Home Blog Page 71

Episode #13: The Biggest COVID Security Issue Today – Identity Across Multi-Cloud

Multi-Cloud Identity Management

The COVID-19 pandemic transformed the way businesses adapted to the new normal of working from home, leveraging the cloud strategy to meet rising demands across all business channels. Most organizations migrated across multiple clouds, compromising their security infrastructure. And now that they are working towards addressing these security concerns, a new challenge has set foot: Multi-Cloud Identity Management.

This is a major problem because identity and access management (IAM) have emerged as a cornerstone of modern cybersecurity programs – and it has become even more important in today’s COVID-driven “digital workplace,” where people can work from anywhere.

While several companies looked for IAM technology vendors that supported multi-cloud management of identities where the native tools offered by the cloud platform vendors worked for multi-cloud infrastructure, several of them found themselves stuck in the sand. To dive deeper into the subject, Augustin Kurian, former Assistant Editor of CISO MAG discussed the IAM and PAM trends with Julie Talbot-Hubbard, SVP, Cyber Protection, and Identity, Optiv, and Andy Walker, Identity and Access Management Leader, Cyber Protection and Identity at Optiv.

RSS: https://feeds.soundcloud.com/users/soundcloud:users:899202688/sounds.rss

Spotify: https://open.spotify.com/show/7pBhvwEVAaL4uUJnzD5rWO

Julie has nearly 20 years of experience in information technology, cybersecurity, and data management across numerous industry verticals. In her current role, she is accountable for developing and implementing Identity, Risk, and Data Protection services leveraging security partner solutions to protect the organization’s most critical assets while ensuring a secure, compliant, and uniform digital experience.

Julie has held key transformative CISO and Data Leadership positions at Symantec, the Ohio State University, Cardinal Health, JP Morgan Chase, Nationwide Insurance, and SunTrust Bank. Her focus was establishing and aligning global security and data strategies while leading the implementation of Security and Data capabilities to reduce each organization’s cyber risks exposure while enabling them to maximize their data to grow revenue, product evolution, and consumer delight.

Currently, Julie is serving on several industry boards: The Identity Defined Security Alliance, Cyberstarts and ForgePoint Capital. Supporting one of her passions, Julie is an active Board member of Women in Technology (WIT), Optiv’s Diversity and Inclusion, and Optiv Women’s Network.

Julie is also vocal about the ongoing issues about gender diversity in cybersecurity and how they can be fixed.

Andy Walker, on the other hand, is a seasoned cybersecurity solutions and services leader with more than 18 years of experience, from consulting with the Fortune 100 to running global cybersecurity in various industry verticals. He brings a unique and diverse perspective on how identity can be leveraged as the center of any cybersecurity strategy and digital transformation journey.

APT Group ‘SideCopy’ Found Targeting Govt. Officials in India

SideCopy Malware Campaign

Days after reports of unauthorized intrusions by Chinese state-sponsored actors targeting the Indian power sector, security researchers have uncovered a new cyberespionage campaign targeting government employees. A security investigation from Cisco Talos found increased cybercriminal activities of SideCopy threat actors group targeting government officials in India. The SideCopy gang was found distributing various malware campaigns intended to compromise targeted devices and steal sensitive data. After infecting the targeted source, the attackers deploy additional plugins like file enumerators, keyloggers, and credential-stealers to capture valuable information from government personnel.

The Evolution of the SideCopy Gang

SideCopy is an advanced persistent threat (APT) group active since 2019. The researchers stated that SideCopy is leveraging techniques that are similar to the Transparent Tribe APT group (also known as APT36) to deploy the malware. SideCopy extended its malicious operations and added new tactics to its arsenal. The researchers found different kinds of malware infections chains spreading customized remote access trojans (RATs) like Allakore, njRAT, and CetaRAT.

The Infection Chain

SideCopy group initiates its infection chain using malicious LNK files, followed by multiple HTAs and loader DLLs to deploy additional and final malware payloads. The researchers found the SideCopy campaign using new RATs and plugins including MargulasRAT, DetaRAT, ReverseRAT, and ActionRAT. In addition to the usage of custom RAT families, SideCopy also used other commodity RATs known as Lilith and Epicenter. The successful malware infection led to the installation of additional payloads and modular plugins to perform various malicious activities like keylogging, file enumeration, and browser password stealing.

“Recent activity from the group, however, signals a boost in their development operations. Talos has discovered multiple new RAT families and plugins currently used in SideCopy infection chains. Targeting tactics and themes observed in SideCopy campaigns indicate a high degree of similarity to the Transparent Tribe APT (aka APT36) also targeting India. These include using decoys posing as operational documents belonging to the military and think tanks and honeytrap-based infections,” Cisco Talos said.

Operation SideCopy

In September 2020, cybersecurity solutions provider Quick Heal revealed evidence related to SideCopy’s cyberespionage campaign. Tracked as “Operation SideCopy,” the campaign targeted Indian Army personnel since 2019 to pilfer sensitive information. Researchers observed three infection chain processes in which attackers exploited equation editor vulnerability (CVE-2017-11882) as the initial infection vector. Read More Here

Morgan Stanley Jumps on the Bandwagon of Accellion Data Breaches

Log4Shell

It seems the ripples of the Accellion data breaches continue to affect organizations’ critical infrastructure. From the Office of the Washington State Auditor (SAO), the Australian Securities and Investment Commission (ASIC), to New Zealand’s Reserve Bank, Accellion’s vulnerability has affected several organizations globally. The recent victim to join the bandwagon of Accellion hacks is Morgan Stanley. The global financial services provider recently reported a data breach after unknown hackers pilfered private data of its customers by exploiting the bug in the Accellion File Transfer Appliance (FTA) server hosted by a third-party vendor. Morgan Stanley has a huge client base, including public and private organizations, government entities, and institutions across the globe. The data breach could impact the company in several aspects.

Accellion FTA Flaw – The Culprit

According to an official statement, a third-party vendor Guidehouse notified Morgan Stanley about the security incident on May 20, 2021. Guidehouse offers account maintenance services to Morgan Stanley’s StockPlan Connect business unit. The vendor claimed that attackers exploited the Accellion FTA vulnerability, before it was patched, to access customer data that maintained for Morgan Stanley. The flaw allowed an unauthorized individual to obtain the decryption key during the security incident even though the files were encrypted.

Information Impacted

The accessed information included customer names, residential addresses, birth dates, social security numbers, and corporate company names. However, the vendor clarified that the affected data does not contain any passwords for the financial accounts and had no impact on any Morgan Stanley applications.

“The Accellion FTA vulnerability that led to this incident was patched in January 2021, within five days of the patch becoming available. Although the data was obtained by the unauthorized individual around that time, the vendor did not discover the attack until March of 2021, and did not discover the impact on Morgan Stanley until May 2021, due to the difficulty in retroactively determining which files were stored in the Accellion FTA appliance when the appliance was vulnerable,” Morgan Stanley said.

Is Clop threat group behind the hack? 

While the attackers behind the security incident are unknown, Guidehouse stated that there is no evidence that the leaked data had been distributed or exposed online. Besides, Guidehouse is providing free credit monitoring services for two years to the affected clients and individuals.

Earlier, Accellion issued a statement regarding continuous attacks that exploited its legacy FTA product. The company claimed that cybercriminal group UNC2546 is likely behind the hacks and data breaches. The threat group sent several extortion emails to the victims threatening to publish their sensitive data on their CL0P LEAKS site on the dark web.

Cybersecurity: Under Pressure!

cybersecurity pressure

If you work in a cybersecurity team, you will be under much pressure these days. According to the latest industry reports, the ongoing pandemic has further widened the demand-supply gap for cybersecurity talent. But this shortage was a challenge long before the pandemic emerged last year. The cybersecurity skills gap now numbers more than 4 million unfilled jobs. In the CISO MAG “Confidence in Hiring” survey, 68.96% of respondents say they are slightly understaffed (37.93%) or severely understaffed (31.03%). Per the (ISC)2 “Cybersecurity Workforce Study, 2020” around 22% of respondents reported a significant shortage of dedicated cybersecurity staff, and 42% reported a slight shortage.

While the supply side hasn’t kept up, the frequency of cyberattacks on organizations increases at an alarming rate as adversaries get bolder and take advantage of the situation. That puts tremendous pressure on the CISOs and their organizations as they struggle to find the right people for the job. “For cybersecurity leaders, the challenge of recruiting and retaining the best technical and business professionals is a constant worry. The security workforce shortage remains substantial. There is continued high demand for cybersecurity professionals and an ongoing shortage of talent,” says Prashant Bhatkal, Security Software Sales Leader, IBM Technology Sales, India/South Asia.

CISOs are confronted with the challenge of finding the right talent from thousands of job applications and resumes that reach their Inboxes every week. As Zoom CISO Jason Lee tells us, “During the pandemic, it has been much more difficult to hire. There is much competition for cybersecurity experience. It is difficult to find and recruit the right people when there are so many positions open out there.”

Dick WilkinsonConcurring with Lee’s views, Dick Wilkinson, Chief Technology Officer, New Mexico Judicial Information Division says, “Organizations struggle to identify the skills they desire in security professionals. Within an IT department security is still mysterious. The skills of implementing controls and responding to minor incidents happen in the shadows. That can make it hard to evaluate what kind of person with what skills will be right for this new job. Anticipating the skills to match near future threats or security trends is even harder.”

Attrition rates are high in the industry, as cybersecurity specialists are in high demand and easily wooed by higher pay packages with fancy perks. And the candidates that are fresh out of university lack other skills that are more aligned to business, leadership, and communication. What good then are fancy degrees and certifications when one cannot communicate risks and articulate the impact of the threat in business terms? Certifications are not too difficult to acquire, given the mushrooming of online training institutions, many of which offer inadequate training that is not aligned to industry requirements…To read the full story, subscribe to CISO MAG.

This story first appeared in the May 2021 issue of CISO MAG.


Brian Pereira

About the Author

Brian Pereirais the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Russia-based APT28 Linked to Mass Brute-force Attacks Against Cloud Networks

Nobelium

State-sponsored actors from Russia have a long history of cyberattacks across the world. There are numerous cyberespionage campaigns linked to Russian hackers. Recently, the federal agencies of the U.S. and the U.K. warned about a series of brute-force attacks led by the Russia-linked APT28 cybercriminal gang.

In a joint report, the agencies stated the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS), military unit 26165, leveraged a Kubernetes cluster to perform a set of brute-force attacks against hundreds of private and public entities across the globe from mid-2019 to early 2021. APT28 is reportedly attributed GTsSS and has multiple identities, including Fancy Bear, Sednit, Tsar Team and STRONTIUM.

Exploiting Microsoft Services

The threat actors launched brute-force attempts against organizations using Microsoft Office 365 cloud services. In a brute-force attack, attackers try to guess usernames and passwords to gain unauthorized access to a targeted source by the trial-and-error method. The attack allows hackers to obtain access to users’ private data, including email account credentials, which actors use for multiple purposes such as initial access, persistence, privilege escalation, and defense evasion.

APT28 threat actors reportedly exploited publicly known vulnerabilities – CVE 2020-0688 and CVE 2020-17144 – in Microsoft Exchange servers for remote code execution and to get privileged access to targeted networks. To hide their criminal activities, they used the TOR platform and VPN services like IPVanish, CactusVPN, WorldVPN, NordVPN, ProtonVPN, and Surfshark.

Sectors Targeted

  • Government and Military services
  • Political and party organizations
  • Defense contractors
  • Energy companies
  • Logistics companies
  • Think tanks
  • Higher education institutions
  • Law firms
  • Media firms

“This campaign has already targeted hundreds of U.S. and foreign organizations worldwide, including U.S. government and Department of Defense entities. While the sum of the targeting is global in nature, the capability has predominantly focused on entities in the U.S. and Europe,” the report said. 

Mitigating Brute-force Attacks

Security admins can boost the security posture of their organization by following certain basic measures. These include:

  • Adopting two-factor or multi-factor authentication
  • Using strong passwords that include numbers, symbols, and both uppercase and lowercase letters
  • Changing all default credentials
  • Implementing a Zero Trust security model to detect anonymous intrusions
  • Restricting access to authentication URLs
  • Enabling CAPTCHA feature for authentication
  • Enabling account lockout option, after multiple wrong login attempts

Warning! Don’t Be Duped by Fake Cryptomining Android Apps

CryptoMining Scams

The exponential rise of cryptocurrency value attracted both investors and cybercriminals at large.  A recent investigation by Lookout, an endpoint-to-cloud security firm, uncovered multiple cryptomining scams operated via fake cryptocurrency Android apps.

Fake Crypto Apps

The researchers found more than 170 Android apps, including 25 on the Google Play Store, which were maliciously crafted to target investors willing to invest in cryptocurrencies. The apps, which affected more than 93,000 victims, were grouped into two categories – BitScam and CloudScam. The apps advertised themselves as offering cloud cryptocurrency mining services, however, failed to deliver the promised services.  In addition to the apps, hackers promoted added services like cryptocurrency purchases and transfers by displaying fake minimum account balances to lure investors into spending more.

The majority of BitScam and CloudScam apps offer paid services. Threat actors also pocketed the money from subscriptions and cryptomining services included in the apps. The apps have reportedly pilfered at least $350,000 from the victims. Google Play has taken down most of these apps after Lookout reported the issue.

“These apps were able to fly under the radar because they don’t actually do anything malicious. They are simply shells set up to attract users caught up in the cryptocurrency craze and collect money for services that don’t exist. Purchasing goods or services online always requires a certain degree of trust — these scams prove that cryptocurrency is no exception,” said Ioannis Gasparis, a mobile application security researcher at Lookout.

Spotting a Crypto Scam App

  • Do research on the app developers. Visit their official website and find their contact details.
  • Always download apps from an official app store to reduce the risk.
  • Read the terms and conditions carefully. Don’t download if you find anything suspicious.
  • Read the reviews to know more about the app.
  • Read the app permissions. Don’t install if the app asks for permissions more than required.

Attackers Exploiting Cryptocurrency Craze

A recent research from Barracuda revealed a 192% rise in cryptocurrency-related cyberattacks has been registered after the Bitcoin surge in October 2020. It was observed that the volume of cryptocurrency-related attacks was associated with the rapidly rising price of Bitcoin. Read More Here

How Cryptojacking and Cryptomining Assaults Work

Sardonic, BitMart

When reporters asked the infamous bank robber Willie Sutton why he robbed banks he allegedly replied, “because that’s where the money is”. It was only a matter of time that cybercriminals, specifically, ransomware extortioners, started to target their currency of choice, Bitcoin, as a means of gaining wealth. If Willie Sutton was living today, he would probably be a cryptojacker in cyberspace, launching cryptojacking attacks and cryptomining assaults on cryptocurrency firms.

By Zachery S. Mitcham, MSA, CCISO, CSIH, VP and Chief Information Security Officer, SURGE Professional Services-Group

What is it?

Simply put, cryptojackers attack enterprise technological systems with the goal of leveraging their computer resources to launch cryptomining assaults on cryptocurrency firms. Graboid, PowerGhost, Badshell, MinerGate, and Prometei are all well know cryptojacking variants that intruders use to capitalize on the resources of the enterprise and personal systems with the intent of conducting cryptomining of popular cryptocurrencies.

How does it work?

Cybercriminals surreptitiously gain access into enterprise or personal computer systems and inject malicious computer code onto them. No systems are safe from cryptojacking. Cloud-based, file-based, and browser-based systems have all been known to have been affected by cryptojackers.  The method of choice used by the intruder to introduce the code onto a system is by way of phishing attacks in various forms.  Once the code’s payload is applied to the system it behaves similarly to a technological parasite, much like a tick on a dog or a leach on a host.  The injected code works in the system background undetected. The preferred code used by the intruder is usually a polymorphic, zero-day, advanced persistent malware deployed as a rootkit.

The intent of the code is not to harm the host, rather hijack its CPU resources in order to launch attacks on other computer systems particularly cryptocurrency targets. Cryptojackers view crypto mining of cryptocurrency as less risky than ransomware in that cryptocurrency firms do not have the same emotional public and law enforcement support as does traditional brick and mortar enterprises that directly affect their everyday lives as was the case with the ransomware attack on the colonial pipeline causing a major consumer panic.

How do I know If my system is affected?

The degraded performance of your system could be an indication that its resources are being used to conduct unwitting cybercriminal activities. Traditional methods used to detect common vulnerabilities such as antivirus protection and popular vulnerability scans are ineffective when it comes to detecting Cryptojacking malware.  Network monitoring tools are more effective in detecting Cryptojacking activities in that they reveal increased and unexplainable CPU usage that could possibly cause endpoint failure due to overheating as a result of the increase in usage. Utilizing various network monitoring tools such as Simple Network Management Protocol tools in tandem with Security Information and Event Management tools configured to detect changes within an enterprise technological network, servers and endpoints will be beneficial in the quest for discovering Cryptojacking within your organization.

How can I protect my system against cryptojackers?

  1. Both non-governmental organizations (NGOs) and government organizations (GOs) can avoid becoming unwitting accessories to cybercrime by implementing the NIST 800-207 Zero Trust framework throughout their enterprise. The Zero trust framework focuses on three primary areas of enterprise computing operations:  the user, the device, and the application.  Computer systems at their inception were designed to be collaborative in nature and therefore did not focus much on security.  In 1988 that paradigm shifted with the introduction of the Morris Worm. Zero Trust now becomes the default, with the idea that the device, the user, and the application cannot be trusted, even when they have been vetted and confirmed as being a legitimate component of the enterprise’s network.  The user’s identity and authentication coupled with the authentication of the device and application access controls are the foundation of this model. Zero trust forces administrators to approach every component of their network as possibly being compromised and therefore require stringent policies and configurations that must be met in order to allow them to operate within its schema.  Network segmentation and sensitive data compartmentalization, irrespective of where the system computing occurs or resides, whether it be in the cloud, or on-premise, are treated in the same manner.  When all of these conditions are met then, and only then will the device, user, or application be allowed to operate freely within the network given audit trails and constant monitoring.
  2. Information security awareness education and training are of paramount importance in combatting Cryptojacking. The enterprise must create a culture of security that is ubiquitous throughout the organization.  Everyone in the enterprise has a role to play in protecting the organization’s technological assets from the Board of Trustees, Senior Management to the frontline operational staff.  Again, this culture must be pervasive throughout the organization.
  3. Newer endpoint protection products are now capable of detecting and isolating some of the most popular Cryptojacking variants. The enterprise must invest in outfitting its computer systems with robust endpoint protection.

The long and short of it is that cybercriminals do not have to comply with any rules, regulatory compliance mandates, or standards.  Their tactics to disrupt, destroy and manipulate organizations technological system operations are ever-evolving.  Therefore, the enterprise must be ever vigilant in the safeguard of their technological resources.

Stay alert! Stay Alive!


About the Author

Zachery S. MitchamZachery S. Mitcham, MSA, CCISO, CSIH is the VP and Chief Information Security Officer at SURGE Professional Services-Group. He is a 20-year veteran of the United States Army where he retired as a Major. He earned his BBA in Business Administration from Mercer University Eugene W. Stetson School of Business and Economics. He also earned an MSA in Administration from Central Michigan University. Zachery graduated from the United States Army School of Information Technology where he earned a diploma with a concentration in systems automation. He completed a graduate studies professional development program earning a Strategic Management Graduate Certificate at Harvard University extension school. Mr. Mitcham holds several computer security certificates from various institutions of higher education to include Stanford, Villanova, Carnegie-Mellon Universities, and the University of Central Florida. He is certified as a Chief Information Security Officer by the EC-Council and a Certified Computer Security Incident Handler from the Software Engineering Institute at Carnegie Mellon University. Zachery received his Information Systems Security Management credentials as an Information Systems Security Officer from the Department of Defense Intelligence Information Systems Accreditations Course in Kaiserslautern, Germany.

Disclaimer

 CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

Caution! Attackers Found Distributing Malicious Privacy Tool to Steal Sensitive Data

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Cybercriminals often enhance their phishing tactics to lure unwitting users into downloading malware. In one such new phishing threat uncovered by security researchers from Proofpoint, threat actors are tricking users into opening/downloading a malicious file disguised as a Privacy Tool service. The said tool is advertised as a files protector and can be used to encrypt user data via a zip-like utility service. Attackers are leveraging a fake website to promote the malicious tool, and have included instructions on how to download it.

Using Smoke Loader Payload

Proofpoint stated that the attackers are using Smoke Loader as an initial payload. Smoke Loader is a popular malware downloader available on the dark web and used by several cybercriminal groups. Once a user downloads the privacy tool, the Smoke Loader automatically installs additional malware payloads, including RedLine and Raccoon Stealer. The malware is specially crafted to exfiltrate sensitive data from the targeted system.

RedLine malware was uncovered in early 2021 and can compromise cold wallets that store cryptocurrencies. Raccoon Stealer is an infamous malware-as-a-service active since 2019, available across various darknet forums. The malware can steal users’ private data such as credentials, credit card details, website cookies, usernames, hardware details, location, installed security software, system data, and data related to Bitcoin wallets.

While threat actors behind this malware campaign are unknown, Proofpoint stated it identified one IP address linked with OpenNIC, a public domain service provider.

“The use of a privacy-themed lure to download information-stealing malware is an ironic yet predatory mechanism for enticing users to download malware. The lure is likely effective as the threat actors behind the campaign appear to have taken considerable time and effort to design a legitimate-looking privacy tool. Based on additional indicators uncovered, it is likely this threat actor is conducting – and has previously conducted – similar campaigns using privacy themes and convincing lures to distribute Smoke Loader and follow-on malware. Proofpoint anticipates this type of theme and activity to continue, especially for consumers who do not have corporate privacy and security services already installed on their hosts,” Proofpoint said.

ENISA Releases Cybersecurity Guide to Secure SMEs

SMEs

The global pandemic led to swift digitization that eventually opened doors to several security issues. Cybercriminals are taking advantage of the situation by exploiting the loopholes in organizations’ networks. Small and medium enterprises (SMEs) have sustained severe challenges to thrive in business, especially during the pandemic.

To help SMEs enhance their cybersecurity posture, the European Union Agency for Cybersecurity (ENISA)  has released a cybersecurity guide for SMEs: 12 Steps to Securing Your Business. The guide will help SMEs cope with cybersecurity challenges and address cyberthreats. The 12 high-level security steps include:

  1. Develop Good Cybersecurity Culture
  2. Provide Appropriate Training
  3. Ensure Effective Third-Party Management
  4. Develop An Incident Response Plan
  5. Secure Access to Systems
  6. Secure Devices
  7. Secure Your Network
  8. Improve Physical Security
  9. Secure Backups
  10. Engage With the Cloud
  11. Secure Online Sites
  12. Seek And Share Information

“The COVID-19 crisis showed how important the Internet and computers, in general, are for SMEs. To thrive in business during the pandemic many SMEs had to take business continuity measures, such as adopting cloud services, improving their internet services, upgrading their websites, and enabling staff to work remotely,” ENISA said.

Cyberattacks in the U.K.

A recent quarterly fraud and cybercrime report from Money.co.uk revealed that the U.K. has seen the biggest rise in cyberattacks, accounting for a loss of £1 billion ($1.38 billion) during Q1 2021. Over 81,018 cases of fraud and cybercrimes with £382.3 million ($528 million) loss were reported in Q2 2021. Each victim of a cyberattack lost over £4,719 ($6,517) between April-June 2021. According to the report, the individuals aged 30-39 sustained the greatest number of cyberattacks in Q2 2021, followed by people aged from 20-29.

“Brits have lost more than a billion pounds as a result of fraudulent and cybercrimes, showing the extent fraudsters have taken advantage of online shoppers during the national lockdown. But it’s encouraging to see that cases have decreased significantly in the second quarter of the year, as life started heading back towards normality. Still, with millions of pounds lost, it’s vital that individuals are aware of what they should be doing to protect themselves against fraudsters,” said James Andrews, personal finance expert at Money.co.uk.

Quantum Encryption and the One-time Keypad

Quantum encryption

Secrecy is important for sending encrypted messages over the internet. Sensitive personal information is often exchanged while remaining vulnerable to hacks, leaks, etc. To make matters worse, we voluntarily accept the risk while being forced to trust the process. This is the price of doing online business.

By Kent Thachek, Co-founder, Simius Technologies

Quantum key distribution (QKD) is the next-generation solution to this problem. This will be the future for encryption standards. We want to improve the transformation of information which has been obfuscated so that only the intended audience receives the message.

As computers become more sophisticated, the codes they use become easier to decrypt. However, the laws of physics can offer us a solution using quantum effects. But let’s make sure we are on the same page.

Simple substitution is the most ancient form of encryption and is considered a basic standard. Swapping characters of the alphabet between different mappings to scramble a message which can be easily pieced together. The rest of encryption follows this as a common standard, but with a twisted variety

Essentially, a lock over the information secures it with a key. Namely, a factor that becomes difficult to reverse compute, and we want to make the lock impossibly difficult to pick as well. Traditional encryption relies on computing resources. For an encrypted message to be hacked, the reverse computation must be feasible. But if we could rely on a messaging system that self-destructs upon interception, it would change the game.

This is where QKD comes in. Using quantum effects to create a random number generator, there is hope in discouraging reverse computation. Although the equipment used might be susceptible to hacking, there are protocols that can be established to mitigate such risks. This leads us to the notion of one-way functions, which are easy to compute but difficult to reverse.

As with multiplying large prime numbers, figuring out the original inputs becomes more difficult with the primes increasing in size. Hence various forms of encryption are based on the number of bits (64,128,256,512, etc). The larger the prime, the more expensive it is to reverse compute. Therefore, a message using increasing numerical complexity to encrypt is bound to make greater difficulty in hacking. Reverse computation is as expensive as it is time-sensitive, but we can only stay ahead of the ball by a small margin.

When using quantum effects to generate keys, this makes it much more difficult for hackers to reverse compute the message. Factoring out these large prime numbers becomes easier by the day with advancements in computation. Quantum encryption, however, quickly breaks this down.

Instead of sending keys over the internet, a special channel and protocol can be used which takes advantage of the laws from physics. Substitution of the random number generator is essential. To get rid of eavesdropping, and identify when a man-in-the-middle attack is present, we must introduce a barrier which they cannot bypass.

This is where any physical phenomena can be used, such as a photon, electron, or even a sound wave, to exhibit quantum effects. This creates the proper random number generator which we need, to stay ahead of any hacking or reverse computation that might attempt to eavesdrop. Not only that, when our private communications are being intercepted, we can detect this.

This is only possible through measurement. When an attacker tries to hack a message that uses QKD, we can detect it. The signal becomes tainted at the point of their interception. Any third party attempting to measure our secure qubits of information will inevitably reveal themselves. This is part of the quantum effects, and our message becomes guarded by the laws of nature. Eavesdropping thus changes the contents of the message, and we can detect this before the data is even sent.

Not only that, the message can be programmed to self-destruct, thereby eliminating the contents from being viewed. Although the equipment can still be susceptible to various vulnerabilities, this is the holy grail for all cybersecurity. The message scrambles itself upon interception because eavesdropping can be easily detected based on a fault-tolerance threshold.

This leads us to a one-time keypad, that becomes ultimately unbreakable. While bits of information is shared, the order in which they are detected becomes key. This is the only way to interpret the message with any degree of accuracy. If photons are polarized at random, the eavesdropper is out of luck.

Case in point, when a hacker attempts to intercept a message secured using QKD, they will need to copy the photons using the correct order of detection. And if they fail, it changes the key. This can be easily detected when checking for errors prior to sending and after receiving a message. Even as small disturbances can change photon polarization, we can still detect these errors.

A single degree of error per photon or quantum bit can add up, past a certain threshold of detection. The hacker would have to be flying very low under the radar, and even then, we could find them dead in their tracks.

The most important takeaway is that this would fundamentally change the infrastructure of the internet if QKD was ever implemented at scale. But it would bring a new level of security unparalleled. Nothing could stop a QKD broadcast, and no one would be able to intercept it unless they had the secret key. It would be game over for spam, phishing, and even spying. Surveillance always goes both ways, and this would make the eavesdropper expose themselves by using the laws of physics to do the dirty work.


About the Author

Kent ThachekKent Thachek is a Disaster Recovery Specialist and Programmer Analyst with a background in Software Engineering, Bioinformatics, and Information Technology, as well as co-founder of Simius Technologies, Inc. With over 15 years of combined experience in programming and cybersecurity, Thachek, has marked his passion for ensuring the success of all technical endeavors through attention to detail and effective communication.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.