Tuesday, August 27, 2013

Be Safe, It’s an Internet Frauds

We often receive emails from known and unknown sources asking for some favor or proposal. Internet fraud is a term used frequently to describe the fraudulent activities performed using the Internet as a medium. It is very easy to hide your identity and initiate the crime seating 1000 of miles away. This is generally propagated like the virus and takes a form of banking scam. The scam can be of many schemes as listed below 



























Estimates of the total losses due to the scam vary widely since many people may be too embarrassed to admit that they were gullible enough to be scammed to report the crime. In addition to the financial cost, many victims also suffer a severe emotional and psychological cost, such as losing their ability to trust people. One man from Cambridgeshire, UK, committed suicide by lighting himself on fire with petrol after realizing that the $1.2 million “internet lottery” that he won was actually a scam.

Before it’s too late let us understand how such scams are triggered. In this blog, I am going to discuss how Business proposal scam leads to financial loss and ways to identify and mitigates the same. 

I received the below email which has a very impressive offer.Let's analyze the mail.

Email Message 

Mail from Alice Farah farah_alice@voila.fr via yahoo.com 

---------------------------------------------------------------------------------------------
Dear Friend.

Greetings to you and your family, I am the manager of bill and exchange in THE BANK, I have a business of 5.5 Million United State Dollars to be transfer to your account for investment in your country, if you are ready to assist me get back to me, I will give you full details on how the fund will be transfer to you.

Be rest assured that everything will be handled confidentially because, this is a great opportunity we cannot afford to miss, as it will make our family profit a lot.

It has been 6 years go, that most of the greedy African Politicians used our bank to launder money overseas through the help of their Political advisers.

Most of the funds which they transferred out of the shores of Africa were gold and oil money that was supposed to have been used to develop the continent.

The Political advisers always inflated the amounts before transfer to foreign accounts so I also used the opportunity to divert part of the fund worth five million five hundred united state dollars I told you about and I am aware that there is no official trace of how much was transferred as all the accounts used for such transfers of fund at that particle time were closed after transfer.

I am the account officer to most of the politicians and when I discovered that they were using me to succeed in their greedy act, I also cleaned some of their banking records from the Bank files and no one cared to ask me for the money was too much for them to control, as I am sending this message to you, I was able to divert five point five Millions Dollars ($5.5M)which is in an escrow transit account belonging to no one in the bank, and now my bank is very anxious to know the real beneficiary of the funds is for they have made a lot of profits with the fund.

It has been more than five years ago and most of the politicians are no longer in power again and they don’t use our bank to transfer funds overseas anymore since their tenure had expired.

The $5.5 Million United State Dollars has been lying in the bank as unclaimed fund and I will soon retire from the bank immediately the fund is transfer into your account over there.

Immediately the fund has been successfully transfer into your account I will come to your country for the sharing of the fund, the fund will be shared 50% for me and 40% for you, and the other 10% for the orphanages home and poor with less-privilege people.

Please know that there is no one that is going to question you about the fund if you will comply with me and follow my instruction which will help us a lot to achieve this goal for everything is well secured.

Please indicate your interest in this transaction by replying back through my private email
and if you are not interested do not waste your time to reply kindly delete my message from your box ok.

Waiting to hear from you soon.

Yours Faithfully,
Mrs. Alice Farah.
------------------------------------------------------------------------------------------------------------


The best way to analyze the mail is to read the message header, which gives all the information i.e. when this mail was originated, source address, Number of hops or the device it has passed thru and so on. The below snippet shows a message header, which needs to be read from bottom in a chronological manner.

Message Header 

Please click on the below image for better resolution.




If you look at the full header information of the email you will most likely see a different reply to and/or return-path, which is the spammers email address. In our case Reply-To: alicefarah5@voila.fr is different then Return-Path: p.godpower@yahoo.com. So that means it’s a spam mail!!!The “From” address can be spoofed with your friend email address as well.

Now, let’s identify the origin of this mail. After analyzing the above message header you can get the below matrix showing how this message has transverse from different network and system. So that’s means the message you send over the internet can be tracked easily and necessary actions can be taken 

From
To
Time received
41.203.233.236
web161306.mail.bf1.yahoo.com [Web]
8/19/2013 7:06:33 PM
127.0.0.1
omp1005.mail.bf1.yahoo.com [Yahoo NNFMP]
8/19/2013 7:06:33 PM
98.139.212.196
tm12.bullet.mail.bf1.yahoo.com [Yahoo NNFMP]
8/19/2013 7:06:33 PM
98.139.215.141
nm47.bullet.mail.bf1.yahoo.com [Yahoo NNFMP]
8/19/2013 7:06:34 PM
nm47-vm1.bullet.mail.bf1.yahoo.com.
mx.google.com
[Google]
8/19/2013 7:06:34 PM
10.224.160.130
[SMTP]
[Google]
8/19/2013 7:06:34 PM
10.52.155.4
[SMTP]
[Google]
8/19/2013 7:06:34 PM

The origin of this message is from IP Address - 41.203.233.236.If you perform Whois IP Address lookup the below detail can be obtained. 

person:         Emmanuel GUIGMA
nic-hdl:        EG4-AFRINIC
address:        ONATEL, 01 P.O. BOX 10 000
address:        Ouagadougou 01
address:        Burkina Faso
address:        OUAGADOUGOU 01 BP 10000
address:        Burkina Faso
e-mail:         guigma@onatel.bf
phone:          +22650305847
fax-no:         +22650315386
source:    AFRINIC # Filtered 

It shows the origin of this message is from Africa.

Be safe and Please don't provide your personal details to such mail. 

Friday, August 23, 2013

Cyber Warfare a Global Digital Weapon

Not every battle starts from ground, air or water…These days, you'll find some of the fiercest fighting going on between computer networks. The Digital Age has transformed the way weapon are been used. Digital Weapon is the new terms referred across the organization & continents.  Rather than using bullets and bombs, the warriors in these confrontations use bits and bytes flowing over the public and protected network.

Cyberwar can be defined as Leveraging the Internet for political, military, and economic espionage activities. Cyber warfare is Politically motivated hacking to conduct sabotage and espionage.


Cyber warfare is a serious concern and only limited specialized skill resources are required, unlike traditional warfare where massive resources, weapon, and equipment are required. The cyber defense should be considered as the fourth arm after the army, navy and air force. Nations are spending huge investment in building young talent for establishing R&D center to defuse/activate attack. The objective is to steal sensitive information about the weapon, strategic and other information which may act as a major decision factor during the war. The reach of such attacks are more since all developed or developing countries are heavily depended on internet and attack can be initiated across the globe.

In today's scenario, many of the Government Sites are running with obsolete solution stack, Vulnerable deployment & coding practice, reactive threat management system making them prone for Cyber Attack.

Multiple cases that have been noticed for Cyber warfare between countries like US, South Korea, Pakistan, China, Israel &  India etc.

On  April 2013, Anonymous launched a cyber war against Israel. It was touted as  “the largest internet battle in history,” hitting 100,000 websites, 30,000 bank accounts, 40,000  Facebook pages and 5,000 Twitter accounts.

Indian Government Departments that have come under Repeated attacks Prime Minister's Office, Ministry of External Affairs, Indo-Tibetan Border Police and DRDO.According to official data, a total of 78 Indian government websites were hacked and 16,035 incidents related to spam, malware infection and system break-in were reported this year so far.

In India, their many agencies focused on Cyber defense are NTRO(National Technical Research Organization), National Critical Information Infrastructure Protection Center and CERT.

Thursday, August 22, 2013

It’s a Game of Power

Not always hacking is associated with stealing information, it sometimes a way to show power, demonstrate protest or a way to communicate thoughts publicly.

Recently, MTNL Mumbai website is hacked by Pakistan Hacker from Australia.




All the legitimate users redirected to a landing page showing message ‘Mr. Creepy was here. Happy Independence Day Pakistan’.

In this case, the 80 lakh customer data was not breached and site is up and running.

Similar, incident happened to other Indian sites like Pune Traffic Police and  Janwani, a social initiative of Maharashtra Chamber of Commerce and Industries & Agriculture, on the eve of India’s 67th Independence Day. The Image shows a guy colored in Green(Symbol of Pakistan) along with a group of people carrying Indian flag.  

Wednesday, August 14, 2013

Card skimming an epidemic!!!

A complex urban lifestyle has made technology advancement to ease the effort and time for carrying day-to-day activities in a busy schedule. Days have gone, when users use to carry a physical form of money for daily needs. Now, users are spending more time online for transactions and other payment related activities. This has lead to another form of fraud associated with cards i.e. skimming which may be described as creating an illegal replica copy of legitimate cards (Credit/ATM).

The scammers try to steal your identity details from the magnetic strip of card, so they can access your accounts and later propagate identity fraud. This may affect mass user community if planned and execute in public places like ATM booths. Fraud transactions are launched outside the boundaries which make even more difficult to enforce stringent laws.

Let’s understand how this is achieved by hiding fraud setup in the actual device of ATM -


Indian Banks are facing a tough situation as Card Skimming has led into a Massive scam and transactions occurring outside Indian Borders (like Mexico, Spain, and United States etc.) have led these financial institutions to face a loss up to Rs 30 Crore in the last one month. ICI Bank, Citibank, SBI Cards and Axis Bank. In fact, Union Bank has also requested some account holder to re-issue the card to mitigate risk raised by Visa.

RBI has already enforced some strict guidelines for the banks to established OTP as a second form of authentication which only users know.
Now, how did this Fraud happen? Fraud is executed by masking or copy the Victim card from the Transaction machine (Petrol Pumps, POS usage), ATMS, other Credit card agencies. Later it’s very easy to use for shopping and other transactions within and across the world.
How to Overcome
RBI made it mandatory to install EMV / Chips on the Cards and upgrade all Merchant Card Processing units to accept Chip-based cards only starting from July-2013.

Some alternative solution can also be implemented to minimize the fraud by enabling transaction approval over the registered number thru SMS. The owner of the card needs to approve the transaction by trying Yes/No. The user can immediately notify the branch if he received any approval notification for the transaction he has not performed.

Till the upgrade, users’ needs to be more careful while using cards and follow some standard checks during transactions 

Warning signs
  • A shop assistant takes your card out of your sight in order to process your transaction.
  • You are asked to swipe your card through more than one machine.
  • You see a shop assistant swipe the card through a different machine to the one you used.
  • You notice something suspicious about the card slot on an ATM (e.g. an attached device).
  • You notice unusual or unauthorized transactions on your account or credit card statement.

Protect yourself from card skimming


  • Keep your credit card and ATM cards safe. Do not share your personal identity number (PIN) with anyone. Do not keep any written copy of your PIN with the card.
  • Check your bank account and credit card statements when you get them. If you see a transaction you cannot explain, report it to your credit union or bank.
  • Choose passwords that would be difficult for anyone else to guess.

Tuesday, January 29, 2013

Banks Transitional move towards Unique Customer Identification Code( UCIC)

The increasing complexity and volume of financial transactions leads to customers having multiple identities within a bank, across the banking system and across the financial system.

Reserve Bank of India has enforced strict guidelines (Know Your Customer (KYC)/Anti-Money Laundering (AML)/Combating of Financing of Terrorism (CFT) Guidelines) to maintain and consolidate single login credential  for transaction operations.

The objective is to provide simple mechanism to track customer information across various channels. Using Unique Customer Identification Code( UCIC), customer can view and track all accounts/relationships with the bank. This will facilitate bank to perform audits and also enhance user ease. 

In this regard, a Working Group constituted by the Government of India has proposed the introduction of unique identifiers for customers across different banks and Financial Institutions for setting up a centralized KYC Registry. While setting up such a system for the entire financial system is likely to take quite some time, banks can make an immediate beginning in this regard by having such identification code for their own customers. HDFC bank has started the transitional move towards having consolidated identify across their customer.

Mapping and maintaining Unique Customer Identification Code will drive solutions like Identity & Access management. Similar, solution will facilitate bank to easily transform the business alignment with regards to upcoming guidelines from RBI.

Friday, May 25, 2012

Security Technology Marathon (Rise/Fall)

As we see more and more businesses are becoming internet-enabled with basic security mechanism in place. The year 2011 was one of the landmark years for high-profile cyber attacks. As the trend is said to continue in 2012 with more sophisticated and targeted attacks, security is a major concern for the IT users of all the segments from Home Users to SMB to Enterprise. Business needs to realign security strategies keeping upcoming security incident in near future. 

The number of data thefts has tripled in the past five years and the graph tends to rise with every passing year. Right from the Government, corporate, data centers and small to medium-sized companies all have been targeted. With the introduction of IT consumerization, issues such as managing and supporting consumer devices and securing data from criminals, malware, and other threats have emerged. Mobility in enterprise sector brings new challenges for managing data, as well as the wide range of devices in the network.

Let’s analyze the technology which may be refined to address the future needs and solutions which may be replaced. The analysis is carried based on various discussions with customer addressing the security challenges and Forrester's predictions.

Technology Rise

1. Risk-based predictive Access mechanism

Profiling of user authentication based on previous accesses and actions will be enforced on the security solution. The solution will perform Predictive threat modeling before providing accesses to data. The solution should be integrated with data encryption technology for all internet-enabled communication. The rise of such solution may be seen in next 3-5 years.

2. Mobile Security

Today organizations are facing major concerns around prevent security incident happening from mobile devices. Mobile devices are the backbone of any industry and hence employees may not be restricted from their use.
Mobile devices theft is alone should be reason enough for businesses to take a more rigorous approach to securing mobile devices, including tracking them when they go missing, and ensuring that remote-wipe capabilities are in place should it be too difficult or expensive to recover the devices. With the "bring your own device to work"--a.k.a. BYOD, or the consumerization of IT-- a trend in full force, expect to see more organizations attempt to add better security to their employees' mobile devices, including smartphones.
The other issues which should be tracked are stealing information from Smartphone using advanced malware and virus attempts. It is often hard to detect the presence and hence neglected for years.

3. Advanced auditing tools

To address the increase in a number of data breaches and current regulatory requirement, there may be a huge demand for sophisticated auditing and correlation tools. The solution will "have the potential to become ubiquitous in enterprise security organizations."Solution like SIEM may be redefined to address SMB

4. Malware analysis

An integrated solution may be required to analyze incidents with the vulnerability present in the system. The solution should identify hidden super malware, monitor basic operations and fight with Ransomware(an infection that holds a device “hostage” until a “ransom” payment is delivered). The rise of such solution may be seen in next 3-5 years. The technology should be flexible for Enterprises, SMB, and home users since attackers are trying to bypass the basic fundamentals of user operations.
The solutions should address the below concerns
  • SSL is safe(Myth), SSL Not So Safe- When you see the padlock icon in your browser's toolbar, you might think that your data is safe, but hackers have found ways to get at your information before you send it securely on the internet. These new forms of malware can identify when you've visited sites protected with SSL--the encryption technology used to keep data safe from prying eyes as it travels across the Internet--and it can grab your username and password before the encryption kicks in. In addition, these sorts of attacks, according to security software vendors, will ignore all Web traffic except encrypted sites to filter out information that it isn't interested in.
  • Super malware-Some malware can access your browser history, and will only infect you if it sees that you've visited certain sites. For instance, a piece of malware designed to steal online banking login information might check to see if you visited a particular bank's website. Expect more malware that goes after certain groups of people or specific bits of information.
  • New Malware Harder to Spot and Remove: You may be infected with malware and not even realize it. While older malware used to make itself known on your PC, newer forms of malware may not even have an interface, and they may not seriously impact your PC's performance. Instead, it all runs in the background, seemingly invisible to you. This hard-to-spot malware can also be hard to remove. For example, a relatively new rootkit called ZeroAccess buries itself deep into your system, and it's extremely difficult to disable since it effectively kills any program that tries to access it (hence the name ZeroAccess).
  • Malware Holds Your PC for Ransom: Ransomware is nothing new--it's been around for a few years in various forms, including fake antivirus software that won't go away unless you pay up. The company pointed to one example where a piece of malware would lock you out of your computer entirely unless you pay up.

5. Network encryption

Although network encryption exists in infrastructure devices such as routers and switches, demand for stand-alone appliances is just starting. In one to three years this could reach the next phase, though, without compliance pressures, this technology will be adopted by only the most stringent and largest of enterprises.

6. Predictive threat modeling

This relatively new concept calls for analyzing how to properly protect important data by proactively modeling threats. In three to five years it could hit the next phase, although the "costs and complexity of current threat modeling tools work as a barrier to adoption of this new technology."

7. DDoS (distributed denial of service) mitigation controls

Due to the increase in hacktivism, "the market for DDoS protection is poised for growth" within one to three years.

8. Storage security and DLP Integration

Storage security requirement may rise due to cloud-based technology adoption. Also, DLP enabled solutions may be redefined to address complex business requirements.

Security technologies may not survive next few years.

1. Network access control

Forrester believes the market for stand-alone NAC offerings will likely be phased out over the next five to 10 years. (Though Forrester suggests there's a bit more hope for "packaging NAC" in security software suites or infrastructure security.) Why is it bad news for NAC? Forrester says only 10% of technology decision-makers will implement it over the next 12 months because "solutions are complex to deploy, scale and manage." There are several NAC architectures, plus hardware and software approaches, and "all the approaches require integration with network infrastructure components." "NAC won't stop a malicious insider who wants to commit a security breach for financial or other reasons.

2. Secure file transfer (as an on-premise appliance)

The need to securely transfer and share files between business partners is high but in three to five years it's going to be done more and more with cloud-based services rather than appliances, according to Forrester.

3. Unified threat management

Though widely deployed in small and branch offices for DSL wide-area network implementations, UTMs face dislocation from new security gateways with more integrated firewall and intrusion features that make UTM look "antiquated.UTM technology may last one to three years to meet competitive challenges and be more "enterprise-ready," though it also acknowledges UTM is likely to be "moderately successful over the long run" in retail stores.

4. Network intrusion prevention (stand-alone)

The market for stand-alone intrusion-prevention systems (IPS), despite its success being deployed by the world's largest companies, is in decline and "will likely phase out in the next 5 to 10 years" as multi-function gateways and firewalls, especially NGFW, include IPS and are used instead of stand-alone IPS equipment.




Thursday, October 27, 2011

Technology Intersection = SMART SECURITY SERVICES

Every Object(Product or Services) has a defined lifecycle and trend associated. It’s often seen, object reaches its maturity which we call as a Peak point before dying or conversing to other technology stack. This is to develop more productive object to cater today’s demand.

Let’s take an example of TV…Traditionally; TV was the only source of entertainment for watching movies and other entertainment program. Later, Internet was picked up to perform business; day to day tasks along with other entertainment enabled services…In the beow diagram “PP” represent Peak point of maturity. Now, People started losing interest and deviating from TV as a product.

Now what???? Do we foresee lesser TV demand?

Please click on the below image for better resolution and display.....



Technology interaction between TV and Internet, which we call as “SMART TV “has developed a new curve out of its dying phase …

SMART TV= TV + Day-to-Day internet enabled Task.
The similar cycle will continue after SMART TV ….Please carefully review both the curves

The above concept will also be applicable to Technology services…If you closely assess the 2nd curve, which produce “SMART IT SERVICES” due to intersection of Internet with Technology services. This intersection has produced cloud enabled services. 

SMART IT SERVICES:  Less expensive (in comparison with traditional form)+ Easy Rollout + Easy Transition+ Pay As You Use+  Highly Available + Best bread Technology Stack + Many More ..

The initial intersection phase is called as acceptance phase, where it’s   been evaluated and truly accepted before it is taken and developed for maturity.

SMART SECURITY SERVICES –Let’s align SMART IT SERVICES for Security enabled offering.
  • Identity as a Service
  • Authentication as a Service
  • VAPT as a service
  • Managed Security as a Service
  • Other security as a service 

Monday, October 24, 2011

Global Password Management Best Practices

In continuation with recent post “5-Which of Password Management”, I thought to drill down on best practices of Global password management. We are calling “Global”, since it is not confined to any entity and even user doesn’t have control on to the application practices. Each application has different password policies and hence password expiration would be different….
Many Username, Many password !!!!!!

Please click on the below image for better resolution and display.....


Using this approach User will only need to remember 4 passwords for Username & Password File.
Please note these are my view and many of you may differ with this approach; however the objective is to provide simplicity using existing tool, Easy Remote management and high security

Thursday, October 6, 2011

Safeguard Enterprise Data during Employee Separation

There have been cases of data loss, where employees were part of such acts during the transition to the new job. A report by “Bnet” shows that 45 percent of employees take data when they change jobs. Such is the case with a former HP employee, who had allegedly sent copies of IBM confidential documents to his Vice President at HP. Prior to joining HP, he was employed by IBM and had access to this information.

Before we drill down, let's analyze the reasons which can be multiple- 

  • Identity & Access Management (IAM) solution not correctly in place or may not be designed effectively-It is often observed that enterprise doesn't develop correct boundaries for IAM. The most important question every CISO or CIO concern about is optimization and efficiency around processes with minimal security incident (to make close to zero). This often leads to comparison with peers on-

          -How we are doing as an organization?

          -What is the next step for building our secure Environment using 

           IAM infrastructure?
          -How to develop IAM maturity model

  • Data Loss Prevention system is missing or may not be developed correctly.
  • A vendor has not captured all the scenarios (happy & unhappy) while developing the system.
  • The vendor is not equipped with SME and domain expertise to understand Technology trends.
  • Periodic system and process review mechanism not in place.
Let's define the best practice approach to avoid such scenarios in Enterprise-

  • Identity & Access Management(IAM) solution-Developing a Strong Enterprise processes-Separation Process should be in place to handle employee resignation scenario and removing access rights to critical systems during Employee Notice period.HR system should be designed to provide user resignation information to the IDM system for de-provisioning of critical systems. However, the above process can be modified/realigned keeping the Business objective in mind.
  • Enforcing Periodic System and process review 
  • Enterprise needs to align with vendors who understand the Subject and can translate business processes keeping domain and business objective in mind.
  • Missing Data Loss Prevention system-A Proper implementation of DLP would have marked this data as sensitive and rated it highly critical. Common exit points of this type of data breach are corporate email, webmail, FTP, removable drives, and printing. At any of these exit points, DLP would have flagged this activity. Let's explore the effectiveness of DLP in the enterprise-There has been misleading information of DLP being able to identify 370 plus file formats. File type identification does not translate into content inspection. It is roughly about 180 file types that this technology can interpret and inspect the contents. In order for DLP to do its job effectively, content inspection is important. Customers tend to get sold on the sheer number of 370, when in fact DLP is equipped to tear down the file on less than half of them.