Home Blog Page 41

The Importance of 5G Security in Today’s World

5G

The wireless communication technology has stepped into the era of 5G, which is a label to an immensely fast and sophisticated data network. 5G has the potential to make the world much more connected due to its critical features like high speed, improved efficiency, better mobility support, high connection density, and capability to connect to many devices. Compared to its predecessor 4G LTE, which was not a viable option at remote places that lacked access to traditional broadband networks, 5G can be deployed as a viable option due to its higher speeds (up to 10 Gbps), lower latency (60 to 120 time faster than 4G), and increased capacity (30-300 GHz) features.

By Ankit Satsangi, Chief Technology Officer and Co-founder of AHAD 

Many public and corporate organizations have adopted or intend to adopt 5G towards their network architecture, and furthermore, 5G will connect to more than seven trillion wireless devices and networks to shrink the average service creation time. With the help of 5G, emerging technologies such as cloud computing, Software Defined Networking (SDN), and Network Function Virtualization (NFV) are being implemented by organizations to meet the growing demands of users, as it helps provide a flexible network operation and management within the constraints of operational expenses[1]. Some of the advanced and beneficial features could be listed as:

  • Device-centric, distributed, programmable, and cloud-based design
  • High data speeds
  • 1-10 Gbps connections to endpoints
  • One millisecond end-to-end round-trip delay
  • Low power consumption
  • Improved connectivity even in remote locations
  • Higher capacity for supporting devices

The 5G technology thus helps connect different digital aspects and needs to provide society with high service availability while using a diverse set of technologies. However, just like any other digital technology where its rapid growth is accompanied by potential security issues, implementing 5G technology escalates the security focus to another level, demanding advanced safeguards.

Importance of 5G Security

Security in the cyber landscape has always been critical and on the agenda of organizations with a digital presence and invested in telecommunications. The advances in technology in environments such as virtualization, IoT, software-defined networking (SDN), network

function virtualization (NFV), edge computing, and Industry 4.0, when met with equally broad yet deteriorating cybersecurity, will have a significant impact on the security and functionality. Some of the 5G standards are flexible enough to allow an overlap of different types of physical and virtual elements between the radio access network (RAN) and core network. Separating the RAN and core network function in the telecommunication environment is sure to affect the performance but is also accompanied by related security impacts such as SDN, NFV, and edge computing-related issues.

In the information technology landscape, 5G security implications can result in decreased traffic visibility, where a lack of WAN solutions like Secure Access Service Edge (SASE) could result in some business traffic visibility. As the growth of 5G and its ability to connect to a large volume of the device is directly connected to the increased IoT usage, the latter’s security implications also affect the former. As IoT devices generally have had poor security, the vulnerability will supposedly expand to the organization’s security framework incorporated with IoT and corresponding 5G technology[2]. Hence, organizations need to deploy IoT security solutions to ensure that their devices are protected. Similarly, the limited 5G supply chains will also lead to security issues as new mobile technologies are more software dependent than traditional mobile networking, which increases the possible attack surface[3]. The telecom network is equally important when conceptualizing security, and 5G security involves understanding aspects like:

  • Increased stake value
  • Risk tolerance
  • Physical & virtual dependencies
  • Security standards, protocols, deployments, and operations
  • Proactive cybersecurity measures
  • Vulnerability management
  • Supply chain security

5G Security Challenges

Organizations with critical infrastructure such as healthcare, energy, and transport tend to incorporate 5G network for faster and efficient operations. But these critical infrastructures will require more security to ensure safety. For, instance security breaches and interruption/shutdown of operations in the energy sector or a single power supply system can be catastrophic for dependent infrastructures. Similarly, there exists a risk of data compromise in the transport layer of the 5G network. Hence, mandating the need to investigate and highlight the important security challenges in 5G networks, and explore potential solutions to mitigate these threats and secure the 5G network[4]. Some of the basic challenges in the 5G network highlighted by Next Generation Mobile Networks (NGMN) could be listed as:

  • Increased network traffic (flash traffic) due to an increase in the number of connected devices in the 5G network and IoT.
  • Need for radio interface security, where encryption keys are sent over insecure channels.
  • Lack of cryptographic integrity and protection for user plane
  • Service-driven constraints on the security architecture lead to the optional use of security measures.
  • Un-updated user-security parameters in roaming, i.e., switching network from one operator network to another, leading to security compromises.
  • Denial of Service (DoS) attacks on the infrastructure due to visible network control elements and unencrypted control channels.
  • Denial of Service (DoS) attacks on end-user devices due to poor security of operating systems (OS), applications, and configuration state.
  • Signaling storms due to lack of coordination in distributed control systems such as the Non-Access Stratum (NAS) layer of Third Generation Partnership Project (3GPP) protocols.

5G Network Security Capabilities

The 5G network, though having its own challenges, was originally designed with features to address threats faced by previous network generations. Some of the features that can strengthen the 5G network’s security postures and address existing security risks could be classified under infrastructure, standalone and non-standalone.

Infrastructure security capabilities

  • Trusted hardware: This involves securing the IoT devices on LTE networks using either protected hardware or virtualized processing environment, which is done at the network level with hardware protection modules (HSMs). These secure components assist with isolating and storing cryptographic processes, encryption, authentication, and cryptographic keys from all network operations.
  • Isolation and policy enforcement: This involves allowing the virtual operations to run on trusted hardware that meets the specified asset policies. The data is encrypted at the virtual hard drive level, where the virtual nodes meet desired trust requirements. A well-defined SDN technology tends to allow authorized network communications between different components.
  • Compliance and visibility: This involves using technical mechanisms that enforce security over the lifecycle of platforms. The secured Workload environment will help organizations mitigate risks and meet compliance standards by documenting and monitoring configuration changes.

Standalone security capabilities

  • User privacy: Devices, while connecting to the cellular network, need to identify themselves and its user, allowing the network operators to limit the access of the network to only approved devices and users. Where many 3GPP-based networks generally distinguish subscribers by assigning them a globally unique identifier known as the Subscription Permanent Identifier (SUPI) to each and then submitting the user’s identifier to the device throughout the link phase. The 5G specifications new security feature allows devices to identify themselves using Subscription Concealed Identifier (SUCI) instead of SUPI during the network link process. This increases protection prevents attackers from observing the link process, capturing the user details, and monitoring the user location.
  • User plane integrity protection: When a device transmits traffic to a cellular network through the user plane, it compares with the Control Plane, which is transmitting messages for network management and scheduling. Hence, the 5G technology allows user plane encryption by the device to protect user privacy. However, researchers have shown that attackers can exploit a lack of User Plane integrity and redirect data such as DNS queries, etc. Thus, the 5g network tends to incorporate a new security feature that gives the device an option to provide the User Plane with integrity protection and encryption.
  • CU/DU split security: Spitting the 5G base stations into Centralized Unit (CU) and Distributed Unit (DU) allows the operation of security-sensitive functions closer to the core network in a more trusted environment.
  • Security Edge Protection Proxy (SEPP): For securing roaming features of inter-operator network connections, SEPP can be used by 5G to interconnect securely. SEPP allows end-to-end confidentiality and integrity between the source and target network for all roaming data traffic and is hailed as a necessary MNO interconnect feature by the 5G standards such as 3GPP TS 23.501 and TS 23.502. New critical security updates include Security Edge Defense Proxy that offers enhanced protection against existing roaming vulnerabilities.

NSA Security Capabilities

  • False base stations: Rouge or false base stations (also known as false stingrays) tend to mimic all network tasks. Though the 3G network majorly addressed this security issue, some devices can still connect to a 2G base station, where the rogue base stations keep them connected to a mimic station. The threat actor aims to identify and track users by asking their devices to send their long-term identifier IMSI. The 5G network addresses this issue through its feature of refreshing temporary identifiers in order to detect false base stations and can also secure the permanent identifier through encryption.

Conclusion

The 5G network technology is becoming more and more prevalent and usable for both general and business adoptions, but security implications also accompany it. Though the 5G network trends incorporate many security features that mitigate pre-existing threats in the 3GPP-based network, organizations need to adopt rigorous security measures. As organizations tend to implement 5G technology as a monitoring and control solution at remote locations, but their existing critical infrastructure possesses a high-risk factor. Thus, there is a need for solutions that securely deploy IoT and other devices on 5G networks tailored to specific industry needs.


About the Author

Ankit SatsangiAnkit Satsangi is a global thought leader and cybersecurity advisor with more than nine years of experience in cyber resilience. He is currently the Chief Technology Officer and co-founder of AHAD info tech. Satsangi is a security professional with expertise across endpoint and network protection. His research interests involve but are not limited to, penetration testing, incident response, risk management, SOC automation, SOC orchestration, carbon black incidence response, vulnerability assessment, Data Leakage Prevention (DLP), and social media and email security.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

SQL Injection Attack: Why is it a Serious Threat?

SQL Injection

SQL Injection Attacks are amongst the most prevalent type of attacks today, which primarily targets web applications. With the rise in the use of web applications because of their efficiency and convenience, attackers have developed various techniques to infiltrate the vulnerability in web apps and gain unauthorized access to obtain confidential data.

One such method is the SQL injection, which utilizes malicious SQL commands that, when executed, modify the backend code, that is, edit, delete, or insert data into the database affecting the CIA triad — Confidentiality, Integrity, and Authenticity of the data. On successfully executing the SQL injection commands, the attacker can spoof identity, tamper with data, disclose data, take complete control over the database, cause repudiation issues, etc. In simple terms, SQL injection, also known as SQLI, is a code injection method used by attackers to gain access and modify the data present in the database of web applications.

See also: What is an SQL Injection Attack and How to Prevent it?

Various organizations, as well as customers, utilize web applications based on their necessities. Upon successful execution of an SQL injection attack, the impact on the businesses is devastating. Apart from the exposure or manipulation of data, the trust between the organization and its customers is affected, tarnishing the company’s reputation in the market. There are numerous types of SQL injection methods such as:

Error-based SQL injection: This type of injection technique causes the SQL databases to send error messages. As a result, the attackers gain information about the structure of the database of the web applications.

Blind SQL injection: Also known as Inferential SQLI, it is the act where an attacker sends payloads to the server. It is aimed at asking true or false questions to the database. Based on the response and the behavior of the sent payload, the attacker learns about the database structure. However, the attacker cannot view the data or information transmitted from the website database, and thus, it is known as name-blind SQLI.

Union-based SQL injection: In this SQL injection attack, the attacker uses the SQL UNION operator, which merges the results of two or more SQL SELECT operators, displayed as a part of the HTTP response.

Organizations and professional experts need to understand the intensity of such attacks. SQL injection attack prevention is essential for every organization to secure and protect its confidential data. One can become a professional web app hacker and security expert to judge and verify the security strategies of an organization’s web applications.

EC-Council’s Web Application Hacking and Security certification provide the necessary skills required to identify and mitigate web app vulnerabilities and exploitable threat factors. Become a certified Web Application Hacking and Security Professional today.

Get Certified Today

SQL Injection

CISA Orders Federal Agencies to Mitigate Actively Exploited Vulnerabilities

actively exploited vulnerabilities, Vulnerabilities, risk-based vulnerability management

The threat of unpatched vulnerabilities is one of the pressing security issues for organizations worldwide. Despite necessary cybersecurity initiatives, threat actors continue to exploit unpatched flaws to penetrate critical systems. The Cybersecurity and Infrastructure Security Agency (CISA) recently issued a Binding Operational Directive (BOD) to reduce the risk of actively exploited vulnerabilities. The new Directive, which applies to all software and hardware found on federal information systems, requires federal civilian agencies to remediate such vulnerabilities within specific timeframes.

Thousands of Unpatched Flaws 

CISA found that malicious actors often look for known unpatched vulnerabilities and exploit them within a short time. From 2015-2018, the number of new flaws surged from 6,487 to 17,305, and 9,883 of these were rated “high” and “critical.”  According to CISA, over 18,000 vulnerabilities were identified in 2020. Both public and private sector organizations find it difficult to remediate the growing security flaws.

“This Directive addresses this challenge by driving mitigations of those vulnerabilities that are being actively exploited to compromise federal agencies and American businesses, building upon existing methods widely used to prioritize vulnerabilities by many organizations today,” CISA said.

Order to Agencies

CISA has released a list of exploited vulnerabilities that expose government network systems to security risks. It has also ordered agencies to remediate them in the stipulated timelines.

  • Within 60 days of issuance, agencies shall review and update agency internal vulnerability management procedures by this Directive. If requested by CISA, agencies will provide a copy of these policies and procedures.
  • Establish a process for ongoing remediation of vulnerabilities that CISA identifies, through inclusion in the CISA-managed catalog of known exploited vulnerabilities, as carrying significant risk to the federal enterprise within a timeframe set by CISA pursuant to this directive.
  • Remediate each vulnerability according to the timelines set forth in the CISA-managed vulnerability catalog. The catalog will list exploited vulnerabilities that carry significant risk to the federal enterprise with the requirement to remediate within six months for vulnerabilities with a Common Vulnerabilities and Exposures (CVE) ID assigned before 2021 and within two weeks for all other vulnerabilities.
  • Report on the status of vulnerabilities listed in the repository. In line with requirements for the Continuous Diagnostics and Mitigation (CDM) Federal Dashboard deployment and OMB annual FISMA memorandum requirements, agencies are expected to automate data exchange and report their respective Directive implementation status through the CDM Federal Dashboard.

“Every day, our adversaries are using known vulnerabilities to target federal agencies. As the operational lead for federal cybersecurity, we use our directive authority to drive cybersecurity efforts toward mitigation of those specific vulnerabilities that we know to be actively used by malicious cyber actors. The Directive lays out clear requirements for federal civilian agencies to take immediate action to improve their vulnerability management practices and dramatically reduce their exposure to cyberattacks. While this Directive applies to federal civilian agencies, we know that organizations across the country, including critical infrastructure entities, are targeted using these same vulnerabilities. It is therefore critical that every organization adopt this Directive and prioritize mitigation of vulnerabilities listed in CISA’s public catalog,” said CISA Director Jen Easterly.

Trick or Treat – Did You Fall for the Google Ads Crypto Scam?

multi-stage bitcoin scam, Google Ads crypto wallet scam

Check Point Research (CPR) has issued a warning about scammers exploiting Google Ads to steal crypto wallets. CPR observed that popular brands like Phantom and MetaMask were being impersonated and used as Google Ads on the search engine to scam users into sharing their crypto wallet’s private key and passphrase.

According to CPR, an estimated $500k (approximately) worth of cryptocurrency was stolen in a matter of days.

The Crypto Lure

Scammers usually resort to phishing campaigns that conventionally use emails to lure or trap victims. The threat actors are leveraging on the crypto market’s popularity and bidding for crypto wallets.

Google Ads that ape popular wallets and crypto platforms such as Phantom App, MetaMask, and Pancake Swap, contain malicious links that appear at the top of the Google search results. Any search query related to the crypto wallet directs the user to one of the infected ads. Clicking any of these malicious links, directs the victim to a fake website, which looks like the brand’s legitimate website. Furthermore, the scammers trick their victims into giving up their wallet passwords, setting the stage for wallet theft.

Oded Vanunu, Head of Products Vulnerabilities Research at Check Point, said, “In a matter of days, we witnessed the theft of hundreds of thousands of dollars’ worth of crypto. We estimate that over $500k worth of crypto was stolen this past weekend alone. I believe we’re at the advent of a new cybercrime trend, where scammers will use Google Search as a primary attack vector to reach crypto wallets instead of traditionally phishing through email. In our observation, each advertisement had careful messaging and keyword selection to stand out in search results. The phishing websites the victims were directed to, reflected meticulous copying and imitation of wallet brand messaging. And what’s most alarming is that multiple scammer groups are bidding for keywords on Google Ads, which is likely a signal of the success of these new phishing campaigns geared to heist crypto wallets. Unfortunately, I expect this to become a fast-growing trend in cybercrime. I strongly urge the crypto community to double-check the URLs they click on and avoid clicking on Google Ads related to crypto wallets at this time.”

CheckPoint Recommends Crypto Security

  1. Examine the browser URL. Only the extension should create the passphrase, and understand if this is an extension or a website, always look at the browser URL.
  2. Look for the extension icon. The extension will contain an extension icon near it and a chrome-extension URL:MetaMask/ chrome extension://
  3. Never give out your passphrase. Users should never give out their passphrases; no one should ever ask for that, as it is useful again only when installing a new wallet.
  4. Skip the ads. If you are looking for wallets or crypto trading and swapping platforms in the crypto space, always look at the first website in your search and not in the ad, as these may mislead you to getting scammed by the attackers.
  5. Take a look at the URL. Last but not least – always double-check the URLs!

Choice of Scammers

Threat actors favor cryptocurrency as a medium of ransom and now also for exploits. Cryptocurrency scams have been escalating and have become more prevalent, with over $70 million losses being reported in the first half of this year and estimated to reach $140 million by the end of the year. More than half of the investment scams were related to cryptocurrency trading, primarily through Bitcoin, as cybercriminals capitalize on users’ interest in cryptocurrency. Cryptocurrency scams are the most reported investment scams causing significant losses. Of the 1,931 reports involving a loss, 955 (49.5%) were due to cryptocurrencies loss of $29,277,896. Bitcoin accounted for over $25 million of these losses.

A report from cybersecurity firm, Barracuda, registered a staggering 192% rise in cryptocurrency-related cyberattacks since the Bitcoin surge of October 2020.

Threat actors pretended to be from highly profitable crypto exchanges and trading platforms, tricking users into investing in their fake schemes. They also leveraged phony celebrity endorsements and gave small returns to investors to gain investors’ trust. In addition to financial frauds, scammers also committed personal data and identity thefts by exploiting investors’ data.

Given the surge in cryptocurrency criminal activities, certain governments have also issued bans on the crypto activity to contain the malicious spread. Some countries are jointly working on stringent laws to make the crypto operators more accountable. Either way, the crypto market remains a popular choice and will only grow moving ahead; what we need is more regulations and accountability to make it mainstream.

See also: Australians Lose Over $70 Mn to Cryptocurrency Scams

Britain’s Labour Party Suffers Cyber Incident

Labour Party

Cyberattacks and data breaches via third-party vendors continue to become prevalent, affecting organizations’ critical data. Britain’s Labour Party recently announced that it had sustained a cyber incident via a third-party firm that handles its membership data. In an official release, the Party stated the security incident compromised its systems affecting its Party members, affiliated supporters, and other individuals who gave their data to the Party. However, the attack did not impact the Party’s data systems.

While the total number of members affected is unknown, the Labour Party stated, it has reported the incident to the National Crime Agency (NCA), National Cyber Security Centre (NCSC), and the Information Commissioner’s Office (ICO) to further investigate its nature, circumstances, and impact.

“On 29 October 2021, we were informed of the cyber incident by the third party. The third party told us that the incident had resulted in a significant quantity of Party data being rendered inaccessible on their systems,” the Party said.

NCSC Recommends

Attackers could exploit the compromised information for various malicious activities. As a precautionary measure, the NCSC recommended security actions to defend against data misuse:

  • Be vigilant against suspicious activity, including suspicious emails, phone calls, or text messages.
  • If you have received an email that you’re not quite sure about, forward it to the Suspicious Email Reporting Service (SERS) via [email protected].
  • Implement two-factor authentication (2FA) where possible to protect your online accounts from unauthorized access

The statement from the Labour Party is unclear and did not include answers for most questions, including the number of impacted members, the type of data impacted, and if it was a ransomware attack.

“With incidents of this nature becoming increasingly common, it is more important than ever to remain vigilant against suspicious activity,” the Party added.

Cyberattacks on Political Parties

Cybersecurity incidents on political parties incur severe repercussions. Attackers could exploit the sensitive data of the parties to meddle in election campaigns and even influence voters. Earlier, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert for all political parties and operatives of critical infrastructure to look out for possible cyberattacks. In a broader light of keeping the organizations and businesses safe from state actors’ foul play, CISA has provided information on specific tactics, techniques, and procedures (TTPs) employed by them.

Cloud Security: Challenges and Trends

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

With nearly 50% of the global corporate data being stored in the cloud, it is no surprise that cloud security has become an essential priority for cloud users. Many people even today argue that their data may be safer on their local servers, where they have more control over its security. Still, the deposit is entirely dependent on the capabilities of the respective organization. In contrast, experts suggest that storing data on the cloud is more secure as the cloud service provides, having a superior security architect in place to protect your data. While both arguments have pros and cons, one cannot deny the degree of freedom and efficient performance of cloud computing. But, at the same time, it could safely be said that any technology is only as efficient as understanding its user, and the same applies to cloud security.

By Abbas Kudrati, Chief Cybersecurity Advisor, Microsoft Asia Pacific

How Cloud Security Differs From Traditional Infosec

The security threat involved with cloud computing is generally more stressed in contrast to its benefits, as the concept of your entire data and operations being in a digital but dynamic environment where things are constantly changing is hard to wrap our heads around. However, cloud security operations are more or less similar to that of IT security. Therefore, understanding the particular difference between them is critical to expel the lingering suspicions about the term ‘cloud.’ Some of the key differences that cloud security needs to consider could be listed as:

  • Restructured boundaries: The core of cloud security deals with access and authorization protocols and restrictions. The traditional security environment controlled access using a perimeter security model, i.e., providing access over local networks, etc. However, the cloud environment is highly interconnected and spread over the internet, where the traffic bypasses traditional perimeters. Thus, the cloud security framework must include security models for application programming interfaces (APIs), identity and access management, account hijacks, malicious insiders, etc. Similarly, preventing unauthorized access by adopting a data-centric approach and strengthening the authorization process are some of the solutions that CSPs need to implement.
  • Virtual scalability: Cloud computing implies hosting resources delivered via software. The data storage and processing in cloud infrastructure are dynamic, scalable, and portable. Hence, the cloud security framework needs to incorporate the environmental variables accompanying the workload. The framework also needs to accommodate both states of rest and transit, either encrypted or transiting dynamically through the cloud management system and APIs, to mitigate threats and data loss.
  • Evolving threat landscape: With the rapid growth in technologies, the threat landscape and attack vectors are also evolving. These sophisticated developments are anything but a positive impact on modern digital security, which of course, includes the cloud. Advanced Persistent Threats (APTs) and increasingly sophisticated malware and ransomware are designed to evade security defenses by targeting vulnerabilities in the computing stack. As a result, there is a pressing need to develop a clear solution to these threats. It is the responsibility of the cloud service providers and clients to stay updated with emerging threats and evolve cloud security practices.

Cloud Security Challenges

Cloud computing and storage is service action between the cloud service provider and the client. Each has its share of task responsibilities while incorporating cloud technology into its existing applications and network. Hence, an implementation error or misconfiguration could lead to vulnerabilities. In addition, cloud security is a key concern for cloud storage providers, as regulatory requirements towards storing sensitive data bind them. But the security reality differs with respect to various aspects involved with the implementation of cloud technology, such as the lack of clear perimeters for the public cloud. These issues are further augmented due to challenges posed by the adoption of modern cloud approaches such as automated Continuous Integration (CI) and Continuous Deployment (CD) methods, distributed serverless architectures, Functions as a Service (FaaS), and containers.

Some of the most prominent threats to cloud security include data breaches, account hijacking, data loss, insecure application program interfaces (APIs), service traffic hijacking, inept cloud storage providers, shared technology, etc., which could very well compromise cloud security. Attacks such as Distributed denial of service (DDoS) tend to shut down a service by overwhelming application/network with help are the most considered issues for cloud security. Apart from this, the human element also contributes significantly towards existing challenges. Most people think external hackers and malicious insiders are the biggest threat to cloud security, but that’s not always the case. Internal employees do present a large risk for cloud security, and these employees need not necessarily have any malicious intentions. However, they could still harm unknowingly through mistakes such as using a personal and unsecured device to access sensitive data, access it outside the organization’s secure network, etc.

The change in threat landscape could be identified and classified into an exploit, transversal, and monetization, where the traditional exploits included social engineering, phishing, and geo-filtering evasion with proxy. In contrast, the exploits for cloud platforms involve acquiring tenant keys from GitHub, RDP/SSH password spray, brute force, etc. Similarly, traditional traversal attacks included credential theft and abuse (hashes, SSH…), scan & exploit, etc., whereas for cloud platforms it has evolved to pivoting to on-premises from the cloud. For the purpose of monetization, threat actors famously use ransomware, targeted data theft, commodity Botnet/DDOS, etc., but the latest attempts have evolved to crypto-mining – (webservers, visitors).

Increased attack surface, lack of visibility and tracking, changing workloads, and complex cloud environments could be considered as some of the advanced cloud-native security challenges that present themselves as multilayered risk factors faced by cloud-oriented operations. Apart from these few other trending security challenges could be listed as follows:

  • DevOps: Organizations that have implemented the highly automated DevOps and CI/CD (Continuous Integration and Continuous Deployment) technologies need to identify vulnerabilities during the SDLC (Systems development life cycle) stages and embed appropriate security controls.
  • Data visibility and control: The crux of any shared cloud storage service is the data is moved outside the corporate network away from devices managed by the IT team. This, in many instances, such as security integration or cloud forensics, makes it slightly difficult to access the data freely. Also, to understand the overall security, the IT team needs the ability to see into the cloud service itself. The limited control and access to underlying elements provided to the client will make it difficult for the client’s infosec team to create a near-perfect defense mechanism around it.
  • Cloud-native breaches: These types of breaches differ from the traditional on-premises breaches, as they often occur using native functions of the cloud. Unlike the traditional IT attacks that require malware to deploy/land attacks, the malicious actions are deployed by exploiting errors or vulnerabilities in a cloud deployment without the use of malware. The threat actors tend to expand their access through weakly configured or protected interfaces and tamper or exfiltrate data.
  • Misconfiguration: The overall security responsibility in the cloud is generally divided into two, i.e., the cloud service provider and the client through the service level agreement (SLA), where each is responsible for the security of their own physical and digital assets within their perimeter. The security responsibility against cloud-native breaches often falls to the cloud customer, including the configuration of the cloud service or assets. Misconfiguration of services, especially in IaaS (Infrastructure as a Service), will lead to vulnerabilities prompting cloud-native breaches. Studies have shown that 99% of misconfigurations go unnoticed by cloud customers [1]. The same could be said for the AWS S3 buckets, where often user roles are configured very loosely, granting extensive privileges to those that do not require it.

Trends in Cloud Security

The shared responsibility cloud model tends to push most virtual infosec responsibility onto the organizations using cloud services, irrespective of whether the data is being used, processed, and managed in a third-party cloud. Thus, organizations are developing new practices to meet these responsibilities. One of the trending methods is using centralized platforms to provide multi-cloud security unified, as most organizations use different and multiple CSP. Tools such as cloud security access broker (CASB) could be helpful to fulfill cause as it sits between users and cloud applications and monitors activity. Another trending approach is to protect your data before it reaches the cloud through encryption, masking, and tokenization. Similarly, organizations are also adopting a zero-trust model to improve their identity and access management; numerous recent breaches today tend to target misconfigured accounts. Hence, organizations are developing specific identity management platform capabilities that could integrate into their cloud environments.

Secure Access Service Edge

Secure Access Service Edge (SASE) is a single cloud-delivered service model that incorporates multiple network security frameworks such as CASB (Cloud Security Access Broker), Zero Trust, FWaaS (Firewall as a Service), etc. onto a single WAN platform. This framework enables fast and secure cloud adoption without interrupting data accessibility. The global pandemic of COVID-19 has acted as both the impetus and the driving force for digitalizing the operations of many corporate organizations, and the cloud has grown in popularity. Correspondingly, cloud security and especially SASE, has goosed the interest of security professionals managing the challenges of remote operations.

SASE tends to merge the network traffic and security priorities while maintaining the direct and fast network-to-cloud connectivity, i.e., a combination of both speed and security control. Furthermore, it allows security professionals of the client organization to apply identity and context that specifies the exact level of performance, reliability, and security for network sessions. Some of the significant benefits of the SASE framework could be listed as:

  • Provides flexibility towards implementing infosec service threat prevention, web filtering, sandboxing, DNS security, credential theft prevention, data loss prevention, next-gen firewall, etc., in cloud architecture.
  • It is a single platform that provides multiple security services. Hence, saving cost and security expenditure for the cloud service user.
  • Simplifies network security by minimizing the number of security assets and applications needed to be managed.
  • The high-speed deliverance and connectivity increase the performance while not compromising security, as its threat prevention model provides a complete content inspection.
  • It is widely known to provide a Zero Trust model to the cloud users by removing trust assumptions when users, devices, or applications connect to the cloud.

    References:

[1] https://www.mcafee.com/enterprise/en-in/security-awareness/cloud.html


About the Author

 Abbas Kudrati With over 21 years of experience in information security, Abbas Kudrati is currently the Chief Cybersecurity Advisor at Microsoft Asia Pacific and has abundant experience in the domains of cloud security, digital transformation, zero-trust network architecture and strategy, cybersecurity strategy and road map development, stakeholder engagement, vendor management, security operation, incident management, security governance, compliance management, enterprise security architecture, and security awareness.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Why Identity Management is the Foundation for Zero Trust Methodology, and Why it Matters

cyberattacks on U.S. and U.K., Barnes & Noble cyberattack, zero trust

As you check into any hotel, a concierge will hand you a keycard. The card gives you access to your room, the fitness center and the pool during operating hours, and opens locked, non-main entrances to the building. Members of the hotel’s housekeeping team have keycards that access each guest room and supply storage areas. Hospitality staff get access to luggage storage, culinary staff to the kitchen. And when keycards are used, the hotel’s security system logs who entered a room and what time they entered. It seems like common sense. People are granted access to only the rooms they need to enter to complete their tasks. Each person has a unique identity in the system — in the hotel it’s the keycard, and in your network, it’s the user listed in your unified identity management system. This is zero-trust architecture, and it all starts with identity.

By Matt Graves, VP of Information Security Practice, MajorKey Technologies

With zero trust methodology that starts with identity in mind, users get the minimal access they need and no more. Everything is tracked through the system, so it’s known which individual is present, what they have access to, and when they used that access.

What appears as common sense isn’t the norm. And that’s because for years, the nature of networks and how employees worked meant that security with perimeter defenses and passwords provided an imperfect but passable solution.

The nature of work today can’t rely on an assumption that each user, once inside a network, can be implicitly trusted. People enter the network from a wide variety of endpoints because of the rise of mobile devices, remote work, and cloud-based applications. Network users are no longer only employees, but customers, outside vendors, and contractors.

Default enterprise directories, like Active Directory, can’t account for all these different users, tracking who is where in the system, granting access as needed and tracking how that access is used. And the most well-known form of computer security — the password — not only isn’t enough to secure your infrastructure, but actually makes getting work done more difficult.

The Perils of Passwords

The top hacking vector in breaches last year, according to the An alarming three out of four IT decision makers whose organization suffered breaches said it involved privileged access credential abuse. According to a Centrify report, 65% said they share root or privileged access to systems and data at least somewhat often.

These over sharers aren’t malicious actors, but they are slowed by a system that creates roadblocks in their work. So even though they know it may not be safe or secure, they share access credentials as a shortcut.

The issue with passwords is that you don’t actually know the identity of the person using a password to access a network resource. Whether the password was shared or stolen, it can’t represent an implicit confirmation of identity.

So instead of passwords, zero trust relies on identity established in a unified user directory. With identities established for each user on the network, they sign in once — what’s known as single sign-on (SSO) — and have secure access to the tools, applications and resources they need.

This not only reduces attack surfaces by reducing the amount of passwords used to access an organization’s resources, but increases productivity as well. A Health Informatics Journal research paper cited a study at a midsized integrated delivery health network in Kentucky comprising five health systems. The study found that the time and dollars spent within one of their five emergency departments utilizing traditional login methods and application timeouts to access an electronic tracking board required more than 14 hours of accumulated lost user productivity during the course an 8-hour shift, equating to $588,600 over the course of a year.

Having a unified user directory and SSO in place, though, is only the first step in creating a zero-trust architecture, because it’s not just about establishing identity (this of course is the foundation), but continuously confirming it. This is where your context- and risk-based policies come into play, allowing access when necessary and requiring secondary confirmation of identity when a user’s actions raise red flags.

Context is King

Back to our hotel analogy, let’s say guests can use their keycards to access the pool area from 7 a.m. to 7 p.m. each day. However, staff need to access the pool during off-hours for maintenance and cleaning, so their keycards can open doors to the pool area 24/7, but during those off-hours, they are prompted for a one-time code texted to their phone.

This is like having a context-based policy. It’s utilizing user identity in combination with a behavioral context to determine whether to trigger multi-factor authentication (MFA). These triggers have become more commonplace for customers, such as when using a bank’s website to access account information from a new, unrecognized device.

In a network environment, these contextual cues can account for the time a resource is being accessed, just like the hotel pool access example, or other factors like geolocation or device. If employees use both work-issued and personal devices to access work resources, a policy could require MFA for any attempts to access a normally allowed resource from a personal device as an additional security measure.

Team members who log in from a new geolocation could be another trigger. If a company’s team member who regularly travels between offices located in Boston and Chicago, both those geolocations could be allowed automatically, but if they sign on from Jacksonville, an MFA request could be triggered. These policies can all be tailored to best meet an organization’s needs based on location and time of day.

These context-based access policies are rapidly changing security standards. Okta surveyed 500 security leaders and found that in 2019, 55% of those leaders listed the network as a top factor for context-based access decisions. A year later, that figure dropped to 20%.

Risk-based policies add an additional layer of security for particularly sensitive data or resources. For example, financial information or data that is subject to federal regulations like HIPAA can be set to always require MFA. And instead of having that verification serving as a one-time check, your system can assert levels of risk tolerance and trigger additional authentication requests based on new contextual information. Identity verification no longer becomes one-and-done, but an ongoing process, powered by a robust identity management system and the clear and concise policies created.

Creating this system sounds complicated, but one of the greatest benefits of an identity-based system developed on the zero trust methodology is that when your architecture is in place, it can actually make navigating the network easier for your users.

Stronger Security Behind the Scenes

Zero trust methodology and architecture offers enterprises intuitive and adaptive security. It simplifies user experiences, while keeping the security running and monitoring actions behind the scenes. It also simplifies your IT management.

A Gigamon survey of senior IT decision makers found that 87% said productivity either had or would have improved since the implementation of zero trust. Of those decision makers, 43% said the increased productivity came from the system running faster, 35% said due to fewer security breaches, and 23% because of reduced downtime.

It begins at onboarding. Let’s say a new sales professional is onboarded and has a user account created, which gives them on day one access to all the resources they need. The role-based security simplifies access for them and eliminates the need for them to filter out what they don’t need. If this employee switches departments, their sales department related access is removed and new access privileges granted by the role change. This is all handled in the identity management system.

A formal offboarding process that ensures access is revoked is also critical to maintain the security of your systems. An Intermedia study found that 89% of those surveyed still had privileged access after leaving their job to sensitive company applications like Salesforce, PayPal, email and SharePoint. Of those surveyed, 45% retained access to confidential data. In zero-trust architecture, when an employee leaves, their user account is maintained for archival logging of important data and history, but their access is revoked through the identity provisioning system.

Ultimately, it all comes down to the three fundamental questions of identity: who is in your system, what they have access to and what are they doing with that access. Zero trust methodology is founded on these three key questions, and the answer is identity management. Without that, your enterprise remains at-risk, your customers and partners frustrated, and your staff stuck in an inefficient system. With identity management, it’s as simple as checking into your favorite hotel.


About the Author

Matt GravesMatt Graves is a Vice President and Information Security Practice Lead at MajorKey Technologies. An experienced information security and cloud architect, Matt is responsible for IAM solutions development across the MajorKey client community. He advises clients on how to evolve their information security strategies and solutions in ways that align with their business objectives and leads solutions architecture to ensure effective delivery. Prior to his current role, Matt held senior operational positions within Highmetric, helping clients implement service management processes and solutions. An expert with multi-cloud platforms, Matt joined the company from the healthcare insurance industry.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Why It Is Time to Go Beyond Passwords

cybersecurity, password, password management,

Passwords are one of the most common techniques used to keep our information safe. However, with growing number of apps, it is not at all easy for a normal person to remember all passwords. Our research estimates that there are about 137 average number of SaaS applications in mid-sized companies. Close to 85 passwords are required by users to remember between their personal and official accounts. Users have tried to circumvent this issue by having the same password on multiple websites or accounts. This is dangerous, as one security hack in one website invariably exposes the individual to the possibility of breaches in other accounts.

By Rohan Vaidya, Managing Director – India at CyberArk

In India, in 2021 alone, there have been several noteworthy breaches. The list of companies includes payment processor, Juspay which had approximately 35 million records compromised; Domino India which had credit card details of close to 10 lakh customers leaked on the dark web; popular discount stock broker, Upstox, which faced unauthorized access into its database and Air India, which announced that the personal details of certain passengers may have been exposed due to a cybersecurity attack on the systems of its data processor responsible for the passenger service system.

If one looks at the scale and pace of attacks, it is clear that attacks have been relentless. For the record, 613+ million passwords have been exposed by data breaches (Source: Have I been Pwned service, DBIR – 2021 Verizon Data Breach Investigations Report).  80% of hacking-related breaches are a result of weak or stolen credentials. This has created increased pressure on the IT help desk, with 20-50% of all IT help desk requests per year being password resets.

Every time you get locked out of an account or can’t access a work resource, you lose valuable time. You must call your IT help desk team, who likely has to reset the password or help you get the access you need to do your job. Our team made some simple calculations to come up with a dollar amount for the lost time spent resolving password issues: an enterprise of 1,000 employees spends about $495,000 annually. Instead of focusing on important business tasks, employee productivity plummets while IT help desk managers pull longer shifts to address access issues and deal with (understandably) frustrated end-users.

To address this issue, many organizations use dedicated password managers. This can be a helpful way to protect your personal passwords by eliminating the need to memorize credentials or store them in a browser. However, this is inadequate in corporate environments, where many different users need many different levels of system access. Password managers can’t manage who gets access to what sensitive resources and for how long. Meanwhile, IT teams have limited visibility into access-related events, creating security gaps and risk exposure.

It is time to think beyond passwords now. Fortunately, today, technology is available to try out new passwordless methods to protect both personal accounts and sensitive data of companies. Adaptive Single Sign-On (SSO) tools are helping employers overcome security challenges associated with traditional passwords and automate manual access granting processes that can bog down IT help desk teams. With this approach, they can analyze user and device context to determine whether the access request is “normal.” The system should know, for instance, if the user is attempting to access a database not usually accessed as part of their day-to-day activities or if a device is in a different city than usual. If the context is abnormal, the system adapts controls such as requesting re-authentication or adjusting the level of access. Analytics can help minimize friction by putting up gates only when necessary, based on a risk score. This can be further strengthened by multi-factor authentication techniques.

Users are also preferring passwordless login techniques. According to Ponemon Institute research, a majority of IT security practitioners and business users (55%) would prefer a method of account protection that doesn’t involve passwords. Data from Microsoft shows that 150 million people are already using passwordless logins each month. Similarly, the 2021 Experian Global Identity & Fraud Report found that consumers have an increasing level of comfort and preference for physical biometric authentication methods (e.g., facial recognition and fingerprints) as well as behavior-based authentication methods (e.g., passively observed signals that require no effort from the user).

In summary, passwordless adoption can lead to several long-lasting benefits. For example, industry research shows that 87% of costs to support passwords dropped by using passwordless authentication techniques. It can also lead to reduced security risks by eliminating credential attacks while reducing the burden on IT and reducing complexity.


About the Author

Rohan VaidyaAs the Regional Director of Sales – India at CyberArk, Rohan Vaidya is responsible for managing sales operations and profitability of the business in the sub-continent. He joined CyberArk in May 2016 with more than 18 years of experience in successfully building brands and businesses in India and the wider Asian region. Prior to joining CyberArk, Rohan was the Head of Region for the Indian sub-continent at K2 Partnering Solutions, a European consulting firm specializing in ERP and Cloud. He has also co-authored a book, That’s Naut My Business.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

BlackMatter Ransomware Group Shuts Shop Citing Pressures from Law Enforcement

BlackMatter ransomware

BlackMatter cybercriminal group announced that it is shutting down operations, citing pressures from law enforcement authorities. Active since July 2021, BlackMatter offers ransomware-as-a-service (Raas), enabling threat actors and cybercriminal affiliates to deploy ransomware. BlackMatter operators have targeted several critical infrastructures in the U.S. and demanded ransom payments ranging from $80,000 to $15,000,000 in Bitcoin and Monero.

The Shutdown 

Cybersecurity research group VX-Underground, in a tweet, shared the message posted by the BlackMatter group, which claimed that they are shutting down their ransomware operations in the next 48 hours.

The BlackMatter gang is suspected to be a successor of the DarkSide ransomware group, responsible for the infamous cyberattack on Colonial Pipeline. Several security experts claimed that BlackMatter incorporated attack techniques of DarkSide, REvil, and LockBit ransomware groups.

What Led to BlackMatter’s Demise? 

While the operators behind BlackMatter have not revealed much about their shutdown, the cybersecurity community opined that the recent cybersecurity initiatives may have forced the group to shut shop.

Recently, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI jointly released a cybersecurity advisory about the infamous BlackMatter ransomware group, with information on its tactics, techniques, and procedures (TTPs). The Biden Administration recently hosted a 30-nation Counter-Ransomware Initiative conference to address the growing ransomware landscape.

Would BlackMatter Return? 

It’s common for cybercriminal groups to cease operations and come back with different names and tactics. A few months ago, DarkSide group announced its shutdown; however, it later came back as BlackMatter.

The Last Victim

Farm services provider NEW Cooperative was the last victim of BlackMatter ransomware. The group reportedly compromised and infected NEW’s network systems and demanded a ransom of $5.9 million for restoration.

Earlier, BlackMatter stated that they wouldn’t attack critical infrastructures such as health care facilities, the defense industry, nuclear power plants, water treatment facilities, the oil and gas industry, non-profit organizations, and government agencies. However, it targeted critical firms, causing severe damage to the consumer economy.

Ransomware Operators Leverage Financial Events Like M&A to Pressurize Victims: FBI

ransomware

The FBI released a notification identifying the use of critical financial events and stock valuation to facilitate targeting and extortion of victims by ransomware groups.

Threat actors are now going beyond network and data vulnerability and leveraging an organization’s financial and market vulnerabilities. The FBI has assessed that the adversaries use significant financial events, such as mergers and acquisitions, to launch ransomware attacks.

“Threat ransomware actors are targeting companies involved in significant, time-sensitive financial events to incentivize ransom payment by these victims. Ransomware is often a two-stage process beginning with an initial intrusion through a Trojan malware, which allows an access broker to perform reconnaissance and determine how to best monetize the access,” the FBI said.

Threat actors scout for confidential, non-public information of the target and coerce the victim to relent to the ransom demands. The victims, in most cases, would concede as they are amid a significant financial event like stock valuation or a merger and acquisition, whereby the consequences of any leaked information could heavily impact the stock value of the company.

The FBI listed multiple ransomware cases from 2020 and 2021:

  • In early 2020, a ransomware actor using the moniker “Unknown” made a post on the Russian hacking forum “Exploit” that encouraged using the NASDAQ stock exchange to influence the extortion process. Following this posting, unidentified ransomware actors negotiating a payment with a victim during a March 2020 ransomware event stated, “We have also noticed that you have stocks. If you will not engage us for negotiation we will leak your data to the nasdaq and we will see what’s gonna happen with your stocks.”
  • Between March and July 2020, at least three publicly traded US companies actively involved in mergers and acquisitions were victims of ransomware during their respective negotiations. Of the three pending mergers, two of the three were under private negotiations.
  • A November 2020 technical analysis of Pyxie RAT, a remote access trojan that often precedes Defray777/RansomEXX ransomware infections, identified several keyword searches on a victim’s network indicating an interest in the victim’s current and near future stock share price.
  • In April 2021, Darkside ransomware actors posted a message on their blog site to show their interest in impacting a victim’s share price. The message stated, “Now our team and partners encrypt many companies that are trading on NASDAQ and other stock exchanges. If the company refuses to pay, we are ready to provide information before the publication, so that it would be possible to earn in the reduction price of shares. Write to us in ‘Contact Us’ and we will provide you with detailed information.”

Evolving Ransomware Techniques

From new malware variants to different hacking methods, threat actors constantly change their approaches to encrypt victims’ data and pressurize them into paying the ransom. To prove their power, the operators behind the Darkside ransomware group announced that they are leveraging new extortion tactics by targeting companies that are listed stock markets like NASDAQ. As reported in April 2021, the Darkside operators stated they are coaxing certain crooked stockbrokers to use insider information of their corporate targets to short-sell a victim company’s stock before disclosing the breach or leak any data. The operators believed that the impact of posting a traded company’s name on its website would cause the victim company’s stock price to fall and help insider traders make profits.

See also: Darkside Ransomware Gang Adopts New Extortion Technique by Targeting Stock Traders

Not conceding to ransom demands has been echoed by experts and authorities across industries, yet the victims’ willingness to pay for their compromised data has been the primary reason why we continue to see a surge in the attacks.

“Paying a ransom emboldens adversaries to target additional organizations, encourages other criminal actors to engage in the distribution of ransomware, and/or may fund illicit activities. Paying the ransom also does not guarantee that a victim’s files will be recovered. However, the FBI understands that when businesses are faced with an inability to function, executives will evaluate all options to protect their shareholders, employees, and customers. Regardless of whether you or your organization have decided to pay the ransom, the FBI urges you to report ransomware incidents to your local FBI field office. Doing so provides the FBI with the critical information they need to prevent future attacks by identifying and tracking ransomware attackers and holding them accountable under US law,” the FBI added.

FBI Recommends

  • Back-up critical data offline.
  • Ensure copies of critical data are in the cloud or on an external hard drive or storage device.
  • Secure your back-ups and ensure data is not accessible for modification or deletion from the system where the original data resides.
  • Install and regularly update anti-virus or anti-malware software on all hosts.
  • Only use secure networks and avoid using public Wi-Fi networks.
  • Use two-factor authentication for user login credentials, use authenticator apps rather than email as actors may be in control of victim email accounts, and do not click on unsolicited attachments or links in emails.
  • Implement least privilege for file, directory, and network share permissions.

Bill-Alderson_HopzeroIn an exclusive quote to CISO MAG, Bill Alderson, CTO, HOPZERO, said, “Sadly, the NSA, CIA, and FBI all losing their lawful intercept tools to hackers increased technical ability greatly.  As with any monetization method – they are increasing their market by simple research to find high stakes, high-visibility situations they can exploit. All is not lost.  Hackers are not omniscient, omnipotent, or omnipresent, as those technically deficient might think, that only AI can fix data compromise. And by AI Security success, those are easy pickings.  My solution rests with hop starvation reducing the attack surface of vital servers by over 99% reducing risk while catching ransomware and phish – hooking-em, cooking-em, and frying-em up in a pan.”