Tuesday, July 5, 2011

Prized Patient information open to Web-Highest Number of Security Breaches in Healthcare - Medical Providers


The below chart represent the highest number of security breaches happing in Healthcare sector of US. The immediate question arise to everyone mind; is it because of low-security standard or control available? This is not True!!!  There are strong controls like HIPPA to address security requirement, but it also depends on how and where these controls are implemented. A strategic initiative needs to be developed, involving management commitment with right tools and strong business processes.   


Type of breaches analyzed:
  1. Unintended disclosure (DISC) - Sensitive information posted publicly on a website, mishandled or sent to the wrong party via email, fax or mail.
  2. Hacking or malware (HACK) - Electronic entry by an outside party, malware, and spyware.
  3. Payment Card Fraud (CARD) - Fraud involving debit and credit cards that are not accomplished via hacking. For example, skimming devices at point-of-service terminals.
  4. Insider ( INSD) - Someone with legitimate access intentionally breaches information - such as an employee or contractor.
  5. Physical loss (PHYS) - Lost, discarded or stolen non-electronic records, such as paper documents
  6. Portable device (PORT) - Lost, discarded or stolen laptop, PDA, smartphone, portable memory device, CD, hard drive, data tape, etc
  7. Stationary device (STAT) - Lost, discarded or stolen stationary electronic device such as a computer or server not designed for mobility.
  8. Unknown or other (UNKN)

Organization type(s) analyzed: BSO - Businesses – Other, BSF - Businesses - Financial and Insurance Services, BSR - Businesses - Retail/Merchant, EDU - Educational Institutions, GOV - Government and Military, MED - Healthcare - Medical Providers, NGO - Nonprofit Organizations

Few examples of breaches are -

Barnes-Jewish Hospital, The Siteman Cancer Center, Washington University Saint Louis, Montana
A laptop containing unencrypted patient information was stolen during the weekend of December 4, 2010.  It contained the names, Social Security numbers, dates of birth, addresses, phone numbers, email addresses, medical records, diagnoses, lab results, insurance information and employment information

Boulder Community Hospital Boulder, Colorado
A contract nurse is accused of accessing patient information without authorization.  He faces a 90-count felony indictment.  He allegedly used the Social Security numbers and other private information found in patient files to open credit cards in patients' names. 

The VA Caribbean Healthcare System San Juan, Puerto Rico
Veterans and staff had their personal information left unsecured in an open area in the San Juan VA Medical Center. Some of the information included patient care assignment documents with names and Social Security numbers a counseling letters.  It is not clear what type of staff information was exposed.  The information was supposed to have been shredded.

Healthcare Partners Long Beach, California
Nineteen computers were stolen during an office burglary on Monday, April 18.  Administrative information such as names, addresses, dates of birth, medical record numbers, and health insurance plan ID numbers was exposed.  Sensitive medical information such as treating physician names, diagnoses, treatment plans, progress notes, prescriptions, referrals, and authorizations were also exposed. A safe with 16 patient checks and 60 patient credit card receipts was also stolen.

Indiana Regional Medical Center Indiana, Pennsylvania
A former employee stole more than 500 patient records for the purpose of using them as evidence in a legal dispute with a physician.  The theft occurred in September of 2010 and included the medical information of three or four patients, as well as administrative information related to hundreds of other patients.

Trinity Medical Center (Montclair Baptist Medical Center) Birmingham, Alabama
A former employee was caught stealing patient information for the purpose of identity theft.  Hundreds of pages of information with patient names, Social Security numbers, dates of birth and some medical information such as scheduled procedure were found at the employee's residential address

Monday, June 27, 2011

Be Careful you may be exposed!!! Protecting your online Identity.


The Internet has changed the meaning of human psychology. Now, every user has some form of online identity either representing social (Facebook, Twitter etc.) or professional (LinkedIn etc.) life. Knowingly or Unknowingly, we post each and every small detail of our life either in the form of text, pictures or are Tagged in someone else profile and even we post-professional details to get some resolution. The way internet is designed, keeps all these details forever. 

Have we ever thought sharing of details over the internet may not be fruitful-socially or professionally? We have seen many examples where people have faced issues during background verification for employment and marriage proposal. They have not realized that proposal or employment is rejected due to some past content, revealing sensitive information. 

As soon as you realize the information is synchronized across and is made available on various search engines. It’s often seen that false and misleading content posted on the internet affects your business image as well.
A simple Google search on “removing online identity” revel 73,300,000 results. Don’t you think it’s a huge number and many users has raised the same concern-


The question is what we can do? There is a fine line between what to expose and what not... We fail to understand that each and every activity of ours is monitored and may not be useful or may create obstruction/difficulties in future life. There are many mechanisms to protect your online identity


  1. Manual deletion of details posted by yourself or requesting other users to remove who tagged your detail.
  2. Google and Yahoo have implemented “Delete URL” functionality for website administrators. This means that if you are a webmaster (or blog owner), you now have the power to stop specific URLS from being indexed (using a Robots.txt file). Non-admins can also take advantage of these tools and request that “private” information be taken down.
  3. Email administrator, to delete your online details 
  4. Online Tools-There is many sophisticated tools available in the market, which helps the user to search online identity details and remove the same. 
  5. SuicideMachine.org is doing its best to expand possibilities of erasing your entire presence; however, it is a work-in-progress research. Please note, that they are not deleting your account! Their aim is rather to remove your private content and friend relationships than just deactivating/deleting the account
  6. Reputation.com-Powerful tools to help you monitor and shape your reputation
  7. Monitor your information online
                    a. Remove personal information from the web
                    b. Define your online presence
                    c. Defend your reputation from negative content

Sunday, June 12, 2011

India's Promising Politician Web Site Hacked …….

The servers and website hosting information of constituencies of Rahul Gandhi and his mother, Congress chief Sonia Gandhi were hacked ..The systems used to store huge databases in terms of constituencies, individuals and trends etc.
Initial investigation reviled password hacking of email account and in turn translated to DNS server address manipulation. It was a well-planned attacked, where Email IDs created for password recovery was also hacked. As experts reset the password for amethi@hotmail.com and accessed the account, they found several suspicious emails. "These emails were sent by domain management console, godaddy.com (of amethinet), to an unknown person on his request regarding password recovery," says the FIR.

Officials said the recovered emails revealed the times at which the IP address password recovery requests were generated by the hacker. "The unknown hacker has cracked all of our domain management console passwords using password recovery email account amethi@hotmail.com and has made changes in DNS zone files so that it got redirected into some other websites," the FIR said.

Amethinet and raebareli were created specifically to address the constituents, but the former, after hacking, opened onto www.pdmce.ac.in, the website of an engineering college in Bahadurgarh, Haryana. When Rahul's team checked the domain name system (DNS) of the website, it showed an IP address different from that of Rahul Gandhi's network. "Amethinet domain is registered with godaddy.com domain and when officials tried to log in to the domain management console, it was not working," the FIR said.

The FIR was filed under 66 Information Technology Act. According to the Act-

  1. Whoever with the intent of cause or knowing that is likely to cause wrongful loss or damage to the public or any person destroys or deletes or alters any information residing in a computer resource or diminishes its value or utility or affects it injuriously by any means, commits hacking. 
  2. Whoever commits hacking shall be punished with imprisonment up to three years, or with fine which may extend up to two lakh rupees, or with both.

Wednesday, June 8, 2011

Rating future Security Services-Cloud.......



Customer in Dilemma with Current Business Trends around security-Every business runs on some basic trust. In today’s digital world, Compliance and standard are the enablers to achieve security along with optimized performance. Every service company has same compliance standards to showcase their capabilities and security mechanism in place. So Customers have no clue which company and services to opt for since every Service companies are providing security using limited available products.



Can Security be rated the way Car Manufacture rate their Products -5Star safety rating. Also, even Other industries(hospitality) rate their services and products like5Star, 4star. To distinguish service providers would be as easy as buying a new car. While dealing with Customer it gives quantitative value and provides more confidence. 

In Near future, do we expect same approach by some Global Security Body(GSB) or by Analyst Firms(Gartner etc) to define star rating for Security which may be mapped with the compliance standards. I am sure most of you will have some concerns around this thought, but let’s take a scenarios of Cloud based solution which are rising  exponentially. Customer should have some  mechanism to identity and rate service provider based on simple rating…These ratings are in turn will be mapped with the Security Infrastructure  hosting the service , like Gateway  security solution, Data Loss Protection, SIEM, Proprietary Encryption and digital signature mechanism, Digital Right Management etc. Also, it won’t be limited to Technology solution; however operational processes needs to aligned as part of compliance standards.

Monday, June 6, 2011

Required Security Solution around Mobile Devices based on recent research.

  • Laptop encryption will be made mandatory at many government agencies and other organizations that store customer/patient data and will be preinstalled on new equipment. Senior executives, concerned about potential public ridicule, will demand that sensitive mobile data be protected
  • Theft of PDA smart phones will grow significantly. Both the value of the devices for resale and their content will draw large numbers of thieves.
  • Cell phone worms will infect at least 100,000 phones, jumping from phone to phone over wireless data networks. Cell phones are becoming more powerful with full-featured operating systems and readily available software development environments. That makes them fertile territory for attackers fueled by cell-phone adware profitability.

Technology solution for a Broken Trust

Enterprise is a combination of 3 pillars- People, Process & technology solutions in order to provide value added services to customer keeping Trust assurance.


An employee uses various devices in an enterprise, since the IT companies are user friendly and support mechanism like smart phones, wireless system and personal Laptops 
which may or may not be aligned with IT security policy.There have been cases of data loss, where employees were part of such act at will. A report by Bnet shows that 45 Percent of employees take data when they change jobs. Such is the case with a former HP employee Atul Malhotra, who had allegedly sent copies of IBM confidential documents to his Vice Presidents at HP. Prior to joining HP, he was employed by IBM and had access to this information.




How can we stop data theft against malpractice?
There is an obvious need to minimize breaches of security, but this task goes beyond simply securing the technologies. Solutions have to be pragmatic and relevant to work processes they are going to protect, so there may be trade-offs. Users have to work with the solution and if usage is too complex or cumbersome it won't work.
This means that C-level management should take a more active role as security shifts from being technology-centric to business risk-centric. Security decisions should involve business-level discussions, and management is in a better position when it comes to determining the risks involved. And the biggest security risk may turn out to be a disgruntled employee.

How could this incident have been prevented?


Proper implementation of DLP would have marked this data as sensitive and rated it a highly critical. Common exit points of this type of data breach are corporate email, web mail, FTP, removable drives and printing. At any of these exit points DLP would have flagged this activity. Periodically, Security Policy should be reviewed and transformed as part of DLP solution.

Thursday, June 2, 2011

It’s A Risky Business ?? Cloud v/s In-house


Cloud computing- once considered a mere buzz-word- in now a happening reality. Cloud based solution provide mechanism to host office on the cloud not just because they are cheaper(they do away with Software costs & hardware), but also provide flexibility to access information from any place with a decent internet connection. It typically works service on depend on rented environment.
So if you’re not on the cloud already, you might want to check out options to see what you’ve been missing out on…
Five Free web based office Suites that might of use

1. Google Docs
2. Office Web Apps
3. Thinkfree
4. Documents to Go
5. Zoho
Fortify Software sponsored a survey of 100 hackers at last month. They discovered that 96% of the respondents think that the cloud creates new opportunities for hacking, and 86% believe that “cloud vendors aren’t doing enough to address cyber-security issues.”

In line with the recent developments, Amazon.com Inc. (AMZN)’s Web Services cloud- computing unit was used by hackers in last month’s attack against Sony Corp.


Is it secure and reliable solution for Customer ?Are we expecting to see growth and Customer attention ?
Definitely, such event will not slow down the usage of Cloud based system, infect it will encourage system owner to build robust security framework. The major loop holes or one of the biggest weak link is the limited user awareness on security i.e. password management.
It has been observed that majority of users either use same password across all the system/application they use or store password in file without any encryption mechanism. User needs to be educated on best practices of password management strategies. Multi-level authentication like OTP should be introduce which will also reduce social engineering attacks.
Intentional attacks can happen from anywhere, but at a same time Cloud provider needs to introduce background verification process to reduce attacks within the cloud …

Cloud solutions are not the only one experiencing issues related to security, however major player in the market devastated and trying to realign the security framework from the security breach.

  • NASA website hacked(May 11, 2011, 04.53pm IST)-According to Fox News, hackers compromised pages on NASA's Jet Propulsion Laboratory website, before the May 16 scheduled launch of the shuttle Endeavor. The affected pages included barrages of "nonsense text" and interest-generating keywords, like "Edit buy adobe premiere pro cs4 some callouts and balloons to make this time it took you and saved you a long time,
  • Nasdaq Confirms Servers Breached
  • Hackers steal owner data from Honda
  • Two Arrested For AT&T iPad Network Breach
  • Nigerian government agency website hacked by “Cyberhacktivists”
  • 100,000 Credit Cards Compromised By Data Breach



Wednesday, June 1, 2011

High Tech Identity Theft-Electronic Pick Pocketing

Technology advancement has lead to many security issues and concerns around the world. Identities are the common and popular target in today scenario. Identities can be credential based or digital identities. Credentials based theft can be prevented by using complex password policy and mechanism along with user awareness. One of the Immerging trends of Digital theft is Electronic Pickpocket to steal your credit card information and passport information. Around 10 Million Victims are affected by this advance form. Simple device is capable to fetch your credit card information, without touching your credit card.

Online Consolidation of Banking Information

The common problem an individual is facing around is management of information associated with identities. Internet is growing giant, which keeps on pulling- information, People, attract unethical community etc. Every user is furious and eagerly looking for Simplified solution to manage their identity & information in a structured form. One of such initiative is taken by mint.com to consolidate information from single interface with various security measures.
More than 5 million users are using this application; however it only available in US. There are various such initiatives, happening to provide Common Authentication body(CAB) under various verticals.
Question is –Are we opening more doors for malicious users by simplifying processes. Subjective to answer; however depends to individual exposure to technology/systems along with importance to ease.

Tuesday, September 8, 2009

TCPIP-Vulnerabilities & Countermeasures

Presentation on TCPIP-Vulnerabilities and Countermeasures


As usage of the Internet and TCP/IP protocols increases, their lack of Built-in security has become more and more Problematic.This paper describes a variety of basic flaws in TCP/IP Protocols and their implementations, and discuss solutions and work-around to these problems.Primarily it also includes exploitation of various design and implementation vulnerability using standard tools.

Teardrop
Some implementations of the TCP/IP IP fragmentation re-assembly code do not properly handle overlapping IP fragments. Teardrop is a widely available attack tool that exploits this vulnerability.

Land Exploit
Some implementations of TCP/IP are vulnerable to packets that are crafted in a particular way (a SYN packet in which the source address and port are the same as the destination--i.e., spoofed).

SYN FLOODING
  • SYN attack floods a targeted system with a series of SYN packets.
  • Each packet causes the targeted system to issue a SYN-ACK response, while the targeted system waits for the ACK that follows the SYN-ACK, it queues up all outstanding SYN-ACK responses on what is known as a backlog queue.
  • SYN-ACKs are moved of the queue only when an ACK comes back or when an internal timer (which is set at relatively long intervals) terminates the TCP three-way handshake

PING FLOODING (ICMP flooding)
An attacker sends a large ping packet to the victim's machine. Most OS do not know what to do with a packet that is larger than the maximum size, it causes the OS to hang or crash.


IP Spoofing
IP Spoofing is an attack where an attacker pretends to be sending data from an IP address other than its own. The IP layer assumes that the source address on any IP packet it receives is the same IP address as the system that actually sent the packet -- it does no authentication. Many higher level protocols and applications also make this assumption, so it seems that anyone able to forge the source address of an IP packet (called "spoofing" an address) could get unauthorized privileges.

IP Spoofing (Blind Attack)
Due to bad designing of the TCP/IP suite, it is almost trivial to spoof a packet apparently originating from a host that is NOT you. The term 'IP spoofing' can be used to describe any process in which a person fakes, or "forges" a packet to look like it came from elsewhere, often a "trusted" host. The ability to spoof IP packets, and the fact that IPv4 does NOT check the validity of the source address and source port in a packet's headers is one of the MAIN vulnerabilities in the TCP/IP protocol suite.

The probability of guessing the sequence number i.e. Attack Feasibility is outlined in below matrix:

Sr. No
Operating System
Attack feasibility
1
Linux
0.05%
2
Windows 2000
12.08%
3
Windows NT4 SP6a + hotfixes
15%
4
Windows 95
100%
5
FreeBSD 4.2 1
4.2 1.00%
6
OpenBSD-current
0.00%
7
HPUX11
100.00%
8
AIX 4.3
100.00%

ISN Attack Feasibility

TCP Session Hijacking (Active Attack)

Tools like Juggernaut (1.02 patch) and hunt are making these once sophisticated attacks very easy.
TCP session hijacking is the term used to describe an attacker hijacking an
already established connection, usually allowing them to execute commands as the actual connected user.

It is due to slight design errors in the TCP/IP suite that this kind of attacks
is possible, making it almost trivial for the attacker who has seized access to
the connection to execute commands as the legitimate user.
There are a few various types of TCP session hijacking techniques, but a very
commonly used one, and arguably the most popular of TCP hijacking techniques is the "Man-in-the-middle" attack.

ATTACKS: TCP SESSION HIJACKING - MAN-IN-THE-MIDDLE ATTACK

The "man-in-the-middle" attack is a common method of taking over a TCP
connection between two hosts, and allows the attacker who has gained access to the connection to execute commands as the client host.

This is done by active passive sniffing of the network for packets travelling
which are related to the target session, modifying them, and injecting them back into the Network so that the two connected hosts cannot easily tell that any modification of the packets has been done.

ARP spoofing therefore is sending out ARP replies (nobody has necessarily asked for it, the attacker just sends one) with a spoofed source address from the IP address you want the hosts to believe you are Here is a small diagram of what would be happening during a Man-In-the-Middle session hijacking attack, assuming that the ARP poisoning attack had already taken place:

There are many such attack depicted in attached presentation [In-depth Presentation on TCP/IP Vulnerability]

Defenses/Counter-measures

As a network is only as secure as its weakest link.However, in mitigating DoS or DDoS attacks, it requires good network design to be able to control the point of entry or the gateway. As for mitigating new attacks, it is essential to have filtering capability based on packet header and content within the network or at the critical gateways in order to filter malicious traffic as a response to such attacks while waiting for a permanent solution from suppliers to be applied to the devices. Applying all known patches and fixes to all devices in the network to prevent known attacks is necessary. Finally, it is important to have the relevant referrals in the policy and legislation to address the issue of DoS and DDoS to ensure an effective cooperation between service providers and law enforcement agencies .
  • Hardening the TCP/IP stack (SYN cookies or SynAttackProtect)
  • Applying latest patches as recommended by your vendor
  • Perimeter Network device like Firewall and border internet router should block IP- spoofed packets and can capable of defending against SYN attacks. With the current IP protocol technology, it is impossible to eliminate IP-spoofed packets.However, you can reduce the likelihood of your site's networks being used to initiate forged packets by filtering outgoing packets that have a source address different from that of your internal network.
  • Apply Anti-spoofing filtering on network device (TCP sequence prediction attacks can be effectively stopped by any router or firewall that is configured not to allow packets from an internal IP address to originate from an external interface.)
  • ISPs could prevent the transmission of fraudulently addressed packets.
  • Servers could be programmed to recognize a SYN source IP address that never completes its connections.
  • The last network defense against SYN floods is to distribute the flood against as many hosts or network devices as possible.