Pages

Sunday, August 12, 2012

Improving IT Security with Vulnerability Assessments & Threat Intelligence


Threats to your IT & Network Security are growing daily; and these threats come from an increasingly large number of sources. These threats are real and have the potential to destroy your business. Luckily, there are ways to minimize these threats and even prevent future IT security breaches.

One of the first things to do is perform a network security vulnerability assessment. A vulnerability assessment will help you identify any potential threats and vulnerabilities currently being posed to your network. Network & IT security vulnerability assessments have become a standard best practice, and most regulatory groups recommend or even require institutions to have a policy or plan that include them. The publisher of the PCI-DSS set of requirements, The PCI Security Council, is among these regulatory groups that now require organizations to perform assessments on a quarterly basis.

Although this task seems very daunting, it can often be a painless and routine process. Many organizations and businesses are choosing to outsource vulnerability assessments and scans to reputable IT Security firms that can consolidate all these scans inside one easily accessible location that includes scan scheduling, report review, and remediation recommendations. Outsourcing helps reduce the load on in-house IT departments, and leaves this highly important task to security experts.

Perimeter E-Security(http://Perimeterusa.com), a leading IT Security and Network firm recommends the following 3 types of network vulnerability scans:

External Scans: External vulnerability scans utilize cloud-based scanners to perform scans on any external-facing devices. Scans completed from this perspective can help organizations understand what someone trying to break into your network would be seeing.

Internal Scans: Internal assessment scans are performed inside of your network, and will expose potential vulnerabilities that an individual would see if they are past edge devices. Scanner software can often be provided that will be installed on a virtual machine or dedicated device, and can even be loaded on an as-needed basis on a shared device.

 PCI Scans: A PCI scan is an external scan that includes the Statement of Attestation and Self-Assessment Questionnaire required by the PCI-DSS set of requirements. This scan also offers additional reporting including an overview of the current status of your PCI compliance, along with any additional areas that are currently out of compliance.

Going even further, Vulnerability Assessments are often offered as on-demand or managed services to fit varying budgets and IT plans. There will most likely be an option that is just right for the needs of your organization. Vulnerability assessments are critical to your IT security, and the best thing to do is start somewhere. If you neglect these security assessments, you could be leaving a gaping hole in your network that is just waiting to be exploited by intruders.

[Guest Author] Taylor Van Sickle is a web marketing specialist & digital designer, and frequently writes about tech, the web, marketing, & diabetes related topics. When he's not tearing it up on the web Taylor enjoys reading, traveling, and coming up with whacky ideas. (http://taylorvansickle.com)

Saturday, August 11, 2012

Hacking Medal from SANS "Capture the Flag" Tournament


The Manhattan Project Spawned Stuxnet


During the summer of 1939 the brilliant Albert Einstein was asked to partake in plans to persuade Franklin D. Roosevelt and the American military to start the “Manhattan Project”. During the same year it was widely speculated that German scientists were also experimenting with similar ideas in nuclear fission and the race was on. With the Germens already experimenting and pushing their reign across Europe it was imperative that America be the first country to have nuclear weapons. 

During the next 5 years the construction of top secret bases and equipment were constructed to have research completed and to create science no one’s done before; not only theoretically designing the reactors to produce plutonium, but being able to both create and produce nuclear fission. Here we see both academic and operational efforts working in tandem to produce a weapon that will change the face of modern warfare. 

Dropping the atomic bombs on Hiroshima and Nagaski are  still widely debated. While dropping their newly created weapons did help put an end to the war, its still widely believed that another driving factor to dropping the weapon was to show Russia that America has nuclear arms and isn’t afraid to use them.  Deploying these weapons on the population of Japan is also still widely disputed. Wondering why America didn’t drop the warheads on a military base, instead of a civilian neighborhood, is still a point of contention. 

Right or wrong after these warheads were dropped and the world was ushered into the nuclear age whether we were ready for it or not. The pandora ’s box was now blown wide open. Not only are we concerned about nuclear attacks in modern times, but we’re trying to stop others from having access to technology we built. Fast forwarded 70 years and we find the pandora’s box is still wide open and getting larger. Down the rabbit hole we go. 

The year is now 2010 and due hostility between Iran and the west a highly complicated piece of malware is created to target only the Siemens supervisory control and data acquisition (SCADA) systems and it’s given the name Stuxnet. The particular SCADA systems Stuxnet was coded to attack are isolated only to the Natanz Iranian nuclear plant, but due to a programming error the worm spread to an engineer’s laptop working on the Iranian centrifuges and escaped into the wild. History was made once again.

Due to the complexity of the code, the cost of the equipment needed to test on (SCADA), the sheer amount of zero day exploits it targeted with intimate knowledge of the exact PLCs, the only culprit to such a sophisticated software was a nation state. When looking at most worms on the internet they normally have a few factors behind their creation: theft of financials, stealing intellectual data or espionage. The Stuxnet malware didn’t have any of these characteristics and was there for one reason: stopping the Iranians from going nuclear. 

During the years prior to the worm being deployed fear of a nuclear Iran and failure of diplomatic pressure and sanction lead America and Israel to embark on something that was never done before.  President George Bush at the time started project “Operation Olympic Games” which was then taken over by President Barack Obama who continued the operation to develop a cyber-weapon aimed at Iran. Since it’s still early on in the history of Stuxnet it’s still heavily speculated that the Americans and Israel’s worked together to develop this technology to stop a common enemy, much like America did with the Manhattan project. 

The acquisition of zero day vulnerabilities and SCADA systems were researched and built to test the code being deployed to the Natanz plant. This is no small feat and most likely took the nation states involved years to research, code and develop. Once again the world was ushered into the next world of modern warfare. The cyber age was now upon us. 

There are many similarities between the Manhattan Project and Operation Olympic Games, both of which are projects where America is working with other countries to develop technology never before used in modern warfare. In the Manhattan Project American refugees from fascist regimes in Europe assisted with American scientists to develop a weapon before their common enemy could achieve it the same goal. With the example of Operation Olympic Games America once again teamed up with another country, mainly Israel, to develop another weapon in attempt to stop their common enemy Iran before they could produce what they assume would be a weapon of mass destruction. 

It’s interesting to look at the reason  Stuxnet was produced in the first place. The chief reason behind America creating Stuxnet was to destroy or slow the progress of Iran from having nuclear capabilities in fear they’d used this new found capability for evil. This is the exact opposite of the Manhattan project and shows the dangers of leveraging new technology without thinking about the long term ramifications of their use. The Stuxnet malware was made chiefly to plug a hole created 70 years earlier by the Manhattan project. Now decades later we’re still dealing with the rabbit hole created with the birth atomic weapons and we’re creating cyber weapons in attempts to put a stop to what we created in the first place. The proof of concept is out in the wild now and any nation state can start creating cyber weapons of this caliber without much difficulty. 

One can only imagine what will come from the release of Stuxnet and other cyber weapons and what we’ll have to do in the next 70 to try and cap the damage that was created. 

How far down the rabbit hole do we go?

Apple, Amazon Announce Changes After Hacking of Wired Reporter


Most of us take the things we have for granted until we lose them. That goes for jobs, friends, our youth and every other thing we hold dear. So, how does it feel when you really do lose everything?

Ask Mat Honan.

Honan, a writer for the tech magazine Wired, is the type of guy who keeps his whole life in “the cloud” – a digital storage space that has no real physical location and is maintained by a collection of unknowable network systems. Honan’s cloud of choice was the iCloud, a storage service offered by Apple, and in the span of less than an hour the bulk of his digital existence was stolen and then erased by a hacker.

The hacker, who agreed to share his method with Honan in exchange for the writer’s promise not to press charges, demonstrated how he used gaps in Amazon and Apple security protocols to harvest enough data to break into Honan’s iCloud account. The hack was shockingly non-technical and only involved a couple calls to set up new passwords to get the required data.

Now both Amazon and Apple have announced they are revamping their security procedures and the new policies that are sure to come will make password resets and account access much more difficult for hackers. Of course, that means those same tasks will become harder for consumers as well and Apple users have already noticed difficulty with accessing their various accounts.

The ramifications of this are not yet clear, but it is safe to assume that more problems are on the horizon as the security of digital cloud storage services – which many argue will become the norm in the near future – will infringe upon the convenience and privacy of users. 

There are several ways to help safeguard against a total loss of data. Backing up information on a personal hard drive, privatizing Web registration data and creating a firewall between sensitive accounts are all options people can use to increase online protection. Honan’s misfortune should be a reminder to all that corporate security measures should be thought of as a secondary measure of defense against the failure of our own personal efforts to stay safe online.

{Guest Author] James Madeiros is a staff writer for
Criminal Justice Degree Schools, a career resource that provides information on education options for earning a cybersecurity degree.

Saturday, August 4, 2012

5 Most Popular Forms of Identity Theft

When you think of identity theft, the first thing that comes to mind is credit card theft. Unfortunately there are other forms of identity theft that everyone should know about. Having an understanding of the different forms of identity theft will help you better prepare for situations if they just so happen to arise.

Medical Theft Identity

It might be a shocking thing to know but there are people who are using other people's identity to latch on to their medical records. The people who tend to do this sort of identity theft are people who live higher risked lifestyles and aren't willing to use their own identity. Medical Identity theft is a serious issue and can create a world wind of mess when it comes to your medical history that may not serve to be true.

Social Security Number Theft

Social security number theft is one of the easiest forms of theft rolling around. People don't realize that many documents that are signed by you, usually ask for your social security number. As time changes, this seems to become a mandatory piece of information. Putting your social security number of documents that ask for them puts you at a high risk for identity theft. If you can avoid inserting your social security number on any form of documentation, then it is advisable you do so. Unless it is justified why it is needed, you should avoid giving your social security number.

Criminal Identity Theft

This form of identity theft isn't a fun experience for anyone. Criminals have honed a skill that allows for them to take on another person's identity when it comes to doing a crime. There have been people who have been led to the police department under false accusations due to someone else taking their identity. If you find yourself involved in such a serious identity theft crime, make sure that you hire on the right team of people who can unravel the mess that is made due to criminal identity theft.

Credit Card Theft

No matter how the pie is sliced, if you own a credit card of any kind, you run the risk of having your identity stolen. Think about all of the times you give your card away to a waitress. If you aren't near your card there is a likely chance that you could have your card information stolen. Most people who take your credit card information, sell the number to someone else. So finding out who stole it in the first place can be a difficult thing to do. It's highly advisable that you pay with cash in places where you would have to disconnect with your credit card. You would have better control of the situation.


Drivers License Theft

This theft isn't as big as the others but it is still a factor in identity theft. Various people have had their share of pull-overs. These pull-overs have led to them being arrested due to a warrant. Unfortunately they didn't commit any traffic violations under their own name. Someone stole their driver license information and used it when they were stopped for a violation. It's important that you keep your drivers license near you at all times.


Author’s Bio: Emma Gomes, a well known writer is known for writing articles on security issues. Visit the website IdentityTheft.net for better knowledge.

Friday, August 3, 2012

Generic vs. Specialized Document Sharing in the Cloud

There has been a lot of buzz around the new entrant into the cloud-based document sharing space with the recent announcement of Google Drive. But not all cloud-based document sharing is the same. Specialized document sharing solutions address a fundamentally different set of business problems than a generic document sharing solution does.  So where do generic document sharing solutions end and specialized document sharing solutions begin?

Generic vs. Specialized?

Generic document sharing solutions started out to address personal file storage in the cloud.  By allowing individuals to put their personal pictures, videos and also documents in the cloud, they would be accessible from anywhere.  With the recent consumerization of IT, businesses quickly found that their employees were using personal solutions as business productivity tools – like sharing business documents with themselves.  Many generic document sharing solutions saw this as an opportunity to enter into the Enterprise Content Sharing space as a way of further monetizing their applications. But much of the functionality and infrastructure is geared towards document accessibility for lots and lots of documents and fails to deliver deeper business process-specific value.
This is where Specialized document sharing comes in. Specialized document sharing providers focus on solving business process specific problems such as how to run due diligence more effectively, gain control and visibility over governance and compliance processes in your organization or improve litigation support. Everything they invest in, from the features in their product to the people in their business, have this domain-specific knowledge.

If you take Firmex as an example, our products and services are geared around helping companies more effectively and successfully run financial transactions. Our Virtual Data Room and our Client Services team support thousands of deals a year. We specialize in being the best data room provider in the market.

With that said, we recently released an infographic using the launch of Google Drive as a means to illustrate the differences between generic and specialized document sharing offerings. We hope you'll find the information to be of value. It is available for viewing and download below.

If you'd like to learn more about how Firmex can support your specific business processes click here or click their contact us link.