Home Blog Page 55

6 Anti-Forensic Techniques That Every Digital Forensic Investigator Dreads

Anti-forensic techniques

Anti-forensics techniques are designed to frustrate digital forensics investigators. They comprise tact and tools to hoodwink digital forensics investigation. Besides, cybercriminals use anti-forensics tools to hide their footprints from computer forensics experts after a data breach or malware campaigns.

This article explains anti-forensics and its top techniques that attackers use to hide or delay forensics investigation.

Purpose of Anti-Forensics

Anti-forensics refers to any strategy or software to thwart a computer inquiry. People can hide information in a variety of ways. Some applications can deceive computers by changing data. Cybercriminals can circumvent data by changing the header or metadata or altering the header from .jpg to .mp3 to trick people into believing it is an audio file.

Cybercriminals use anti-forensic techniques to falsify the cyber forensics evidence report, leading the forensic investigators on a wrong investigation trail. Therefore, it becomes a daunting task for the forensic investigator to retrieve any evidence from the crime scene. The forensics investigation process requires a lot of time to identify these anti-forensic techniques.

Anti-forensic techniques are used to:

  • Delete evidence of cybercrime
  • Compromise forensic analyst’s reports
  • Delete or modify the log records of the attacker’s activities

Forensic investigators find it tough to recover any solid evidence against the attacker or trace the digital footprints. Therefore, they cannot pinpoint the origin of the attack to retrieve stolen data or reach the attacker group to negotiate the outcomes of the attacks. Several anti-forensic techniques go undetected in a threat or malware detection tool or security analysis.

Top 6 Anti-Forensic Techniques  

With the increase in ransomware attacks and other malware campaigns, it’s evident that cybercrimes are increasingly using sophisticated techniques to launch their attack. Some of the popular anti-forensics’ methods threat attackers use include:

1. Encryption

One of the widespread anti-forensic techniques is encryption, which is the art of embedding confidential and sensitive information into ciphertext (garbled text). Modern-day encryption algorithms are used to prevent unwanted eyes from accessing the concealed text, image, or code. Attackers make use of full-volume encryption and a key file to hide their malicious codes or campaigns. A secret key is used to seal the information, which is then decrypted — deciphering ciphertext back to plain text at the destination point.

Forensic analysts are unable to decrypt malicious files without an authenticated secret key. Malicious files which are encrypted are not detected in many security screening techniques and tools.

2. Program Packers

Program packers are just one of the many anti-forensics techniques that attackers use to hide their data from any detection or scanning methods. Like cryptography, the packers first compress/encrypt the data files and other executable file codes. The program packers were initially used to compress the size of the files and programs. However, hackers started utilizing packers to hide an infected file or program to trespass the security by avoiding detection through anti-malware tools or security analysis.

Some of the packers used for malicious purposes are UPX, The Enigma Protector, MPRESS, etc.

3. Overwriting data

Attackers use overwriting programs to circumvent forensics investigations and minimize digital footprints. Otherwise known as data cleaning or data erasure, securely deleting data is an old-school trick that attackers use. Many tools are available today to overwrite crucial text, metadata, or entire media on a storage system, which hinders the task of forensic analysts during the recovery phase. This technique of overwriting original data minimizes the attacker’s digital footprints of false and altered data. Overwriting data includes:

  • Overwriting all the original data
  • Overwriting individual files
  • Overwriting previously deleted files and working on those files until no free space remains

4. Onion Routing

Onion routing is a technique used to communicate anonymously over a network where the messages are encrypted in a layered manner. The layered encryption resembles an onion, hence the name. The Onion Router or TOR is used to access the web anonymously, providing hackers with a great option to access the dark web, hide their footprints and launch cyberattacks. Onion Routing allows hackers to hide their internet activities, IP address, and network usage.

The data transmitted through onion routing passes through multiple network nodes, each with layered encryption. The data reaches the destination when the last encryption layer is passed through. Forensic investigators will successfully break through each layer from the destination to the exit node to determine the attacker. Onion routing makes it difficult for forensic investigators to trace the attack back to the attacker and increases the time for security analysis.

5. Steganography

Steganography is the process of hiding secret messages or information within an audio, image, video, or text file in a non-suspicious manner. Steganography techniques are often incorporated with encryption to provide an added layer of security. The secret data is extracted by the authenticated person with access to the destination using a steganography tool for decoding the hidden message.

Hackers have been using steganography to hide malicious codes and files within legitimate files to bypass security and obfuscate their trails. This anti-forensic technique allows attackers to conduct malicious activities without being detected through threat detection tools and other security parameters. Hackers have been known to hide secret malicious payloads or suspicious messages with invisible ink within images of celebrities, news articles, advertisements, etc.

6. Changing Timestamps

Forensic investigators can pinpoint or trace the attacker by figuring out the location and time of the attack. Therefore, attackers use anti-forensic techniques such as changing timestamps to hide or eliminate the logs, determining the attacker’s location or attack time. Changing timestamps can delete the entries or overwrite the entry logs, making it difficult for the investigator to determine the actual information for evidence.

Attackers can even modify the timestamp of a file or program as an added method to escape the investigation. They alter the timestamp on the servers to bypass the network security, launch an attack and delete the evidence without it being logged into the server.

The challenges anti-forensics tools present to a digital forensics’ investigation are alarming. Businesses are transitioning to remote work frameworks and adopting sophisticated digital practices. Likewise, malicious actors using anti-forensics tools and techniques to launch malware campaigns are evolving and increasingly complex. They can also encrypt network protocols to perform identity theft or corrupt files. Therefore, organizations must implement countermeasure strategies to detect, report, and restrict the use of anti-forensic techniques. However, only a qualified team of digital forensic experts trained in the field can perform these tasks. So, if you further your career in this field, you need to gain knowledge and a certificate in a credible program.

Become a Certified Hacking Forensics Investigator

Certified Hacking Forensics Investigator (C|HFI) certification presents a detailed insight into digital forensics with hands-on and lab-based training. The program trains participants to tackle real-life threat incidents allowing them to investigate, record, and report cybercrimes to prevent future attacks. You can also gain proficiency in different subjects under this program – cloud forensics, data acquisition and duplication, computer forensics investigation process.

Computer forensics is a thriving field. Through C|HFI you can prepare yourself to be eligible for different job roles such as forensic analysts, cybercrime investigators, malware analysts, and security consultants.


20+ Job Roles | 4,000+ Job Openings | Avg. Salary of $96,000

Start your C|HFI Certification and Explore New Career Opportunities in the World of Digital Forensics.


FAQs

1. What is the role of computer forensics in an investigation?

To gather the digital forensics evidence in case of cybercrime, one can understand the role of a computer forensics expert in three steps to track the attacker:

  1. Preserving or securing the digital device
  2. Analyzing the state of digital device
  3. Reporting retrieved information

2. How much can one earn as digital forensics professional?

According to PayScale, the average salary for a computer forensic analyst is $75,073. The median salary for an entry-level computer forensic analyst is $65,371, according to Salary.com.


References:

  1. https://resources.infosecinstitute.com/topic/top-13-popular-packers-used-in-malware/
  2. https://resources.infosecinstitute.com/topic/computer-forensics-anti-forensic-tools-techniques/
  3. https://www.researchgate.net/publication/228339244_Anti-forensics_Techniques_detection_and_countermeasures

2022 Drifting Clouds: The Security Trend

cloud, cloud security

The future of cloud computing and the corresponding information security is and should be the prime concern for every business, provided a majority of them are migrating or aiming to shift to the cloud to further develop their business operations. The global pandemic could be said to have served as a stimulus for business and security heads to opt for cloud services. But with this spontaneous growth in demand for cloud-based solutions raises the question as to how safe the service is when subjected to the current threat landscape, and this will be able to keep up with the change in technology landscape and trends.

By Mohamed Mostafa, Global CISO for Egyptian Arab Land (EAL) 

The pandemic served as a multiplier for CIOs’ interest in the cloud.

– Gartner

More subscribers, bigger scalability

Whilst the impact of the global pandemic was at its peak, shutting down many non-IT businesses, it would not be an exaggeration to say that it was the cloud computing technology that supported a large portion of the global supply chain and economy from falling apart. Without the cloud, it would have been a challenge for a business to function as it did, and more and more businesses are now migrating to cloud storage and services, with Gartner predicting public cloud service to grow by 23%.

Worldwide end-user spending on public cloud services is forecast to grow 23.1% in 2021 to total $332.3 billion, up from $270 billion in 2020.

– Gartner

Cloud technology is growing continuously in terms of both size and capabilities, with an aim to improve organizational agility and correspond to the new workload. Different service models and platforms are available for organizations to incorporate their supply chain, partially or completely. With such great dependence on the cloud, it is imperative for businesses to think about its growth and security capabilities to manage the workload in the coming future.

Emerging trends and new opportunities

Cloud computing has always been subjected to dramatic changes in its short tenure. It boldly transitioned supportive software tactical resources to speed up processing and global access to an important strategic framework for greater supply chain output and secured operation. Marching in the new decade, now the cloud is transforming again by opening up new and wide-reaching avenues of opportunity that aim at connecting organizations and communities at a level never seen before. These emerging trends are accelerators for innovative technologies for the cloud and virtual ecosystem. The integration of technologies such as blockchain, Internet of Things (IoT), Artificial Intelligence, and Machine Learning (AI and ML) is projected to impact every industry and business sector.

Emerging technologies such as containerization, virtualization, and edge computing are becoming more mainstream and driving additional cloud spending.

– Gartner

Organizations aiming at incorporating cloud-native solutions in their supply chain need to understand the upcoming changes in cloud computing and security as they may greatly impact their optimization of operations architecture. It implies that, as more and more organizations make a shift to the cloud, we will be able to see new technology and security trends. To ensure that organizations are prepared for the rapidly approaching cloud-native change, here are some of the cloud technology and security trends that IT and cybersecurity leaders should look out for.

Depending on a single cloud may not be sufficient

Hybrid cloud topology implies utilizing all the computing, storage, and service environment available, i.e., hybrid cloud implementation and on-premise infrastructure, with orchestration across various resources and platforms. Though public and private clouds have their own benefits such as scalability, low costs, security, and flexibility, the main value of implementing cloud lies in providing support to increase the pace of business transformation. Hence, some of the drawbacks of implementing public and private cloud individually, such as higher security responsibility, lower data control, higher OPEX expenditure, may hinder the cause. Hence, the hybrid approach allows applications and assets to operate across cloud instances and architectures within an agile environment.

Organizations need to determine whether or not to choose a hybrid cloud in response to their evolving need (and compliance requirements). These dynamics of hybrid cloud implementation depend upon factors such as scale and sensitivity of the workload, big data, flexibility and processing capacity needs, available resources, and compliance requirements.

On the verge of hyper-scale cloud

Though the aim of edge computing is to bring the computing and data storage close to the device or data source, edge cloud is a virtualized infrastructure that has the benefit of both cloud and on-prem operations. Edge cloud has the ability to handle a sudden spike in the workload due to an increase in user activity and helps scale applications and processes for both testing and deployment. Its high efficiency and scalability features are its prime benefits and are also cost-effective. Edge cloud computing could seamlessly integrate with manufacturing, enterprise, healthcare, gaming, media, and telecommunication sectors. The Telco edge overlaps with use cases of AR (Augmented Reality) and VR (Virtual Reality), automobile, and many other industries that have a telco-based mobile platform or supply chain.

Securing the serverless

Cloud-native security (CNS) aims at securing the cloud-native computing of scalable applications and processes in dynamic environments such as public, private, and hybrid clouds. Cloud-native technologies such as containers, service meshes, microservices, etc., are serverless entities that tend to balance and manage the orchestration and monitoring of infrastructure operations.

Elevating the need for focus on infrastructure, cloud-native computing helps developers focus their time and energy on optimizing business operations. Cloud-native security requires high fidelity, and lack of centralized visibility increases the likelihood of vulnerabilities going undetected. Cloud-native integrated security also involves the incorporation of artificial intelligence and continuous assessment and monitoring towards data analysis capabilities.

In practice, ML “solutions” have yet to offer practical applications for security, but this will change over the next 18 months, as we start to see examples of ML deployed within some very specific use cases.

– Paloalto network.

AI and ML

Artificial intelligence can significantly increase security in the cloud through vulnerability detection and threat modeling. AI provides the cloud with automated functions such as event production, automated threat detection, data control through endpoint protection and authentication, vulnerability assessment, and real-time monitoring. Learning through various algorithms and data captured across the network, AI will learn to detect incidents, suspicious behavior, unauthorized access and combine this with automated operations to further improve cloud security.

Similarly, machine learning has the capability to provide the cloud service and corresponding security with boost for specific use cases such as data classification, malware detection, and automation functions. It will implement automated reasoning to evaluate security configurations, policy effectiveness, permissions, etc., from different points of view.

Through 2025, 90% of the organizations that fail to control public cloud use will inappropriately share sensitive data.

– Gartner

The ceaseless vigil

Continuous monitoring has been at the center of cloud security debates for a while now, and projects such as CCM (Cloud Controls Matrix), which are used to evaluate cloud service providers (CSP), also take this feature into account. Security monitoring is a critical component of cloud-native security that involves automated solutions for vulnerability detection to oversee both physical and virtual storage assets to assess data, behavior, applications, and infrastructure for potential security risks. Continuous monitoring will prevent data loss in the cloud, thus putting the business and security leaders at ease and more inclined towards migrating data and supply chain operations to the cloud.

Through 2025, 99% of cloud security failures will be the customer’s fault.

– Gartner.

Managing the security posture of cloud

Cloud Security Posture Management (CSPM) aims at identifying issues and risks related to misconfiguration and compliance in the cloud. It involves tools designed to detect and fix cloud misconfiguration issues and can use the defined best practice according to the cloud environment it is deployed in. Some tools combine real-time monitoring and automation for mitigating issues arising from misconfiguration. It involves capabilities such as maintaining best practice inventory, mapping configuration status to security control framework, working in all modes of containerized, hybrid cloud, and multi-cloud environments, monitor storage buckets, encryption, permissions, etc., for compliance risks.

Cloud-based PKI

The role of Public Key Infrastructure (PKI) is to manage secured digital assets (that involves systems, user, service, or a router) while sharing information over untrusted networks. It has become an essential asset to organizations for a security control framework. PKI helps secure data along with end-to-end lifecycle automation while operating in accordance with the industry best practices. PKI combines different technologies for authenticating users, devices in the cloud environment. It allows confidentiality and authentication of identities while maintaining the conversation private. Its core functionalities involve confidentiality of identities, managing the availability of CIA triad components, authorizing accesses, and maintaining data integrity.

Conclusion

Cloud security implementation is a joint responsibility between the cloud service provider (CSP) and business operations/owners (with the responsibility of business owners to assure the right implementation from both parties). The future of cloud security is dependent upon how the above-mentioned trends transform themselves into active profiles of aggressive threat prediction measures. With ransomware attacks on the rise, along with the increase in its sophistication that renders traditional and legacy security useless, it could be said that cloud security will be the new face of cybersecurity. In order to defeat attacks that use innovative and disruptive technologies, threat prediction has become essential for real-time threat mitigation. As cybersecurity moves to the cloud, it can use big data and instant analytics over the end users to quickly address known vulnerabilities and predict threats that may ted to bypass the existing security.

The native cloud security will create a harmonious approach that analyses the stream of threat events across all user databases to create a global threat monitoring platform. This collaborative approach involves leveraging big data and analytics applied across multiple users involved with the same cloud environment to build an ecosystem that instantly predicts threats through a global threat monitoring and mitigating system. Predictive security could be said to be the way forward, as it is said to be the ideal threat mitigation system that could keep malicious actors at bay in the coming years. Analysis of endpoint data to detect and disseminate potential threat information across the cloud entities under a single umbrella is an effective predictions system that is capable of protecting against future and as-yet-unknown attacks.

References:

  1. https://hackernoon.com/what-does-the-future-hold-for-cloud-security-i82e35md
  2. https://www.gartner.com/en/newsroom/press-releases/2021-04-21-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-grow-23-percent-in-2021
  3. https://www.netapp.com/hybrid-cloud/what-is-hybrid-cloud/
  4. https://stlpartners.com/edge-computing/what-is-edge-computing/
  5. https://www.checkpoint.com/cyber-hub/cloud-security/what-is-cloud-native-security/
  6. https://www.paloaltonetworks.com/blog/2020/04/cloud-security-2021/
  7. https://www.tftus.com/blog/ways-ai-is-improving-cloud-security
  8. https://digitalguardian.com/blog/what-cloud-security-monitoring
  9. https://technologymagazine.com/cloud-and-cybersecurity/ibm-acquire-bluetab-expand-data-and-hybrid-cloud-services
  10. https://searchcloudsecurity.techtarget.com/definition/Cloud-Security-Posture-Management-CSPM
  11. https://www.encryptionconsulting.com/cloud-based-public-key-infrastructure-architecture/

About the Author

Mohamed Mostafa With nearly 30 years of experience in networking and information security, Mohamed Mostafa is an expert at overseeing the development and execution of information security and risk management programs for highly regulated, multinational companies. He is currently the global CISO for Egyptian Arab Land (EAL) bank, while simultaneously serving as an executive member of the CyberEdBoard Community. He holds multiple certifications and has an astounding knowledge of conducting in-depth assessments for swiftly identifying gaps in processes, practices, and controls, towards protecting critical assets from a broad range of threats whilst ensuring compliance with all regulatory requirements. He is an accomplished leader ability to train and lead high-performing teams for IT infrastructure and information security operations, disaster recovery, and incident response. His accomplishments involve numerous large-scale projects managements with complex requirements, across the financial and banking sectors.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

61 Mn Fitness Tracking Records Leaked via Unsecured GetHealth Database

Healthcare IoT, Fitness Trackers

The rise of IoT devices in the health care sector led to various potential cyber risks. The usage of wearable devices like fitness bands and health trackers has become rampant lately. The security of fitness trackers becomes a perennial concern as they store users’ sensitive data. A recent security investigation from WebsitePlanet found an unsecured database exposing over 61 million records of fitness wearable devices online. The database, which belonged to GetHealth, was not password-protected, allowing anyone open access.  The database is now secured after researchers reported the issue to GetHealth.

Based in New York, GetHealth provides a unified solution to access health and wellness data from hundreds of wearables, medical devices, and applications. The GetHealth platform can sync health-related data from various sources, including Fitbit, Misfit Wearables, Microsoft Band, Strava, Google Fit, 23andMe, Daily Mile, FatSecret, Jawbone UP, Life Fitness, MapMyFitness, MapMyWalk, Moves App, PredictBGL, Runkeeper, Sony Lifelog, Strava, VitaDock, Withings, Apple HealthKit, Android Sensor, and S Health.

Data Exposed

Most of the exposed information included users’ first and last names, display names, date of birth, weight, height, gender, geolocation, etc. “This information was in plain text while there was an ID that appeared to be encrypted. The geolocation was structured as in America/New_York, Europe/Dublin and revealed that users were located all over the world,” WebsitePlanet said.

While analyzing a sample of 20,000 records, the researchers found that most of the exposed data is from Fitbit (appeared 2,766 times) and Apple HealthKit (17,764). The users of Apple Healthkit are most affected by this security incident as Healthkit collects more health data such as blood pressure, body weight, sleep levels, and glucose levels than other devices or applications.

Security Risks with Fitness Trackers          

Fitness trackers are designed to monitor our health by accessing critical information. Unfortunately, they could also lead to several privacy risks. Users’ sensitive information is a money-making business for threat actors. The exposed information could be misused by cybercriminals in targeted phishing attacks, identity thefts or perform social-engineering attacks.

“This case sets an example of how lack of care with sensitive data can make risks escalate indefinitely, as millions of people were exposed simply by wearing tracking devices during their workout sessions,” WebsitePlanet added.

Hackers Use SSID Stripping to Trick Users Into Joining Rogue APs

SSID Stripping

With the evolution of new threat actors and their latest attack vectors, the cyberthreat landscape is larger than expected.  Security experts from AirEye recently uncovered a new hacking method, dubbed as SSID Stripping, which could be leveraged to trick unwitting users into connecting to fraudulent wireless networks.

What is SSID Stripping?

In a joint research with Technion, AirEye revealed that threat actors could manipulate the name of a wireless network, particularly the SSID (Service Set Identifier), to display as a legitimate network to the users. SSID Stripping enables attackers to trick users into connecting to rogue Wi-Fi networks set up by them. Users connected to these networks would become vulnerable to device compromise, malware attacks, and data thefts.

In general, Wi-Fi networks are identified based on their network name, formally known as SSID. The SSID acts as the primary identifier for a user to find and connect to a specific network. Different devices provide different network names, which are also called Access Points (APs).

The SSID Stripping method appeared to be a severe security threat, as it impacts several networks and devices running on Windows, macOS, Ubuntu, Android, and iOS. “The SSID published by any AP in the proximity of a wireless client is processed by that client – regardless of whether there is any trust between the client device and the AP. Hence an attacker may attempt to include malicious payload within the SSID in an attempt to exploit a vulnerable client implementation,” AirEye said.

Findings

The research discovered three types of “display errors” using which attackers alter/manipulate the network names. These include:

  • Display Error 1 – A display of only a prefix of the actual network names
  • Display Error 2 – Omissions of some characters from the display name
  • Display Error 3 – Some characters are pushed outside of the visible portion of the display name

Impact

Cybercriminals can use SSID Stripping to perform various attacks, which includes:

  • Creating a more effective rogue Access Point (AP), easily deceiving the user into connecting to a rogue network
  • Incorporating an attack within a network name without raising suspicions from a user or system admins
  • Deploying a malicious code on devices in the rogue network
  • Monitoring or stealing sensitive information from the compromised devices

How to Check for SSID Stripping Vulnerability

AirEye has released a free Windows-based tool, dubbed Hide ‘n Seek, using which users and organizations can verify if they’re vulnerable to the SSID Stripping attack.

“The tool publishes numerous network names using SSID Stripping techniques, based on the original SSID that the user provides. Users can then find out how these network names are displayed on the various devices in their organization to get a sense of how vulnerable their environment is,” AirEye added.

Data Security: More Than Just Confidential Computing

Dr. Nataraj Nagaratnam, Confidential Computing

Sharing sensitive data for processing among ecosystem partners is a challenge. We continue to see enterprises grapple with security concerns associated with moving workloads to the cloud. That’s why Confidential Computing has garnered much interest. As conversations move from ‘whether’ to implement technology to ‘rather’ what are the capabilities, the user community is becoming more receptive to Confidential Computing and looking at leveraging the capability to protect data across the compute lifecycle. As use cases increase, the opportunities to innovate and leverage computing prowess have also evolved. It is not only about security but about data privacy and multiparty computing.

To get a perspective on the adoption and opportunities around Confidential Computing, Minu Sirsalewala, Editorial Consultant, CISO MAG, spoke with Dr. Nataraj Nagaratnam, IBM Fellow and CTO for Cloud Security, IBM. Dr. Nagaratnam deliberated the opportunities around Confidential Computing and the next disruptive technology.

As an IBM Fellow Dr. Nagaratnam is the CTO for Cloud Security with expanded responsibility to lead the security and compliance management, including extensions of these capabilities into hybrid cloud. He oversees the technical architecture for key components of IBM Cloud for Financial Services and the IBM Confidential Computing roadmap. Dr. Nagaratnam is a recognized security expert across the industry and has consistently demonstrated vision and thought leadership, coupled with an ability to execute and implement new technology and solutions for both IBM and clients. He has made sustained security contributions across IBM’s cloud, security and middleware offerings, including most recently the Confidential Computing-based services in IBM Cloud, which serve as the basis for IBM Cloud for Financial Services and IBM’s work in regulated industries. His work has established data security and data privacy credibility for IBM Could and extended his prior contributions to the IBMid, IBM Security, Tivoli and WebSphere businesses.  What excites him every day is not only solving real client problems but also nurturing technical talent. He sees mentoring and helping others to build their leadership skills as a key part of his role. One such notable instance is the assignment he had at India Software Labs and the impact he has made in building the leadership pipeline.

Edited excerpts of the interview follow:

Confidential Computing is all about protecting data in use. Data is stored in the trusted execution environment (TEE) or enclaves and is run on server platforms that could be vulnerable to side-channel and timing attacks. How can Confidential Computing address this risk?

From a technology perspective, Confidential Computing as an enabling technology is about data in use. But the way that we have been doing this at IBM is to leverage the technology to address in a holistic approach, including data at rest, data in transit, data in use.

Confidential Computing is a platform that offers a set of services that customers can consume directly in a secured environment. As a person who has been in the security industry and seen the security landscape evolve, there’s nothing like ‘the person’ is fully secure. Hardware, as compared to software, was not a part of the security hygiene. The vulnerabilities or bugs in hardware had not been thought of the way the software sector was researched and reported. But now, with more hardware-based technology like cognitive computing, the perspective has changed and hardware security is also becoming mainstream. Suddenly the underlying vulnerabilities are also getting attention. This is good news for the industry as more Confidential Computing becomes mainstream and addresses use cases the security posture improves.

Industry leaders at it IBM or Intel or AMD and other large players are working in a unified effort to leverage their expertise and focus on security research to have industry standards in place. They are all working as a consortium to address the challenges and find solutions to the problem. A common challenge is that a particular issue on a given vendor platform may not exist on another platform and the risk does not get addressed. But as an industry, we are taking the findings and learnings from all platforms and are incorporating them to make a common standard. The partners are now putting in a collaborative effort and identifying the value and promise of Confidential Computing for data protection and data privacy and moving forward.

What use cases work best for a Confidential Computing environment?

All use cases are about data protection and privacy of data, both from a risk perspective, and regulatory compliance.

The first set of use cases that we are seeing is, as customers move to the cloud; given the shared responsibility model between them and a cloud provider, they want to have much more of technical control over how their data is accessed.

As cloud providers, customers are questioning them if they have access to their data, their key and more importantly asking for evidence to prove that their data cannot be accessed. The cloud provider is extending that assurance of privacy in a public cloud environment.

For example, let’s look at some of our customers like Daimler – automotive industry in Europe and Bank of America – financial services industry as two use cases. Both these customers deal with confidential and sensitive data and need the assurance, not just operational but technical assurance that we cannot access the keys or the data. So in these use cases, we provide capabilities in platforms about key management systems, what we call ‘keep your own key’, where we provide assurance that it is theirs. Thereby providing them the security of a private cloud, in a public cloud setting. This enables our customers to achieve the level of security and protection like key management and hardware security modules which they practiced on-premise—to be controlled in the public cloud. This has truly opened up the complete use cases. And not just that, within a Confidential Computing environment, where encryption at rest is protected and keep your own key is protected, the security is so stringent that even our operators cannot have access to the system. So in a way, what we are doing is leveraging the use case, it’s about mitigating the risk of privileged user access into the system.

Another use case is of fine-grained control PII (personally identifiable information) data when you want to encrypt-decrypt it. Sensitive personal information like Aadhar numbers or social security numbers in the U.S. needs to be encrypted at the application level. So what we are working on and leveraging is that computers not only keep your own key but also ensure the databases can be encrypted and stored before it leaves the application server. When we look at these highly sensitive data, there are patterns there, especially in the world of Hybrid Cloud and AI. This is a set of use cases coming up called secure multi-party computing.

To explain, take the retail industry, a retailer is seeing organized crime and experiencing a spate of robberies at the stores. They have data they’re analyzing and on talking to their peers and another retail chain, it is known that they’re also facing the same problem. They apply machine learning to identify these patterns so that they can better protect and investigate against these organized crimes. In order to do that, they need to share data that is very sensitive. The data needs to be shared in a way it’s all secure, protected and encrypted. Here they leverage computing concepts like IBM’s hyper-protect services on the IBM cloud. What it does is, take encrypted data from both retailers one and two, put it in an enclave, process the data-which the machine learning algorithm runs within a computing environment and share the findings. The data is computed without being accessed and this has opened up amazing opportunities for people to collaborate and share data. There is a spectrum of use cases emerging as we have consumption computing becoming mainstream.

A full version of this interview will appear in the October 2021 issue of CISO MAG. Subscribe now!

Olympus Confirms Cyberattack Affected Sales and Manufacturing Networks

Microsoft, Cyberattack on Olympus

Not only health care providers, organizations that provide health care technology also become vulnerable to cyberattacks. Medical technology provider Olympus admitted that it had sustained a malware attack lately that impacted some of its sales and manufacturing networks in EMEA (Europe, Middle East, and Africa) regions.

As per official updates (1 & 2), the company temporarily suspended the operations of the affected systems and reported the issue to law enforcement and forensic authorities for further investigation. Olympus also clarified that its regular business operations are unaffected amid cyberattacks.

“Upon detection of suspicious activity, we immediately mobilized a specialized response team including forensics experts, and we are currently working with the highest priority to resolve this issue. As part of the investigation, we have suspended data transfers in the affected systems and have informed the relevant external partners. We have reported the incident to the relevant government authorities. We will continue to take all necessary measures to serve our customers and business partners securely,” Olympus said.

While the threat actors behind the attack are unknown, the investigation claims no evidence of loss, unauthorized use, or disclosure of any data so far. Besides, there is no sign that the cybersecurity incident affected any systems outside of the EMEA region.

BlackMatter’s Involvement

While Olympus claims it is a malware attack, several security experts believe it to be a ransomware attack by the BlackMatter group. It is suspected that the BlackMatter ransomware group compromised and infected Olympus network systems. Attackers also left a ransom note demanding for ransom to recover the encrypted files.

BlackMatter is relatively a new ransomware-as-a-service group (Raas) that emerged recently in the cyberthreat landscape. It is suspected that BlackMatter is a successor of the infamous DarkSide ransomware group that went underground after the attack on Colonial Pipeline. Security experts claim that BlackMatter has capabilities similar to DarkSide, REvil, and LockBit ransomware operators.

Apple Releases Security Updates for Two Zero-Day Vulnerabilities

CISA vulnerabilities, Zero-Day Attack, zero-day vulnerabilities, Apple

The Citizen Lab informed about a new zero-click iMessage exploit, FORCEDENTRY, targeting Apple’s image rendering library. Apple released a security update to address the zero-day vulnerability infecting its products.

See also: Why Zero Trust Model is a Top Priority for Security Leaders Today

Not too long ago, media was rife with news about Pegasus spyware from Israeli company NSO Group being used to snoop on activists, journalists, people in political power, and senior government officials across the globe. A list of more than 50,000 people, which were supposedly targeted, was made public. An important aspect, in addition to the spyware, was the vulnerability discovered in the Apple products. The vulnerability was exploited by Pegasus spyware to infect Apple devices like iPhone, iPad, Apple Watch, or Mac, providing access to the camera and microphone and giving access to the digital life of the device user.

The recently reported vulnerability was assigned CVE-2021-30860 and is described as a maliciously crafted PDF that may lead to arbitrary code execution. Earlier in the year, Apple had added a security feature called ‘BlastDoor’ across its operating systems to add an extra security layer in the iMessage. The spyware bypasses this feature and surreptitiously plants itself on the infected device.

The Vulnerabilities

The vulnerabilities tracked as CVE-2021-30860 and CVE-2021-30858, allow maliciously crafted documents to execute commands when accessed on vulnerable devices.

Vulnerability CVE-2021-30860 CoreGraphics is an integer overflow bug discovered by Citizen Lab that allows maliciously crafted PDF to execute arbitrary code when opened in iOS and macOS.

CVE-2021-30858 is a WebKit used after a free vulnerability that allowed hackers to create maliciously crafted web pages that execute commands when they visit them on iPhones and macOS.

In an urgent update, Apple has urged its customers to run the latest software updates for the fixes to take effect by installing iOS 14.8, MacOS 11.6 and WatchOS 7.6.2.

With the next iOS 15 on the anvil, the company is expected to add security features to fix the spyware intrusion and tighten its defense.

What is Man-in-the-Middle Attack and How to Prevent them

Man-in-the-Middle Attack

Man-in-the-middle (MITM) attacks are gaining importance in the cyberattack landscape as threat actor groups are leveraging it more often to harvest users’ sensitive data and break into targeted network systems. Personal information obtained via MITM attacks could be used to launch various cyberattacks, including identity theft, illicit fund transfers, and credential stuffing attacks.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is Man-in-the-Middle Attack? 

In a man-in-the-middle attack, the perpetrator places himself in an ongoing communication or data transfer between an application/service and its user to spy or impersonate someone. The MITM attackers mainly focus on stealing personal information like bank account numbers, credit/debit numbers, account login credentials, and other banking-related data. They primarily target e-commerce sites, financial applications and websites, other websites, where logging in is involved.

The MITM attack typically occurs between two genuine communicating hosts, between a machine and a user; two machines; two users, enabling a hacker to snoop a conversation or exploit the targeted system.

Man-in-the-Middle Attack
Infographic: CISO MAG

Impacts of MITM Attack

A successful MITM attack could enable an attacker to:

  • Position themselves as proxies in an ongoing conversation or data transfer
  • Exploit the communication and data transmission stealthily
  • Steal confidential information regarding trade secrets or fund transfer details
  • Insert malicious codes or links disguised as legitimate data

Types of Man-in-the-Middle Attacks

1. Email Hijacking

In email hijacking, threat actors compromise victims’ email account and eavesdrop on the email conversations. Email hijackers also leverage phishing lures like social engineering tactics to obtain sensitive information or inject malware by impersonating an authorized person.

2. IP Spoofing Attacks 

In an IP spoofing or IP address spoofing attack, hackers create a false IP address source to impersonate another computing system to break into a network monitor the activities silently. Threat actors primarily leverage IP spoofing attacks to launch Denial of Service (DoS) attacks.

3. Session Hijacking

Session hijacking, also known as cookie hijacking, is a process of exploiting an online session to illicitly gain access to the information or services on the website, application, or device. Session hijackers typically target browser or web application sessions while you are shopping online or paying bills.

4. DNS Spoofing 

Also known as DNS cache poisoning or DNS poisoning, a DNS spoofing attack corrupts the DNS server by changing the actual IP address with the bogus one in the server’s cache memory. Attackers use this technique to redirect the web traffic to the hackers-controlled site to harvest sensitive data.

5. Wi-Fi Eavesdropping

Most public Wi-Fi networks are insecure and easy to tamper with. Threat actors often rely on public Wi-Fi hotspots to infiltrate into user networks to eavesdrop on the activities.

Cybercriminals could also launch a Wi-Fi Eavesdropping attack by creating their Wi-Fi hotspot called Evil Twin – a fraudulent Wi-Fi access point disguised as legitimate that spies on wireless communications.

6. Man-in-the-Browser 

In man-in-the-browser attacks, threat actors try to exploit vulnerabilities in browsers and web applications to deploy malware, Trojans, and malicious Java codes to capture users’ private information in real-time.

Real-World MITM Attacks

From exploiting Cable Haunt vulnerability that exposed over 200 million modem gateways in Europe to snooping more than 500 million UC Browser users, the MITM attacks have increased their reach in the security landscape. The man-in-the-middle attack is also included in the primary attack techniques used by cybercriminals to launch significant cyberattacks along with Distributed Denial of Service Attack (DDoS), SQL Injection attack, and phishing attacks.

How to Prevent Man-in-the-Middle Attacks

In general, most MITM attacks can be detected and prevented by following basic security and encryption measures. Users must:

  • Avoid public and insecure Wi-Fi connections while using e-commerce or banking websites
  • Pay attention to browser notifications for unsecured websites.
  • Properly log out from all applications online after the session.
  • Secure your device with an intrusion detection system. Deploy strong firewalls and protocols to prevent unauthorized intrusions.
  • Secure communication protocols like TLS and HTTPS with robust encryption and authentication procedures.
  • Verify domain names and browsers before visiting an unknown or insecure website.
  • Check for a green or gray padlock located to the left of the web address for legitimacy. In case the browser shows a red padlock, the website might be insecure.

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from Rudra.

Overcoming the Challenges of Executing a Remote Security Policy

Remote Security Policy, Remote Work Jeopardizes Corporate Network Security: Report

Gartner estimates that around 30% of workers in India will be remote in 2022. While the penetration might be low compared to the U.S., where remote work will account for around 53% of the workforce, the sheer volume of remote workers in India will be significant. That makes it crucial for every organization to have a Remote Security Policy.

By Nitin Varma, Managing Director – India & SAARC, CrowdStrike

As today’s workforce moves outside physical office spaces, modern security architectures are having to move away from a well-defined perimeter where everything was consistent and trustworthy. The increase in a distributed workforce in addition to the adoption of cloud-based computer infrastructure means that the attack surface is also expanding. Not having a full view of the attack surface can pose enormous challenges for organizations.

Here are some points organizations must consider while implementing a remote security policy for new, remote environments: 

Identity and Authentication Protection

Research from CrowdStrike finds that attackers can move around inside enterprise infrastructure very swiftly. The ‘breakout time’ or the time it takes attackers to move from the initial machine to the other was reduced by 50% to 4 hours, 28 minutes in 2020. For example, in the recent SolarWinds supply chain and Microsoft Exchange breaches, cyber attackers remained undetected in networks for extended periods disguised under genuine credentials. As a result, companies need to shift to security methods that authenticate a user’s identity at every-level with such threats lurking around. In addition, organizations should rework security policies to ensure increased visibility, access controls and put more checks in place across all levels. 

Employee Cyber Education

An organization’s risk increases substantially when its employees don’t understand concerns around cyber threats. Home networks further complicate this by posing a significant gap in companies’ ability to address attacks quickly and effectively in a remote environment. Organizations need to fill that gap by guiding and sensitizing employees to the effects of cyber threats. While reliance on home routers may be unavoidable, introducing some basic best practices can significantly improve employee vigilance about keeping sensitive company data safe. In addition, employees should get well-versed with cyber incident response protocols to adapt if and when an incident hits.

Know Everyone Connecting to Your Business Assets

These connections are typically endpoints such as mobile, laptops, desktops, or private networks. They must be assessed regularly to understand their security posture so that threats are detected and prevented promptly. In addition, organizations must also develop the ability to perform remote surgical incident response and support as needed. Using the Zero Trust architecture can help with this. 

Remote Security Policy: A Case for Zero Trust

A remote security policy must include zero trust. In a Zero Trust model, there aren’t any trusted sources. Most businesses often arm themselves against every threat outside the network, protecting their castle with high walls and a moat, but forget there can also be threats inside the ramparts.

The Zero Trust model assumes future attackers are present both inside and outside the organizational network. Therefore, every request to access a system must be continuously authenticated, authorized, and encrypted, combining real-time analysis and Machine Learning (ML). Otherwise, there are chances of missing the critical window before an intruder moves from the first compromised machine to the remaining network system

Around 80% of all breaches result from compromised identities; therefore, it’s become increasingly evident that adopting Zero Trust architecture is crucial.

Two-factor and multi-factor authentication (MFA) are among the most common ways to confirm a user’s identity and increase the network’s security. A proper end-to-end Zero Trust solution can provide the organization with MFA coverage and comprehensive visibility. In addition, such software also allows monitoring across authentication traffic and user behavior, helping improve the enterprise’s security hygiene. 

Importance of Zero Trust for Remote Workplaces

CrowdStrike’s 2021 Global Threat Report found that eCrime intrusions increased to 79% in 2020, compared to 69% the previous year. Additionally, it shows that attacks motivated by financial gain are taking a larger share of the total. Cyberattacks, including ransomware, have increased as work environments changed and organizations were required to support more remote employees. As threats increase against these remotely located systems, the ability to block attacks and respond rapidly in the event of a compromise is becoming more challenging. Therefore, organizations require a combination of measures to protect against today’s threat landscape.

If done correctly, Zero Trust can protect against devastating threats such as those that compromise legitimate credentials and target employees’ identities to ensure better defenses against supply chain and sophisticated ransomware attacks.

For example, we’ve seen cyber crooks demanding double extortion techniques, where they ask for a ransom in return for an organization’s sensitive data and then order an additional ransom with the threat of disclosing or selling the data. Zero Trust models are essential for companies against these escalating attacks because they prevent further damage once a network is compromised.

Of course, Zero Trust architecture is just one aspect of any comprehensive remote strategy. While technology plays an integral part in protecting the organization, digital capabilities alone cannot prevent breaches. To create a genuinely resilient enterprise, organizations must educate their employees and make them aware of security challenges. And, they must adopt a comprehensive security solution that reduces the risk of attacks, incorporates a variety of endpoint monitoring, detection, and response capabilities, and leverages threat hunting to secure their networks.

About the Author

Nitin Varma, Managing Director - India & SAARC, CrowdStrike, remote security policyNitin Varma comes with 20+ years of experience in sales and business development, global account Management, CXO relationship management, business strategy and sales process re-engineering. In January 2020, he joined CrowdStrike as MD – India & SAARC. Nitin is responsible for leading the business in the India & SAARC for CrowdStrike. Previously he has worked with organizations like Tata telecom, Avaya, Cisco, Palo Alto Networks before joining CrowdStrike.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

National Coding Week 2021 Reminds Us About the Importance of Digital Literacy

National Coding Week

Learning digital skills and gaining technical knowledge are essential in a rapidly changing digital world. People with no or minimal digital knowledge often fall victim to various online scams and frauds. To bring awareness to this digital literacy gap, the global security community celebrates National Coding Week every year.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Coding is the process of using a programming language to instruct a computer to perform specific activities. Computers follow a set of instructions (code) written in a programming language such as C, C++, Java, and HTML. Each of these programming languages has a unique set of keywords and syntax for creating instructions for computers.

What is National Coding Week?

National Coding Week encourages adults and children to learn digital skills. This year, National Coding Week will occur between 13-19 September. Several security experts, organizations, and volunteers will organize various learning sessions that provide basic knowledge on coding and programming.

Origin

The idea of the National Coding Week movement was started in the U.K., in September 2014, by former headteacher Richard Rolfe and tech entrepreneur Jordan Love. They were also appointed as EU Code Week Ambassador for the U.K. Since then, the movement has been educating several people in the country in improving their digital literacy and in protecting against various threats online. The National Coding Week has spread beyond the U.K. into the EU, the U.S., Australia, and other countries.

Importance of Digital Literacy

Advances in technology have changed the way people work and interact. It also changed the way children learn with the increase in virtual and e-learning platforms. According to a survey, 75% of fifth and eighth graders are non-proficient in 21st-century skills. It also found that providing students with tools for building digital literacy skills is crucial for closing this severe skills gap. Digital knowledge gives the ability to use information and communication online more effectively, without falling prey to cybercriminals. Students develop technical skills and practice cyber hygiene while using the Internet on digital devices, by becoming digitally literate.

Conclusion

Coding has become critical for all businesses in different sectors. Coders and software developers are a crucial asset in every organization, to advance and maintain websites, applications, and other digital operations. As organizations continue to run their businesses amid distributed work environments, the National Coding Week reminds us of the importance of coding skills across all sectors.

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from Rudra.