting malicious JavaScript scripts or codes into the targeted website’s URL or content. The malicious scripts automatically deploy and infect the victim’s device when an unsuspecting user visits that website.

Types of Cross-Site Scripting (XSS) Attacks

1. Stored XSS Attack 

Also known as a persistent XSS attack, a Stored XSS attack occurs when an attacker injects a malicious code directly into a vulnerable server. The malware is permanently stored on the targeted servers in repositories such as a database, message forum, visitor logs, and comment sections in stored XSS attacks.

2. Blind XSS Attack 

A blind XSS attack, also known as a persistent XSS attack, occurs when a hacker deploys a malware payload on the targeted server and executes it via backend applications.

3. Reflected XSS Attack 

Reflected XSS attack involves spreading the malicious code via different attack vectors like a phishing email, message, or website. Reflected XSS attackers trick users into clicking malicious links disguised as legitimate content on a compromised website.

Risks of Cross-Site Scripting (XSS) Attacks

Most browsers could fall victim to XSS attacks if the web applications or websites fail to validate the malicious codes inserted by XSS attackers.

An XSS attack could allow an attacker to:

  • Steal cookie details
  • Alter user settings
  • Hijack user sessions
  • Turn trusted websites into malicious ones
  • Display inappropriate content on the targeted website
  • Display malicious content or malware disguised as legitimate content
  • Perform impersonation and defacement attacks

How to Prevent Cross-Site Scripting (XSS) Attacks 

Though the consequences of an XSS attack are severe, practicing proper cyber hygiene measures would help mitigate the risks. These include:

  • Website developers and owners must ensure that their websites and web applications will validate/sanitize the user inputs before displaying them online.
  • Users must avoid clicking/downloading suspicious URLs/attachments online.
  • Websites or web applications that accept user inputs must filter unknown code inputs like HTML and JavaScript.
  • Regularly scan and address security vulnerabilities on web pages and applications.

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Trickbot Remains the Most Prevalent Malware

Trickbot Malware

The evolution of new malware variants has become prevalent in the cyberthreat landscape. Cybercriminals continue to create novel malicious codes, botnets, or redesign old malware variants to compromise the targeted networks without getting caught. Cybersecurity solutions provider Check Point reported that modular botnets and banking Trojans have become widespread, targeting critical sectors across the globe. Its latest Global Threat Index for October 2021 report revealed that the infamous Trickbot Trojan remains the most prevalent malware variant, affecting 4% of organizations worldwide. It’s also found that “Apache HTTP Server Directory Traversal” is the most exploited vulnerability in 2021.

Top Malware Families

1. Trickbot 

Trickbot malware was once a banking Trojan and evolved as a prolific malware used in several cyberattacks against businesses and individuals across the globe. Trickbot’s capabilities include lateral movement in the network for maximum damage, exfiltrating user credentials from browsers, stealing cookies and OpenSSH keys, theft of RDP, VNC, and PuTTY credentials, and installing additional payloads like ransomware.

2. XMRig

XMRig is an open-source CPU mining software used for the mining process of the Monero cryptocurrency and was first seen in the wild in May 2017. The malware has affected 3% of organizations globally.

3. Remcos

Remcos is a remote access trojan (RAT) that first appeared in the wild in 2016. Remcos distributes itself through malicious Microsoft Office documents attached to SPAM emails and is designed to bypass Microsoft Windows UAC security and execute malware with high-level privileges. This malware has affected over 2% of organizations across the globe.

Also Read: Best way to handle malware attacks is automation and continuous monitoring

Most Targeted Sectors

While attackers distributed their malware variants globally, the most targeted industries are:

  • Education and Research sector
  • Communications
  • Government and Military

Top Exploited Vulnerabilities

Check Point stated that Web Servers Malicious URL Directory Traversal is the most commonly exploited vulnerability in October 2021, affecting over 60% of organizations globally, followed by Web Server Exposed Git Repository Information Disclosure, impacting 55% of organizations worldwide, and HTTP Headers Remote Code Execution with a global impact of 54%.

“The Apache vulnerability only came to light early in October and is already one of the top ten most exploited vulnerabilities worldwide, showing how fast attackers move. This vulnerability can lead threat actors to map URLs to files outside the expected document root by launching a path traversal attack. It’s imperative that Apache users have appropriate protection technologies in place. This month, Trickbot, which is often used to drop ransomware, is the most prevalent malware. Globally, one out of every 61 organizations is impacted by ransomware every week. That’s a shocking figure, and companies need to do more. Many attacks start with a simple email, so educating users on how to identify a potential threat is one of the most important defenses an organization can deploy,” said Maya Horowitz, VP of Research at Check Point Software.

Mitigation

Prakash BellExplaining on how organizations can mitigate the significance risks from evolving malware threats, Prakash Bell, Customer Success Head and Security Engineer Team Lead, Check Point Software Technologies, India, said, “Several Malwares are very difficult for a “non-technical” eye to recognize. Therefore, if you suspect you have been infected it would be wise to consult with a security professional or use third party tools and protections designed to identify, block and even remove this threat from your computer.”

Prakash Bell also recommended certain security precautions which include:

  1. Go to Check your username in the OS
  2. Go to /Users/[username]/Library/LaunchAgents directory
  3. Check for suspicious filenames in this directory (example below is a random name) /Users/user/Library/LaunchAgents/com.wznlVRt83Jsd.HPyT0b4Hwxh.plist
  4. Remove the suspicious file

Some preventive measures to both Mac and Window users:

  1. Not open suspicious attachments
  2. Avoid visiting suspicious websites
  3. Use 3rd party protection software to help identify and prevent malicious behavior on their computer

Costco Store Payment Terminal Breached by Data Skimmer

Costco Data Skimmer

Costco Wholesale Corporation, a big-box retail store company, discovered a breach at one of its retail store terminals where a card skimming device was being used at the payment counter to skim data.

On discovering the payment card skimming device, the company issued notification letters updating customers about the possibility of their card data being stolen if they had made a recent purchase at that particular store.

Costco said, “We recently discovered a payment card skimming device at a Costco warehouse you recently visited. Our member records indicate that you swiped your payment card to make a purchase at the affected terminal during the time the device may have been operating.”

“If unauthorized parties were able to remove information from the device before it was discovered, they may have acquired the magnetic stripe of your payment card, including your name, card number, card expiration date, and CVV,” Costco alerted.

A routine inspection of pin pads resulted in device detection by the Costco personnel, and law enforcement agencies were notified.

As a cautionary measure, the company has asked its customers to check their recent bank and credit card statements for unauthorized charges or transactions. In addition, it is offering the victims IDX identity theft protection services, which provide 12 months of credit monitoring, a $1 million insurance reimbursement policy, and ID theft recovery services.

The Skim Game

The device was supposedly a physical device that is placed on the payment card scanner to intercept details from the magnetic strips of the cards.

In an era where malicious cyberattacks like ransomware and phishing emails are more popular, old-school methods like data skimming cards are less heard of. Digital skimmers like Magecart attackers have been found distributing PHP web shells, known as Smilodon or Megalodon, disguised as favicon to obtain remote access to the targeted servers.

Security researchers from Malwarebytes had found the Magecart Group 12, a cybercriminal gang best known for their attacks on online stores, targeting Magento online stores to pilfer customers’ sensitive information. Magento is an e-commerce platform that allows websites to create their online store.

“This technique is interesting as most client-side security tools will not be able to detect or block the skimmer. There are several ways to load skimming code but the most common one is by calling an external JavaScript resource. When a customer visits an online store, their browser will request a domain hosting the skimmer. Although criminals will constantly expand on their infrastructure it is relatively easy to block these skimmers using a domain/IP database approach,” Malwarebytes said.

Typically, these fraudulent transactions are common at ATMs, fuel pumps, and POS terminals where card readers are manipulated to store or ape the swiped cards details.

As pandemic regulations ease globally, citizens flock supermarkets, restaurant chains, and other public services along with continued online purchasing. The threat surface is only ever-expanding, and all we can do is be alert and mitigate risk with precautionary measures to prevent data skimming.

Also read: New “Baka” Skimmer Designed to Evade Detection: Visa