Saturday, June 6, 2015

The Threat Is Coming From Inside the Network: Insider Threats Outrank External Attacks

The Threat Is Coming From Inside the Network: Insider Threats Outrank External Attacks
More than half of serious cybersecurity issues involve insider threats in some capacity, according to new research from IBM. These business insiders have access to data and can often be the starting point for an attack, perhaps even unknowingly.
iStock

The Threat Is Coming From Inside the Network: Insider Threats Outrank External Attacks


There are plenty of reasons to assume that most cyberattacks are the work of far-off bad guys with a political ax to grind or searching for fame and fortune. After all, we hear about them in news reports just about every day, leaving businesses and consumers wondering whether their data can ever be considered safe again. What’s not discussed, however, is that 55 percent of all attacks are carried out by malicious insiders or inadvertent actors, also known as insider threats. In other words, they were instigated by people you’d be likely to trust. IBM Security is releasing two reports to educate the public on these threats: the “IBM 2015 Cyber Security Intelligence Index” and the “IBM X-Force Threat Intelligence Quarterly – 2Q 2015.”
Depiction of composition of threats to network security
In the Cyber Security Intelligence Index, IBM Security Services reveals insights based on the continuous monitoring of billions of events per year. In 2014, organizations monitored by IBM Security Services experienced approximately 81 million security events, amounting to over 12,000 attacks and 109 incidents for each client. The Index proves statistically that every company is being compromised.
“Unauthorized Access” led all security incidents in 2014. For the two previous years, malicious code and sustained probes or scans dominated the security incident landscape. However, Shellshock and Heartbleed were game changers in 2014, which allowed Unauthorized Access incidents to rise to the top and account for 37 percent of all events in 2014, up 19 percent from 2013.
Download the IBM 2015 Cyber Security Intelligence Index

An Inside Job

The rise of social media, cloud, mobility and big data is making insider threats harder to identify while also providing more ways to pass protected information. If we break out the malicious insiders from the inadvertent actors, we see several profiles: disgruntled employees who exit the company but still have access to old privileges or create back doors before leaving; malicious insiders taking advantage of lax deprovisioning of expired or orphan accounts to attack valuable resources or with privileged access who sell information for financial gain; and the inadvertent insiders who do not mean harm but fall prey to social engineering schemes that grant access to outside attackers. There are even “quasi-insiders” who could be considered trusted third-party contract workers.
In the IBM X-Force Threat Intelligence Quarterly, we investigate how social engineering has turned an annoyance like spam into a legitimate attack vector, with for-profit operators creating and selling spam campaigns to trick inadvertent insiders to open an attachment or click on a link. Although the current volume of spam is comparable to that of 2013, the percentage of spam carrying malware jumped from 1 percent in early 2013 to around 4 percent in 2015, making this a high-growth channel for spreading malware.

Friday, June 5, 2015

ACM legt KPN boete op na hack klantdata

ACM legt KPN boete op na hack klantdata


03-06-2015 

Politie
Autoriteit Consument & Markt (ACM) heeft KPN een boete opgelegd van 364.000 euro voor het onvoldoende beveiligen van systemen waarin de persoonsgegevens van klanten zijn opgeslagen. De instantie legde de telecomaanbieder in december 2013 een boete op maar KPN ging in hoger beroep tegen de uitspraak.

Het gaat om een zaak uit 2012 waarbij een hacker inbrak in het netwerk van KPN. ACM (voorheen OPTA) startte een onderzoek naar de wijze waarop KPN de persoonsgegevens van haar klanten beveiligde.
ACM: 'Uit het onderzoek bleek dat in de periode voorafgaand aan de hack de beveiliging van deze gegevens van KPN-klanten en de wijze waarop het veiligheidsbeleid in de organisatie was geborgd onvoldoende was.' De autoriteit stelt overigens dat KPN, nadat de hack was ontdekt, 'voortvarend heeft gereageerd om de beveiliging van zijn netwerken en systemen op orde te brengen.'
Het boetebesluit van ACM wordt nu pas openbaar gemaakt, omdat KPN zich tegen eerdere openbaarmaking heeft verzet bij de voorzieningenrechters van de rechtbank Rotterdam en het College van Beroep voor het bedrijfsleven (CBb). Het CBb heeft zich op 1 juni 2015 uitgesproken over de zaak. Daarop heeft ACM besloten het boetebesluit en de beslissing op bezwaar te publiceren.
Op 8 januari 2015 heeft de rechtbank Rotterdam geoordeeld dat ACM terecht aan KPN een boete heeft opgelegd. Tegen deze uitspraak van de rechtbank heeft KPN hoger beroep ingesteld bij het CBb.

Zorgplicht telecomaanbieders


ACM licht verder toe: 'Op alle telecomaanbieders rust de plicht (‘zorgplicht’) om de persoonsgegevens en de persoonlijke levenssfeer van hun klanten op een passend niveau te beveiligen. De maatregelen die de telecomaanbieders treffen, garanderen een passend beveiligingsniveau, rekening houdend met de stand van de techniek, de kosten van de te nemen maatregelen en het risico op doorbreking van de bescherming.'
ACM-bestuurslid Anita Vegter: 'Klanten stellen hun persoonsgegevens beschikbaar aan telecombedrijven om van hun diensten gebruik te kunnen maken. Zij doen dit in het vertrouwen dat deze bedrijven zorgvuldig met hun gegevens omgaan en goed beschermen. Gebeurt dat onvoldoende, zoals in dit geval bij KPN, dan schaadt dat het vertrouwen van consumenten in de telecommarkt. Dit is een ongewenste situatie waar wij tegen optreden.'

Opnieuw in beroep


Een KPN-woordvoerder meldt aan de NOS: 'Het is duidelijk dat in 2012 iemand in onze systemen kon inbreken. Wij betreuren dat.' Hij wijst erop dat er geen klantgegevens op straat zijn komen te liggen en dat er is geïnvesteerd in verbetering van de beveiliging. KPN gaat opnieuw in beroep tegen de boete.


Read more: http://www.computable.nl/artikel/nieuws/overheid/5405176/1277202/acm-legt-kpn-boete-op-na-hack-klantdata.html#ixzz3cCQNGKsX

Thursday, June 4, 2015

Outsourcing IT Security Infrastructure Is Like Hiring a Good Lawn Service Company


Outsourcing IT Security Infrastructure Is Like Hiring a Good Lawn Service Company

By Jay Bretzmann


Many organizations struggle to find both the skilled resources and the funding required to deploy on-premises security intelligence solutions. The easy alternative is simply outsourcing the activity, but participants in certain industries are reluctant to relinquish control for safeguarding their trade secrets and customer private data. One significant network breach can damage the brand reputation and potentially result in business failure when handled poorly. If you’re one of these organizations, you want to maintain a higher degree of control but have heretofore had few options outside of doing everything yourself or hiring professional services consultants or managed service providers.

Why Outsourcing?

Cloud-based security intelligence solutions can help you address these two main pain points using a hybrid model. Clients benefit from outsourcing the infrastructural work associated with deploying and maintaining a security intelligence or next-generation security information and event management (SIEM) solution and save capital budget expenses by easily integrating a SIEM platform. This also helps reduce your time to value since experienced professionals use the cloud resources for delivering the service — typically in a period of days rather than weeks or months.
Outsourcing your security intelligence infrastructure to maximize existing IT resources provides a similar benefit to hiring a lawn service company to keep your estate grounds looking good. Beyond regularly scheduled mowings, the turf experts also troubleshoot issues with moss, grubs and other pests that cause bare spots so you have more time to watch the game. Security infrastructure vendors similarly apply bug-fix releases and vulnerability patches to improve the efficiency of, and remove potential risks in, IT security software. Lawn service vendors apply fertilizer to properly feed the grass throughout the year, and they aerate and overseed in the fall to support new growth next spring — similar to the way in which infrastructure-as-a-service (IaaS) vendors transparently grow appliance processing power or add storage capacity to support business growth.


This new model allows you to achieve greater security visibility by focusing all your available resources on monitoring for evidence of attacks, fraud and advanced threats, as well as performing any necessary compliance reporting. Your team remains in control and must plan for and initiate all remediation activities. Of course, you can also work with security services to help monitor the network even if it’s just for gap periods like weekend coverage. And there’s nothing like doing a little pre-planning around emergency response services, including outsourcing on-call resources for a faster and better-orchestrated response should lightning strike.

1.25 million Japanese pension records leaked following phishing attack

1.25 million Japanese pension records leaked following phishing attack

stock-video-waving-flag-of-japan-10067The Japan Pension Service has suffered a data breach, affecting the pension records of some 1.25 million people.
According to the Bangkok Post, “An employee opened an e-mail with a virus, triggering the release of client names, pension account numbers, birth dates and addresses”.
The breach was discovered on May 28 and the identity of the criminal hacker(s) remains unknown.
“These are the people’s vital pensions. I have instructed Health and Welfare Minister (Yasuhisa) Shiozaki to consider the pension recipients and do everything possible,” Japan’s Prime Minister Shinzo Abe told reporters when the breach was made public.
Compromised data included:
  • Names and pension numbers of 31,000 individuals;
  • Names, pension numbers and birth dates of 1.25 million individuals;
  • Names, pension numbers, birth dates and home addresses of another 50,000.
Spear phishing attack
The data breach was caused by a successful spear-phishing campaign that targeted staff of the service. A member of staff opened an attachment, ultimately infecting the PC with malware. The infected machine has been removed from the network and it’s not believed that the malware spread.
Thankfully, the PC wasn’t connected to the core computer system, which keeps financial details of the pension system’s members, officials said.
This breach demonstrates just how damaging the insider threat is to organisations. Without regular training on information security awareness, it’s highly likely that an employee will instigate a data breach – intentional or not.

Wednesday, June 3, 2015

Facebook and OpenPGP


With millions of users all around the world, social networks are tasked with protecting a massive amount of information. Facebook notification encryption is the latest tool that will help with this endeavor, adding private keys to communications.

Facebook Notification Encryption Uses OpenPGP to Protect Users


Sometimes social networks seem like a place where everything becomes public sooner or later, but a recently introduced Facebook notification encryption feature may provide an unusually high level of security to certain kinds of communication.
In a public note available to all its users, the company described Facebook notification encryption as an experiment of sorts that will roll out gradually, beginning on the desktop and later expanding to mobile. It involves OpenPGP, through which consumers would generate a private key only they know and a public key that would be affiliated with their Facebook account. Adding an OpenPGP to a profile by visiting the “Account” section on a profile and then editing the “Contact and Basic Info” area would mean any notifications sent to that account holder would be impossible to read without the private key.
As PC World noted, average consumers may not feel they need Facebook notification encryption for the kind of messages they get from friends and family. In some scenarios, though, the feature could help prevent hackers from taking over accounts by attempting to generate password resets. No wonder other online services such as Google’s Gmail are expected to be adding OpenPGP as a part of their security measures in the near future.
This isn’t the only area where the social network is trying to reassure consumers that it’s a service they can trust. BetaNewspointed out that besides Facebook notification encryption, the company has also recently leveraged Tor for those worried about connecting via HTTPS, along with a tool — not yet available to all users — that will periodically assess an account’s degree of vulnerability.
According to Ars Technica, Facebook notification encryption builds extra security by using not only a consumer’s private key, but adding its own on outgoing messages. For example, if a cybercriminal were to attempt a phishing scheme by impersonating the company and asking a user for credentials, it would be fairly easy to spot thanks to the lack of outbound encryption key. Overall, the move could be influential enough that OpenPGP becomes more of a standard across a range of online services that everyday people use — the kind of best practice that makes Facebook the security industry’s best friend.
This article was brought to you by SecurityIntelligence.com. The views and opinions expressed by the author do not reflect the position of IBM

Monday, June 1, 2015

Facebook introduces PGP encryption for sensitive emails


Facebook introduces PGP encryption for sensitive emails
Users of the social network can now opt to encrypt email notifications such as password resets and other confidential information
Encryption: as easy as pushing a button? Photograph: Lasse Kristensen / Alamy/Alamy
Facebook is offering users the ability to encrypt password reset emails for the first time, using the popular PGP email encryption standard.
Users who want to take advantage of the new security standards can tell Facebook their public key, and the site will then ensure that any sensitive emails that it sends out, such as password resets or other notifications, will be encrypted. The company will also cryptographically sign messages it sends, which allows users to verify that the sender genuinely is Facebook.
In a blogpost, Facebook explained how the feature will work. “Today we are gradually rolling out an experimental new feature that enables people to add OpenPGP public keys to their profile; these keys can be used to ‘end-to-end’ encrypt notification emails sent from Facebook to your preferred email accounts. People may also choose to share OpenPGP keys from their profile, with or without enabling encrypted notifications.”
The encryption standard Facebook is using, PGP (which stands for “pretty good privacy”), is seen as the gold standard of email encryption. The Edward Snowden revelations revealed it to be one of the few encryption standards which national security services had failed to undermine in some way, despite its 20-year history.
The standard is a form of what is called “public key cryptography”, where every user has pair of keys, one designed to be shared widely, and the other to be kept utterly secret. Messages are encrypted using the public key, and can then only be decrypted using the private one.
Giving the public key to Facebook thus solves two problems: it lets the site encrypt users’ emails, and it also aids dissemination of public keys.
Gnu Privacy Guard (or GPG), the specific version of PGP that Facebook has chosen to use, remains a notoriously difficult tool to employ, and it seems unlikely the encryption options will be widely used in the near future.
But the move underscores Facebook’s goal to roll out tools which will help vulnerable subsets of its userbase. The company says : “it’s very important to us that the people who use Facebook feel safe and can trust that their connection to Facebook is secure; for instance this is why we run connections to our site over [encryption standard] HTTPS with HSTS, and why we provide a Tor onion site for people who want to enjoy security guarantees beyond those offered by HTTPS.”
  • Philip Zimmermann: king of encryption reveals his fears for privacy 

Google, WhatsApp And Facebook Message Encryption Under Threat From Intelligence Agencies


Google, WhatsApp And Facebook Message Encryption Under Threat From Intelligence Agencies

  
Google, WhatsApp And Facebook Message Encryption Under Threat From Intelligence Agencies


Users of Google, WhatsApp and Facebook are a trifle disconcerted by the probable enforcement of laws in the UK that would require these social network giants to enable the intelligence agencies to have access to encrypted messages.
This law, proposed by the Conservatives, is a necessary evil that will make it a lot easier for Intelligence Agencies to apprehend criminals by learning about plans and help them prevent many crimes.
The prime suspects of any case, suspected terrorists, pedophiles, killers and other anti social elements can be better tracked and crimes can be averted, as per notable agencies like MI5, MI6 and the GCHQ, who are expected to be in charge of this analysis.
  
Eyes are now stuck to the new developments in the investigatory powers bill that is expected to be in place soon.
This new bill would force the social networking companies to hand over the encrypted messages of suspects, so that their online messaging and SNP could be well assessed to see if they are linked with any upcoming crime. This could mean that the Snooper’s Charter would be killed off.
Of course, the bill faced major blockade, both from users and from the social networks themselves, who are more concerned about maintaining the privacy of their users.
The networks have refused to hand these messages over and the users have expressed their discontent over their private lives being taken apart and analysed by total strangers.
This refusal to hand over messages has been criticized strongly by Robert Hannigan, Director of GHCQ, who believes that this measure will not just prevent crimes, but will also help schools to identify if the candidate applies for a post in the school staff has a clean background, further contributing to the safety of kids in school. But the bill was already announced in the queen’s speech and it actually might be too late to prevent the same from being enforced.
  
The agencies would nevertheless take a lot of time to be able to decipher the messages as they are far more sophisticated than usual encryptions.