Home Blog Page 51

Do Your Part #BeCyberSmart this 2021 Cybersecurity Awareness Month

BeCyberSmart

Awareness is the key to make everything better in our lives. While everyone knows how technology and connected devices play a significant role in everyday routines, only a few are aware of the security implications of the technology if not appropriately managed. The National Cybersecurity Awareness Month sheds light on various security vulnerabilities, and offers actionable guidance to users and organizations defending against evolving cyberthreats in cyberspace.

Initiated by the National Cyber Security Alliance (NCSA) and the U.S. Department of Homeland Security (DHS) in October 2004, the Cybersecurity Awareness Month continues to raise awareness among users and organizations, to own their role in protecting their part of cyberspace and the importance of taking proactive steps to enhance cybersecurity.

In its 18th year, Cybersecurity Awareness Month continues using last year’s theme – Do Your Part. #BeCyberSmart.

The Cybersecurity and Infrastructure Security Agency (CISA) and NCSA stated that 2021 Cybersecurity Awareness Month will focus on multiple areas, which include:

  • Week of October 4: Be Cyber Smart.
  • Week of October 11: Phight the Phish!
  • Week of October 18: Explore. Experience. Share. – Cybersecurity Career Awareness Week
  • Week of October 25: Cybersecurity First

The agencies also offered cybersecurity technical and non-technical resources to help users improve their cybersecurity posture and mitigate security risks. “Use the hashtag #BeCyberSmart before and during October to promote your involvement in raising cybersecurity awareness,” CISA said.

POTUS Proclamation on Cybersecurity Awareness Month

This year’s Cybersecurity Awareness Month has become crucial for the U.S. government as the country sustained a series of cyber and ransomware attacks affecting its critical infrastructures. POTUS Joe Biden asked people, businesses, and institutions in the U.S. to recognize the importance of cybersecurity and protect against cyberthreats in support of national security and resilience.

“Our Nation is under a constant and ever-increasing threat from malicious cyber actors. Ransomware attacks have disrupted hospitals, schools, police departments, fuel pipelines, food suppliers, and small businesses, delaying essential services and putting the lives and livelihoods of Americans at risk. During Cybersecurity Awareness Month, I ask everyone to Do Your Part.  Be Cyber Smart.  All Americans can help increase awareness on cybersecurity best practices to reduce cyber risks,” Biden said.

The Most and Least Cybersecure Country Across the World

Microsoft 2022 flaw, Cybersecurity interest, Personnel Security Program

Cybersecurity has become a primary concern for many governments and organizations, after cybercriminals have extended their cyberespionage campaigns worldwide. Several organizations have already increased their cybersecurity budgets to boost their security capabilities to defend against evolving cyberthreats. As per Google data trends, the interest in cybersecurity reached an all-time high on Google Search, showing users and organizations increased focus on security.

Cybersecurity Interest

Based on the analysis presented by Atlas VPN, the rise of interest in cybersecurity occurred in February 2016, with a google trends score of 49. However, the increase dipped to 27 later during the end of 2016. The cybersecurity keyword interest came back up to a score of 49 again in October 2017. Two years later, in October 2019, cybersecurity interest peaked at a score of 76, and cybersecurity is at its highest point — 100 score value.

“Increasing interest in cybersecurity should not be a surprise as more frequent and more significant cyberattacks occur. In addition, people over the years have become more aware of their privacy online and how to protect themselves against cybercriminals by using security tools,” Atlas VPN said.

Countries with Most Cybersecurity Interest

Cybersecurity interest among users and organizations continues to grow with the increase in the cyberthreat landscape. As per the data, Singapore stood as the most interested country in cybersecurity with 100 points score in Google Trends. The country has introduced several cybersecurity initiatives to boost the resilience of critical information infrastructure, mobilize businesses and the community to create safe cyberspace, develop a vibrant cybersecurity ecosystem, and forge international partnerships.

Saint Helena stood second with a score of 59, followed by the U.S. with a 48 score and Kenya reached fourth place for interest in cybersecurity with a 42 score.

Multiple cyberattacks on U.S. government administrations and businesses made the country focus more on cybersecurity initiatives, such as investing more in cybersecurity and spreading awareness to mitigate evolving threats. The Biden Administration lately announced collaborations with the tech giants to enhance the cybersecurity posture in the country.

“Cybersecurity and our privacy online have become important topics in the current climate. More and more people understand that anyone could get hacked and losing your personal information can be costly. So, educating yourself about cybersecurity and looking into security products and services can help you become more resilient against cyberthreats,” Atlas VPN added.

The Most and Least Cybersecure Country

A similar analysis found Denmark the safest country with users attacked by ransomware trojans (0.02%) and crypto miners (0.11%). It also had zero users attacked by mobile ransomware Trojans and mobile banking trojans. Tajikistan is the least cybersecure country in the world, followed by Bangladesh and China. Tajikistan was the worst-scoring country, with users attacked by banking malware (4.7%), malware attack (41.16%), and crypto miners (5.7%).

CISA and NSA Jointly Release VPN Cybersecurity Information Sheet

Fortinet VPN, VPN, VPN devices

A Virtual Private Network (VPN) strengthens data privacy and security by providing a secure connection for users when joining another network online. Despite the security advantages, VPNs have become a frequent target for cybercriminals. From the Chinese APT group’s vulnerability exploitation of Pulse Secure’s VPNs to the latest exposure of 500,000 Fortinet VPN account details on the dark web, several state-sponsored actors have exploited unpatched bugs to gain access to vulnerable VPN devices.

VPN Security

In order to thwart the rising security incidents and help organizations improve their VPN security defenses against cyberattacks, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) jointly released a Cybersecurity Information Sheet detailing on selecting and hardening remote access VPN solutions. NSA stated that it released the cybersecurity information sheet to help secure the Department of Defense, National Security Systems, and the Defense Industrial Base.

The agencies stated that VPN servers become entry points for threat actors to penetrate critical networks. Multiple nation-states advanced persistent threat (APT) actors have weaponized common vulnerabilities and exposures (CVEs) to gain access to vulnerable VPN devices.

Exploitation of vulnerabilities in VPN networks enable bad actors to

  • Steal credentials.
  • Remotely execute code.
  • Weaken encrypted traffic’s cryptography.
  • Hijack encrypted traffic sessions.
  • Monitor sensitive data from the device.
  • Perform large-scale compromise to the corporate network.

 How to Select Remote Access VPN Solutions

  • Avoid selecting non-standard VPN solutions, including a class of products referred to as Secure Sockets Layer/Transport Layer Security (SSL/TLS) VPNs
  • Refer to the National Information Assurance Partnership (NIAP) Product Compliant List for validated VPNs
  • Carefully read vendor documentation to ensure potential products support IKE/IPsec VPNs
  • Identify whether the product uses SSL/TLS in a proprietary or non-standards-based VPN protocol when unable to establish an IKE/IPsec VPN
  • Check whether the product supports strong authentication credentials and protocols and disables weak certificates and protocols by default
  • Ensure the product includes protection against intrusions, such as the use of signed binaries or firmware images, a secure boot process that verifies boot code before it runs, and integrity validation of runtime processes and files

How to Harden Remote Access VPN Solutions

  • Use tested and validated VPN products from the NIAP product list
  • Employ robust authentication methods like multi-factor authentication (MFA)
  • Apply patches and updates regularly
  • Reduce the VPN’s attack surface by disabling non-VPN-related features
  • Configure strong cryptography and authentication
  • Run on strictly necessary features
  • Protect and monitor access to and from the VPN
  • Secure the network entrance

“Remote access VPNs are entryways into corporate networks and all the sensitive data and services they have. This direct access makes them prized targets for malicious actors. Keep malicious actors out by selecting a secure, standards-based VPN and hardening its attack surface. This is essential for ensuring a network’s cybersecurity,” the agencies said in an advisory.

APAC Companies Struggling with Growing Volume of Digital Certificates: DigiCert Report

professional certifications, certificates, PKI, PKI Automation

DigiCert, Inc., a leading provider of TLS/SSL, IoT and other PKI solutions, today released its “2021 State of PKI Automation” survey that shows the typical enterprise in the Asia Pacific (APAC) now manages over 40,000 publicly and privately trusted PKI certificates. Manually managing this volume of certificates can lead to costly outages if not handled correctly, as evidenced by the finding that two-thirds have experienced outages caused by certificates expiring unexpectedly. More than one-third (35%) have experienced five to six such outages in the past six months alone, compared to the 25% global average. Due to these issues and others, there is strong interest in adopting PKI automation.

What are PKI Certificates?

PKI stands for Public Key Infrastructure. It is a framework that enables the encryption of public keys and includes their affiliated crypto-mechanisms. Two asymmetric keys (mathematical codes) are required to encrypt and decrypt information transmitted and received over the internet: a public and a private key. The public key is validated by a certifying authority and contains the name and identity of the host or the owner, and it can be shared publicly. It is used to encrypt the data before transmitting it to the intended recipient. The private key is secret and sent only to the person for whom the message is intended. It is used to decrypt the message.

This enables a highly secure network environment for use by applications and hardware — to exchange information, validate websites or even digital certificates.

Why is PKI Automation Necessary?

There are millions of certificates and keys exchanged every day on the Internet, and all this requires robust and secure PKI infrastructure – to manage the keys and certificates associated with it. Certificates have expiry dates, and processes must keep track of expiring certificates. The system also needs to authenticate certificates and look for rogue certificates, unmanaged certificates and outages caused by certificates expiring unexpectedly. Doing all these processes manually can be stressful for organizations.

So, leading organizations are 10 times more likely to have already implemented automation to do all this. They’re meeting PKI SLAs and doing a better job at self-reporting deficiencies.

percentage of digital certificates
Source: DigiCert

2021 State of PKI Automation Survey – APAC Findings

APAC is the region with more enterprises having trouble managing the workload, with 65% of the respondents stating that they are concerned about how much time is spent managing certificates. They also lack visibility. 35% of enterprises use more than three departments to manage certificates, leading to confusion. The typical enterprise says as many as 1,000 of the certificates are unmanaged, and nearly half (48%) say they frequently discover so-called “rogue” certificates (certificates that were implemented without IT’s knowledge or management), the highest occurrence among other regions surveyed.

“The volume of certificates has grown dramatically,” said Brian Trzupek, SVP of Product at DigiCert. “Further, validity periods for public TLS certificates have dropped from three years to one year since 2018. As a result, enterprises are finding it increasingly difficult to manually manage digital certificate workflows. They are looking for certificate automation, but need reassurance on how to do it and an understanding of the long-term costs and security benefits.”

“Manual processes aren’t an effective way to manage a large number of certificates. Something can always go wrong. Automating the management of PKI certificates is the obvious answer,” says Mike Mallos, Infrastructure Services Manager at Qantas. “It helps us improve security and compliance, become more agile and increase our productivity.”

Most enterprises are considering PKI automation, with 86% at least discussing it. Only 10% are at the stage where they are already implementing or maybe even finished implementing a solution. 12% say they are not discussing it and have no plans to do so. Most (70%) expect to implement a solution within 12 months.

apac enterprises towards PKI automation
Source: DigiCert

Not All Enterprises are the Same

The survey included a series of questions in determining how well (or poorly) each respondent was doing across a wide range of PKI metrics. After the scores were totaled, the respondents were split into three groups:

  • Leaders: Organizations that are doing the very best
  • Laggards: Organizations that are doing the worst
  • Middle: Organizations that are doing okay

The Leaders and Laggards were then compared to examine the differences and explore what the Leaders were doing better.

Leaders perform two to three times better than Laggards in every area, including minimizing PKI security risks, avoiding PKI downtime and meeting PKI-related SLAs. Laggards are seeing a wide range of PKI-related penalties, including lost productivity, compliance issues, loss of customers and even lost revenue.

leading vs lagging in pki automation
Source: DigiCert

Lessons from PKI Leaders

PKI Leaders are more likely to say PKI automation is important to their organization’s future. Further, PKI Leaders are twice as concerned about the time it takes to manage PKI certificates.

PKI automation leaders
Source: DigiCert

Recommendations

DigiCert recommends that companies begin to address automation of their certificate management processes, including their business workflows, to ensure they continue to adhere to best practices in PKI deployments. This includes the following:

Certificates:

  • Identify and create an inventory of the entire certificate landscape, from TLS to code signing, client certificates and more.
  • Remediate keys and certificates that are not compliant with corporate policy.
  • Protect with best practices for issuance and revocation. Standardize and automate enrollment, issuance and renewal.

Certificate Workflows: Address unmanaged or manual certificate workflows, such as code signing, document signing, email certificates or other identity and access solutions, with software that centralizes visibility and control and automates workflows.

The survey was conducted by ReRez Research of IT professionals within 400 enterprise organizations of 1,000 or more employees in North America, EMEA, Asia Pacific and Latin America.

To get the full report, visit https://www.digicert.com/campaigns/pki-automation.

Rise in RAT Campaigns Illustrates Growing Malware Threat

Trojans, RAT, remote access trojan, Snip3 Crypter-as-a-Service

Ransomware has made more than its fair share of headlines in the past 18 months. It has become a top priority for C-Suites and government officials who’ve either already been crippled by large payouts and extended downtime or have watched from the sidelines as businesses and allies fall victim. However, what has been less talked about is the danger that Remote Access Trojans (RATs) pose to enterprises today — the malware program that allows cybercriminals to enjoy administrative control over a company’s network. While these threats have flown slightly under the radar until now, a wave of new RAT campaigns targeting the travel and tourism industries, as well as the financial sector, and its customers, has pushed them into the limelight.

By Michael Gorelik, CTO & Head of Threat Intelligence, Morphisec

In May, the FBI said that it had found threat actors to be impersonating Truist, the sixth-largest U.S. bank holding company. That spear-phishing campaign attempted to infect victims with RAT malware. The campaign used several phishing techniques commonly associated with RAT campaigns today to spoof the financial institution, such as registered domains, email subjects, and even a malicious Windows app that mimicked Truist’s legitimate Financial SecureBank app.

For background, in a unique and ongoing RAT delivery campaign that my cybersecurity firm Morphisec has been tracking since February, threat actors have also incorporated malicious scripts/executables alongside a legitimate application to disguise their intentions. And while we know these types of phishing techniques have soared in the past year, it’s cybercriminals’ deployment of RAT malware afterward that is perhaps causing enterprises the gravest concern in recent months.

Daily Advancements Make RATs a Top CISO Concern

Obviously, ransomware owns the headlines for a reason, with the average total cost of recovery more than doubling from roughly $761,000 in 2020 to $1.85 million in 2021, according to Sophos. But with RAT malware growing increasingly sophisticated and more complex to detect, many organizations have found themselves with their backs against the wall and counting on the efficiency of often outdated antivirus software that has proven easily bypassable.

The reality is advancements in the attack chain have made most next-gen security solutions futile. After all, the ability to gain administrative control over a target’s network is one of the main advantages of deploying RAT malware, and threat actors are usually able to disable whatever antivirus tool is installed quickly.

In fact, in the aforementioned RAT campaign discovered by Morphisec, attackers could disable Microsoft Defender by dropping a Batch script and an LNK file pointing to the script. This was after they used an AutoHotKey (AHK)based loader to distribute various RATs such as RevengeRAT, LimeRAT, and AsyncRAT.

Meanwhile, in May, another new, highly evasive RAT loader was discovered called Snip3. This RAT was able to bypass detection-centric solutions with relative ease through several advanced techniques, such as its ability to execute PowerShell “remotely signed” script and to evade sandboxes and emulators through advanced detection.

Indeed, it doesn’t seem like too long ago when the security industry would track malware and crypters over a long period with little change. Today, however, we see modifications daily. And not only to one part of the attack chain, but to the entire chain. This rapid change has significantly increased the challenges faced by the AV world…To read the full story, subscribe to CISO MAG.

This story first appeared in the August 2021 issue of CISO MAG.


About the Author

Michael GorelikMichael Gorelik is the CTO and Head of Threat Intelligence at Morphisec, the leader in cloud-delivered endpoint and server security solutions. Prior to Morphisec, Gorelik was the VP of R&D at MotionLogic GmbH, and before that served in senior leadership positions at Deutsche Telekom Labs. He holds B.Sc and M.Sc degrees from the Computer Science department at Ben-Gurion University, focusing on low-level synchronization in different OS architectures. Gorelik also jointly holds six patents in the IT space.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Microsoft Releases Exchange Emergency Mitigation Service

Microsoft, Cyberattack on Olympus

Microsoft suffered a series of attacks after cybercriminals started exploiting unpatched ProxyShell vulnerabilities in Microsoft Exchange servers. Several state-sponsored attackers are still targeting organizations that have not addressed the flaws. In order to mitigate this ongoing security issue and protect Exchange Servers against cyberthreats,  Microsoft has added a new feature – the Microsoft Exchange Emergency Mitigation (EM) service in its September 2021 Cumulative Update (CU). The technology giant stated that the new feature is the fastest and easiest way to mitigate the highest risks to connected, on-premises Exchange servers before installing applicable security updates (SUs).

“After the release of the March SUs, we learned that many of our customers weren’t ready to install them because they were not running a supported CU. Based on our customer engagements, we realized that there was a need for a simple, easy to use, automated solution that could help customers quickly protect their on-premises Exchange servers, especially those who did not have dedicated security or IT teams to apply critical updates,” Microsoft said in an advisory.

The latest feature comes after multiple threat actor groups exploited the zero-day bugs in the Microsoft Exchange Servers.

How the Emergency Mitigation Works

The emergency mitigation component is based on Microsoft’s Exchange On-premises Mitigation Tool (EOMT), released in March. EOMT helps users and organizations to mitigate potential cyberattacks exposed by the ProxyShell bugs.

As per the advisory, the EM runs as a Windows service on the exchange server and works with the cloud-based Office Config Service (OCS), to protect against security threats that have known mitigations. The EM service verifies the OCS for available mitigations every hour and then downloads a signed XML file containing the mitigation configuration settings.

“Since in the future mitigations may be released at any time, we chose to have an hourly EM service check for mitigations. If Microsoft learns about a security threat and we create a mitigation for the issue, that mitigation can be sent directly to the Exchange server, which would automatically implement the pre-configured settings. The mitigation package is a signed XML file that contains configuration settings for mitigating a known security threat. Once received by the Exchange server, the EM service validates the signature to verify that the XML was not tampered with and has the proper issuer and subject, and after successful validation applies the mitigations,” the advisory added.

However, Microsoft kept EM optional for users who want Microsoft to create and automatically apply vulnerability mitigations to their Exchange servers. Organizations or security admins, who don’t want to use EM, can disable the EM feature and continue to use the EOMT to mitigate threats manually.

5.4 Mn DDoS Attacks Reported in H1 2021, Europe and EMEA Most Affected

DDoS attack on VoIP Providers , DDoS Attacks , DDoS Attack on Yandex

Distributed Denial of Service (DDoS) attacks could cause severe damage to organizations’ critical systems. The number of DDoS attacks on global organizations has increased as cybercriminal groups leverage various DDOS techniques to compromise targeted sources. A recent analysis from Atlas VPN revealed that cybercriminals launched nearly 5.4 million DDoS attacks in the first half of 2021, an 11% increase compared to the first half of 2020. Out of these, attackers leveraged compromised computer systems and botnet networks in 2.8 million of the attacks.

In a DDoS attack, threat actors try to make a targeted system or service unavailable to its users by flooding it with unwanted incoming traffic from different sources. DDoS attackers infect targeted devices/websites/services and turn them into bots, which no longer accept requests from legitimate visitors as it gets unnecessary traffic from fraudulent requests.

 DDoS Attacks in H1 of 2021

  • The first month of this year saw the most significant number (972,000) of DDoS attacks. In February, attacks dropped by a little over 5% to 921,000 and rose again by 5% in March to 968,000.
  • In April, DDoS attacks dropped by 9% to 882,000 and further decreased in May by 5% to 842,000 attacks. In June, the DDoS attacks reached the lowest point in H1 2021, dropping 10% to 759,000.
  • Nearly 41,000 DDoS attacks in H1 2021 were aimed at commercial VPNs, resulting in collateral damage affecting many entities.

DDoS Attacks Across Regions

While the number of DDoS attacks across the globe increased exponentially, the report stated that countries in Europe, the Middle East, and Africa (EMEA) sustained the most DDoS attacks in the first half of this year. Nearly 2 million DDoS attacks were aimed at organizations in these regions, with an average duration of 47 minutes per attack. The world’s biggest DDoS attack of H1 2021 was directed at Russian search engine provider Yandex. The attack was implemented via a new botnet tracked as Meris.

North America and the Asia-Pacific regions received nearly 1.3 million and 1.2 million DDoS attacks, respectively. The average duration of a DDoS attack aimed at North America was only 40 minutes, the shortest out of all the regions, while DDoS attacks targeting Asia-Pacific were on average 62 minutes long. Latin America was targeted the least out of all the regions across the world. The country encountered 555,039 most extended DDoS attacks in H1 2021 — an average of 63 minutes.

DDoS Turning to RDDoS

Several threat actor groups found shifting to ransom distributed denial of service (RDDoS) attacks to launch extortion schemes on targeted organizations. As per a survey, over 44% of businesses sustained an RDDoS attack in the past 12 months. Nearly 70% of organizations were targeted with RDDoS attacks, and 36% agreed to pay the ransom. In an RDDoS attack, cybercriminals either launch a DDoS attack and then demand ransom to stop, or they may ask for the ransom first by threatening with a DDoS attack if not paid.

Hackers Targeted Over 75,000 Mailboxes in a Credential Phishing Campaign

credential phishing campaigns

Security researchers from Armorblox uncovered an ongoing credential phishing campaign exploiting the brand of email encryption provider Zix. The analysis claim that the campaign has targeted several organizations across different sectors, including education, financial services, energy, health care, and many state and local government agencies. Zix is a security technology company that provides global organizations with email encryption and email data loss prevention services.

What is Credential Phishing Attack?

In credential phishing attacks, threat actors distribute malicious URLs via emails impersonating popular brands. Once a victim clicks on the URL, it either downloads malware on the victim device or automatically redirects the user to a hacker-operated site that steals user credentials.

Attackers Impersonated Zix Brand

The researchers stated that attackers sent malicious emails to the targets by spoofing an encrypted message notification from Zix. The malicious links in the email directed the victims to download an HTML file onto the system. Zix stated the campaign targeted more than 75,000 mailboxes by evading security detections across Office 365, Google Workspace, Exchange, and Cisco ESA.

See also: What are Credential Stuffing Attacks and How to Prevent Them

Attackers reportedly sent emails titled “Secure Zix message,” claiming that the victim had received a secure message from Zix. The email recommended the victim click on the Message button to view the secure message. The spam emails were sent via thefullgospelbaptist.com domain.

Selective Targets

Attackers distributed their malicious links across a select group of employees from various departments by leveraging different attack techniques, including:

  • Social engineering
  • Brand impersonation
  • Replicating existing workflows
  • Drive-by download
  • Exploiting legitimate domain

“While the spread is seemingly randomized, attackers might also have deliberately chosen their victims to be across departments and to contain a good mix of senior leadership and individual contributors. These employees are unlikely to communicate often with each other when they receive an email that looks suspicious,” the researchers said.

Security Precautions

Security experts from Armorblox also recommended users to:

  • Implement augment native email security with additional controls
  • Train the workforce to identify social engineering and other phishing tactics
  • Follow password management best practices across all departments in the organization
  • Deploy multi-factor authentication (MFA) on all possible business and personal accounts
  • Avoid using passwords that tie into your publicly available information (date of birth, anniversary date, etc.)

How Honeypots Boost Organizations’ Security

Honeypot

Cybercriminals often leverage various phishing lures to attract unwitting users. Similarly, security professionals also rely on the honeypot technique to attract cybercriminals and find their attacking network. Identifying attackers’ hacking courses and paths help security experts build their own strategies to thwart potential cyberattacks.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What are Honeypots?  

A honeypot is a decoy security mechanism used to detect or counteract unauthorized intrusions to critical network systems. They are designed to look like a legitimate system or database to trap attackers trying to break into a system. During the process, the hackers are stealthily observed without the intruder’s knowledge.

The primary function of a honeypot is to expose itself as a potential target (like an unsecured database or system) for online intruders and gather their information to notify the defenders.

Security experts consider honeypot program as the best mechanism to:

  • Identify hackers and their attacking vectors
  • Collect attackers’ data
  • Estimate threat actors movement
  • Detect and prevent security incidents
  • Understand security defense capabilities
  • Implement better security protocols

Honeypot Methodology

Usually, a honeypot setup consists of a genuinely looking decoy computer system or a server with dummy applications and data posing as a vulnerable target to exploit. Once an attacker breaks into the honeypot, the security admins can identify how the hackers compromised the target, the hacking techniques they deploy, and how their networks defended or compromised. The honeypot experiment will help organizations identify security loopholes and strengthen the overall cybersecurity defenses.

Types of Honeypots

1. Research Honeypots

Research honeypots are used to analyze hacker activities and developments. Information stored in research honeypots helps security analysts track stolen data and identify various attackers involved in the intrusion.

2. Production Honeypots

These honeypots are placed inside production networks as bait to draw intruders away from the production network. A production honeypot is designed to look like a legitimate part of the production network and contains fake data to attract hackers.

3. Pure Honeypots

Pure honeypots mimic a legitimate production system with mock confidential files and user information, appearing realistic to hackers. Pure honeypots are complex and difficult to maintain.

4. High Interaction Honeypots

High interaction honeypot impersonates the activities of a production system, hosting different applications and services. These honeypots are designed to lure an attacker into gaining root-level access to the database to monitor their actions.

5. Low Interaction Honeypots

Low interaction honeypots are primarily placed in a production environment. These honeypots act as an early security warning mechanism to prevent cyber intrusions. Most organizations or security teams rely on low interaction honeypots as they are easy to deploy and maintain. Though low interaction honeypots are more likely to look fake to intruders, they are good at detecting botnet and malware attacks.

Honeypot – Effective Preventive Measure

Deploying honeypots offer several security advantages to companies that are trying to boost their network defenses. Implementing honeypot technologies help security admins to break the attacker chain and avoid possible cyber risks. Electronics manufacturer Panasonic claimed that it increased its Internet of Things (IoT) security by connecting them to internet honeypots. Panasonic stated that it has been able to find around 179 million attack cases and nearly 25,000 malware samples, of which 4,800 were targeting IoT. 

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from Rudra.

What Is Digital Evidence and Why Is It Important in 2021?

Digital evidence

Digital evidence, also known as electronic evidence, offers information/data of value to a forensics investigation team. Every piece of data/information present on the digital device is a source of digital evidence. This includes email, text messages, photos, graphic images, documents, files, images, video clips, audio clips, databases, Internet browsing history etc.

With the dependence on electronic media and IoT devices, the risks and vulnerabilities associated with digital devices are also high. E.g., cybercriminals can launch a malware campaign by infecting a computer with a virus to further their malicious intent. Here, digital forensics experts’ role in identifying and preserving evidence gathered from the digital device during a criminal investigation is paramount.

This article explains digital evidence, its types, and how you can pursue a career in this field.

What is Digital Evidence?

As explained in the above section, digital evidence is best described as the data generated or found on any electronic device such as mobile phones, computers, smart TVs etc. Every electronic device combined with IoT technology is a potential source of digital evidence and is crucial to forensic investigations. Forensics experts gather, identify and preserve the evidence from these sources to track the perpetrators of the crime and present them in a court of law. Additionally, pieces of digital evidence prove useful in corroborating a timeline of events.

A digital forensic examiner must consider a variety of types of evidence. We shall discuss a few.

1. Analogical Evidence

Analogical evidence can prove helpful in scenarios with limited information or credible evidence to present during the investigation. By drawing comparisons between two similar cases, analogical evidence can lend credibility during a formal argument; however, it cannot be shown in court as proof.

2. Anecdotal Evidence

Anecdotal evidence loosely translates to accounts or stories by people to a specific incident or event. However, such testimonies do not hold valid in a court but can be used as supporting theory to grasp better or analyze a situation.

3. Circumstantial Evidence

Circumstantial evidence is evidence not drawn from direct observation of a fact in issue. It depends on inferences from a series of facts to draw conclusions in connection with the crime. This evidence is indirect evidence. For example, when investigators retrieve an audio clip about someone expressing their wish to commit a crime before a crime occurs, or some inferences can be drawn from someone’s search history on the web related to the crime. But this is not a direct observation of the crime as it is being committed.

4. Character Evidence

Character evidence is considered as a testimony that validates a person’s actions on a specific depending on the character of that person. Character evidence is handy to prove intent, motive, or opportunity.

5. Digital Evidence

Today, digital evidence has multiple sources, starting from email, text messages, hard drives, social media accounts, audio and video files, smart TVs etc. Therefore, digital data sourced from electronic media and Internet devices is an important link in solving crimes.

Types of Digital Evidence or Proof

In a court of law, evidence is of supreme importance; it is crucial to establish facts. Data or relevant information from electronic devices is pulled from two types of sources.

  • Volatile or non-persistent: Hard disks and removable devices are a few examples of volatile data devices, which means that data is not accessible when they are unplugged from the computer. Further, data can be deliberately erased or wiped from these devices, to destroy evidence. Of course, Volatile also refers to memory that relies on power to store its contents, such as RAM chips. When the power is switched off, the memory contents are lost.
  • Non-volatile, which is persistent: Persistent data is stored permanently in memory, and a loss in power doesn’t erase its content. For example, data stored in flash memory, ROM (Read-only memory), CD/ DVD, or tape.

Forensics investigation is incomplete without digital evidence. Digital data or information stored in electronic devices are associated with e-crime – another word for cybercrime. In the digitalization era, every Internet-enabled electronic device like a smartwatch, smart TV, video game console etc., can be a key component in gathering information to crack a case.

Additionally, the five rules of gathering digital evidence that every forensic expert should keep in mind are that digital evidence should be: admissible, authentic, complete, reliable, and believable. Hence, skilled individuals trained in this field need to handle the digital evidence, which brings us to the next section.

How to Conduct Digital Evidence Acquisition and Analysis

Digital forensics experts gather digital evidence to identify and analyze the case. Based on the type of electronic or digital device, forensic experts decide on their digital acquisition method. While containing the spread of cybercrime is the primary step after a cyberattack, gathering and analyzing digital evidence comes next.

One of the key points to note while handling digital evidence is to isolate the evidence source after seizing the available electronic media. Acquisition of digital data follows forensic principles and procedures. Moreover, forensic analysts need to isolate and store the digital data gathered from the evidence to maintain its authenticity and integrity. Tampered data or evidence is not admissible in a court of law. Next, analyzing the evidence for crucial information is important after creating a forensic image of the electronic media for examination.

While following proper procedures are crucial, digital forensics investigators face many obstacles.

Challenges of Digital Evidence

Acquiring digital evidence is not free of challenges. Only experts with the appropriate skillset and training are qualified to collect digital evidence. It is different from gathering physical evidence, and therefore, handling the digital acquisition of data is not free of risks.

Data stored in electronic media is volatile and is subject to changes or modifications. For example, a software update can change the data in the phone, or suspects can delete their data from the cloud or use the wipe-clean feature on their phones to remove any evidence. Consequently, this can prove tricky for investigators in carrying out the investigation. Besides, examining the massive volumes of data extracted from electronic media or devices is also a tedious task and requires the expertise of a skilled expert.

A forensic expert must be updated on the latest technological changes to be able to analyze and document the evidence. With the changes in big data and the latest technology updates, forensic experts need to be skilled in extracting data from multiple sources without modifying them and preserving the source of evidence for authenticity and integrity.

So, if you have a passion for solving crimes and analyzing evidence to track the perpetrators of cybercrime, the branch of forensic science is right for you. There is a need for cybersecurity specialists trained in digital forensics, which brings us to the last section of the article.

How to Get Certified in Forensic Science

As mentioned earlier, there is a significant demand for digital forensics analysts trained in industry-specific skills. Every organization needs digital forensics investigators to recover lost or stolen data in case of a data breach. Moreover, mapping your workforce to the right skill set is crucial to handle digital data acquisitions.

Hence, a credible course like EC-Council’s Computer Hacking Forensic Investigator (C|HFI) certification helps participants gain the necessary skills. The program highlights the various stages of collecting digital evidence — identification, collection, acquisition, and preservation and equips students with the industry-relevant skills and latest resources to tackle real-world scenarios.

The scope of the C|HFI program is enormous, and one can apply for various job roles such as Forensic Analyst. Forensic Accountant, Cryptographer, Information Security Analyst, Mobile Forensics Examiner, Computer Crime Investigator etc. According to PayScale, the average salary of a CHFI is $96k per year.


20+ Job Roles | 4,000+ Job Openings | Avg. Salary of $96,000

Start your C|HFI Certification and Explore New Career Opportunities in the World of Digital Forensics.


FAQs

  1. What are a few examples of digital evidence?

Not every electronic media or evidence is admissible in court. A few digital pieces of evidence that a court of law considers are emails, digital photographs, accounting files, browser history, GPS tracks, databases, text messages, audio and video files.

  1. What are the rules for digital evidence?

The five rules of gathering digital evidence that every forensic expert should keep in mind are that digital evidence should be – admissible, authentic, complete, reliable, and believable to be admissible in court.


References:

  1. http://www.forensicsciencesimplified.org/digital/
  2. https://nij.ojp.gov/digital-evidence-and-forensicsW